Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@

| Version | Supported |
|---|---|
| `v0.1.0-beta.2` / `0.1.0-dev` | Best effort during pre-release (beta.1 superseded) |
| `v0.1.0-beta.4` / `0.1.0-dev` | Best effort during pre-release |
| Stable versions | None released yet |

## 2. Reporting a Vulnerability
Expand Down
3 changes: 2 additions & 1 deletion .github/SUPPORT.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,8 @@

Thank you for using PatchGate.

PatchGate is a public pre-release (`0.1.0-dev`, Action tag `v0.1.0-beta.2`).
PatchGate is a public pre-release (`0.1.0-dev`, Action tag `v0.1.0-beta.4`, commit
`d8c67a848a95d456707e6c580a43e4e56e6071a0`).
Support is **best effort**. There is no SLA for consumer questions, no
on-call, and no promise that a maintainer will debug a specific repository's
GitHub Ruleset, branch protection, or workflow graph. PatchGate reports
Expand Down
21 changes: 10 additions & 11 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -98,14 +98,14 @@ readiness.

| Area | Current evidence | Status and limit |
| --- | --- | --- |
| G0 public foundation | Public repository `https://github.com/daichunghy/patchgate`, Apache-2.0 license, Community Profile 100%, seven repository topics, Discussions, private vulnerability reporting, protected `main`, CI workflow, and successful public `main` CI runs including the recorded `32563526945` on `main@e4052f2` | Foundation is present; public default branch is `main@6db56a4` after PR #26; `main` requires six CI contexts and one approving review, `0.1.0-dev` remains an unpublished package, beta tags through `v0.1.0-beta.2` exist, and there is no downstream usage; the hardening PR #9 was merged by the repository administrator on 2026-08-22 without an independent approving review, which is recorded here as a maintainer decision rather than independent-review evidence |
| G0 public foundation | Public repository `https://github.com/daichunghy/patchgate`, Apache-2.0 license, Community Profile 100%, seven repository topics, Discussions, private vulnerability reporting, protected `main`, CI workflow, and successful public `main` CI runs | Foundation is present at public `main@d8c67a8`; `main` requires six CI contexts and one approving review, `0.1.0-dev` remains an unpublished package, and beta.4 is the current public Action pre-release. There is no downstream usage; maintainer-bypass merges remain recorded as maintainer decisions rather than independent-review evidence |
| G1 deterministic contract | TypeScript evaluator, schemas, receipt digests, recorded fixtures, security coverage, and deterministic tests | Locally verified; this does not prove a live GitHub integration |
| G2 local preflight | `preflight`, `validate`, `init`, `doctor`, Git-ref loading, discovery classification, text/JSON parity, and six CLI process tests (the sixth covers the `evaluate --output` alias and its fail-closed conflict, PR #40) | Local user flow is verified; three consented usability sessions and UR acceptance evidence are still open |
| G3 GitHub adapter | Recorded/mock authenticated snapshot flow, bounded requests, source and SHA binding, TOCTOU re-read, redaction, branch-protection and Rulesets subset contract, 25 integration tests and the latest recorded GET-only smoke for PR #9 head `5f9ccb5` | The tested head built a schema-valid live snapshot and receipt with final status `human_review_required`; missing approval/ownership/linkage evidence remains explicit; unsupported Ruleset semantics and merge-group membership remain fail-closed |
| G4 Action | Root `action.yml`, `src/action/index.ts`, committed ncc bundle, pinned workflows, required CI/CodeQL merge-group triggers, clean-room bundle verification, idempotent check delivery including a neutral check run when the snapshot is rejected (PR #26), consumer fixture smoke and explicit non-ready merge-group handling are merged into `main` | Local consumer boundary is verified; no live external consumer E2E, production release or two consenting non-blocking shadow installations |
| User value and release | Protocols, roadmap, five public Discussions including [#10](https://github.com/daichunghy/patchgate/discussions/10), a [pilot request](https://github.com/daichunghy/patchgate/issues/4), three contribution issues, public Project #1, merged PR #9 and the `v0.1.0-beta.2` pre-release (`v0.1.0-beta.1` superseded) with a recorded shadow-installation no-go decision exist; four context-specific questions were posted to related OSS repositories | No completed G2 sessions, external replies or contributions, external shadow installations, enforcement pilots, production release, or `v0.1` claim |
| User value and release | Protocols, roadmap, public Discussions, pilot request, contribution issues, public Project #1, merged hardening work and the `v0.1.0-beta.4` pre-release with a recorded shadow-installation no-go decision exist | No completed G2 sessions, external replies or contributions, external shadow installations, enforcement pilots, production release, or `v0.1` claim |

The public default branch is currently `main@a9edc3a`. [PR #9](https://github.com/daichunghy/patchgate/pull/9)
The public default branch is currently `main@d8c67a8`. [PR #9](https://github.com/daichunghy/patchgate/pull/9)
and follow-ups #15–#21, #23, #25 and #26 were merged on 2026-08-22, and #28,
#36 and #40 were merged on 2026-08-23, each by the repository
administrator after temporarily lifting `enforce_admins`; the setting was
Expand All @@ -121,7 +121,7 @@ and CodeQL `32563526929` on `main@e4052f2`, earlier runs through
[32559824706](https://github.com/daichunghy/patchgate/actions/runs/32559824706)
on `main@c9f643e`, and the first public run
[CI 32333914059](https://github.com/daichunghy/patchgate/actions/runs/32333914059).
For `main@a9edc3a`, default-branch CI run
For `main@d8c67a8`, default-branch CI run
[32616034636](https://github.com/daichunghy/patchgate/actions/runs/32616034636)
completed successfully while CodeQL `32616034425` was still in progress when
this snapshot was written.
Expand All @@ -141,13 +141,13 @@ and #39 (`actions/checkout` 7) were merged on 2026-08-23 after green CI, and
the split CodeQL 4.37.7 PRs #35/#37 were superseded by a combined init+analyze
bump; the `create-check-run` default flip also shipped in that PR. Every merge
used the recorded admin-bypass pattern and is a maintainer decision. The pre-release
[`v0.1.0-beta.2`](https://github.com/daichunghy/patchgate/releases/tag/v0.1.0-beta.2)
was tagged at `main@edab0ec` on 2026-08-22 after a live maintainer smoke
[`v0.1.0-beta.4`](https://github.com/daichunghy/patchgate/releases/tag/v0.1.0-beta.4)
is pinned to `main@d8c67a8` after a live maintainer smoke
([daichunghy/patchgate-beta-smoke](https://github.com/daichunghy/patchgate-beta-smoke))
found and fixed a critical Action input-parsing bug that made `v0.1.0-beta.1`
unusable on real runners
([findings](docs/reviews/2026-08-22-live-smoke-findings.md),
[release record](docs/releases/2026-08-22-beta-candidate.md)); it is beta
[release record](docs/releases/2026-08-23-beta.4.md)); it is beta
shadow-evidence scope only — not production, adoption or a `v0.1` claim.

The current milestone audit is [the 2026-08-20 G4/G0 continuation audit](docs/reviews/2026-08-20-g4-g0-audit.md). The newest records are the [2026-08-22 multi-persona review round](docs/reviews/2026-08-22-multi-persona-review.md), the [2026-08-22 live consumer smoke findings](docs/reviews/2026-08-22-live-smoke-findings.md) and the [2026-08-22 Mimosa static-advisory adjudication](docs/reviews/2026-08-22-mimosa-static-advisory-adjudication.md) — re-run the sealed scan after any change to `src/github/client.ts` transport handling. The latest verification command to rerun after a change is:
Expand Down Expand Up @@ -212,16 +212,15 @@ produced by the adapter — not a raw GitHub event payload.
Current allowed Action form (shadow only):

```yaml
- uses: daichunghy/patchgate@v0.1.0-beta.2
- uses: daichunghy/patchgate@d8c67a848a95d456707e6c580a43e4e56e6071a0
with:
fail-on: never
create-check-run: true
```

`fail-on: blocked` is the enforcement form intended for the first stable
release, not for this pre-release. Pin `v0.1.0-beta.2` or later:
`v0.1.0-beta.1` Action inputs were unreadable on real runners and the tag
is superseded.
release, not for this pre-release. Pin the beta.4 full SHA above; older beta
tags are superseded.

The first supported rule classes are:

Expand Down
20 changes: 10 additions & 10 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,12 +16,12 @@ The evaluator is deterministic and explainable. It does not determine who or
what produced the code, whether the code is correct, safe, or merge-worthy, and
it cannot force external automation to stop working.

**Status:** public pre-release. The package is unpublished (`private: true`,
`0.1.0-dev`). The Action tag
[`v0.1.0-beta.2`](https://github.com/daichunghy/patchgate/releases/tag/v0.1.0-beta.2)
is the recommended immutable reference for **shadow** evaluation only.
`v0.1.0-beta.1` is superseded. This is not production, not a `v0.1` claim,
and not evidence of external pilots or adoption.
**Status:** public pre-release. The npm package remains unpublished (`private: true`,
`0.1.0-dev`). The current Action release is
[`v0.1.0-beta.4`](https://github.com/daichunghy/patchgate/releases/tag/v0.1.0-beta.4),
and consumers should pin commit `d8c67a848a95d456707e6c580a43e4e56e6071a0` for
**shadow** evaluation only. This is not production, not a `v0.1` claim, and
not evidence of external pilots or adoption.

## Try it locally

Expand Down Expand Up @@ -64,9 +64,9 @@ Longer walkthrough: [Getting started](docs/getting-started.md).
## GitHub Action candidate

The Action is bundled for the repository's local shadow workflow. The tagged
pre-release [`v0.1.0-beta.2`](https://github.com/daichunghy/patchgate/releases/tag/v0.1.0-beta.2)
is the recommended immutable reference for shadow evaluation; `v0.1.0-beta.1`
is superseded because its Action inputs were unreadable on real runners.
pre-release [`v0.1.0-beta.4`](https://github.com/daichunghy/patchgate/releases/tag/v0.1.0-beta.4)
is the current release; pin commit `d8c67a848a95d456707e6c580a43e4e56e6071a0`
for shadow evaluation.
Production consumers must still wait for a stable public release. Do not use
the placeholder `patchgate/patchgate@v0.1.0-dev` as an installable public
reference. Consumer setup, permissions and the shadow workflow are documented
Expand Down Expand Up @@ -209,7 +209,7 @@ The repository maintains a clean root directory structure (9 files max) with mod
- [Project constitution](docs/PROJECT_CONSTITUTION.md)
- [Example policy](docs/patchgate.example.yml)
- [Action usage guide](docs/github-action-usage.md)
- [v0.1.0-beta.2 release record](docs/releases/2026-08-22-beta-candidate.md)
- [v0.1.0-beta.4 release record](docs/releases/2026-08-23-beta.4.md)
- [Contributing](.github/CONTRIBUTING.md)
- [Security policy](.github/SECURITY.md)
- [Code of conduct](.github/CODE_OF_CONDUCT.md)
Expand Down
5 changes: 5 additions & 0 deletions docs/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,11 @@

All notable changes to PatchGate will be documented in this file.

### Beta release — 2026-08-23 (`v0.1.0-beta.4`)
- Released [`v0.1.0-beta.4`](https://github.com/daichunghy/patchgate/releases/tag/v0.1.0-beta.4), pinned to `d8c67a848a95d456707e6c580a43e4e56e6071a0`.
- Updated the consumer Action reference, default Check Run behavior, CLI `--output` alias, and full-SHA workflow pins.
- This remains shadow-evidence only: no production, adoption, external pilot, or stable `v0.1` claim.

The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

Expand Down
13 changes: 6 additions & 7 deletions docs/getting-started.md
Original file line number Diff line number Diff line change
@@ -1,15 +1,14 @@
# Getting started

PatchGate is a public pre-release. The npm package is unpublished
(`private: true`, `0.1.0-dev`). The Action tag `v0.1.0-beta.2` is for
shadow evaluation only — not production, not a `v0.1` claim, and not
evidence of external pilots.
(`private: true`, `0.1.0-dev`). The current Action release is `v0.1.0-beta.4`,
which is for shadow evaluation only — not production, not a `v0.1` claim, and
not evidence of external pilots. Pin commit
`d8c67a848a95d456707e6c580a43e4e56e6071a0`.

This walkthrough uses a clone and a local build. Do not run `npx patchgate`:
that npm name is a different project. This CLI is unpublished. A later
publish, if any, would use a scoped name such as `@daichunghy/patchgate`.
`npx github:daichunghy/patchgate` also fails today: committed `dist/` is
the Action bundle, not `dist/src/cli.js`.
that npm name is a different project. The direct GitHub install is available
for the beta release, while the CLI remains an unpublished npm package.

## 1. Clone and build

Expand Down
13 changes: 7 additions & 6 deletions docs/github-action-usage.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,9 +15,10 @@ after the documented gates have been reviewed.
In **Shadow Mode**, PatchGate observes only (`fail-on: never`). It evaluates
the PR, writes the `ContributionReceipt`, and can post a Check Run without
blocking merge. Pin
[`v0.1.0-beta.2`](https://github.com/daichunghy/patchgate/releases/tag/v0.1.0-beta.2)
for this pre-release; `v0.1.0-beta.1` is superseded because Action inputs were
unreadable on real runners. This is not production and not a `v0.1` claim.
[`v0.1.0-beta.4`](https://github.com/daichunghy/patchgate/releases/tag/v0.1.0-beta.4)
for this pre-release and pin commit
`d8c67a848a95d456707e6c580a43e4e56e6071a0`. This is not production and not a
`v0.1` claim.

The Action reads GitHub metadata through the API. Do **not** check out
pull-request code in this workflow. `github.token` cannot be granted the
Expand Down Expand Up @@ -57,9 +58,9 @@ jobs:
# branch-protection snapshots fail closed (correct). A PAT/App token
# with administration:read is required for a complete native-control
# snapshot. beta.2 posts a Check Run for successful evaluations;
# snapshot-rejection Check Runs landed after that tag (see main).
# snapshot-rejection Check Runs are included in beta.4.
- name: Run PatchGate Shadow Gate
uses: daichunghy/patchgate@v0.1.0-beta.2
uses: daichunghy/patchgate@d8c67a848a95d456707e6c580a43e4e56e6071a0
with:
fail-on: never
create-check-run: true
Expand All @@ -75,7 +76,7 @@ workflow. It is still not production or a `v0.1` claim.

```yaml
- name: Run PatchGate Enforcing Gate
uses: daichunghy/patchgate@v0.1.0-beta.2
uses: daichunghy/patchgate@d8c67a848a95d456707e6c580a43e4e56e6071a0
with:
fail-on: blocked
create-check-run: true
Expand Down
29 changes: 29 additions & 0 deletions docs/releases/2026-08-23-beta.4.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
# PatchGate `v0.1.0-beta.4`

**Release date:** 23 August 2026
**Tag:** [`v0.1.0-beta.4`](https://github.com/daichunghy/patchgate/releases/tag/v0.1.0-beta.4)
**Pinned commit:** `d8c67a848a95d456707e6c580a43e4e56e6071a0`

## Scope

Beta.4 is the current public Action pre-release for non-blocking shadow
evaluation. Pin the full commit SHA in consumer workflows and keep
`fail-on: never` until the external consumer and shadow-installation gates are
closed.

## What changed

- `create-check-run` defaults to `true` and mirrors the Action metadata;
- `evaluate --output` is an alias of `--report`, with conflicting paths rejected;
- the committed Action bundle includes the current CLI parser and neutral
rejection Check Run behavior;
- repository workflow actions use full SHA pins;
- the public release was verified by local `npm run verify`, CI, CodeQL, the
clean-room bundle check, and the maintainer smoke repository.

## Limits

This is not a production release, Marketplace listing, `v0.1` claim, external
adoption evidence, or proof of an external shadow pilot. Native-control
visibility is incomplete with `GITHUB_TOKEN`; a PAT or GitHub App token with
`administration: read` is required for that part of the snapshot.
9 changes: 5 additions & 4 deletions docs/releases/beta-release-and-rollback.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# Beta release and rollback runbook

**Status:** release preparation only; no beta or `v0.1` release is authorized
by this document.
**Status:** runbook for the current public beta; it does not authorize a stable
`v0.1` release or production enforcement.

This runbook closes the documentation path requested in [issue #5](https://github.com/daichunghy/patchgate/issues/5).
It does not override the constitution, branch protection, pilot consent or the
Expand All @@ -20,8 +20,9 @@ Before publishing a beta, the maintainer must have independently recorded:
no-go decision;
- support, security-reporting, compatibility and unsupported-behavior wording.

The current repository has a public pre-release PR and a private development
package, so these prerequisites are not yet all satisfied.
The current repository has public pre-release `v0.1.0-beta.4` and a private
development package. The two external shadow installations and production
gates remain open.

## Release procedure

Expand Down