Repository navigation
Tabellio v0.5.0
Tabellio v0.5.0 is the first publication candidate after v0.2.0.
Versions 0.3.0 and 0.4.0 were development milestones. They were not tagged, released on GitHub, or published to npm. This release consolidates their capabilities with the validation hardening subsequently merged to main.
Highlights
- Product-validity manifests bind acceptance outcomes, invariants, forbidden outcomes, risk, required validator types, metrics, artifacts, and cost telemetry to an exact candidate commit.
- Required evidence ends as
passed,failed, orblocked; missing proof and unknown required cost telemetry block readiness. - Release plans bind the exact merged commit, terminal review state, validation manifest, release notes, package version, and private control refs to a short-lived approval.
- Pre-merge review gates require an open pull request and exact-head durable
readyevidence; terminal state cannot be backfilled after merge. - Post-merge validation compares the landed commit with
HEAD^, preserving exact-head proof after squash merges. - Validation workspaces, isolated homes, caches, and generated output live in private external temporary sessions.
- Workspace containment and Git worktree cleanup fail closed before validation evidence can be published.
- Preflight reads Codex hook-trust state directly. It never invokes the repair-oriented
entire doctorcommand.
Publication Boundary
This document describes a release candidate. Publishing the annotated tag, private control refs, GitHub release, or npm package remains separately approval-gated. Pull-request merge also remains an explicit operator action.
Run all release gates on the exact merged main commit before authorizing publication.