Repository navigation
docs: process documents and release tooling for the 1.0-beta release - #519
Conversation
Supersedes the 2026-08-07 plan. Describes the package split, the 1.0-beta release branch, per-package staging branches, the test-first sequence for core, routing of the 33 review findings, and lockstep publishing with semantic-release. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Two trivial assertions on the committed sample-sr.dcm fixture. The purpose is to exercise the CI checks on the 1.0-beta branch and prove they run and report on pull requests. See RELEASE_PLAN.md section 6, step 0. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…e 24 fs.readFileSync can return a small file inside a larger shared memory pool. Taking .buffer on that result hands the parser the whole pool, with the file sitting at a nonzero offset, and the DICM marker check then fails. Node 24 pools more aggressively, which is why anonymizer.test.js and data.test.js fail there today (7 tests) while Node 22 passes by luck of alignment. This adds readFileAsArrayBuffer() to testUtils and routes all 22 file-read sites through it. Typed-array .buffer uses are untouched. Same class of problem as issue #311. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ware helper The first pass converted single-line fs.readFileSync(...).buffer sites. CI on Node 24 then failed in a second population: reads assigned to a variable first, with .buffer taken on a later line. This converts those sites in data.test.js, data-options.test.js, lossless-read-write.test.js and normalizers.test.js, and drops the imports that became unused. Sites that already handle byteOffset correctly are untouched. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
ensureTestDataDir checked for the directory and then created it. Two parallel jest workers can both pass the check, and the slower mkdir then fails with EEXIST, which failed test_multiframe_1 on one CI leg. mkdirSync with recursive:true succeeds whether or not the directory exists, so the check goes away. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Three process documents the release plan calls for. The style guide defines the audience (healthcare-literate, no assumed programming or imaging jargon) and bans machine-flavored prose. The PR template requires plain-language descriptions, runnable examples, test evidence, and fixture citations. DATACITATION.md records the origin and license of every committed DICOM test file, with the legacy files honestly marked as provenance-pending. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
semantic-release computes one version from conventional commits; stamp-workspace-versions.mjs writes it into every publishable workspace package.json, and pnpm -r publish releases them together under the npm beta tag. The publish workflow now also fires on 1.0-beta and release/0.5x, and passes NODE_AUTH_TOKEN for pnpm publish. Nothing publishes until the repository owner adds 1.0-beta to the publish environment allowlist. See RELEASE_PLAN.md sections 9 and 12. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Adapts the rules from Cursor's unslop skill: the fuller AI-vocabulary list, filler phrases, fancy synonyms for is, vague attributions, synonym cycling, false ranges, punctuation and formatting rules (em dashes, colons, bold, sentence-case headings, straight quotes), abstract metaphor nouns, and a plain-speech section that includes the rule against over-compressed arrow-speak. Also states the boundary this guide draws that unslop does not: metaphors that teach a concept to a non-technical reader stay, metaphors that decorate go. The guide's own prose now follows its own em-dash rule. Source: https://github.com/cursor/plugins/blob/main/pstack/skills/unslop/SKILL.md Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Adopts wayfarer3130's review comments: the engines split from the data types (core = building blocks only; legacy = today's readers and writers; parser = the new streaming reader; generator = the new writers). The vendored dicom-parser tokenizer is dropped from the 1.0 stream entirely, and about 300 tests retire with it. @dcmjs/media is added as a bundle over dicomdir, pdfs, and video, which all remain individually installable. The wrapper publishes as @dcmjs/dcmjs during the beta so the real dcmjs name stays untouched until the team is ready. FHIR stays in the plan with its landing order marked as an open question. Section 7 is rewritten to the simpler tests-travel-with-code approach discussed since the first draft. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…s sequencing Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
There were three things found that I htink are worth looking at:
Before GA: no effect, because the file is only on 1.0-beta.
Suggested fix: write the step in RELEASE_PLAN §9 (for example, the first package merge has a BREAKING CHANGE: footer). Or run semantic-release --dry-run --branches 1.0-beta to confirm.
RELEASE_PLAN §3 and §9 say that the beta publishes as @dcmjs/dcmjs, and that "the unscoped dcmjs name starts publishing ... when the team decides it is ready." The beta tag does not change latest, so users that do nothing are safe. But the plan and the config disagree. Ask the author which result is correct, and change the other one.
|
wayfarer3130
left a comment
There was a problem hiding this comment.
A few comments,
also dcmjs is already claimed, by "dcmjs", which might be Steve, or it might be whoever registered the other dcmjs github (whcih hasn't done anything)
…arifications from review Rewrites the section-1 metaphor in direct terms and retitles section 6. Adds the breaking-change-commit requirement for the first 1.0.0-beta.1 version calculation, documents the private root package during the beta, records dist-tag promotion as a deliberate manual step, and fixes the appendix publishCmd to tag by channel instead of hardcoding beta. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ng the beta Review found the publish command hardcoded --tag beta, which would have followed 1.0-beta into master at GA, and that a recursive publish would ship the unscoped dcmjs name during the beta against the plan's intent. The tag now derives from the release channel, and the root package is private until the @dcmjs/dcmjs wrapper PR renames it. Dist-tag promotion stays deliberately manual, now documented in RELEASE_PLAN section 10. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Thanks Bill — all four are addressed on this branch (and flowing to the staging branches):
🤖 Generated with Claude Code |
|
@awatson1978 - can you update the notes to indicate we will publish to @dcmjs-org/ paths and will reconsider if we can get the @dcmjs path later? I've contacted the owner of that, but don't have a response yet. |
The @dcmjs npm organization is not ours; per review discussion the packages publish under @dcmjs-org (matching the GitHub organization), and the team can reconsider the shorter scope if its owner responds. Every package name in the plan now reads @dcmjs-org/. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Done — everything now reads 🤖 Generated with Claude Code |
Per review on #542: the guide existed to hold the staged-landing PR descriptions to one standard, and every description is now written. Removed rather than kept stale; git history preserves it if the team wants it back later. The PR template keeps the one-line spirit of it. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
# Conflicts: # RELEASE_PLAN.md
wayfarer3130
left a comment
There was a problem hiding this comment.
Just a few changes for better security/publishing design - note that trusted publishing will become required in 2027, so we might as well go with it.
- Raise minimumReleaseAge to 2880 (2 days).
- Pin semantic-release and its plugins as exact devDependencies.
- Pin each action by commit SHA.
- Publish with OIDC trusted publishing instead of the long-lived npm token.
- Turn off cache: pnpm in the publish job.
…publish job Review feedback from #519 (trusted publishing becomes required in 2027, so adopt it now): - minimumReleaseAge 1440 -> 2880 (two days) - semantic-release and its five plugins are exact-pinned devDependencies installed from the lockfile; the publish step runs pnpm exec semantic-release instead of cycjimmy/semantic-release-action with runtime-fetched extra_plugins - every action in the publish workflow is pinned by commit SHA - npm auth is OIDC trusted publishing: no NPM_TOKEN/NODE_AUTH_TOKEN, no registry-url .npmrc; RELEASE_PLAN documents the per-package trusted publisher setup and the first-publish bootstrap - cache: pnpm removed from the publish job Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
All five are in (fe4c87e) — agreed on getting ahead of the 2027 requirement rather than migrating later:
Appendix B in RELEASE_PLAN now states the whole hardening posture in one place so it survives after this PR's conversation. 🤖 Generated with Claude Code |
…them pnpm 11 stopped reading package.json pnpm.overrides (it warned on every install), so the security pins silently stopped applying and the audit gate failed once the lockfile was regenerated: form-data@3 and ws@7 resolved to advisory-vulnerable versions through jest 27's jsdom chain, with more paths added by the new semantic-release devDependencies. Ports the fix already on release/1.0-beta-core: the overrides block (old pins plus audit minimums for adm-zip, js-yaml, brace-expansion, browserslist, ws@7, form-data@3) and the braces GHSA ignore (advisory names a patched >=3.0.4 that still does not exist on the registry; all paths are dev tooling) live in pnpm-workspace.yaml, and the dead package.json pnpm field is removed. pnpm audit --audit-level=high exits 0; full suite 320/320. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
The audit failure after the previous push had a root cause worth recording: pnpm 11 stopped reading 🤖 Generated with Claude Code |
This PR is the first step of the plan in #518. It adds the process documents and the release tooling for the
1.0-betarelease. Merge of this PR publishes nothing.Process documents
.github/PULL_REQUEST_TEMPLATE.mdsets what a PR description must have. A small staging PR fills in the summary and the checklist only. Each package merge into1.0-betafills in all sections: a runnable example, test evidence, benchmarks where the PR claims a performance change, and fixture citations.DATACITATION.mdrecords the origin and the license of each committed DICOM test file. The format follows the file of the same name in OHIF. The origin of the six oldertest/*.dcmfiles is not known yet. The planned@dcmjs-org/fixtureswork traces these files, or replaces them with synthetic files (RELEASE_PLAN.md, section 6, step 2).Release tooling
All packages release together, with one shared version number:
scripts/stamp-workspace-versions.mjswrites that version into the root package and into each public workspace package. The script skips private packages.pnpm -r publishpublishes all public packages. On1.0-beta, the packages go to the npmbetatag.The changes:
.releaserc.jsonsets three release branches:master,1.0-beta(prereleasebeta), andrelease/0.5x(range0.x). The@semantic-release/npmplugin only sets the version and does not publish. The@semantic-release/execplugin runs the stamp script andpnpm -r publish..github/workflows/publish-package.ymlnow also runs on a push to1.0-betaand torelease/0.5x. The workflow loads@semantic-release/exec, and setsNODE_AUTH_TOKENfromNPM_TOKEN, becausepnpm publishreads that variable.package.jsonmarks the rootdcmjspackage"private": trueon this branch. A recursive publish thus cannot publish the unscopeddcmjsname by accident (RELEASE_PLAN.md, section 9).test/stamp-workspace-versions.test.jshas two tests. The first test stamps a scratch workspace and makes sure that the script skips private packages. The second test makes sure that the script rejects a string that is not a version, and changes no file.Corrections to RELEASE_PLAN.md
@dcmjs/scope. An earlier rename to@dcmjs-orgalso changed this historical sentence by mistake.@dcmjs-orgnpm organization, if necessary. The item also tells the owner to make sure thatNPM_TOKENcan publish new packages under@dcmjs-org. The old item named the@dcmjsscope.Before the first publish
The
publishGitHub environment still controls the workflow. The workflow cannot run from1.0-betauntil the repository owner does the actions in RELEASE_PLAN.md, section 12:1.0-beta.1.0-betato the allowed branches of thepublishenvironment.@dcmjs-orgnpm organization, if necessary, and make sure thatNPM_TOKENcan publish under that scope.An earlier version of this PR also added
docs/WRITING_STYLE.md. Commit 2a5935e removed that guide, because the authoring work is complete.🤖 Generated with Claude Code