Releases: 0xprogrammable/hookbuilder
Release list
Programmable v4 Builder v0.6.0
Programmable v4 Builder v0.6.0
This release publishes the exact portable Builder package, generated plugin payload, manifest, SBOM, checksums, kernel
evidence, and release receipt for one immutable Git revision. Publication does not establish model behavior, project
approval, deployment, audit, Registry acceptance, provider support, or live product evidence.
Release scope
- Source-receipted, EVM-only Chainlink profiles and atomic product packs for CCIP, CRE, Data Feeds, Data Streams, and
VRF v2.5, composed with the matching generic safety capability instead of one umbrella context. - Independently authored Ethereum production invariants from a date-pinned ETHSkills review. ETHSkills source text and
code were not copied because the reviewed repository had no operative license file. - Concise common CLI journeys with at most three primary root causes and explicit exhaustive report output.
- Enforced end-to-end efficiency budgets covering model and judge usage, repository stages, emitted bytes, retries,
latency, activated references, and descendant agents; missing measurements fail closed. - Compiler source-closure revalidation before execution, plugin-payload MCP startup, and stricter project-output proof
boundaries. - No portable same-user candidate execution. The Builder requires a separately trusted external sandbox, ships with an
empty trust store, rejects caller-provided authority, and cannot convert legacy command receipts into proven output.
Generator-backed source inventory
These are source inventories, not execution results:
- The maintainability size generator discovers 321 production JavaScript modules across its two configured roots.
- The generated Contract Registry contains 50 schema contracts and 25 validator closures comprising 1,032 transitive
module bindings across 174 distinct modules. - The release-evidence source inventory finds 54 unit, one fuzz and three invariant Solidity functions in the Fee V2
kernel, 58 functions in total. - The repository gate dynamically discovers 9
evals/tests/*.test.mjsfiles. A filename count is not a model run or
test-pass receipt.
The release artifacts bind these inventories to the exact published commit and tree. A later source change requires new
evidence and cannot reuse this release identity.
Evidence boundary
- The package release requires a clean immutable commit, protected public CI, the complete repository and reference
kernel rehearsal, deterministic artifacts, exact checksums, and post-publication installation canaries. - Real named model tiers and an independent judge were not run for a behavioral claim. A trusted separate-UID,
container, or VM sandbox, comparable public repository population, independently novel holdout and immutable prior
comparator, pinned-fork cases, and installed-host natural-language-to-submission runs remainEXTERNAL_BLOCKED. - No independent audit, Registry activation, provider guarantee, deployment, signature flow, project approval, routing,
or onchain state is claimed by this package release.
The generated receipt retains releaseCandidate: false because package publication does not manufacture the deferred
behavioral evidence. The owner-authorized public tag is an immutable distribution boundary, not an audit verdict.
Programmable v4 Builder v0.5.1
Programmable v4 Builder v0.5.1
This release publishes the exact portable Builder package, generated plugin payload, manifest, SBOM, checksums, and
release receipt for one immutable Git revision. Publication does not establish model behavior, project approval,
deployment, audit, Registry acceptance, provider support, or live product evidence.
Intended version scope
- schema-bound open-world ProjectSpec, graph, architecture, repository-plan, and resumable-state compilation;
- first-class trade-capability compilation with explicit no-market handling, closed standard-v4/canonical-adapter
manifests, and typed local quote/execution evidence that never claims route approval; - closed capability contracts and executable semantic composition checks;
- typed v4 permission, callback, accounting, HookMiner, address, runtime, and PoolManager semantic bindings, plus an
exact local standard-AMM Universal Router/Permit2 parity lane; - source-derived semantic-coverage holds for underdeclared implementations;
- fresh-repository end-to-end eval infrastructure with encrypted sealed-after-design cases and explicit provider blocking;
- current upstream and local toolchain provenance, semantic rule ownership, and maintainability gates;
- portable Skill/plugin parity at package version
0.5.1.
Evidence boundary
The exact frozen commit, tree, skill tree, test commands, kernel campaign, eval hashes, installation receipts, and
remaining blockers belong in the generated release artifacts. The owner-authorized package release records model and
external behavior gates truthfully as unverified or EXTERNAL_BLOCKED; it does not convert them into passes or make a
behavior-qualified release claim. The public tag is an immutable distribution boundary, not an audit verdict.
The local release rehearsal performs no push, tag, GitHub release, publication, Registry write, deployment, signing,
approval, or onchain action.
Known limitations
- No host-native behavior receipt, Registry activation, production deployment, provider guarantee, or independent audit
is claimed by the package release. - Current source heads are drift canaries, not one compatibility set. Generated projects must use one exact tested
dependency lane and revalidate every changed preimage. - The standard Fee V2 exact-output witness remains sensitive to intervening swaps that change live rounding remainders;
a stale witness reverts atomically but can cause ordering or gas grief. - Model-backed release thresholds require multiple fresh runs across frontier, medium, and small tiers. When unavailable,
only the complete harness and its external blocker are evidence. - The 216-run model matrix and fork-dependent cases remain
EXTERNAL_BLOCKEDuntil independent agent and judge
adapters, three named model tiers, an independent judge model, and a fork RPC are supplied. Structural and fake-agent
harness passes are not substituted for those results. - Universal Router evidence is an exact, local compatibility lane for allowance-transfer ERC-20 and native-ETH routes.
The added V4Quoter/route tests cover only their explicitly supported modes and local state. They do not prove Permit2
signature flows, deployed-address reachability, aggregator discovery, external fork execution, routing approval, or
an audit of the generated project. - The exact offline SDK/test compatibility tree currently carries 36 transitive npm advisories (17 low, 9 moderate,
10 high, 0 critical). They are not treated as fixed or suitable for an application runtime merely because the local
fixed-vector route tests do not exercise their network and tooling surfaces. - Live upstream and package-deprecation visibility requires registry and GitHub network access. A rate-limited or
unavailable endpoint remains an explicit external blocker; the scheduled read-only workflow does not silently turn
missing observations into a clean result.
v0.4.3
Stable Submit a Launch transport release.
- preserves the canonical multiline Git commit message
- safely recovers interrupted application branches
- retries only terminal draft-creation 404s within a bounded window
- revalidates authority, fork identity, branch head, and duplicate state before every retry
- retains draft-only submission with no approval, merge, deployment, signing, or launch authority
The exact v0.4.3 flow was proven with a real six-file draft application against Submit a Launch and closed unmerged after all required checks passed.
v0.4.2
Stable Submit a Launch compatibility bridge.
Hookbuilder now prepares its exact six-file Submission 1.5 application for 0xprogrammable/submit-launch while preserving the existing fee policy and two-step write confirmation. It cannot approve, merge, deploy, sign, or launch.
This release supersedes the withdrawn v0.4.1 tag. The release receipt, tag, commit, tree, archive, manifest, SBOM, and checksums are bound to the same frozen revision.
v0.4.1 — withdrawn
Do not install or use this tag.
The publication tool created v0.4.1 from the default branch instead of the frozen maintenance commit. Its attached release receipt names a different commit, so the release is intentionally withdrawn and must not be used as submission evidence. Use the next verified patch release instead.
Programmable v4 Builder v0.4.0
The first standalone release of Programmable v4 Builder: a portable Agent Skill that turns a plain-language product idea or existing repository into a checked, reviewable Uniswap v4 project and exact GitHub application.
Install
gh skill install 0xprogrammable/programmable-v4-builderPinned installation:
gh skill install 0xprogrammable/programmable-v4-builder programmable-v4-hook-builder@v0.4.0 --agent codex --scope userWhat ships
- Four open starters and 33 composable capability packs for ordinary launches, custom hooks, games, maps, wallet quests, SDK clients, liquidity systems, external services, novel architectures, and more.
- A progressive knowledge router that expands public Lego pack ids and loads only the relevant Uniswap, Programmable, security, runtime, SDK, or workflow context.
- Pinned official-source records across v4 core, periphery, SDKs, Universal Router, Permit2, OpenZeppelin hooks, Uniswap AI, and deployment references.
- Closed submission schemas, semantic checks, fee-conformance tooling, source binding, GitHub application preparation, read-only status, and explicit two-step external actions.
- The inclusive Programmable 10 bps policy, with immutable claim authority
0x4957f49620AFf3Adbbe8195a4f633E49cc93376cseparated from platform administration.
Release evidence
- Public CI passed on Node 20 and 22.
- 34 Solidity unit, fuzz, and invariant tests passed.
- Slither 0.11.5 ran 101 detectors with zero remaining findings; CodeQL passed.
- The exact public tag was installed and verified in fresh Codex, Claude Code, and GitHub Copilot targets.
- The official-source drift check reported no findings across 23 repositories, 2 feeds, 32 deployment records, and 16 source artifacts on 2026-08-02.
Release assets contain a deterministic skill archive, file-level SHA-256 manifest, SPDX 2.3 SBOM, release-state receipt, and SHA256SUMS.
Honest boundary
This release is a Builder and review system. It is not an independent security audit, deployment, provider approval, Uniswap endorsement, or guarantee that generated projects are safe. Model-backed prompt evaluations were not run because they require an explicit provider credential and may cost money. Every generated project still needs exact review and evidence for its own source, configuration, dependencies, and runtime.