Repository navigation
Releases: Fueav/code-quality
Release list
v0.5.11
Prevent local zsh startup files from bypassing fake tools in cron tests. Add a regression with a deliberately invalid startup PATH, and fix current Claude marketplace metadata.
Record a paired Astra/Sol calibration on four identical committed fixtures at high effort. Both models classified all four correctly; the small sample does not justify changing the Sol/max default. Read-only review, frozen evidence, and review-round limits remain intact. Upgrade shared Harness runtime to v0.8.0 while preserving native release checks.
Validation: native candidate/release checks, full release tests, independent review, and four-platform release builds with checksums.
v0.5.10
Simplify review invocation and CI while preserving the native review transaction.
- Skill, GitHub Actions, and Jenkins use one run command; plan and doctor remain optional diagnostics.
- Preserve user-selected model and reasoning settings, read-only review scope, evidence freezing, and restricted recovery.
- Upgrade the repository to the slim Harness contract with conditional verification and engine v0.6.0.
Validated with native Go/Python release checks, four independent skill decision scenarios, and full Harness release verification.
v0.5.9 — Observable Review Lifecycle
Highlights
- Adds structured
text|jsonllifecycle progress events for Plan, Native, Restricted, recovery, finalization, and publication. - Preserves Native Review semantics: no prompt injection and no provider-output parsing.
- Keeps stdout result contracts unchanged; progress is advisory on stderr.
- Enables an upper Service layer to report the current review phase on a five-minute cadence.
This release improves review observability and perceived responsiveness; it does not claim to reduce provider execution time.
v0.5.8
Native Review checkpoint and restricted-only resume
- Persist a digest-bound, owner-only checkpoint immediately after Native Review freezes.
- Add the official
quality-review resume-restricted --session <absolute-dir>entry point without rerunning Native Review. - Enforce at most 1 Native attempt and 2 Restricted attempts with immutable per-attempt audit artifacts.
- Add result schema v10 and company envelope v3 while preserving v8/v9 and envelope v1/v2 contracts.
- Validate exact Git objects, trusted diff, frozen findings, policy/schema contracts, locks, and publication state before resume.
- Record independent Native/Restricted duration and token metrics with safe heartbeat and failure classification.
code-quality-service requires its separate schema-v10/session-store upgrade before enabling restricted resume in company CI.
v0.5.7
v0.5.7
This release keeps native Codex Exec / Claude Code review as the discovery layer and adds a deterministic production-floor gate before P0/P1 findings become release blockers.
What changed
- Freeze native review evidence first, then send only frozen P0/P1 candidates to one restricted adjudication call using the same provider, model, and reasoning effort.
- Inject the V1.2 production-floor policy as trusted Codex developer instructions or a Claude system prompt; the adjudication call is always read-only and ignores host customizations.
- Recompute blocker retention in ordinary code from supported severity, reachability, evidence, change causality, concrete trigger, and complete causal-chain facts. Model recommendations do not decide the gate.
- Silently remove P0/P1 candidates that do not meet the floor from public JSON, Markdown, and summaries while retaining raw frozen evidence for audit.
- Fail closed with
ERROR/HOLDwhen restricted adjudication or its evidence protocol is invalid. - Stop automatic review after
FULL → INCREMENTAL; a further incremental request returnsMANUAL_REQUIRED, zero provider invocations, and exit code 5 before creating a session.
Contracts
- Native result schema advances to v9 with one-or-two provider invocations and the
DISMISSEDincremental resolution. - Prompt contract advances to v3.
- Company CI envelope v2 wraps schema-v9 results; envelope v1 and schema v8 remain immutable.
- Existing P2/P3 findings remain non-blocking advisories and do not trigger restricted adjudication.
v0.5.6
v0.5.6
- Resolve one Provider model, reasoning effort, execution profile, scope, goal, and Git range for each review, then pass the same values to
plan,doctor, andrun-codex/run-claude. - Make
maxthe bundled production-CI default and the fixed value in official company-side README and Jenkins examples. - Add a plan artifact to the reusable GitHub workflow and Jenkins example so operators can compare the frozen
review_keyandcontract_digestbefore Provider execution. - Document external
runner_policy_versionisolation for additional Service/Runner restrictions. A policy change invalidates REUSED and INCREMENTAL admission and forces FULL without modifying schema-v8 results or envelope-v1. - Add direct contract coverage proving plan, doctor, and run produce the same identity when given one argument set.
Compatibility note: CLI review semantics and schemas remain v8/v3/envelope-v1. The reusable workflow still accepts explicit model and reasoning-effort inputs, but its default reasoning effort is now max. Because tool version is part of the review contract, v0.5.5 results are not eligible as v0.5.6 incremental parents and correctly require a FULL review.
v0.5.5
v0.5.5
- Add explicit
--base-ref/--head-refdirection and the read-onlyplancommand so local and CI callers can freeze the same base tip, head, merge-base, changed files, contract digest, andreview_keybefore invoking a Provider. - Add
FULLandINCREMENTALreview scopes. Incremental runs inspect onlyprevious_head..current_head, re-evaluate every previous P0/P1, retain unresolved blockers, and report new delta findings separately. - Fail closed with machine-readable
FULL_REQUIRED, exit code 4, and zero Provider invocations when lineage, base tip, contract, Provider settings, ancestry, previous-result validation, or non-empty-delta requirements are not satisfied. - Upgrade detailed results to schema v8 and summaries to schema v3 with deterministic review/finding identities, lineage, resolution evidence, and incremental counts.
- Publish the versioned company-CI envelope contract for external
EXECUTED / REUSEDandCURRENT / SUPERSEDEDstate without adding cache, PR publication, or repair-loop behavior to the CLI. - Preserve legacy exact
--base / --target, GitHub PR, GitLab MR, and localorigin/HEADdiscovery behavior, plus the v0.5.4 release floor where only P0/P1 block and P2/P3 remain advisory.
Compatibility note: detailed-result consumers must adopt schema v8 and summary consumers must adopt schema v3. An incremental caller must keep the complete immutable previous review-result.json; on FULL_REQUIRED, rerun explicitly with --review-scope full and without --previous-result.
v0.5.4
v0.5.4
- Make the production release gate priority-aware: P0/P1 findings return
BLOCK; P2/P3-only reviews retain their findings as advisories and returnPASS. - Define the P0-P3 boundary in the Provider output schema and filter style, naming, preference, ordinary maintainability, and unsupported scale speculation from findings.
- Upgrade the detailed native result to schema v7 and
review-summary.jsonto schema v2 with separateblocking_issuesandadvisory_issuescounts. - Split Markdown output into release-blocking issues and advisories while preserving one frozen Provider call and fail-closed
ERRORbehavior. - Update the CLI, Codex and Claude Code plugins, GitHub reusable workflow, Jenkins guide, installation docs, and contract tests to v0.5.4.
Compatibility note: summary consumers must no longer treat every entry in issues as a blocker. Use blocking_issues, advisory_issues, or the per-issue priority.
v0.5.3
v0.5.3
- 用
PASS / BLOCK / ERROR一眼说明是否有问题、是否可以继续发布流程。 - 有效 finding 直接返回
BLOCK并使 Jenkins/GitHub CI 失败;不可信扫描返回ERROR,默认阻止发布。 - Codex 与 Claude Code 使用原生 JSON Schema 结构化输出。
- CI 主产物只保留简明 Markdown/JSON,完整原始证据统一归档为
evidence.tar.gz。 - Jenkins 生产配置继续使用已登录的本机 Provider,PR 级扫描固定
reasoning_effort=high,不需要 API Key。
v0.5.2
v0.5.2
Production-ready PR review support for a pre-authenticated self-hosted Linux runner.
- Reuses the runner user’s existing Codex or Claude Code login; no Provider API key, CLI install, or temporary login in the reusable workflow.
- Treats a pull request as the review unit and freezes the true merge-base-to-head scope plus PR identity in result schema v5.
- Adds the
production-ciexecution profile: read-only, customization-isolated provider invocation while preserving the existing personal defaults. - Keeps findings report-only:
MANUAL_REVIEWpublishes evidence without automatically blocking merge; execution failures still fail the check.
See the README Linux CI section for the minimal caller and runner prerequisites.