Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
41 changes: 35 additions & 6 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,12 +7,41 @@ later entries are regular releases.

## Unreleased

- Audit comment ingestion now uses GitHub-specific response, aggregate-byte,
item, and request-page budgets. Oversized pages reduce `per_page` and restart
safely, complete histories receive a stable reread, and omissions, duplicate
IDs, edits, incomplete terminal proof, and budget exhaustion fail with
actionable diagnostics. Lineage controls are recognized only as standalone
HTML control-comment lines outside inline and fenced examples (#1104).
- No changes yet.

## 1.6.0 — operational clarity and minimum telemetry

Code Mower 1.6.0 makes local operational state safer to interpret and adds a
closed, metadata-only lifecycle-summary contract for the optional Slack control
surface. See the [release notes](docs/v160-release-notes.md) and the
[qualification contract](docs/v160-qualification.md).

- Reconcile doctor warnings with their JSON states and keep hosted-only checks
out of ordinary local adoption diagnostics (#1064 / #1099).
- Replace managed Board services atomically, verify either the new or restored
binding from host state, and refuse ambiguous reconciliation (#1082 / #1100,
hardened by #1103).
- Filter Board inventory by identity-verified repository, expose invoking,
serving, installed, managed-service, and restart state consistently, and give
stale managed or transient Boards an exact recovery command (#1063 / #1109).
- Treat an ordinary pull request with no Code Mower provenance as neutral
`unmanaged`, while keeping a visible malformed Code Mower claim actionable
and fail-closed (#1083 / #1097).
- Make adoption diagnostics share-safe by default and require an explicit local
view for private paths and identifiers (#1084 / #1102).
- Isolate spend evidence across repositories and attach a pre-PR builder record
only when its branch exactly matches one fetched pull request, improving cost
coverage without exporting new fields or private data (#1106 / #1108).
- Bound GitHub audit-comment history by response, aggregate-byte, item, and
request-page budgets; adaptively restart smaller pages; prove a stable
terminal history; and fail closed on omissions, duplicate or changed IDs,
truncation, and exhausted budgets. Recognize lineage controls only as exact
standalone HTML comments outside fenced Markdown, while malformed controls
from trusted authorities remain fail-closed (#1104 / #1107).
- Freeze the provider-neutral `code_mower.controlSurfaceSessionSummary.v1`
contract, its accepted and rejected fixtures, capability gate, transition
suppression, local Board projection, and metadata-only cloud emitter
(#921 / #1098).

## 1.5.2 — documentation and repository maintenance

Expand Down
26 changes: 13 additions & 13 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,23 +10,23 @@ It is not a drop-in unattended merge gate. Humans still own credentials,
repository policy, reviewer promotion, and exceptional decisions.

<!-- code-mower:release-facts:start -->
This source defines Code Mower `v1.5.2`, with package spec
`code-mower==1.5.2`. Confirm the release tag on GitHub Releases and the package
This source defines Code Mower `v1.6.0`, with package spec
`code-mower==1.6.0`. Confirm the release tag on GitHub Releases and the package
version on the selected index before using an index install command; source version
and publication state are separate facts.
Python 3.12 or newer is required.
See the [release notes](https://github.com/codemower-ai/code-mower/blob/main/docs/v152-release-notes.md)
and [qualification contract](https://github.com/codemower-ai/code-mower/blob/main/docs/v152-qualification.md).
See the [release notes](https://github.com/codemower-ai/code-mower/blob/main/docs/v160-release-notes.md)
and [qualification contract](https://github.com/codemower-ai/code-mower/blob/main/docs/v160-qualification.md).
<!-- code-mower:release-facts:end -->
Historical v1.4.x artifacts and qualification records remain unchanged.
The v1.4.2 release did not claim the bounded hosted Devin canary tracked by
[#951](https://github.com/codemower-ai/code-mower/issues/951); that result is
not claimed by its immutable qualification record.

Documentation on `main` follows the source on `main`. For an installed release,
read its immutable versioned guide, such as the
[`v1.5.2` guide](https://github.com/codemower-ai/code-mower/blob/v1.5.2/docs/try-in-10-minutes.md),
and confirm the tag and package exist before using pinned install commands.
read its immutable versioned guide. After v1.6.0 publication, use the
[`v1.6.0` guide](https://github.com/codemower-ai/code-mower/blob/v1.6.0/docs/try-in-10-minutes.md).
Confirm the tag and package exist before using pinned install commands.

## What Code Mower Adds

Expand Down Expand Up @@ -102,7 +102,7 @@ ID with `session lease renew --session-id SESSION_ID` or `session lease release
--dry-run` or `--no-lease` for read-only work.

Codex, Claude Code, and Cursor are qualified for the shared session, telemetry,
lease, and Jira-authority contract in the current v1.5.2 release. Devin, Grok
lease, and Jira-authority contract in the current v1.6.0 source line. Devin, Grok
Bot, Antigravity,
Muse, and custom hosts are recognized for briefs and provenance, while their
execution remains an explicit handoff or provider-specific transport. See
Expand Down Expand Up @@ -230,7 +230,7 @@ and the [Cloud Data Contract](https://github.com/codemower-ai/code-mower/blob/ma

## Optional Hosted Slack

v1.5.2 retains the basic Slack control surface introduced in v1.5.0 for one
v1.6.0 retains the basic Slack control surface introduced in v1.5.0 for one
private workspace and one authorized private, unshared channel. A Code Mower
team administrator opens
**Setup → Manage Slack integration** in the hosted dashboard and completes OAuth
Expand Down Expand Up @@ -259,7 +259,7 @@ for both workflows, supported behavior, and the trust boundary.

## Current Capabilities And Limits

| Area | v1.5.2 posture |
| Area | v1.6.0 posture |
| --- | --- |
| Default builders and reviewers | Claude Code + Codex |
| Session hosts | Codex, Claude Code, and Cursor qualified; other identities recognized but require explicit handoff/provider transport |
Expand All @@ -269,19 +269,19 @@ for both workflows, supported behavior, and the trust boundary.
| Forge and merge gate | GitHub |
| Cloud | Optional metadata/report upload; no upload by default |
| Graphify | Optional bounded local repository-graph provider behind the packet contract; no default dependency and no network access for the provider |
| Slack | Optional hosted OAuth and `/codemower` control surface for one private workspace/channel; exact bindings, qualified supervisor, and numeric caps gate work |
| Slack | Optional hosted OAuth and `/codemower` control surface for one private workspace/channel; exact bindings, qualified supervisor, and numeric caps gate work; metadata-only lifecycle summaries require exact hosted capability acceptance |

GitLab, Bitbucket, broad unattended rollout, uncalibrated merge gates, Devin
peer-orchestrator/reviewer parity, a hosted work-order CLI, a required Graphify
dependency, Slack telemetry/Board links, and rich Slack UX are outside v1.5.2. The current priorities
dependency, Slack-to-Board links, and rich Slack UX are outside v1.6.0. The current priorities
and boundaries are recorded in
[Current State And Roadmap](https://github.com/codemower-ai/code-mower/blob/main/docs/current-state-and-roadmap.md).

## Optional Repository Context Graph

Graphify's optional bounded provider foundation landed in v1.4.0; its complete
qualified integration, scorecard and query behavior shipped in v1.4.1 and
remain available in v1.5.2. It is separately installed into an operator-owned
remain available in v1.6.0. It is separately installed into an operator-owned
environment, explicitly activated, and outside the base dependency set: a
default Claude + Codex install adds no Graphify dependency, no indexer, no
background service, and no watcher.
Expand Down
17 changes: 16 additions & 1 deletion code-mower-package-manifest.json
Original file line number Diff line number Diff line change
Expand Up @@ -342,6 +342,21 @@
"source": "docs/v152-release-runbook.md",
"target": "docs/v152-release-runbook.md"
},
{
"kind": "doc",
"source": "docs/v160-qualification.md",
"target": "docs/v160-qualification.md"
},
{
"kind": "doc",
"source": "docs/v160-release-notes.md",
"target": "docs/v160-release-notes.md"
},
{
"kind": "doc",
"source": "docs/v160-release-runbook.md",
"target": "docs/v160-release-runbook.md"
},
{
"kind": "package",
"source": "generated",
Expand Down Expand Up @@ -2375,6 +2390,6 @@
"module": "code_mower",
"name": "code-mower",
"source_layout": "src/code_mower",
"version": "1.5.2"
"version": "1.6.0"
}
}
2 changes: 1 addition & 1 deletion docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -40,6 +40,6 @@ historical release evidence and are not current operating guidance.

## Lifecycle

The manifest currently classifies 63 supporting, 53 frozen, and 5 archived document(s).
The manifest currently classifies 63 supporting, 56 frozen, and 5 archived document(s).
See [Documentation lifecycle](documentation-lifecycle.md) before adding, moving,
or changing release-sensitive documentation.
2 changes: 1 addition & 1 deletion docs/cloud-benchmarking.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ reports, and the local Board without a hosted account. CodeMower.com is an
optional destination for longitudinal team reporting and future aggregate
benchmarks.

## Current v1.5.2 Client Surface
## Current v1.6.0 Client Surface

The current client can:

Expand Down
99 changes: 55 additions & 44 deletions docs/current-state-and-roadmap.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,15 +22,17 @@ dry-run-first.

## Current Source And Published Baseline

This source defines Code Mower `v1.5.2`, with package spec
`code-mower==1.5.2`. Confirm the release tag on GitHub Releases and the package
This source defines Code Mower `v1.6.0`, with package spec
`code-mower==1.6.0`. Confirm the release tag on GitHub Releases and the package
version on the selected index before using an index install command; source
version and publication state are separate facts. See the
[v1.5.2 release notes](https://github.com/codemower-ai/code-mower/blob/main/docs/v152-release-notes.md)
and [qualification contract](https://github.com/codemower-ai/code-mower/blob/main/docs/v152-qualification.md).
After publication, the GitHub Release and linked release issue carry the
observed source SHA, artifact digests, canary outcomes, publication run and
reinstall evidence.
version and publication state are separate facts. The latest published baseline
remains `v1.5.2` until the entry gates and qualification contract for #1105 are
complete. See the
[v1.6.0 release notes](https://github.com/codemower-ai/code-mower/blob/main/docs/v160-release-notes.md),
[qualification contract](https://github.com/codemower-ai/code-mower/blob/main/docs/v160-qualification.md),
and [candidate runbook](v160-release-runbook.md). The GitHub Release and #1105
will carry observed source SHA, artifact digests, canary, soak, publication,
and reinstall evidence after those observations exist.
Historical v1.4.x artifacts and qualification records remain unchanged.

`v1.4.0`, `v1.4.1` and `v1.4.2` have all shipped, and the v1.4.0 and v1.4.1
Expand Down Expand Up @@ -133,10 +135,12 @@ future hosted-service work.
- Graphify's bounded provider foundation shipped in v1.4.0; its complete
qualified integration, scorecard and query behavior shipped in v1.4.1. It
remains optional and has no default dependency.
- Slack in v1.5.2 supports one private workspace with explicit member, repository
- Slack in v1.6.0 retains one private workspace with explicit member, repository
and private-channel mappings plus private start, status, answer and
confirmed-cancel interactions. Telemetry, Board links, Slack Connect, public
channels and richer Slack UX remain planned v1.6 work.
confirmed-cancel interactions. Metadata-only lifecycle summaries remain
disabled until the hosted service advertises the exact accepted contract.
Slack-to-Board links, Slack Connect, public channels and richer Slack UX are
deferred.
- Provider cost fields remain unknown when the provider does not return them.
- A successful release campaign proves installation and operational transport,
not builder quality or reviewer promotion readiness.
Expand All @@ -147,32 +151,36 @@ future hosted-service work.

## Current Release And v1.6.0

`v1.5.2` is released and is the current supported package. It retains the
basic Slack boundary from v1.5.0 and adds the five reliability revisions from
#1050: hosted-install clarity, host-independent tests, lane-exact audit seals,
checkout-free remote doctor, safe existing-repository initialization, and
clearer status/version reporting.

The [v1.6.0 milestone](https://github.com/codemower-ai/code-mower/milestone/2)
and [epic #1066](https://github.com/codemower-ai/code-mower/issues/1066) are the
live trackers. The planned children are:

1. Board inventory filters, version parity, stale detection, and service
guidance ([#1063](https://github.com/codemower-ai/code-mower/issues/1063));
2. doctor warning taxonomy and hosted-posture scope
([#1064](https://github.com/codemower-ai/code-mower/issues/1064));
3. hosted adoption prompts, current documentation, and a normal 24-hour release
soak with two independent install or upgrade passes
([#1065](https://github.com/codemower-ai/code-mower/issues/1065));
4. the closed, versioned optional Slack telemetry contract and OSS emitters
([#921](https://github.com/codemower-ai/code-mower/issues/921)); and
5. hosted validation, aggregation, export/deletion, and fresh authenticated
views for that contract
([#978](https://github.com/codemower-ai/code-mower/issues/978)).

#1063, #1064, and the documentation portion of #1065 can proceed in parallel.
#921 freezes the shared contract and fixtures before #978 enables hosted
ingest. None of this planned work is part of v1.5.2.
`v1.5.2` is released and remains the current supported package. The `v1.6.0`
source line now contains the completed doctor taxonomy, atomic Board replacement,
identity-verified Board inventory and version guidance, neutral `unmanaged`
state for ordinary pull requests with no Code Mower provenance, share-safe
adoption diagnostics, cross-repository cost isolation, and the closed
metadata-only control-surface summary contract. Visible malformed Code Mower
claims remain actionable and fail-closed. The optional client
emitter remains fail-closed unless the hosted service advertises the exact
accepted contract identity.

The [v1.6.0 milestone](https://github.com/codemower-ai/code-mower/milestone/2),
[epic #1066](https://github.com/codemower-ai/code-mower/issues/1066), and
[release issue #1105](https://github.com/codemower-ai/code-mower/issues/1105)
are the live trackers. All immutable-candidate entry gates are complete. Board
clarity #1063 merged through PR #1109, and audit-history hardening #1104 merged
through PR #1107. Hosted PR #542 merged at
`bcddaa25c633f2dcf8fa2077d6ecb8004c1d8f88`; production deployment
`6581697672` succeeded in two steps; production deployment
`dpl_HxhK4CHrYPkCCzjxS9rGjSuBG8C8` is Ready; authenticated health advertises the
exact accepting contract; the migration ledger is 79/79; and one sanitized
probe was accepted exactly once and isolated to `jeff-internal`. Public evidence
is recorded in
[#978 comment 5770184083](https://github.com/codemower-ai/code-mower/issues/978#issuecomment-5770184083).

After the release PR merges, #1105 serializes the one immutable build, bounded
private Slack canary, local-versus-hosted reconciliation, 24-hour soak, two
independent installation passes, exact-head release audits, publication, and
canonical reinstall. #978 remains open until the retained candidate completes
the canary and local-versus-hosted aggregate reconciliation. None of those
post-merge observations is claimed by this source preparation.

## Near-Term Roadmap

Expand Down Expand Up @@ -338,13 +346,16 @@ administration/readiness; #920 consumes the immutable candidate to obtain one
accepted completion and one accepted confirmed cancellation under an explicit
numeric cap while preserving every attempt and reservation; #923 records the
tag, publication and independent reinstall evidence.
Slack telemetry/Board/cloud links and rich UX remain v1.6.0. Slack consumes the
durable lifecycle instead of scraping terminal or Board output and carries no
raw private context or private reviewer findings.

The source implementation and qualification contract are complete. Consult #923
and the GitHub Release for the observed lifecycle, canary, publication and
canonical reinstall state.
The v1.6.0 source adds capability-gated, metadata-only lifecycle summaries to
the local Board and optional cloud emitter. Slack-to-Board links and rich UX
remain deferred. Slack consumes the durable lifecycle instead of scraping
terminal or Board output and carries no raw private context or private reviewer
findings.

The source implementation and qualification contract are complete. This
statement covers the basic v1.5.0 interaction boundary.
Consult #923 and the GitHub Release for the observed v1.5.0 lifecycle, canary,
publication and canonical reinstall state.

## Delivery Order

Expand Down
9 changes: 9 additions & 0 deletions docs/docs-manifest.yml
Original file line number Diff line number Diff line change
Expand Up @@ -362,3 +362,12 @@ documents:
- path: docs/v152-release-runbook.md
status: frozen
sha256: 7a7492e3e297d920dbb76b7c25339f3865d545c108a0114e65b1a3d989ad3bcd
- path: docs/v160-qualification.md
status: frozen
sha256: 39e99c1a27aaf2405e9280e3ca7bc1c9465ad3a5965c7e71e39dc558a011173d
- path: docs/v160-release-notes.md
status: frozen
sha256: 07bc43f511070dc4da114040f4e8f58a33cc639cb7aa3950c0508d14f0cfac59
- path: docs/v160-release-runbook.md
status: frozen
sha256: a14703176f7d2bc009ff4285eaad72f452f636c93198089cca62f10944d25e76
4 changes: 2 additions & 2 deletions docs/early-adopter-invite-runbook.md
Original file line number Diff line number Diff line change
Expand Up @@ -40,8 +40,8 @@ Want to try Code Mower for 10 minutes?
It is an OSS local-first tool for setting up AI peer-programmer/reviewer lanes
on your real codebase, with optional privacy-first cloud reporting.

After v1.5.2 is published, start here:
https://github.com/codemower-ai/code-mower/blob/v1.5.2/docs/try-in-10-minutes.md
After v1.6.0 is published, start here:
https://github.com/codemower-ai/code-mower/blob/v1.6.0/docs/try-in-10-minutes.md

Cloud sharing is optional. The default bundle excludes source code, raw diffs,
model transcripts, raw stdout/stderr, auth output, and secrets.
Expand Down
Loading
Loading