diff --git a/.github/scripts/verify-forbidden-release-artifacts.mjs b/.github/scripts/verify-forbidden-release-artifacts.mjs index 6c541f0d..fd669623 100644 --- a/.github/scripts/verify-forbidden-release-artifacts.mjs +++ b/.github/scripts/verify-forbidden-release-artifacts.mjs @@ -77,13 +77,13 @@ function expectFailure(action, pattern) { } function selfTest() { - const tag = 'v0.40.0-beta.6' + const tag = 'v0.40.0-beta.7' expectFailure( () => assertTagAbsent({ status: 128, stdout: '', stderr: 'network error' }, tag), /Unable to prove forbidden git tag/, ) expectFailure( - () => assertTagAbsent({ status: 0, stdout: 'deadbeef refs\/tags\/v0.40.0-beta.6\n', stderr: '' }, tag), + () => assertTagAbsent({ status: 0, stdout: 'deadbeef refs\/tags\/v0.40.0-beta.7\n', stderr: '' }, tag), /forbids git tag/, ) expectFailure( diff --git a/.github/scripts/verify-packed-retrieval-parity.mjs b/.github/scripts/verify-packed-retrieval-parity.mjs index 2e28b7dc..964ec42c 100644 --- a/.github/scripts/verify-packed-retrieval-parity.mjs +++ b/.github/scripts/verify-packed-retrieval-parity.mjs @@ -58,7 +58,8 @@ function assertPackageMeasurement(record, tarballPath) { const evaluationTooling = manifest.items?.find((item) => item.id === 'evaluation-tooling') const activePhase = manifest.items?.find((item) => item.id === manifest.current?.active_phase) const budget = activePhase?.npm_package_budget ?? evaluationTooling?.npm_package_budget - const receipt = activePhase?.terminal_language_corrective?.package_candidate + const receipt = activePhase?.terminal_language_release?.package_candidate + ?? activePhase?.terminal_language_corrective?.package_candidate ?? activePhase?.corrective_release?.package_candidate ?? activePhase?.corrective?.package_candidate ?? manifest.current diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index df50d39b..ae7afd7d 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -54,8 +54,8 @@ jobs: exit 1 fi - if [[ "$VERSION" != "0.40.0-beta.6" ]]; then - echo "This release candidate is authorized only for 0.40.0-beta.6" + if [[ "$VERSION" != "0.40.0-beta.7" ]]; then + echo "This release candidate is authorized only for 0.40.0-beta.7" exit 1 fi @@ -164,8 +164,8 @@ jobs: PACKAGE_NAME="$(node -pe 'require("./package.json").name')" VERSION="$(node -pe 'require("./package.json").version')" SPEC="$PACKAGE_NAME@$VERSION" - EXPECTED_SHASUM="4c98dd99cd321e741cabd689f0803d99e519f389" - EXPECTED_INTEGRITY="sha512-o6L/BiJ1wrTWCaK537p60pGUC5i8zY0Zqz7NqD1zW4fJl/ewjF3cgysf4dbOkY4y49DkYDTG2qoUh1DGvq2Q0Q==" + EXPECTED_SHASUM="1aafe5952aea2f353711d5af36fa564a147312f5" + EXPECTED_INTEGRITY="sha512-K5CEUr2lRR1IoNCS9O74jMA7PDDgQMkdx3QM/cF+h17jyAj6Gt3Gpk8vkzKSz7SKFR44KgpnJeLkV5lXyzdgYw==" VERIFIED=false for attempt in 1 2 3 4 5 6; do diff --git a/CHANGELOG.md b/CHANGELOG.md index f6ad9d97..1f2b2674 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,12 @@ All notable changes to the TypeScript package will be documented in this file. ## [Unreleased] +## [0.40.0-beta.7] - 2026-08-02 + +### Fixed + +- **Natural finished-report workflow questions now retain the complete authenticated corridor.** Complete, unquoted `finished report` and `done report` terminals normalize without changing identifiers, active persistence operations, compound terminals, locator semantics, graph/index/query schemas, CLI, MCP, dependencies, or retrieval budgets. Formal installed-package and comparator qualification remains open in #631. + ## [0.40.0-beta.6] - 2026-08-02 ### Fixed diff --git a/README.md b/README.md index ab249534..f3bfaff9 100644 --- a/README.md +++ b/README.md @@ -12,14 +12,14 @@ The result is a complete, ordered answer dossier backed by exact source evidence MCP advertises only the tools capability. It exposes no resources or prompts. -[![npm next](https://img.shields.io/npm/v/%40lubab%2Fmadar/next?label=npm%20next)](https://www.npmjs.com/package/@lubab/madar/v/0.40.0-beta.6) +[![npm next](https://img.shields.io/npm/v/%40lubab%2Fmadar/next?label=npm%20next)](https://www.npmjs.com/package/@lubab/madar/v/0.40.0-beta.7) [![node >=20](https://img.shields.io/badge/node-%E2%89%A520-3c873a)](https://nodejs.org/) [![local first](https://img.shields.io/badge/local--first-no%20cloud%20required-0f766e)](#local-by-design) [![license MIT](https://img.shields.io/badge/license-MIT-16a34a)](https://github.com/mohanagy/madar/blob/next/LICENSE) ## What's new -See [beta.6 changes](https://github.com/mohanagy/madar/blob/next/CHANGELOG.md#0400-beta6---2026-08-02). This corrective manual-test candidate precedes #631 qualification; it makes no comparative performance or retention claim. +See [beta.7 changes](https://github.com/mohanagy/madar/blob/next/CHANGELOG.md#0400-beta7---2026-08-02). This terminal-language corrective manual-test candidate precedes #631 qualification; it makes no comparative performance or retention claim. ## Start in three steps diff --git a/docs/claims-and-evidence.md b/docs/claims-and-evidence.md index 9a97ce1f..f6e94c27 100644 --- a/docs/claims-and-evidence.md +++ b/docs/claims-and-evidence.md @@ -22,7 +22,7 @@ Those experiments answer different questions. Neither is a universal claim about ## Beta boundary -The completed Core Reset product path, semantic execution index #632, and obligation-driven retrieval #630 support manual-test prereleases for JavaScript/TypeScript repositories. Capability Validation and the earlier Native-vs-Graphify comparator were cancelled before any campaign, provider request, paid spend, or result. `0.40.0-beta.5` is immutable published manual-test history; its owner test led to the bounded correction merged in PR #637. `0.40.0-beta.6` is authorized under npm `next` so that correction can be tested before #631 qualification. Neither beta is comparative evidence, and beta.6 makes no comparative correctness, token, latency, cost, activation, retention, or external-user claim. +The completed Core Reset product path, semantic execution index #632, and obligation-driven retrieval #630 support manual-test prereleases for JavaScript/TypeScript repositories. Capability Validation and the earlier Native-vs-Graphify comparator were cancelled before any campaign, provider request, paid spend, or result. `0.40.0-beta.5` and `0.40.0-beta.6` are immutable published manual-test history; beta.6 failed the installed finished-report and zero-fallback gate. Terminal-language corrective PR #641 then merged to protected `next` at `e84d266734344397eec9a6bcd2e1a3a5070dc3ea`, preserving reviewed tree `5ffed3bc25cb537aafd3bb905ed9df08a7143d69`. `0.40.0-beta.7` is owner-authorized under npm `next` for installed manual testing after its release gates pass, but remains unpublished, unqualified, and non-comparative until then. None of these betas proves comparative correctness, token, latency, cost, activation, retention, or external-user outcomes, and #631 remains open. The historical evaluation contracts remain development records. A future comparison or stable-release claim requires a new issue, fresh owner authorization, and new reproducible evidence. diff --git a/docs/core-reset/removal-manifest.yml b/docs/core-reset/removal-manifest.yml index 6b464582..60ebc3e1 100644 --- a/docs/core-reset/removal-manifest.yml +++ b/docs/core-reset/removal-manifest.yml @@ -23,7 +23,7 @@ review: disposition_changes: 11 amendment: 'Source lists remain complete and de-overlapped. Issue #588 moved four guaranteed extraction orphans into the completed delete contract. Issue #592 transferred stage.ts, freshness.ts, and source-discovery.ts to evidence-path-query and doctor.ts to thin-delivery. Approved issues #596 and #599 combined the original 54-file / 29,441-LOC query closure with nine finalizer files / 3,590 LOC, yielding one completed 63-file / 33,031-LOC predecessor contract and 22 ownership transfers. proof-report.ts plus review-compare.ts remain move-to-delete changes; serve.ts changed from rebuild to delete, raising disposition_changes from 4 to 7. Owner-approved issue #602 removed stale thin-delivery ownership of deleted serve.ts, transferred package-metadata.ts and shell.ts from rebuild to evaluation-tooling move ownership, raising disposition_changes from 7 to 9, and absorbed the remaining non-core-graph-products and activation-and-extra-integrations production owners into one exact 16-file / 7,277-LOC thin-delivery deletion contract. PR #604 completed that contract without further ownership change. Owner-approved issue #606 transferred graph-source-root.ts and workspace-copy.ts from safe-workspace-primitives to evaluation-tooling, raising disposition_changes from 9 to 11, and activated the exact 20-file / 4,698-LOC move contract from protected base 317dda89f2ea5c75e7626a26b104ceca1bd04ce5. Governance activation merged at 452ad84890c012392c5e6af613e8bfeb17de45db without production source changes. PR #608 completed the exact move without changing any surviving production TypeScript or dependency. First-stage owner-approved issue #610 governance activation merged at dcb52596a3efa89f9ef5d372231ce97a91ae5f9f, then independent review stopped its uncommitted implementation under conditions 7, 8, and 13 before any implementation PR, campaign lock, provider request, or spend. First-stage owner-approved issue #612 authorizes only an eight-path governance-only v2 candidate from that exact merge; its separate activation merge approval remains required. It changes no production ownership or disposition. Issue #625 modifies five existing evidence-path-query production paths and changes no ownership or disposition. Corrective #632 completed at c88823ecbeb6da6284cf74ecbd304e9315ffd4fa. Issue #630 added exactly three production-source owners for its planner, workflow builder and evidence hydrator and completed through protected-next merge 9703a7090fd3ef3600b4ab4e298b12f0faa05a1e; existing adapter and query surfaces retain their historical owners. Graph/index generation, schemas, CLI, MCP, and package dependencies remain unchanged by the beta.5 release preparation.' cancellation_amendment: 'On 2026-07-28 the owner closed Capability Validation issues #610, #612, #614, #615, and #616 as not planned and revoked every unconsumed preparation, activation, implementation, campaign, provider, spend, and target-execution authority. No campaign ran, no comparative result exists, provider requests remain zero, and spend remains USD 0. The governance-only v2 activation remains immutable history. Issue #618 is a separate bounded retrieval repair and does not revive Capability Validation or Graphify.' - release_amendment: 'Historical release receipt: @lubab/madar@0.40.0-beta.3 was published under npm dist-tag next and GitHub prerelease v0.40.0-beta.3 from exact protected-next commit ece7d0d02643ecec08bd91aa904a4514aa845f42. Issue #625 and PR #626 subsequently completed the generic evidence-skeleton repair on protected next at b6562b715133304bd46e537b6f39008bc1e02095. Issue #627 then published @lubab/madar@0.40.0-beta.4 under npm dist-tag next and the matching GitHub prerelease from exact protected-next commit 9043320cfa08370e5cdd3911bfb9283005aa9912 and tree f51d6e75e3b806dec6caf9ff0be43fc2ab5713fc. After #630 completed, owner receipts 5155128419 and 5155128626 authorized exactly @lubab/madar@0.40.0-beta.5 under npm dist-tag next; it was published from protected-next merge 81045cc08f1df797ecb86748c9bce09db62aeebd by trusted-publishing run 30734176943. Corrective PR #637 then merged at protected-next commit 68729161699b7592bea6984e1aa22c7b4b0833e8 and tree 4500d416d0e890b1dc67c9228a2cbb49cf4220a3. Owner receipts 5157473339 and 5157473448 separately authorized exactly @lubab/madar@0.40.0-beta.6 under npm dist-tag next; it was published from protected-next merge 66b795e76a76c6946b85e5eb878e3f576b4e3dbb and tree ff57246a55e51459836946d6b5b9853d0cdcc372 by release workflow 30746816714. Installed-package receipt 5158293324 then recorded a blocking terminal-language and zero-fallback manual-qualification failure. npm latest remains 0.32.0. Stable 0.40.0, a GitHub Release, MCP Registry publication, any beta.6 tag, comparative claims, and main remain outside this release.' + release_amendment: 'Historical release receipt: @lubab/madar@0.40.0-beta.3 was published under npm dist-tag next and GitHub prerelease v0.40.0-beta.3 from exact protected-next commit ece7d0d02643ecec08bd91aa904a4514aa845f42. Issue #625 and PR #626 subsequently completed the generic evidence-skeleton repair on protected next at b6562b715133304bd46e537b6f39008bc1e02095. Issue #627 then published @lubab/madar@0.40.0-beta.4 under npm dist-tag next and the matching GitHub prerelease from exact protected-next commit 9043320cfa08370e5cdd3911bfb9283005aa9912 and tree f51d6e75e3b806dec6caf9ff0be43fc2ab5713fc. After #630 completed, owner receipts 5155128419 and 5155128626 authorized exactly @lubab/madar@0.40.0-beta.5 under npm dist-tag next; it was published from protected-next merge 81045cc08f1df797ecb86748c9bce09db62aeebd by trusted-publishing run 30734176943. Corrective PR #637 then merged at protected-next commit 68729161699b7592bea6984e1aa22c7b4b0833e8 and tree 4500d416d0e890b1dc67c9228a2cbb49cf4220a3. Owner receipts 5157473339 and 5157473448 separately authorized exactly @lubab/madar@0.40.0-beta.6 under npm dist-tag next; it was published from protected-next merge 66b795e76a76c6946b85e5eb878e3f576b4e3dbb and tree ff57246a55e51459836946d6b5b9853d0cdcc372 by release workflow 30746816714. Installed-package receipt 5158293324 then recorded a blocking terminal-language and zero-fallback manual-qualification failure. Terminal-language corrective PR #641 passed all six exact-head CI jobs, independent review, CodeRabbit disposition and zero unresolved threads, then merged at protected-next commit e84d266734344397eec9a6bcd2e1a3a5070dc3ea with reviewed tree 5ffed3bc25cb537aafd3bb905ed9df08a7143d69. Owner receipts 5159641693 and 5159642279 authorize exactly @lubab/madar@0.40.0-beta.7 under npm dist-tag next from that anchor after the separate release candidate passes the same gates. Publication remains pending, #631 remains open and unqualified, and npm latest remains 0.32.0. Stable 0.40.0, a GitHub Release, MCP Registry publication, any beta.7 tag, comparative claims, and main remain outside this release.' current: updated_at: 2026-08-02 @@ -38,13 +38,13 @@ current: production_loc_removed: 2150 production_loc_net: 152 npm_files: 102 - npm_packed_bytes: 155330 - npm_unpacked_bytes: 654008 - npm_shasum: c107e87c185c39e9acc0d3a33d55e4bbe2e8eb30 - npm_integrity: sha512-/is0gABnCpimVQWLdvyFBtqhhrwSkuwgYtzQIp8FDBcSqAoLqXK4E5C3CTHqLxIWWKAtNUx8o90B7TOtMb9VCg== - npm_artifact_sha256: f341a2b3e36d074b7cdad2656bb4895393b82894223489778dad7ac623069621 + npm_packed_bytes: 155339 + npm_unpacked_bytes: 654026 + npm_shasum: 1aafe5952aea2f353711d5af36fa564a147312f5 + npm_integrity: sha512-K5CEUr2lRR1IoNCS9O74jMA7PDDgQMkdx3QM/cF+h17jyAj6Gt3Gpk8vkzKSz7SKFR44KgpnJeLkV5lXyzdgYw== + npm_artifact_sha256: f4b33dacda9261eb0af8fa9302d5e51dd47e07235a7af9072b4dbfe5a50a21ca measurement_state: source_and_package_exact - snapshot_scope: terminal_language_corrective_unpublished_candidate + snapshot_scope: terminal_language_beta7_unqualified_manual_test_package_candidate release_candidate: version: 0.40.0-beta.4 protected_anchor_commit: 9043320cfa08370e5cdd3911bfb9283005aa9912 @@ -122,6 +122,28 @@ current: registry_metadata_publication: forbidden tag: forbidden main_target: forbidden + terminal_language_manual_test_candidate: + version: 0.40.0-beta.7 + preparation_anchor_commit: e84d266734344397eec9a6bcd2e1a3a5070dc3ea + preparation_anchor_tree: 5ffed3bc25cb537aafd3bb905ed9df08a7143d69 + authorization_receipt: https://github.com/mohanagy/madar/issues/631#issuecomment-5159641693 + parent_authorization_receipt: https://github.com/mohanagy/madar/issues/629#issuecomment-5159642279 + target_branch: next + npm_dist_tag: next + publication_state: authorized_pending_protected_next_release_merge + qualification_state: unqualified_pending_owner_manual_test_and_formal_631_gate + package_candidate: + npm_files: 102 + npm_packed_bytes: 155339 + npm_unpacked_bytes: 654026 + npm_shasum: 1aafe5952aea2f353711d5af36fa564a147312f5 + npm_integrity: sha512-K5CEUr2lRR1IoNCS9O74jMA7PDDgQMkdx3QM/cF+h17jyAj6Gt3Gpk8vkzKSz7SKFR44KgpnJeLkV5lXyzdgYw== + npm_artifact_sha256: f4b33dacda9261eb0af8fa9302d5e51dd47e07235a7af9072b4dbfe5a50a21ca + stable_or_latest: forbidden + github_release: forbidden + registry_metadata_publication: forbidden + tag: forbidden + main_target: forbidden targets: production_typescript_files_max: 80 @@ -2696,6 +2718,7 @@ items: provider_traffic_or_spend: requires_separate_owner_authorization beta_publication: authorized_exact_0.40.0-beta.5_by_receipt_5155128419 corrective_beta_publication: published_exact_0.40.0-beta.6_by_receipt_5157856602 + terminal_language_beta_publication: authorized_exact_0.40.0-beta.7_by_receipt_5159641693 stable_or_latest_publication: forbidden github_release: forbidden registry_metadata_publication: forbidden @@ -2742,11 +2765,20 @@ items: package_ceiling_change: forbidden publication: forbidden terminal_language_corrective: - status: local_candidate + status: merged_unpublished_candidate authorization_receipt: https://github.com/mohanagy/madar/issues/631#issuecomment-5158293324 protected_base: 66b795e76a76c6946b85e5eb878e3f576b4e3dbb protected_base_tree: ff57246a55e51459836946d6b5b9853d0cdcc372 target_branch: next + pull_request: https://github.com/mohanagy/madar/pull/641 + reviewed_head: 8c21c687adce70a483073c5406e0e5b1356cfaea + reviewed_tree: 5ffed3bc25cb537aafd3bb905ed9df08a7143d69 + merge_commit: e84d266734344397eec9a6bcd2e1a3a5070dc3ea + merge_tree: 5ffed3bc25cb537aafd3bb905ed9df08a7143d69 + ci_run: https://github.com/mohanagy/madar/actions/runs/30753189853 + independent_review: passed_no_blocker + coderabbit: passed_with_non_blocking_docstring_warning + unresolved_threads: 0 modified_sources: - src/domain/query/plan.ts test_sources: @@ -2822,7 +2854,29 @@ items: registry_metadata_publication: forbidden tag: forbidden main_target: forbidden - notes: 'Issues #632 and #630 are complete and beta.5 is immutable published manual-test history. The beta.5 owner test found one generic workflow-bound parser defect and one ready-state client-handoff defect before formal #631 qualification. Corrective receipt 5157008370 authorized exactly two zero-net production-source modifications plus the zero-fallback evaluator correction from protected next 81045cc08f1df797ecb86748c9bce09db62aeebd; PR #637 merged the reviewed correction at protected-next commit 68729161699b7592bea6984e1aa22c7b4b0833e8 and tree 4500d416d0e890b1dc67c9228a2cbb49cf4220a3. Owner receipts 5157473339 and 5157473448 authorized beta.6, which was published from protected-next merge 66b795e76a76c6946b85e5eb878e3f576b4e3dbb by workflow 30746816714. Installed-package receipt 5158293324 then recorded a blocking failure: the exact finished-report prompt was incomplete at 6/7 and the natural client fell back to repository tools. The focused local terminal-language corrective remains unpublished and is not the final ten-stage comparator or zero-fallback qualification. No comparative claim or provider campaign exists yet; stable/latest, GitHub Release, Registry publication, a tag and main remain forbidden.' + terminal_language_release: + version: 0.40.0-beta.7 + preparation_anchor_commit: e84d266734344397eec9a6bcd2e1a3a5070dc3ea + preparation_anchor_tree: 5ffed3bc25cb537aafd3bb905ed9df08a7143d69 + authorization_receipt: https://github.com/mohanagy/madar/issues/631#issuecomment-5159641693 + parent_authorization_receipt: https://github.com/mohanagy/madar/issues/629#issuecomment-5159642279 + target_branch: next + npm_dist_tag: next + publication_state: authorized_pending_protected_next_release_merge + qualification_state: unqualified_pending_owner_manual_test_and_formal_631_gate + package_candidate: + npm_files: 102 + npm_packed_bytes: 155339 + npm_unpacked_bytes: 654026 + npm_shasum: 1aafe5952aea2f353711d5af36fa564a147312f5 + npm_integrity: sha512-K5CEUr2lRR1IoNCS9O74jMA7PDDgQMkdx3QM/cF+h17jyAj6Gt3Gpk8vkzKSz7SKFR44KgpnJeLkV5lXyzdgYw== + npm_artifact_sha256: f4b33dacda9261eb0af8fa9302d5e51dd47e07235a7af9072b4dbfe5a50a21ca + stable_or_latest: forbidden + github_release: forbidden + registry_metadata_publication: forbidden + tag: forbidden + main_target: forbidden + notes: 'Issues #632 and #630 are complete and beta.5 and beta.6 are immutable published manual-test history. The beta.5 owner test found one generic workflow-bound parser defect and one ready-state client-handoff defect before formal #631 qualification. Corrective receipt 5157008370 authorized exactly two zero-net production-source modifications plus the zero-fallback evaluator correction from protected next 81045cc08f1df797ecb86748c9bce09db62aeebd; PR #637 merged the reviewed correction at protected-next commit 68729161699b7592bea6984e1aa22c7b4b0833e8 and tree 4500d416d0e890b1dc67c9228a2cbb49cf4220a3. Owner receipts 5157473339 and 5157473448 authorized beta.6, which was published from protected-next merge 66b795e76a76c6946b85e5eb878e3f576b4e3dbb by workflow 30746816714. Installed-package receipt 5158293324 then recorded a blocking failure: the exact finished-report prompt was incomplete at 6/7 and the natural client fell back to repository tools. Terminal-language corrective PR #641 passed all six exact-head CI jobs, independent review, CodeRabbit disposition and zero unresolved threads, then merged to protected next as e84d266734344397eec9a6bcd2e1a3a5070dc3ea with reviewed tree 5ffed3bc25cb537aafd3bb905ed9df08a7143d69. Owner receipts 5159641693 and 5159642279 authorize the exact beta.7 package under npm next for manual testing after its separate release PR passes every gate. Beta.7 is not the final ten-stage comparator or zero-fallback qualification, and #631 remains open and unqualified. No comparative claim or provider campaign exists yet; stable/latest, GitHub Release, Registry publication, a tag and main remain forbidden.' exit_gate: The installed exact-head package matches or beats the strongest frozen baseline, scores at least 90 mean with no run below 85 or critical error, makes one Madar retrieval with zero repository-tool fallback in natural-client runs, and passes closed-book, parity, budget, CI, independent-review, and zero-thread gates. - id: non-core-graph-products diff --git a/docs/core-reset/scorecard.md b/docs/core-reset/scorecard.md index 37b35095..996ea75e 100644 --- a/docs/core-reset/scorecard.md +++ b/docs/core-reset/scorecard.md @@ -2,7 +2,7 @@ > **RFC:** [#577](https://github.com/mohanagy/madar/issues/577) > **Milestone:** [`v0.40.0 — Core Reset`](https://github.com/mohanagy/madar/milestone/7) -> **Status:** accepted; semantic execution index #632 and obligation-driven retrieval #630 are complete; `0.40.0-beta.5` and `0.40.0-beta.6` are immutable published manual-test history; [beta.6 publication receipt](https://github.com/mohanagy/madar/issues/631#issuecomment-5157856602) records protected `next` merge `66b795e76a76c6946b85e5eb878e3f576b4e3dbb`; its [installed-package failure receipt](https://github.com/mohanagy/madar/issues/631#issuecomment-5158293324) records a blocking terminal-language and zero-fallback failure; a focused unpublished corrective is in progress; npm `latest` remains `0.32.0`; stable release, GitHub Release, MCP Registry publication, beta.6 tag, comparative claims, and `main` remain unauthorized +> **Status:** accepted; semantic execution index #632 and obligation-driven retrieval #630 are complete; `0.40.0-beta.5` and `0.40.0-beta.6` are immutable published manual-test history; beta.6 failed its installed terminal-language and zero-fallback gate; corrective PR #641 passed every protected gate and merged as `e84d266734344397eec9a6bcd2e1a3a5070dc3ea` with reviewed tree `5ffed3bc25cb537aafd3bb905ed9df08a7143d69`; owner receipts authorize exact `0.40.0-beta.7` publication under npm `next` for installed manual testing after its separate release gates pass; beta.7 remains unpublished and unqualified, #631 remains open, and npm `latest` remains `0.32.0`; stable release, GitHub Release, MCP Registry publication, beta.7 tag, comparative claims, and `main` remain unauthorized This is the phase-gate evidence ledger. An issue or PR link is not evidence by itself; each gate needs a reproducible test, receipt, measurement, or external-user record. @@ -45,12 +45,12 @@ The schema-validated, share-safe receipt was recorded at tooling checkout `250a6 | Retrieval regression #625 | **Passed** | Replace phrase-gated recovery with a generic bounded, graph-coherent evidence skeleton/forest without exceeding the inherited package ceilings | [#625](https://github.com/mohanagy/madar/issues/625) completed through [PR #626](https://github.com/mohanagy/madar/pull/626), merged at `b6562b715133304bd46e537b6f39008bc1e02095`; [six-job CI](https://github.com/mohanagy/madar/actions/runs/30533140531), independent exact-head review, CodeRabbit PASS, and zero unresolved threads | | Semantic execution index #632 | **Passed** | Authenticated ordered body facts, exact async channels and receiver/type-proven persistence pass every source, graph, indexing, latency, package, CI, review and zero-thread gate | [#632](https://github.com/mohanagy/madar/issues/632); corrective [PR #634](https://github.com/mohanagy/madar/pull/634) passed all six CI jobs, independent review, CodeRabbit and zero unresolved threads, then merged as `c88823ecbeb6da6284cf74ecbd304e9315ffd4fa` with tree `b715764668b4296e9e8ab4da715374f47af137db` | | Obligation-driven retrieval #630 | **Passed** | Return a complete authenticated workflow dossier or exact missing obligations within amended budgets | [PR #635](https://github.com/mohanagy/madar/pull/635) passed exact-head source/package, focused 267/267, full 899/899, coverage, 14/14 real-GoValidate, 100-sample warm p95, parity, release, Registry validation, isolation, audit, typecheck/build/build-eval, six-job CI, CodeRabbit, independent review and 13/13 resolved-thread gates; protected squash merge `9703a7090fd3ef3600b4ab4e298b12f0faa05a1e` preserved reviewed tree `5db67cbe19a9479409192558ea40b0ac8e3add78` | -| No-fallback qualification #631 | **In progress — beta.6 manual gate failed** | Installed exact-head package matches or beats the strongest frozen baseline and requires zero repository-tool fallback | [#631](https://github.com/mohanagy/madar/issues/631); published beta.6 failed the exact finished-report and natural-client zero-fallback gate; a focused unpublished corrective is in progress, while the formal frozen comparison has not started | +| No-fallback qualification #631 | **In progress — beta.7 unqualified** | Installed exact-head package matches or beats the strongest frozen baseline and requires zero repository-tool fallback | [#631](https://github.com/mohanagy/madar/issues/631); published beta.6 failed the exact finished-report and natural-client zero-fallback gate; the correction merged and beta.7 is authorized only as the next installed manual-test boundary, while the formal frozen comparison has not started | | External validation | **Deferred** | Activation, retention, and paid-intent evidence remains required for later stable claims, not this beta | No external-validation claim in `0.40.0-beta.4` | -| Beta release | **Beta.5 and beta.6 published** | Preserve both immutable artifacts and do not republish the unpublished #631 corrective without new owner authorization | [beta.5 receipt](https://github.com/mohanagy/madar/issues/631#issuecomment-5155719419); [beta.6 receipt](https://github.com/mohanagy/madar/issues/631#issuecomment-5157856602); exact beta.6 artifact 102 files / 155,257 packed / 653,996 unpacked with shasum `4c98dd99cd321e741cabd689f0803d99e519f389`; no stable/latest, GitHub Release, Registry publication, tag, or `main` | +| Beta release | **Beta.5 and beta.6 published; beta.7 authorized** | Preserve both immutable artifacts and publish beta.7 only from its protected release merge after every named gate passes | [beta.5 receipt](https://github.com/mohanagy/madar/issues/631#issuecomment-5155719419); [beta.6 receipt](https://github.com/mohanagy/madar/issues/631#issuecomment-5157856602); [beta.7 authorization](https://github.com/mohanagy/madar/issues/631#issuecomment-5159641693); exact beta.7 candidate 102 files / 155,339 packed / 654,026 unpacked with shasum `1aafe5952aea2f353711d5af36fa564a147312f5`; no stable/latest, GitHub Release, Registry publication, tag, or `main` | | Stable release | Not started | Every separately retained stable gate passed; old core absent; migration docs ready | Pending; the beta does not satisfy this gate | -Issues `#622`, `#625`, `#632`, and `#630` are complete on `next`. Evaluation Tooling Isolation completed through #606 and PR #608 at 43 production files / 11,956 LOC; #618 completed at 43 production files / 12,008 LOC with `+69/-17/net +52`; #622 completed at 43 production files / 12,147 LOC with `+164/-25/net +139`; and #625 completed at 43 production files / 12,454 LOC with `+1,409/-1,102/net +307` against its protected base. Beta.5 is immutable published history at exact protected-`next` commit `81045cc08f1df797ecb86748c9bce09db62aeebd`; beta.6 is immutable published history at protected-`next` commit `66b795e76a76c6946b85e5eb878e3f576b4e3dbb` and failed its installed manual qualification. Capability Validation issues #610, #612, #614, #615, and #616 are closed not planned: no campaign ran, provider requests remain zero, and paid spend remains USD 0. #630 completed at exact protected-`next` merge `9703a7090fd3ef3600b4ab4e298b12f0faa05a1e`; corrective PR #637 merged at `68729161699b7592bea6984e1aa22c7b4b0833e8`; #631 now owns a focused unpublished corrective before later formal qualification. +Issues `#622`, `#625`, `#632`, and `#630` are complete on `next`. Evaluation Tooling Isolation completed through #606 and PR #608 at 43 production files / 11,956 LOC; #618 completed at 43 production files / 12,008 LOC with `+69/-17/net +52`; #622 completed at 43 production files / 12,147 LOC with `+164/-25/net +139`; and #625 completed at 43 production files / 12,454 LOC with `+1,409/-1,102/net +307` against its protected base. Beta.5 is immutable published history at exact protected-`next` commit `81045cc08f1df797ecb86748c9bce09db62aeebd`; beta.6 is immutable published history at protected-`next` commit `66b795e76a76c6946b85e5eb878e3f576b4e3dbb` and failed its installed manual qualification. Capability Validation issues #610, #612, #614, #615, and #616 are closed not planned: no campaign ran, provider requests remain zero, and paid spend remains USD 0. #630 completed at exact protected-`next` merge `9703a7090fd3ef3600b4ab4e298b12f0faa05a1e`; corrective PR #637 merged at `68729161699b7592bea6984e1aa22c7b4b0833e8`; terminal-language corrective PR #641 merged at `e84d266734344397eec9a6bcd2e1a3a5070dc3ea`; beta.7 is authorized for installed manual testing, while #631 remains open and unqualified before later formal comparison. ### Directed multigraph phase evidence (passed) @@ -194,7 +194,7 @@ The following contract facts are historical. Issues #610 and #612, together with - `@lubab/madar@0.40.0-beta.4` is published under npm `next` from exact protected-`next` commit `9043320cfa08370e5cdd3911bfb9283005aa9912` and tree `f51d6e75e3b806dec6caf9ff0be43fc2ab5713fc`; tag `v0.40.0-beta.4` and the matching [GitHub prerelease](https://github.com/mohanagy/madar/releases/tag/v0.40.0-beta.4) target that commit. - The published npm 12.0.1 artifact is 102 files / 159,937 packed / 639,875 unpacked bytes with shasum `c5250a0d308b3d6df374851154ddb393a678a992`, integrity `sha512-772P+n4Cx55nqC+CAx8A1aTJ2rY4yk1hUH45lAlxNMMw4YRj8hhswgDiCwczS5hx1S3a+Z+KUv2jma/zWjQZ6w==`, and tarball SHA-256 `8bd8d501b8cd3546e16a5a1ddac1f7649434e685517e1171fbd5897515e76e6b`. -- npm `latest` remains `0.32.0`. Beta.5 and beta.6 are immutable published manual-test history; beta.6 failed its installed manual qualification, and the focused correction is not authorized for publication. Stable release, GitHub Release, MCP Registry publication, beta.6 tag, new comparative claims, and `main` remain out of scope. +- npm `latest` remains `0.32.0`. Beta.5 and beta.6 are immutable published manual-test history; beta.6 failed its installed manual qualification, the focused correction is merged, and beta.7 is authorized under npm `next` only after its release gates pass. Stable release, GitHub Release, MCP Registry publication, beta.7 tag, new comparative claims, and `main` remain out of scope. ### Semantic execution index #632 (passed) @@ -208,12 +208,12 @@ The following contract facts are historical. Issues #610 and #612, together with - The correction measures 44 production files / 15,719 LOC at `+3,462/-197/net +3,265`, below the unchanged net `+3,500` ceiling; 102 package files / 149,453 packed / 639,867 unpacked bytes; and a 60,271,172-byte real GoValidate graph, ratio `1.2292551823152718`, with 12,313 nodes / 32,717 edges / six exact queue channels / 42 typed channel edges. Its graph SHA-256 is `569af2dcd681c4db48124a47bceac7036a94b344f2a2f88e8cb35f6120711610`. Focused verification passes 247/247; the coverage suite passes 80 files / 785 tests at 85.85% statements (7,715/8,986), 79.46% branches (6,959/8,757), 92.37% functions (1,369/1,482), and 89.22% lines (6,481/7,264). The frozen corpus is attested as 6,889 files / 177,796,450 bytes / SHA-256 `3fa9a0a3edc13cf1439d572292601fff43c43a94f7a50948349f9a69123fa7a7`; five fresh indexing trials pass at 13.49-second median / `0.608754512635379` baseline ratio, and 100 warm retrieval samples pass at 238.83405145000143 ms p95. - Corrective reviewed head `da3e1ad360855c950cae6986a9774c45fcb527d0` passed all six [exact-head CI jobs](https://github.com/mohanagy/madar/actions/runs/30699876911), independent review, CodeRabbit and zero unresolved threads. Protected squash merge `c88823ecbeb6da6284cf74ecbd304e9315ffd4fa` preserved tree `b715764668b4296e9e8ab4da715374f47af137db`. No retrieval-v2 or publication work was part of #632. -### Obligation-driven retrieval #630 (complete) and #631 (manual test active) +### Obligation-driven retrieval #630 (complete) and #631 (beta.7 authorized, unqualified) - [#630](https://github.com/mohanagy/madar/issues/630) starts from protected `next` commit `c88823ecbeb6da6284cf74ecbd304e9315ffd4fa` and tree `b715764668b4296e9e8ab4da715374f47af137db`. It owns explicit obligations, bounded recovery, strict answerability and the `madar.retrieve` v2 dossier. - The completed #630 implementation measures 44 production files / 15,871 LOC at `+2,302/-2,150/net +152` with full-index diff SHA-256 `76340caade75454a96e546117c55128e1a69d15720dc60d1a800f5ceb4971693`; its replacement planner, workflow and hydrator total 1,424 source LOC / 60,933 emitted bytes, and its exact package is 102 files / 155,124 packed / 653,497 unpacked bytes. Owner [amendment](https://github.com/mohanagy/madar/issues/630#issuecomment-5153369147) changed only the replacement emitted ceiling and npm unpacked ceiling; both pass. The focused suite, full suite, coverage, portable CI oracle, all 14 real-GoValidate formulations, 100-sample warm reference, six exact-head CI jobs, CodeRabbit, independent review, and all 13 review threads passed before protected squash merge `9703a7090fd3ef3600b4ab4e298b12f0faa05a1e` preserved reviewed tree `5db67cbe19a9479409192558ea40b0ac8e3add78`. -- [#631](https://github.com/mohanagy/madar/issues/631) has an active focused terminal-language corrective after published beta.6 failed its installed exact-prompt and zero-fallback manual gate. The local correction is not a qualification result and has no npm-publication authority. -- Neither issue authorizes provider traffic or spend, a GitHub Release, external Registry metadata publication, a beta.6 tag, stable/`latest`, or `main`; any real comparator campaign requires separate owner authorization. +- [#631](https://github.com/mohanagy/madar/issues/631) remains open after published beta.6 failed its installed exact-prompt and zero-fallback manual gate. The focused correction merged in PR #641; beta.7 is authorized only for installed manual testing and is not a qualification result. +- Neither issue authorizes provider traffic or spend, a GitHub Release, external Registry metadata publication, a beta.7 tag, stable/`latest`, or `main`; any real comparator campaign requires separate owner authorization. ## Graph gates diff --git a/docs/designs/2026-07-19-core-reset.md b/docs/designs/2026-07-19-core-reset.md index 6b18f56f..5b9e65f3 100644 --- a/docs/designs/2026-07-19-core-reset.md +++ b/docs/designs/2026-07-19-core-reset.md @@ -3,7 +3,7 @@ > **Tracking issue:** [#577](https://github.com/mohanagy/madar/issues/577) > **Milestone:** [`v0.40.0 — Core Reset`](https://github.com/mohanagy/madar/milestone/7) > **Project:** [Madar Roadmap](https://github.com/users/mohanagy/projects/8) -> **Status:** accepted — semantic execution index #632 and obligation-driven retrieval #630 are complete; `0.40.0-beta.5` and `0.40.0-beta.6` are immutable published manual-test history; beta.6 published from protected `next` merge `66b795e76a76c6946b85e5eb878e3f576b4e3dbb` and then failed the installed terminal-language and zero-fallback manual gate; a focused unpublished #631 corrective is in progress; Capability Validation remains cancelled; npm `latest`, stable release, GitHub Release, MCP Registry publication, beta.6 tag, comparative claims, and `main` remain unauthorized +> **Status:** accepted — semantic execution index #632 and obligation-driven retrieval #630 are complete; `0.40.0-beta.5` and `0.40.0-beta.6` are immutable published manual-test history; beta.6 failed the installed terminal-language and zero-fallback gate; focused corrective PR #641 passed every protected gate and merged at `e84d266734344397eec9a6bcd2e1a3a5070dc3ea` with reviewed tree `5ffed3bc25cb537aafd3bb905ed9df08a7143d69`; `0.40.0-beta.7` is authorized under npm `next` for installed manual testing after its release gates pass but remains unpublished and unqualified; #631 remains open; Capability Validation remains cancelled; npm `latest`, stable release, GitHub Release, MCP Registry publication, beta.7 tag, comparative claims, and `main` remain unauthorized ## Decision @@ -508,6 +508,12 @@ The beta.5 owner test found one generic workflow-bound parser defect and one rea Matching owner receipts on [#631](https://github.com/mohanagy/madar/issues/631#issuecomment-5157473339) and [#629](https://github.com/mohanagy/madar/issues/629#issuecomment-5157473448) authorized exactly `@lubab/madar@0.40.0-beta.6` under npm dist-tag `next`. [Publication receipt 5157856602](https://github.com/mohanagy/madar/issues/631#issuecomment-5157856602) records protected merge `66b795e76a76c6946b85e5eb878e3f576b4e3dbb`, tree `ff57246a55e51459836946d6b5b9853d0cdcc372`, and release workflow 30746816714. The immutable artifact is 102 files / 155,257 packed / 653,996 unpacked bytes, shasum `4c98dd99cd321e741cabd689f0803d99e519f389`, integrity `sha512-o6L/BiJ1wrTWCaK537p60pGUC5i8zY0Zqz7NqD1zW4fJl/ewjF3cgysf4dbOkY4y49DkYDTG2qoUh1DGvq2Q0Q==`, and tarball SHA-256 `12d8abe1ac3d0945c654f4df2582ac1de63f2aeee55d82d4bf5b053d92036074`. [Installed-package receipt 5158293324](https://github.com/mohanagy/madar/issues/631#issuecomment-5158293324) then recorded an incomplete 6/7 finished-report result and natural-client repository fallback. The focused terminal-language corrective remains unpublished and is not the final #631 qualification. npm `latest`, stable release, GitHub Release, external MCP Registry publication, a beta.6 git tag, comparative claims, and `main` are forbidden. +## Release amendment — `0.40.0-beta.7` authorized terminal-language manual-test candidate + +Terminal-language corrective [PR #641](https://github.com/mohanagy/madar/pull/641) normalized only the accepted finished/done report terminals and observed recovery wording while preserving graph/index/query schema, CLI, MCP, dependencies and retrieval budgets. Exact head `8c21c687adce70a483073c5406e0e5b1356cfaea` passed all six required CI jobs in [run 30753189853](https://github.com/mohanagy/madar/actions/runs/30753189853), independent semantic, test/spec and governance review, CodeRabbit disposition and zero unresolved threads. Protected squash merge `e84d266734344397eec9a6bcd2e1a3a5070dc3ea` preserves reviewed tree `5ffed3bc25cb537aafd3bb905ed9df08a7143d69`. + +Matching owner receipts on [#631](https://github.com/mohanagy/madar/issues/631#issuecomment-5159641693) and [#629](https://github.com/mohanagy/madar/issues/629#issuecomment-5159642279) authorize exactly `@lubab/madar@0.40.0-beta.7` under npm dist-tag `next` after its separate release candidate passes all local gates, all six exact-head CI jobs, independent review, honest CodeRabbit disposition and zero unresolved threads. The exact candidate is 102 files / 155,339 packed / 654,026 unpacked bytes, shasum `1aafe5952aea2f353711d5af36fa564a147312f5`, integrity `sha512-K5CEUr2lRR1IoNCS9O74jMA7PDDgQMkdx3QM/cF+h17jyAj6Gt3Gpk8vkzKSz7SKFR44KgpnJeLkV5lXyzdgYw==`, and tarball SHA-256 `f4b33dacda9261eb0af8fa9302d5e51dd47e07235a7af9072b4dbfe5a50a21ca`. Publication is pending and does not qualify or close #631. npm `latest`, stable release, GitHub Release, external MCP Registry publication, a beta.7 git tag, comparative claims, and `main` are forbidden. + ## Migration and compatibility - `main` and `0.32.x` are maintenance-only while the RFC is active. @@ -642,3 +648,4 @@ On 2026-07-26 the owner approved the original Capability Validation proposal has | 2026-08-02 | `0.40.0-beta.5` manual-test release published | Owner receipts on #631 and #629 authorized exactly `@lubab/madar@0.40.0-beta.5`; protected merge `81045cc08f1df797ecb86748c9bce09db62aeebd` triggered trusted publication under npm `next`. npm `latest` remained `0.32.0`; no GitHub Release, Registry publication, beta.5 tag, comparative claim, or `main` action occurred. | | 2026-08-02 | Beta.5 corrective gaps fixed | PR #637 fixed generic workflow-bound parsing, ready-state client handoff guidance, and whole-trace zero-fallback evaluation, then merged to protected `next` at `68729161699b7592bea6984e1aa22c7b4b0833e8` with reviewed tree `4500d416d0e890b1dc67c9228a2cbb49cf4220a3`. Formal #631 qualification remains pending. | | 2026-08-02 | `0.40.0-beta.6` published; manual qualification failed | Owner receipts authorized exactly `@lubab/madar@0.40.0-beta.6`; protected merge `66b795e76a76c6946b85e5eb878e3f576b4e3dbb` published it under npm `next`. Installed-package receipt 5158293324 records the blocking 6/7 finished-report result and repository fallback. The focused correction is unpublished; npm `latest`, stable release, GitHub Release, Registry publication, beta.6 tag, comparative claims, and `main` remain forbidden. | +| 2026-08-02 | Terminal-language correction merged; beta.7 authorized | PR #641 passed all six exact-head CI jobs, independent review, CodeRabbit and zero threads, then merged to protected `next` as `e84d266734344397eec9a6bcd2e1a3a5070dc3ea`, preserving reviewed tree `5ffed3bc25cb537aafd3bb905ed9df08a7143d69`. Owner receipts authorize exact `0.40.0-beta.7` publication under npm `next` after its separate release gates pass; #631 remains open and unqualified. | diff --git a/docs/mcp-registry/server.json b/docs/mcp-registry/server.json index 16c0af19..2298c4e7 100644 --- a/docs/mcp-registry/server.json +++ b/docs/mcp-registry/server.json @@ -9,13 +9,13 @@ "source": "github", "url": "https://github.com/mohanagy/madar" }, - "version": "0.40.0-beta.6", + "version": "0.40.0-beta.7", "packages": [ { "registryType": "npm", "registryBaseUrl": "https://registry.npmjs.org", "identifier": "@lubab/madar", - "version": "0.40.0-beta.6", + "version": "0.40.0-beta.7", "runtimeHint": "npx", "transport": { "type": "stdio" diff --git a/docs/release.md b/docs/release.md index 7a407af8..62c47463 100644 --- a/docs/release.md +++ b/docs/release.md @@ -6,7 +6,7 @@ Use this checklist when preparing a new `madar` release. Preparation and approva ## 1. Prepare the release commit -1. Update the package version without creating a pre-merge tag. For this beta, run `npm version 0.40.0-beta.6 --no-git-tag-version`. +1. Update the package version without creating a pre-merge tag. For this beta, run `npm version 0.40.0-beta.7 --no-git-tag-version`. 2. Review `package.json` and `package-lock.json` to confirm the new version is correct. 3. Update `CHANGELOG.md` with the user-visible changes in the release. 4. Make sure any linked docs, examples, install flows, and `docs/mcp-registry/server.json` reflect the new behavior. @@ -17,15 +17,18 @@ Use this checklist when preparing a new `madar` release. Preparation and approva From the repository root: +Release preparation for this beta requires Node.js `22.22.3` or newer within the Node 22 release line. npm `12.0.1` does not support Node 20 or earlier Node 22 releases. + ```bash +npm install --global npm@12.0.1 npm ci npm run release:verify npm run registry:validate npm run typecheck npm run build +npm sbom --sbom-format cyclonedx --package-lock-only > sbom.cdx.json npm run test:run npm pack --dry-run -npm sbom --sbom-format cyclonedx --package-lock-only > sbom.cdx.json ``` `npm run release:verify` locks the public package metadata, changelog version entry, and npm-visible README links before publish so repository/documentation drift is caught in one pass. @@ -60,7 +63,7 @@ After the verification steps are green: 1. Configure the npm package's trusted publisher for GitHub Actions workflow filename `release.yml`, repository `mohanagy/madar`, and no environment. The workflow uses GitHub OIDC and contains no registry token or no-provenance fallback. If trusted publishing or provenance is unavailable, stop before publication. 2. Push and merge the verified release commit so the published README links already exist on the target release branch (`main` for stable releases, `next` for prereleases). -3. For `0.40.0-beta.6`, `.github/workflows/release.yml` runs only when the versioned `package.json` reaches protected `next`. It requires the workflow SHA to equal the live protected `next` tip, reruns every release gate, and then runs `npm publish --tag next --access public --provenance` through npm Trusted Publishing. +3. For `0.40.0-beta.7`, `.github/workflows/release.yml` runs only when the versioned `package.json` reaches protected `next`. It requires the workflow SHA to equal the live protected `next` tip, reruns every release gate, and then runs `npm publish --tag next --access public --provenance` through npm Trusted Publishing. 4. The workflow verifies the exact npm version, immutable shasum and integrity, `next` dist-tag, unchanged `latest` dist-tag, Trusted Publishing provenance, and registry signatures. If publication succeeds but later verification is interrupted, the same exact-version path verifies the immutable artifact rather than attempting to overwrite it. 5. This beta explicitly creates no git tag or GitHub Release and does not dispatch the separate **Publish MCP Registry metadata** workflow. Stable releases and later Registry publication require separate owner authorization and a separately reviewed workflow change. 6. Before posting on npm/GitHub directories, social/news sites, or videos/blogs, complete the copied proof-first launch checklist from [`docs/launch-checklist.md`](./launch-checklist.md) so every public surface starts from a dated receipt plus caveats. diff --git a/docs/roadmap.md b/docs/roadmap.md index c859820b..a119183f 100644 --- a/docs/roadmap.md +++ b/docs/roadmap.md @@ -11,7 +11,7 @@ Madar is executing an accepted Core Reset. The roadmap is outcome-driven: work a - [Removal manifest](core-reset/removal-manifest.yml) — keep, rebuild, move, delete, and defer decisions - [Scorecard](core-reset/scorecard.md) — technical and business evidence gates -The RFC is **accepted**. Scope and baseline, Directed multigraph, Canonical TypeScript/JavaScript index, the combined legacy/non-code deletion, Generation and reconciliation, Evidence-path query, Thin Delivery, Evaluation Tooling Isolation, the bounded retrieval repairs in [#618](https://github.com/mohanagy/madar/issues/618), [#622](https://github.com/mohanagy/madar/issues/622), and [#625](https://github.com/mohanagy/madar/issues/625), semantic execution index [#632](https://github.com/mohanagy/madar/issues/632), and obligation-driven retrieval [#630](https://github.com/mohanagy/madar/issues/630) have passed. Capability Validation and the earlier Native-vs-Graphify campaign are cancelled history. `0.40.0-beta.5` and `0.40.0-beta.6` are immutable published manual-test history. Beta.6 was published from protected `next` merge `66b795e76a76c6946b85e5eb878e3f576b4e3dbb`, then its installed-package test recorded a blocking terminal-language and zero-fallback failure on [#631](https://github.com/mohanagy/madar/issues/631#issuecomment-5158293324). A focused unpublished corrective is in progress. npm `latest` remains `0.32.0`; stable release, GitHub Release, MCP Registry publication, a beta.6 tag, comparative claims, and `main` remain unauthorized. +The RFC is **accepted**. Scope and baseline, Directed multigraph, Canonical TypeScript/JavaScript index, the combined legacy/non-code deletion, Generation and reconciliation, Evidence-path query, Thin Delivery, Evaluation Tooling Isolation, the bounded retrieval repairs in [#618](https://github.com/mohanagy/madar/issues/618), [#622](https://github.com/mohanagy/madar/issues/622), and [#625](https://github.com/mohanagy/madar/issues/625), semantic execution index [#632](https://github.com/mohanagy/madar/issues/632), and obligation-driven retrieval [#630](https://github.com/mohanagy/madar/issues/630) have passed. Capability Validation and the earlier Native-vs-Graphify campaign are cancelled history. `0.40.0-beta.5` and `0.40.0-beta.6` are immutable published manual-test history. Beta.6 failed its installed terminal-language and zero-fallback gate; the focused correction passed protected review and merged as `e84d266734344397eec9a6bcd2e1a3a5070dc3ea` with reviewed tree `5ffed3bc25cb537aafd3bb905ed9df08a7143d69`. `0.40.0-beta.7` is authorized under npm `next` for installed manual testing after its separate release gates pass, but remains unpublished and unqualified. [#631](https://github.com/mohanagy/madar/issues/631) remains open. npm `latest` remains `0.32.0`; stable release, GitHub Release, MCP Registry publication, a beta.7 tag, comparative claims, and `main` remain unauthorized. ## Passed — directed multigraph @@ -185,9 +185,13 @@ The original owner receipts on [#631](https://github.com/mohanagy/madar/issues/6 The beta.5 owner test exposed a generic workflow-bound parsing defect and a ready-state client handoff defect. Corrective [PR #637](https://github.com/mohanagy/madar/pull/637) fixed those gaps with zero net production LOC and merged to protected `next` at `68729161699b7592bea6984e1aa22c7b4b0833e8`, preserving reviewed tree `4500d416d0e890b1dc67c9228a2cbb49cf4220a3`. Matching owner receipts authorized exactly `@lubab/madar@0.40.0-beta.6`; [publication receipt 5157856602](https://github.com/mohanagy/madar/issues/631#issuecomment-5157856602) records protected merge `66b795e76a76c6946b85e5eb878e3f576b4e3dbb`, tree `ff57246a55e51459836946d6b5b9853d0cdcc372`, and release workflow 30746816714. The immutable artifact is 102 files / 155,257 packed / 653,996 unpacked bytes with shasum `4c98dd99cd321e741cabd689f0803d99e519f389` and tarball SHA-256 `12d8abe1ac3d0945c654f4df2582ac1de63f2aeee55d82d4bf5b053d92036074`. -## In progress — beta.6 manual qualification failed; focused corrective #631 +## Authorized terminal-language manual-test candidate — `0.40.0-beta.7` -[#631](https://github.com/mohanagy/madar/issues/631) remains in progress. The installed beta.6 exact prompt returned incomplete at 6/7 and its natural Claude session used repository fallback, so beta.6 did not qualify. The focused terminal-language corrective is unpublished; even after its local exact-prompt gate passes, the frozen ten-stage comparison against `0.32.0`, `0.40.0-beta.4`, one pinned Graphify commit, and a no-tool control remains pending. Provider traffic or spend, npm publication, stable/`latest`, GitHub Release, Registry publication, tag, comparative claims, and `main` remain unauthorized. +The installed beta.6 exact prompt returned incomplete at 6/7 and its natural Claude session used repository fallback, so beta.6 did not qualify. Terminal-language corrective [PR #641](https://github.com/mohanagy/madar/pull/641) passed all six exact-head CI jobs, independent review, CodeRabbit disposition and zero unresolved threads, then merged to protected `next` at `e84d266734344397eec9a6bcd2e1a3a5070dc3ea` with reviewed tree `5ffed3bc25cb537aafd3bb905ed9df08a7143d69`. Matching owner receipts on [#631](https://github.com/mohanagy/madar/issues/631#issuecomment-5159641693) and [#629](https://github.com/mohanagy/madar/issues/629#issuecomment-5159642279) authorize exactly `@lubab/madar@0.40.0-beta.7` under npm dist-tag `next` after the separate release candidate passes every gate. The candidate is 102 files / 155,339 packed / 654,026 unpacked bytes with shasum `1aafe5952aea2f353711d5af36fa564a147312f5` and tarball SHA-256 `f4b33dacda9261eb0af8fa9302d5e51dd47e07235a7af9072b4dbfe5a50a21ca`. + +## In progress — beta.7 authorized; #631 remains unqualified + +[#631](https://github.com/mohanagy/madar/issues/631) remains open and in progress. Beta.7 publication is only the next installed manual-test boundary; it is not the frozen ten-stage comparison against `0.32.0`, `0.40.0-beta.4`, one pinned Graphify commit, and a no-tool control. Provider traffic or spend, stable/`latest`, GitHub Release, Registry publication, a tag, comparative claims, and `main` remain unauthorized. ## Validation — release decision diff --git a/package-lock.json b/package-lock.json index 0ad9fdfe..8e9d594b 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "@lubab/madar", - "version": "0.40.0-beta.6", + "version": "0.40.0-beta.7", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@lubab/madar", - "version": "0.40.0-beta.6", + "version": "0.40.0-beta.7", "license": "MIT", "dependencies": { "gpt-tokenizer": "^3.4.0", diff --git a/package.json b/package.json index bd41f34d..5178e212 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@lubab/madar", - "version": "0.40.0-beta.6", + "version": "0.40.0-beta.7", "mcpName": "io.github.mohanagy/madar", "description": "Give AI coding agents a small, authenticated evidence path through large TypeScript and JavaScript repositories.", "license": "MIT", diff --git a/sbom.cdx.json b/sbom.cdx.json index 1e23d6d5..b4f5521c 100644 --- a/sbom.cdx.json +++ b/sbom.cdx.json @@ -2,10 +2,10 @@ "$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json", "bomFormat": "CycloneDX", "specVersion": "1.5", - "serialNumber": "urn:uuid:c6b28dd1-6a13-44c0-9c26-c431364c2402", + "serialNumber": "urn:uuid:893079b8-a154-45b4-aef6-f78cc0063adc", "version": 1, "metadata": { - "timestamp": "2026-08-02T11:22:19.155Z", + "timestamp": "2026-08-02T18:31:08.236Z", "lifecycles": [ { "phase": "pre-build" @@ -19,14 +19,14 @@ } ], "component": { - "bom-ref": "@lubab/madar@0.40.0-beta.6", + "bom-ref": "@lubab/madar@0.40.0-beta.7", "type": "library", "name": "@lubab/madar", - "version": "0.40.0-beta.6", + "version": "0.40.0-beta.7", "scope": "required", "author": "mohanagy", "description": "Give AI coding agents a small, authenticated evidence path through large TypeScript and JavaScript repositories.", - "purl": "pkg:npm/%40lubab/madar@0.40.0-beta.6", + "purl": "pkg:npm/%40lubab/madar@0.40.0-beta.7", "properties": [], "externalReferences": [ { @@ -3103,7 +3103,7 @@ ], "dependencies": [ { - "ref": "@lubab/madar@0.40.0-beta.6", + "ref": "@lubab/madar@0.40.0-beta.7", "dependsOn": [ "gpt-tokenizer@3.4.0", "typescript@6.0.3", diff --git a/tests/unit/core-reset-governance.test.ts b/tests/unit/core-reset-governance.test.ts index 8f63c225..442bc118 100644 --- a/tests/unit/core-reset-governance.test.ts +++ b/tests/unit/core-reset-governance.test.ts @@ -543,6 +543,21 @@ const TERMINAL_LANGUAGE_PACKAGE = { 'sha512-/is0gABnCpimVQWLdvyFBtqhhrwSkuwgYtzQIp8FDBcSqAoLqXK4E5C3CTHqLxIWWKAtNUx8o90B7TOtMb9VCg==', npm_artifact_sha256: 'f341a2b3e36d074b7cdad2656bb4895393b82894223489778dad7ac623069621', } as const +const BETA_7_AUTHORIZATION = + 'https://github.com/mohanagy/madar/issues/631#issuecomment-5159641693' +const BETA_7_PARENT_AUTHORIZATION = + 'https://github.com/mohanagy/madar/issues/629#issuecomment-5159642279' +const BETA_7_PREPARATION_ANCHOR = 'e84d266734344397eec9a6bcd2e1a3a5070dc3ea' +const BETA_7_PREPARATION_TREE = '5ffed3bc25cb537aafd3bb905ed9df08a7143d69' +const BETA_7_PACKAGE = { + npm_files: 102, + npm_packed_bytes: 155_339, + npm_unpacked_bytes: 654_026, + npm_shasum: '1aafe5952aea2f353711d5af36fa564a147312f5', + npm_integrity: + 'sha512-K5CEUr2lRR1IoNCS9O74jMA7PDDgQMkdx3QM/cF+h17jyAj6Gt3Gpk8vkzKSz7SKFR44KgpnJeLkV5lXyzdgYw==', + npm_artifact_sha256: 'f4b33dacda9261eb0af8fa9302d5e51dd47e07235a7af9072b4dbfe5a50a21ca', +} as const const NO_FALLBACK_CORRECTIVE_AUTHORIZATION = 'https://github.com/mohanagy/madar/issues/631#issuecomment-5157008370' const NO_FALLBACK_CORRECTIVE_PARENT = @@ -983,7 +998,8 @@ describe('core reset governance', () => { expect(roadmap).toContain('## Completed — obligation-driven retrieval #630') expect(roadmap).toContain('## Published manual-test candidate — `0.40.0-beta.5`') expect(roadmap).toContain('## Published corrective manual-test candidate — `0.40.0-beta.6`') - expect(roadmap).toContain('## In progress — beta.6 manual qualification failed; focused corrective #631') + expect(roadmap).toContain('## Authorized terminal-language manual-test candidate — `0.40.0-beta.7`') + expect(roadmap).toContain('## In progress — beta.7 authorized; #631 remains unqualified') expect(roadmap).toContain(CAPABILITY_VALIDATION_PROPOSAL_SHA256) expect(roadmap).toContain(CAPABILITY_VALIDATION_OWNER_APPROVAL) expect(roadmap).toContain(CAPABILITY_VALIDATION_RFC_APPROVAL) @@ -1087,6 +1103,7 @@ describe('core reset governance', () => { expect(design).toContain('## Completed amendment — obligation-driven retrieval #630') expect(design).toContain('## Release amendment — `0.40.0-beta.5` published manual-test candidate') expect(design).toContain('## Release amendment — `0.40.0-beta.6` corrective manual-test candidate') + expect(design).toContain('## Release amendment — `0.40.0-beta.7` authorized terminal-language manual-test candidate') expect(design).toContain(CAPABILITY_VALIDATION_PROPOSAL_SHA256) expect(design).toContain(CAPABILITY_VALIDATION_OWNER_APPROVAL) expect(design).toContain(CAPABILITY_VALIDATION_RFC_APPROVAL) @@ -1183,10 +1200,10 @@ describe('core reset governance', () => { expect(scorecard).toContain('| Capability validation v2 | **Stopped / not planned**') expect(scorecard).toContain('| Retrieval regression #618 | **Passed**') expect(scorecard).toContain('| Retrieval regression #625 | **Passed**') - expect(scorecard).toContain('| Beta release | **Beta.5 and beta.6 published**') + expect(scorecard).toContain('| Beta release | **Beta.5 and beta.6 published; beta.7 authorized**') expect(scorecard).toContain('| Semantic execution index #632 | **Passed**') expect(scorecard).toContain('| Obligation-driven retrieval #630 | **Passed**') - expect(scorecard).toContain('| No-fallback qualification #631 | **In progress — beta.6 manual gate failed**') + expect(scorecard).toContain('| No-fallback qualification #631 | **In progress — beta.7 unqualified**') expect(scorecard).toContain(CAPABILITY_VALIDATION_PROPOSAL_SHA256) expect(scorecard).toContain(CAPABILITY_VALIDATION_OWNER_APPROVAL) expect(scorecard).toContain(CAPABILITY_VALIDATION_RFC_APPROVAL) @@ -1232,7 +1249,7 @@ describe('core reset governance', () => { expect(scorecard).toContain('every warmup/measured result must remain correct; an empty positive result fails') expect(scorecard).toContain('| Retrieval regression #622 | **Passed**') expect(scorecard).toContain('Issues `#622`, `#625`, `#632`, and `#630` are complete on `next`') - expect(scorecard).toContain('focused unpublished corrective before later formal qualification') + expect(scorecard).toContain('beta.7 is authorized for installed manual testing, while #631 remains open and unqualified') expect(scorecard).toContain(OBLIGATION_RETRIEVAL_MERGE) expect(scorecard).toContain('1,424 source LOC / 60,933 emitted bytes') expect(scorecard).toContain( @@ -1387,6 +1404,30 @@ describe('core reset governance', () => { tag: string main_target: string } + terminal_language_manual_test_candidate: { + version: string + preparation_anchor_commit: string + preparation_anchor_tree: string + authorization_receipt: string + parent_authorization_receipt: string + target_branch: string + npm_dist_tag: string + publication_state: string + qualification_state: string + package_candidate: { + npm_files: number + npm_packed_bytes: number + npm_unpacked_bytes: number + npm_shasum: string + npm_integrity: string + npm_artifact_sha256: string + } + stable_or_latest: string + github_release: string + registry_metadata_publication: string + tag: string + main_target: string + } } items: Array<{ id: string @@ -1534,9 +1575,9 @@ describe('core reset governance', () => { base_commit: OBLIGATION_RETRIEVAL_BASE, completed_phase_commit: OBLIGATION_RETRIEVAL_MERGE, ...OBLIGATION_RETRIEVAL_SOURCE, - ...TERMINAL_LANGUAGE_PACKAGE, + ...BETA_7_PACKAGE, measurement_state: 'source_and_package_exact', - snapshot_scope: 'terminal_language_corrective_unpublished_candidate', + snapshot_scope: 'terminal_language_beta7_unqualified_manual_test_package_candidate', }) expect(manifest.current.release_candidate).toMatchObject({ version: '0.40.0-beta.4', @@ -1604,6 +1645,23 @@ describe('core reset governance', () => { tag: 'forbidden', main_target: 'forbidden', }) + expect(manifest.current.terminal_language_manual_test_candidate).toMatchObject({ + version: '0.40.0-beta.7', + preparation_anchor_commit: BETA_7_PREPARATION_ANCHOR, + preparation_anchor_tree: BETA_7_PREPARATION_TREE, + authorization_receipt: BETA_7_AUTHORIZATION, + parent_authorization_receipt: BETA_7_PARENT_AUTHORIZATION, + target_branch: 'next', + npm_dist_tag: 'next', + publication_state: 'authorized_pending_protected_next_release_merge', + qualification_state: 'unqualified_pending_owner_manual_test_and_formal_631_gate', + package_candidate: BETA_7_PACKAGE, + stable_or_latest: 'forbidden', + github_release: 'forbidden', + registry_metadata_publication: 'forbidden', + tag: 'forbidden', + main_target: 'forbidden', + }) expect(manifest.rules.length).toBeGreaterThan(0) expect(manifest.items.length).toBeGreaterThan(10) @@ -2504,6 +2562,8 @@ describe('core reset governance', () => { dependency_state: `satisfied_by_${OBLIGATION_RETRIEVAL_MERGE}`, beta_publication: 'authorized_exact_0.40.0-beta.5_by_receipt_5155128419', corrective_beta_publication: 'published_exact_0.40.0-beta.6_by_receipt_5157856602', + terminal_language_beta_publication: + 'authorized_exact_0.40.0-beta.7_by_receipt_5159641693', stable_or_latest_publication: 'forbidden', github_release: 'forbidden', registry_metadata_publication: 'forbidden', @@ -2531,11 +2591,20 @@ describe('core reset governance', () => { package_candidate: NO_FALLBACK_CORRECTIVE_PACKAGE, }, terminal_language_corrective: { - status: 'local_candidate', + status: 'merged_unpublished_candidate', authorization_receipt: TERMINAL_LANGUAGE_AUTHORIZATION, protected_base: TERMINAL_LANGUAGE_BASE, protected_base_tree: TERMINAL_LANGUAGE_TREE, target_branch: 'next', + pull_request: 'https://github.com/mohanagy/madar/pull/641', + reviewed_head: '8c21c687adce70a483073c5406e0e5b1356cfaea', + reviewed_tree: BETA_7_PREPARATION_TREE, + merge_commit: BETA_7_PREPARATION_ANCHOR, + merge_tree: BETA_7_PREPARATION_TREE, + ci_run: 'https://github.com/mohanagy/madar/actions/runs/30753189853', + independent_review: 'passed_no_blocker', + coderabbit: 'passed_with_non_blocking_docstring_warning', + unresolved_threads: 0, modified_sources: ['src/domain/query/plan.ts'], test_sources: [ 'tests/unit/query-plan.test.ts', @@ -2589,6 +2658,23 @@ describe('core reset governance', () => { tag: 'forbidden', main_target: 'forbidden', }, + terminal_language_release: { + version: '0.40.0-beta.7', + preparation_anchor_commit: BETA_7_PREPARATION_ANCHOR, + preparation_anchor_tree: BETA_7_PREPARATION_TREE, + authorization_receipt: BETA_7_AUTHORIZATION, + parent_authorization_receipt: BETA_7_PARENT_AUTHORIZATION, + target_branch: 'next', + npm_dist_tag: 'next', + publication_state: 'authorized_pending_protected_next_release_merge', + qualification_state: 'unqualified_pending_owner_manual_test_and_formal_631_gate', + package_candidate: BETA_7_PACKAGE, + stable_or_latest: 'forbidden', + github_release: 'forbidden', + registry_metadata_publication: 'forbidden', + tag: 'forbidden', + main_target: 'forbidden', + }, }) expect(noFallbackQualification.corrective.constraints.publication).toBe('forbidden') const correctiveSources = execFileSync( @@ -3056,7 +3142,7 @@ describe('core reset governance', () => { completed_phase_commit: OBLIGATION_RETRIEVAL_MERGE, ...OBLIGATION_RETRIEVAL_SOURCE, measurement_state: 'source_and_package_exact', - snapshot_scope: 'terminal_language_corrective_unpublished_candidate', + snapshot_scope: 'terminal_language_beta7_unqualified_manual_test_package_candidate', }) expect(manifest.items.filter((item) => item.status === 'in_progress').map((item) => item.id)) .toEqual([NO_FALLBACK_QUALIFICATION_ID]) @@ -3918,9 +4004,9 @@ describe('core reset governance', () => { base_commit: OBLIGATION_RETRIEVAL_BASE, completed_phase_commit: OBLIGATION_RETRIEVAL_MERGE, ...OBLIGATION_RETRIEVAL_SOURCE, - npm_files: TERMINAL_LANGUAGE_PACKAGE.npm_files, - npm_packed_bytes: TERMINAL_LANGUAGE_PACKAGE.npm_packed_bytes, - npm_unpacked_bytes: TERMINAL_LANGUAGE_PACKAGE.npm_unpacked_bytes, + npm_files: BETA_7_PACKAGE.npm_files, + npm_packed_bytes: BETA_7_PACKAGE.npm_packed_bytes, + npm_unpacked_bytes: BETA_7_PACKAGE.npm_unpacked_bytes, }) expect(manifest.items.filter((item) => item.status === 'in_progress').map((item) => item.id)) .toEqual([NO_FALLBACK_QUALIFICATION_ID]) @@ -4328,7 +4414,7 @@ describe('core reset governance', () => { }) expect(currentPackage).toEqual({ ...implementationPackage, - version: '0.40.0-beta.6', + version: '0.40.0-beta.7', files: implementationPackage.files.filter( (path) => !SEMANTIC_EXECUTION_PACKAGE_EXCLUSIONS.includes( path as (typeof SEMANTIC_EXECUTION_PACKAGE_EXCLUSIONS)[number], @@ -4352,12 +4438,12 @@ describe('core reset governance', () => { const currentLock = JSON.parse(read('package-lock.json')) as any expect(currentLock).toEqual({ ...implementationLock, - version: '0.40.0-beta.6', + version: '0.40.0-beta.7', packages: { ...implementationLock.packages, '': { ...implementationLock.packages[''], - version: '0.40.0-beta.6', + version: '0.40.0-beta.7', }, }, }) @@ -5318,11 +5404,11 @@ describe('core reset governance', () => { base_commit: OBLIGATION_RETRIEVAL_BASE, completed_phase_commit: OBLIGATION_RETRIEVAL_MERGE, ...OBLIGATION_RETRIEVAL_SOURCE, - npm_files: TERMINAL_LANGUAGE_PACKAGE.npm_files, - npm_packed_bytes: TERMINAL_LANGUAGE_PACKAGE.npm_packed_bytes, - npm_unpacked_bytes: TERMINAL_LANGUAGE_PACKAGE.npm_unpacked_bytes, + npm_files: BETA_7_PACKAGE.npm_files, + npm_packed_bytes: BETA_7_PACKAGE.npm_packed_bytes, + npm_unpacked_bytes: BETA_7_PACKAGE.npm_unpacked_bytes, measurement_state: 'source_and_package_exact', - snapshot_scope: 'terminal_language_corrective_unpublished_candidate', + snapshot_scope: 'terminal_language_beta7_unqualified_manual_test_package_candidate', }) expect(manifest.items.filter((item) => item.status === 'in_progress').map((item) => item.id)) .toEqual([NO_FALLBACK_QUALIFICATION_ID]) @@ -6964,7 +7050,8 @@ describe('core reset governance', () => { expect(governance).toContain('## Completed — obligation-driven retrieval #630') expect(governance).toContain('## Published manual-test candidate — `0.40.0-beta.5`') expect(governance).toContain('## Published corrective manual-test candidate — `0.40.0-beta.6`') - expect(governance).toContain('## In progress — beta.6 manual qualification failed; focused corrective #631') + expect(governance).toContain('## Authorized terminal-language manual-test candidate — `0.40.0-beta.7`') + expect(governance).toContain('## In progress — beta.7 authorized; #631 remains unqualified') expect(governance).toContain('## Stopped amendment — capability validation v1') expect(governance).toContain('## Historical accepted amendment — capability validation v2') expect(governance).toContain('## Cancelled amendment — capability validation') @@ -6976,6 +7063,7 @@ describe('core reset governance', () => { expect(governance).toContain('## Completed amendment — obligation-driven retrieval #630') expect(governance).toContain('Release amendment — `0.40.0-beta.5` published manual-test candidate') expect(governance).toContain('Release amendment — `0.40.0-beta.6` corrective manual-test candidate') + expect(governance).toContain('Release amendment — `0.40.0-beta.7` authorized terminal-language manual-test candidate') expect(governance).toContain('Release amendment — `0.40.0-beta.3` published') expect(governance).toContain('Release amendment — `0.40.0-beta.4` ready') expect(governance).toContain('/compilerOptions/removeComments=true') diff --git a/tests/unit/release-hygiene.test.ts b/tests/unit/release-hygiene.test.ts index 43eb3443..0eecbe13 100644 --- a/tests/unit/release-hygiene.test.ts +++ b/tests/unit/release-hygiene.test.ts @@ -9,6 +9,15 @@ interface PackageManifest { scripts?: Record } +interface CycloneDxSbom { + serialNumber: string + metadata: { + timestamp: string + tools: Array<{ vendor: string; name: string; version: string }> + component: { name: string; version: string; purl: string } + } +} + function loadFile(path: string): string { return readFileSync(join(process.cwd(), path), 'utf8') } @@ -112,14 +121,43 @@ describe('release hygiene', () => { it('documents the release verification command in the release checklist', () => { const releaseDoc = loadFile('docs/release.md') + const nodePrerequisiteIndex = releaseDoc.indexOf( + 'Node.js `22.22.3` or newer within the Node 22 release line', + ) + const npmPinIndex = releaseDoc.indexOf('npm install --global npm@12.0.1') + const sbomIndex = releaseDoc.indexOf( + 'npm sbom --sbom-format cyclonedx --package-lock-only > sbom.cdx.json', + ) + const testIndex = releaseDoc.indexOf('npm run test:run') expect(releaseDoc).toContain('npm run release:verify') - expect(releaseDoc).toContain('npm version 0.40.0-beta.6 --no-git-tag-version') + expect(releaseDoc).toContain('npm version 0.40.0-beta.7 --no-git-tag-version') expect(releaseDoc).toContain('`main` for stable releases, `next` for prereleases') expect(releaseDoc).toContain('npm publish --tag next --access public --provenance') + expect(nodePrerequisiteIndex).toBeGreaterThan(0) + expect(npmPinIndex).toBeGreaterThan(nodePrerequisiteIndex) + expect(npmPinIndex).toBeGreaterThan(0) + expect(sbomIndex).toBeGreaterThan(npmPinIndex) + expect(testIndex).toBeGreaterThan(sbomIndex) + }) + + it('keeps a regenerated beta.7 SBOM newer than the corrective merge anchor', () => { + const sbom = JSON.parse(loadFile('sbom.cdx.json')) as CycloneDxSbom + + expect(sbom.serialNumber).toMatch(/^urn:uuid:[0-9a-f-]{36}$/) + expect(sbom.serialNumber).not.toBe('urn:uuid:c6b28dd1-6a13-44c0-9c26-c431364c2402') + expect(Date.parse(sbom.metadata.timestamp)).toBeGreaterThan( + Date.parse('2026-08-02T15:09:37Z'), + ) + expect(sbom.metadata.tools).toContainEqual({ vendor: 'npm', name: 'cli', version: '12.0.1' }) + expect(sbom.metadata.component).toMatchObject({ + name: '@lubab/madar', + version: '0.40.0-beta.7', + purl: 'pkg:npm/%40lubab/madar@0.40.0-beta.7', + }) }) - it('publishes beta.6 from a protected next push without a tag or GitHub Release', () => { + it('publishes beta.7 from a protected next push without a tag or GitHub Release', () => { const releaseWorkflow = loadFile('.github/workflows/release.yml') expect(releaseWorkflow).toContain('branches:') @@ -148,15 +186,15 @@ describe('release hygiene', () => { expect(releaseWorkflow).toContain('test "$RELEASE_SHA" = "$GITHUB_SHA"') expect(releaseWorkflow).toContain('test "$GITHUB_REF" = "refs/heads/next"') expect(releaseWorkflow).toContain('verify_forbidden_release_artifacts_absent') - expect(releaseWorkflow).toContain('if [[ "$VERSION" != "0.40.0-beta.6" ]]') + expect(releaseWorkflow).toContain('if [[ "$VERSION" != "0.40.0-beta.7" ]]') expect(releaseWorkflow).toContain('npm run publish:next') expect(releaseWorkflow).toContain('dist.attestations.provenance') expect(releaseWorkflow).toContain('cd "$VERIFY_DIR"') expect(releaseWorkflow).toContain('npm audit signatures') expect(releaseWorkflow).not.toContain('npm --prefix "$VERIFY_DIR" init') - expect(releaseWorkflow).toContain('4c98dd99cd321e741cabd689f0803d99e519f389') + expect(releaseWorkflow).toContain('1aafe5952aea2f353711d5af36fa564a147312f5') expect(releaseWorkflow).toContain( - 'sha512-o6L/BiJ1wrTWCaK537p60pGUC5i8zY0Zqz7NqD1zW4fJl/ewjF3cgysf4dbOkY4y49DkYDTG2qoUh1DGvq2Q0Q==', + 'sha512-K5CEUr2lRR1IoNCS9O74jMA7PDDgQMkdx3QM/cF+h17jyAj6Gt3Gpk8vkzKSz7SKFR44KgpnJeLkV5lXyzdgYw==', ) expect(releaseWorkflow).toContain('LATEST_VERSION" == "0.32.0"') expect(publishIndex).toBeGreaterThan(0) @@ -164,7 +202,7 @@ describe('release hygiene', () => { expect(releaseWorkflow).not.toContain('--no-provenance') }) - it('proves beta.6 has no tag or GitHub Release before and after publication', () => { + it('proves beta.7 has no tag or GitHub Release before and after publication', () => { const releaseWorkflow = loadFile('.github/workflows/release.yml') const absenceChecks = releaseWorkflow.match( /node \.github\/scripts\/verify-forbidden-release-artifacts\.mjs "\$TAG"/g,