Skip to content

Toolkit 0.10.0: local review provider, diagnostics and OCR controls - #184

Merged
xeonvs merged 16 commits into
mainfrom
codex/v0.10.0-local-review
Sep 9, 2026
Merged

xeonvs merged 16 commits into
mainfrom
codex/v0.10.0-local-review

Conversation

@xeonvs

@xeonvs xeonvs commented Sep 8, 2026 •

Copy link
Copy Markdown
Owner

Scope and delivery state

Closes #181 and #182 for release 0.10.0 and replaces planning Draft #183. The reviewed base is 8ae890b6f78388554281e649dc8201737679968a; this PR head is d805df19a4f1e593a223b5a172b651c28209a734.

Delivered

  • Shared provider-neutral review reporting while preserving GitLab-only acquisition, receipts, publication, suppression, discussions, and approval behavior.
  • Standalone preflight --local / review --local using the normal OCR, LLM, tools, validation, and DLP pipeline, with private Markdown plus console delivery and no forge mutation.
  • Bounded private debug bundles, explicit reasoning controls, OCR 1.11.6 qualification, and safe optional progress.
  • Final remediation from the owner-authorized local OCR review: descriptor-pinned report/debug parents prevent visible-ancestor replacement redirects; exact multipart truncation is truthful; independent warnings survive incomplete coverage; interrupts propagate; and optional progress safely disables on conventional blocking CI stderr rather than risking the review. Interactive terminals and explicitly nonblocking embedding streams retain bounded phase progress.
  • The canonical decision-flow document now includes the detailed progress observer diagram and is linked from the repository instructions.

Verification

  • Local final remediation validation: scripts/quality.sh check — 1711 tests, 408 subtests, 86.72% coverage; Gitleaks, Ruff formatting, mypy, Bandit, git diff --check, and Towncrier 0.10.0 draft passed.
  • The one authorized real local OCR review completed the full prior Draft range with OCR 1.11.6 and openai/gpt-5.6-terra; its private artifacts remain retained. No additional OCR run was performed after remediation.
  • Fresh Codex Security diff scan ea5159c6-c05c-45fd-8268-69429c1d3184 reviewed only 99cac29..d805df1: complete coverage, zero findings.
  • Exact-head hosted checks passed: CI, Build artifacts, Security, CodeQL, and Dependency review.
  • The remediation commit is SSH-signed; no review threads are open.

The PR is ready for its authorized protected squash merge. Stable publication, compact artifact identity readback, issue/milestone closure, and the required docs-only no-release reconciliation follow separately under the release contract; no private OCR diagnostics or provider values are published here.

@xeonvs xeonvs added this to the v0.10.0 milestone Sep 8, 2026
@xeonvs xeonvs self-assigned this Sep 8, 2026
@xeonvs
xeonvs marked this pull request as ready for review September 9, 2026 11:20
@xeonvs
xeonvs merged commit 9cfa6b6 into main Sep 9, 2026
1 check passed
@xeonvs
xeonvs deleted the codex/v0.10.0-local-review branch September 9, 2026 11:21
@xeonvs xeonvs mentioned this pull request Sep 9, 2026
xeonvs added a commit that referenced this pull request Sep 9, 2026
## Scope

Prepare and authorize stable toolkit **v0.10.0** for the completed OCR
1.11.6
qualification and standalone local-provider work tracked by:

- #181
- #182

This release PR contains repository-side preparation only. Stable
publication
and external reconciliation remain pending until this exact PR is merged
and
the protected Release workflow completes.

## Reviewed implementation

- Feature PR: #184
- Reviewed feature head: `d805df19a4f1e593a223b5a172b651c28209a734`
- Protected squash merge: `9cfa6b645119ed9230e790cca585376dd906dacc`
- Release base: `9cfa6b645119ed9230e790cca585376dd906dacc`
- Release head: `1192787b8a150964f0d99d832552273019163ac0`

## Development publication

- Workflow:
https://github.com/xeonvs/open-code-review-toolkit/actions/runs/34345119338
- Deterministic TestPyPI build, publication, provenance verification,
and
wheel/sdist installation smoke all passed. This is a development
artifact,
  not stable delivery.

## Release preparation

- Stable marker: `0.10.0`
- Next development marker: `0.10.1`
- Deterministic source epoch: `1788952887`
- Authorized issue set: `[181, 182]`
- Towncrier fragments were rendered into `CHANGELOG.md`.
- Public GitLab example now pins toolkit `0.10.0`.
- The complete execution plan is archived at
`docs/engineering/execution_history/releases.md#plan-toolkit-0-10-0`
with
  stable external delivery pending.
- `.release-reconciled-version` intentionally remains `0.9.1` until
  independent external readback is complete.

## Release validation

- `scripts/quality.sh check`: **1,712 tests, 408 subtests, 86.72%
coverage**.
- Focused release/documentation suite: **121 passed**.
- Ruff formatting, MyPy, Bandit, `uv lock --check`, OCR manifest
validation,
  `pip-audit`, release-note extraction, `git diff --check`, and pinned
  Gitleaks 8.24.3 passed.
- Two independent builds with the release source epoch were
byte-identical and
  passed Twine. Wheel SHA-256:
  `8254b332993582d921c5ac12fc14e7e6496a85779a652ec3c3d215ba0740f1f1`;
  sdist SHA-256:
  `5f0aa399cb2458e208ac5e7ae16e8b78f92fc493cc3a37fca11e4d63ae060e45`.
- Clean wheel and sdist installations passed `ocr-ci --help` smoke
checks.
- The authorized OCR review was already completed for feature work using
OCR
1.11.6 and `openai/gpt-5.6-terra`; it is not repeated for release
metadata.

## Post-merge gates

The protected Release workflow must independently prove registry bytes,
PEP 740
provenance, GitHub attestations, annotated tag target, immutable GitHub
Release
and exact assets, the release receipt, supported-Python registry
installs, and
Actions-owned issue receipts. It then closes #181 and #182. After
compact
independent readback and milestone closure, one protected
documentation-only
no-release reconciliation PR will record those facts and advance
`.release-reconciled-version` without producing another stable release.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[OCR compatibility] Qualify v1.11.6

1 participant