Repository navigation
Releases: acgetchell/research-repo-tools
Release list
v0.1.8
⚠️ Breaking Changes
- replace tag and tag-release with release-tag, and
tag-preview with release-tag-preview. Remove tag-force and require TAG
for release-check. The untagged release check CLI remains available. - Semgrep scan owns its complete output directory and defaults
to aggregate semgrep.json/semgrep.sarif reports. Use a dedicated output
directory. Numbered reports are now emitted per batch. - managed consumers must enforce the installed release's
Python minimum in application metadata regardless of inheritance settings.
The current Python 3.14 baseline remains unchanged.
Merged Pull Requests
Added
-
Centralize validation and shared tool versions
b8da6c1- Add check, fix, and typecheck commands for complete Python inventories
while preserving native policies and read-only checks. - Offer opt-in Ruff, ty, and pytest versions through the installed
release's python-tools extra. - Preview and apply tool adoption with drift checks, rollback, and
preserved consumer runtime support and configuration. - Retain inherited versions during dependency updates and provide thin
Just recipes with adoption and opt-out guidance.
- Add check, fix, and typecheck commands for complete Python inventories
-
Add notebook fixtures and Just inspection APIs
030f121- Run notebook integrations in isolated projects with the caller's locked
interpreter, preserving manifests and avoiding native toolchain setup. - Expose pinned Just metadata and dry-run results for consumer recipe policy.
- Reject junction aliases in evidence, measurement, publication, release,
and worktree paths, and reject nonportable release filenames. - Refresh uv and notebook development dependencies and document the public
integration contracts and portable path boundaries.
- Run notebook integrations in isolated projects with the caller's locked
-
Add complete runs and host profiling
3cd0d52- Apply a captured common harness to both revisions with independent gates,
complete Criterion samples, and explicit phase provenance. - Retain immutable runs with validated latest selection and named reference
series for offline reports. - Capture typed host observations and configured native Rust/Cargo profiling
declarations while preserving unknown values and original TOML. - Print validated OSV, Gitleaks, and Semgrep finding summaries without
exposing sensitive scanner output.
- Apply a captured common harness to both revisions with independent gates,
-
[breaking] Add reviewed publishing and shared release recipes
9c9be75- Gate stable GitHub Releases on reviewed source, protected-branch ancestry,
successful exact-commit checks, and required assets. - Ship a consumer-owned crates.io OIDC workflow using a temporary token
with native Cargo packaging and bounded publication verification. - Share release recipes and ordered release instructions across registries,
with account-specific setup kept in a private maintainer task. - Preserve authored dependency bodies and links through the shared
changelog policy while retaining common grouping and breaking notes. - Keep the declared changelog generator consistent across setup and CI.
- Honor explicit task-specific authorization for Git operations while
retaining a read-only default.
- Gate stable GitHub Releases on reviewed source, protected-branch ancestry,
-
Add Actions maintenance and portable tool updates
63b94f7- Add opt-in Actions updates with immutable commit pins, version reports,
and compatibility checks for retained tool wrapper actions. - Check steps and reusable workflows against consumer-owned GitHub
selected-actions policies with precise source diagnostics. - Support verified uv-tool and Homebrew owners and managed dprint/rumdl
binaries while preserving authoritative pins and installation constraints. - Keep tool updates separate from shell setup, protect staged file
publication from concurrent edits, and run cheap checks before workflows.
- Add opt-in Actions updates with immutable commit pins, version reports,
-
[breaking] Add SARIF policies and batched Semgrep reports
0fb811eAdd strict driver and namespace selection for SARIF, preserving metadata
and correcting indexed rule references with distinct upload categories.
Publish complete SARIF and figure generations through a shared directory
transaction with rollback and retained recovery data.Scan bounded Semgrep batches once for paired JSON/SARIF reports. Expose
consumer suppression, jobs, target timeout, category and layout policies;
verify exact coverage and active findings agreement before publication.
Document the supported interfaces and downstream implementation deletion map. -
Add ID policies and opt-in launch/reset workflows
f1fdb1bSupport configurable full-match cell-ID policies while preserving the
default nbformat contract and existing source IDs.Launch locked JupyterLab with explicit browser behavior and private
session caches. Preview tracked-notebook restoration from the index or
a selected revision, applying only declared cleanup after opt-in and
path validation. -
[breaking] Enforce the installed Python support minimum
5ed34f1Reconcile application Requires-Python alongside exact shared-package pins,
extras, tooling constraints and development settings during adoption.
Preserve stricter consumer ranges and reject incompatible constraints.Reject stale packaging metadata in ordinary Python, toolchain and setup
gates without mutation or an opt-out. Bootstrap an exact target release
under older consumer interpreters using its published support metadata. -
Add reproducible papers and raw line limits
1ffd3c7Expose optional paper date and PDF checks with deterministic Tectonic metadata normalization, consumer-declared policy, and validated artifact publication.
Discover native build environments without provisioning host packages.Add configurable all-line UTF-8 validation over shared Git selection while preserving the existing Markdown table exemption.
-
Run Cargo examples with discovery and live output
bd0fd33Discover binary examples through Cargo metadata and execute native build
artifacts with consumer-owned selection, features, deadlines, and assertions.
Build ordinary examples once and run each feature override immediately after
its build so shared binary paths cannot inherit a later feature policy.Add optional exact stdout assertions to live execution while preserving
nonzero exits and deadlines, including when the output sink is blocked.
Document the public contracts and migration from static validation plans.
Changed
-
Name oversized payload cases explicitly
3ef6c34- Use short case names so pytest can set its current-test environment
variable on Windows, including for the one-megabyte response fixture.
- Use short case names so pytest can set its current-test environment
-
Cover installed group-constraint diagnostics
6516808
Documentation
-
Centralize Windows development guidance
759f8a3- Require agents to read the Windows guidance in CONTRIBUTING.md before
changing paths, subprocesses, or package checks.
- Require agents to read the Windows guidance in CONTRIBUTING.md before
-
Clarify capability test directory paths
a639d2eState that the capability directory names in the contributor guide are
relative to tests/.
Fixed
-
Verify tool reachability and isolate install checks
4f01dcd- Reject inherited tool locks whose matching Ruff, ty, or pytest records
are unreachable from the selected dev dependency graph. - Keep offline package-update fixtures self-contained by resolving against
a wheel built from the tested artifact and using a fresh test cache.
- Reject inherited tool locks whose matching Ruff, ty, or pytest records
-
Reject linked samples and extra Just recipes
06c8b6f- Reject symlink and junction Criterion roots before reading estimates.
- Limit Just dry runs to one recipe invocation while preserving dependency
previews. - Correct Windows package checks to preserve temporary cleanup and compare
native Just invocation paths.
-
Preserve UTF-8 output in isolated package checks
a89da02- Select UTF-8 explicitly for isolated Python consumers while retaining
startup isolation and the import checks' no-bytecode policy. - Document Windows encoding, native path, and fixture cleanup rules for
contributors and agents.
- Select UTF-8 explicitly for isolated Python consumers while retaining
-
Keep kernel history in memory [
825fa17](https://github.c...
v0.1.7
Merged Pull Requests
Added
-
Add reusable patch approval and auto-merge
2ef9ba8- Approve allowlisted uv and Cargo patch updates using repository-owned dependency and file policies, including every member of grouped updates.
- Bind approval to a single GitHub-signed Dependabot head commit and require active rulesets with stale-review dismissal and strict checks.
- Replace CodeRabbit approval polling and the personal token requirement with GITHUB_TOKEN and native squash auto-merge.
- Provide settings payloads and document consumer SHA pinning, setup, rollout, and post-merge verification.
-
Add shared Python adoption, security scans, and cleanup
d975bb2- Add opt-in Python baseline inheritance and recoverable preview/apply migration while preserving consumer runtime and lint policies.
- Manage cargo-deny and checksum-verified OSV/Gitleaks binaries, with explicit scan inputs, redacted reports, and blocking failure handling.
- Share Semgrep inventory, Rust documentation scans, and fixture checks.
- Support first-release preparation without a fabricated predecessor and opt-in blocking of dependency installation in notebooks.
- Add just clean for obsolete package-owned installations, with previews and retention roots; keep user-wide installations untouched.
- Preserve executable helpers and reject linked adoption environments; handle relative cleanup roots and TOML tables without final newlines.
- Correct Windows Bash CRLF assumptions in the Dependabot test harness.
- Document public configuration factories and consumer migration, cleanup, and release contracts; repair README links for PyPI.
- Update platformdirs to 4.11.15.
Fixed
-
Make Dependabot workflow tests portable
3f1bfc9- Use jq's portable -b option for Ubuntu compatibility while preserving LF output on Windows.
- Pass Bash scripts through binary stdin to preserve embedded quoting and prevent Windows newline translation.
- Add a dynamic PyPI version badge to the README linking to the package.
-
Isolate Dependabot test scripts from child stdin
937f151- Run Bash from temporary files with LF line endings so child processes cannot consume the workflow script through stdin.
- Normalize jq output before simulating Windows CRLF behavior.
- Document that GITHUB_TOKEN approval replaces CodeRabbit polling and personal tokens while required CodeRabbit status checks still apply.
-
Preserve exact CRLF bytes in Dependabot test fixtures
a5aa0f5- Replace sed-based newline simulation with Bash builtins to avoid platform-dependent text conversion.
- Assert exact LF and CRLF bytes before and after command substitution, including when external text filters normalize line endings.
-
Authenticate scanner setup and detect notebook installs
d0ae1bd- Authenticate GitHub release metadata with GITHUB_TOKEN or GH_TOKEN and pass the workflow token to native setup to avoid anonymous API rate limits.
- Detect nested sudo/env wrappers and Windows executable paths and casing in notebook installation commands.
- Inspect literal subprocess calls after notebook magics while preserving original source line numbers.
- Remove stale numbered OSV and Semgrep JSON/SARIF reports, including symlinks, while preserving unrelated files and symlink targets.
-
Reject linked scanner report directories
0f98931- Reject symlinks and Windows junctions in OSV and Semgrep output paths, including parent components, before creating directories or removing reports.
- Prevent cleanup from deleting reports through directory links while preserving numbered-report cleanup and report-symlink removal.
-
Honor configured updates and verified base merges
cbb2ea6- Approve configured uv, Cargo, and GitHub Actions updates, including minor and major versions, without duplicate dependency-name filters.
- Accept verified GitHub base merges only when ancestry and original dependency-file contents are preserved.
- Document file allowlists, shared workflow adoption, and retirement of CodeRabbit approval requests and personal tokens.
Maintenance
-
Bump hatchling in the python group #53
ac5efccBumps the python group with 1 update: hatchling.
Updates
hatchlingfrom 1.32.0 to 1.32.3 -
Bump the github-actions group with 4 updates #52
d2469f6Bumps the github-actions group with 4 updates: codecov/codecov-action,
github/codeql-action/init, github/codeql-action/analyze and
github/codeql-action/upload-sarif.Updates
codecov/codecov-actionfrom 7.1.0 to 7.1.1Updates
github/codeql-action/initfrom 4.38.0 to 4.38.1Updates
github/codeql-action/analyzefrom 4.38.0 to 4.38.1Updates
github/codeql-action/upload-sariffrom 4.38.0 to 4.38.1
v0.1.6
Added
-
Share zizmor audits and complete Python checks
638a797- Add zizmor check with a verified scanner pin, explicit persona, token discovery and redaction, and required-online or offline modes.
- Fail CI on workflow findings while preserving SARIF generation and restricting privileged uploads for fork and Dependabot runs.
- Apply full configured Ruff and ty checks to tracked and nonignored Python files, including fixtures, through shared file selection.
- Ship an opt-in annotation policy and adoption guidance covering Python 3.14, precise fixture exceptions, and canonical validation gates.
Fixed
-
Allow SARIF uploads from private repositories
56e0e31- Grant actions: read in the packaged workflow for private-repository SARIF uploads, preserving existing permissions.
- Update the locked wcwidth dependency from 0.8.4 to 0.9.0.
v0.1.5
Added
-
Add read-only inspection and configurable advice
9946fc7- Add text and versioned JSON inventories for nbformat 4 notebooks, with source-preview controls and structural repair diagnostics.
- Add descriptive-ID warnings, configurable native Ruff rules, and optional subprocess timeout advice with opt-in strict mode.
- Reject invalid Unicode before notebook execution and prevent raw JSON values from leaking through parser diagnostics.
- Honor the consumer root for executable lookup, export paths, and uv synchronization despite ambient project selectors.
- Preserve UTF-8 and newlines in generated CLI output, retain subprocess diagnostics, and handle grouped expected failures.
- Validate supplied release asset digests before downloading and reject portable aliases of Git metadata paths.
- Update the uv pin to 0.12.18 and document notebook adoption, release publication, and shared workflow ownership.
Fixed
-
Suppress parser warnings during timeout advice
3b6cff7- Suppress SyntaxWarning only while parsing cells, preventing stderr leakage and false syntax skips under warnings-as-errors.
- Preserve genuine syntax-error handling and caller warning filters.
- Clarify that download_release_asset saves verified assets and requires a separate extract_archive call to unpack them.
v0.1.4
Added
-
Add configured benchmark and release workflows
4384fce- Select release pairs and measure benchmarks in isolated worktrees with source, harness, toolchain, and dependency provenance.
- Manage authenticated baseline assets and draft release uploads with hash verification, safe retries, and optional publication.
- Convert legacy evidence while preserving original hashes, and support report promotion, archival, offline rendering, and CSV export.
- Prepare future-release documents with source inventory rechecks and exact verification against existing release tags.
- Add portable file selection, command batching, configured validation, and checked CI and toolchain environment exports.
- Support canonical release tags and dependency-only Python environments, with consumer templates and MCMC migration guidance.
v0.1.3
Added
-
Add managed SARIF tools and public Python utility APIs
5e1290e- Manage clippy-sarif and sarif-fmt with exact locked installation, checked execution, and upgrades limited to declared tools.
- Expose executable resolution and text/byte command runners that preserve Git input bytes and original failure diagnostics.
- Support transactional byte publication with target validation, preserved permissions, rollback, and structured recovery errors.
- Document API compatibility, platform limits, and consumer migration.
-
Add configurable policies and structured plans
cf4331f- Declare required files, fixed metadata, and active release references with exclusions for historical evidence.
- Expose typed discovery, checks, plans, and consumer adapters for contributing edits and validating complete candidates.
- Apply the exact previewed bytes with stale-input checks and transactional rollback; reject fixed DOI mismatches before editing.
- Document replacing MCMC's release orchestration with configuration and small adapters while retaining consumer-owned evidence policy.
-
Add Criterion comparison and evidence APIs
b3de44f- Add validated timing comparisons with explicit units and complete common, added, and missing benchmark inventories.
- Preserve exact evidence bytes with deterministic serialization, source and harness provenance, and explicit compatibility checks.
- Support bounded asset retrieval, safe archive extraction, and recoverable publication with immutable evidence and alias protection.
- Add performance commands for comparison, extraction, retrieval, retained-data rendering, and verification.
- Document retained-evidence migration while keeping benchmark execution and scientific acceptance policies in consumers.
-
Add evidence-backed document publication
1ad1c56- Add Python publication plans and a TOML-driven performance publish command with check and preview modes.
- Render selected timing tables and optional SVGs with explicit labels, units, and links, without plotting dependencies.
- Verify provenance, release references, and exact tagged artifact bytes before publishing documents and figures with snapshot checks and rollback.
- Preserve surrounding document bytes, historical links, and UTF-8 preview output across platforms.
- Document migration through consumer schema and renderer adapters.
- Share the Git-mutation opt-out across checkout and installed consumer suites while retaining full coverage by default.
Changed
-
Make public API consumer checks portable
08140cf- Resolve relative interpreter paths without crossing Windows drives.
- Explicitly use UTF-8 for the Unicode subprocess probe so inherited encodings cannot cause decoding failures.
Fixed
-
Handle discovery errors and Windows check failures
4114c94- Report failed or timed-out release discovery on stderr and return status 1 instead of propagating subprocess exceptions.
- Describe release updates as transactional with rollback on failure, removing the inaccurate atomicity claim.
- Use explicit LF and CRLF fixtures so release-policy checks preserve exact bytes consistently across platforms.
-
Protect performance inputs and enforce portable text writes
a494030- Reject comparison outputs within either Criterion input root, including equivalent path aliases.
- Reject Unicode surrogates in archive names before filesystem access.
- Enforce explicit newline policies through just newline-check, included in just check and just ci.
- Make generated scripts and fixtures portable while preserving intentional LF/CRLF data and malformed ZIP names on Windows.
v0.1.2
Merged Pull Requests
- Bump astral-sh/setup-uv in the github-actions group #18
Added
-
Add managed Cargo upgrades and notebook workflows
2ad1023- Add toolchain upgrade and update-cargo-tools, publishing Cargo pins only after installation succeeds and preserving prior pins on failure.
- Include managed Cargo upgrades in the consumer update workflow.
- Add optional notebook environment setup, validation, output cleanup, and fresh-kernel execution with source-preserving reports.
- Check notebook syntax, Ruff rules and formatting, and ty types with diagnostics tied to stable cell IDs.
- Honor configured notebook groups and reject numeric overflow before execution or file changes.
- Fix draft release creation using annotated tag notes.
-
Complete dependency and tool update workflows
edf7e34- Add aggregate, dependency-only, Cargo, Python, and tools-only recipes while preserving support for Python-only consumers.
- Keep Cargo exclusions and additional resolution roots under consumer control.
- Upgrade the full Python lock and synchronize dev with managed tools, retaining update-python-deps as an alias.
- Bootstrap updates from the tooling group so native consumer builds wait until the final checked sync.
- Support cargo-audit, cargo-machete, samply, tectonic, and tex-fmt with executable verification and native prerequisite guidance.
- Document the superseded uv, Just, and cargo-update policies.
Fixed
-
Guard Cargo pin publication and Windows notebook sync
f28204b- Recheck source content and symlink targets after staging Cargo pin updates, refusing publication when either has changed.
- Start notebook-sync with managed Python to prevent Windows from replacing the environment while its CLI is running.
-
Require a cargo-edit pin for cargo upgrade
0dc0034- Reject cargo upgrade through toolchain run when cargo-edit is undeclared, even if an unmanaged copy is available on PATH.
- Direct consumers to declare an exact pin and run just setup to install and verify the tool before upgrading dependencies.
-
Enforce cargo-edit pins for direct upgrades
bd74456- Require a declared cargo-edit pin for direct cargo-upgrade calls and clarify exact version and setup requirements.
- Exercise real Cargo requirement and lockfile updates from installed wheels in Linux, macOS, and Windows CI.
- Prevent false Windows failures when comparing executable paths.
Maintenance
-
Bump astral-sh/setup-uv in the github-actions group #18
9867b46Bumps the github-actions group with 1 update: astral-sh/setup-uv.
Updates
astral-sh/setup-uvfrom 10.0.1 to 10.1.0
v0.1.1
Added
-
Add CodeRabbit review and publish verified release assets to PyPI
e9f9b7d- Add shared branch and uncommitted review commands with thin Just recipes, verified origin/main freshness, and streamed CodeRabbit output.
- Require repository instructions and unambiguous review configuration; keep live reviews opt-in and outside routine validation.
- Attach validated distributions and signed provenance to draft GitHub releases, then publish the verified assets to PyPI without rebuilding.
- Preserve environment approval and verify release identity, asset inventory, and provenance before upload.
- Add release-update and tag-preview recipes, and consolidate metadata, changelog, tagging, and publication guidance in docs/RELEASING.md.
Fixed
-
Preserve authored history and stabilize regeneration
c22d1be- Retain declared release dates instead of replacing them with Git dates.
- Preserve squash-entry structure and wording without promoting embedded headings or removing semantically similar content.
- Compare archives through the same formatter to make regeneration idempotent while retaining genuine conflict detection.
- Validate extracted notes against the requested release, rejecting duplicate targets, ambiguous boundaries, and conflicting references.
- Add changelog check and just changelog-check for strict validation of the root changelog and all archives.