Skip to content

chore(release): v1.0.3, and drop the bundle lockfile for a version floor - #99

Merged
rbmuller merged 1 commit into
mainfrom
chore/release-1.0.3
Sep 22, 2026
Merged

rbmuller merged 1 commit into
mainfrom
chore/release-1.0.3

Conversation

@rbmuller

Copy link
Copy Markdown
Owner

Ships the Claude Desktop extension from #98, and fixes a design flaw in it.

The flaw

The bundle pinned scherlok==X.Y.Z and ran uv run --locked. But the bundle is packed during the release that publishes X.Y.Z, so uv lock on the release commit cannot resolve — the version is not on PyPI yet — and a committed lockfile could only ever pin the previous release. I hit this on the first bump after merging #98.

The fix

A floor instead: scherlok[duckdb,mysql]>=X.Y.Z,<2, no lockfile, no --locked.

  • Raised on every release; tests/test_mcpb.py keeps it equal to the package version.
  • <2 so a future major cannot break installed extensions.
  • Installed extensions pick up later 1.x fixes without a reinstall.
  • Trade-off: the install is no longer byte-reproducible. For a desktop extension that tracks its own project's releases, getting fixes automatically is worth more, and the cryptography<50 guard that protects Intel Macs stays.
  • Measured: cold cache launch 5.5s with resolution, against 4.3s with a lockfile. Bundle 204 KB, 4 files.

Release

Version bumped in all seven locations (pyproject.toml, __init__.py, dbt_project.yml, server.json ×2, mcpb/manifest.json, mcpb/pyproject.toml). CHANGELOG, MCP guide and the CONTRIBUTING checklist corrected to describe the floor rather than the lockfile.

After merge, tagging v1.0.3 publishes to PyPI and GHCR, republishes to the MCP Registry, and for the first time attaches scherlok-1.0.3.mcpb to the GitHub release.

Bumps every version location and ships the Claude Desktop extension.

The lockfile design from #98 could not work: the bundle is packed during
the release that publishes the version it depends on, so `uv lock` in the
release commit resolves against a version PyPI does not have yet, and a
committed lock could only ever pin the previous release. Replaced with a
floor, `scherlok[duckdb,mysql]>=X.Y.Z,<2`, raised on every release and
held equal to the package version by tests. Installed extensions now also
pick up later 1.x fixes without a reinstall.

Cold-cache launch measured at 5.5s with resolution, against 4.3s with a
lockfile. Bundle is 204 KB, 4 files.
@rbmuller
rbmuller merged commit 80a21d1 into main Sep 22, 2026
8 checks passed
@rbmuller
rbmuller deleted the chore/release-1.0.3 branch September 22, 2026 16:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant