Prepare v0.6.1 provider evidence - #91
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Prepare Open Code Review Toolkit v0.6.1 by separating protected-target policy from the forge diff base, retaining changed template evidence within bounded collection, and exposing bounded untrusted merge-request intent through the existing evidence MCP boundary.
Implementation, the one permitted local OCR review, post-OCR remediation, and local validation are complete. The branch is published only at this finalized checkpoint to avoid repeated GitHub Actions consumption.
Tracks #87, #88, #89, #90.
Implementation
ocr-ci --versionfrom centralized package metadata.OCR 1.9.4 qualification
sha256sum.txt, Linux amd64 CLI/preview/JSON consumer contracts, and classified the release for human review.TraceSummaryis an internal no-output-change refactor; Go MCP SDK remains v1.6.1.66a591c291947fd7036628f69698c3d240b497e8aa13c5837caae271f014414fwas verified, installed, and passed the real local contract probe.Trust-boundary review
--ruletransport preserves exact bytes and explicit external operator-owned paths remain untouched.Validation
summary; the dispatcher now accepts declared inactive fields, rejects unknown fields, and real installed wheel/sdist stdio tests prove summary/list/get plus raw synthetic MR-context retrieval.aafe57f.Release closure
Release v0.6.1PR is reviewed and merged.mainis synchronized cleanly.