Skip to content

Modernize Storefront SDK for v1.2 - #12

Merged
roncodes merged 8 commits into
release/v1.2.0from
feature/release-v1.2-sdk-modernization-plan
Sep 26, 2026
Merged

roncodes merged 8 commits into
release/v1.2.0from
feature/release-v1.2-sdk-modernization-plan

Conversation

@roncodes

@roncodes roncodes commented Aug 31, 2026 •

Copy link
Copy Markdown
Member

Summary

  • refactors all maintained runtime source to strict TypeScript while preserving the v1.1.14 public and wire contracts plus the accepted marketplace APIs from PR feat: add marketplace SDK helpers #11;
  • restores genuine ESM and directly constructible CommonJS, generates strict declarations, and ships a self-contained browser entry;
  • adds deterministic contract and failure-path tests with exact 100% statements, branches, functions, and lines plus an 86.32% critical-path mutation score;
  • verifies the exact packed tarball through npm, pnpm, Yarn, Bun, Vite, webpack, Next.js client/server, Ember with Vite/Embroider, browser, SSR-safe import, and three TypeScript resolver modes;
  • modernizes CI, security, dependency automation, release-branch tagging, npm trusted publishing and provenance, immutable checksummed artifacts, and scheduled/manual non-destructive API smoke testing;
  • rewrites the README and adds API, compatibility, migration, contribution, security, release, and audited route-contract documentation.

Release stack

This pull request targets release/v1.2.0, not main directly.

  1. Review and merge this PR into release/v1.2.0.
  2. Release PR Release v1.2.0 #14 then contains the complete v1.2.0 source, version, changelog, and release notes.
  3. After all application and repository gates pass, merge PR Release v1.2.0 #14 into main.
  4. The release workflow validates branch/version/note parity, creates v1.2.0, publishes the verified tarball through the protected npm environment, and creates the checksummed GitHub Release.

Compatibility and security decisions

  • the default constructor, newInstance, named exports, stores/actions, request verbs/paths/payloads, synchronous errors, resource hydration, and callable CommonJS shape are frozen by executable snapshots;
  • @fleetbase/sdk@1.2.13 cannot be safely externalized: webpack reports no ESM exports and its advertised CommonJS .js file is inside a type: module boundary;
  • the SDK is therefore a patched build-time-only input bundled into all runtime artifacts; consumers no longer install its vulnerable dependency graph;
  • countries-list and date-fns remain normal external runtime dependencies;
  • historical src/cart-store and src/customer-store deep paths were unreachable and blocked by the old exports map, so their active action-based replacements remain the compatible public surface.

Verification

  • pnpm run check passes at package version 1.2.0;
  • coverage is 364/364 statements, 306/306 branches, 189/189 functions, and 343/343 lines;
  • mutation baseline is 164/190 mutants killed, 86.32%, above the required 80%;
  • pnpm audit --prod --audit-level moderate reports no known vulnerabilities;
  • the verified tarball passes ESM, callable CommonJS, Node16/NodeNext/Bundler declarations, browser global, npm/pnpm/Yarn/Bun, Vite, webpack, Next.js client/server, and Ember Vite/Embroider consumers;
  • CI covers Node 22 and 24, experimental Node 26, package consumers, framework consumers, dependency review, production audit, mutation testing, and CodeQL.

Release-owner gates

  • configure the documented npm-production and storefront-smoke GitHub environments;
  • configure npm trusted publishing for .github/workflows/publish.yml;
  • ensure the repository inherits the organization _GITHUB_AUTH_TOKEN used by the shared release-tag workflow;
  • record Storefront Web/App and marketplace acceptance;
  • merge release PR Release v1.2.0 #14 only after those gates pass;
  • verify npm provenance, dist-tags, registry metadata, and the tarball SHA-256 attached to the GitHub Release.

No package is published by this pull request.

@roncodes
roncodes force-pushed the feature/release-v1.2-sdk-modernization-plan branch from 8051bb8 to a3633b2 Compare August 31, 2026 11:41
@roncodes roncodes changed the title Plan Storefront SDK modernization and release hardening Modernize Storefront SDK for v1.2 Aug 31, 2026
@roncodes roncodes mentioned this pull request Sep 26, 2026
@roncodes
roncodes changed the base branch from main to release/v1.2.0 September 26, 2026 06:14
@roncodes
roncodes merged commit 68273a6 into release/v1.2.0 Sep 26, 2026
29 checks passed
@roncodes
roncodes deleted the feature/release-v1.2-sdk-modernization-plan branch September 26, 2026 06:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant