Skip to content

Release v0.4.7 - #75

Merged
xeonvs merged 1 commit into
mainfrom
release/v0.4.7
Aug 11, 2026
Merged

Release v0.4.7#75
xeonvs merged 1 commit into
mainfrom
release/v0.4.7

Conversation

@xeonvs

@xeonvs xeonvs commented Aug 11, 2026

Copy link
Copy Markdown
Owner

Summary

  • prepare stable toolkit 0.4.7 from the exact protected feature merge;
  • record closed release authorization metadata for issues 70-73, stable and next version markers, and a deterministic source epoch;
  • consume Towncrier fragments 69-73 into the generated changelog and exact v0.4.6...v0.4.7 release notes;
  • archive the externally reconciled 0.4.6 plans under stable-tag anchors while keeping the 0.4.7 plan active through external delivery.

Refs #70. Refs #71. Refs #72. Refs #73.

Validation

  • scripts/quality.sh check: 623 tests plus 85 subtests, 79.09% coverage, Ruff, formatting, strict mypy, and Bandit with zero medium/high findings
  • release-focused validation: 137 tests plus 15 subtests; release-note, metadata, archive, OCR manifest, workflow YAML, changed-shell, and diff checks
  • pip-audit --skip-editable: no known vulnerabilities
  • repository-pinned Gitleaks 8.24.3 over the release history
  • two reproducible stable builds, Twine, exact metadata/content, zero runtime dependencies, and restricted-path hostile-shadow installs on Python 3.12-3.14
  • wheel SHA-256: 15c86588987fd441aebf7a43235571e2d14f789aa7a8e1f59cbd24ce113978b2
  • sdist SHA-256: 5ad2563c9cfc4e6fc9da95d425df44c5e53e62de05ddad462eeda0b41626ac6a
  • user-visible fragments were consumed into CHANGELOG.md; public content remains synthetic and contains no credentials or private payloads

Security and compatibility impact

The release authorizer executes from the protected base that predates this candidate. The candidate head and squash merge are treated only as bounded data. Publication is bound to this exact reviewed tree, exact protected parent, live required checks and App integration IDs, tracked issue set, and deterministic artifact inputs.

Toolkit 0.4.7 adds conservative exact-SHA GitLab approval without automatic unapproval, proves actionable suggestion ranges against the immutable reviewed head, and qualifies OCR 1.9.0 through 1.9.1. Python support remains >=3.12,<3.15, runtime dependencies remain empty, English remains the default, and the mandatory built-in evidence MCP remains independent from optional external MCP servers.

External delivery pending after merge

  • stable TestPyPI and PyPI byte/hash readback;
  • PyPI Integrity provenance and GitHub artifact attestations;
  • annotated v0.4.7 tag, exact immutable GitHub Release assets, and release-receipt.json;
  • published-artifact installs on Python 3.12, 3.13, and 3.14;
  • bot-owned receipt comments and completed closure of issues 70-73.

These facts do not exist yet and are intentionally not claimed by this PR. The release workflow and independent readback complete them after squash merge. This is the final repository mutation for the 0.4.7 lifecycle; no separate closure PR is planned.

@xeonvs
xeonvs marked this pull request as ready for review August 11, 2026 09:48
@xeonvs
xeonvs merged commit 3caa50b into main Aug 11, 2026
13 checks passed
@xeonvs
xeonvs deleted the release/v0.4.7 branch August 11, 2026 09:51
@xeonvs
xeonvs deployed to testpypi-public-disclosure August 11, 2026 09:52 — with GitHub Actions Active
@xeonvs
xeonvs deployed to pypi-production August 11, 2026 09:53 — with GitHub Actions Active
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant