Conversation
… for an unchanged branch
Code Review SummaryStatus: No Issues Found | Recommendation: Merge Executive SummaryReviewed the Kilo MCP beta labeling and the new per-release changelog/SBOM tooling across 14 changed files; the changed code is internally consistent, and no correctness, security, or data-integrity issues were found on the PR's changed lines. Files Reviewed (14 files)
Notes (no findings)
Reviewed by deepseek-v4.1-flash · Input: 110.2K · Output: 41.2K · Cached: 2M Review guidance: REVIEW.md from base branch |
E2E verification (GCloud VM, deleted afterwards)Result: done. All scenarios passed at Release job (
|
| Scenario | Result |
|---|---|
| A: first release | Tag kilo-mcp-release/2026-10-05-<sha7> with bundle-sha256=…, a CycloneDX 1.6 SBOM with 6 bundled packages, the release notes, the kilo-mcp-changelog branch, and a PR create with --assignee iscekic. |
| B: rerun of the same commit | The job reused the tag and printed changelog: … (already present). It pushed nothing and kept 1 section. |
C: changelog PR squash-merged and branch deleted, then fix(kilo-mcp): … (#9999) |
The notes list only #9999, not the changelog PR. The branch was rebuilt on the new main with the new section on top. |
D: commit that changes only CHANGELOG.md |
No kilo-mcp input changed: the job skipped every later step. |
E: kilo-mcp change outside the bundle (vitest.config.ts) |
The kilo-mcp bundle is unchanged … no release. |
A bug was found and fixed in cbb5c86: the first section had no blank line after the header.
Beta label (wrangler dev --env dev, apps/web stubbed)
The test ran the full OAuth flow: register, authorize, status, org picker, token, and initialize.
- Consent page:
<p><strong>Beta:</strong> Kilo MCP is in beta. Its tools and behavior can change.</p> initialize:serverInfo.title = "Kilo MCP (beta)". The instructions start withKilo MCP is in beta: its tools and behavior can change.
A stub replaced apps/web. A real GitHub tag push, Release, and PR run only on the first production deploy after the merge.
What
Kilo MCP (
services/kilo-mcp) is now marked beta, and each production release of it gets a changelog section and an SBOM.1. Beta label
initialize:serverInfo.titleisKilo MCP (beta). The instructions start with a beta notice.kilo-mcpskill template has the beta notice..kilo/skills/kilo-mcp/SKILL.mdwas regenerated.2. Changelog (
services/kilo-mcp/CHANGELOG.md)kilo-mcp-releaseindeploy-production.ymlruns afterdeploy-workerssucceeds. It calls.github/workflows/kilo-mcp-release.yml.wrangler deploy --dry-run). It releases only when the bundle SHA-256 differs from the previous release.kilo-mcp-release/<date>-<sha7>. The annotated tag recordsbundle-sha256.scripts/kilo-mcp-release-notes.mjs bodylists the merged PRs that touchedservices/kilo-mcp/since the previous tag. It uses the same PR-link format as the kilo-app changelog.landrebuilds thekilo-mcp-changelogbranch as one commit on the newest main. A merged PR never loses a section, and the open PR never conflicts with main.3. SBOM
scripts/kilo-mcp-sbom.mjsreads the esbuild metafile of the bundle. A package is a component only if the bundle carries bytes of it.pnpm-lock.yamlintegrity. The document records the commit, the tag, and the bundle SHA-256.--latest=false) and kept as thekilo-mcp-sbom-<sha>workflow artifact.docs/sbom.mddescribes the new family.The script reuses the kilo-app and mobile SBOM helpers. Those helpers are now exported; their behavior did not change.
Verification
node --test scripts/kilo-mcp-release.test.mjs: 6 pass. The tests cover land, a squash-merge followed by a branch delete, a rerun, and tree-shaken and virtual inputs.kilo-app-release,mobile-sbom-pnpm,mobile-sbom-cyclonedx,deployment-workflows, andkilo-mcp-catalogscript tests pass.services/kilo-mcpvitestindexandconsenttests pass: 140. Typecheck, lint, andactionlintare clean.