Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ jobs:
run: |
set -euo pipefail
printf '%s\n' "$EXPECTED_SHA" | grep -Eq '^[0-9a-f]{40}$'
test "$ACTUAL_REF" = "refs/tags/v1.4.1"
test "$ACTUAL_REF" = "refs/tags/v1.4.2"
test "$ACTUAL_SHA" = "$EXPECTED_SHA"

build-distributions:
Expand Down
55 changes: 37 additions & 18 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,21 +5,7 @@ project used alpha/beta prerelease tags while the first-user setup path,
provider posture, and optional cloud sharing loop were hardening; v1.0 and
later entries are regular releases.

## 1.4.1 — source candidate (publication pending)

- Add inert `init --graphify` guidance for the accepted separate-environment
0.9.58 pin; keep default installation free of Graphify dependencies/indexing.
- Clarify starter-to-installed Devin verification and 12-hour session lease
discovery, renewal and same-ID cross-process release.
- Prepare versioned release gates, package materialization and qualification
evidence for the accepted stabilization, lineage and Graphify baseline.
See [candidate notes](docs/v141-release-notes.md) for inclusion and limitations.
Publication, installed-package acceptance and release-specific scorecard,
campaign, Board and cloud evidence remain pending #915.

## Unreleased

### Added
## 1.4.2 — source candidate (publication pending)

- `code-mower board service` manages a persistent local Board: render a
reviewable definition, install, inspect, restart, and remove it. macOS uses
Expand All @@ -29,13 +15,46 @@ later entries are regular releases.
another supervisor on the port, or an ambiguous repository selection. The
serving gate validates port, repository slug, exact private repository path,
installed version, serving version, and the exact argument list behind a
delayed health check. Exact local paths stay local.
delayed health check. Exact local paths stay local (#961).
See [Board service lifecycle](docs/board-service-lifecycle.md).
- `code-mower board stop --repo OWNER/REPO` resolves one exact known binding.
Selectors must agree: an ambiguous, duplicate, or contradicting
repository/port/PID selection stops nothing, and a port a keepalive-managed
service would immediately reclaim is refused instead of reported as stopped.
`board list` now marks each Board managed or transient.
service would immediately reclaim is refused instead of reported as
stopped. `board list` now marks each Board managed or transient (#961).
- Board's work-first Now/Timeline/Releases/Health views, provider-neutral
remote lifecycle observations, exact local work observations, and the
qualified independent head-bound evidence and session-visibility
composition are accepted on `main` (#999, #1000, #1001, #1002, #1003 / #951).
This source PR adds no new cloud event fields; Slack-specific and hosted
cloud mappings remain #921.
- Version, changelog, release notes, current docs, and package/release
qualification contracts updated for v1.4.2, distinguishing local Board
visibility from future Slack/cloud mappings.
See [candidate notes](docs/v142-release-notes.md) and the
[evidence matrix](docs/v142-qualification.md) for inclusion and limitations.
Publication, installed-package acceptance, restart verification against the
two observed local Board services (port 5332, `codemower-ai/code-mower`,
plus one additional private-repository port, each restarted by its
classified managed-or-transient posture), and the #951 bounded hosted
Devin canary remain pending #952.

## 1.4.1 — published

- Added inert `init --graphify` guidance for the accepted separate-environment
0.9.58 pin; default installation stays free of Graphify dependencies/indexing.
- Clarified starter-to-installed Devin verification and 12-hour session lease
discovery, renewal and same-ID cross-process release.
- Shipped versioned release gates, package materialization and qualification
evidence for the accepted stabilization, lineage and Graphify baseline.
See [release notes](docs/v141-release-notes.md) for inclusion and limitations.
Publication, installed-package acceptance and the release-specific
scorecard, campaign, Board and cloud evidence completed the #915 closeout.

## Unreleased

### Added

- Staged trusted lineage producer primitives for supervised takeover and same-writer
delivery persistence, authenticated semantic publication, explicit builder-label
reconciliation, and transport-preserving attribution. Independent workflow and
Expand Down
26 changes: 13 additions & 13 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,14 +9,14 @@ The current release is supervised-pilot, bring-your-own-agent-loop software.
It is not a drop-in unattended merge gate. Humans still own credentials,
repository policy, reviewer promotion, and exceptional decisions.

The current source candidate is `v1.4.1`, with target install spec
`code-mower==1.4.1`. Publication and installed-package qualification are pending
[#915](https://github.com/codemower-ai/code-mower/issues/915). The published
`v1.4.0` artifacts remain unchanged. Install commands below target v1.4.1 after
publication; candidate rehearsals use the exact verified artifact.
The current source candidate is `v1.4.2`, with target install spec
`code-mower==1.4.2`. Publication and installed-package qualification are pending
[#952](https://github.com/codemower-ai/code-mower/issues/952). The published
`v1.4.0` and `v1.4.1` artifacts remain unchanged. Install commands below target
v1.4.2 after publication; candidate rehearsals use the exact verified artifact.

Documentation on `main` follows the source on `main`. After v1.4.1 publication, start with the
[`v1.4.1` guide](https://github.com/codemower-ai/code-mower/blob/v1.4.1/docs/try-in-10-minutes.md).
Documentation on `main` follows the source on `main`. After v1.4.2 publication, start with the
[`v1.4.2` guide](https://github.com/codemower-ai/code-mower/blob/v1.4.2/docs/try-in-10-minutes.md).

## What Code Mower Adds

Expand Down Expand Up @@ -44,7 +44,7 @@ one stable `pipx` installation:
```bash
python3.12 --version
export CODE_MOWER_PYTHON="$(command -v python3.12)"
pipx install --python "$CODE_MOWER_PYTHON" code-mower==1.4.1
pipx install --python "$CODE_MOWER_PYTHON" code-mower==1.4.2
command -v code-mower
code-mower --version
```
Expand Down Expand Up @@ -114,7 +114,7 @@ ID with `session lease renew --session-id SESSION_ID` or `session lease release
--dry-run` or `--no-lease` for read-only work.

Codex, Claude Code, and Cursor are qualified for the shared session, telemetry,
lease, and Jira-authority contract in v1.4.1. Devin, Grok Bot, Antigravity,
lease, and Jira-authority contract in v1.4.2. Devin, Grok Bot, Antigravity,
Muse, and custom hosts are recognized for briefs and provenance, while their
execution remains an explicit handoff or provider-specific transport. See
[Participants And Sessions](docs/sessions.md) and the
Expand Down Expand Up @@ -222,7 +222,7 @@ and the [Cloud Data Contract](docs/cloud-data-contract.md).

## Current Capabilities And Limits

| Area | v1.4.1 posture |
| Area | v1.4.2 posture |
| --- | --- |
| Default builders and reviewers | Claude Code + Codex |
| Session hosts | Codex, Claude Code, and Cursor qualified; other identities recognized but require explicit handoff/provider transport |
Expand All @@ -236,7 +236,7 @@ and the [Cloud Data Contract](docs/cloud-data-contract.md).

GitLab, Bitbucket, broad unattended rollout, uncalibrated merge gates, Devin
peer-orchestrator/reviewer parity, a hosted work-order CLI, a required Graphify
dependency, and Slack worker delivery are outside the v1.4.1 candidate. The current priorities and
dependency, and Slack worker delivery are outside the v1.4.2 candidate. The current priorities and
boundaries are recorded in
[Current State And Roadmap](docs/current-state-and-roadmap.md).

Expand All @@ -249,7 +249,7 @@ boundaries are recorded in
- [Upgrade An Existing Repository](docs/upgrade-existing-repo.md)
- [Quickstart Reference](docs/quickstart.md)
- [Troubleshooting](docs/troubleshooting.md)
- [First Run Transcript](docs/first-run-transcript.md)
- [First Run Transcript](docs/first-run-transcript.md) (v1.4.0 illustrative shape, not the current v1.4.2 pin)

### Sessions, Builders, And Reviewers

Expand Down Expand Up @@ -291,7 +291,7 @@ boundaries are recorded in
- [Cloud Data Contract](docs/cloud-data-contract.md)
- [Release Qualification](docs/release-qualification.md)
- [Public Release Checklist](docs/public-release-checklist.md)
- [v1.4.1 Release Notes](docs/v141-release-notes.md)
- [v1.4.2 Release Notes](docs/v142-release-notes.md)
- [Release History And Archived Plans](docs/release-history.md)
- [Changelog](CHANGELOG.md)
- [Contributing](CONTRIBUTING.md)
Expand Down
2 changes: 1 addition & 1 deletion code-mower-package-manifest.json
Original file line number Diff line number Diff line change
Expand Up @@ -2170,6 +2170,6 @@
"module": "code_mower",
"name": "code-mower",
"source_layout": "src/code_mower",
"version": "1.4.1"
"version": "1.4.2"
}
}
2 changes: 1 addition & 1 deletion docs/build-loop-in-30-minutes.md
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,7 @@ audit evidence, skip to section 2.
```bash
python3.12 --version
export CODE_MOWER_PYTHON="$(command -v python3.12)"
pipx install --python "$CODE_MOWER_PYTHON" code-mower==1.4.1
pipx install --python "$CODE_MOWER_PYTHON" code-mower==1.4.2
gh auth status >/dev/null 2>&1 && echo "gh auth ok" || { echo "gh auth NOT ready"; false; }
code-mower init --easy
code-mower init --easy --apply --output-dir .code-mower.generated
Expand Down
4 changes: 2 additions & 2 deletions docs/builders-grok-cursor.md
Original file line number Diff line number Diff line change
Expand Up @@ -67,9 +67,9 @@ no builder sidecar. Use the separately staged
and its required `target_json`, `policy_json`, `authority_json`, and
`transport_json` inputs for reviewed integration by a trusted caller. That
producer owns the explicit-input contract; do not derive these inputs from PR
metadata or execute PR code/configuration to obtain them. The 1.4.1 source
metadata or execute PR code/configuration to obtain them. The 1.4.2 source
candidate remains unqualified and unpublished; activation against the released
package remains gated by #915.
package remains gated by #952.

Treat each PR branch as single-writer. The owning `builder:<lane>` identity is
the only lane that should push commits to that branch; other builders and audit
Expand Down
2 changes: 1 addition & 1 deletion docs/cloud-benchmarking.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ reports, and the local Board without a hosted account. CodeMower.com is an
optional destination for longitudinal team reporting and future aggregate
benchmarks.

## Current v1.4.1 Source Surface
## Current v1.4.2 Source Surface

The current client can:

Expand Down
65 changes: 39 additions & 26 deletions docs/current-state-and-roadmap.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,11 +22,11 @@ dry-run-first.

## Current Source Candidate And Published Baseline

The current source candidate is `v1.4.1`, with target install spec
`code-mower==1.4.1`. Publication and installed-package qualification are pending
[#915](https://github.com/codemower-ai/code-mower/issues/915).
The current source candidate is `v1.4.2`, with target install spec
`code-mower==1.4.2`. Publication and installed-package qualification are pending
[#952](https://github.com/codemower-ai/code-mower/issues/952).

The published v1.4.0 baseline requires Python 3.12 or newer. It provides:
The published v1.4.0 and v1.4.1 baselines require Python 3.12 or newer. Each provides:

- pipx, uv tool, and contributor installation paths;
- safe setup previews and selectable participants;
Expand Down Expand Up @@ -137,10 +137,13 @@ sequence from the stabilization epic is:
plus [#974](https://github.com/codemower-ai/code-mower/issues/974) evidence
verification. #963 is accepted through the #990/#991/#992 replacement stages
and final #997 integration, not the unaccepted #989 draft.
2. Ship those fixes together with Graphify as `v1.4.1`
2. Graphify shipped together with those fixes as `v1.4.1`
([#915](https://github.com/codemower-ai/code-mower/issues/915)).
3. Ship Board as `v1.4.2`. Board work is underway;
[#935](https://github.com/codemower-ai/code-mower/issues/935) is complete.
3. Ship Board as `v1.4.2`. Board's code is accepted on `main`, including
[#935](https://github.com/codemower-ai/code-mower/issues/935),
#956/#957/#999/#1000/#1002, #961 via PR #1001, and #951's PR #1003; #951
stays open only for its bounded hosted Devin canary, and #952 is the
release PR.
4. Supervised Slack remains planned for `v1.5.0`; its runtime work is deferred
until the sequence above is complete.

Expand All @@ -155,9 +158,10 @@ qualification, transport capability, repository policy, and runtime readiness.
It rejects an unqualified Devin orchestrator before lease or session writes and
checks bounded hosted builder admission before new work. See
[Participant Qualification](participant-qualification.md). These are main-line
stabilization changes awaiting the next package. Effective-authority rendering
stabilization changes that shipped in `v1.4.1`. Effective-authority rendering
([#955](https://github.com/codemower-ai/code-mower/issues/955)) is accepted through #988;
neither is part of the immutable `v1.4.0` artifact.
neither is part of the immutable `v1.4.0` artifact, and both are part of the
published `v1.4.1` artifact.

Each step below is an independently gated epic rather than one cross-cutting
implementation PR.
Expand Down Expand Up @@ -200,26 +204,36 @@ decision, and `code-mower context-graph`, described in the
#982) consumes
a pinned structured JSON contract and generates bounded impact, dependency,
symbol, and related-test packets in one shape for Claude, Codex, and Devin.
Release #915 prepares that accepted source and stabilization baseline for the
package. The release-specific comparative scorecard, installed artifacts,
publication, campaign, Board and fresh aggregate evidence remain pending.
Release #915 shipped that accepted source and stabilization baseline as
`v1.4.1`, completing the release-specific comparative scorecard, campaign,
Board, and fresh aggregate evidence as part of that closeout.

Installation stays opt-in, no command requires an index to exist, and Code
Mower owns refresh policy rather than parsing human-oriented MCP prose.

### 3. Board Clarity And Session Visibility — `v1.4.2` ([#945](https://github.com/codemower-ai/code-mower/issues/945) / release [#952](https://github.com/codemower-ai/code-mower/issues/952))

Board implementation is underway rather than unstarted.
Board implementation is accepted on `main`, not underway.
[#935](https://github.com/codemower-ai/code-mower/issues/935) is complete and
merged with [#973](https://github.com/codemower-ai/code-mower/issues/973);
[#956](https://github.com/codemower-ai/code-mower/issues/956) and
[#957](https://github.com/codemower-ai/code-mower/issues/957) are drafts behind
main that need refreshing before review. Remaining work is presentation and
producers, persistent Board services
([#961](https://github.com/codemower-ai/code-mower/issues/961)), and integrated
qualification ([#951](https://github.com/codemower-ai/code-mower/issues/951)),
then the release PR #952. #961 is required before #951 and #952, and #951
consumes #975, #955, #962, #963, and #976 through its integration dependencies.
[#957](https://github.com/codemower-ai/code-mower/issues/957) are merged, as
are the work-first Now/Timeline/Releases/Health views
([#1000](https://github.com/codemower-ai/code-mower/issues/1000)), exact
local work observations
([#999](https://github.com/codemower-ai/code-mower/issues/999)),
provider-neutral remote lifecycle observations
([#1002](https://github.com/codemower-ai/code-mower/issues/1002)), and
persistent Board services with stale-keepalive rejection during release
restart ([#961](https://github.com/codemower-ai/code-mower/issues/961), via
[PR #1001](https://github.com/codemower-ai/code-mower/pull/1001)).
#951's integrated qualification code (independent head-bound evidence and
session-visibility composition, via
[PR #1003](https://github.com/codemower-ai/code-mower/pull/1003)) is also
merged; #951 itself stays open only for its bounded hosted Devin canary,
which is tracked separately from this merged code evidence. Remaining work
is the release PR #952, which does not add cloud fields and does not claim
#951's pending hosted canary.

Board is a read model over one closed local observation model. Missing or stale
evidence stays explicitly unknown or last-observed; Board never infers runtime
Expand Down Expand Up @@ -250,16 +264,15 @@ documentation work.

1. Complete `v1.4.0` stabilization on main: the seven #979 implementation PRs
plus the #974 evidence verification.
2. Ship those main-only fixes together with Graphify as `v1.4.1` through #915,
after #914.
2. Graphify shipped together with those main-only fixes as `v1.4.1` through
#915, after #914.
3. Ship Board as `v1.4.2` through #952, after #961 and #951.
4. Merge the supervised Slack runtime last, accepted in #923 for `v1.5.0`.

Elapsed time, implementation difficulty, or an open draft PR never changes this
release order. An explicit evidence-backed Graphify deferral recorded in
#915/#902 may satisfy that one dependency. Merged post-`v1.4.0` fixes, including
#935/#973, count as on main until a later published package is verified to
contain them.
release order. Graphify's #915/#902 dependency is satisfied: it shipped as
`v1.4.1`. Merged post-`v1.4.0` fixes, including #935/#973, count as on main
until a later published package is verified to contain them.

Each child issue should produce one reviewable PR with one branch writer,
independent current-head review, the normal gate, and package-level validation.
Expand Down
8 changes: 4 additions & 4 deletions docs/early-adopter-invite-runbook.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# Early Adopter Invite Runbook

Current source target: v1.4.1. Publication and installed qualification remain
pending #915; release invitations and pinned index installs follow that acceptance.
Current source target: v1.4.2. Publication and installed qualification remain
pending #952; release invitations and pinned index installs follow that acceptance.

Use this runbook for the first 5-10 friendly users before widening Code Mower
to 20-50 early OSS users.
Expand Down Expand Up @@ -41,7 +41,7 @@ It is an OSS local-first tool for setting up AI peer-programmer/reviewer lanes
on your real codebase, with optional privacy-first cloud reporting.

Start here:
https://github.com/codemower-ai/code-mower/blob/v1.4.1/docs/try-in-10-minutes.md
https://github.com/codemower-ai/code-mower/blob/v1.4.2/docs/try-in-10-minutes.md

Cloud sharing is optional. The default bundle excludes source code, raw diffs,
model transcripts, raw stdout/stderr, auth output, and secrets.
Expand All @@ -56,7 +56,7 @@ Before inviting a user:
```bash
python3.12 --version
export CODE_MOWER_PYTHON="$(command -v python3.12)"
pipx install --python "$CODE_MOWER_PYTHON" code-mower==1.4.1
pipx install --python "$CODE_MOWER_PYTHON" code-mower==1.4.2
code-mower --version
```

Expand Down
6 changes: 3 additions & 3 deletions docs/early-adopter-v05.md
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
# Code Mower Early Adopter Guide

Current source target: v1.4.1. Publication and installed qualification remain
pending #915; release invitations and pinned index installs follow that acceptance.
Current source target: v1.4.2. Publication and installed qualification remain
pending #952; release invitations and pinned index installs follow that acceptance.

This document records the historical v0.5 early-adopter product plan. The
current public install path is the v1.4.1 supervised-pilot release; use
current public install path is the v1.4.2 supervised-pilot release; use
[Install And Bootstrap](install.md), [Try Code Mower In 10 Minutes](try-in-10-minutes.md),
and [Quickstart](quickstart.md) for live adoption steps.

Expand Down
5 changes: 5 additions & 0 deletions docs/first-run-transcript.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,10 @@
# First Run Transcript

Historical: this transcript is pinned to the published `v1.4.0` shape and is
not updated for the current `v1.4.2` candidate. Use [Install And
Bootstrap](install.md) and [Try Code Mower In 10
Minutes](try-in-10-minutes.md) for current guidance.

This page shows the intended first-run shape before a user installs anything.
It is a static transcript, not a guarantee that every machine will produce the
same provider warnings.
Expand Down
5 changes: 5 additions & 0 deletions docs/first-user-demo-transcript.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,10 @@
# First-User Demo Transcript

Historical: this transcript is pinned to the published `v1.4.0` shape and is
not updated for the current `v1.4.2` candidate. Use [Quickstart](quickstart.md)
and [First-User Install Rehearsal](first-user-install-rehearsal.md) for
current guidance.

This is a sanitized transcript of the first-user install rehearsal shape. It is
designed for someone evaluating Code Mower for the first time: no private repo,
no provider tokens, no uploads, and no hidden local machine assumptions.
Expand Down
Loading
Loading