Skip to content

Release v0.6.1 - #92

Merged
xeonvs merged 1 commit into
mainfrom
release/v0.6.1
Aug 15, 2026
Merged

Release v0.6.1#92
xeonvs merged 1 commit into
mainfrom
release/v0.6.1

Conversation

@xeonvs

@xeonvs xeonvs commented Aug 15, 2026

Copy link
Copy Markdown
Owner

Summary

Validation

  • scripts/quality.sh check: 810 tests and 105 subtests, 81.21% branch coverage
  • complete suite on Python 3.12.14, 3.13.15, and 3.14.7
  • focused release authorization, receipt, notes, TestPyPI, distribution, integration, and installed wheel/sdist MCP contracts
  • deterministic stable double build, Twine, closed archive contents, and clean supported-Python installs
  • OCR compatibility manifest, lockfile, workflow/shell syntax, pip-audit, canonical Bandit, Gitleaks, and git diff --check
  • examples and repository material remain synthetic and private-safe
  • stable TestPyPI/PyPI bytes and PEP 740 provenance independently read back
  • GitHub attestations, annotated tag, immutable Release, release assets, and receipt independently read back
  • Actions-owned receipt lifecycle closes every tracked issue

Changed boundaries

This PR is the final repository-side release mutation only. It changes stable/next version markers, deterministic release authorization, generated changelog and release notes, the synthetic example pin, and execution-history archival. It does not change runtime, provider, parser, persistence, MCP, workflow, or trust-boundary implementation.

The complete production-boundary and anti-mock evidence matrix was delivered in feature PR #91. Test doubles do not replace the production owner being claimed; real Git, local HTTP/TLS, hostile persisted readback, stdio MCP, subprocess, installed wheel/sdist, and OCR-consumer paths provide integration evidence.

Security and compatibility impact

  • recommends checksum-verified OCR 1.9.4 and publishes toolkit 0.6.1 with Python 3.12-3.14 support
  • preserves the explicit non-claim that model-dependent matching/contradictory/unknown MR-intent semantics were not qualified by the single final OCR run; transport and queryability are proven without a fake LLM test
  • preserves the 2,000-character bootstrap budget remediation (1,643 characters for the final review store; 1,974 for the dense installed-artifact fixture)
  • contains no credentials, private hosts, paths, provider payloads, or private repository identifiers

External delivery readback

Release workflow 31882059298 published byte-identical wheel and sdist files to TestPyPI, PyPI, and immutable GitHub Release v0.6.1; PEP 740 registry provenance, GitHub build attestations, annotated tag target, release notes/assets, receipt identity, and Python 3.12-3.14 installs were independently verified. The next development line 0.6.2.dev55 also published successfully.

Issue #87 was unexpectedly auto-closed by GitHub when the release PR body text issues #87-#90 was interpreted as a closing reference. It was reopened because that actor/timing violated the intended Actions-only closure gate. The immutable Actions receipt comment is present, but trusted recovery run 31882374375 correctly failed closed because GitHub marks a reopened issue with state_reason=REOPENED, which the pre-publication authorizer does not accept. Issues #88-#90 were closed by github-actions[bot]; #87 remains open rather than being manually or cosmetically closed.

Signed-off-by: xeonvs <11463419+xeonvs@users.noreply.github.com>
@xeonvs
xeonvs merged commit cd842de into main Aug 15, 2026
13 checks passed
@xeonvs
xeonvs deleted the release/v0.6.1 branch August 15, 2026 11:26
@xeonvs
xeonvs deployed to testpypi-public-disclosure August 15, 2026 11:29 — with GitHub Actions Active
@xeonvs
xeonvs deployed to pypi-production August 15, 2026 11:30 — with GitHub Actions Active
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant