Fix v0.11.1 installation and OCR qualification - #216
Merged
Merged
Conversation
xeonvs
marked this pull request as ready for review
September 23, 2026 07:21
Merged
xeonvs
added a commit
that referenced
this pull request
Sep 23, 2026
## Release preparation Authorize stable v0.11.1 from the reviewed feature and OCR promotion merges. This PR advances the stable marker to 0.11.1 and the next development line to 0.12.0, binds the sorted milestone issues 214, 217, and 218, renders Towncrier, pins the public example to toolkit 0.11.1 with OCR 1.12.9, and archives the repository-complete plan with external delivery pending. The official installation now receives the hash-locked runtime dependency asset before the verified toolkit wheel; the stable workflow will publish and verify that asset with its receipt. Tracked milestone: v0.11.1 (#214, #217, #218). The Release workflow owns their final closure after immutable receipt readback. ## Validation - Feature PR #216 and OCR promotion PR #219 passed exact-head CI and merged; both development TestPyPI workflows completed successfully. - Hosted OCR qualification run 35831453766 established adjacent 1.12.8–1.12.9 compatibility, with source review for the F# Rules and selection change. - Local release/docs tests, full `scripts/quality.sh check`, release notes rendering, formatter, signed commit, and staged/tree/history Gitleaks passed. Stable registries, immutable GitHub Release, receipt readback, and external reconciliation remain post-merge gates.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem and result
The official GitLab example for toolkit 0.11.x installs only a wheel with
--no-deps, leaving MCP and other runtime dependencies absent on clean Python. Issue #214 tracks the fix. The recipe now verifies a releaseruntime-requirements.txtasset againstSHA256SUMS, installs its binary dependencies with hashes, then installs the verified toolkit wheel and runspip check. Build, development, and stable registry checks exercise a real installed MCP gateway/schema exchange; a clean wheel-only negative control fails as expected.The stable release workflow binds the runtime lock to provenance, checksums, receipt v2, draft recovery, and immutable asset readback while keeping PyPI/TestPyPI limited to wheel and sdist. The OCR qualification workflow installs frozen dependencies before probing, records a closed status even if setup fails, and preserves historical evidence through OCR 1.12.7 while checking the 1.12.8+ F# and exclusion contracts. Scheduled qualification pauses indefinitely from 2026-10-01 UTC; manual dispatch remains available.
The engineering workflow layer adopts 0.9.8 instruction routes, archive state, and optional GPT-6 utility/explorer/reviewer profiles. The repository's public-content and Gitleaks gates remain active.
Validation
git diff --check, staged/tree/history Gitleaks, and commit-signature verification passed.This PR prepares the feature; stable v0.11.1 publication follows the separate protected release PR and its registry/asset gates.