Skip to content

Release v0.11.0 - #212

Merged
xeonvs merged 1 commit into
mainfrom
release/v0.11.0
Sep 19, 2026
Merged

xeonvs merged 1 commit into
mainfrom
release/v0.11.0

Conversation

@xeonvs

@xeonvs xeonvs commented Sep 19, 2026 •

Copy link
Copy Markdown
Owner

Scope

Prepare and authorize stable toolkit v0.11.0 for the governed MCP federation, stage-aware DLP and OCR 1.12.0–1.12.7 qualification work tracked by:

This release PR contains repository-side preparation only. Stable publication and external reconciliation remain pending until this exact PR is merged and the protected Release workflow completes.

Reviewed implementation

Development publication

  • Workflow: https://github.com/xeonvs/open-code-review-toolkit/actions/runs/35444762966
  • Version: 0.11.0.dev98
  • Wheel SHA-256: 379684bce1983cb4058e1916bb4ae75c61d00cb8d7b0ccf45240b36b57122952
  • Sdist SHA-256: 36236b7246c722f8df35495775ce6b80c38b8c76fe40e4e7aca22a68fee11d34
  • Workflow verification passed provenance, exact TestPyPI bytes, hash-locked runtime dependency installation, and clean wheel/sdist CLI smokes.

Release preparation

  • Stable marker: 0.11.0
  • Next development marker: 0.12.0
  • Deterministic source epoch: 1789823158
  • Authorized issue set: [188, 189, 190, 191, 192, 193, 201, 202, 203, 204, 205, 206, 207, 209, 210]
  • Towncrier fragments are rendered into CHANGELOG.md.
  • Public GitLab example pins toolkit 0.11.0 with OCR 1.12.7.
  • Both feature and corrective plans are archived at docs/engineering/execution_history/releases.md#plan-toolkit-0-11-0 with stable external delivery pending.
  • .release-reconciled-version intentionally remains 0.10.1 until independent external readback.

Release validation

  • scripts/quality.sh check: passed.
  • Focused release/documentation suite: 109 passed.
  • Release-note extraction, marker contract and git diff --check: passed.
  • Local source-epoch-controlled builds are byte-identical and pass Twine plus clean wheel/sdist CLI smokes with the hash-locked runtime closure. Wheel SHA-256: fa64701e627e1045cb9b597f79c05f834265f160f127564dcec9702375e2f072; sdist SHA-256: 7a03f4bd1ff657f333111ef9155380fadcbd83f4beac0dce1f44d6818e0d103e.
  • Feature qualification already completed local OCR v1.12.7 (openai/gpt-5.6-terra, 61/61 reviews, 22 evidence MCP calls, four findings fixed) and Codex Security scan cc04b394-e16f-48b4-92ac-71cb2a27c963 with no reportable findings. No material security/runtime delta was introduced by this release-only commit.
  • Local Gitleaks did not run because the repository requires 8.30.1 while the local binary is 8.24.3; the exact-head hosted secrets gate is required before merge.

Post-merge gates

The protected Release workflow must independently prove stable TestPyPI/PyPI bytes, PEP 740 provenance, GitHub attestations, supported-Python installs, annotated tag target, immutable GitHub Release and exact five assets, the release receipt, and workflow-owned issue receipts. A later protected documentation-only reconciliation PR will record those facts, close the milestone from live state, and advance .release-reconciled-version without changing the published release.

@xeonvs
xeonvs marked this pull request as ready for review September 19, 2026 13:27
@xeonvs
xeonvs merged commit db18025 into main Sep 19, 2026
13 checks passed
@xeonvs
xeonvs deleted the release/v0.11.0 branch September 19, 2026 13:41
@xeonvs
xeonvs deployed to testpypi-public-disclosure September 19, 2026 13:49 — with GitHub Actions Active
@xeonvs
xeonvs deployed to pypi-production September 19, 2026 13:50 — with GitHub Actions Active

This branch was successfully deployed

2 active deployments
pypi-production — 9fdabc74 Deployed Sep 19, 2026 by xeonvs via publish-pypi #111
testpypi-public-disclosure — 9fdabc74 Deployed Sep 19, 2026 by xeonvs via publish-testpypi #111
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant