Skip to content

Prepare v0.9.0 unprotected-target integrity release - #171

Merged
xeonvs merged 15 commits into
mainfrom
codex/v0.9.0-unprotected-target-integrity
Sep 3, 2026
Merged

Prepare v0.9.0 unprotected-target integrity release#171
xeonvs merged 15 commits into
mainfrom
codex/v0.9.0-unprotected-target-integrity

Conversation

@xeonvs

@xeonvs xeonvs commented Sep 2, 2026

Copy link
Copy Markdown
Owner

Goal

Deliver safe limited OCR reviews for explicitly permitted unprotected GitLab targets while preserving immutable identity, comment-only approval boundaries, valid receipt/action attribution, detached-pipeline diagnostics, and adjacent OCR 1.11.2/1.11.3 compatibility.

Tracked work

These issues are assigned to milestone v0.9.0. The stable Release workflow, not this feature PR, owns their final closure.

Delivery plan

  1. Keep the first remote commit plan-only.
  2. Maintain [Bug]: Pre-execution status posting ignores the CI_COMMIT_SHA fallback #167, [Bug]: Receipt v6 can reject a toolkit-finalized review when evidence action counts diverge #169, [Feature]: Add an explicit limited mode for unprotected GitLab target branches #168 runtime, [Feature]: Add an explicit limited mode for unprotected GitLab target branches #168 documentation, [OCR compatibility] Qualify v1.11.2 #170, and [OCR compatibility] Qualify v1.11.3 #172 as separately reviewed signed logical slices.
  3. Self-review before every commit, then review every commit and the complete range.
  4. Run all deterministic quality, compatibility, Towncrier, security, package, archive, and privacy gates.
  5. Retain the completed single Codex Security diff scan and its reviewed remediation; do not rerun it.
  6. Retain both semantic OCR diagnostics unchanged. No additional semantic OCR is authorized. OCR 1.11.3 is qualified through deterministic/no-provider probes and hostile regressions only.
  7. Push the complete implementation only after local closure, finish hosted review/checks, and exact-head squash merge.
  8. Verify the TestPyPI development build, then complete the protected release/v0.9.0 publication and independent registry/provenance/Release/issue closure lifecycle.

Implemented result

  • Exact reviewed identity and constrained unprotected-target decisions are shared across review, posting, and later-action gates.
  • Private action receipt v3 separately reconciles attempted and completed built-in evidence actions.
  • Receipt v8 binds immutable review/protection identity and a closed failed-tool diagnostic state.
  • Valid findings and summaries survive absent, malformed, hostile, non-zero, or contradictory additive OCR diagnostics; bounded credential-redacted details go only to local/CI stderr.
  • Toolkit-owned OCR preview and review children cannot inherit OCR_RAW_LOGGING.
  • docs/review-decision-flow.md is the canonical detailed Mermaid decision map and is linked from root agent instructions and strategy guidance.
  • OCR 1.11.3 is the final checksum-pinned and preflight-accepted runtime for toolkit 0.9.0.

Local closure

Exact head 3441e8a77d71b026db89a896d6374f6cb0a09b99 passed the complete deterministic quality matrix (1,486 tests and 408 subtests, 86.38% coverage and all scoped floors), compatibility validation, Towncrier draft, frozen Ruff formatting, Gitleaks, dependency audit, signature verification, diff checks, deterministic double build/Twine, archive privacy, and separate clean wheel/sdist CLI smokes. No additional OCR or Codex Security run occurred.

@xeonvs
xeonvs marked this pull request as ready for review September 3, 2026 08:14
@xeonvs
xeonvs merged commit 3c7e38c into main Sep 3, 2026
13 checks passed
@xeonvs
xeonvs deleted the codex/v0.9.0-unprotected-target-integrity branch September 3, 2026 08:14
@xeonvs xeonvs mentioned this pull request Sep 3, 2026
xeonvs added a commit that referenced this pull request Sep 3, 2026
## Release scope

Prepare stable toolkit 0.9.0 for the exact authorized issue set:

- #167 — one strict reviewed-source identity across review, diagnostics,
posting, and later actions
- #168 — explicit limited comment-only reviews for unprotected GitLab
targets, receipt v8, documentation, and synthetic examples
- #169 — action receipt v3 attempted/completed reconciliation without
losing valid review publication
- #170 — OCR 1.11.2 adjacent qualification and JavaScript/C++ Rules
routing
- #172 — OCR 1.11.3 promotion, raw-capture containment, additive
failed-tool diagnostics, and canonical Mermaid decision maps

The stable Release workflow owns issue and milestone closure; this PR
deliberately uses no closing keywords.

## Reviewed implementation evidence

- Feature PR #171 reviewed head:
`3441e8a77d71b026db89a896d6374f6cb0a09b99`
- Feature squash merge: `3c7e38c08a48c9af1d0b0c5e10ecf0ac8b5eacc3`
- Development publication: [run
33732297187](https://github.com/xeonvs/open-code-review-toolkit/actions/runs/33732297187),
version `0.8.8.dev83`
- Development wheel SHA-256:
`706dfce3991a00b9e93aa65f19bb30baa6b323eab57d8c449d170310a63bbfaf`
- Development sdist SHA-256:
`b22e1fa5eacade47a130e21474442034aee28c93b5f6880a652981efb353de99`
- Codex Security scan `cecd81ce-bc01-42eb-bedf-a4a2a44a096c`: zero
reportable findings; not rerun
- OCR 1.11.3 qualification: [run
33725971286](https://github.com/xeonvs/open-code-review-toolkit/actions/runs/33725971286),
evidence SHA-256
`6ad0e1f607b2ddcbb9e7b25e4432d6102ec22d7ef6847c2858c8fb22d38cc0f2`

## Repository release mutations

- set stable/next versions to `0.9.0` / `0.9.1`
- bind deterministic source epoch `1788423271` and exact sorted
authorization issues `[167,168,169,170,172]`
- render the complete Towncrier section and remove consumed fragments
- pin the published GitLab example and configuration reference to
toolkit `0.9.0`
- archive the repository-complete plan with external stable delivery
pending and return `PLANS.md` to its inactive template

## Validation

- complete quality gate: 1,487 tests plus 408 subtests, 86.38% coverage,
all scoped floors passed
- focused release/documentation contracts: 71 passed
- OCR compatibility manifest validation, frozen Ruff format, dependency
audit, pinned Gitleaks, and diff checks passed
- two source-epoch-controlled builds are byte-identical and pass Twine
- stable build hashes: wheel
`fda7a7c5a09e836f20692ff20f1449ee8114749da0be248ff24680367e0d9f60`;
sdist `720825c10dcdc38e403b66c18ab17dd9b2fd8a36919a96973634b5ed08fd391c`
- archive privacy and clean wheel/sdist installs with `ocr-ci --help`
passed on Python 3.12, 3.13, and 3.14

## External handoff

Stable TestPyPI/PyPI publication, registry and Release byte equality,
PEP 740 provenance, GitHub attestations, annotated tag, immutable
five-asset GitHub Release, release receipt validation, supported-Python
readback installs, issue receipts/closure, milestone closure, and branch
cleanup remain pending until this exact reviewed release head is
squash-merged.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant