Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
27 changes: 27 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,33 @@ project used alpha/beta prerelease tags while the first-user setup path,
provider posture, and optional cloud sharing loop were hardening; v1.0 and
later entries are regular releases.

## v1.3.0

Code Mower can optionally give its Claude and Codex participants the same bounded,
cited organizational evidence through an explicitly selected Coworker account.
Default setup remains Claude + Codex without a context-provider dependency.

### Added

- Provider-neutral context policies, immutable packets, citations, scope/expiry
checks and a synthetic local-graph fixture for future adapters.
- Optional Coworker OAuth with signed account/workspace verification, OS vault
storage, online refresh before retrieval/replay, and local-first disconnect.
- Bounded read-only retrieval, private work-order and reviewer delivery,
context-revision-aware review validity, and private detailed review feedback.
- Optional init selection and shared redacted doctor/status/session readiness.
Explicit unavailable-input declarations distinguish optional outages from
required context; identity inspection is a local-terminal-only operation.
- A bounded two-case frozen-reference qualification with honest relevance and
productivity limits. Graphify remains a separately tracked v1.3.x candidate.

### Fixed

- Required-context changes are read from trusted repository configuration on each
gate run, so an older code-only review cannot survive a newly required input.
- Failed context attachment releases its local capacity; optional discovery
failures preserve ordinary no-context audit behavior.

## v1.2.2

Code Mower v1.2.2 keeps Jira workflow state and Board current-state reporting
Expand Down
17 changes: 11 additions & 6 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,8 @@ The short version:
exposure, or GitHub Actions churn;
- turn issue text, external docs, and project doctrine into local work orders
before an agent starts coding;
- optionally give Claude and Codex the same authorized organizational evidence
through a private Coworker connection, with fresh review when context changes;
- generate local reviewer value reports from known-clean and known-blocked PRs;
and
- optionally share sanitized metadata with [CodeMower.com](https://codemower.com)
Expand All @@ -26,8 +28,8 @@ Default cloud bundles exclude source code, raw diffs, raw model transcripts,
raw stdout/stderr, auth output, and secrets.

Documentation on `main` follows the source on `main`. If you install the
published `code-mower==1.2.2` package, use the documentation from the matching
[`v1.2.2` tag](https://github.com/codemower-ai/code-mower/tree/v1.2.2) so the
published `code-mower==1.3.0` package, use the documentation from the matching
[`v1.3.0` tag](https://github.com/codemower-ai/code-mower/tree/v1.3.0) so the
commands and package stay aligned as development continues.

## Design Principles
Expand Down Expand Up @@ -222,7 +224,7 @@ agent report its actual host posture, exact installed version, doctor result,
Board URL, and any owner-only click-list before it mutates the repo.

The current package-index announcement entry point is the tagged
[Try Code Mower In 10 Minutes](https://github.com/codemower-ai/code-mower/blob/v1.2.2/docs/try-in-10-minutes.md)
[Try Code Mower In 10 Minutes](https://github.com/codemower-ai/code-mower/blob/v1.3.0/docs/try-in-10-minutes.md)
guide. The v1.0 supervised-pilot release includes the native Board, the
controller dry-run and policy contract, adoption and upgrade hardening from
recent install rehearsals, package-index release checks, provider-diversity
Expand Down Expand Up @@ -337,7 +339,7 @@ Provider-contract baseline for the next release train:

For release verification,
[First-User Install Rehearsal](docs/first-user-install-rehearsal.md) records
the package-index procedure for `v1.2.2` / `code-mower==1.2.2`. The
the package-index procedure for `v1.3.0` / `code-mower==1.3.0`. The
GitHub release records the workflow and rehearsal evidence for the exact tag.
After publication, [Release Qualification](docs/release-qualification.md)
coordinates provider-specific install and operational checks without treating
Expand Down Expand Up @@ -531,8 +533,8 @@ measurement work.

## Installation Status

The current package-index release baseline is `v1.2.2`, with pinned package
install spec `code-mower==1.2.2`. Release evidence is recorded on the GitHub
The current package-index release baseline is `v1.3.0`, with pinned package
install spec `code-mower==1.3.0`. Release evidence is recorded on the GitHub
release and in the first-user install rehearsal. The public repository is
[codemower-ai/code-mower](https://github.com/codemower-ai/code-mower), and
GitHub releases remain the auditable source for tags, build artifacts, and
Expand Down Expand Up @@ -647,6 +649,9 @@ first so local work exercises the same package entrypoint users install.
- [v1.2 Release Notes](docs/v12-release-notes.md)
- [v1.2.1 Release Notes](docs/v121-release-notes.md)
- [v1.2.2 Release Notes](docs/v122-release-notes.md)
- [v1.3.0 Release Notes](docs/v130-release-notes.md)
- [Optional Coworker Setup](docs/context-setup.md)
- [Context Qualification and Limits](docs/v130-context-qualification.md)
- [Post-v0.8 Effectiveness Assessment](docs/post-v08-effectiveness-assessment.md)
- [v1.0.1 Effectiveness Assessment](docs/v101-effectiveness-assessment.md)

Expand Down
2 changes: 1 addition & 1 deletion docs/build-loop-in-30-minutes.md
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,7 @@ audit evidence, skip to section 2.
```bash
python3.12 --version
export CODE_MOWER_PYTHON="$(command -v python3.12)"
pipx install --python "$CODE_MOWER_PYTHON" code-mower==1.2.2
pipx install --python "$CODE_MOWER_PYTHON" code-mower==1.3.0
gh auth status >/dev/null 2>&1 && echo "gh auth ok" || { echo "gh auth NOT ready"; false; }
code-mower init --easy
code-mower init --easy --apply --output-dir .code-mower.generated
Expand Down
6 changes: 3 additions & 3 deletions docs/cloud-benchmarking.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,9 +29,9 @@ observability/evaluation backend.

## Release Stages

### Current v1.2.2: Metadata-Only Upload, Board, Productivity, And Qualification
### Current v1.3.0: Metadata-Only Upload, Board, Productivity, And Qualification

The current v1.2.2 line keeps cloud sharing opt-in for adopters who explicitly
The current v1.3.0 line keeps cloud sharing opt-in for adopters who explicitly
want to share sanitized benchmark metadata, summarized Board mirrors, or
aggregate productivity metrics with Code Mower Cloud. The OSS tool is still
local-first:
Expand All @@ -43,7 +43,7 @@ code-mower cloud upload .code-mower/cloud-benchmark-bundle --yes --json
code-mower cloud dogfood --json
code-mower cloud dogfood --event productivity_summary=productivity-summary.json --json
code-mower cloud board-snapshot --repo-slug OWNER/REPO --json
code-mower release qualify --release-tag v1.2.2 --package-spec code-mower==1.2.2 --output adoption-result.json --execute
code-mower release qualify --release-tag v1.3.0 --package-spec code-mower==1.3.0 --output adoption-result.json --execute
code-mower cloud export --event adoption_run=adoption-result.json --repo-slug OWNER/REPO --json
```

Expand Down
19 changes: 10 additions & 9 deletions docs/context-provider-contract.md
Original file line number Diff line number Diff line change
Expand Up @@ -132,14 +132,15 @@ No dependency or credential implementation is introduced by this ADR.
The local connection lifecycle and delivery implementations must enforce these
rules; a synthetic fixture or structurally valid JSON is not authorization.

## Proposed commands
## Implemented commands

These are design targets, not commands available in v1.2.2:
The qualified connection and delivery path is available in v1.3.0. See the
[setup guide](context-setup.md) for installation and explicit account selection:

```text
code-mower context connect coworker --connection example-context
code-mower context doctor --connection example-context
code-mower context fetch --connection example-context --work-order PATH
code-mower context fetch --connection example-context --request-stdin --json
code-mower context disconnect --connection example-context
```

Expand All @@ -158,8 +159,8 @@ use with HTTP 400; the SDK cleared the in-memory credentials. The old access
token's earlier successful initialization after access-token revocation shows
why offline JWT verification is insufficient for packet replay authorization.

C3 must force an online SDK refresh before every context retrieval or replay,
under a per-connection lock, and require a successful token response with a
The connection runtime forces an online SDK refresh before every context retrieval or replay,
under a per-connection lock, and requires a successful token response with a
newly verified principal/workspace/client binding. A failed refresh invalidates
the local generation and cached evidence. Do not fall back to the old token,
a stored token file, another account, or another connection. A bare MCP GET
Expand All @@ -171,12 +172,12 @@ remote revocation failures without restoring local access. An already-issued
bearer token outside Code Mower may remain usable until its expiry; do not
promise immediate global access-token revocation. Preserve other connections.

C3 must test local disconnect, concurrent refresh, generation changes,
wrong-account rejection, expiry, and unavailable refresh. C4 must retain the
The regression suite tests local disconnect, concurrent refresh, generation changes,
wrong-account rejection, expiry, and unavailable refresh. The retrieval adapter retains the
observed partial status and citations under strict request/document/byte/time
limits. Existing C2 tests cover structural scope/recipient rejection only;
they are not live provider authorization evidence. Complete the private pilot
and runtime qualification before a v1.3 release. Public artifacts contain no
they are not live provider authorization evidence. The [v1.3 qualification scorecard](v130-context-qualification.md) distinguishes
live delivery evidence from frozen reference assessment. Public artifacts contain no
private account identities, source text, source IDs, or credentials.

## Later Graphify candidate
Expand Down
19 changes: 12 additions & 7 deletions docs/current-state-and-roadmap.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# Code Mower Current State And Roadmap

This is the short source-of-truth snapshot for the public OSS package, the
hosted CodeMower.com surface, and the near-term path from the current v1.2.2
hosted CodeMower.com surface, and the near-term path from the current v1.3.0
line toward broader supervised adoption.

## Positioning
Expand All @@ -22,19 +22,24 @@ codebase, at what cost, and with which review policy.

## Current OSS State

Version 1.3 adds optional Coworker organizational context with explicit private
account selection, bounded cited packets and context-aware independent review.
The [qualification scorecard](v130-context-qualification.md) reports mixed retrieval
relevance without claiming productivity gains. Graphify remains a later candidate.

The public OSS repository is:

```text
https://github.com/codemower-ai/code-mower
```

The current package-index release baseline is `v1.2.2`, with pinned package
install spec `code-mower==1.2.2`. Release evidence is recorded on the GitHub
The current package-index release baseline is `v1.3.0`, with pinned package
install spec `code-mower==1.3.0`. Release evidence is recorded on the GitHub
release and in the first-user install rehearsal. It is intended to be installed
from the package index for supervised pilots, with GitHub tag/source installs
kept as a fallback and development path.

The v1.2.2 supervised-pilot release keeps the Python 3.12+ runtime contract,
The v1.3.0 supervised-pilot release keeps the Python 3.12+ runtime contract,
pipx/uv install matrix, non-expiring dispatch-token diagnostics, native redacted
lane status, the local Board, Board history and admin commands, spend/verdict
timelines, owner queue, optional metadata-only agent cards, explicit cloud Board
Expand Down Expand Up @@ -144,8 +149,8 @@ The beta-to-v1.0 line has proved:
- a friendly-user rollout plan that turns install, doctor, first report,
optional cloud dry-run/upload, and dashboard usefulness into explicit
acceptance criteria for the first 5-10 users; and
- the current public PyPI package-install rehearsal from `v1.2.2` /
`code-mower==1.2.2` with a
- the current public PyPI package-install rehearsal from `v1.3.0` /
`code-mower==1.3.0` with a
10/10 first-user readiness score, proving install, generated setup, doctor,
draft calibration, value-report, cloud export, and dry-run dogfood without a
local Code Mower checkout. The earlier beta.52 package rehearsal remains
Expand Down Expand Up @@ -324,7 +329,7 @@ these questions in the first few minutes:
- Where is the code intentionally structured, and where is it still being
refactored from extraction-era shape?

The v1.2.2 line now gives adopters that trust test plus first productivity
The v1.3.0 line now gives adopters that trust test plus first productivity
visibility. More provider adapters are useful only when install, doctor, first
report, privacy, measurement, and code structure remain boring and credible.

Expand Down
4 changes: 2 additions & 2 deletions docs/early-adopter-invite-runbook.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ It is an OSS local-first tool for setting up AI peer-programmer/reviewer lanes
on your real codebase, with optional privacy-first cloud reporting.

Start here:
https://github.com/codemower-ai/code-mower/blob/v1.2.2/docs/try-in-10-minutes.md
https://github.com/codemower-ai/code-mower/blob/v1.3.0/docs/try-in-10-minutes.md

Cloud sharing is optional. The default bundle excludes source code, raw diffs,
model transcripts, raw stdout/stderr, auth output, and secrets.
Expand All @@ -53,7 +53,7 @@ Before inviting a user:
```bash
python3.12 --version
export CODE_MOWER_PYTHON="$(command -v python3.12)"
pipx install --python "$CODE_MOWER_PYTHON" code-mower==1.2.2
pipx install --python "$CODE_MOWER_PYTHON" code-mower==1.3.0
code-mower --version
```

Expand Down
4 changes: 2 additions & 2 deletions docs/early-adopter-v05.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# Code Mower Early Adopter Guide

This document records the historical v0.5 early-adopter product plan. The
current public install path is the v1.2.2 supervised-pilot release; use
current public install path is the v1.3.0 supervised-pilot release; use
[Install And Bootstrap](install.md), [Try Code Mower In 10 Minutes](try-in-10-minutes.md),
and [Quickstart](quickstart.md) for live adoption steps.

Expand Down Expand Up @@ -145,7 +145,7 @@ Cut a v0.5 alpha or beta only after:

## Current Release

`v1.2.2` is the current supervised-pilot release. It keeps the
`v1.3.0` is the current supervised-pilot release. It keeps the
local-first package path from alpha.1, the cloud doctor service-readiness check
from alpha.5, the hardened provider-auth doctor diagnostics needed for
early-adopter troubleshooting, the dogfood dry-run path that feeds the
Expand Down
4 changes: 2 additions & 2 deletions docs/first-run-transcript.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,15 +9,15 @@ same provider warnings.
```bash
python3.12 --version
export CODE_MOWER_PYTHON="$(command -v python3.12)"
pipx install --python "$CODE_MOWER_PYTHON" code-mower==1.2.2
pipx install --python "$CODE_MOWER_PYTHON" code-mower==1.3.0
code-mower --version
```

Expected shape:

```text
Python 3.12.x
code-mower 1.2.2
code-mower 1.3.0
```

## Generate Local Setup
Expand Down
6 changes: 3 additions & 3 deletions docs/first-user-demo-transcript.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,9 +14,9 @@ release.
```bash
python3.12 -m venv "$WORK_DIR/venv"
"$WORK_DIR/venv/bin/python" -m pip install --upgrade pip
"$WORK_DIR/venv/bin/python" -m pip install code-mower==1.2.2
"$WORK_DIR/venv/bin/python" -m pip install code-mower==1.3.0
"$WORK_DIR/venv/bin/code-mower" migration package-install-rehearsal \
--package-spec code-mower==1.2.2 \
--package-spec code-mower==1.3.0 \
--allow-package-index \
--python "$(command -v python3.12)" \
--json
Expand All @@ -29,7 +29,7 @@ python3.12 -m venv "$WORK_DIR/venv"
"mode": "package-install-rehearsal",
"status": "pass",
"steps": 27,
"package_spec": "code-mower==1.2.2",
"package_spec": "code-mower==1.3.0",
"toy_repo": "$WORK_DIR/toy-repo",
"doctor_status": "warn",
"generated_artifacts": {
Expand Down
Loading
Loading