From 8ba4e48b6d2041b54927d6a07a58c9c05b6e0927 Mon Sep 17 00:00:00 2001 From: Jason Doyle Date: Mon, 7 Sep 2026 12:46:55 -0700 Subject: [PATCH] Publish stable WorldCut 1.0 --- .github/workflows/release-dotnet.yml | 2 +- .github/workflows/release-python.yml | 9 ++-- CHANGELOG.md | 14 +++--- README.md | 23 +++++---- docs/PORT_RELEASES.md | 17 +++---- docs/STABILITY.md | 50 +++++++++++++++++++ examples/azure-sre-agent/README.md | 4 +- examples/azure-sre-agent/requirements.txt | 6 +-- .../github-actions/deployment-gate-go.yml | 4 +- examples/github-actions/deployment-gate.yml | 2 +- .../dotnet/README.md | 2 +- .../WorldCut.AgentFramework.Example.csproj | 2 +- .../dotnet/packages.lock.json | 6 +-- package-lock.json | 4 +- package.json | 3 +- scripts/test-package.mjs | 1 + 16 files changed, 102 insertions(+), 47 deletions(-) create mode 100644 docs/STABILITY.md diff --git a/.github/workflows/release-dotnet.yml b/.github/workflows/release-dotnet.yml index 16a8dc7..35ff50c 100644 --- a/.github/workflows/release-dotnet.yml +++ b/.github/workflows/release-dotnet.yml @@ -84,7 +84,7 @@ jobs: shell: bash run: | cd release-artifacts/dotnet/dist - sha256sum * > ../SHA256SUMS + sha256sum ./* > ../SHA256SUMS - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 with: name: dotnet-package diff --git a/.github/workflows/release-python.yml b/.github/workflows/release-python.yml index bcc3e57..ba6f53f 100644 --- a/.github/workflows/release-python.yml +++ b/.github/workflows/release-python.yml @@ -77,13 +77,14 @@ jobs: - name: Build exact distributions working-directory: ports/python run: | - export SOURCE_DATE_EPOCH="$(git show -s --format=%ct HEAD)" + SOURCE_DATE_EPOCH="$(git show -s --format=%ct HEAD)" + export SOURCE_DATE_EPOCH python -m build - twine check dist/* + twine check ./dist/* mkdir -p ../../release-artifacts/python/dist - cp dist/* ../../release-artifacts/python/dist/ + cp ./dist/* ../../release-artifacts/python/dist/ cd ../../release-artifacts/python/dist - sha256sum * > ../SHA256SUMS + sha256sum ./* > ../SHA256SUMS - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 with: name: python-package diff --git a/CHANGELOG.md b/CHANGELOG.md index 5d3d6ce..756383e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,8 +2,10 @@ ## Unreleased -- Prepared stable `1.0.0` releases for the Go, Python, and .NET package lines. - This is an API-stability promotion; protocol `0.1`, engine `0.1.2`, canonical +## 1.0.0 - 2026-09-07 + +- Promoted the npm, Go, Python, and .NET package/API lines to stable `1.0.0`. + This is an API-stability release; protocol `0.1`, engine `0.1.2`, canonical results, and verification digests are unchanged. - Added tested agent effect-gating examples: - a Microsoft Agent Framework .NET workflow whose effect executor is @@ -44,12 +46,12 @@ Go integrations in the port README, root README, `docs/INTEGRATIONS.md`, `docs/AGENTIC_DATA_KERNEL.md`, and `docs/VALIDATION.md`. The Go module keeps its single `jcs` dependency and adds no GitHub, Kubernetes, or cloud SDK. -- Added OIDC trusted-publishing workflows for Python `0.1.1` on PyPI and - `WorldCut`/`WorldCut.Tool` `0.1.1` on NuGet.org, including protected tag +- Added OIDC trusted-publishing workflows for Python on PyPI and + `WorldCut`/`WorldCut.Tool` on NuGet.org, including protected tag validation, exact-artifact checks, and language-specific GitHub releases. -- Published `WorldCut` and `WorldCut.Tool` `0.1.1` on NuGet.org with +- Published stable `WorldCut` and `WorldCut.Tool` `1.0.0` on NuGet.org with repository signatures and verified package contents. -- Published Python `worldcut` `0.1.1` on PyPI with verified PEP 740 +- Published stable Python `worldcut` `1.0.0` on PyPI with verified PEP 740 attestations for the wheel and source distribution. ## 0.2.0 - 2026-09-04 diff --git a/README.md b/README.md index fb933cb..f3ab92b 100644 --- a/README.md +++ b/README.md @@ -33,9 +33,10 @@ contract deterministically. ## Production status -WorldCut 0.1 is supported for deterministic decision gating when the documented -metadata, clock, identity, and trusted-process assumptions hold. It fails closed -when required evidence is absent. +WorldCut `1.x` is the stable package and API line. It implements protocol `0.1` +and engine `0.1.2` for deterministic decision gating when the documented +metadata, clock, identity, and trusted-process assumptions hold. It fails +closed when required evidence is absent. It is not a general security boundary or a substitute for provider authentication, signed provenance, or transactional effect execution. Review @@ -60,18 +61,18 @@ results, as described in | Port | Protocol / engine | Status | | --- | --- | --- | -| TypeScript | 0.1 / 0.1.2 | Reference package with documented integrations | -| [Go](ports/go) | 0.1 / 0.1.2 | Stable `v1.0.0` module prepared; current public tag is `v0.2.0` | -| [Python](ports/python) | 0.1 / 0.1.2 | Stable `1.0.0` package prepared; current public release is `0.1.1` | -| [.NET](ports/dotnet) | 0.1 / 0.1.2 | Stable `1.0.0` library and tool prepared; current public release is `0.1.1` | +| TypeScript | 0.1 / 0.1.2 | Stable [`worldcut@1.0.0`](https://www.npmjs.com/package/worldcut) reference package with documented integrations | +| [Go](ports/go) | 0.1 / 0.1.2 | Stable [`ports/go/v1.0.0`](https://github.com/Jason-Doyle/WorldCut/releases/tag/ports/go/v1.0.0) verifier, integrations, and two CLIs | +| [Python](ports/python) | 0.1 / 0.1.2 | Stable [`worldcut==1.0.0`](https://pypi.org/project/worldcut/1.0.0/) package and `worldcut-py` CLI | +| [.NET](ports/dotnet) | 0.1 / 0.1.2 | Stable [`WorldCut 1.0.0`](https://www.nuget.org/packages/WorldCut/1.0.0) library and [`WorldCut.Tool 1.0.0`](https://www.nuget.org/packages/WorldCut.Tool/1.0.0) CLI | Python and .NET implement the verifier and CLI. The adapters and integrations are available in TypeScript and Go. -The stable language SDK release candidates are version-only promotions: -protocol `0.1`, engine `0.1.2`, canonical results, and verification digests are -unchanged. Registry tags are created only after the exact merged commit passes -main CI. +Package versions and wire versions are independent. The stable `1.x` packages +continue to implement protocol `0.1` and engine `0.1.2`; the 1.0 promotion did +not change canonical results or verification digests. See +[`docs/STABILITY.md`](docs/STABILITY.md). Registry release configuration is documented in [`docs/PORT_RELEASES.md`](docs/PORT_RELEASES.md). diff --git a/docs/PORT_RELEASES.md b/docs/PORT_RELEASES.md index 4290dfc..1af479b 100644 --- a/docs/PORT_RELEASES.md +++ b/docs/PORT_RELEASES.md @@ -10,19 +10,18 @@ Python and .NET use registry-specific protected tag workflows: Current registry status: -- Go `ports/go/v0.2.0` is currently published. Stable `ports/go/v1.0.0` is - prepared with the same protocol and engine semantics. It includes the +- Go `ports/go/v1.0.0` is published with the same protocol and engine + semantics. It includes the adapters, the GitHub Actions gate, the Agentic Data Kernel adapter, `worldcut-github-ci-go`, and the Go construction API. The `v1.0.0` tag declares that exported surface stable; it is not a protocol-version change. -- .NET `0.1.1` is currently published as - [`WorldCut`](https://www.nuget.org/packages/WorldCut/0.1.1) and - [`WorldCut.Tool`](https://www.nuget.org/packages/WorldCut.Tool/0.1.1). - Stable `1.0.0` packages are prepared for the protected release workflow. -- Python `0.1.1` is currently published as - [`worldcut`](https://pypi.org/project/worldcut/0.1.1/) with PEP 740 digital - attestations for both distributions. Stable `1.0.0` artifacts are prepared. +- .NET `1.0.0` is published as + [`WorldCut`](https://www.nuget.org/packages/WorldCut/1.0.0) and + [`WorldCut.Tool`](https://www.nuget.org/packages/WorldCut.Tool/1.0.0). +- Python `1.0.0` is published as + [`worldcut`](https://pypi.org/project/worldcut/1.0.0/) with PEP 740 digital + attestations for both distributions. Package versions and wire versions are intentionally independent. The stable SDK releases continue to implement protocol `0.1` and engine `0.1.2`. diff --git a/docs/STABILITY.md b/docs/STABILITY.md new file mode 100644 index 0000000..7e3755d --- /dev/null +++ b/docs/STABILITY.md @@ -0,0 +1,50 @@ +# Stability and versioning + +WorldCut `1.x` is the stable package and public API line for the TypeScript, +Go, Python, and .NET implementations. + +Package versions, protocol versions, and engine versions are independent: + +| Identifier | Current value | Meaning | +| --- | --- | --- | +| Package/API line | `1.x` | Consumer-facing API compatibility under Semantic Versioning | +| Protocol | `0.1` | Verification input and requirement wire format | +| Engine | `0.1.2` | Exact validation, result construction, planning, and digest semantics | +| Canonicalization | `worldcut-json-v1` | Canonical JSON and digest byte rules | + +The `1.0.0` promotion does not change protocol behavior or any committed +conformance result. It declares the reviewed public APIs ready for normal +production integration under the assumptions in +[`PRODUCTION.md`](PRODUCTION.md). + +## Compatibility commitment + +Within the `1.x` package lines: + +- existing public APIs, CLI commands, and stable error codes will not be + removed or incompatibly changed; +- additive APIs and integrations may be introduced in minor releases; +- bug fixes that preserve protocol results may be released as patches; +- changes to normative verification results require an engine-version change + and updated conformance vectors; +- incompatible package API changes require a new package major version; +- incompatible wire-format changes require a new protocol version. + +The packages may release independently. A package patch or minor release can +continue implementing protocol `0.1` and engine `0.1.2`. + +## Supported surfaces + +The stability commitment covers: + +- the TypeScript `worldcut` library package and the `worldcut` and + `worldcut-github-ci` commands; +- Go verifier, construction API, adapters, integrations, and both CLIs; +- Python `worldcut` library and `worldcut-py`; +- .NET `WorldCut` and `WorldCut.Tool`; +- documented JSON schemas, stable error codes, canonicalization, result + construction, and verification-record digests. + +Provider APIs, cloud service behavior, and the completeness or truthfulness of +supplied evidence remain outside WorldCut's control. Integrations fail closed +when required provider data is unavailable or invalid. diff --git a/examples/azure-sre-agent/README.md b/examples/azure-sre-agent/README.md index 501c87c..2e3ac74 100644 --- a/examples/azure-sre-agent/README.md +++ b/examples/azure-sre-agent/README.md @@ -2,7 +2,7 @@ Azure SRE Agent custom Python tools accept a typed `main(...)` function and must return JSON-serializable data. `worldcut_gate.py` follows that contract and -uses the published `worldcut==0.1.1` PyPI package. +uses the stable `worldcut==1.0.0` PyPI package. ## Create the tool @@ -10,7 +10,7 @@ In **Builder > Agent Canvas > Create > Tool > Python tool**, create: - name: `worldcut_gate` - inputs: `verification_input` (`str`) and `target_role` (`str`) -- pip dependency: `worldcut==0.1.1` +- pip dependency: `worldcut==1.0.0` - code: paste `worldcut_gate.py` Test with the contents of `../coherent-deployment.json` and target role `head`. diff --git a/examples/azure-sre-agent/requirements.txt b/examples/azure-sre-agent/requirements.txt index cd930f1..9eae4c4 100644 --- a/examples/azure-sre-agent/requirements.txt +++ b/examples/azure-sre-agent/requirements.txt @@ -1,6 +1,6 @@ -worldcut==0.1.1 \ - --hash=sha256:71d6d64b75a2a40b4e60bf202da90696a05b606b01dafe04199df1e50c255a84 \ - --hash=sha256:09efb72cc9ce86e40b40c86373395c0c50a9e9c69fea42502240ed2364ba6fc6 +worldcut==1.0.0 \ + --hash=sha256:a9e2d0e6cb5ab214484018a3feb2a23c1d96bb908d6791dea0aeb7165f287b0d \ + --hash=sha256:ddad7b8255ab5a4c9e932e363b3d9c47b3d6b93175ddda1092c9d37533f70ac1 rfc8785==0.1.4 \ --hash=sha256:520d690b448ecf0703691c76e1a34a24ddcd4fc5bc41d589cb7c58ec651bcd48 \ --hash=sha256:e545841329fe0eee4f6a3b44e7034343100c12b4ec566dc06ca9735681deb4da diff --git a/examples/github-actions/deployment-gate-go.yml b/examples/github-actions/deployment-gate-go.yml index cb53fb0..1e56718 100644 --- a/examples/github-actions/deployment-gate-go.yml +++ b/examples/github-actions/deployment-gate-go.yml @@ -22,9 +22,9 @@ jobs: with: go-version: stable - # The Go gate ships in the ports/go/v0.2.0 module tag. + # The Go gate ships in the stable ports/go/v1.0.0 module tag. - name: Install the WorldCut Go gate - run: go install github.com/Jason-Doyle/WorldCut/ports/go/cmd/worldcut-github-ci-go@v0.2.0 + run: go install github.com/Jason-Doyle/WorldCut/ports/go/cmd/worldcut-github-ci-go@v1.0.0 - name: Verify latest completed CI run id: worldcut diff --git a/examples/github-actions/deployment-gate.yml b/examples/github-actions/deployment-gate.yml index 056aa2b..fc223f2 100644 --- a/examples/github-actions/deployment-gate.yml +++ b/examples/github-actions/deployment-gate.yml @@ -23,7 +23,7 @@ jobs: node-version: 22.19.0 - name: Install WorldCut - run: npm install --global worldcut@0.2.0 + run: npm install --global worldcut@1.0.0 - name: Verify latest completed CI run id: worldcut diff --git a/examples/microsoft-agent-framework/dotnet/README.md b/examples/microsoft-agent-framework/dotnet/README.md index 42be28d..8e7bf99 100644 --- a/examples/microsoft-agent-framework/dotnet/README.md +++ b/examples/microsoft-agent-framework/dotnet/README.md @@ -40,5 +40,5 @@ The sample effect is intentionally a recorded dry run. Replace the indicated line in `ApplyEffectExecutor` with the real operation while preserving the gate and exact immutable target. Do not expose a second unguarded write tool. -Packages are pinned to `WorldCut 0.1.1` and +Packages are pinned to stable `WorldCut 1.0.0` and `Microsoft.Agents.AI.Workflows 1.20.0`. diff --git a/examples/microsoft-agent-framework/dotnet/WorldCut.AgentFramework.Example.csproj b/examples/microsoft-agent-framework/dotnet/WorldCut.AgentFramework.Example.csproj index 9c77113..1b6054a 100644 --- a/examples/microsoft-agent-framework/dotnet/WorldCut.AgentFramework.Example.csproj +++ b/examples/microsoft-agent-framework/dotnet/WorldCut.AgentFramework.Example.csproj @@ -16,7 +16,7 @@ - + diff --git a/examples/microsoft-agent-framework/dotnet/packages.lock.json b/examples/microsoft-agent-framework/dotnet/packages.lock.json index 3009199..4b6c7bc 100644 --- a/examples/microsoft-agent-framework/dotnet/packages.lock.json +++ b/examples/microsoft-agent-framework/dotnet/packages.lock.json @@ -27,9 +27,9 @@ }, "WorldCut": { "type": "Direct", - "requested": "[0.1.1, 0.1.1]", - "resolved": "0.1.1", - "contentHash": "MP73bfjXn+uVS7Ia24l5Duv6s9nma/Be1aRmwqW6Qcm68sGIQBW0JTbmXcibKC0mD1IPz30tMda/RtmTKbj3iw==" + "requested": "[1.0.0, 1.0.0]", + "resolved": "1.0.0", + "contentHash": "x8pOS6+MVvL2FS+wkvle1E5R9ozfcPEg1UyvKhapUYyhX43QeMtIbguBn38on4c284dFltHwAytUQbnu+Ahvvw==" }, "Google.Protobuf": { "type": "Transitive", diff --git a/package-lock.json b/package-lock.json index 0e1f965..c83987c 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "worldcut", - "version": "0.2.0", + "version": "1.0.0", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "worldcut", - "version": "0.2.0", + "version": "1.0.0", "license": "Apache-2.0", "bin": { "worldcut": "dist/cli.js", diff --git a/package.json b/package.json index 29909b4..93d8d1b 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "worldcut", - "version": "0.2.0", + "version": "1.0.0", "description": "Verify cross-service observations against explicit version and temporal decision constraints.", "license": "Apache-2.0", "author": "Jason Doyle", @@ -76,6 +76,7 @@ "docs/VALIDATION.md", "docs/DIFFERENTIAL.md", "docs/AGENT_EFFECT_GATING.md", + "docs/STABILITY.md", "spec", "conformance", "README.md", diff --git a/scripts/test-package.mjs b/scripts/test-package.mjs index 36277d0..9c2095a 100644 --- a/scripts/test-package.mjs +++ b/scripts/test-package.mjs @@ -62,6 +62,7 @@ try { "docs/VALIDATION.md", "docs/DIFFERENTIAL.md", "docs/AGENT_EFFECT_GATING.md", + "docs/STABILITY.md", "spec/0.1/PROTOCOL.md", "spec/0.1/CANONICALIZATION.md", "spec/0.1/CONFORMANCE.md",