Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
140 commits
Select commit Hold shift + click to select a range
527c077
feat(backends): add EngraphisCloudDecisionClient and update Pro/Team …
Coding-Dev-Tools Sep 28, 2026
aad1e34
fix: harden cloud decisions and recent graph and release regressions
Coding-Dev-Tools Sep 28, 2026
8d8d691
feat(jev): add TypeSafeDecisionClient BYOK adapter and tests
Coding-Dev-Tools Sep 28, 2026
e2883d9
fix: bound decision response time and preserve streamed body limits
Coding-Dev-Tools Sep 28, 2026
0d65753
feat(mcp,init): support BYOK Jev API key installation and decision ga…
Coding-Dev-Tools Sep 28, 2026
a04f166
fix: enforce decision deadline while parsing response headers
Coding-Dev-Tools Sep 28, 2026
75e6274
fix: bound proxy CONNECT responses by decision deadline
Coding-Dev-Tools Sep 28, 2026
be61950
fix: share decision deadline across connection retries and sends
Coding-Dev-Tools Sep 28, 2026
2b16d92
fix: require an explicit non-fallback decision response
Coding-Dev-Tools Sep 28, 2026
1c3e88f
fix: keep loopback decision credentials away from proxies
Coding-Dev-Tools Sep 28, 2026
3ccbb58
test: compare exact hostname in proxy routing expectations
Coding-Dev-Tools Sep 28, 2026
9cb95f6
fix: serialize GitHub release publication and retained repairs
Coding-Dev-Tools Sep 28, 2026
b0a51de
feat(workspaces): route project memory and preview selective moves
Coding-Dev-Tools Sep 28, 2026
c848591
Integrate consented managed Jev with saved Cloud sessions
Coding-Dev-Tools Sep 28, 2026
5d1163f
Preserve reviewed transport deadlines and fail closed on advisory fal…
Coding-Dev-Tools Sep 28, 2026
1f0f140
Fix Jev setup and loopback reviews, align trial contracts, and refres…
Coding-Dev-Tools Sep 28, 2026
39bf4e2
Integrate deadline and release safeguards before workspace routing
Coding-Dev-Tools Sep 28, 2026
04941d6
Bind workspace routing evidence to the integrated safeguards
Coding-Dev-Tools Sep 28, 2026
c7cfb38
Integrate workspace routing and Jev in one consistent tool catalog
Coding-Dev-Tools Sep 28, 2026
b036a2f
Bind combined workspace and Jev evidence to the validated source
Coding-Dev-Tools Sep 28, 2026
a2f63c7
Probe descendant cleanup after timeout without a scheduler race
Coding-Dev-Tools Sep 28, 2026
8562c01
Include credential refresh in the managed Jev request deadline
Coding-Dev-Tools Sep 28, 2026
f0e86b6
Merge commit 'a2f63c73' into codex/managed-jev-benefits-20260928
Coding-Dev-Tools Sep 28, 2026
ef19f70
Finalize clean source and immutable evidence for the combined core PR
Coding-Dev-Tools Sep 28, 2026
7bba568
Run CodeQL security gates for stacked Codex pull requests
Coding-Dev-Tools Sep 28, 2026
d320331
Merge remote-tracking branch 'origin/codex/workspace-organization-pr'…
Coding-Dev-Tools Sep 28, 2026
7cce7e4
Require member policy for remote Jev decisions
Coding-Dev-Tools Sep 28, 2026
46bfce3
Validate Jev decision inputs through actual transport contracts
Coding-Dev-Tools Sep 28, 2026
595a395
Reject conventional credential assignments before Jev requests
Coding-Dev-Tools Sep 28, 2026
f4dd95a
Normalize managed Jev bootstrap origins and clarify secure setup
Coding-Dev-Tools Sep 28, 2026
1b3c297
fix(release): remove unsupported concurrency queue key and recheck La…
Coding-Dev-Tools Sep 28, 2026
f985ff3
fix(jev): remove control-only setup and validation blockers
Coding-Dev-Tools Sep 28, 2026
3e7d024
fix: preserve reviewed GitHub release publication queue
Coding-Dev-Tools Sep 28, 2026
baf1052
fix(release): retain supported publication queue
Coding-Dev-Tools Sep 28, 2026
a3f2654
fix(jev): preserve trusted key updates and injected client compatibility
Coding-Dev-Tools Sep 28, 2026
49bd369
fix(cloud): preserve completed refresh rotations at request deadlines
Coding-Dev-Tools Sep 28, 2026
c442ce3
fix(pi): update vulnerable IP address classification dependency
Coding-Dev-Tools Sep 28, 2026
92d0f94
fix(pi): pin patched IP classification dependency across candidate stack
Coding-Dev-Tools Sep 28, 2026
44764fe
merge: carry patched Pi dependency into workspace routing candidate
Coding-Dev-Tools Sep 28, 2026
0645a41
merge: integrate the patched Pi dependency through the candidate stack
Coding-Dev-Tools Sep 28, 2026
927185d
Preserve local dashboard rendering and graph cache improvements
Coding-Dev-Tools Sep 28, 2026
fe46d79
fix(pi): update test host and audit development dependencies
Coding-Dev-Tools Sep 28, 2026
a498e03
fix(pi): update test host and audit development dependencies
Coding-Dev-Tools Sep 28, 2026
6b0537c
Merge Pi test host security fix into workspace organization
Coding-Dev-Tools Sep 28, 2026
87f19b8
Merge Pi host security checks through managed Jev stack
Coding-Dev-Tools Sep 28, 2026
3a9651a
fix(cloud): prove chunked refresh completion across watchdog expiry
Coding-Dev-Tools Sep 29, 2026
fc14ae2
Merge commit '3a9651a1920f85e53b113094d063ef96569ba18a' into codex/da…
Coding-Dev-Tools Sep 29, 2026
b0477a3
Preserve graph cache isolation and renderer lifecycle intent
Coding-Dev-Tools Sep 29, 2026
7e3af7f
Preserve additional local graph query improvements for review
Coding-Dev-Tools Sep 29, 2026
15eeb57
Separate relocation policy from bounded transactional storage operations
Coding-Dev-Tools Sep 29, 2026
69f427e
Preserve existing line endings in evidence documentation
Coding-Dev-Tools Sep 29, 2026
3af569c
Keep evidence refresh limited to changed content
Coding-Dev-Tools Sep 29, 2026
593b3cc
Bind managed Jev configuration to its credential origin and bound tra…
Coding-Dev-Tools Sep 29, 2026
fe3459e
Scope graph classification probes and preserve legacy shared entities
Coding-Dev-Tools Sep 29, 2026
4fd41bc
Keep maximum workspace moves compatible with legacy SQLite limits
Coding-Dev-Tools Sep 29, 2026
3700f68
Integrate reviewed workspace storage and publish final managed Jev ev…
Coding-Dev-Tools Sep 29, 2026
cbd8b42
Merge commit '3700f68fb2535e61de0c1b43eae7b60430faf2c1' into codex/da…
Coding-Dev-Tools Sep 29, 2026
8a4583d
Bind reviewed graph and dashboard changes to immutable v105 evidence
Coding-Dev-Tools Sep 29, 2026
9321e60
Clarify explicitly scoped reads with unknown sessions
Coding-Dev-Tools Sep 29, 2026
201431b
Merge commit '9321e60d85f26ceedb947adf01df8349bdc307b7' into codex/ma…
Coding-Dev-Tools Sep 29, 2026
da8cb78
Synchronize graph cache metadata across requests and worker invalidation
Coding-Dev-Tools Sep 29, 2026
46a99b8
Merge commit '201431bde99a0e4185c38c18e3a8ed197280e8de' into codex/da…
Coding-Dev-Tools Sep 29, 2026
e00581e
Refresh shipped skill checksum for scoped-read guidance
Coding-Dev-Tools Sep 29, 2026
17df5f9
fix(skill): update SCOPING.md checksum in skill-assets manifest
Coding-Dev-Tools Sep 29, 2026
74be1b1
Merge branch 'codex/workspace-organization-pr' into codex/managed-jev…
Coding-Dev-Tools Sep 29, 2026
f969a47
fix(mcp): rebuild FastMCP Settings model before instantiation to reso…
Coding-Dev-Tools Sep 29, 2026
1aafbfb
fix(graph): preserve CSS background gradients, blend modes, and opaci…
Coding-Dev-Tools Sep 29, 2026
ad1d687
Merge remote-tracking branch 'origin/codex/managed-jev-benefits-20260…
Coding-Dev-Tools Sep 29, 2026
bc963ba
Integrate scoped-read skill checksum while retaining managed Jev assets
Coding-Dev-Tools Sep 29, 2026
bd309b4
Merge commit 'f969a476e8a6344557f4f4157c50f55a0298bc97' into codex/ma…
Coding-Dev-Tools Sep 29, 2026
85a4660
Refresh immutable evidence after MCP compatibility repair
Coding-Dev-Tools Sep 29, 2026
a36be53
Integrate MCP evidence and preserve graph exports at fractional displ…
Coding-Dev-Tools Sep 29, 2026
b5de3fe
Keep graph gradient ownership check compatible with CSS parsing
Coding-Dev-Tools Sep 29, 2026
30b0f09
Require literal MCP remote consent and refresh immutable source evidence
Coding-Dev-Tools Sep 29, 2026
16227d9
Preserve compatible global graph incidence and integrate strict MCP c…
Coding-Dev-Tools Sep 29, 2026
7899c6e
Make the discovered decision example valid and safely offline
Coding-Dev-Tools Sep 29, 2026
23758d1
Integrate valid Smart decision example and refresh graph source evidence
Coding-Dev-Tools Sep 29, 2026
4b98e56
docs: explain managed and BYOK Jev decisions in README
Coding-Dev-Tools Sep 29, 2026
adac026
Merge commit '4b98e560' into codex/dashboard-cache-readiness-20260928
Coding-Dev-Tools Sep 29, 2026
c9f42d6
fix: keep command decisions advisory and require complete inputs
Coding-Dev-Tools Sep 29, 2026
f67e9c9
merge: qualify advisory-only MCP decisions with dashboard source
Coding-Dev-Tools Sep 29, 2026
8f210d4
fix: retire consumed refreshes with invalid subject metadata
Coding-Dev-Tools Sep 29, 2026
356aa8a
fix: distinguish all and empty graph layer caches
Coding-Dev-Tools Sep 29, 2026
f10dbc4
Merge validated session fix and refresh graph cache evidence
Coding-Dev-Tools Sep 29, 2026
7977dc2
Prepare 1.7.9 managed Jev client release and qualification evidence
Coding-Dev-Tools Sep 29, 2026
5954b5f
Derive campaign client version from the loaded package
Coding-Dev-Tools Sep 29, 2026
c737116
fix(mcp): classify local decision advice conservatively
claude Sep 29, 2026
84c4e9a
docs: note the Command Code hook routing upgrade path
claude Sep 29, 2026
29a2567
refactor(store): drop the empty workspace branch in edges_for
claude Sep 29, 2026
07b3c70
chore(evidence): bind review follow-ups to immutable v116 evidence
claude Sep 29, 2026
f17d1d6
fix(mcp): flag forced checkouts and require a shared subject for supe…
claude Sep 29, 2026
d302365
chore(evidence): bind review fixes to immutable v117 evidence
claude Sep 29, 2026
75e7814
fix(mcp): honor git global options and negation equivalence in local …
claude Sep 29, 2026
b179129
chore(evidence): bind round-two review fixes to immutable v118 evidence
claude Sep 29, 2026
e72f142
fix(mcp): compare negation targets and flag path-specific discards
claude Sep 29, 2026
c8d2dc2
chore(evidence): bind round-three review fixes to immutable v119 evid…
claude Sep 29, 2026
315d501
fix(mcp): defer conflicting values and flag worktree and force-create…
claude Sep 29, 2026
bb85823
chore(evidence): bind round-four review fixes to immutable v120 evidence
claude Sep 29, 2026
a5c9ead
fix(mcp): oppose only ruled-out values and widen credential and disca…
claude Sep 29, 2026
4cb4909
chore(evidence): bind round-five review fixes to immutable v121 evidence
claude Sep 29, 2026
b8e5455
fix(mcp): uncap git global options and fold clustered flags and cannot
claude Sep 29, 2026
13ac391
chore(evidence): bind round-six review fixes to immutable v122 evidence
claude Sep 29, 2026
2adee81
fix(mcp): read contrasts, negated failures and terse negations correctly
claude Sep 29, 2026
7d1fa9a
chore(evidence): bind round-seven review fixes to immutable v123 evid…
claude Sep 29, 2026
86c0fe3
Merge the 1.7.9 release preparation (#242) into these follow-ups
claude Sep 29, 2026
769b728
fix(mcp): read "no longer" as a negation in completion checks
claude Sep 29, 2026
d42c413
fix(llm): make Anthropic client work with Claude 5.x models
claude Sep 29, 2026
1c473e2
test(e2e): use the current Anthropic default model in the LLM status …
claude Sep 29, 2026
c5c27b8
fix(mcp): keep program-running and file-writing options out of read_only
claude Sep 29, 2026
1b1a0b3
chore(evidence): bind the restacked tree to immutable v124 evidence
claude Sep 29, 2026
fbb088e
fix(decide,llm): close review gaps in model detection and completion …
claude Sep 29, 2026
61cd3d5
fix(ci,pi): patch new Pi advisories and stop Windows hiding step fail…
claude Sep 30, 2026
ecfff5f
fix(ci,pi): patch new Pi advisories and stop Windows hiding step fail…
claude Sep 30, 2026
8ae79b7
Merge the Pi advisory and Windows CI fix from #238 into #239
claude Sep 30, 2026
c28fc4f
Merge the Pi advisory and Windows CI fix from #238 into #240
claude Sep 30, 2026
d8a03c8
Merge the Pi advisory and Windows CI fix from #238 into #241
claude Sep 30, 2026
fe63768
Merge the Pi advisory and Windows CI fix from #238 into #242
claude Sep 30, 2026
dac3a4c
Merge the Pi advisory and Windows CI fix from #242 into #243
claude Sep 30, 2026
fce655b
Fix the locked Pi test dependency without waiving audits
Coding-Dev-Tools Oct 1, 2026
9515c65
Include the fully audited Pi dependency fix in workspace routing
Coding-Dev-Tools Oct 1, 2026
639cdbb
Include the fully audited Pi dependency fix in PR 240
Coding-Dev-Tools Oct 1, 2026
dc8c513
Include the fully audited Pi dependency fix in PR 241
Coding-Dev-Tools Oct 1, 2026
63031f5
Include the fully audited Pi dependency fix in PR 242
Coding-Dev-Tools Oct 1, 2026
efee3c6
Integrate the fully audited Pi fix into the final release candidate
Coding-Dev-Tools Oct 1, 2026
df123e5
Pin npm for reproducible Pi shrinkwrap repair on both runners
Coding-Dev-Tools Oct 1, 2026
ac5ba42
Pin the compatible npm runtime in PR 239
Coding-Dev-Tools Oct 1, 2026
6676b57
Pin the compatible npm runtime in PR 240
Coding-Dev-Tools Oct 1, 2026
d4ea965
Pin the compatible npm runtime in PR 241
Coding-Dev-Tools Oct 1, 2026
3bd7043
Pin the compatible npm runtime in PR 242
Coding-Dev-Tools Oct 1, 2026
561e1e1
Merge reproducible Pi npm pin into review stack
Coding-Dev-Tools Oct 1, 2026
a984521
Finish decision guard fixes and bind final 1.7.9 candidate evidence
Coding-Dev-Tools Oct 1, 2026
b89cd14
Bound Git option guard backtracking without limiting flags
Coding-Dev-Tools Oct 1, 2026
1dccf8a
Integrate reviewed Core release repairs into bounded guard fix
Coding-Dev-Tools Oct 1, 2026
ffd2342
Bind bounded guard repair to fresh offline evidence
Coding-Dev-Tools Oct 1, 2026
0ff3300
Allow large installed-journey wheels to survive slow download pauses
Coding-Dev-Tools Oct 1, 2026
cf41fd7
Carry installed-journey download resilience into PR 239
Coding-Dev-Tools Oct 1, 2026
ca88a7f
Carry installed-journey download resilience into PR 240
Coding-Dev-Tools Oct 1, 2026
27f41b4
Carry installed-journey download resilience into PR 241
Coding-Dev-Tools Oct 1, 2026
053fba8
Carry installed-journey download resilience into PR 242
Coding-Dev-Tools Oct 1, 2026
156150b
Complete candidate changelog and propagate resilient installed-produc…
Coding-Dev-Tools Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .claude-plugin/marketplace.json
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@
"name": "engraphis-memory",
"source": "./",
"description": "Discipline for giving agents durable, scoped, explainable memory across sessions and repos with the Engraphis MCP tools.",
"version": "1.7.8"
"version": "1.7.9"
}
]
}
2 changes: 1 addition & 1 deletion .claude-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "engraphis-memory",
"version": "1.7.8",
"version": "1.7.9",
"description": "Give agents durable, scoped, explainable memory across sessions and repos via the Engraphis MCP tools. Use when you learn something worth keeping, need prior context before acting, or ask why/how a fact changed. Covers remember/recall, why/timeline, forget/pin/correct, sessions, and code search.",
"author": {
"name": "The Engraphis Authors",
Expand Down
10 changes: 5 additions & 5 deletions .claude-plugin/skill-assets.sha256
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
df65a383a1ff80572fb6ebd9a807dca6d1ffc0f99f373971262de035b8e3622d .claude-plugin/marketplace.json
a03b5c38d836651d2c5c52173d21a5adeacfbbc4b80aac991c2154b6e060e174 .claude-plugin/plugin.json
4bc8979b9ffeb97190960e551dbf4ddc6f7aeeb7b86894fd2298a59ff0001efa skills/engraphis-memory/SKILL.md
c1d184247775c8b3bf4d3f185d54fcac983aca8c54638a05d85b21e20db3ae7c .claude-plugin/marketplace.json
c5d0c26f28c9ee14092f9deaf24c98dd8bef49d971fef2b7a537ffb1ab9f2887 .claude-plugin/plugin.json
aeee7a94671ceb306fe2d24c5acc9f2d96ad8a8e7410536566799eea6265f080 skills/engraphis-memory/SKILL.md
055655db84af07561d002f0c69744313d8413c39f3e873f941f0fa0b1e76dc66 skills/engraphis-memory/references/CONVENTIONS.md
62019760766ff472a76a0f81437898f39e3c1fe2631732b7b7733e50c1ad837f skills/engraphis-memory/references/SCOPING.md
9e5f1c8e91ca5697e828ab9e468504b8e1aa28e34f61307c9fcd850969126be9 skills/engraphis-memory/references/TOOLS.md
9d090a03f5b3f36a34d91f66b72c3844591f6915755ac3a6c6ba5f1b16977de5 skills/engraphis-memory/references/SCOPING.md
07de31349fc135895377cfcf852c490f732c19e83a627c311d724c5d2146dbb5 skills/engraphis-memory/references/TOOLS.md
23 changes: 21 additions & 2 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -138,6 +138,22 @@ ENGRAPHIS_RETENTION_SUPERVISOR=none
# ENGRAPHIS_GRAPH_HOST=127.0.0.1
# ENGRAPHIS_GRAPH_PORT=8720

# ── System 1 Decision Gating (TypeSafe AI Jev) ───────────────────────────
# Advisory typed decisions for command screening and evidence assessment.
# Default none/local sends no requests; each remote call needs allow_remote=true.
# Pro & Team include a managed allowance when enabled by the service (no personal key needed).
# For BYOK, enter the key at a hidden prompt and pipe it directly to the CLI:
# python -c "import getpass,warnings; warnings.simplefilter('error',getpass.GetPassWarning); print(getpass.getpass('TypeSafe API key: '))" | engraphis-init --jev-key -
# The key stays out of shell history and process arguments. If hidden input is
# unavailable, the prompt fails instead of accepting visible input.
# Community/BYOK users can set their own TypeSafe API key:
# TYPESAFE_API_KEY=
# JEV_API_KEY=
# TYPESAFE_BASE_URL=https://api.typesafe.ai
# ENGRAPHIS_DECISION_BACKEND=none # none | local | managed | auto | byok
# ENGRAPHIS_DECISION_MODEL=jev-1.13.0


# Standalone MCP-over-HTTP server (`engraphis-mcp-http`). Loopback-only by default;
# any non-loopback bind (via these or ENGRAPHIS_HOST) requires ENGRAPHIS_API_TOKEN.
# ENGRAPHIS_HTTP_HOST=127.0.0.1
Expand Down Expand Up @@ -180,7 +196,7 @@ ENGRAPHIS_RETENTION_SUPERVISOR=none
ENGRAPHIS_LLM_PROVIDER=openai
# Model name (provider-specific):
# openai: gpt-4o-mini, gpt-4o, gpt-4.1-mini, o4-mini ...
# anthropic: claude-3-5-haiku-20241022, claude-3-5-sonnet-20241022 ...
# anthropic: claude-sonnet-5-5, claude-opus-5-5, claude-haiku-4-5 ...
# google: gemini-1.5-flash, gemini-2.0-flash ...
# openrouter: anthropic/claude-3.5-sonnet, openai/gpt-4o-mini ...
# custom: any model name your OpenAI-compatible endpoint accepts
Expand All @@ -194,6 +210,9 @@ ENGRAPHIS_LLM_MODEL=gpt-4o-mini
# ENGRAPHIS_LLM_BASE_URL=https://openrouter.ai/api/v1
# Optional: extra headers (JSON string) for custom providers.
# ENGRAPHIS_LLM_EXTRA_HEADERS={"HTTP-Referer":"https://myapp.com","X-Title":"engraphis"}
# Optional: reasoning effort (low|medium|high|xhigh|max) for Claude models that think by
# default (Opus 5+, Sonnet 5+, Fable). Default medium; ignored by other providers and models.
# ENGRAPHIS_LLM_EFFORT=medium

# ── Hosted Pro / Team customer client ───────────────────────────────────────
# Cloud Sync, Analytics, Automation, Auto Dreaming, Auto Consolidation, and Team
Expand Down Expand Up @@ -253,7 +272,7 @@ ENGRAPHIS_LLM_MODEL=gpt-4o-mini
# ENGRAPHIS_STATE_DIR=/data/.engraphis

# The private control plane may report ``workspace_write_grace`` for already-authorized
# hosted-account continuity, capped at 24 hours. It never extends the exact 3-day trial,
# hosted-account continuity, capped at 24 hours. It never extends the 7-day Pro or 14-day Team trial,
# subscription expiry, or cloud access, and it never restricts the free local core.

# Managed compute consent is decided automatically and needs no customer action: a
Expand Down
14 changes: 13 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -235,13 +235,23 @@ jobs:
python -m pip install -e ".[test]"
- name: Install and verify the Pi package
working-directory: integrations/pi
# Windows defaults to pwsh, which reports only the last command's exit code.
shell: bash
env:
ENGRAPHIS_PI_TEST_COMMAND: engraphis-mcp
run: |
# npm 10 crashes while repairing a nested published shrinkwrap.
npm install --global --ignore-scripts npm@11.12.1
npm ci --ignore-scripts
# The test host's published shrinkwrap overrides this package's nested pin.
# Repair that exact leaf in the installed host, preserving its other locked deps.
# --omit=dev excludes the host's own authoring tools, not this package's test tools.
npm install --prefix node_modules/@earendil-works/pi-coding-agent --ignore-scripts --no-save --omit=dev brace-expansion@5.0.12
node -e "require('node:assert/strict').equal(require('./node_modules/@earendil-works/pi-coding-agent/node_modules/brace-expansion/package.json').version, '5.0.12')"
npm run verify
npm run test:integration
npm audit --omit=dev
npm audit
npm audit --no-package-lock --include=dev

browser-accessibility:
name: browser accessibility smoke
Expand Down Expand Up @@ -441,7 +451,9 @@ jobs:
wheels = list(Path("dist").glob("*.whl"))
assert len(wheels) == 1
profile = os.environ["ENGRAPHIS_SMOKE_PROFILE"]
# Large server wheels can pause longer than pip's default socket timeout.
subprocess.run([str(executable), "-m", "pip", "install",
"--timeout", "120", "--retries", "5",
str(wheels[0].resolve()) + f"[{profile}]"], check=True)
subprocess.run([str(executable), "-m", "pip", "check"], check=True)
(root / "environment.lock").write_text(subprocess.check_output(
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,8 @@ on:
push:
branches: [main]
pull_request:
branches: [main]
# Stacked PRs must receive the same security gate before reaching main.
branches: [main, "codex/**"]
schedule:
- cron: "23 4 * * 1"

Expand Down
34 changes: 32 additions & 2 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -892,6 +892,11 @@ jobs:

github-release:
name: Publish GitHub Release
# Share one publication lock with repairs, including runs on other refs.
concurrency:
group: engraphis-github-release-publication
cancel-in-progress: false
queue: max
needs: publish
environment: release-qualification
if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v')
Expand Down Expand Up @@ -953,6 +958,11 @@ jobs:

github-release-repair:
name: Repair GitHub Release
# Hold the lock from the Latest lookup through all GitHub release writes.
concurrency:
group: engraphis-github-release-publication
cancel-in-progress: false
queue: max
environment: release-qualification
if: >-
github.event_name == 'workflow_dispatch' &&
Expand Down Expand Up @@ -1231,7 +1241,27 @@ jobs:
run: |
set -euo pipefail
notes_args=()
latest_args=(--latest)
promote_latest=true
if [ "$WAIVE_QUALIFICATION" = "true" ]; then
# A retained older repair must not displace a newer public Latest.
# Both authorized candidates already have a public release history;
# failed lookups or unknown tag formats stop before any release write.
current_latest="$(gh release view --repo "$GH_REPO" --json tagName --jq .tagName)"
promote_latest="$(python - "$RELEASE_TAG" "$current_latest" <<'PY'
import re
import sys

def version(tag):
if re.fullmatch(r"v(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)", tag) is None:
raise SystemExit("Latest release comparison requires stable version tags")
return tuple(map(int, tag[1:].split(".")))

print("true" if version(sys.argv[1]) >= version(sys.argv[2]) else "false")
PY
)"
latest_args=(--latest=false)
if [ "$promote_latest" = "true" ]; then latest_args=(--latest); fi
{
printf '## Release qualification\n\n'
printf 'The owner waived full-product qualification for this release. Mandatory full-product gates are not represented as passed.\n\n'
Expand All @@ -1254,7 +1284,7 @@ jobs:
gh release upload "$RELEASE_TAG" verified-dist/* release-evidence/* \
--repo "$GH_REPO" \
--clobber
if [ "$WAIVE_QUALIFICATION" = "true" ]; then
if [ "$WAIVE_QUALIFICATION" = "true" ] && [ "$promote_latest" = "true" ]; then
gh release edit "$RELEASE_TAG" --repo "$GH_REPO" --latest
fi
else
Expand All @@ -1264,5 +1294,5 @@ jobs:
--generate-notes \
"${notes_args[@]}" \
--title "Engraphis ${RELEASE_TAG#v}" \
--latest
"${latest_args[@]}"
fi
10 changes: 5 additions & 5 deletions BENCHMARKS.md
Original file line number Diff line number Diff line change
Expand Up @@ -94,14 +94,14 @@ interpretation and do not count as additional benchmark-quality gains.
### Public numeric evidence registry

Every exact public aggregate retained below comes from the checked-in, public-safe
[`offline-fixtures-v80.json`](docs/benchmark-evidence/offline-fixtures-v80.json) artifact. Its
[`offline-fixtures-v128.json`](docs/benchmark-evidence/offline-fixtures-v128.json) artifact. Its
SHA-256 is
`ac63dac1e34c66b658eeb5846599ef42d774a5e212860b2a909941f364c82bc2`, also recorded in the
`73f2d1a8cd6e2db070577582a2266f6605efc052800da17db9938f7a274bf755`, also recorded in the
adjacent `.sha256` file. The artifact contains no raw questions, answers, prompts, customer data,
or per-record content fingerprints.

The fixture-suite digest is
`431b525443f5b4875646e7f6470d107f584120bdd6ee7f53d0b6484d003fa0f7`. The artifact defines
`6e1be135db67964cfb48a2125ac846a9a420662b69ed4d7f61c21d1c87d971b2`. The artifact defines
the digest algorithm and records the SHA-256 of every suite and dataset file. Each evidence ID
also binds its exact command through `sha256(UTF-8 exact command)`:

Expand All @@ -123,10 +123,10 @@ Historical LoCoMo, graph, handoff, consolidation, and security figures remain pr
source artifacts but are omitted from the current chart until each has a matching immutable,
public-safe artifact. The chart labels coding outcomes, external datasets, and operational
capacity as pending evaluation tracks rather than implying scores. Regenerate it with
`python scripts/render_benchmark_report.py --report docs/benchmark-evidence/offline-fixtures-v80.json --output docs/images/context-efficiency.svg` after selecting the report to publish.
`python scripts/render_benchmark_report.py --report docs/benchmark-evidence/offline-fixtures-v128.json --output docs/images/context-efficiency.svg` after selecting the report to publish.

The companion examples are also generated from that artifact with
`python -m scripts.render_benchmark_examples --report docs/benchmark-evidence/offline-fixtures-v80.json --output docs/images/evidence-backed-agent-examples.svg`.
`python -m scripts.render_benchmark_examples --report docs/benchmark-evidence/offline-fixtures-v128.json --output docs/images/evidence-backed-agent-examples.svg`.
The historical-to-executable mapping is in
[`docs/BENCHMARK_CHANGE_COVERAGE.md`](docs/BENCHMARK_CHANGE_COVERAGE.md).

Expand Down
Loading
Loading