Repository navigation
Prepare Kitaru 0.26.0 coordinated release - #1074
Merged
Merged
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
schustmi
approved these changes
Sep 10, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed?
Prepare the coordinated Kitaru 0.26.0 release with UI
kitaru-ui-v0.5.0, ten Python plugins, and the TypeScript 0.3.0 package set. UI 0.5.0 is published and its bundle checksum is verified; the core rehearsal wheel includes that exact bundle.Why?
The release brings the merged import, analyzer, provider-connection, and Mastra replay work into installable versions with matching server defaults. Core 0.26.0 is the deterministic proposal from the latest stable 0.25.0 and all merged PR labels, including the breaking import-response change.
Release context
Selected releases
kitarukitaru-braintrust-importerkitaru-langfuse-importerkitaru-langsmith-importerkitaru-logfire-importerkitaru-phoenix-importerkitaru-jsonl-importerkitaru-pydantic-aikitaru-claude-agent-sdkkitaru-mastra-importerkitaru-post-import-insights@zenml-io/kitaru,@zenml-io/kitaru-mastra,@zenml-io/kitaru-vercel-aiLeave
kitaru-evaluator0.1.3,kitaru-langgraph0.1.2, andkitaru-openai-agents0.2.0 unchanged: their package paths have no changes since their own stable tags. Vercel AI participates in the documented TypeScript lockstep release despite having no direct implementation change.Complete core source PR range since 0.25.0
#940, #970, #972, #973, #974, #975, #976, #977, #978, #980, #983, #984, #986, #987, #988, #992, #993, #994, #995, #996, #997, #998, #999, #1000, #1001, #1004, #1005, #1007, #1008, #1009, #1010, #1011, #1013, #1014, #1015, #1016, #1017, #1018, #1019, #1020, #1021, #1022, #1023, #1024, #1032, #1033, #1034, #1036, #1037, #1039, #1041, #1042, #1043, #1044, #1045, #1047, #1048, #1063, #1064, #1066, #1069, #1072
Compatibility and ordering
The insights package requires core
>=0.26.0. The five provider importers retain basekitaru>=0.24.0for file parsing, but theirapiextras now require>=0.26.0; eachadapterextra includes[api]and inherits that floor. Core 0.25.0 lacks the query and retry APIs those modules import. All selected default requirements/display versions match their package manifests; adapters and the Mastra importer remain outside the default catalog.kitaru-ui.tar.gzandkitaru-ui.tar.gz.sha256. Rehearse the eligible release commit without publication.python/kitaru/v0.26.0, then verify its PyPI availability before dependent plugins. Public image and Helm jobs may still be running.typescript/kitaru/v0.3.0and verify all three npm packages before publishing the Mastra importer, whose recorded-context replay requires the new adapter.0.1.0rc0; run its released-candidate live smoke before proposing a stable promotion.mainto the reviewed release commit, then reviews/merges the generated development-reset PR ondevelop.Core startup stores the queued default package requirements without installing them. Worker tasks that select those versions must wait until their packages are available; there is no automatic fallback to an older package.
Pending publication and follow-ups
Reviewer Notes
Start with the compatibility split: a file-only user can retain core 0.24.0, while installing
[api]or[adapter]must select core 0.26.0. Verify that the five provider extras and insights wheel express those floors. A permissive API floor installs successfully but fails when the API module imports unavailable core symbols.Review the five importer changelogs for source-identity changes. Phoenix now prefixes external IDs with project identity, so reimporting older bare-ID traces can create additional sessions. The assembled core changelog incorporates both fragments and the legacy Mastra entry, and removes superseded empty-analysis behavior.
Reproduction
Run
uv run --no-sync python scripts/smoke_plugin_artifacts.py --candidate-dir plugins/candidate-wheelsto build clean wheel installations and verify default registration twice. Inspect wheelMETADATA: no development placeholder or checkout URL should occur inRequires-Dist.Follow the quickstart candidate-install steps in
.github/workflows/ci.yml, then run itsscripts/run_ci_e2e.pywith PostgreSQL available. Expect a fresh server, ten imported sessions, completed built-in/custom evaluations, and a cohort; the harness cleans up its isolated database. For the published path, runuv sync --frozenanduv run --frozen python scripts/run_ci_e2e.pyfrom the example directory before installing candidate wheels.Local checks run
just check, release inventory validation, exact UI declaration validation, andgit diff --checkpassed.The preparation checks above preceded merge. Post-merge rehearsal and artifact evidence, plus exact publication commands, follow below. No paid provider calls or deployment were performed.
Verified post-merge publication handoff
PR #1074 merged at
0d806f832e3afa05ad14bd045629dd8be4f51afe. Its tree matches the approved candidate. All selected tags were unused at verification. Run these commands inzenml-io/kitaru; each tag deliberately names the exact reviewed commit, independently of later branch changes. These commands publish packages and require the release owner's explicit go-ahead.Core first
The core non-publishing rehearsal 34494267685 passed at this commit. Both artifact checksums passed, and the wheel includes 201 UI assets with the verified UI 0.5.0 checksum. All publication jobs were skipped. A local serving smoke using the actual rehearsal wheel passed for the root and SPA routes and all 199 static assets; browser rendering was not exercised.
TypeScript after rehearsal
The TypeScript non-publishing rehearsal 34494271785 passed at the exact merge SHA, with publishing skipped. All three tarball checksums, packed manifests, clean Node 22 install, five public exports, client construction, and strict TypeScript consumer compilation passed. Wait for core 0.26.0 PyPI availability before running this block. One tag publishes all three npm packages.
Python plugins after core and TypeScript
Wait for the core publish-python job and verify exact core 0.26.0 on PyPI. Verify all three npm 0.3.0 packages before the Mastra importer. Run the remaining plugin rehearsals, including the insights registry-install check that needs published core 0.26.0. Push each tag separately and check that its workflow starts.
Completion and independent follow-ups
After all required public core artifacts and its GitHub Release succeed, verify that main can fast-forward to python/kitaru/v0.26.0 and give the release owner the main-promotion commands. Complete that promotion before merging the generated development-reset PR. The public quickstart remains runnable on its verified published 0.25.0 lockfile.
kitaru-skills#51 remains open. Its proposed 0.17.0 version and reviewed release commit must be settled separately under its skills-release instructions; no skills tag is ready yet. Frontend #521, the ZenML docs follow-up from #994, and hosted model availability from #1024 remain independent follow-ups.