Code Mower v1.0.8 closes the remaining trust gaps found while dogfooding the multi-provider release-qualification campaign. It preserves supervised-pilot gate semantics, the Python 3.12+ requirement, and the metadata-only privacy boundary.
Install the pinned package:
export CODE_MOWER_PYTHON="$(command -v python3.12)"
pipx install --python "$CODE_MOWER_PYTHON" code-mower==1.0.8
code-mower --versionHosted agents and CI boxes can use:
uv tool install --python 3.12 code-mower==1.0.8
code-mower --version- Codex and Claude audit verdict transport preserves valid metadata-only P3 findings with line 0 while still requiring actionable source lines for blocking P0/P1/P2 findings (#681, PR #715).
- Campaign retries retain ordered attempt chronology and terminal failure evidence without persisting provider output (#711, PR #716).
- Local adapters prove the requested Python 3.12+ runtime, truthful authentication readiness, and the expected closed result artifact (#710, PR #719).
- Campaign status, watch, upload, and Board find the same campaign after a checkout or worktree changes through a metadata-only user index (#712, PR #720).
- Release qualification can install the exact candidate from a closed TestPyPI source before production publication (#713, PR #723).
- Cursor Cloud Agent is the builder identity, distinct from Cursor BugBot and Grok Bot reviewer identities (#717, PR #722).
- Antigravity campaigns use explicit project identity and isolated execution rather than ambient IDE state (#721, PR #724).
- Hosted Cursor Cloud Agent and Devin profiles require verified dispatch and result transport through five explicit readiness checks (#718, PR #725).
Qualify one provider environment against the exact release:
code-mower release qualify \
--release-tag v1.0.8 \
--package-spec code-mower==1.0.8 \
--output adoption-result.json \
--executeCheck the whole campaign posture and preview before applying:
code-mower doctor --adoption --repo OWNER/REPO
code-mower release campaign \
--release-tag v1.0.8 \
--package-spec code-mower==1.0.8 \
--repo-slug OWNER/REPOFor a TestPyPI candidate, add --package-source testpypi. Applied hosted
providers also require the issue that receives their trusted dispatch and
result comments.
code-mower release campaign dispatch \
--release-tag v1.0.8 \
--apply \
--repo-slug OWNER/REPO \
--issue ISSUE_NUMBER
code-mower release campaign watch --release-tag v1.0.8Preview the closed cloud bundle, then upload it explicitly:
code-mower release campaign upload --release-tag v1.0.8 --json
code-mower release campaign upload --release-tag v1.0.8 --yes --jsonQualification writes the closed code_mower.adoptionResult.v1 artifact.
Campaign upload converts completed results into additive, metadata-only
adoption_run events. It does not upload source, raw diffs, prompts, transcripts,
issue body text, raw provider output, authentication output, local paths, or
secrets.
For an existing pipx install:
export CODE_MOWER_PYTHON="$(command -v python3.12)"
PIP_NO_CACHE_DIR=1 pipx install --force --python "$CODE_MOWER_PYTHON" code-mower==1.0.8
code-mower --version
code-mower board listFor hosted agents using uv:
uv tool install --python 3.12 --reinstall --refresh-package code-mower code-mower==1.0.8
code-mower --versionRestart a Board that still serves an older package. For existing repositories,
review migration setup-drift output in a pull request before applying any
generated changes.
The implementation PRs passed package CI on Python 3.12, 3.13, and 3.14, Gitar, and exact-head peer audits. Four exact-head audit rounds on the hosted transport work found and corrected readiness, remediation, and timeout defects before merge.
Campaign upload remains opt-in and metadata-only. It excludes source, raw diffs, prompts, transcripts, issue body text, raw stdout/stderr, authentication output, local paths, and secrets.