Skip to content

go-live 4/9: replace main's tree with v2 #1817

Description

@cliffhall

Phase 4 of 9 in the v2 go-live runbook — see #1804 (§5). Depends on phase 3. Reversible (no force-push).

Replace main's tree with v2's, preserving main's history.

Tasks

  • Freeze merges to v2/main for the duration; pick a low-traffic window.
  • Retarget all open main PRs to v1/main (will triage later)
  • True merge that takes v2's tree wholesale:
git checkout -b chore/v2-golive main
git merge --no-commit -s ours v2/main     # record v2/main as a parent, keep no tree yet
git rm -rf . && git checkout v2/main -- . # tree becomes exactly v2/main's
git commit
  • Verify git diff main v2/main is empty after merge.
  • Open as a PR against main so the review trail exists; confirm CI is green on main after merge.

Why not git reset --hard v2/main

A reset + force-push looks simpler but discards main's history and requires disabling branch protection on the default branch. The merge above keeps the history, keeps the PR trail, and makes v2/main a merge parent — so main becomes a true superset and v2/main can afterwards be fast-forwarded or retired cleanly.

Activity

  1. self-assigned this
    on Jul 27, 2026
  2. changed the title [-]go-live 3/9: lock the v1 dist-tag and deprecate all four packages on npm[/-] [+]go-live 4/9: replace main's tree with v2[/+] on Jul 27, 2026
  3. cliffhall commented on Jul 28, 2026

    @cliffhall
    MemberAuthor

    Added step: retargeted all open main PRs to v1/main (done)

    Before the tree swap, every open PR against main was re-pointed at v1/main.

    Why this was needed and is not in the issue. Replacing main's tree does not close open PRs, but it makes them unmergeable — they are diffs against a v1 tree that no longer exists. The runbook defers the v1 backlog to #1819 (phase 6), which runs after this phase, so those PRs would have spent phases 4–5 in a broken state and anything worth porting would have had to be recovered from a diff that no longer applied. Two of them are security fixes of exactly the class §8 warns about keeping (#1732 DNS-rebinding TOCTOU, #1696/#1695 OAuth token handling).

    Why it is safe. v1/main strictly descends from main — it was branched from ac3c1a12, which is still main's head — so git merge-base --is-ancestor origin/main origin/v1/main holds. Every PR's merge base is unchanged and its diff is preserved exactly. Spot-checked afterwards: #1732 (5 files), #1696 (2 files) and #1519 both still report MERGEABLE.

    Result:

    Base Open PRs
    main 0
    v1/main 125
    v2/main 4

    ⚠️ It is 125, not ~30. gh pr list defaults to a limit of 30, so the backlog looked far smaller on first inspection — each retarget simply pulled another off the queue. Worth carrying into #1819: bulk-closing 125 PRs is a materially different job from 30, and §8's warning about GitHub secondary rate limits definitely applies at that size. The --limit 500 flag is needed to see the real set.

    Triage is unchanged and still belongs to #1819; this step only preserves the option.

  4. added this to the v2.0.0 milestone on Jul 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

v2Issues and PRs for v2

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions