Skip to content

chore(main): release engine-and-dependents libraries#9171

Merged
JSONbored merged 2 commits into
mainfrom
release-please--branches--main--groups--engine-and-dependents
Jul 27, 2026
Merged

chore(main): release engine-and-dependents libraries#9171
JSONbored merged 2 commits into
mainfrom
release-please--branches--main--groups--engine-and-dependents

Conversation

@JSONbored

@JSONbored JSONbored commented Jul 27, 2026

Copy link
Copy Markdown
Owner

🤖 I have created a release beep boop

engine: 3.15.2

3.15.2 (2026-07-27)

Fixes

  • orb: bind identity to credentials instead of renameable logins or trusted request bodies (#9121, #9125, #9126, #9131) (#9177) (6860b26)
  • security: close a guardrail bypass, a repo-scope auth gap, and fail-open telemetry ingest (#9112) (6dc0e3c)
  • trust: commit the decision record to what actually decided, record the holdout draw, and fix the attestation envelope's width and freshness (#9178) (0eadcbd)
mcp: 3.15.2

3.15.2 (2026-07-27)

Features

  • mcp: add loopover-mcp agent start CLI subcommand (#8443) (c2190cd)
  • mcp: add remote + stdio + CLI surfaces for the selftune override audit (#7997) (050f8cb)
  • mcp: register loopover_check_improvement_potential stdio tool (#7963) (a4c15d6)
  • mcp: register loopover_generate_contributor_issue_drafts as a local stdio tool (#7989) (6a55b8d)
  • mcp: register loopover_get_agent_audit_feed as a local stdio tool (#7971) (84a7878)
  • mcp: register loopover_get_automation_state as a local stdio tool (#7966) (ca738de)
  • mcp: register loopover_get_contributor_profile as a local stdio tool (#7760) (#7958) (3790ecd)
  • mcp: register loopover_get_repo_onboarding_pack as a local (#7977) (b9aa25f)
  • mcp: register loopover_list_notifications as a local stdio tool (#7761) (#7965) (8c2950c)
  • mcp: register loopover_mark_notifications_read as a local stdio tool (#7950) (fa3581d), closes #7762
  • mcp: register loopover_propose_action as a local stdio tool (#7991) (7c1a21e)
  • mcp: register loopover_refresh_repo_docs as a local stdio tool (#7974) (4dccaa6), closes #7754
  • mcp: register loopover_watch_issues as a local stdio tool (#7961) (43099df), closes #7763

Fixes

  • build: migrate loopover-miner/loopover-mcp to out-of-place dist/ emit (#8590) (c896797)
  • deps: resolve postcss + tar audit findings via overrides (#8612) (bca96ff)
  • mcp: await PostHog flush via unit-tested stdio wrapper (#8738) (7ee07cc), closes #8690
  • mcp: correct loopover_check_issue_slop description and drop the dead issue-slop rubric (#8959) (fcecf0c), closes #8907
  • mcp: exit the CLI cleanly on a broken-pipe stdout/stderr error (#8731) (2fc27bc), closes #8691
  • mcp: print usage help for bare loopover-mcp invocation instead of starting stdio server (#8486) (c096106), closes #8313
  • mcp: stop --json=false and --exit-code=false enabling the flag they disable (#8725) (60f9f8f)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @loopover/engine bumped from ^3.14.1 to ^3.15.2
miner: 3.15.2

3.15.2 (2026-07-27)

Features

  • miner: run the target repo's own test/lint/build commands before opening a PR (#8819) (e10abf2)
  • miner: wire deny-hook synthesis to a live consumer and give it an operator CLI (#8806) (#8817) (33bacda)
  • orb: salvageability axis — hold fixable, well-authored PRs instead of one-shot-closing (#8986) (7fd84ff)
  • selfhost: PostHog AI observability across ORB and AMS (#8623) (a9d9c0e)

Fixes

  • engine: treat an Infinity WIP cap as uncapped, not collapsed to 0 (#8945) (6aaea39)
  • miner: AmsPolicySpec parse warnings are computed but never surfaced to the operator (#8978) (3369ebc), closes #8853
  • miner: compare-and-set the orphan reclaim so a stale probe cannot free a live re-acquired slot (#8992) (8444812)
  • miner: delete the orphaned portfolio chat-action duplicate (#8662) (1cc2146)
  • miner: drop stale ProcessEnv casts on resolveReplaySnapshotDbPath (#8768) (7b2104d), closes #8642
  • miner: fail acquire() on an attempt_id/repo mismatch (#8964) (266b07d)
  • miner: fall back to global config.apiUrl in loopoverApiUrl (#8937) (4dfe15d)
  • miner: governor reputation-history read-modify-write is unguarded, unlike sibling scalar-state writes (#8988) (62e6d25), closes #8855
  • miner: governor-chokepoint-persisted's load-evaluate-save cycle isn't atomic (#8993) (49a27c2), closes #8856
  • miner: include laptop-state in doctor integrity and migrate store lists (#8749) (713145f), closes #8641
  • miner: printHelp() omits the working deny-hooks subcommand (#8933) (1eeaae1), closes #8851
  • miner: reclaim orphaned worktree allocations on every acquire() (#8918) (eab6ecf)
  • miner: refuse a duplicate attempt when this miner already has an open PR for the exact issue (#8808) (#8815) (d5ec15a)
  • miner: reject a portfolio-queue identifier containing the '::' composite-id separator (#8925) (32ee72e)
  • miner: self-review-context never supplies recent-merged-PR history, contradicting its own "same fidelity" claim (#8969) (987f7ce), closes #8852
  • miner: wire AMS policy resolver to the documented discovery order (#9106) (f2f32cc), closes #8863
  • review: auto-clear stale manual-review lock-contention hold; sync engine gate-decision twin (#9107) (6aacf08)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @loopover/engine bumped from ^3.14.1 to ^3.15.2

This PR was generated with Release Please. See documentation.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jul 27, 2026

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
🔵 In progress
View logs
loopover-ui 316e10d Jul 27 2026, 06:42 AM

@JSONbored JSONbored self-assigned this Jul 27, 2026
@superagent-security

Copy link
Copy Markdown
Contributor

Superagent didn't find any vulnerabilities or security issues in this PR.

@codecov

codecov Bot commented Jul 27, 2026

Copy link
Copy Markdown

Bundle Report

Bundle size has no change ✅

@JSONbored
JSONbored force-pushed the release-please--branches--main--groups--engine-and-dependents branch 3 times, most recently from 793594d to 91eba3a Compare July 27, 2026 06:10
@superagent-security

Copy link
Copy Markdown
Contributor

Superagent didn't find any vulnerabilities or security issues in this PR.

@codecov

codecov Bot commented Jul 27, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.94%. Comparing base (4d21d7c) to head (5d37ab8).
⚠️ Report is 1 commits behind head on main.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #9171   +/-   ##
=======================================
  Coverage   93.94%   93.94%           
=======================================
  Files         821      821           
  Lines       81601    81601           
  Branches    24769    24769           
=======================================
  Hits        76662    76662           
  Misses       3556     3556           
  Partials     1383     1383           
Flag Coverage Δ
backend 95.22% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

@loopover-orb loopover-orb Bot added the gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier. label Jul 27, 2026
@loopover-orb

loopover-orb Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

Caution

🛑 LoopOver review result - fixes required

Review updated: 2026-07-27 06:35:19 UTC

9 files · 1 AI reviewer · 1 blocker · CI failing · unstable

🛑 Suggested Action - Manual Review

Review summary
This is an automated release-please version-bump PR that syncs .release-please-manifest.json, package.json versions, package-lock.json, and CHANGELOG.md entries across loopover-engine (3.15.1→3.15.2), loopover-mcp and loopover-miner (3.14.1→3.15.2), all correctly cross-referencing the underlying fix/feature commits already merged to main. The version and dependency bumps are internally consistent (engine version matches the ^3.15.2 dependency ranges in mcp/miner, and expected-engine.version is updated to match), and CHANGELOG content lines up with the PR description.

Nits — 4 non-blocking
  • This release PR doesn't link to a maintainer-authorized issue per the repo's contribution policy, but that requirement is typically waived for bot-generated release-please PRs — worth confirming this is exempted in CI config.
  • package-lock.json is a large generated diff; nothing to review there beyond confirming the version bumps are consistent, which they are.
  • If CI failures (validate-code, validate-tests, validate) are not simply due to this branch being 2 commits behind main, verify whether the newly-released engine 3.15.2 fixes (e.g. the security/orb identity-binding fix) require corresponding test updates that haven't landed on this branch yet.
  • Diff looks like trivial or whitespace-only churn — Reduce whitespace-only or formatting-only churn and keep the diff focused on substantive changes.

Why this is blocked

  • No linked issue detected: No closing reference or linked issue number was found in the PR metadata/body. — If this PR is intended to solve an issue, link it explicitly in the PR body.
📋 Copy for AI agents — paste into your coding agent
Fix the following blocker(s) from this PR review:

1. No linked issue detected: No closing reference or linked issue number was found in the PR metadata/body. — If this PR is intended to solve an issue, link it explicitly in the PR body.

CI checks failing

  • validate
  • validate-tests
  • validate-code

Decision drivers

  • ❌ Code review — 1 blocker (1 reviewer)
  • ❌ Gate result — Blocking (Repo-configured hard blocker found.)
Context & advisory signals — never blocks the verdict
Signal Result Evidence
Linked issue ✅ No-issue rationale PR body explains why no issue is linked.
Related work ⚠️ 1 scoped overlap Top overlaps are listed below; lower-confidence bulk is hidden.
Change scope ❌ 8/20 High review scope from cached public metadata (no linked issue context).
Validation posture ✅ 25/25 PR body includes validation/test evidence.
Contributor workload ✅ 10/10 Author activity: 13 registered-repo PR(s), 13 merged, 299 issue(s).
Contributor context ✅ Confirmed Gittensor contributor JSONbored; Gittensor profile; 13 PR(s), 299 issue(s).
Improvement ℹ️ Insufficient signal risk: low · value: insufficient-signal
Review context
  • Author: JSONbored
  • Role context: owner (maintainer lane)
  • Public audience mode: oss maintainer
  • Lane context: Repository is configured for direct PR review.
  • Public profile languages: not available
  • Official Gittensor activity: 13 PR(s), 299 issue(s).
  • Related work: Titles/paths share 2 meaningful terms. (issue #9102)
Contributor next steps
  • Start here: Treat this as maintainer-lane context rather than normal contributor-lane activity.
  • Then work through the remaining 3 steps in the Signals table above.
Signal definitions
  • Related work = same linked issue, overlapping active PRs, or title/path similarity.
  • Change scope = cached public metadata such as size labels, draft state, and review-burden hints.
  • Validation posture = whether the PR provides enough public validation/test evidence for maintainer review.
  • Contributor workload = public contributor activity and cleanup pressure, not a repo-wide quality failure.
  • Contributor context = public GitHub/Gittensor identity context; non-Gittensor status is not a blocker.
🧪 Chat with LoopOver

Ask LoopOver a question about this PR directly in a comment — grounded only in the same cached, public-safe facts shown above, never a new claim.

  • @loopover ask &lt;question&gt; answers contribution-quality Q&A with source citations and freshness.
  • @loopover chat &lt;question&gt; answers in natural prose from cached decision-pack facts via local inference (maintainer/collaborator; read-only).
  • A plain-language @loopover mention with a real question is routed to the closest matching read-only command automatically — no exact syntax required.

Full command reference: https://loopover.ai/docs/loopover-commands

🧪 Experimental — new and may change.

Decision record
  • action: hold · clause: missing_linked_issue
  • config: 03a7f8b529a9 · pack: oss-anti-slop
  • record: 67c540714be2 (schema v3, head 76f9e1f)

🟩 Safe / merged · 🟦 Advisory · 🟨 Held for review · 🟥 Blocked / closed


💰 Earn for open-source contributions like this. Gittensor lets GitHub contributors earn for the work they already do — register to start earning →.

Checked by LoopOver, a quiet PR intelligence layer for OSS maintainers.

  • Re-run LoopOver review

@loopover-orb loopover-orb Bot added the manual-review Gittensor contributor context label Jul 27, 2026
@JSONbored
JSONbored force-pushed the release-please--branches--main--groups--engine-and-dependents branch from 76f9e1f to 316e10d Compare July 27, 2026 06:42
@JSONbored
JSONbored merged commit e1ae2f0 into main Jul 27, 2026
5 checks passed
@JSONbored
JSONbored deleted the release-please--branches--main--groups--engine-and-dependents branch July 27, 2026 06:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment