Skip to content

Prepare Kitaru 0.27.0 release - #1141

Merged
strickvl merged 1 commit into
developfrom
feat/prepare-kitaru-0.27.0
Sep 21, 2026
Merged

strickvl merged 1 commit into
developfrom
feat/prepare-kitaru-0.27.0

Conversation

@strickvl

Copy link
Copy Markdown
Collaborator

What changed?

This prepares one coordinated stable release: Kitaru core 0.27.0, the TypeScript package set 0.4.0, and all 14 Python plugin distributions. Core selects the verified stable kitaru-ui-v0.5.1 bundle.

Release unit Version
kitaru 0.27.0
@zenml-io/kitaru, @zenml-io/kitaru-mastra, @zenml-io/kitaru-vercel-ai 0.4.0
kitaru-braintrust-importer 0.4.0
kitaru-claude-agent-sdk 0.1.0
kitaru-evaluator 0.2.0
kitaru-jsonl-importer 0.2.0
kitaru-langfuse-importer 0.4.0
kitaru-langgraph 0.2.0
kitaru-langsmith-importer 0.4.0
kitaru-logfire-importer 0.4.0
kitaru-mastra-importer 0.2.0
kitaru-openai-agents 0.3.0
kitaru-phoenix-importer 0.4.0
kitaru-post-import-insights 0.1.1
kitaru-pydantic-ai 0.3.0
kitaru-typesafe-evaluator 0.1.0

The release versions are unused on their registries and their exact Git tags are unused. The release commit resolves every development-only core pin, keeps post-import insights at its compatible kitaru>=0.26.0 floor, and keeps TypeSafe at its compatible kitaru>=0.22.0 floor.

Why?

The changes since 0.26.0 include two breaking session-node migrations: external IDs replace positional node identity, and reasoning_selectors replace stored reasoning text. The deterministic release rule therefore selects core 0.27.0; the pre-1.0 TypeScript and plugin packages receive minor releases where their public inputs or observable outputs changed.

Publishing these versions together prevents plugin wheels from advertising compatibility with core versions that do not contain the node contract or bounded import helpers they now use.

Release context

The frontend prerequisite is complete: kitaru-ui-v0.5.1 is stable at 41f19ac7734e56a7a7ad02c292a722cead931503, its release and commit checks passed, and both bundle assets have a verified checksum.

The GitHub environment pypi-kitaru-typesafe-evaluator exists and the release owner configured the matching PyPI pending Trusted Publisher. PyPI does not expose pending-publisher configuration publicly, so confirm those fields once more before pushing the first TypeSafe tag.

Source PRs by release unit:

The independent Kitaru skills release remains a follow-up after core and plugins publish. Merge kitaru-skills#52, decide whether kitaru-skills#53 belongs, then use that repository's skills-release procedure to select and publish its version. The guided-tour screenshots noted in #1116 also remain follow-up work.

The quickstart now installs the already-published core 0.26.0 under uv sync --frozen. After 0.27.0 and the selected plugins are public, follow up by refreshing its core/plugin requirements and lockfile again, rerunning frozen E2E, and ensuring the update reaches main.

Post-merge publication order

Do not run these commands until this PR has merged and develop points at the reviewed merge commit.

  1. Publish core from zenml-io/kitaru:
git checkout develop
git tag python/kitaru/v0.27.0 HEAD
git push origin python/kitaru/v0.27.0
  1. Wait for the core publish-python job to succeed and verify https://pypi.org/pypi/kitaru/0.27.0/json.

  2. Publish every selected Python plugin from the same reviewed develop commit, pushing one tag per command:

git checkout develop
git tag python/kitaru-braintrust-importer/v0.4.0 HEAD
git push origin python/kitaru-braintrust-importer/v0.4.0
git tag python/kitaru-claude-agent-sdk/v0.1.0 HEAD
git push origin python/kitaru-claude-agent-sdk/v0.1.0
git tag python/kitaru-evaluator/v0.2.0 HEAD
git push origin python/kitaru-evaluator/v0.2.0
git tag python/kitaru-jsonl-importer/v0.2.0 HEAD
git push origin python/kitaru-jsonl-importer/v0.2.0
git tag python/kitaru-langfuse-importer/v0.4.0 HEAD
git push origin python/kitaru-langfuse-importer/v0.4.0
git tag python/kitaru-langgraph/v0.2.0 HEAD
git push origin python/kitaru-langgraph/v0.2.0
git tag python/kitaru-langsmith-importer/v0.4.0 HEAD
git push origin python/kitaru-langsmith-importer/v0.4.0
git tag python/kitaru-logfire-importer/v0.4.0 HEAD
git push origin python/kitaru-logfire-importer/v0.4.0
git tag python/kitaru-mastra-importer/v0.2.0 HEAD
git push origin python/kitaru-mastra-importer/v0.2.0
git tag python/kitaru-openai-agents/v0.3.0 HEAD
git push origin python/kitaru-openai-agents/v0.3.0
git tag python/kitaru-phoenix-importer/v0.4.0 HEAD
git push origin python/kitaru-phoenix-importer/v0.4.0
git tag python/kitaru-post-import-insights/v0.1.1 HEAD
git push origin python/kitaru-post-import-insights/v0.1.1
git tag python/kitaru-pydantic-ai/v0.3.0 HEAD
git push origin python/kitaru-pydantic-ai/v0.3.0
git tag python/kitaru-typesafe-evaluator/v0.1.0 HEAD
git push origin python/kitaru-typesafe-evaluator/v0.1.0
  1. After the required core/plugin artifacts are available and the TypeScript rehearsal has passed, publish the TypeScript release set from the reviewed develop commit:
git checkout develop
git tag typescript/kitaru/v0.4.0 HEAD
git push origin typescript/kitaru/v0.4.0
  1. After required public core jobs and the GitHub Release succeed, fast-forward main to the immutable core tag:
git checkout main
git merge --ff-only python/kitaru/v0.27.0
git push origin main

Do not merge the generated development-reset PR until main contains python/kitaru/v0.27.0. Report any managed-image, installer-smoke, or reset-PR failure separately from artifacts that already published successfully.

Reviewer Notes

Review this as one release graph rather than isolated version bumps. Start with the 0.27.0 changelog and release declaration to confirm the breaking-change rationale and UI selection. Then check each plugin's changelog against its dependency floor, and verify that the eight default-catalog requirements exactly match their package versions. Finish with the TypeScript lockstep manifests and both Python lockfiles; they should contain version changes only, without unrelated dependency churn.

The highest-risk mistake would be publishing a plugin before core 0.27.0 is visible on PyPI, or publishing TypeSafe without the pending publisher matching the GitHub environment. The release workflows remain the only publication path; this PR creates no tags and publishes nothing.

Reproduction

Run uv run python scripts/release_ui.py --version 0.27.0 and confirm it resolves stable kitaru-ui-v0.5.1. Run uv run --no-project --with packaging==26.2 python scripts/release_units.py validate and confirm all 15 release units validate. Run just plugin-artifact-smoke to build the core and all plugin wheels, install them cleanly, import their configured entrypoints, and verify default registration.

For the public quickstart installation path, run uv sync --frozen and KITARU_EXAMPLE_SERVER_PORT=18000 uv run --frozen python scripts/run_ci_e2e.py from examples/python/pydantic_ai_ticket_resolver; the run should create a session against an isolated local server and finish with 1 passed.

Local checks run

  • just check
  • uv run pytest -q tests/server/test_default_plugins.py tests/scripts/test_release_units.py tests/scripts/test_release_ui.py (107 passed)
  • uv run --project plugins ruff format --config plugins/pyproject.toml --check plugins
  • uv run --project plugins ruff check --config plugins/pyproject.toml plugins
  • uv run --project plugins ty check --project plugins
  • uv run --project plugins pytest -q -c plugins/pyproject.toml plugins/tests tests/server/test_default_plugins.py (1,997 passed, 2 skipped)
  • just plugin-artifact-smoke
  • pnpm run pack:check under Node 22.22.3
  • Frozen quickstart sync and E2E (1 passed)
  • Release UI resolution, 15-unit inventory validation, lockfile checks, registry/tag collision checks, and git diff --check

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedpypi/​kitaru@​0.25.0 ⏵ 0.26.074 +1100100100100

View full report

@strickvl
strickvl marked this pull request as ready for review September 21, 2026 15:31
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-21T15:34:25.185432Z f5169f1 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@strickvl
strickvl merged commit 0e72a13 into develop Sep 21, 2026
52 checks passed
@strickvl
strickvl deleted the feat/prepare-kitaru-0.27.0 branch September 21, 2026 16:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants