Repository navigation
Prepare Kitaru 0.27.0 release - #1141
Merged
Merged
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
strickvl
marked this pull request as ready for review
September 21, 2026 15:31
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
schustmi
approved these changes
Sep 21, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed?
This prepares one coordinated stable release: Kitaru core
0.27.0, the TypeScript package set0.4.0, and all 14 Python plugin distributions. Core selects the verified stablekitaru-ui-v0.5.1bundle.kitaru0.27.0@zenml-io/kitaru,@zenml-io/kitaru-mastra,@zenml-io/kitaru-vercel-ai0.4.0kitaru-braintrust-importer0.4.0kitaru-claude-agent-sdk0.1.0kitaru-evaluator0.2.0kitaru-jsonl-importer0.2.0kitaru-langfuse-importer0.4.0kitaru-langgraph0.2.0kitaru-langsmith-importer0.4.0kitaru-logfire-importer0.4.0kitaru-mastra-importer0.2.0kitaru-openai-agents0.3.0kitaru-phoenix-importer0.4.0kitaru-post-import-insights0.1.1kitaru-pydantic-ai0.3.0kitaru-typesafe-evaluator0.1.0The release versions are unused on their registries and their exact Git tags are unused. The release commit resolves every development-only core pin, keeps post-import insights at its compatible
kitaru>=0.26.0floor, and keeps TypeSafe at its compatiblekitaru>=0.22.0floor.Why?
The changes since
0.26.0include two breaking session-node migrations: external IDs replace positional node identity, andreasoning_selectorsreplace stored reasoning text. The deterministic release rule therefore selects core0.27.0; the pre-1.0 TypeScript and plugin packages receive minor releases where their public inputs or observable outputs changed.Publishing these versions together prevents plugin wheels from advertising compatibility with core versions that do not contain the node contract or bounded import helpers they now use.
Release context
The frontend prerequisite is complete:
kitaru-ui-v0.5.1is stable at41f19ac7734e56a7a7ad02c292a722cead931503, its release and commit checks passed, and both bundle assets have a verified checksum.The GitHub environment
pypi-kitaru-typesafe-evaluatorexists and the release owner configured the matching PyPI pending Trusted Publisher. PyPI does not expose pending-publisher configuration publicly, so confirm those fields once more before pushing the first TypeSafe tag.Source PRs by release unit:
httpx2in the quickstart lockfile to 2.12.0 #1115, Add Python agent registration helpers #1090, Bump the minor-and-patch group across 1 directory with 2 updates #1110, Cancel jobs left pending past a timeout #1106, Pin the expected error on MCP fuzzxfailtests #1103, Requirecyclopts>=4.25.1so CLI typo errors name the right option #1104, Strengthen LangGraph capture accounting #1086, Bump the minor-and-patch group across 1 directory with 5 updates #1100, Bump mcp from 2.1.1 to 2.2.0 in the adapters-and-llm-sdks group across 1 directory #1098, Support @mastra/core 1.65 and 1.66 in the Mastra adapter #1092, Support PydanticAI 2.41-2.43 #1091, Bump the dev-tooling group with 2 updates #1097, Stream and batch API imports #1049, Expose analytics enabled in server info response #1094, Identify session nodes by external id #1073, Replace session node reasoning with reasoning selectors #1078, Allow providers on evaluators #1080, Add a skipped task status for analysis tasks that do not run #1079, Add import source to the import completed event #1077, Start Kitaru 0.26.0 development #1075.kitaru-braintrust-importer: Stream and batch API imports #1049, Replace session node reasoning with reasoning selectors #1078.kitaru-claude-agent-sdk: Identify session nodes by external id #1073, Replace session node reasoning with reasoning selectors #1078.kitaru-evaluator: Strengthen deterministic evaluator properties #1084, Identify session nodes by external id #1073.kitaru-jsonl-importer: Identify session nodes by external id #1073.kitaru-langfuse-importer: Stream and batch API imports #1049, Identify session nodes by external id #1073, Replace session node reasoning with reasoning selectors #1078.kitaru-langgraph: Strengthen LangGraph capture accounting #1086, Identify session nodes by external id #1073.kitaru-langsmith-importer: Stream and batch API imports #1049, Replace session node reasoning with reasoning selectors #1078.kitaru-logfire-importer: Stream and batch API imports #1049.kitaru-mastra-importer: Strengthen importer fuzzing and normalization #1083, Identify session nodes by external id #1073, Replace session node reasoning with reasoning selectors #1078.kitaru-openai-agents: Identify session nodes by external id #1073.kitaru-phoenix-importer: Stream and batch API imports #1049.kitaru-post-import-insights: Identify session nodes by external id #1073.kitaru-pydantic-ai: Support PydanticAI 2.44-2.46 #1139, Support PydanticAI 2.41-2.43 #1091, Identify session nodes by external id #1073, Replace session node reasoning with reasoning selectors #1078.kitaru-typesafe-evaluator: Add TypeSafe judge evaluations for recorded sessions #1138.@biomejs/biometo 2.5.13 #1117, Bump the vercel-ai group across 1 directory with 2 updates #1108, Cancel jobs left pending past a timeout #1106, Support @mastra/core 1.65 and 1.66 in the Mastra adapter #1092, Expose analytics enabled in server info response #1094, Identify session nodes by external id #1073, Replace session node reasoning with reasoning selectors #1078, Allow providers on evaluators #1080, Add a skipped task status for analysis tasks that do not run #1079.The independent Kitaru skills release remains a follow-up after core and plugins publish. Merge
kitaru-skills#52, decide whetherkitaru-skills#53belongs, then use that repository's skills-release procedure to select and publish its version. The guided-tour screenshots noted in #1116 also remain follow-up work.The quickstart now installs the already-published core
0.26.0underuv sync --frozen. After0.27.0and the selected plugins are public, follow up by refreshing its core/plugin requirements and lockfile again, rerunning frozen E2E, and ensuring the update reachesmain.Post-merge publication order
Do not run these commands until this PR has merged and
developpoints at the reviewed merge commit.zenml-io/kitaru:Wait for the core
publish-pythonjob to succeed and verifyhttps://pypi.org/pypi/kitaru/0.27.0/json.Publish every selected Python plugin from the same reviewed
developcommit, pushing one tag per command:developcommit:mainto the immutable core tag:Do not merge the generated development-reset PR until
maincontainspython/kitaru/v0.27.0. Report any managed-image, installer-smoke, or reset-PR failure separately from artifacts that already published successfully.Reviewer Notes
Review this as one release graph rather than isolated version bumps. Start with the
0.27.0changelog and release declaration to confirm the breaking-change rationale and UI selection. Then check each plugin's changelog against its dependency floor, and verify that the eight default-catalog requirements exactly match their package versions. Finish with the TypeScript lockstep manifests and both Python lockfiles; they should contain version changes only, without unrelated dependency churn.The highest-risk mistake would be publishing a plugin before core
0.27.0is visible on PyPI, or publishing TypeSafe without the pending publisher matching the GitHub environment. The release workflows remain the only publication path; this PR creates no tags and publishes nothing.Reproduction
Run
uv run python scripts/release_ui.py --version 0.27.0and confirm it resolves stablekitaru-ui-v0.5.1. Runuv run --no-project --with packaging==26.2 python scripts/release_units.py validateand confirm all 15 release units validate. Runjust plugin-artifact-smoketo build the core and all plugin wheels, install them cleanly, import their configured entrypoints, and verify default registration.For the public quickstart installation path, run
uv sync --frozenandKITARU_EXAMPLE_SERVER_PORT=18000 uv run --frozen python scripts/run_ci_e2e.pyfromexamples/python/pydantic_ai_ticket_resolver; the run should create a session against an isolated local server and finish with1 passed.Local checks run
just checkuv run pytest -q tests/server/test_default_plugins.py tests/scripts/test_release_units.py tests/scripts/test_release_ui.py(107 passed)uv run --project plugins ruff format --config plugins/pyproject.toml --check pluginsuv run --project plugins ruff check --config plugins/pyproject.toml pluginsuv run --project plugins ty check --project pluginsuv run --project plugins pytest -q -c plugins/pyproject.toml plugins/tests tests/server/test_default_plugins.py(1,997 passed, 2 skipped)just plugin-artifact-smokepnpm run pack:checkunder Node22.22.31 passed)git diff --check