Skip to content

Epic: v1.0.8 release qualification reliability and pre-announcement gate #709

Description

@jeffhuber

Goal

Make multi-provider release qualification deterministic, discoverable, evidence-complete, and usable before broad release announcement. Ship v1.0.8 through the Code Mower gate, qualify it across local and hosted provider paths, upload metadata-only evidence, and leave the builder-calibration ledger current.

Ordered work

  1. Fix audit verdict transport for metadata findings without source lines (Preserve audit verdicts when metadata findings omit source lines #681).
  2. Complete the bounded reliability children of Make local release campaign qualification deterministic and preserve failure evidence #708:
    • deterministic Python 3.12+ runtime plus truthful authentication/result readiness;
    • retry chronology plus terminal fail/incomplete evidence upload.
  3. Make release-campaign state discoverable across worktrees without breaking existing generated workflows or local campaign files.
  4. Add a bounded candidate-package source suitable for pre-announcement qualification, initially TestPyPI with explicit index controls and exact identity checks.
  5. Verify Cursor/Grok Bot and Devin hosted campaign transport using trusted comments and bounded response deadlines.
  6. Publish v1.0.8 only after local checks, both peer audits, release readiness, package workflow rehearsal, and candidate qualification are green.
  7. Run the v1.0.8 campaign, inspect and upload metadata-only adoption results, update Builder calibration: five bounded deliveries each for Cursor, Muse, Antigravity, and Devin #659, and record the final release posture.

Constraints

  • One issue per PR; keep PRs under 300 lines where practical.
  • Code Mower gate plus Codex and Claude peer audits; author lanes never gate themselves.
  • Dry-run before dispatch, upload, or publish.
  • No source, diffs, transcripts, issue bodies, raw stdout/stderr, auth output, local paths, or secrets in cloud events.
  • Existing campaign files remain readable; generated workflows are added or updated compatibly, never casually renamed.
  • Hosted paid work never retries automatically.

Dependency map

The audit transport, deterministic runtime/readiness, attempt-evidence, and campaign-discovery issues are parallel-safe. Candidate-source qualification depends on the campaign identity contract remaining stable. Hosted verification depends on the candidate source and transport readiness. Release and final qualification are serial.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    epicEpic tracking issueserial-releaseSerialize because it changes release, gate, or final adoption posturev1.0.8Code Mower v1.0.8 release qualification reliability

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions