diff --git a/.github/SECURITY.md b/.github/SECURITY.md index d4613f0..0d6b1a8 100644 --- a/.github/SECURITY.md +++ b/.github/SECURITY.md @@ -4,7 +4,7 @@ | Version | Supported | |---|---| -| `v0.1.0-beta.2` / `0.1.0-dev` | Best effort during pre-release (beta.1 superseded) | +| `v0.1.0-beta.4` / `0.1.0-dev` | Best effort during pre-release | | Stable versions | None released yet | ## 2. Reporting a Vulnerability diff --git a/.github/SUPPORT.md b/.github/SUPPORT.md index 3aee5ce..82eb219 100644 --- a/.github/SUPPORT.md +++ b/.github/SUPPORT.md @@ -2,7 +2,8 @@ Thank you for using PatchGate. -PatchGate is a public pre-release (`0.1.0-dev`, Action tag `v0.1.0-beta.2`). +PatchGate is a public pre-release (`0.1.0-dev`, Action tag `v0.1.0-beta.4`, commit +`d8c67a848a95d456707e6c580a43e4e56e6071a0`). Support is **best effort**. There is no SLA for consumer questions, no on-call, and no promise that a maintainer will debug a specific repository's GitHub Ruleset, branch protection, or workflow graph. PatchGate reports diff --git a/AGENTS.md b/AGENTS.md index 144746c..0bc81fd 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -98,14 +98,14 @@ readiness. | Area | Current evidence | Status and limit | | --- | --- | --- | -| G0 public foundation | Public repository `https://github.com/daichunghy/patchgate`, Apache-2.0 license, Community Profile 100%, seven repository topics, Discussions, private vulnerability reporting, protected `main`, CI workflow, and successful public `main` CI runs including the recorded `32563526945` on `main@e4052f2` | Foundation is present; public default branch is `main@6db56a4` after PR #26; `main` requires six CI contexts and one approving review, `0.1.0-dev` remains an unpublished package, beta tags through `v0.1.0-beta.2` exist, and there is no downstream usage; the hardening PR #9 was merged by the repository administrator on 2026-08-22 without an independent approving review, which is recorded here as a maintainer decision rather than independent-review evidence | +| G0 public foundation | Public repository `https://github.com/daichunghy/patchgate`, Apache-2.0 license, Community Profile 100%, seven repository topics, Discussions, private vulnerability reporting, protected `main`, CI workflow, and successful public `main` CI runs | Foundation is present at public `main@d8c67a8`; `main` requires six CI contexts and one approving review, `0.1.0-dev` remains an unpublished package, and beta.4 is the current public Action pre-release. There is no downstream usage; maintainer-bypass merges remain recorded as maintainer decisions rather than independent-review evidence | | G1 deterministic contract | TypeScript evaluator, schemas, receipt digests, recorded fixtures, security coverage, and deterministic tests | Locally verified; this does not prove a live GitHub integration | | G2 local preflight | `preflight`, `validate`, `init`, `doctor`, Git-ref loading, discovery classification, text/JSON parity, and six CLI process tests (the sixth covers the `evaluate --output` alias and its fail-closed conflict, PR #40) | Local user flow is verified; three consented usability sessions and UR acceptance evidence are still open | | G3 GitHub adapter | Recorded/mock authenticated snapshot flow, bounded requests, source and SHA binding, TOCTOU re-read, redaction, branch-protection and Rulesets subset contract, 25 integration tests and the latest recorded GET-only smoke for PR #9 head `5f9ccb5` | The tested head built a schema-valid live snapshot and receipt with final status `human_review_required`; missing approval/ownership/linkage evidence remains explicit; unsupported Ruleset semantics and merge-group membership remain fail-closed | | G4 Action | Root `action.yml`, `src/action/index.ts`, committed ncc bundle, pinned workflows, required CI/CodeQL merge-group triggers, clean-room bundle verification, idempotent check delivery including a neutral check run when the snapshot is rejected (PR #26), consumer fixture smoke and explicit non-ready merge-group handling are merged into `main` | Local consumer boundary is verified; no live external consumer E2E, production release or two consenting non-blocking shadow installations | -| User value and release | Protocols, roadmap, five public Discussions including [#10](https://github.com/daichunghy/patchgate/discussions/10), a [pilot request](https://github.com/daichunghy/patchgate/issues/4), three contribution issues, public Project #1, merged PR #9 and the `v0.1.0-beta.2` pre-release (`v0.1.0-beta.1` superseded) with a recorded shadow-installation no-go decision exist; four context-specific questions were posted to related OSS repositories | No completed G2 sessions, external replies or contributions, external shadow installations, enforcement pilots, production release, or `v0.1` claim | +| User value and release | Protocols, roadmap, public Discussions, pilot request, contribution issues, public Project #1, merged hardening work and the `v0.1.0-beta.4` pre-release with a recorded shadow-installation no-go decision exist | No completed G2 sessions, external replies or contributions, external shadow installations, enforcement pilots, production release, or `v0.1` claim | -The public default branch is currently `main@a9edc3a`. [PR #9](https://github.com/daichunghy/patchgate/pull/9) +The public default branch is currently `main@d8c67a8`. [PR #9](https://github.com/daichunghy/patchgate/pull/9) and follow-ups #15–#21, #23, #25 and #26 were merged on 2026-08-22, and #28, #36 and #40 were merged on 2026-08-23, each by the repository administrator after temporarily lifting `enforce_admins`; the setting was @@ -121,7 +121,7 @@ and CodeQL `32563526929` on `main@e4052f2`, earlier runs through [32559824706](https://github.com/daichunghy/patchgate/actions/runs/32559824706) on `main@c9f643e`, and the first public run [CI 32333914059](https://github.com/daichunghy/patchgate/actions/runs/32333914059). -For `main@a9edc3a`, default-branch CI run +For `main@d8c67a8`, default-branch CI run [32616034636](https://github.com/daichunghy/patchgate/actions/runs/32616034636) completed successfully while CodeQL `32616034425` was still in progress when this snapshot was written. @@ -141,13 +141,13 @@ and #39 (`actions/checkout` 7) were merged on 2026-08-23 after green CI, and the split CodeQL 4.37.7 PRs #35/#37 were superseded by a combined init+analyze bump; the `create-check-run` default flip also shipped in that PR. Every merge used the recorded admin-bypass pattern and is a maintainer decision. The pre-release -[`v0.1.0-beta.2`](https://github.com/daichunghy/patchgate/releases/tag/v0.1.0-beta.2) -was tagged at `main@edab0ec` on 2026-08-22 after a live maintainer smoke +[`v0.1.0-beta.4`](https://github.com/daichunghy/patchgate/releases/tag/v0.1.0-beta.4) +is pinned to `main@d8c67a8` after a live maintainer smoke ([daichunghy/patchgate-beta-smoke](https://github.com/daichunghy/patchgate-beta-smoke)) found and fixed a critical Action input-parsing bug that made `v0.1.0-beta.1` unusable on real runners ([findings](docs/reviews/2026-08-22-live-smoke-findings.md), -[release record](docs/releases/2026-08-22-beta-candidate.md)); it is beta +[release record](docs/releases/2026-08-23-beta.4.md)); it is beta shadow-evidence scope only — not production, adoption or a `v0.1` claim. The current milestone audit is [the 2026-08-20 G4/G0 continuation audit](docs/reviews/2026-08-20-g4-g0-audit.md). The newest records are the [2026-08-22 multi-persona review round](docs/reviews/2026-08-22-multi-persona-review.md), the [2026-08-22 live consumer smoke findings](docs/reviews/2026-08-22-live-smoke-findings.md) and the [2026-08-22 Mimosa static-advisory adjudication](docs/reviews/2026-08-22-mimosa-static-advisory-adjudication.md) — re-run the sealed scan after any change to `src/github/client.ts` transport handling. The latest verification command to rerun after a change is: @@ -212,16 +212,15 @@ produced by the adapter — not a raw GitHub event payload. Current allowed Action form (shadow only): ```yaml -- uses: daichunghy/patchgate@v0.1.0-beta.2 +- uses: daichunghy/patchgate@d8c67a848a95d456707e6c580a43e4e56e6071a0 with: fail-on: never create-check-run: true ``` `fail-on: blocked` is the enforcement form intended for the first stable -release, not for this pre-release. Pin `v0.1.0-beta.2` or later: -`v0.1.0-beta.1` Action inputs were unreadable on real runners and the tag -is superseded. +release, not for this pre-release. Pin the beta.4 full SHA above; older beta +tags are superseded. The first supported rule classes are: diff --git a/README.md b/README.md index b497d14..181b804 100644 --- a/README.md +++ b/README.md @@ -16,12 +16,12 @@ The evaluator is deterministic and explainable. It does not determine who or what produced the code, whether the code is correct, safe, or merge-worthy, and it cannot force external automation to stop working. -**Status:** public pre-release. The package is unpublished (`private: true`, -`0.1.0-dev`). The Action tag -[`v0.1.0-beta.2`](https://github.com/daichunghy/patchgate/releases/tag/v0.1.0-beta.2) -is the recommended immutable reference for **shadow** evaluation only. -`v0.1.0-beta.1` is superseded. This is not production, not a `v0.1` claim, -and not evidence of external pilots or adoption. +**Status:** public pre-release. The npm package remains unpublished (`private: true`, +`0.1.0-dev`). The current Action release is +[`v0.1.0-beta.4`](https://github.com/daichunghy/patchgate/releases/tag/v0.1.0-beta.4), +and consumers should pin commit `d8c67a848a95d456707e6c580a43e4e56e6071a0` for +**shadow** evaluation only. This is not production, not a `v0.1` claim, and +not evidence of external pilots or adoption. ## Try it locally @@ -64,9 +64,9 @@ Longer walkthrough: [Getting started](docs/getting-started.md). ## GitHub Action candidate The Action is bundled for the repository's local shadow workflow. The tagged -pre-release [`v0.1.0-beta.2`](https://github.com/daichunghy/patchgate/releases/tag/v0.1.0-beta.2) -is the recommended immutable reference for shadow evaluation; `v0.1.0-beta.1` -is superseded because its Action inputs were unreadable on real runners. +pre-release [`v0.1.0-beta.4`](https://github.com/daichunghy/patchgate/releases/tag/v0.1.0-beta.4) +is the current release; pin commit `d8c67a848a95d456707e6c580a43e4e56e6071a0` +for shadow evaluation. Production consumers must still wait for a stable public release. Do not use the placeholder `patchgate/patchgate@v0.1.0-dev` as an installable public reference. Consumer setup, permissions and the shadow workflow are documented @@ -209,7 +209,7 @@ The repository maintains a clean root directory structure (9 files max) with mod - [Project constitution](docs/PROJECT_CONSTITUTION.md) - [Example policy](docs/patchgate.example.yml) - [Action usage guide](docs/github-action-usage.md) -- [v0.1.0-beta.2 release record](docs/releases/2026-08-22-beta-candidate.md) +- [v0.1.0-beta.4 release record](docs/releases/2026-08-23-beta.4.md) - [Contributing](.github/CONTRIBUTING.md) - [Security policy](.github/SECURITY.md) - [Code of conduct](.github/CODE_OF_CONDUCT.md) diff --git a/docs/CHANGELOG.md b/docs/CHANGELOG.md index 2eedd40..0df3abb 100644 --- a/docs/CHANGELOG.md +++ b/docs/CHANGELOG.md @@ -2,6 +2,11 @@ All notable changes to PatchGate will be documented in this file. +### Beta release — 2026-08-23 (`v0.1.0-beta.4`) +- Released [`v0.1.0-beta.4`](https://github.com/daichunghy/patchgate/releases/tag/v0.1.0-beta.4), pinned to `d8c67a848a95d456707e6c580a43e4e56e6071a0`. +- Updated the consumer Action reference, default Check Run behavior, CLI `--output` alias, and full-SHA workflow pins. +- This remains shadow-evidence only: no production, adoption, external pilot, or stable `v0.1` claim. + The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). diff --git a/docs/getting-started.md b/docs/getting-started.md index b5422ff..f4edece 100644 --- a/docs/getting-started.md +++ b/docs/getting-started.md @@ -1,15 +1,14 @@ # Getting started PatchGate is a public pre-release. The npm package is unpublished -(`private: true`, `0.1.0-dev`). The Action tag `v0.1.0-beta.2` is for -shadow evaluation only — not production, not a `v0.1` claim, and not -evidence of external pilots. +(`private: true`, `0.1.0-dev`). The current Action release is `v0.1.0-beta.4`, +which is for shadow evaluation only — not production, not a `v0.1` claim, and +not evidence of external pilots. Pin commit +`d8c67a848a95d456707e6c580a43e4e56e6071a0`. This walkthrough uses a clone and a local build. Do not run `npx patchgate`: -that npm name is a different project. This CLI is unpublished. A later -publish, if any, would use a scoped name such as `@daichunghy/patchgate`. -`npx github:daichunghy/patchgate` also fails today: committed `dist/` is -the Action bundle, not `dist/src/cli.js`. +that npm name is a different project. The direct GitHub install is available +for the beta release, while the CLI remains an unpublished npm package. ## 1. Clone and build diff --git a/docs/github-action-usage.md b/docs/github-action-usage.md index 28af915..0a6731a 100644 --- a/docs/github-action-usage.md +++ b/docs/github-action-usage.md @@ -15,9 +15,10 @@ after the documented gates have been reviewed. In **Shadow Mode**, PatchGate observes only (`fail-on: never`). It evaluates the PR, writes the `ContributionReceipt`, and can post a Check Run without blocking merge. Pin -[`v0.1.0-beta.2`](https://github.com/daichunghy/patchgate/releases/tag/v0.1.0-beta.2) -for this pre-release; `v0.1.0-beta.1` is superseded because Action inputs were -unreadable on real runners. This is not production and not a `v0.1` claim. +[`v0.1.0-beta.4`](https://github.com/daichunghy/patchgate/releases/tag/v0.1.0-beta.4) +for this pre-release and pin commit +`d8c67a848a95d456707e6c580a43e4e56e6071a0`. This is not production and not a +`v0.1` claim. The Action reads GitHub metadata through the API. Do **not** check out pull-request code in this workflow. `github.token` cannot be granted the @@ -57,9 +58,9 @@ jobs: # branch-protection snapshots fail closed (correct). A PAT/App token # with administration:read is required for a complete native-control # snapshot. beta.2 posts a Check Run for successful evaluations; - # snapshot-rejection Check Runs landed after that tag (see main). + # snapshot-rejection Check Runs are included in beta.4. - name: Run PatchGate Shadow Gate - uses: daichunghy/patchgate@v0.1.0-beta.2 + uses: daichunghy/patchgate@d8c67a848a95d456707e6c580a43e4e56e6071a0 with: fail-on: never create-check-run: true @@ -75,7 +76,7 @@ workflow. It is still not production or a `v0.1` claim. ```yaml - name: Run PatchGate Enforcing Gate - uses: daichunghy/patchgate@v0.1.0-beta.2 + uses: daichunghy/patchgate@d8c67a848a95d456707e6c580a43e4e56e6071a0 with: fail-on: blocked create-check-run: true diff --git a/docs/releases/2026-08-23-beta.4.md b/docs/releases/2026-08-23-beta.4.md new file mode 100644 index 0000000..e7952f7 --- /dev/null +++ b/docs/releases/2026-08-23-beta.4.md @@ -0,0 +1,29 @@ +# PatchGate `v0.1.0-beta.4` + +**Release date:** 23 August 2026 +**Tag:** [`v0.1.0-beta.4`](https://github.com/daichunghy/patchgate/releases/tag/v0.1.0-beta.4) +**Pinned commit:** `d8c67a848a95d456707e6c580a43e4e56e6071a0` + +## Scope + +Beta.4 is the current public Action pre-release for non-blocking shadow +evaluation. Pin the full commit SHA in consumer workflows and keep +`fail-on: never` until the external consumer and shadow-installation gates are +closed. + +## What changed + +- `create-check-run` defaults to `true` and mirrors the Action metadata; +- `evaluate --output` is an alias of `--report`, with conflicting paths rejected; +- the committed Action bundle includes the current CLI parser and neutral + rejection Check Run behavior; +- repository workflow actions use full SHA pins; +- the public release was verified by local `npm run verify`, CI, CodeQL, the + clean-room bundle check, and the maintainer smoke repository. + +## Limits + +This is not a production release, Marketplace listing, `v0.1` claim, external +adoption evidence, or proof of an external shadow pilot. Native-control +visibility is incomplete with `GITHUB_TOKEN`; a PAT or GitHub App token with +`administration: read` is required for that part of the snapshot. diff --git a/docs/releases/beta-release-and-rollback.md b/docs/releases/beta-release-and-rollback.md index 4d7f763..a415f22 100644 --- a/docs/releases/beta-release-and-rollback.md +++ b/docs/releases/beta-release-and-rollback.md @@ -1,7 +1,7 @@ # Beta release and rollback runbook -**Status:** release preparation only; no beta or `v0.1` release is authorized -by this document. +**Status:** runbook for the current public beta; it does not authorize a stable +`v0.1` release or production enforcement. This runbook closes the documentation path requested in [issue #5](https://github.com/daichunghy/patchgate/issues/5). It does not override the constitution, branch protection, pilot consent or the @@ -20,8 +20,9 @@ Before publishing a beta, the maintainer must have independently recorded: no-go decision; - support, security-reporting, compatibility and unsupported-behavior wording. -The current repository has a public pre-release PR and a private development -package, so these prerequisites are not yet all satisfied. +The current repository has public pre-release `v0.1.0-beta.4` and a private +development package. The two external shadow installations and production +gates remain open. ## Release procedure