Canonical basic-Slack v1.5.0 release gate — owner-approved, reconciled 2026-09-17
This section supersedes older dependency and acceptance text below where it conflicts.
v1.4.2 Board published and qualified
Lineage: attest issue-to-PR creation and local audit publication #1020 /Lineage: publish local audits through a verified GitHub workflow #1022 provenance foundations merged through Lineage: attest initial issue-to-PR creation #1021 /Publish local audit verdicts through a verified GitHub workflow #1023
Audit publication: verify repository-dispatch workflow identity correctly #1025 repository-dispatch publication bootstrap correction
Slack: minimal opt-in setup, doctor, and runbook for v1.5.0 #922 /Slack: explicit private-workspace setup, readiness doctor and runbook #1024 minimal opt-in setup, redacted doctor and runbook
CodeMower.com: single-workspace Slack OAuth installation and explicit policy binding #918 private isolated-workspace admin lifecycle, privacy-log, rollout and rollback exercise
Build and rehearse one immutable v1.5 candidate: default Slack-free install, explicit Slack opt-in, v1.4.2 upgrade, disable/uninstall and rollback; include Fix Graphify inventory limits and frontend test discovery #1007 in package/release notes
Slack: Devin dispatch, clarification, completion, and cancellation bridge #920 completion and confirmed-cancellation canaries against that immutable candidate, after explicit numeric cap authorization
Replay/dedupe/restart/revocation/privacy evidence, exact-head release audit, green CI and authoritative gate
Publish v1.5.0 tag/package, independently reinstall, reconcile evidence and close Slack: Devin dispatch, clarification, completion, and cancellation bridge #920 /CodeMower.com: single-workspace Slack OAuth installation and explicit policy binding #918 /Epic: Basic supervised Slack ingress for v1.5.0 #903 /Roadmap through v1.5.0: bounded builders, Graphify, Board, and supervised Slack #900
Final publication follows candidate canaries; the final published package is not a canary prerequisite. #921 /#978 , rich Slack UX, Slack Connect, public channels, broad provider selection and optional #951 are v1.5.1.
Part of #903 and roadmap #900 .
v1.5.0 release and qualification
Dependencies
v1.4.2 Board package published and locally qualified through Release: publish and qualify Board clarity v1.4.2 #952
Board: integrate head-bound evidence and qualify local and hosted session visibility #951 hosted Board observation canary, if retained as a final release criterion
CodeMower.com: single-workspace Slack OAuth installation and explicit policy binding #918 OAuth/policy binding
Slack: connect authorized tasks to a qualified Code Mower supervisor #977 qualified supervisor adapter
Slack: durable inbox/outbox and start/status/cancel interaction #919 durable interactions
Slack: Devin dispatch, clarification, completion, and cancellation bridge #920 supervised hosted bridge
v1.5.1: Slack telemetry contract and OSS Board/cloud emitters #921 OSS telemetry contract and emitters
v1.5.1: CodeMower.com Slack telemetry, aggregation, and fresh views #978 hosted telemetry ingest and fresh views
Slack: minimal opt-in setup, doctor, and runbook for v1.5.0 #922 setup, doctor and operating guidance
Campaign: support isolated Codex authentication on headless Linux #983 isolated headless Codex campaign authentication
Board: manage persistent services and reject stale keepalive bindings during release restart #1001 persistent Board service lifecycle merged for inclusion in the next package
Release integrity: reject transient publication text in final tags #1014 final-tag release-state integrity gate
Adoption polish: explain drift direction and stabilize Board startup evidence #1015 adoption evidence polish for drift, Board startup, and provider-specific prompts
Lineage: attest issue-to-PR creation and local audit publication #1020 attested issue-to-PR creation lineage and local audit publication
Final acceptance
Complete and cancel bounded work through the qualified Slack-to-supervisor path.
Verify signature/replay handling, durable receipt-before-ack, deduplication, retries, clarification answers and uncertain-create reconciliation.
Verify privacy, tenant isolation, retention/deletion, restart recovery, rate limiting and least-privilege scopes.
Verify local Board, stored metadata receipt and freshly observed hosted aggregate views independently.
Verify hosted deployment and rollback evidence.
Pass source/package builds, fresh install, upgrade and default/no-optional-provider rehearsals.
Include PR Fix Graphify inventory limits and frontend test discovery #1007 's post-v1.4.2 Graphify compatibility fixes in the published release notes; rebuild only generations those gaps left affected/partial.
Obtain an independent exact-head release audit with zero P0/P1/P2 findings, green CI and authoritative gate.
Publish and verify v1.5.0 artifacts, then update Epic: Basic supervised Slack ingress for v1.5.0 #903 /Roadmap through v1.5.0: bounded builders, Graphify, Board, and supervised Slack #900 with final evidence.
Paid completion/cancellation canaries require explicit campaign-wide caps. Provider exit, implementation completion, reviewed head, authorized/settled spend, stored receipt and fresh aggregate visibility remain separate evidence.
Owner-approved basic Slack release gate (2026-09-17)
Required dependencies
#951 , #921 , and #978 are v1.5.1 work and do not block v1.5.0.
Final acceptance
One private workspace and explicit immutable user/channel/repository policy pass.
Private start, status, answer, completion, and cancellation work through one qualified supervisor/hosted-builder path.
One capped completion canary reaches verified PR/head completion.
One capped cancellation canary records acknowledgement and observed provider exit.
Replay, deduplication, restart recovery, revocation, uncertain mutation handling, least privilege, and privacy pass.
Fresh default install remains Slack-free; opt-in fresh install and upgrade rehearsals pass.
Hosted rollout, rollback, disable, and uninstall evidence pass.
Source/package checks, independent exact-head release audit, CI, and authoritative gate pass.
v1.5.0 artifacts are published and independently reinstalled.
Roadmap through v1.5.0: bounded builders, Graphify, Board, and supervised Slack #900 and Epic: Basic supervised Slack ingress for v1.5.0 #903 receive final immutable evidence.
Canonical basic-Slack v1.5.0 release gate — owner-approved, reconciled 2026-09-17
This section supersedes older dependency and acceptance text below where it conflicts.
Final publication follows candidate canaries; the final published package is not a canary prerequisite. #921/#978, rich Slack UX, Slack Connect, public channels, broad provider selection and optional #951 are v1.5.1.
Part of #903 and roadmap #900.
v1.5.0 release and qualification
Dependencies
Final acceptance
Paid completion/cancellation canaries require explicit campaign-wide caps. Provider exit, implementation completion, reviewed head, authorized/settled spend, stored receipt and fresh aggregate visibility remain separate evidence.
Owner-approved basic Slack release gate (2026-09-17)
Required dependencies
#951, #921, and #978 are v1.5.1 work and do not block v1.5.0.
Final acceptance