Skip to content

Release/0.1.8 - #12

Merged
qmarcelle merged 5 commits into
mainfrom
release/0.1.8
Jul 21, 2026
Merged

Release/0.1.8#12
qmarcelle merged 5 commits into
mainfrom
release/0.1.8

Conversation

@qmarcelle

Copy link
Copy Markdown
Contributor

Runtime correction

The audit found the inaccurate approval wording in two locations:

src/evidence.ts
src/tools/workspace.ts

Change both to a bounded statement:

Include the recorded co-change partners, or stop and review the exception with a human.

Add tests that prove:

missing evidenced partners still produce deny;
the message includes the new wording;
the message no longer includes get explicit human approval;
partner presence remains path-membership enforcement;
no override mechanism has been introduced.
Documentation correction

Complete the already drafted changes, but fix the additional mismatch the adversarial review identified:

Billfold uses one checkout/Stripe partner;
the local repository fixture walkthrough uses two partners.

Clearly label them as separate proof paths rather than describing both as the same example.

Also update:

hero wording;
remove unsupported A/B framing;
stale codex-demo-fixture links;
Billfold reproduction;
local versus provider network boundary;
path coverage versus semantic sufficiency;
current agents-audit producer name;
changelog.
Release

Stages 0.1.7 across the three sync points (package.json, package-lock,
runtime VERSION in src/index.ts). Cut from main so PR #10 (e0827a8,
array frameworkManifest normalization) is included -- the prior release
branch did not contain it.

Normalizer fix only. Extension stays 0.1.2 (separate vsce track).
.vscode/ is untracked developer convenience (extension-host launch +
build task). It failed check:structure, the first gate in
prepublishOnly, blocking local publish. The checker consults
git check-ignore plus config/repository-structure.json; .vscodeignore
governs vsce bundling only and has no bearing here.

Kept separate from the 0.1.7 version bump.
The npm publish workflow asserted tarball contents by filename only, so
a release could ship without the array-manifest normalizer and stay
green. 0.1.5 and 0.1.6 both did exactly that (HAC-206).

Extracts the packed tarball and greps dist/services/workspace.js for
normalizeFrameworkManifest. Verified to discriminate: the published
0.1.6 tarball fails this check, a 0.1.7 pack passes it.

Scope is deliberately narrow -- this is a presence check on a symbol.
It catches the fix going missing, not the fix being wrong. A behavioural
gate needs a non-empty frameworkManifest fixture, because an empty array
normalizes to undefined with or without the fix and discriminates
nothing. That fixture is the follow-up.
Copilot AI review requested due to automatic review settings July 21, 2026 23:01

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@qmarcelle
qmarcelle merged commit 1261728 into main Jul 21, 2026
2 checks passed
@qmarcelle
qmarcelle deleted the release/0.1.8 branch July 21, 2026 23:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants