Skip to content

chore(release): v1.8.20 — supply-chain pin + maintenance clear-down - #404

Merged
KbWen merged 1 commit into
mainfrom
chore/v1.8.20-release
Aug 12, 2026
Merged

chore(release): v1.8.20 — supply-chain pin + maintenance clear-down#404
KbWen merged 1 commit into
mainfrom
chore/v1.8.20-release

Conversation

@KbWen

@KbWen KbWen commented Aug 12, 2026

Copy link
Copy Markdown
Owner

Release cut for v1.8.20. Docs-only: version banners, CHANGELOG, and the release's own Ship History entry. No engine, test, or logic change rides this PR — everything substantive was already merged and individually CI-green.

What it packages

Ten commits sat unreleased on main while the banner still read 1.8.19.

PR #402 backlog #166 (P1) — the TruffleHog pin bound the wrapper, not the scanner. Now pinned by image digest; AC-3's false "full-history scan" claim and the Domain Decision that generated it corrected; new docs/architecture/ci-security.log.md
PR #395 backlog #163+#164 — audit-wave leftovers
PRs #386/#377/#378 three dependabot bumps, open 8–15 days
PRs #397/#399/#400/#401/#403 records wave, including the archival of this repo's only different-vendor review artifact

What it changes here

Banners 1.8.19 → 1.8.20 across the canonical 7 (deploy.sh ACX_VERSION, CITATION.cff version + date-released, Model Guide EN/zh-TW, Testing Protocol EN/zh-TW, antigravity-v5-runtime.md), CHANGELOG [1.8.20], SSoT sequence 148 → 149 with the cap-10 rotation.

Shipping a known state, not a quiet one

The CHANGELOG names five defects filed and deliberately unfixed (#167#171) rather than omitting them — including the scanner false-positive class that blocked this release's own security PR. Each fix touches tool, workflow, or .gitattributes code a docs-only cut must not carry, and #171's detector exclusion is a security-coverage decision that deserves its own review.

It also records a governance failure rather than burying it: PR #402 was classified quick-win at 276 lines across four modules, against a hard block at 200 lines / 2 modules — which is what let its review gate be skipped. Independent review caught it; it was reclassified to hotfix through the documented rollback mechanism, with the retroactive sequencing stated plainly. The durable fix is procedural — measure the diff, then classify — and the two units after it did so.

Evidence

  • Banner sweep verified both directions: each of the 7 replacements asserted to match exactly once before writing, then grep -rn "1\.8\.19" across the same 7 files → no matches.
  • Guarded SSoT write under optimistic locking → {"status": "ok"}; 10 Ship History entries before and after; check_ssot_caps.pyship history 10/10, spec index 26/30.
  • check_audit_chain.pyaudit chain intact.
  • validate.sh pass=118 warn=4 fail=0 skip=2 — machine-local totals (a clean checkout runs 18 fewer active-work-log checks); CI is the replayable evidence.
  • A wrong fact caught before it landed: the Ship History entry first named the wrong rotated entry. Corrected in the staged content, so it never reached current_state.md.

Not done at merge

Per repo-gotchas #12 — and forgotten twice before — the release is not complete when this merges. The lightweight v1.8.20 tag and gh release create --latest are separate manual steps, tracked to completion in this session.

🤖 Generated with Claude Code

Packages ten commits that sat unreleased on main while the banner still read
1.8.19: the #166 P1 supply-chain fix (PR #402), the #163/#164 audit-wave
leftovers (PR #395), three dependabot bumps open 8-15 days (PRs #386/#377/#378),
and the records wave (PRs #397/#399/#400/#401/#403).

Version banners 1.8.19 -> 1.8.20 across the canonical 7 files (deploy.sh
ACX_VERSION, CITATION.cff version + date-released 2026-08-12, Model Guide
EN+zh-TW, Testing Protocol EN+zh-TW, antigravity-v5-runtime.md framework-version
reference); CHANGELOG [1.8.20] in house format. No engine, test, or logic change
in the release cut itself.

SSoT sequence 148 -> 149 via guard_context_write.py under optimistic locking;
Ship History rotated at cap 10 (Ship-fix-149-worklog-family-skip-2026-07-27 to
archive/ship-history-2026.md).

The CHANGELOG names five defects filed and deliberately not fixed (#167-#171),
including the scanner false-positive class that blocked this release's own
security PR, and records that PR #402 was misclassified quick-win at 276 lines
across four modules against a 200-line/2-module hard block -- caught by
independent review, reclassified to hotfix, sequencing recorded rather than
presented as clean. Shipping a known state beats shipping a quiet one.

Post-merge completion per repo-gotchas #12, NOT optional and forgotten twice
before: lightweight v1.8.20 tag plus gh release create --latest.

Evidence: banner sweep asserted exactly-one-match per replacement, then reverse
grep for 1.8.19 across the same 7 files returned nothing. check_ssot_caps.py
'ship history 10/10, spec index 26/30'; chain intact; validate.sh pass=118
warn=4 fail=0 skip=2. A wrong rotated-entry name was caught in the staged
content and never reached current_state.md.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@KbWen
KbWen merged commit 3faae10 into main Aug 12, 2026
19 checks passed
@KbWen
KbWen deleted the chore/v1.8.20-release branch August 12, 2026 16:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant