Toolkit 0.8.6: OCR 1.11.0 and precise security signals - #154
Merged
Conversation
9 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Release-ready implementation for toolkit
0.8.6at exact head2a96f02b58eb54fc3e71ff1e9cec7343f4a20076(tree0d37e445782671e9cbe95e2d6a0ba2ce1599eb17).Added
format and the OCR 1.11.0 status-first format, preserving status, churn, and order.
.hbs) and Mustache (.mustache) review Rules from OCR 1.11.0.Fixed
knowledge injectionanddependency injectionnolonger inflate reviewer-guide security count or effort; closed vulnerability classes
and explicit security metadata remain promoted.
tool_choiceare stripped before result persistence and receipt binding. Laundering through findings
or warnings remains publication-filtered and approval-ineligible.
1.10.0 through 1.10.2 while production preflight remains exact OCR 1.11.0.
Changed
baseline only, never a supported fallback.
low/medium/high envelope.
uv tool install, limitspipto an activated virtualenvironment, and verifies checksum-pinned OCR separately.
Unchanged
ocr.run-manifest/v1, receipt v5, provider-neutralDLP/publication/approval ownership, toolkit telemetry, and GitLab tool/token summaries.
The toolkit leaves the override unset and recommends no provider-specific value.
mediumand max-tools runtime behavior: omitted/0/49/50remains effective
100;101raises the cap to101. OCR 1.11.0 corrects help text,not this runtime loop.
OCR qualification
72c511104f078110ea78bb8f1f2bb1d4048f4d20(v0.8.5)2a96f02b58eb54fc3e71ff1e9cec7343f4a200760d37e445782671e9cbe95e2d6a0ba2ce1599eb171.11.033158664020, issue [OCR compatibility] Qualify v1.11.0 #15513f68cc2eca1a36d42140e9d37797b68fea5cbbf4b6345ec01ec1b06910fab60ac8bf5a0fcd176bb9dcc15b169e90f4b52bf32787adef17a850489dbed97fb78sha256sum.txtSHA-256:9dff050ec859882bef26037415b8bd9e5db70c5a7d960e5eb3989385372311eeThe checksum-verified local OCR passed version/help, preview, grouping, Rules, result,
budget, numeric CLI, and completion-cap probes. The single configured-provider semantic
review ran against exact head
d2249abaa1760a1ac15e7b0ab75414e7af5a37eaatconcurrency 1 and completed all 7 selected files with no failed, reused, or waived
coverage. Its one valid qualification-parser finding was fixed and regression-tested in
the final head above. No semantic OCR rerun was performed.
Validation
1,321tests plus363subtests;86.52%branch coverage; locked risk groups85% / 82% / 86% / 87%.draft, dependency audit, pinned Gitleaks 8.24.3, and diff hygiene pass.
content/privacy checks pass.
above; no other correctness, privacy, release, documentation, or example inconsistency
remains.
Delivery boundary
OCR 1.11.0 was reconciled against BL-010, BL-017, and BL-021; none of their remaining
acceptance criteria is closed by this release. Upstream Action/plugin/launcher/provider
preset changes are not toolkit behavior. B2B, shared templates, and consumer repositories
are outside this PR.