Skip to content

fix(release): publish only xml-sec - #165

Merged
polaz merged 4 commits into
mainfrom
fix/release-plz-workspace-pr-name
Sep 29, 2026
Merged

polaz merged 4 commits into
mainfrom
fix/release-plz-workspace-pr-name

Conversation

@polaz

@polaz polaz commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Configure release-plz and the publish workflow to release only xml-sec; internal workspace packages remain unpublished.
  • Compile the existing shared parser sources into the public crate so its package is self-contained.
  • Bundle both vendored MIT notices and the README image in the crate archive.
  • Keep the unbounded decoder private while exposing bounded XML decoding with trusted encoding metadata and lexical helpers.

Validation

  • release-plz 0.3.169 update selected only xml-sec 0.1.16 -> 0.1.17.
  • cargo package -p xml-sec --allow-dirty compiled the packaged crate; archive inspection confirmed both notices and assets/usdt-qr.svg.
  • 3661 workspace tests, 24 doctests, all-feature Clippy, formatting, and alloc-only XML-input target check passed.

git_only from the coordinode reference is intentionally omitted: historical tags predate the current internal workspace members, so historical-workspace reconstruction fails before package selection.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T01:18:18.894153Z 3181866 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

Next included review available in 9 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: structured-world/xml-sec/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: c870f2d7-c895-4341-9b62-3f5c5b544c93

📥 Commits

Reviewing files that changed from the base of the PR and between bf6d1d0 and 3181866.

📒 Files selected for processing (6)
  • Cargo.toml
  • LICENSE-THIRD-PARTY
  • README.md
  • src/encoding.rs
  • src/lib.rs
  • tests/encoding_public_api.rs

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: structured-world/xml-sec/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 5d21792f-caf2-4456-b983-04ef578e6cae

📥 Commits

Reviewing files that changed from the base of the PR and between 89b4f10 and bf6d1d0.

📒 Files selected for processing (49)
  • .github/scripts/check-support-crate-versions.sh
  • .github/scripts/test-check-support-crate-versions.sh
  • .github/workflows/ci.yml
  • .github/workflows/release.yml
  • .release-plz.toml
  • Cargo.toml
  • README.md
  • crates/xml-sec-xml-input/Cargo.toml
  • crates/xml-sec-xml-input/src/lib.rs
  • crates/xml-sec-xslt/Cargo.toml
  • src/document.rs
  • src/encoding.rs
  • src/lib.rs
  • src/sxd_document/dom.rs
  • src/sxd_document/dom_no_unsafe.rs
  • src/sxd_document/lazy_hash_map.rs
  • src/sxd_document/lib.rs
  • src/sxd_document/parser.rs
  • src/sxd_document/raw.rs
  • src/sxd_document/raw_no_unsafe.rs
  • src/sxd_document/str.rs
  • src/sxd_document/str_ext.rs
  • src/sxd_document/string_pool.rs
  • src/sxd_document/string_pool_no_unsafe.rs
  • src/sxd_document/thindom.rs
  • src/sxd_document/thindom_no_unsafe.rs
  • src/sxd_document/writer.rs
  • src/sxd_document/writer_no_unsafe.rs
  • src/sxd_xpath/axis.rs
  • src/sxd_xpath/context.rs
  • src/sxd_xpath/expression.rs
  • src/sxd_xpath/function.rs
  • src/sxd_xpath/lib.rs
  • src/sxd_xpath/macros.rs
  • src/sxd_xpath/node_test.rs
  • src/sxd_xpath/nodeset.rs
  • src/sxd_xpath/parser.rs
  • src/sxd_xpath/token.rs
  • src/sxd_xpath/tokenizer.rs
  • src/xml/dom/preflight.rs
  • src/xml_input/lexical.rs
  • src/xml_input/shared.rs
  • src/xmldsig/builder.rs
  • src/xmldsig/mutation.rs
  • src/xmldsig/xpath.rs
  • src/xmlenc/encrypt.rs
  • tools/xmlsec1/src/commands.rs
  • vendor/sxd-document-no-unsafe/Cargo.toml
  • vendor/sxd-xpath-no-unsafe/Cargo.toml
💤 Files with no reviewable changes (4)
  • .github/workflows/ci.yml
  • .github/scripts/test-check-support-crate-versions.sh
  • .github/scripts/check-support-crate-versions.sh
  • .github/workflows/release.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The pull request adds shared XML byte decoding to xml-sec, embeds the document and XPath implementations, and changes support-crate CI and release configuration. It also updates documentation and package manifests to reflect the crate layout.

Changes

Shared XML input

Layer / File(s) Summary
Shared XML decoding
Cargo.toml, src/xml_input/*, crates/xml-sec-xml-input/*, src/{document.rs,encoding.rs,xml/dom/preflight.rs}, src/{xmldsig/*,xmlenc/encrypt.rs}, tools/xmlsec1/src/commands.rs, README.md
Adds strict XML and text decoding, encoding detection, declaration validation, and decoded-size limits. The shared implementation is exposed through xml-sec and used by existing decoding and lexical call sites. Tests cover encoding detection, decoding, and limits.

Embedded document and XPath engines

Layer / File(s) Summary
Embedded document and XPath engines
Cargo.toml, src/lib.rs, src/sxd_document/*, src/sxd_xpath/*, src/xmldsig/xpath.rs, vendor/sxd-*-no-unsafe/Cargo.toml
Adds feature configuration and crate-local modules for the document and XPath implementations. The vendored manifests point to shared source files, and embedded builds use crate-local imports and visibility.

Release and publication policy

Layer / File(s) Summary
Release and publication policy
.github/scripts/*support-crate-versions.sh, .github/workflows/ci.yml, .github/workflows/release.yml, .release-plz.toml, crates/xml-sec-xslt/Cargo.toml, crates/xml-sec-xml-input/Cargo.toml, vendor/sxd-*-no-unsafe/Cargo.toml, README.md
Removes the support-crate version check and its CI job. Release configuration selects xml-sec; the support crates are marked unpublished. The README describes the internal XSLT crate and the shared XML input implementation.

Priority: ➖ Normal

Estimated code review effort: 4 (Complex) | ~45 minutes

Change: Bug fix

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 62.50% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 72 functions across 25 files. (7 skipped:… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: configuring releases to publish only the public xml-sec package.
Full details: Docstring Coverage

Explanation

Docstring coverage is 62.50% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 72 functions across 25 files. (7 skipped: 7 unsupported.)

✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bf6d1d0696

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread Cargo.toml
Comment thread src/lib.rs Outdated
@greptile-apps

greptile-apps Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Consolidates internal support crates into the main package.

No outstanding findings block merging.

Summary

The crate includes the README image, and its public XML input API provides bounded decoding with trusted encoding metadata. No outstanding findings remain.

Reviews (3) · Last reviewed commit: "fix(xml): expose bounded trusted decodin..."

Comment thread Cargo.toml
Comment thread src/lib.rs Outdated
@greptile-apps

This comment has been minimized.

@polaz
polaz merged commit c443c1e into main Sep 29, 2026
27 checks passed
@polaz
polaz deleted the fix/release-plz-workspace-pr-name branch September 29, 2026 01:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant