Skip to content

chore: restore post-v0.2.3 development identity - #189

Open
YuzeJ21 wants to merge 7 commits into
mainfrom
codex/post-v023-development-identity
Open

chore: restore post-v0.2.3 development identity#189
YuzeJ21 wants to merge 7 commits into
mainfrom
codex/post-v023-development-identity

Conversation

@YuzeJ21

@YuzeJ21 YuzeJ21 commented Aug 10, 2026

Copy link
Copy Markdown
Owner

Summary

  • advance the post-release source identity from published v0.2.3 to unreleased 0.2.4.dev0 while leaving the v0.2.3 tag, GitHub Release, assets, checksums, and commit-bound historical evidence intact;
  • add a fail-closed repository contract that prevents a published final version from being reused by a different committed tree, tracked/index change, or package-relevant untracked input—including ignored files under force-included wheel roots—while preserving explicitly build-excluded local state such as .coverage 2;
  • record post-v0.2.3 CLI lifecycle parity, strict saved-record validation, packaged Chromium coverage, Python 3.13, bounded keyboard/focus and zoom evidence, and verified-public provenance under Unreleased;
  • reconcile README, roadmap, development environment, v0.2.3 status and platform matrices, market comparison, and superseded audit boundaries;
  • remove implemented CLI lifecycle and packaged-browser work from future proposals while keeping real screen-reader, Windows desktop, Linux desktop, non-Chromium, and WCAG evidence unsupported.

Repository truth

TDD and verification

  • Observed the release-tree contract fail before changing 0.2.3, then pass after advancing the version.
  • Added and observed failing regressions for tracked dirty state, package-relevant untracked files, the real non-ignored .coverage 2 exclusion, and ignored files under Hatch force-included wheel roots before implementing each repair.
  • Ruff: passed.
  • Complete suite: 1,993 passed and 2 intentional skips.
  • Combined coverage: 95.06%; the 95% gate passed.
  • Repository contracts: 84 passed.
  • Acceptance benchmark: 12 cases / 13 criteria; zero mismatches, zero must-have False Ready outcomes, zero false blockers, and zero unexecuted categories.
  • Comparison benchmark: 2 cases; zero mismatches.
  • Two exact-head wheel builds with SOURCE_DATE_EPOCH=1706745600 were byte-identical at SHA-256 66a8843307aefae85da21e7b678c513ebaacf00a8b3c580a0446a3075a6fa076.
  • Artifact inventory: 101 wheel entries, 556 source-distribution entries, zero forbidden matches.
  • Clean install: pip check passed; distribution, module, and new-review identities all reported 0.2.4.dev0; both CLI versions, both installed benchmarks, and exact loopback health passed.
  • Installed-wheel Chromium regression: 3 passed with the existing loopback-only networking and console/page-error assertions.
  • Independent review: all four actionable Important findings were repaired test-first; final re-review found no remaining Critical or Important findings.

Evidence boundary

This is ScopeProof engineering evidence only. ScopeProof remains an evidence assistant, not a correctness oracle, and does not execute target-repository code. Static candidates are not runtime verification. Reviewer/source-owner identity remains asserted rather than authenticated. The GitHub Action remains opt-in and informational. No release, tag, package publication, outreach, R-002 retuning, R-003 generation, beta activation, private-repository support, or Stage 1 credit is included.

Real screen-reader operation, Windows desktop, Linux desktop, non-Chromium browsers, WCAG conformance, Python 3.14 compatibility, and genuine external adoption remain unsupported or unverified.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: eb7df35183

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tests/test_repository_contracts.py
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant