Skip to content

Toolkit 0.8.6: OCR 1.11.0 and precise security signals - #154

Merged
xeonvs merged 9 commits into
mainfrom
codex/v0.8.6-ocr-1.11.0-security-signal
Aug 28, 2026
Merged

Toolkit 0.8.6: OCR 1.11.0 and precise security signals#154
xeonvs merged 9 commits into
mainfrom
codex/v0.8.6-ocr-1.11.0-security-signal

Conversation

@xeonvs

@xeonvs xeonvs commented Aug 28, 2026

Copy link
Copy Markdown
Owner

Summary

Release-ready implementation for toolkit 0.8.6 at exact head
2a96f02b58eb54fc3e71ff1e9cec7343f4a20076 (tree
0d37e445782671e9cbe95e2d6a0ba2ce1599eb17).

Added

  • Strict qualification-only grouping inventory checks for the historical OCR 1.10.x
    format and the OCR 1.11.0 status-first format, preserving status, churn, and order.
  • Handlebars (.hbs) and Mustache (.mustache) review Rules from OCR 1.11.0.
  • Provider-private reasoning and request-state containment regressions.

Fixed

  • [Bug]: Avoid false security promotion for neutral domain phrases #153: neutral phrases such as knowledge injection and dependency injection no
    longer inflate reviewer-guide security count or effort; closed vulnerability classes
    and explicit security metadata remain promoted.
  • Provider-private reasoning, encrypted/native replay payloads, and request tool_choice
    are stripped before result persistence and receipt binding. Laundering through findings
    or warnings remains publication-filtered and approval-ineligible.
  • Repeatable qualification now accepts the historical grouping wire shape for OCR
    1.10.0 through 1.10.2 while production preflight remains exact OCR 1.11.0.

Changed

  • OCR 1.11.0 is the sole accepted runtime. OCR 1.10.2 is an adjacent comparison
    baseline only, never a supported fallback.
  • The GitLab review job timeout is 45 minutes for OCR's 15/30/45-minute
    low/medium/high envelope.
  • Installation recommends uv tool install, limits pip to an activated virtual
    environment, and verifies checksum-pinned OCR separately.

Unchanged

  • OCR result and ocr.run-manifest/v1, receipt v5, provider-neutral
    DLP/publication/approval ownership, toolkit telemetry, and GitLab tool/token summaries.
  • The inherited OCR completion cap and support for an operator-selected positive override.
    The toolkit leaves the override unset and recommends no provider-specific value.
  • Default effort medium and max-tools runtime behavior: omitted/0/49/50
    remains effective 100; 101 raises the cap to 101. OCR 1.11.0 corrects help text,
    not this runtime loop.

OCR qualification

  • Toolkit base: 72c511104f078110ea78bb8f1f2bb1d4048f4d20 (v0.8.5)
  • Final feature head: 2a96f02b58eb54fc3e71ff1e9cec7343f4a20076
  • Final feature tree: 0d37e445782671e9cbe95e2d6a0ba2ce1599eb17
  • OCR target: 1.11.0
  • Hosted compatibility evidence: run 33158664020, issue [OCR compatibility] Qualify v1.11.0 #155
  • Linux amd64 SHA-256: 13f68cc2eca1a36d42140e9d37797b68fea5cbbf4b6345ec01ec1b06910fab60
  • Darwin arm64 SHA-256: ac8bf5a0fcd176bb9dcc15b169e90f4b52bf32787adef17a850489dbed97fb78
  • sha256sum.txt SHA-256: 9dff050ec859882bef26037415b8bd9e5db70c5a7d960e5eb3989385372311ee

The checksum-verified local OCR passed version/help, preview, grouping, Rules, result,
budget, numeric CLI, and completion-cap probes. The single configured-provider semantic
review ran against exact head d2249abaa1760a1ac15e7b0ab75414e7af5a37ea at
concurrency 1 and completed all 7 selected files with no failed, reused, or waived
coverage. Its one valid qualification-parser finding was fixed and regression-tested in
the final head above. No semantic OCR rerun was performed.

Validation

  • 1,321 tests plus 363 subtests; 86.52% branch coverage; locked risk groups
    85% / 82% / 86% / 87%.
  • Ruff format/lint, strict MyPy, Bandit, OCR manifest validation, lock check, Towncrier
    draft, dependency audit, pinned Gitleaks 8.24.3, and diff hygiene pass.
  • Two deterministic wheel/sdist builds are byte-identical; Twine and archive
    content/privacy checks pass.
  • Clean wheel and sdist installs plus CLI smoke pass on Python 3.12, 3.13, and 3.14.
  • Holistic self-review found and fixed the compatibility-documentation drift described
    above; no other correctness, privacy, release, documentation, or example inconsistency
    remains.

Delivery boundary

OCR 1.11.0 was reconciled against BL-010, BL-017, and BL-021; none of their remaining
acceptance criteria is closed by this release. Upstream Action/plugin/launcher/provider
preset changes are not toolkit behavior. B2B, shared templates, and consumer repositories
are outside this PR.

@xeonvs xeonvs added this to the v0.8.6 milestone Aug 28, 2026
@xeonvs xeonvs mentioned this pull request Aug 28, 2026
9 tasks
@xeonvs
xeonvs marked this pull request as ready for review August 28, 2026 10:37
@xeonvs
xeonvs merged commit 58170e9 into main Aug 28, 2026
13 checks passed
@xeonvs
xeonvs deleted the codex/v0.8.6-ocr-1.11.0-security-signal branch August 28, 2026 10:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant