Skip to content

Release v0.10.0 - #185

Merged
xeonvs merged 1 commit into
mainfrom
release/v0.10.0
Sep 9, 2026
Merged

xeonvs merged 1 commit into
mainfrom
release/v0.10.0

Conversation

@xeonvs

@xeonvs xeonvs commented Sep 9, 2026 •

Copy link
Copy Markdown
Owner

Scope

Prepare and authorize stable toolkit v0.10.0 for the completed OCR 1.11.6
qualification and standalone local-provider work tracked by:

This release PR contains repository-side preparation only. Stable publication
and external reconciliation remain pending until this exact PR is merged and
the protected Release workflow completes.

Reviewed implementation

Development publication

Release preparation

  • Stable marker: 0.10.0
  • Next development marker: 0.10.1
  • Deterministic source epoch: 1788952887
  • Authorized issue set: [181, 182]
  • Towncrier fragments were rendered into CHANGELOG.md.
  • Public GitLab example now pins toolkit 0.10.0.
  • The complete execution plan is archived at
    docs/engineering/execution_history/releases.md#plan-toolkit-0-10-0 with
    stable external delivery pending.
  • .release-reconciled-version intentionally remains 0.9.1 until
    independent external readback is complete.

Release validation

  • scripts/quality.sh check: 1,712 tests, 408 subtests, 86.72% coverage.
  • Focused release/documentation suite: 121 passed.
  • Ruff formatting, MyPy, Bandit, uv lock --check, OCR manifest validation,
    pip-audit, release-note extraction, git diff --check, and pinned
    Gitleaks 8.24.3 passed.
  • Two independent builds with the release source epoch were byte-identical and
    passed Twine. Wheel SHA-256:
    8254b332993582d921c5ac12fc14e7e6496a85779a652ec3c3d215ba0740f1f1;
    sdist SHA-256:
    5f0aa399cb2458e208ac5e7ae16e8b78f92fc493cc3a37fca11e4d63ae060e45.
  • Clean wheel and sdist installations passed ocr-ci --help smoke checks.
  • The authorized OCR review was already completed for feature work using OCR
    1.11.6 and openai/gpt-5.6-terra; it is not repeated for release metadata.

Post-merge gates

The protected Release workflow must independently prove registry bytes, PEP 740
provenance, GitHub attestations, annotated tag target, immutable GitHub Release
and exact assets, the release receipt, supported-Python registry installs, and
Actions-owned receipts for the tracked release issue set after immutable receipt
readback. After compact independent readback and milestone closure, one protected
documentation-only no-release reconciliation PR will record those facts and advance
.release-reconciled-version without producing another stable release.

@xeonvs
xeonvs merged commit f33674e into main Sep 9, 2026
1 check passed
@xeonvs
xeonvs deleted the release/v0.10.0 branch September 9, 2026 11:45
@xeonvs
xeonvs deployed to testpypi-public-disclosure September 9, 2026 11:50 — with GitHub Actions Active
@xeonvs
xeonvs deployed to pypi-production September 9, 2026 11:51 — with GitHub Actions Active
xeonvs added a commit that referenced this pull request Sep 9, 2026
## Scope

Complete the already-published **v0.10.0** lifecycle with a strict,
documentation-only
`no-release` reconciliation. No package/runtime source, stable/dev
marker, release
metadata, tag, distribution, registry publication, provenance,
attestation, receipt,
or GitHub Release asset is changed.

## Verified delivery

- Release PR: #185
- Protected merge: `f33674ebe88eab10406123299e8a9c8728171781`
- Successful idempotent recovery: [workflow
34348030036](https://github.com/xeonvs/open-code-review-toolkit/actions/runs/34348030036)
- Immutable release:
[v0.10.0](https://github.com/xeonvs/open-code-review-toolkit/releases/tag/v0.10.0)
- Authorized issue set: #181, #182; each has one GitHub Actions-owned
receipt and is closed.
- Milestone `v0.10.0` is closed with zero open issues.

The first release workflow,
[34347350040](https://github.com/xeonvs/open-code-review-toolkit/actions/runs/34347350040),
passed its build, registry, provenance, attestation and supported-Python
gates, but GitHub returned an `Internal Server Error` while accepting
the new tag; no tag, Release, receipt, or issue receipt had been
created. The recovery dispatch reused the exact authorization tuple and
completed idempotently.

## Changes

1. Advance `.release-reconciled-version` from `0.9.1` to `0.10.0`.
2. Replace the pending v0.10.0 archive state with concise,
independently-read-back facts.
3. Update the archive index from stable-delivery handoff to completed
external reconciliation.
4. Document and test the rule that release PRs list tracked issues only
in non-closing prose: the Release workflow is their sole post-receipt
closure owner.
5. Correct the closed #185 PR body to remove the accidental closing
phrase that caused #181's premature merge-time closure; this does not
mutate any published artifact.

## Local validation and self-review

- `uv run pytest tests/test_operations_docs.py -q`: **31 passed**
- `uv run ruff format --check tests/test_operations_docs.py`: passed
- `uv run ruff check tests/test_operations_docs.py`: passed
- `git diff --check origin/main...HEAD`: passed
- `scripts/gitleaks.sh f33674e HEAD`:
passed
- Full scope review confirms exactly five files, all closure
documentation/marker/test surfaces.

No OCR or Codex Security rerun is appropriate for this no-release
closure; the sole
authorized final OCR review was already completed for the feature range,
while hosted
CI will validate this exact documentation head.

This branch was successfully deployed

2 active deployments
pypi-production — 1192787b Deployed Sep 9, 2026 by xeonvs via publish-pypi #102
testpypi-public-disclosure — 1192787b Deployed Sep 9, 2026 by xeonvs via publish-testpypi #102
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant