Skip to content

Roadmap through v1.5.0: bounded builders, Graphify, Board, and supervised Slack #900

Description

@jeffhuber

Canonical v1.5.0 critical path — owner-approved, reconciled 2026-09-17

This section supersedes older v1.5 dependency/checklist text below where it conflicts.

  1. Audit provenance: Lineage: attest issue-to-PR creation and local audit publication #1020 and Lineage: publish local audits through a verified GitHub workflow #1022 are complete through merged Lineage: attest initial issue-to-PR creation #1021/Publish local audit verdicts through a verified GitHub workflow #1023. Audit publication: verify repository-dispatch workflow identity correctly #1025 is the remaining bootstrap correction for verified repository-dispatch publication.
  2. Basic Slack operator surface: merge Slack: explicit private-workspace setup, readiness doctor and runbook #1024 and close Slack: minimal opt-in setup, doctor, and runbook for v1.5.0 #922 after a verified exact-head Claude PASS and authoritative gate.
  3. Private operational acceptance: complete CodeMower.com: single-workspace Slack OAuth installation and explicit policy binding #918's isolated-workspace install, immutable binding, rotation, disable, deletion/reinstall, privacy-log, rollout and rollback exercise.
  4. Immutable candidate: build one candidate artifact from the intended v1.5 commit; rehearse default Slack-free install, explicit Slack opt-in, v1.4.2 upgrade, disable/uninstall and rollback. Include Fix Graphify inventory limits and frontend test discovery #1007 in package and release notes.
  5. Live qualification: after explicit numeric authorization, run Slack: Devin dispatch, clarification, completion, and cancellation bridge #920's completion and cancellation canaries against that immutable candidate. Recommended cap remains 1 ACU each, 2 ACU aggregate, zero automatic recovery creates.
  6. Release: finish Release: qualify and publish basic supervised Slack ingress in v1.5.0 #923 exact-head audit/gate, publish tag/package, independently reinstall, reconcile evidence, then close Epic: Basic supervised Slack ingress for v1.5.0 #903 and Roadmap through v1.5.0: bounded builders, Graphify, Board, and supervised Slack #900.

#921/#978 telemetry and hosted analytics, rich Slack UX, Slack Connect, public channels, broad provider selection and optional #951 are v1.5.1 work. Canaries qualify the immutable candidate before final publication; final publication is not a canary prerequisite.

Completion roadmap through v1.5.0

Current position

Release Result Canonical evidence Remaining boundary
v1.4.0 Published and qualified bounded hosted-builder campaign complete Devin remains qualified only for bounded builder work
v1.4.1 Published and qualified Graphify release commit d52bc68396397edfeae782d08a768386f89a00f2; #902/#915 closed none for the release
v1.4.2 Published and qualified Board release commit 55339bf1acf76d33be5937e80bdaad772e0b2bf5; #952 closed #951 remains open only for a separately authorized hosted Devin observation canary
v1.5.0 Active phase Slack foundations #916/#929 and #917/#933 are merged deliver and qualify supervised Slack ingress

The repository-wide post-v1.4.2 documentation audit merged through #1009 at 5272bfe33d5d5fc583ab672352ee86f880ec5701. It reconciles installation, Graphify, Board, qualification, release and roadmap guidance. PR #1007 is also merged on main but is not in the immutable v1.4.2 package; its Graphify compatibility fixes will ship in the next appropriate release.

Approved revisions carried forward

  1. Precise provider qualification. Transport support, bounded builder eligibility, orchestration authority and merge-review authority remain separate claims.
  2. Verified handoff and contributor lineage. Replacement writers require source quiescence; exact-head contributors and reviewers must be reconciled before acceptance.
  3. Qualified Slack supervision. Slack is ingress and conversation transport. A separately qualified Codex/Claude supervisor owns dispatch, clarification, review, cancellation and recovery decisions.
  4. Independent operational evidence. Implementation completion, provider exit, reviewed head, authorized/settled spend, upload receipt and fresh aggregate visibility remain independent facts.
  5. Accurate release and tracker state. A merged change is recorded as shipped only after the verified package or deployment contains it; historical evidence stays bound to its original head.

v1.5.0 delivery map

Wave Issues Deliverable
Foundation already accepted #916/#929, #917/#933 provider-neutral Slack contract and authenticated receipt-before-ack ingress
Parallel prerequisites #918, #977, #983 hosted OAuth/policy binding; qualified OSS supervisor adapter; isolated headless Codex campaign authentication
Durable interaction and bridge #919, then #920 durable start/status/cancel/answer flow and supervised hosted-builder bridge
Paired telemetry #921, then #978 frozen OSS contract/emitters followed by hosted validation, aggregation and fresh views
Setup and operation #922 optional setup, doctor, readiness and operating guidance
Release convergence #923 completion/cancellation canaries, adversarial/retry/upgrade checks, hosted rollout/rollback, package publication and final evidence

#951 may run its one bounded hosted observation canary in parallel only after the owner explicitly authorizes a new campaign-wide 1 ACU cap. No prior #935 allowance is reusable. The pending canary does not undo the published v1.4.2 result and no hosted session is implied by roadmap execution.

Delivery contract

  • One named Code Mower builder and one writer per branch.
  • Every PR requires an independent eligible exact-head audit, zero P0/P1/P2 findings, relevant tests, privacy/package checks, normal CI and authoritative code-mower/gate.
  • A changed head invalidates prior audit evidence. Release, tag, package publication and deployment actions remain serialized.
  • Board stays a read-only local observation model. Graphify stays optional, local and explicit-refresh. Slack stays authorized ingress under a qualified supervisor.
  • Public evidence excludes source, diffs, prompts, task/answer prose, private identities, credentials, raw provider records, private repository names and graph contents.
  • Paid campaigns require an explicit per-campaign and aggregate cap, no blind retry after an uncertain create, and separate authorized-versus-settled spend reporting.

Completion gates

Close #900 only after v1.5.0 is published and every required release, deployment, canary, package and evidence boundary is accepted.


Owner-approved v1.5.0 release boundary (2026-09-17)

v1.5.0 ships basic supervised Slack for one private workspace. One explicitly configured qualified Codex or Claude supervisor may accept authorized work and use hosted Devin as a bounded builder. Required user functions are private start, status, clarification answer, completion, and confirmed cancellation. Authorization is restricted by immutable workspace, user, channel, and repository bindings.

Required before publication: #1022; the remaining #918 private administration exercise; minimal #922 setup, doctor, and runbook; two explicitly capped #920 live canaries; fresh install and upgrade rehearsals; hosted rollout and rollback evidence; exact-head release audit; package/tag publication; and final reconciliation through #923.

Deferred to v1.5.1: #921/#978 Slack telemetry and hosted analytics, rich Slack UX, Slack Connect, public-channel posting, broad provider selection, and optional #951 Board hosted observation. The telemetry deferral does not weaken durable local state, provider-exit evidence, privacy, authorization, replay protection, cancellation confirmation, or exact PR/head verification.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestepicEpic tracking issue

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions