TAB-29: prepare Tabellio v0.7.0 release candidate - #56
Conversation
Entire-Checkpoint: 29c1c7c761ec
Entire-Checkpoint: 29c1c7c761ec
Entire-Checkpoint: 1a7858ccb0d6 Entire-Checkpoint: 29c1c7c761ec
Entire-Checkpoint: d123a88b9899 Entire-Checkpoint: 29c1c7c761ec
Entire-Checkpoint: 80c483965edd Entire-Checkpoint: 29c1c7c761ec
Entire-Checkpoint: 8648bed8c3f0 Entire-Checkpoint: 29c1c7c761ec
Entire-Checkpoint: 5f2b26ae1e15
Entire-Checkpoint: 79aed0fa931c
Entire-Checkpoint: a91d97f163c9
Entire-Checkpoint: 4370fb5a4f45
Entire-Checkpoint: d43fbf86bed8
Entire-Checkpoint: 7044872f4085
Entire-Checkpoint: 0c3674f381c8
Entire-Checkpoint: 00cd873c5d9a
Entire-Checkpoint: 0bdb97273214
ci: run Tabellio gates on macOS M4
Merge the published v0.6.0 runner identity contract with the TAB-18 through TAB-29 provenance rebuild, then add aligned release, install, validation, and GTM launch contracts. Plane-Work-Item: TAB-29 Entire-Checkpoint: e9c20a23247c
|
Linked to Plane Work Item(s) References This comment was auto-generated by Plane |
Write generated analytics evidence and symlink fixtures only in temporary directories so concurrent tests cannot change the runner fingerprint. Plane-Work-Item: TAB-29 Entire-Checkpoint: 1d61908f1ad0
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 34f6bff8ad
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
Plane-Work-Item: TAB-29 Entire-Checkpoint: 5624ce72982f
|
@codex review Please review updated head d9be7d3. It addresses the three prior findings: nested Git index flags, the installed provenance demo command, and package inclusion of private local state. Focused regressions, both exact-head gates, and an installed-package demo passed. The PR description contains the current evidence. |
|
Codex Review: Didn't find any major issues. Breezy! Reviewed commit: ℹ️ About Codex in GitHubCodex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback". |
Plane-Work-Item: TAB-29 Entire-Checkpoint: 5624ce72982f
|
Codex Review: Didn't find any major issues. Can't wait for the next one! Reviewed commit: ℹ️ About Codex in GitHubCodex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback". |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 26203793ae
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
Remove the obsolete v0.6 release manifest from the v0.7 candidate. Preserve legacy evidence readers while enforcing identity requirements from committed manifests. Plane-Work-Item: TAB-29 Entire-Checkpoint: 3fd6b8c1294c
Plane-Work-Item: TAB-29 Entire-Checkpoint: 3fd6b8c1294c
|
@codex review Please review exact head 5306a31. Both latest P1 findings are fixed: the obsolete v0.6 manifest is removed, and identity-required manifests reject legacy evidence without runner identity. Compatibility remains for non-identity-required manifests. Required GitHub checks, Buildkite #183, canonical and v0.7 local gates passed. Fixture repairs and regression tests are included. |
|
Codex Review: Didn't find any major issues. 🚀 Reviewed commit: ℹ️ About Codex in GitHubCodex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback". |
Summary
Prepare the Tabellio v0.7.0 release candidate so teams can install the package, identify the runner, and reject stale or conflicting candidate evidence.
Review fixes
tabellio-provenance-democommand.Validation
Exact candidate:
5306a31d616397f4f93f41e78065086a8d33b4e4.tabellio-pr-evidence-5306a31.json.refs/tabellio/validations:commits/5306a31d616397f4f93f41e78065086a8d33b4e4/validation-f8dc2fbc-cab3-48f1-89d5-dfa4bd385314.json.refs/tabellio/validations:commits/5306a31d616397f4f93f41e78065086a8d33b4e4/validation-2f43665c-7bff-43f3-8d46-2d3fb59a8318.json.Boundaries
This PR prepares source for v0.7.0. Merge does not publish an npm package, create a release, or deploy production. Historical PR #44 is superseded by this candidate.
Plane-Work-Item: TAB-29
Entire-Checkpoint: 3fd6b8c1294c