Skip to content

Commit ec54f0c

Browse files
authored
integration: assemble OpenUsage Bar 0.6 RC candidate (#48)
Merge the verified standalone 0.6 RC integration candidate into main. Release and external Canary gates remain separately controlled.
2 parents 9cd134a + 3e1f19d commit ec54f0c

188 files changed

Lines changed: 20121 additions & 872 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

.github/ISSUE_TEMPLATE/canary_report.yml

Lines changed: 45 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@ body:
66
attributes:
77
value: |
88
Never include API keys, cookies, account names, prompts, responses, raw Provider payloads, device serial numbers, or unredacted logs. Security issues belong in a private vulnerability report.
9+
Follow the [canary protocol](https://github.com/tttboy123/openusage-bar/blob/main/docs/canary.md) and the [Local API v1 compatibility policy](https://github.com/tttboy123/openusage-bar/blob/main/docs/api/compatibility-v1.md).
910
- type: input
1011
id: canary-label
1112
attributes:
@@ -18,7 +19,15 @@ body:
1819
id: version
1920
attributes:
2021
label: Product version and build
21-
placeholder: 0.4.2 (6)
22+
placeholder: 0.6.0 (9)
23+
validations:
24+
required: true
25+
- type: input
26+
id: previous-version
27+
attributes:
28+
label: Previous version and build
29+
description: Record the published N-1 build used for the upgrade test.
30+
placeholder: 0.4.4 (8)
2231
validations:
2332
required: true
2433
- type: input
@@ -56,24 +65,40 @@ body:
5665
placeholder: 2026-07-18 through 2026-08-16
5766
validations:
5867
required: true
68+
- type: textarea
69+
id: event-dates
70+
attributes:
71+
label: UTC event dates
72+
description: Record only UTC dates and pass/fail results. Do not include hostnames, usernames, account names, or absolute home paths.
73+
placeholder: |
74+
Install: YYYY-MM-DD — Pass
75+
Scheduled collection after restart: YYYY-MM-DD — Pass
76+
N-1 upgrade: YYYY-MM-DD — Pass
77+
Rollback and reinstall: YYYY-MM-DD — Pass
78+
validations:
79+
required: true
5980
- type: checkboxes
6081
id: checks
6182
attributes:
6283
label: Completed checks
6384
options:
64-
- label: Checksum, manifest, SBOM, and attestation verified
85+
- label: Packaged candidate verifier passed checksum, manifest, SBOM, and all six attestations
6586
required: true
6687
- label: Clean install and first trustworthy fact completed
6788
required: true
68-
- label: Scheduled refresh and collector restart completed
89+
- label: Collector scheduled refresh completed
90+
required: true
91+
- label: Scheduled collection advanced after restart without Refresh
6992
required: true
70-
- label: Mac restart completed
93+
- label: Menu-bar item was visibly present and opened its popover
7194
required: true
7295
- label: N-1 upgrade completed without data decrease
7396
required: true
7497
- label: Rollback drill and candidate reinstall completed
7598
required: true
76-
- label: No credentials, identity, prompts, responses, or raw payloads are included
99+
- label: UI, CLI JSON, and Local API agreed at one dataRevision
100+
required: true
101+
- label: Balance state and freshness were checked, or this setup exposes no Balance capability
77102
required: true
78103
- type: dropdown
79104
id: blocking-incident
@@ -85,14 +110,25 @@ body:
85110
validations:
86111
required: true
87112
- type: dropdown
88-
id: diagnostics
113+
id: diagnostic-scan
89114
attributes:
90-
label: Redacted diagnostics attached
115+
label: Privacy scan result for attached diagnostics
91116
options:
92-
- No
93-
- Yes - reviewed locally before attachment
117+
- No diagnostics attached
118+
- Passed locally before attachment
94119
validations:
95120
required: true
121+
- type: checkboxes
122+
id: safety
123+
attributes:
124+
label: Safety review
125+
options:
126+
- label: I included no credentials, cookies, account identity, prompts, responses, raw Provider payloads, unredacted logs, or absolute home paths.
127+
required: true
128+
- label: My random canary label does not identify a person, device, host, or Provider account.
129+
required: true
130+
- label: I will report any suspected private-data disclosure through a private vulnerability report instead of this public issue.
131+
required: true
96132
- type: textarea
97133
id: notes
98134
attributes:
Lines changed: 104 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,104 @@
1+
name: Provider support request / Provider 接入请求
2+
description: Propose a trustworthy Provider data source or volunteer to implement one.
3+
title: "[Provider]: "
4+
labels: [enhancement, help wanted]
5+
body:
6+
- type: markdown
7+
attributes:
8+
value: |
9+
OpenUsage Bar prefers an existing OpenUsage integration, then an official read-only API, then a documented custom feed. It does not accept credentials, raw Provider payloads, prompts, responses, direct account identity, or fragile browser scraping without a separate security review.
10+
11+
OpenUsage Bar 优先复用 OpenUsage,其次使用官方只读 API,再使用有文档的自定义 Feed。请勿提交密钥、Cookie、原始厂商响应、Prompt、Response 或直接账号身份。
12+
13+
Contributors should start with the Provider Adapter Kit in `docs/provider-adapter-kit.md` and submit synthetic fixtures only. / 贡献者请从 `docs/provider-adapter-kit.md` 的 Provider Adapter Kit 开始,只提交合成 Fixture。
14+
- type: input
15+
id: provider
16+
attributes:
17+
label: Provider or client / 厂商或客户端
18+
placeholder: GLM, Kimi, Qwen, Claude Code, OpenCode...
19+
validations:
20+
required: true
21+
- type: dropdown
22+
id: region
23+
attributes:
24+
label: Region / 区域
25+
options:
26+
- China / 中国站
27+
- International / 国际站
28+
- Both with separate endpoints / 国内与国际站点分离
29+
- Local client only / 仅本地客户端
30+
- Unknown / 尚不确定
31+
validations:
32+
required: true
33+
- type: dropdown
34+
id: primary-fact
35+
attributes:
36+
label: Primary fact requested / 主要数据类型
37+
options:
38+
- Daily token activity / 每日 Token 活动
39+
- Subscription capacity and reset / 订阅余量与重置
40+
- API spend or billed cost / API 消耗或账单费用
41+
- Local client detection only / 仅本地客户端发现
42+
- Multiple fact families / 多种数据类型
43+
validations:
44+
required: true
45+
- type: dropdown
46+
id: source-type
47+
attributes:
48+
label: Best known source / 已知最佳来源
49+
options:
50+
- Existing OpenUsage output / 现有 OpenUsage 输出
51+
- Official read-only API / 官方只读 API
52+
- Official local logs or CLI / 官方本地日志或 CLI
53+
- Documented custom feed / 有文档的自定义 Feed
54+
- No trustworthy source found / 尚未找到可信来源
55+
validations:
56+
required: true
57+
- type: input
58+
id: source-url
59+
attributes:
60+
label: Public documentation or repository / 公开文档或仓库
61+
description: Link only to public documentation or source code. Do not paste a private endpoint containing credentials.
62+
placeholder: https://...
63+
- type: textarea
64+
id: semantics
65+
attributes:
66+
label: Data semantics / 数据语义
67+
description: Describe scope, units, windows, reset behavior, pagination, regions, and known delay. State what Unknown and zero mean.
68+
placeholder: |
69+
Scope:
70+
Units:
71+
Window and reset:
72+
Pagination:
73+
Reporting delay:
74+
Unknown versus covered zero:
75+
validations:
76+
required: true
77+
- type: textarea
78+
id: authentication
79+
attributes:
80+
label: Authentication and privacy / 认证与隐私
81+
description: Name only the credential type and minimum read-only scope. Never paste the credential itself.
82+
placeholder: API key with usage:read; local Keychain item owned by the upstream client; no credential required...
83+
validations:
84+
required: true
85+
- type: dropdown
86+
id: contribution
87+
attributes:
88+
label: Contribution intent / 参与意愿
89+
options:
90+
- I can implement and test it / 我可以实现并测试
91+
- I can provide redacted fixtures / 我可以提供脱敏 Fixture
92+
- I can perform live validation / 我可以进行真实账号验证
93+
- Request only / 仅提出需求
94+
validations:
95+
required: true
96+
- type: checkboxes
97+
id: safety
98+
attributes:
99+
label: Safety confirmation / 安全确认
100+
options:
101+
- label: I included no credentials, cookies, account identity, prompts, responses, or raw private payloads. / 我没有提交任何凭证、Cookie、账号身份、Prompt、Response 或原始私有响应。
102+
required: true
103+
- label: I understand that unsupported facts must remain Unknown rather than zero. / 我理解不支持或缺失的数据必须保持 Unknown,不能显示为零。
104+
required: true

.github/action-pins.json

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
{
2+
"schemaVersion": 1,
3+
"pins": [
4+
{
5+
"repository": "actions/attest",
6+
"version": "v4.2.0",
7+
"commit": "f7c74d28b9d84cb8768d0b8ca14a4bac6ef463e6"
8+
},
9+
{
10+
"repository": "actions/checkout",
11+
"version": "v7.0.1",
12+
"commit": "3d3c42e5aac5ba805825da76410c181273ba90b1"
13+
},
14+
{
15+
"repository": "actions/setup-python",
16+
"version": "v7.0.0",
17+
"commit": "5fda3b95a4ea91299a34e894583c3862153e4b97"
18+
},
19+
{
20+
"repository": "actions/upload-artifact",
21+
"version": "v7.0.1",
22+
"commit": "043fb46d1a93c77aae656e7c1c64a875d1fc6a0a"
23+
}
24+
]
25+
}

.github/pull_request_template.md

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,3 +10,10 @@
1010
## Provider and privacy impact
1111

1212
Describe any new credential scope, endpoint, subprocess, ledger field, or exported API fact. Write `None` when this change has no provider or privacy impact.
13+
14+
## Local API compatibility impact
15+
16+
Classify the change as `None`, `additive`, `deprecated`, or `breaking` using
17+
`docs/api/compatibility-v1.md`. For any Local API change, include current
18+
schema validation and frozen N-1 client evidence. Breaking changes must use a
19+
new API major version rather than changing v1 in place.

.github/workflows/ci.yml

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -19,14 +19,16 @@ jobs:
1919
env:
2020
DEVELOPER_DIR: /Applications/Xcode_26.6.app/Contents/Developer
2121
steps:
22-
- uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5
22+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
2323
with:
2424
fetch-depth: 0
25-
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6
25+
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
2626
with:
2727
python-version: "3.13"
2828
cache: pip
2929
cache-dependency-path: requirements-build.txt
30+
- name: Verify immutable GitHub Action pins
31+
run: python3 scripts/verify_action_pins.py
3032
- name: Bootstrap pinned build dependencies
3133
run: scripts/bootstrap.sh
3234
- name: Verify release metadata consistency
@@ -45,7 +47,7 @@ jobs:
4547
scripts/release_dmg_audit.sh dist/OpenUsage-Bar-*.dmg
4648
- name: Prove isolated install, upgrade, rollback, and uninstall
4749
run: scripts/release_smoke.sh
48-
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
50+
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
4951
with:
5052
name: openusage-bar-macos-arm64
5153
path: |

.github/workflows/release.yml

Lines changed: 9 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -16,18 +16,22 @@ jobs:
1616
env:
1717
DEVELOPER_DIR: /Applications/Xcode_26.6.app/Contents/Developer
1818
steps:
19-
- uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5
19+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
2020
with:
2121
fetch-depth: 0
22-
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6
22+
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
2323
with:
2424
python-version: "3.13"
2525
cache: pip
2626
cache-dependency-path: requirements-build.txt
27+
- name: Verify immutable GitHub Action pins
28+
run: python3 scripts/verify_action_pins.py
2729
- name: Bootstrap pinned build dependencies
2830
run: scripts/bootstrap.sh
2931
- name: Verify immutable tag and release metadata
3032
run: .build-venv/bin/python scripts/verify_release_metadata.py
33+
- name: Audit locked Python dependencies
34+
run: scripts/audit_dependencies.sh
3135
- name: Scan the complete Git history for credentials
3236
run: scripts/release_secret_scan.py --history
3337
- name: Test and build
@@ -38,8 +42,10 @@ jobs:
3842
run: |
3943
.build-venv/bin/python scripts/release_artifact_audit.py dist/OpenUsage-Bar-*.zip
4044
scripts/release_dmg_audit.sh dist/OpenUsage-Bar-*.dmg
45+
- name: Prove isolated install, upgrade, rollback, and uninstall
46+
run: scripts/release_smoke.sh
4147
- name: Attest release assets
42-
uses: actions/attest@f7c74d28b9d84cb8768d0b8ca14a4bac6ef463e6 # v4
48+
uses: actions/attest@f7c74d28b9d84cb8768d0b8ca14a4bac6ef463e6 # v4.2.0
4349
with:
4450
subject-path: |
4551
dist/OpenUsage-Bar-*.dmg

0 commit comments

Comments
 (0)