Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 22 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,28 @@ its linked release entry for the exact published source and assets.

## Unreleased

No changes currently recorded.
Development version: `0.2.4.dev0`. Public install remains the immutable v0.2.3 release.

### Post-release engineering

- Added CLI lifecycle parity for criterion resolution, atomic external E3/E4 runtime-evidence
recording, final acceptance, and changed-head comparison over validated local records.
- Enforced a strict saved-record envelope and lifecycle-output validation. Failed commands do not
mutate saved records, and low-evidence acceptance notes share one fail-closed core policy across
CLI and Streamlit.
- Added an installed-wheel packaged Chromium regression at 1280×720 and 390×844 with exact
Playwright 1.62.0, isolated local storage, loopback-only networking, and console/page-error
assertions.
- Added Python 3.13 package, CLI, deterministic-benchmark, and exact workbench-health engineering
coverage in both a genuine local CPython 3.13 environment and protected CI.
- Added a keyboard-only installed-workbench path with visible-focus assertions and
bounded native 200% zoom evidence on the tested macOS/Chrome configuration.
- Enforced verified-public provenance before a live GitHub source can be persisted, exported, or
counted toward Alpha. Private, ambiguous, malformed, and legacy-unverified sources fail closed.

These changes are ScopeProof engineering evidence only and earn zero Stage 1 credit. Real
screen-reader operation, Windows desktop, Linux desktop, non-Chromium browser behavior, and WCAG
conformance remain unsupported.

## 0.2.3 — Evidence integrity and reviewer loop

Expand Down
6 changes: 6 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -111,6 +111,12 @@ at zero. The
[exact-head verification audit](docs/audits/exact-head-runtime-evidence/verification.md)
records the product-tree engineering evidence and remaining gaps.

The repository's current source line is the unreleased development version `0.2.4.dev0`; it is
not a replacement release asset. Post-v0.2.3 engineering merged CLI lifecycle commands, strict
saved-record validation, installed Chromium coverage, Python 3.13 and bounded keyboard/focus
evidence, and verified-public provenance enforcement. Those changes remain engineering evidence
only. The public install continues to be the immutable v0.2.3 release, and Stage 1 remains zero.

GitHub exposes visible check runs but does not reliably expose every repository's required-check
policy to anonymous clients. ScopeProof therefore labels this value **Observed CI state** and counts
only explicit success as passing.
Expand Down
9 changes: 9 additions & 0 deletions ROADMAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@ which provides the wheel, source archive, and checksum manifest.
| Area | Current state |
|---|---|
| Published install | v0.2.3 GitHub Release with wheel, source archive, and checksum manifest |
| Active source line | Unreleased `0.2.4.dev0`; no v0.2.4 release, tag, or package publication exists |
| Verified product baseline | PR #184 release integration landed on `main` at `448c42758ea139bf9203cbf1bb04b02b02ae412c` |
| Product verification | Full product-code verification is bound to `fb74d4bbb402f4de3e2fabb56ce28c948214f8c2`; package, install, installed-benchmark, and health artifacts are bound to `81598899fcd85df58ab22f9212f2e8382f4a5e5f`. |
| Release integration evidence | PR #184 release integration at `448c42758ea139bf9203cbf1bb04b02b02ae412c`; exact-main CI, CodeQL, and Pages all succeeded, and `origin/main` matched at the 2026-08-08 branch-start snapshot |
Expand All @@ -28,6 +29,14 @@ which provides the wheel, source archive, and checksum manifest.
Verify live GitHub and current release records before relying on publication state. Engineering
milestones can proceed while Stage 1 waits, but they do not advance product-validation stages.

After the v0.2.3 release, PR #185 merged core-backed CLI lifecycle parity and packaged Chromium
proof at `30177733ef312ced22e6a2e57e3df6fdb1e92507`; PR #187 merged Python 3.13 plus bounded
keyboard/focus and zoom engineering evidence at `c548759b5464ad5bb98baf1e996397f241dfc455`; and
PR #188 merged verified-public provenance enforcement at
`077f9351283b319b82854ad1df95eac7ce614e21`. CLI lifecycle parity is implemented;
verified-public provenance enforcement is implemented. These changes form the `0.2.4.dev0`
development line and earn no Stage 1 credit.

## Stage 0 — Reviewer-first product reset

Status: prior PR #177 repairs remain historical engineering evidence. PR #180
Expand Down
4 changes: 4 additions & 0 deletions docs/audits/accessibility-platform-evidence/verification.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
# Accessibility and platform evidence verification

> **Historical evidence boundary:** This audit remains bound to its named commit, tree, version,
> and environment. The [current status](../../releases/v0.2.3-status-and-next-stages.md) supersedes
> unqualified present-state inferences and does not rewrite the results below.

## Evidence boundary

- Date: 2026-08-09 (America/Toronto).
Expand Down
4 changes: 4 additions & 0 deletions docs/audits/exact-head-runtime-evidence/verification.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
# Exact-head merged-product runtime-evidence verification

> **Historical evidence boundary:** This audit remains bound to its named commit, tree, version,
> and environment. The [current status](../../releases/v0.2.3-status-and-next-stages.md) supersedes
> unqualified present-state inferences and does not rewrite the results below.

Machine-readable evidence manifest:
[`verification.json`](verification.json). The manifest is the structured
repository-contract input; this document remains the human-readable audit.
Expand Down
4 changes: 4 additions & 0 deletions docs/audits/post-release-cli-browser/verification.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
# Post-release truth, CLI parity, and packaged-browser verification

> **Historical evidence boundary:** This audit remains bound to its named commit, tree, version,
> and environment. The [current status](../../releases/v0.2.3-status-and-next-stages.md) supersedes
> unqualified present-state inferences and does not rewrite the results below.

## Evidence boundary

- Date: 2026-08-08 (America/Toronto).
Expand Down
4 changes: 4 additions & 0 deletions docs/audits/v0.2.3-integrity-reviewer-loop/verification.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
# ScopeProof v0.2.3 integrity and reviewer-loop verification

> **Historical evidence boundary:** This audit remains bound to its named commit, tree, version,
> and environment. The [current status](../../releases/v0.2.3-status-and-next-stages.md) supersedes
> unqualified present-state inferences and does not rewrite the results below.

## Evidence identity and boundary

- Date: 2026-08-03 (America/Toronto)
Expand Down
4 changes: 4 additions & 0 deletions docs/audits/v0.2.3-product-convergence/verification.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
# ScopeProof v0.2.3 product-convergence verification

> **Historical evidence boundary:** This audit remains bound to its named commit, tree, version,
> and environment. The [current status](../../releases/v0.2.3-status-and-next-stages.md) supersedes
> unqualified present-state inferences and does not rewrite the results below.

## Evidence identity and boundary

- Date: 2026-08-02 (America/Toronto)
Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
# v0.2.3 Workbench Accessibility and First-Use Audit

> **Historical evidence boundary:** This audit remains bound to its named commit, tree, version,
> and environment. The [current status](../../releases/v0.2.3-status-and-next-stages.md) supersedes
> unqualified present-state inferences and does not rewrite the results below.

Status: internal engineering audit
Date: 2026-07-26
Environment: macOS, Streamlit local server, in-app Chromium browser
Expand Down
4 changes: 4 additions & 0 deletions docs/audits/workbench-ux-simplification/verification.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
# Workbench UX simplification verification

> **Historical evidence boundary:** This audit remains bound to its named commit, tree, version,
> and environment. The [current status](../../releases/v0.2.3-status-and-next-stages.md) supersedes
> unqualified present-state inferences and does not rewrite the results below.

## Scope and evidence boundary

- Date: 2026-08-01 (America/Toronto)
Expand Down
15 changes: 12 additions & 3 deletions docs/commercialization/market-comparison-2026-07-26.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,9 @@ Boundary: competitor capabilities below are vendor-advertised unless explicitly
labelled as a ScopeProof implementation fact. This document is not customer or
market validation.

Version boundary: public install remains v0.2.3; current source is the unreleased `0.2.4.dev0`
development line. Post-release engineering changes do not constitute market validation.

## Product category

ScopeProof is not a general AI code reviewer, test-management system, or static
Expand Down Expand Up @@ -87,6 +90,10 @@ criterion is supported at this exact head.”
- Conservative False Ready posture and inspectable missing-evidence
explanations.
- Portable exports and versioned local records.
- CLI lifecycle parity is implemented for core-backed resolution, external runtime verification,
final acceptance, and changed-head comparison.
- Bounded keyboard-only and visible-focus engineering evidence is implemented for the installed
Chromium path; it is not accessibility conformance.

### Where ScopeProof is immature

Expand All @@ -97,8 +104,9 @@ criterion is supported at this exact head.”
integration with an issue or test-management source.
- Retrieval coverage is intentionally conservative and the completed R-002
baseline found candidates for only 5 of 20 research criteria.
- Accessibility is not yet verified with keyboard-only completion, a screen
reader, 200% zoom, Windows, or Linux.
- Real screen-reader operation, Windows desktop, Linux desktop, non-Chromium browser behavior, and
WCAG conformance remain unsupported. The bounded keyboard/focus and native-zoom checks do not
establish those broader claims.
- There is no evidence yet that users will repeat the workflow or pay for a team
product.

Expand All @@ -112,7 +120,8 @@ criterion is supported at this exact head.”
2. Preserve retrieval diagnostics as explanations, never verdict evidence.
3. Improve conservative retrieval only through new constructed regressions and
a prospectively frozen holdout; do not retune on R-002.
4. Finish keyboard, zoom, assistive-technology, and available-platform checks.
4. Attempt real assistive-technology and available desktop-platform checks only in genuine,
observable environments; keep unavailable rows unsupported.
5. Keep export, changed-head re-review, and missing-evidence explanations clear.

### Design now, implement only after genuine use evidence
Expand Down
17 changes: 15 additions & 2 deletions docs/development-environment.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,14 @@
# Reproducible development environment

ScopeProof supports Python 3.11 and newer. The contributor baseline is Python 3.12 with dependencies resolved by the checked-in `uv.lock`. This path uses only local and free open-source tooling; it does not require an OpenAI or other paid LLM API.
The public install remains v0.2.3; the current repository source is the unreleased `0.2.4.dev0`
development line. Python 3.11, Python 3.12, and Python 3.13 have current package/CLI engineering
coverage. Python 3.11 is the declared floor, Python 3.12 is the locked contributor baseline, and
Python 3.13 is exercised in protected compatibility CI and a genuine local interpreter check.
Python 3.14 is unverified pending a clean, genuine compatibility run; the current `>=3.11`
metadata must not be read as verified 3.14 support.

Dependencies are resolved by the checked-in `uv.lock`. This path uses only local and free
open-source tooling; it does not require an OpenAI or other paid LLM API.

## Create or refresh the environment

Expand Down Expand Up @@ -68,7 +76,12 @@ Run the local workbench with:
uv run scopeproof-web --host 127.0.0.1 --port 8501
```

The Python 3.11 CI lane remains the compatibility floor. A separate locked Python 3.12 lane verifies that the committed resolution can be recreated and runs repository contracts plus the deterministic benchmark before the required `verify` job.
The Python 3.11 CI lane remains the compatibility floor. A separate locked Python 3.12 lane
verifies that the committed resolution can be recreated and runs repository contracts plus both
deterministic benchmarks. The Python 3.13 lane runs the complete suite, builds and installs a wheel,
checks dependencies and both CLI versions, runs both installed benchmarks, and requires exact
loopback workbench health before the required `verify` job. These Linux-runner checks are package
and CLI evidence, not Linux desktop evidence.

## Known-good UI baseline

Expand Down
17 changes: 16 additions & 1 deletion docs/releases/v0.2.3-platform-package-matrix.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,27 @@ Merged product commit: `2a320df966eff30c05a2b1dce607a247201fa165` (PR #180)
Merged product tree: `add81a2d0ba7e64f8e4318a1959bbe7e6e4acfc8`
Independently verified PR head: `ed9f9c0cf6b7cf7cc25403d6138e7a8391f55e0f`
Verified PR-head tree: `add81a2d0ba7e64f8e4318a1959bbe7e6e4acfc8`
Public install and latest release: v0.2.1
Historical public install at the 2026-08-02 audit time: v0.2.1
Current public install: v0.2.3
Historical local checkout verification head: `87e95a76ca4100458465da520049992e8b39af5c`

Historical package build base: `482d1a78f5d3345029d35d33a518ca36bc2f8e29`
Classification: internal engineering evidence only

## 2026-08-09 post-release development boundary

The public package and every historical hash below remain bound to v0.2.3 and their named source
trees. Current repository source is the unreleased `0.2.4.dev0` development line. Later merged
engineering work added an installed-wheel Chromium lifecycle regression, a keyboard-only path with
visible-focus assertions at 1280×720 and 390×844, bounded native 200% zoom on one macOS/Chrome
configuration, and clean Python 3.13 package, CLI, benchmark, and loopback-health checks.

Those results do not establish real screen-reader operation, Windows desktop, Linux desktop,
non-Chromium browser behavior, or WCAG conformance. Hosted Linux CI is package/runtime evidence,
not Linux desktop evidence. This additive boundary supersedes only unqualified current-status
inferences; it does not rewrite any earlier measurement, artifact identity, or limitation below.
All engineering evidence adds zero Stage 1 credit.

## 2026-08-02 merged product-tree package verification

PR #180 merged the independently verified head's exact product tree as
Expand Down
26 changes: 15 additions & 11 deletions docs/releases/v0.2.3-status-and-next-stages.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,9 @@
# ScopeProof v0.2.3 status, gaps, and next stages

Date: 2026-08-03
Release-baseline date: 2026-08-03; current development alignment: 2026-08-09
Current release baseline: PR #184 release integration at
`448c42758ea139bf9203cbf1bb04b02b02ae412c`
Current development line: unreleased `0.2.4.dev0` after merged PR #185, PR #187, and PR #188
Exact-main engineering checks: CI run `30854382641`, CodeQL run `30854382413`,
and Pages run `30854382659`; exact-main CI, CodeQL, and Pages all succeeded
Historical source integration: PR #183 at
Expand All @@ -18,6 +19,15 @@ which contains the wheel, source archive, and checksum manifest.
Product-validation state: Stage 0 source integration is complete; release and
test work do not change Stage 1, which remains at zero. Stages 2–4 remain gated.

PR #185 merged CLI lifecycle parity, the strict saved-record envelope, and packaged Chromium
regression at `30177733ef312ced22e6a2e57e3df6fdb1e92507`. PR #187 merged Python 3.13 plus bounded
keyboard/focus and native-zoom engineering evidence at
`c548759b5464ad5bb98baf1e996397f241dfc455`. PR #188 merged verified-public provenance enforcement
at `077f9351283b319b82854ad1df95eac7ce614e21`, so private, ambiguous, malformed, and
legacy-unverified live sources fail closed. CLI lifecycle parity is implemented;
verified-public provenance enforcement is implemented. These post-release changes belong to
`0.2.4.dev0`, not the immutable v0.2.3 assets, and add zero Stage 1 credit.

PR #174 head `e96d9929e651ca36bf178a6fedff0e89e8df3675` passed Python 3.11
compatibility, locked-environment, `verify`, and CodeQL before it was merged to
`main` as `178df8a1c8034edc4d3240d790e3e4c668dfa82a`. The merged source includes
Expand Down Expand Up @@ -120,7 +130,7 @@ code-review comments, scan security, or automatically fix a PR.
| Exports | Pydantic-backed JSON, Markdown, CSV, and HTML with runtime identity, linked/unlinked state, and exact criteria-source provenance | Exported content is a review record, not certification |
| Alpha evidence | One-time outcome capture only from a fully revalidated saved review with matching public-GitHub origin, PR, exact head, criteria, and provenance | Demo, fixture, research, legacy-unknown, mutated, or non-public origins contribute zero qualifying alpha evidence |
| Engineering benchmarks | 12-case constructed acceptance benchmark, two-case comparison benchmark, R-001 research case, and frozen 20-case R-002 research baseline | All contribute zero Stage 1 credit |
| Local workbench and CLI | Cleaner five-stage Streamlit hierarchy plus offline source-confirmation preparation, review, export, list, delete, benchmark, and comparison commands | Local owner operation and UI tests are not participant or accessibility validation |
| Local workbench and CLI | Cleaner five-stage Streamlit hierarchy plus offline source-confirmation preparation; review, resolve, atomic runtime verification, final acceptance, export, list, delete, benchmark, and changed-head comparison commands | Local owner operation and UI tests are not participant or accessibility validation |

## Primary use cases

Expand Down Expand Up @@ -166,7 +176,7 @@ remains zero independent use.
| 200% zoom | Supported bounded local evidence | Installed Chrome 151.0.7922.77 reported native `Zoom: 200%`, device pixel ratio changed from 1 to 2, the exact-head keyboard path completed, and no named control was horizontally clipped on the tested macOS/display configuration. This is not responsive resizing or a broad browser/platform claim. |
| VoiceOver or another real screen reader | Unsupported current evidence | The installed VoiceOver service was detectable, but bounded control attempts exposed no observable screen-reader state, speech, caption, focus announcement, or reading-order result. |
| Python 3.11 | Remote CI evidence only | Python 3.11 CI passed at the exact merged PR head; no local Python 3.11 desktop flow was executed |
| Python 3.13 | Supported local engineering evidence | A genuine CPython 3.13.14 environment passed clean wheel installation, `pip check`, both versioned CLIs, both deterministic benchmarks, and exact workbench health. The new hosted 3.13 job must pass before its Linux-runner result is claimed. |
| Python 3.13 | Supported package/runtime engineering evidence | A genuine local CPython 3.13.14 environment passed clean wheel installation, `pip check`, both versioned CLIs, both deterministic benchmarks, and exact workbench health. Protected Python 3.13 CI passed on PR #187 and resulting `main`; this is package/runtime evidence, not Linux desktop evidence. |
| Windows and Linux desktop | Unavailable environment | Build, install, launch, and complete representative workflows on those operating systems |
| Stage 1 | External evidence gate | A non-owner supplies a real public PR, public requirements, source-owner confirmation, exact head SHA, saved review, and genuine outcome |
| Stage 2 | Stage gate | Every Stage 1 target passes before repeat-use and commercial-discovery evidence is collected |
Expand Down Expand Up @@ -250,20 +260,14 @@ target repository code.
current PR head, invalidate stale prior conclusions on `synchronize`, and
keep the current Action informational until independent use justifies
promotion.
2. **CLI lifecycle parity:** expose resolution, atomic external verification,
final acceptance, and changed-head comparison through the core-backed CLI
without weakening Streamlit or schema boundaries.
3. **Non-executing evidence adapters:** design validated import records for
2. **Non-executing evidence adapters:** design validated import records for
JUnit-style results, coverage summaries, contract reports, build/deployment
records, and externally supplied runtime attestations. Imported data remains
evidence with provenance, not proof of correctness.
4. **Authenticated reviewer identity:** current runtime records now retain
3. **Authenticated reviewer identity:** current runtime records now retain
review-scoped identity and attribution, but authentication, optional expiry,
and externally signed attestations remain future decisions without accounts,
silent overrides, or automatic approval.
5. **Real-browser regression coverage:** automate the packaged pointer path
first, then add keyboard, responsive viewport, and zoom checks only where
the execution environment provides trustworthy control.

### Demand-gated candidates

Expand Down
Loading