You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Complete the final 1.0 release audit, resolve or explicitly reject every remaining release risk, publish Gitworthy 1.0, and verify the released artifact through the same CLI and MCP workflows users will run.
1.0 is the trust milestone for the local-first decision engine: stable contracts, evidence-honest verdicts, safe hostile-input handling, durable outcomes, reproducible evaluation, bounded agent scouting, and proven installation/upgrade behavior.
Product definition
Gitworthy 1.0 is:
An MIT-licensed local decision engine exposed through CLI and MCP.
A bounded scout/preflight layer for humans and coding agents.
Evidence-backed ACT / VERIFY / SKIP decisions with explicit checked and not-checked coverage.
Durable local runs, decisions, outcomes, capture, recheck, and export.
A stable machine contract suitable for Cursor, ChatGPT, Hermes, Codex, OpenClaw, and other harnesses.
Gitworthy 1.0 is not:
A hosted SaaS.
A coding/implementation agent.
An autonomous issue claimant or PR author.
A telemetry-dependent service.
A guarantee that ACT means safe to code without evidence review and fresh recheck.
Contributor readiness: RELEASE OWNER ONLY until all gates are satisfied. Contributors can help resolve linked blockers, but final audit and publish require maintainer sign-off.
Decision-quality release gates
At least 150 adjudicated frozen cases.
At least 30 adjudicated hard-SKIP cases.
At least 30 investigated/adjudicated ACT cases.
Zero false hard SKIP in the release corpus.
ACT precision >= 90% on adjudicated investigated ACT cases.
Every definitive blocker path, mandatory provider failure, policy path, and supported disposition has frozen coverage.
VERIFY cases name a specific, justified next check rather than generic uncertainty.
Live drift suite reviewed with no unexplained provider/API regression.
Real-usage release gates
Maintainer dogfood history includes repeated MCP-first scout and execute workflows with recorded outcomes.
At least 3 external beta users complete the core workflow; target 5.
At least two MCP hosts/harnesses and two supported operating systems are represented.
Every accepted beta correctness/safety defect has a regression case.
No unresolved P0/P1 issue affecting verdict correctness, data integrity, secret handling, installation, or MCP transport.
Contract release gates
CLI commands, flags, exit codes, JSON schemas, and error semantics are frozen and documented.
MCP tool names, inputs, structured outputs, annotations, and errors are frozen and documented.
Verdict, disposition, finding strength/effect, next-action, partial-status, retryability, config, ranking, brief, store, capture, fixture, and report schemas are stable.
Compatibility/deprecation suite passes for every supported upgrade source.
Human output is clearly excluded from machine parsing guarantees.
README and docs accurately distinguish released behavior from post-1.0 ideas.
Reliability and security release gates
Quality, frozen eval, package smoke, and MCP self-test pass on supported Linux, macOS, and Windows environments.
Version metadata is synchronized across package, CLI, MCP/server metadata, schemas, changelog, and release tag.
Package contents are explicitly reviewed.
npm publish credentials/trusted publishing and provenance are validated.
Release notes summarize breaking changes, migration steps, known limitations, support matrix, and rollback.
Repository release, npm package, and any MCP registry metadata point to the same source/version.
A post-publish smoke test runs against gitworthy@1.0.0, not the local workspace.
Previous release remains available and rollback instructions are verified.
Final audit procedure
Generate the final frozen eval and quality report.
Review every open issue and PR; close, defer with rationale, or mark as 1.0 blocker.
Run full doctor/data doctor from a clean environment.
Build one release artifact and test that exact digest on the supported matrix.
Run migration and rollback proof against representative prior data.
Verify docs, examples, website/domain, support email, security contact, npm metadata, GitHub topics, and release links.
Tag and publish 1.0 through the protected release workflow.
Install gitworthy@1.0.0 fresh and run CLI/MCP smoke plus a known frozen/live-safe check.
Publish the release audit report and known limitations.
Monitor first-user reports and be prepared to yank/deprecate only under the documented emergency process.
Stop conditions
Do not publish 1.0 if any of the following is true:
A false hard SKIP is unresolved.
Mandatory-check failure can still produce ACT.
A supported migration can lose or silently discard data.
MCP stdout can be contaminated by logs or telemetry.
Packed-package behavior differs materially from source-tree tests.
Required schemas or compatibility fixtures are missing.
A P0/P1 security, correctness, data-loss, or install issue remains open.
Release metrics are below the documented gates.
Deliverables
1.0.0 release tag and GitHub release.
Published npm package and verified metadata/provenance.
Final release audit and eval-quality report.
Migration/rollback and support documentation.
Updated roadmap marking 1.0 complete and separating post-1.0 hosted/productization work.
Post-publish smoke evidence and issue-triage plan.
Post-1.0 boundary
Hosted scheduled hunts, shared team history, private-repository coordination, organization policy, notifications, and an agent-dispatch API remain separate post-1.0 productization work. They must not delay the stable local engine unless a foundational contract is missing.
Outcome
Complete the final 1.0 release audit, resolve or explicitly reject every remaining release risk, publish Gitworthy 1.0, and verify the released artifact through the same CLI and MCP workflows users will run.
1.0 is the trust milestone for the local-first decision engine: stable contracts, evidence-honest verdicts, safe hostile-input handling, durable outcomes, reproducible evaluation, bounded agent scouting, and proven installation/upgrade behavior.
Product definition
Gitworthy 1.0 is:
Gitworthy 1.0 is not:
Dependencies and readiness
Decision-quality release gates
SKIPin the release corpus.Real-usage release gates
Contract release gates
Reliability and security release gates
Packaging, migration, and release-operation gates
gitworthy@1.0.0, not the local workspace.Final audit procedure
gitworthy@1.0.0fresh and run CLI/MCP smoke plus a known frozen/live-safe check.Stop conditions
Do not publish 1.0 if any of the following is true:
Deliverables
1.0.0release tag and GitHub release.Post-1.0 boundary
Hosted scheduled hunts, shared team history, private-repository coordination, organization policy, notifications, and an agent-dispatch API remain separate post-1.0 productization work. They must not delay the stable local engine unless a foundational contract is missing.