Repository navigation
Releases: IntelIP/Tabellio
Release list
Tabellio v0.7.0
Tabellio v0.7.0 gives engineering teams a local, inspectable evidence trail for AI-assisted pull requests.
This release collects bounded evidence from Git, Entire, GitHub, Buildkite, validation, security checks, and legacy tracker imports in a local PostgreSQL store. It produces review packets tied to the exact code under review and keeps missing, stale, conflicting, or failed evidence visible. Runner identity includes the package version, source commit, source cleanliness, and a matching release tag when available.
Install and run the first workflow:
npm install --save-dev @intelip/tabellio@0.7.0
npx tabellio-version --expect-version 0.7.0
npx tabellio-provenance-demoThe demo requires Node.js 20+, Git, and local PostgreSQL client/server binaries. It uses temporary synthetic data and removes its temporary files. The demo does not establish live-provider performance or customer results. This release does not include a hosted service or web dashboard.
Source commit: cc6f91d.
Tabellio v0.6.0
Tabellio v0.6.0
Tabellio v0.6.0 makes the running control-plane version independently identifiable.
Added
tabellio-version, a machine-readable local identity command.- Runner identity in validation-result v0.4: package name, package version, exact source commit, source cleanliness, and matching release tag.
- A focused product-validation manifest for the v0.6.0 identity contract.
Compatibility
- Existing validation-result v0.1, v0.2, and v0.3 documents remain supported.
- Git commit pins remain the distribution mechanism for consumer repositories.
Verification
tabellio-version \
--expect-version 0.6.0 \
--expect-ref HEAD \
--require-clean \
--require-release-tagThe release-tag requirement passes only when v0.6.0 is an annotated tag on the
exact commit in the GitHub origin remote and a published, non-draft GitHub
Release exists for that tag. A local-only tag reports tagged, never released.
Tabellio v0.5.0
Tabellio v0.5.0 is the first publication candidate after v0.2.0.
Versions 0.3.0 and 0.4.0 were development milestones. They were not tagged, released on GitHub, or published to npm. This release consolidates their capabilities with the validation hardening subsequently merged to main.
Highlights
- Product-validity manifests bind acceptance outcomes, invariants, forbidden outcomes, risk, required validator types, metrics, artifacts, and cost telemetry to an exact candidate commit.
- Required evidence ends as
passed,failed, orblocked; missing proof and unknown required cost telemetry block readiness. - Release plans bind the exact merged commit, terminal review state, validation manifest, release notes, package version, and private control refs to a short-lived approval.
- Pre-merge review gates require an open pull request and exact-head durable
readyevidence; terminal state cannot be backfilled after merge. - Post-merge validation compares the landed commit with
HEAD^, preserving exact-head proof after squash merges. - Validation workspaces, isolated homes, caches, and generated output live in private external temporary sessions.
- Workspace containment and Git worktree cleanup fail closed before validation evidence can be published.
- Preflight reads Codex hook-trust state directly. It never invokes the repair-oriented
entire doctorcommand.
Publication Boundary
This document describes a release candidate. Publishing the annotated tag, private control refs, GitHub release, or npm package remains separately approval-gated. Pull-request merge also remains an explicit operator action.
Run all release gates on the exact merged main commit before authorizing publication.
Tabellio v0.2.0
Tabellio v0.2.0 completes the GitHub-only repository migration and strengthens the agentic Git control plane.
Highlights
- GitHub is now the canonical code store and thin pull-request surface; private review, validation, and Entire state stays in the separate private GitHub control repository.
- Exact-commit validation, durable review cycles, Git-native ledgers, mandatory Entire checkpoint binding, and approval-gated git-spice operations are included.
- The retired one-time Forgejo review-cycle migration command, decoder, helpers, documentation, tests, and fixtures are removed from the current tree.
- All 34 inherited Fallow interface findings were classified. Narrow method-level suppressions preserve legitimate contracts; unresolved dead-code findings and stale suppressions are both zero.
Release proof
- merged commit:
64875307b98d4bc6a897f5f3c1437c5b9231eeb0 - pull request: #18
- GitHub checks: Tests, Fallow changed-code, and Package dry-run passed
- merged-head validation:
validation-61254649-5ff7-4ab9-9f17-b0013eb9355a - local suite: 71 tests passed
- package dry run: version
0.2.0, 101 entries
This GitHub release does not publish the npm package.
See CHANGELOG.md for the complete release notes.
Tabellio v0.1.0
Initial public release of Tabellio.
Tabellio adds evidence-backed pull request governance for agentic development workflows. This release includes:
- Evidence envelope contract with the tabellio-evidence/v0.1 schema version.
- Dependency-free Node.js evidence writer and validators.
- Default-deny external action policy for protected side effects.
- Reusable GitHub Actions workflow for pull request evidence checks.
- Pull request evidence template and minimal valid evidence fixture.
- OpenSSF Scorecard workflow and SARIF upload.
- Documentation for setup, workflow model, evidence schema, Codex review, research grounding, and the agentic tooling stack covering Code Storage, Entire, Graphite, GitHub, Codex, and Tabellio boundaries.
Validation:
- npm run check passed locally.
- Tabellio Evidence check passed on PR #5.
- OpenSSF Scorecard passed on main.