Prepare v0.9.0 unprotected-target integrity release - #171
Merged
Conversation
xeonvs
marked this pull request as ready for review
September 3, 2026 08:14
Merged
xeonvs
added a commit
that referenced
this pull request
Sep 3, 2026
## Release scope Prepare stable toolkit 0.9.0 for the exact authorized issue set: - #167 — one strict reviewed-source identity across review, diagnostics, posting, and later actions - #168 — explicit limited comment-only reviews for unprotected GitLab targets, receipt v8, documentation, and synthetic examples - #169 — action receipt v3 attempted/completed reconciliation without losing valid review publication - #170 — OCR 1.11.2 adjacent qualification and JavaScript/C++ Rules routing - #172 — OCR 1.11.3 promotion, raw-capture containment, additive failed-tool diagnostics, and canonical Mermaid decision maps The stable Release workflow owns issue and milestone closure; this PR deliberately uses no closing keywords. ## Reviewed implementation evidence - Feature PR #171 reviewed head: `3441e8a77d71b026db89a896d6374f6cb0a09b99` - Feature squash merge: `3c7e38c08a48c9af1d0b0c5e10ecf0ac8b5eacc3` - Development publication: [run 33732297187](https://github.com/xeonvs/open-code-review-toolkit/actions/runs/33732297187), version `0.8.8.dev83` - Development wheel SHA-256: `706dfce3991a00b9e93aa65f19bb30baa6b323eab57d8c449d170310a63bbfaf` - Development sdist SHA-256: `b22e1fa5eacade47a130e21474442034aee28c93b5f6880a652981efb353de99` - Codex Security scan `cecd81ce-bc01-42eb-bedf-a4a2a44a096c`: zero reportable findings; not rerun - OCR 1.11.3 qualification: [run 33725971286](https://github.com/xeonvs/open-code-review-toolkit/actions/runs/33725971286), evidence SHA-256 `6ad0e1f607b2ddcbb9e7b25e4432d6102ec22d7ef6847c2858c8fb22d38cc0f2` ## Repository release mutations - set stable/next versions to `0.9.0` / `0.9.1` - bind deterministic source epoch `1788423271` and exact sorted authorization issues `[167,168,169,170,172]` - render the complete Towncrier section and remove consumed fragments - pin the published GitLab example and configuration reference to toolkit `0.9.0` - archive the repository-complete plan with external stable delivery pending and return `PLANS.md` to its inactive template ## Validation - complete quality gate: 1,487 tests plus 408 subtests, 86.38% coverage, all scoped floors passed - focused release/documentation contracts: 71 passed - OCR compatibility manifest validation, frozen Ruff format, dependency audit, pinned Gitleaks, and diff checks passed - two source-epoch-controlled builds are byte-identical and pass Twine - stable build hashes: wheel `fda7a7c5a09e836f20692ff20f1449ee8114749da0be248ff24680367e0d9f60`; sdist `720825c10dcdc38e403b66c18ab17dd9b2fd8a36919a96973634b5ed08fd391c` - archive privacy and clean wheel/sdist installs with `ocr-ci --help` passed on Python 3.12, 3.13, and 3.14 ## External handoff Stable TestPyPI/PyPI publication, registry and Release byte equality, PEP 740 provenance, GitHub attestations, annotated tag, immutable five-asset GitHub Release, release receipt validation, supported-Python readback installs, issue receipts/closure, milestone closure, and branch cleanup remain pending until this exact reviewed release head is squash-merged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Goal
Deliver safe limited OCR reviews for explicitly permitted unprotected GitLab targets while preserving immutable identity, comment-only approval boundaries, valid receipt/action attribution, detached-pipeline diagnostics, and adjacent OCR 1.11.2/1.11.3 compatibility.
Tracked work
These issues are assigned to milestone
v0.9.0. The stable Release workflow, not this feature PR, owns their final closure.Delivery plan
release/v0.9.0publication and independent registry/provenance/Release/issue closure lifecycle.Implemented result
OCR_RAW_LOGGING.docs/review-decision-flow.mdis the canonical detailed Mermaid decision map and is linked from root agent instructions and strategy guidance.Local closure
Exact head
3441e8a77d71b026db89a896d6374f6cb0a09b99passed the complete deterministic quality matrix (1,486 tests and 408 subtests, 86.38% coverage and all scoped floors), compatibility validation, Towncrier draft, frozen Ruff formatting, Gitleaks, dependency audit, signature verification, diff checks, deterministic double build/Twine, archive privacy, and separate clean wheel/sdist CLI smokes. No additional OCR or Codex Security run occurred.