Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -111,7 +111,7 @@ jobs:
--source-sha "$SOURCE_SHA" --dist "$RUNNER_TEMP/rehearsal-dist"
- name: Rehearse the exact installed wheel offline
run: |
python scripts/rehearse_v150.py --dist "$RUNNER_TEMP/rehearsal-dist" \
python scripts/rehearse_v151.py --dist "$RUNNER_TEMP/rehearsal-dist" \
--source-sha "$SOURCE_SHA" --work-dir "$RUNNER_TEMP/rehearsal"
- name: Upload sanitized pre-merge evidence
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/release-candidate.yml
Original file line number Diff line number Diff line change
Expand Up @@ -63,7 +63,7 @@ jobs:
env:
SOURCE_SHA: ${{ inputs.expected_sha }}
run: |
python scripts/rehearse_v150.py --dist "$RUNNER_TEMP/candidate" \
python scripts/rehearse_v151.py --dist "$RUNNER_TEMP/candidate" \
--source-sha "$SOURCE_SHA" --work-dir "$RUNNER_TEMP/rehearsal"
cp "$RUNNER_TEMP/rehearsal/rehearsal.json" "$RUNNER_TEMP/candidate/rehearsal.json"

Expand Down
6 changes: 6 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,12 @@ later entries are regular releases.

## Unreleased

No additional changes recorded.

## 1.5.1 — release

Cross-provider installation, audit provenance, safe initialization, remote-observer diagnostics, and Board/status clarity. See [release notes](docs/v151-release-notes.md) and the [qualification contract](docs/v151-qualification.md).

@gitar-bot gitar-bot Bot Sep 20, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Bug: CHANGELOG rewrites already-published v1.5.0 release text

CHANGELOG.md's ## 1.5.1 — release heading is new, but the diff also edits the pre-existing ## 1.5.0 — release section, changing "remain v1.5.1. Audit publication binds the current head reliably (#1025)." to "remain v1.6.0." This section documents the already-published v1.5.0 release. The project's own rule, stated in docs/pypi-release.md ("Editing main cannot repair that tagged README or the README embedded in its package. Never rewrite a published tag to correct the wording."), and echoed in README.md's example about immutable candidate text, forbids retroactively editing text that shipped in a prior release. Rewriting the v1.5.0 changelog entry to reflect a later roadmap decision (Slack telemetry deferred to v1.6.0 instead of v1.5.1) corrupts the historical record of what v1.5.0 actually stated at release time. The correct fix is to leave the v1.5.0 section's original wording untouched and only state the updated deferral target in the new v1.5.1 section/current-facing docs.

Revert the edit to the historical v1.5.0 entry and only reflect the v1.6.0 deferral in current-facing text (already updated in docs/current-state-and-roadmap.md and the new v1.5.1 release notes).:

- Explicit `slack setup` hosted manifest and redacted `slack doctor` (#1024).
  Default install remains Slack-free. Offline snapshots never prove live readiness.
  Basic private-workspace interaction only; telemetry/Board links and rich UX
  remain v1.5.1. Audit publication binds the current head reliably (#1025).

Was this helpful? React with 👍 / 👎


- Local audit publication now binds each reviewer seal to the exact Actions
job, matrix lane, run, and first attempt that produced it. Independent Codex
and Claude lanes in one run no longer make publication ambiguous, while a
Expand Down
22 changes: 11 additions & 11 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,12 +9,12 @@ Code Mower is supervised-pilot, bring-your-own-agent-loop software.
It is not a drop-in unattended merge gate. Humans still own credentials,
repository policy, reviewer promotion, and exceptional decisions.

This source defines Code Mower `v1.5.0`, with package spec
`code-mower==1.5.0`. Confirm the release tag on GitHub Releases and the package
This source defines Code Mower `v1.5.1`, with package spec
`code-mower==1.5.1`. Confirm the release tag on GitHub Releases and the package
version on the selected index before using an index install command; source
version and publication state are separate facts. See the
[v1.5.0 release notes](https://github.com/codemower-ai/code-mower/blob/main/docs/v150-release-notes.md)
and [qualification contract](https://github.com/codemower-ai/code-mower/blob/main/docs/v150-qualification.md).
[v1.5.1 release notes](https://github.com/codemower-ai/code-mower/blob/main/docs/v151-release-notes.md)
and [qualification contract](https://github.com/codemower-ai/code-mower/blob/main/docs/v151-qualification.md).
After publication, the GitHub Release and linked release issue carry the
observed source SHA, artifact digests, canary outcomes, publication run and
reinstall evidence.
Expand All @@ -25,7 +25,7 @@ not claimed by its immutable qualification record.

Documentation on `main` follows the source on `main`. For an installed release,
read its immutable versioned guide, such as the
[`v1.5.0` guide](https://github.com/codemower-ai/code-mower/blob/v1.5.0/docs/try-in-10-minutes.md),
[`v1.5.1` guide](https://github.com/codemower-ai/code-mower/blob/v1.5.1/docs/try-in-10-minutes.md),
and confirm the tag and package exist before using pinned install commands.

## What Code Mower Adds
Expand Down Expand Up @@ -54,13 +54,13 @@ one stable `pipx` installation:
```bash
python3.12 --version
export CODE_MOWER_PYTHON="$(command -v python3.12)"
pipx install --python "$CODE_MOWER_PYTHON" code-mower==1.5.0
pipx install --python "$CODE_MOWER_PYTHON" code-mower==1.5.1
command -v code-mower
code-mower --version
```

`command -v code-mower` should print the path you expect and `code-mower
--version` should print `code-mower 1.5.0` before you point Code Mower at a
--version` should print `code-mower 1.5.1` before you point Code Mower at a
repository. If you do not have pipx, install it from the
[official pipx installation guide](https://pipx.pypa.io/stable/installation/).

Expand Down Expand Up @@ -285,7 +285,7 @@ for both workflows, supported behavior, and the trust boundary.

## Current Capabilities And Limits

| Area | v1.5.0 posture |
| Area | v1.5.1 posture |
| --- | --- |
| Default builders and reviewers | Claude Code + Codex |
| Session hosts | Codex, Claude Code, and Cursor qualified; other identities recognized but require explicit handoff/provider transport |
Expand All @@ -299,7 +299,7 @@ for both workflows, supported behavior, and the trust boundary.

GitLab, Bitbucket, broad unattended rollout, uncalibrated merge gates, Devin
peer-orchestrator/reviewer parity, a hosted work-order CLI, a required Graphify
dependency, Slack telemetry/Board links, and rich Slack UX are outside v1.5.0. The current priorities
dependency, Slack telemetry/Board links, and rich Slack UX are outside v1.5.1. The current priorities
and boundaries are recorded in
[Current State And Roadmap](https://github.com/codemower-ai/code-mower/blob/main/docs/current-state-and-roadmap.md).

Expand Down Expand Up @@ -400,9 +400,9 @@ does not need rebuilding. See
- [Cloud Data Contract](https://github.com/codemower-ai/code-mower/blob/main/docs/cloud-data-contract.md)
- [Release Qualification](https://github.com/codemower-ai/code-mower/blob/main/docs/release-qualification.md)
- [Public Release Checklist](https://github.com/codemower-ai/code-mower/blob/main/docs/public-release-checklist.md)
- [v1.5.0 Release Notes](https://github.com/codemower-ai/code-mower/blob/main/docs/v150-release-notes.md)
- [v1.5.1 Release Notes](https://github.com/codemower-ai/code-mower/blob/main/docs/v151-release-notes.md)
- [v1.4.2 Release Notes](https://github.com/codemower-ai/code-mower/blob/main/docs/v142-release-notes.md)
- [v1.5.0 Qualification Contract](https://github.com/codemower-ai/code-mower/blob/main/docs/v150-qualification.md)
- [v1.5.1 Qualification Contract](https://github.com/codemower-ai/code-mower/blob/main/docs/v151-qualification.md)
- [v1.4.2 Qualification Record](https://github.com/codemower-ai/code-mower/blob/main/docs/v142-qualification.md)
- [Release History And Archived Plans](https://github.com/codemower-ai/code-mower/blob/main/docs/release-history.md)
- [Changelog](https://github.com/codemower-ai/code-mower/blob/main/CHANGELOG.md)
Expand Down
17 changes: 16 additions & 1 deletion code-mower-package-manifest.json
Original file line number Diff line number Diff line change
Expand Up @@ -307,6 +307,21 @@
"source": "docs/v150-release-runbook.md",
"target": "docs/v150-release-runbook.md"
},
{
"kind": "doc",
"source": "docs/v151-qualification.md",
"target": "docs/v151-qualification.md"
},
{
"kind": "doc",
"source": "docs/v151-release-notes.md",
"target": "docs/v151-release-notes.md"
},
{
"kind": "doc",
"source": "docs/v151-release-runbook.md",
"target": "docs/v151-release-runbook.md"
},
{
"kind": "package",
"source": "generated",
Expand Down Expand Up @@ -2290,6 +2305,6 @@
"module": "code_mower",
"name": "code-mower",
"source_layout": "src/code_mower",
"version": "1.5.0"
"version": "1.5.1"
}
}
6 changes: 3 additions & 3 deletions docs/build-loop-in-30-minutes.md
Original file line number Diff line number Diff line change
Expand Up @@ -57,14 +57,14 @@ If path A has not been completed in this repository, do this reviewer-gate
checkpoint first. If you already have a merged setup PR with Codex and Claude
audit evidence, skip to section 2.

Confirm `code-mower==1.5.0` is visible on the selected package index before
Confirm `code-mower==1.5.1` is visible on the selected package index before
running this install block. Prepublication qualification uses the retained
candidate wheel from the [v1.5.0 release runbook](v150-release-runbook.md).
candidate wheel from the [v1.5.1 release runbook](v151-release-runbook.md).

```bash
python3.12 --version
export CODE_MOWER_PYTHON="$(command -v python3.12)"
pipx install --python "$CODE_MOWER_PYTHON" code-mower==1.5.0
pipx install --python "$CODE_MOWER_PYTHON" code-mower==1.5.1
gh auth status >/dev/null 2>&1 && echo "gh auth ok" || { echo "gh auth NOT ready"; false; }
code-mower init --easy
code-mower init --easy --apply --output-dir .code-mower.generated
Expand Down
10 changes: 5 additions & 5 deletions docs/current-state-and-roadmap.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,12 +22,12 @@ dry-run-first.

## Current Source And Published Baseline

This source defines Code Mower `v1.5.0`, with package spec
`code-mower==1.5.0`. Confirm the release tag on GitHub Releases and the package
This source defines Code Mower `v1.5.1`, with package spec
`code-mower==1.5.1`. Confirm the release tag on GitHub Releases and the package
version on the selected index before using an index install command; source
version and publication state are separate facts. See the
[v1.5.0 release notes](https://github.com/codemower-ai/code-mower/blob/main/docs/v150-release-notes.md)
and [qualification contract](https://github.com/codemower-ai/code-mower/blob/main/docs/v150-qualification.md).
[v1.5.1 release notes](https://github.com/codemower-ai/code-mower/blob/main/docs/v151-release-notes.md)
and [qualification contract](https://github.com/codemower-ai/code-mower/blob/main/docs/v151-qualification.md).
After publication, the GitHub Release and linked release issue carry the
observed source SHA, artifact digests, canary outcomes, publication run and
reinstall evidence.
Expand Down Expand Up @@ -310,7 +310,7 @@ administration/readiness; #920 consumes the immutable candidate to obtain one
accepted completion and one accepted confirmed cancellation under an explicit
numeric cap while preserving every attempt and reservation; #923 records the
tag, publication and independent reinstall evidence.
Slack telemetry/Board/cloud links and rich UX remain v1.5.1. Slack consumes the
Slack telemetry/Board/cloud links and rich UX remain v1.6.0. Slack consumes the
durable lifecycle instead of scraping terminal or Board output and carries no
raw private context or private reviewer findings.

Expand Down
8 changes: 4 additions & 4 deletions docs/early-adopter-invite-runbook.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# Early Adopter Invite Runbook

Source target: v1.5.0 supervised-pilot baseline. Release invitations and pinned
index installs target `code-mower==1.5.0` only after that version is visible on
index installs target `code-mower==1.5.1` only after that version is visible on
the selected package index.

Use this runbook for the first 5-10 friendly users before widening Code Mower
Expand Down Expand Up @@ -41,8 +41,8 @@ Want to try Code Mower for 10 minutes?
It is an OSS local-first tool for setting up AI peer-programmer/reviewer lanes
on your real codebase, with optional privacy-first cloud reporting.

After v1.5.0 is published, start here:
https://github.com/codemower-ai/code-mower/blob/v1.5.0/docs/try-in-10-minutes.md
After v1.5.1 is published, start here:
https://github.com/codemower-ai/code-mower/blob/v1.5.1/docs/try-in-10-minutes.md

Cloud sharing is optional. The default bundle excludes source code, raw diffs,
model transcripts, raw stdout/stderr, auth output, and secrets.
Expand All @@ -57,7 +57,7 @@ Before inviting a user:
```bash
python3.12 --version
export CODE_MOWER_PYTHON="$(command -v python3.12)"
pipx install --python "$CODE_MOWER_PYTHON" code-mower==1.5.0
pipx install --python "$CODE_MOWER_PYTHON" code-mower==1.5.1
code-mower --version
```

Expand Down
22 changes: 11 additions & 11 deletions docs/first-user-install-rehearsal.md
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
# First-User Install Rehearsal

v1.5.0 uses the exact install pin `code-mower==1.5.0`. Verify that version is
v1.5.1 uses the exact install pin `code-mower==1.5.1`. Verify that version is
published on the selected index, then verify the command path and version after
installing. The [v1.5.0 qualification contract](v150-qualification.md) defines
installing. The [v1.5.1 qualification contract](v151-qualification.md) defines
the required evidence. After publication, the GitHub Release and linked release
issue carry the observed source SHA, artifact digests, canary outcomes,
publication run and reinstall evidence. Use the
[candidate runbook](v150-release-runbook.md) for
[candidate runbook](v151-release-runbook.md) for
prepublication local-wheel rehearsals. Offline preparation does not establish
live Slack readiness.

Expand Down Expand Up @@ -59,7 +59,7 @@ Use the current public tag or release candidate:

```bash
code-mower migration package-install-rehearsal \
--package-spec code-mower==1.5.0 \
--package-spec code-mower==1.5.1 \
--allow-package-index \
--python "$(command -v python3.12)" \
--json
Expand All @@ -83,7 +83,7 @@ For a fixed output directory:

```bash
code-mower migration package-install-rehearsal \
--package-spec code-mower==1.5.0 \
--package-spec code-mower==1.5.1 \
--allow-package-index \
--python "$(command -v python3.12)" \
--work-dir /tmp/code-mower-first-user-rehearsal \
Expand Down Expand Up @@ -127,7 +127,7 @@ deciding the package index or the release is broken. For pipx:

```bash
export CODE_MOWER_PYTHON="$(command -v python3.12)"
PIP_NO_CACHE_DIR=1 pipx install --force --python "$CODE_MOWER_PYTHON" code-mower==1.5.0
PIP_NO_CACHE_DIR=1 pipx install --force --python "$CODE_MOWER_PYTHON" code-mower==1.5.1
code-mower --version
```

Expand All @@ -137,7 +137,7 @@ For uv:
env -u UV_INDEX -u UV_DEFAULT_INDEX -u UV_INDEX_URL -u UV_EXTRA_INDEX_URL \
-u UV_FIND_LINKS -u UV_NO_INDEX -u UV_OFFLINE \
uv --no-config --no-cache tool install --python 3.12 --reinstall \
--default-index https://pypi.org/simple/ code-mower==1.5.0
--default-index https://pypi.org/simple/ code-mower==1.5.1
code-mower --version
```

Expand Down Expand Up @@ -168,7 +168,7 @@ repository after the package install succeeds:

```bash
code-mower migration package-install-rehearsal \
--package-spec code-mower==1.5.0 \
--package-spec code-mower==1.5.1 \
--allow-package-index \
--repo-path /path/to/external-repo \
--python "$(command -v python3.12)" \
Expand Down Expand Up @@ -260,7 +260,7 @@ When a product repository already has Code Mower wrapper files, the same

```bash
code-mower migration package-install-rehearsal \
--package-spec code-mower==1.5.0 \
--package-spec code-mower==1.5.1 \
--allow-package-index \
--repo-path /path/to/product-repo \
--python "$(command -v python3.12)" \
Expand Down Expand Up @@ -321,9 +321,9 @@ If this fails, fix the first-user path before cutting or promoting a release.
## Stable Package-Index Release Procedure

The following v1.4.2 publication commands are historical evidence, not the
v1.5.0 sequence. For v1.5.0 build the merge-SHA candidate first, qualify it in
v1.5.1 sequence. For v1.5.1 build the merge-SHA candidate first, qualify it in
#918 and explicitly authorized #920, then tag/publish the unchanged source SHA
and the same artifacts through #923. Follow [the current runbook](v150-release-runbook.md).
and the same artifacts through #923. Follow [the current runbook](v151-release-runbook.md).

Publish and rehearse the package-index artifacts in this order. After the
release tag exists at the release commit, dispatch both package-index
Expand Down
10 changes: 5 additions & 5 deletions docs/friendly-user-rollout-v05.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# Friendly-User Rollout Plan

Source target: v1.5.0 supervised-pilot baseline. Release invitations and pinned
index installs target `code-mower==1.5.0` only after that version is visible on
index installs target `code-mower==1.5.1` only after that version is visible on
the selected package index.

This is the operating plan for the first 5-10 friendly users before Code Mower
Expand Down Expand Up @@ -33,14 +33,14 @@ out in the invite:
```bash
python3.12 --version
export CODE_MOWER_PYTHON="$(command -v python3.12)"
pipx install --python "$CODE_MOWER_PYTHON" code-mower==1.5.0
pipx install --python "$CODE_MOWER_PYTHON" code-mower==1.5.1
```

This source defines Code Mower `v1.5.0`, with package spec
`code-mower==1.5.0`. Confirm the release tag on GitHub Releases and the package
This source defines Code Mower `v1.5.1`, with package spec
`code-mower==1.5.1`. Confirm the release tag on GitHub Releases and the package
version on the selected index before using an index install command; source
version and publication state are separate facts. After publication, see the
[v1.5.0 release](https://github.com/codemower-ai/code-mower/releases/tag/v1.5.0).
[v1.5.1 release](https://github.com/codemower-ai/code-mower/releases/tag/v1.5.1).

## Invite Criteria

Expand Down
Loading
Loading