v1.7.4
Reliability fixes
- Consume delayed and large piped input safely; generate complete stdin recipes and accept empty optional continuation feedback (#41, #42).
- Keep peer mutation receipts bounded and reject deterministic failures before creating tracked jobs (#43, #44).
- Preserve authoritative Claude terminal, authentication, and rate-limit failures ahead of text heuristics (#32, #47, #48).
- Freeze the audited MCP tool registry, isolate test host markers, document pinned installation, and refresh vulnerable development dependencies (#26, #33, #35, #40).
Verification
-
Tag target: merge commit
2ed8323f2d52ce9635c25b02a7c71b468565c087from PR #50; its complete Git tree matches the qualified candidate exactly. -
Independent task and blocker-fix reviews passed; Claude Opus adversarial findings were addressed.
-
Local check: 958 unit, 120 integration, and 24 E2E tests passed; Node 18 unit/integration checks passed.
-
Coverage: 92.72% lines/statements, 83.9% branches, 98.29% functions. All required mutation thresholds passed.
-
All five required hosted checks passed on candidate
9c29f8712160161a8aa8b0d2e45abfe7df95c0d9. -
Post-merge CI run 33916023986 passed on the release target: macOS full check, Ubuntu coverage, Node 18, and Windows.
-
Full and production dependency audits reported zero vulnerabilities.
-
Artifact:
cc-plugin-codex-1.7.4.tgz, 656044 bytes, 92 files; SHA-25612c69f44eb8ff9f22d319373aa25dd50f73fc454defb216b375eafb75443c944. -
Fresh exact-artifact design and research workflows completed through critique and synthesis with Claude Fable 5.1 (1M context) and Codex Astra 6. Both selected Brave tools and native structured output were observed; no fallback, parser diagnostics, repeated attempts, workspace changes, or active jobs remained.
-
Packed validation rejects unselected, nonregistry, and lookalike Brave evidence. Tracked receipts remained below 2 KiB and logs passed redaction checks.
-
Exact-tag installation verified:
cc@cbepx1.7.4 enabled; marketplace HEAD equals the tag target; all 92 installed package files match the qualified artifact. Setup/check ready with four trusted hooks; Codex doctor reports zero warnings/failures. -
Installed-cache Fable 5.1 and Opus 5 smokes returned exact markers, 1M context, no fallback, parser errors, or touched files. Reloading skills/hooks in an already-running Codex session still requires a restart.
Manual qualification automation (#27), direct-test state isolation (#45), historical rendering (#46), and signal-safe temporary-input cleanup (#49) remain follow-ups.