- GitHub issues are the source of truth for scope, acceptance criteria, milestone membership, and status.
ROADMAP.mdis this repository's single ordered project backlog and cold-session resume contract.- The numbered order below is the project priority. The first open item is next unless the maintainer explicitly reorders the queue.
- A GitHub milestone is a planned release; its open issues are the work required before that release can close.
- An optional generated
GOALS.mdmay scope execution inside a consumer repo, but it never overrides this project's priority queue. - Remove completed issues from the queue, add every new actionable issue once, and keep every open issue assigned to a milestone.
- Pull requests reference their owning issue. Failing proof, review, or required CI never merges.
- The active engineering slice is #175 in
/Users/stefanayala/codex-sdlc-issue175onfix/issue-175-final-fable-response, based on currentorigin/mainatb7c8d4590a483afa0be61f1bb9ed4408d3b520cd. - Tell tool-free Fable to return one immediate final schema-valid JSON review from the complete supplied evidence; the runtime guarantee remains strict rejection and a non-certifying receipt for deferral, narration, or any other invalid output.
- #157 is integrated through PR #166, #158 through PR #165, #167 through PR #170, and #172 through PR #173. #158's one-time meta-review owner exception is consumed; do not reuse or broaden it. Required pre/post-merge Windows CI passed for the integrated slices.
- #174 is frozen at candidate tree
2636c7da25fcd9a19735112f938e050981012a6c. Canonical proof passed 11/11, but Fable returned only repository-inspection deferral prose; the strict gate wrote a non-certifyinginvalid_executionreceipt, cancelled incomplete Sol, and recommends no retry. - #86 is frozen at final candidate tree
7cfa28ec0add78c706cd24f28b15a9e9e99d023b. Canonical proof passed 11/11, but normal Sol High plus Fable High review converged on the #174 P1, so its receipt is non-certifying and the candidate must not be delivered or retried. - Do not edit, stage, clean, or merge the dirty root checkout. It contains unrelated historical work.
- After #175 integrates, resume #174 from a fresh current-main worktree and fresh proof/review candidate. Then resume #86, followed by a fresh authorized plan for frozen #109 v4; do not reuse consumed gate attempts or obsolete plans.
- Continue through the complete
1.0.0block below. Do not start post-1.0 work while an earlier release blocker remains open.
- Latest published GitHub release:
v0.7.37. - Latest published npm release:
codex-sdlc-wizard@0.7.37. - Development package metadata:
0.7.38; it is not a published release. - Next major release:
1.0.0 — Bounded autonomous delivery. - The synchronized 1.0 milestone contains ten open release issues and fifteen completed issues as of 2026-08-23.
- The release objective is bounded autonomous delivery: exact-candidate proof, terminating independent review, honest failures, one canonical workflow entry, trustworthy Windows behavior, real Windows acceptance, and immutable publish verification.
- Real Windows Codex Desktop and CLI acceptance remains the final hardware-dependent gate before publish verification.
1.0.0is the next public release. Do not divert the release train into another 0.7.x feature batch.
- Reduce tool-free Fable deferral and fail closed — #175: instruct immediate review JSON and reject every invalid response (
1.0.0, P0, active). - Keep model-policy migration claims truthful — #174: leave migration pending while preserved guidance still authorizes autonomous xhigh (
1.0.0, P0, frozen until #175 lands). - Enforce High-only autonomous Sol work — #86: remove autonomous xhigh escalation and the former maintainer exception (
1.0.0, P0, frozen until #174 lands). - Complete the measured bounded-correction pilot — #109: incremental corrective commits with a final whole-PR gate (
1.0.0, P0, frozen until #174 and #86 land). - Block executable Git configuration at delivery — #141: reject exec-capable Git config in exact-candidate commands (
1.0.0). - Restore one canonical workflow entry — #127: remove duplicate global and repo-local
$sdlcexposure (1.0.0). - Eliminate nondeterministic Windows proof cleanup — #92: fix access-denied proof-stamp teardown (
1.0.0). - Keep Windows review evidence honest — #93: detect WindowsApps PowerShell before trusting review validation (
1.0.0). - Run the final real-Windows acceptance gate — #79: validate the exact 1.0 candidate in Codex Desktop and CLI, including observed config/picker precedence (
1.0.0, human-required). - Publish and verify the major release — #88: publish and verify
codex-sdlc-wizard1.0.0 across GitHub, npm, plugin, Codex Desktop, and Codex CLI surfaces (1.0.0, human-required where credentials require it). - Audit host-managed memory before premium rollout — #129: compare host memory with checked-in repository truth (
1.1.0). - Implement the premium Codex host lane — #128: Fable High plans/reviews and Sol High builds with one reconciliation (
1.1.0). - Make Fable review output evidence-first — #123: tighten cross-model review output (
1.1.0). - Preserve known-good behavior during upgrades — #84: adopt a stability contract for model and harness changes (
1.1.0). - Classify self-targeting maintenance as SDLC work — #130: treat mutating setup, update, and repair commands honestly (
1.1.0). - Validate PowerShell policy before mutation — #153: reject invalid reviewer policy before updater writes (
1.1.0). - Align skill metadata with evidence lanes — #154: make headings and descriptions honest (
1.1.0). - Add one read-only health entrypoint — #82: implement a Codex-native doctor flow with explicit repair (
1.1.0). - Audit generated instruction ownership — #95: reconcile
AGENTS.mdwith current Codex guidance (1.1.0). - Make sibling harnesses coexist safely — #106: define shared-root ownership with
claude-sdlc-harness(1.1.0). - Teach the issue-to-PR-to-release lifecycle — #100: enforce bounded issue, pull-request, milestone, and merge state (
1.1.0). - Support ordered multi-milestone goals — #151: continue across ordered milestones and hand off cleanup safely (
1.1.0). - Make terminal lifecycle state declarative — #136: reconcile exact status after merge (
1.1.0). - Add an opt-in progress dashboard — #135: show issue and milestone progress without claiming readiness (
1.1.0). - Preserve privacy in feedback attribution — #126: make source-repository attribution opt-in (
1.1.0). - Soak the released contract in real consumer repos — #112: collect daily post-1.0 feedback and make only proven fixes (
1.1.0). - Measure adversarial refutation against bounded review — #138: compare cross-vendor review strategies (
1.1.0, research). - Research convergence-based termination — #132: compare convergence with fixed correction caps (
1.1.0, research). - Retain concise failed-proof evidence — #124: preserve failed-test summaries when broad proof output truncates (
1.1.0). - Separate confidence from defect severity — #131: require actionable reviewer remediation without conflating confidence (
1.1.0). - Make explicit updates one-step and agent-driven — #147: honor requests to update to the latest wizard (
1.1.0). - Make after-hours Windows pushes guard-compatible — #162: provide an explicit safe push override path (
1.1.0). - Emit bounded provider progress during reviews — #164: expose long-running dual-review progress (
1.1.0). - Harden standalone Fable supervision — #171: bound standalone Fable process trees and bind review-run identity (
1.1.0). - Track third-party release provenance — #168: add third-party asset provenance to release preflight (
1.1.0). - Research a fast incremental model lane — #114: evaluate GPT-5.3-Codex-Spark (
1.2.0). - Benchmark optional worker orchestration — #72: compare direct Sol driving with bounded Luna workers (
1.2.0). - Research context-pressure policy — #77: measure compaction thresholds and worker effects (
1.2.0). - Submit the proven release to the Plugins Directory — #66: complete universal directory submission (
Distribution, human-required). - Research recurring post-1.0 distribution — #140: evaluate agent marketplaces and directories (
Distribution, research). - Audit CI/CD for independent value — #108: retain only release-enforcing evidence (
1.3.0). - Prove fast-first without weakening full-final — #139: evaluate a bounded CI tier (
1.3.0, research). - Detect release drift deterministically — #99: reconcile package, tag, release, and issue state (
1.3.0). - Timebox the cumulative upstream audit — #65: evaluate upstream v1.74.0 through v1.91.0 (
1.3.0). - Reconcile upstream v1.96.0 — #113: evaluate the newer SDLC Wizard release (
1.3.0). - Reconcile upstream v1.98.0 — #160: translate applicable upstream changes (
1.3.0). - Keep release documentation impact-based — #105: add stabilized demos only when they materially help (
1.4.0). - Consolidate redundant proof documentation — #104: fold
PROVE-IT.mdintoTESTING.mdby default (1.4.0). - Rename wizard to harness with a controlled migration — #101: apply the sibling-repo migration checklist safely (
1.4.0). - Clean contributor attribution only through an explicit history operation — #107: remove bot attribution without risking repository history (
1.4.0, human-required). - Research persistent Codex output style — #144: identify and measure the nearest supported mechanism (
Research, non-blocking). - Research DeepSeek Harness after 1.0 — #142: evaluate portable plugin ideas (
Research, non-blocking). - Track the in-app Browser range-slider defect — #134: require observable native slider interaction (
Research, external-tooling, non-blocking). - Map the SDLC experience across Copilot tiers — #125: compare every Copilot host (
Research, non-blocking). - Identify the Microsoft-enterprise coding host — #122: prove the supported enterprise surface (
Research, human-required, non-blocking). - Evaluate another CLI host — #97: research a GitHub Copilot CLI adapter (
Research, non-blocking). - Revisit portable enforcement after host adapters stabilize — #58: compare a portable SDLC MCP server with per-host skills (
Research, non-blocking). - Decide the Copilot Studio adoption path — #96: research a front end only after portable enforcement is justified (
Research, human-required, non-blocking). - Keep Copilot Studio implementation contingent — #163: build and E2E-test the agent only after #96 selects adoption or experiment (
Research, contingent, non-blocking). - Release the post-1.0 Copilot adapter — #169: build and release the GitHub Copilot SDLC harness after 1.0 (
Research, post-1.0, non-blocking).