go-live 4/9: replace main's tree with v2 #1817
Description
Activity
- changed the title
[-]go-live 3/9: lock the v1 dist-tag and deprecate all four packages on npm[/-][+]go-live 4/9: replace main's tree with v2[/+]on Jul 27, 2026 Added step: retargeted all open
mainPRs tov1/main(done)Before the tree swap, every open PR against
mainwas re-pointed atv1/main.Why this was needed and is not in the issue. Replacing
main's tree does not close open PRs, but it makes them unmergeable — they are diffs against a v1 tree that no longer exists. The runbook defers the v1 backlog to #1819 (phase 6), which runs after this phase, so those PRs would have spent phases 4–5 in a broken state and anything worth porting would have had to be recovered from a diff that no longer applied. Two of them are security fixes of exactly the class §8 warns about keeping (#1732 DNS-rebinding TOCTOU, #1696/#1695 OAuth token handling).Why it is safe.
v1/mainstrictly descends frommain— it was branched fromac3c1a12, which is stillmain's head — sogit merge-base --is-ancestor origin/main origin/v1/mainholds. Every PR's merge base is unchanged and its diff is preserved exactly. Spot-checked afterwards: #1732 (5 files), #1696 (2 files) and #1519 both still reportMERGEABLE.Result:
Base Open PRs main0 v1/main125 v2/main4 ⚠️ It is 125, not ~30.gh pr listdefaults to a limit of 30, so the backlog looked far smaller on first inspection — each retarget simply pulled another off the queue. Worth carrying into #1819: bulk-closing 125 PRs is a materially different job from 30, and §8's warning about GitHub secondary rate limits definitely applies at that size. The--limit 500flag is needed to see the real set.Triage is unchanged and still belongs to #1819; this step only preserves the option.
Phase 4 of 9 in the v2 go-live runbook — see #1804 (§5). Depends on phase 3. Reversible (no force-push).
Replace
main's tree with v2's, preservingmain's history.Tasks
v2/mainfor the duration; pick a low-traffic window.mainPRs tov1/main(will triage later)git diff main v2/mainis empty after merge.mainso the review trail exists; confirm CI is green onmainafter merge.Why not
git reset --hard v2/mainA reset + force-push looks simpler but discards
main's history and requires disabling branch protection on the default branch. The merge above keeps the history, keeps the PR trail, and makesv2/maina merge parent — somainbecomes a true superset andv2/maincan afterwards be fast-forwarded or retired cleanly.