Skip to content

Releases: acgetchell/research-repo-tools

v0.1.8

Choose a tag to compare

@github-actions github-actions released this 09 Oct 04:37
299c8de

⚠️ Breaking Changes

  • replace tag and tag-release with release-tag, and
    tag-preview with release-tag-preview. Remove tag-force and require TAG
    for release-check. The untagged release check CLI remains available.
  • Semgrep scan owns its complete output directory and defaults
    to aggregate semgrep.json/semgrep.sarif reports. Use a dedicated output
    directory. Numbered reports are now emitted per batch.
  • managed consumers must enforce the installed release's
    Python minimum in application metadata regardless of inheritance settings.
    The current Python 3.14 baseline remains unchanged.

Merged Pull Requests

  • Bump hatchling #68
  • Bump the github-actions group with 4 updates #67

Added

  • Centralize validation and shared tool versions b8da6c1

    • Add check, fix, and typecheck commands for complete Python inventories
      while preserving native policies and read-only checks.
    • Offer opt-in Ruff, ty, and pytest versions through the installed
      release's python-tools extra.
    • Preview and apply tool adoption with drift checks, rollback, and
      preserved consumer runtime support and configuration.
    • Retain inherited versions during dependency updates and provide thin
      Just recipes with adoption and opt-out guidance.
  • Add notebook fixtures and Just inspection APIs 030f121

    • Run notebook integrations in isolated projects with the caller's locked
      interpreter, preserving manifests and avoiding native toolchain setup.
    • Expose pinned Just metadata and dry-run results for consumer recipe policy.
    • Reject junction aliases in evidence, measurement, publication, release,
      and worktree paths, and reject nonportable release filenames.
    • Refresh uv and notebook development dependencies and document the public
      integration contracts and portable path boundaries.
  • Add complete runs and host profiling 3cd0d52

    • Apply a captured common harness to both revisions with independent gates,
      complete Criterion samples, and explicit phase provenance.
    • Retain immutable runs with validated latest selection and named reference
      series for offline reports.
    • Capture typed host observations and configured native Rust/Cargo profiling
      declarations while preserving unknown values and original TOML.
    • Print validated OSV, Gitleaks, and Semgrep finding summaries without
      exposing sensitive scanner output.
  • [breaking] Add reviewed publishing and shared release recipes
    9c9be75

    • Gate stable GitHub Releases on reviewed source, protected-branch ancestry,
      successful exact-commit checks, and required assets.
    • Ship a consumer-owned crates.io OIDC workflow using a temporary token
      with native Cargo packaging and bounded publication verification.
    • Share release recipes and ordered release instructions across registries,
      with account-specific setup kept in a private maintainer task.
    • Preserve authored dependency bodies and links through the shared
      changelog policy while retaining common grouping and breaking notes.
    • Keep the declared changelog generator consistent across setup and CI.
    • Honor explicit task-specific authorization for Git operations while
      retaining a read-only default.
  • Add Actions maintenance and portable tool updates
    63b94f7

    • Add opt-in Actions updates with immutable commit pins, version reports,
      and compatibility checks for retained tool wrapper actions.
    • Check steps and reusable workflows against consumer-owned GitHub
      selected-actions policies with precise source diagnostics.
    • Support verified uv-tool and Homebrew owners and managed dprint/rumdl
      binaries while preserving authoritative pins and installation constraints.
    • Keep tool updates separate from shell setup, protect staged file
      publication from concurrent edits, and run cheap checks before workflows.
  • [breaking] Add SARIF policies and batched Semgrep reports
    0fb811e

    Add strict driver and namespace selection for SARIF, preserving metadata
    and correcting indexed rule references with distinct upload categories.
    Publish complete SARIF and figure generations through a shared directory
    transaction with rollback and retained recovery data.

    Scan bounded Semgrep batches once for paired JSON/SARIF reports. Expose
    consumer suppression, jobs, target timeout, category and layout policies;
    verify exact coverage and active findings agreement before publication.
    Document the supported interfaces and downstream implementation deletion map.

  • Add ID policies and opt-in launch/reset workflows
    f1fdb1b

    Support configurable full-match cell-ID policies while preserving the
    default nbformat contract and existing source IDs.

    Launch locked JupyterLab with explicit browser behavior and private
    session caches. Preview tracked-notebook restoration from the index or
    a selected revision, applying only declared cleanup after opt-in and
    path validation.

  • [breaking] Enforce the installed Python support minimum
    5ed34f1

    Reconcile application Requires-Python alongside exact shared-package pins,
    extras, tooling constraints and development settings during adoption.
    Preserve stricter consumer ranges and reject incompatible constraints.

    Reject stale packaging metadata in ordinary Python, toolchain and setup
    gates without mutation or an opt-out. Bootstrap an exact target release
    under older consumer interpreters using its published support metadata.

  • Add reproducible papers and raw line limits 1ffd3c7

    Expose optional paper date and PDF checks with deterministic Tectonic metadata normalization, consumer-declared policy, and validated artifact publication.
    Discover native build environments without provisioning host packages.

    Add configurable all-line UTF-8 validation over shared Git selection while preserving the existing Markdown table exemption.

  • Run Cargo examples with discovery and live output
    bd0fd33

    Discover binary examples through Cargo metadata and execute native build
    artifacts with consumer-owned selection, features, deadlines, and assertions.
    Build ordinary examples once and run each feature override immediately after
    its build so shared binary paths cannot inherit a later feature policy.

    Add optional exact stdout assertions to live execution while preserving
    nonzero exits and deadlines, including when the output sink is blocked.
    Document the public contracts and migration from static validation plans.

Changed

  • Name oversized payload cases explicitly 3ef6c34

    • Use short case names so pytest can set its current-test environment
      variable on Windows, including for the one-megabyte response fixture.
  • Cover installed group-constraint diagnostics 6516808

Documentation

  • Centralize Windows development guidance 759f8a3

    • Require agents to read the Windows guidance in CONTRIBUTING.md before
      changing paths, subprocesses, or package checks.
  • Clarify capability test directory paths a639d2e

    State that the capability directory names in the contributor guide are
    relative to tests/.

Fixed

  • Verify tool reachability and isolate install checks
    4f01dcd

    • Reject inherited tool locks whose matching Ruff, ty, or pytest records
      are unreachable from the selected dev dependency graph.
    • Keep offline package-update fixtures self-contained by resolving against
      a wheel built from the tested artifact and using a fresh test cache.
  • Reject linked samples and extra Just recipes 06c8b6f

    • Reject symlink and junction Criterion roots before reading estimates.
    • Limit Just dry runs to one recipe invocation while preserving dependency
      previews.
    • Correct Windows package checks to preserve temporary cleanup and compare
      native Just invocation paths.
  • Preserve UTF-8 output in isolated package checks
    a89da02

    • Select UTF-8 explicitly for isolated Python consumers while retaining
      startup isolation and the import checks' no-bytecode policy.
    • Document Windows encoding, native path, and fixture cleanup rules for
      contributors and agents.
  • Keep kernel history in memory [825fa17](https://github.c...

Read more

v0.1.7

Choose a tag to compare

@github-actions github-actions released this 26 Sep 20:00
0a02204

Merged Pull Requests

  • Bump hatchling in the python group #53
  • Bump the github-actions group with 4 updates #52

Added

  • Add reusable patch approval and auto-merge 2ef9ba8

    • Approve allowlisted uv and Cargo patch updates using repository-owned dependency and file policies, including every member of grouped updates.
    • Bind approval to a single GitHub-signed Dependabot head commit and require active rulesets with stale-review dismissal and strict checks.
    • Replace CodeRabbit approval polling and the personal token requirement with GITHUB_TOKEN and native squash auto-merge.
    • Provide settings payloads and document consumer SHA pinning, setup, rollout, and post-merge verification.
  • Add shared Python adoption, security scans, and cleanup
    d975bb2

    • Add opt-in Python baseline inheritance and recoverable preview/apply migration while preserving consumer runtime and lint policies.
    • Manage cargo-deny and checksum-verified OSV/Gitleaks binaries, with explicit scan inputs, redacted reports, and blocking failure handling.
    • Share Semgrep inventory, Rust documentation scans, and fixture checks.
    • Support first-release preparation without a fabricated predecessor and opt-in blocking of dependency installation in notebooks.
    • Add just clean for obsolete package-owned installations, with previews and retention roots; keep user-wide installations untouched.
    • Preserve executable helpers and reject linked adoption environments; handle relative cleanup roots and TOML tables without final newlines.
    • Correct Windows Bash CRLF assumptions in the Dependabot test harness.
    • Document public configuration factories and consumer migration, cleanup, and release contracts; repair README links for PyPI.
    • Update platformdirs to 4.11.15.

Fixed

  • Make Dependabot workflow tests portable 3f1bfc9

    • Use jq's portable -b option for Ubuntu compatibility while preserving LF output on Windows.
    • Pass Bash scripts through binary stdin to preserve embedded quoting and prevent Windows newline translation.
    • Add a dynamic PyPI version badge to the README linking to the package.
  • Isolate Dependabot test scripts from child stdin
    937f151

    • Run Bash from temporary files with LF line endings so child processes cannot consume the workflow script through stdin.
    • Normalize jq output before simulating Windows CRLF behavior.
    • Document that GITHUB_TOKEN approval replaces CodeRabbit polling and personal tokens while required CodeRabbit status checks still apply.
  • Preserve exact CRLF bytes in Dependabot test fixtures
    a5aa0f5

    • Replace sed-based newline simulation with Bash builtins to avoid platform-dependent text conversion.
    • Assert exact LF and CRLF bytes before and after command substitution, including when external text filters normalize line endings.
  • Authenticate scanner setup and detect notebook installs
    d0ae1bd

    • Authenticate GitHub release metadata with GITHUB_TOKEN or GH_TOKEN and pass the workflow token to native setup to avoid anonymous API rate limits.
    • Detect nested sudo/env wrappers and Windows executable paths and casing in notebook installation commands.
    • Inspect literal subprocess calls after notebook magics while preserving original source line numbers.
    • Remove stale numbered OSV and Semgrep JSON/SARIF reports, including symlinks, while preserving unrelated files and symlink targets.
  • Reject linked scanner report directories 0f98931

    • Reject symlinks and Windows junctions in OSV and Semgrep output paths, including parent components, before creating directories or removing reports.
    • Prevent cleanup from deleting reports through directory links while preserving numbered-report cleanup and report-symlink removal.
  • Honor configured updates and verified base merges
    cbb2ea6

    • Approve configured uv, Cargo, and GitHub Actions updates, including minor and major versions, without duplicate dependency-name filters.
    • Accept verified GitHub base merges only when ancestry and original dependency-file contents are preserved.
    • Document file allowlists, shared workflow adoption, and retirement of CodeRabbit approval requests and personal tokens.

Maintenance

v0.1.6

Choose a tag to compare

@github-actions github-actions released this 23 Sep 20:14
6794c1f

Added

  • Share zizmor audits and complete Python checks 638a797

    • Add zizmor check with a verified scanner pin, explicit persona, token discovery and redaction, and required-online or offline modes.
    • Fail CI on workflow findings while preserving SARIF generation and restricting privileged uploads for fork and Dependabot runs.
    • Apply full configured Ruff and ty checks to tracked and nonignored Python files, including fixtures, through shared file selection.
    • Ship an opt-in annotation policy and adoption guidance covering Python 3.14, precise fixture exceptions, and canonical validation gates.

Fixed

  • Allow SARIF uploads from private repositories 56e0e31

    • Grant actions: read in the packaged workflow for private-repository SARIF uploads, preserving existing permissions.
    • Update the locked wcwidth dependency from 0.8.4 to 0.9.0.

v0.1.5

Choose a tag to compare

@github-actions github-actions released this 23 Sep 08:51

Added

  • Add read-only inspection and configurable advice
    9946fc7

    • Add text and versioned JSON inventories for nbformat 4 notebooks, with source-preview controls and structural repair diagnostics.
    • Add descriptive-ID warnings, configurable native Ruff rules, and optional subprocess timeout advice with opt-in strict mode.
    • Reject invalid Unicode before notebook execution and prevent raw JSON values from leaking through parser diagnostics.
    • Honor the consumer root for executable lookup, export paths, and uv synchronization despite ambient project selectors.
    • Preserve UTF-8 and newlines in generated CLI output, retain subprocess diagnostics, and handle grouped expected failures.
    • Validate supplied release asset digests before downloading and reject portable aliases of Git metadata paths.
    • Update the uv pin to 0.12.18 and document notebook adoption, release publication, and shared workflow ownership.

Fixed

  • Suppress parser warnings during timeout advice 3b6cff7

    • Suppress SyntaxWarning only while parsing cells, preventing stderr leakage and false syntax skips under warnings-as-errors.
    • Preserve genuine syntax-error handling and caller warning filters.
    • Clarify that download_release_asset saves verified assets and requires a separate extract_archive call to unpack them.

v0.1.4

Choose a tag to compare

@github-actions github-actions released this 22 Sep 19:53
3d827f0

Added

  • Add configured benchmark and release workflows 4384fce

    • Select release pairs and measure benchmarks in isolated worktrees with source, harness, toolchain, and dependency provenance.
    • Manage authenticated baseline assets and draft release uploads with hash verification, safe retries, and optional publication.
    • Convert legacy evidence while preserving original hashes, and support report promotion, archival, offline rendering, and CSV export.
    • Prepare future-release documents with source inventory rechecks and exact verification against existing release tags.
    • Add portable file selection, command batching, configured validation, and checked CI and toolchain environment exports.
    • Support canonical release tags and dependency-only Python environments, with consumer templates and MCMC migration guidance.

v0.1.3

Choose a tag to compare

@github-actions github-actions released this 22 Sep 00:45
0218f6b

Added

  • Add managed SARIF tools and public Python utility APIs
    5e1290e

    • Manage clippy-sarif and sarif-fmt with exact locked installation, checked execution, and upgrades limited to declared tools.
    • Expose executable resolution and text/byte command runners that preserve Git input bytes and original failure diagnostics.
    • Support transactional byte publication with target validation, preserved permissions, rollback, and structured recovery errors.
    • Document API compatibility, platform limits, and consumer migration.
  • Add configurable policies and structured plans cf4331f

    • Declare required files, fixed metadata, and active release references with exclusions for historical evidence.
    • Expose typed discovery, checks, plans, and consumer adapters for contributing edits and validating complete candidates.
    • Apply the exact previewed bytes with stale-input checks and transactional rollback; reject fixed DOI mismatches before editing.
    • Document replacing MCMC's release orchestration with configuration and small adapters while retaining consumer-owned evidence policy.
  • Add Criterion comparison and evidence APIs b3de44f

    • Add validated timing comparisons with explicit units and complete common, added, and missing benchmark inventories.
    • Preserve exact evidence bytes with deterministic serialization, source and harness provenance, and explicit compatibility checks.
    • Support bounded asset retrieval, safe archive extraction, and recoverable publication with immutable evidence and alias protection.
    • Add performance commands for comparison, extraction, retrieval, retained-data rendering, and verification.
    • Document retained-evidence migration while keeping benchmark execution and scientific acceptance policies in consumers.
  • Add evidence-backed document publication 1ad1c56

    • Add Python publication plans and a TOML-driven performance publish command with check and preview modes.
    • Render selected timing tables and optional SVGs with explicit labels, units, and links, without plotting dependencies.
    • Verify provenance, release references, and exact tagged artifact bytes before publishing documents and figures with snapshot checks and rollback.
    • Preserve surrounding document bytes, historical links, and UTF-8 preview output across platforms.
    • Document migration through consumer schema and renderer adapters.
    • Share the Git-mutation opt-out across checkout and installed consumer suites while retaining full coverage by default.

Changed

  • Make public API consumer checks portable 08140cf

    • Resolve relative interpreter paths without crossing Windows drives.
    • Explicitly use UTF-8 for the Unicode subprocess probe so inherited encodings cannot cause decoding failures.

Fixed

  • Handle discovery errors and Windows check failures
    4114c94

    • Report failed or timed-out release discovery on stderr and return status 1 instead of propagating subprocess exceptions.
    • Describe release updates as transactional with rollback on failure, removing the inaccurate atomicity claim.
    • Use explicit LF and CRLF fixtures so release-policy checks preserve exact bytes consistently across platforms.
  • Protect performance inputs and enforce portable text writes
    a494030

    • Reject comparison outputs within either Criterion input root, including equivalent path aliases.
    • Reject Unicode surrogates in archive names before filesystem access.
    • Enforce explicit newline policies through just newline-check, included in just check and just ci.
    • Make generated scripts and fixtures portable while preserving intentional LF/CRLF data and malformed ZIP names on Windows.

v0.1.2

Choose a tag to compare

@github-actions github-actions released this 20 Sep 06:59
62f3a41

Merged Pull Requests

  • Bump astral-sh/setup-uv in the github-actions group #18

Added

  • Add managed Cargo upgrades and notebook workflows
    2ad1023

    • Add toolchain upgrade and update-cargo-tools, publishing Cargo pins only after installation succeeds and preserving prior pins on failure.
    • Include managed Cargo upgrades in the consumer update workflow.
    • Add optional notebook environment setup, validation, output cleanup, and fresh-kernel execution with source-preserving reports.
    • Check notebook syntax, Ruff rules and formatting, and ty types with diagnostics tied to stable cell IDs.
    • Honor configured notebook groups and reject numeric overflow before execution or file changes.
    • Fix draft release creation using annotated tag notes.
  • Complete dependency and tool update workflows edf7e34

    • Add aggregate, dependency-only, Cargo, Python, and tools-only recipes while preserving support for Python-only consumers.
    • Keep Cargo exclusions and additional resolution roots under consumer control.
    • Upgrade the full Python lock and synchronize dev with managed tools, retaining update-python-deps as an alias.
    • Bootstrap updates from the tooling group so native consumer builds wait until the final checked sync.
    • Support cargo-audit, cargo-machete, samply, tectonic, and tex-fmt with executable verification and native prerequisite guidance.
    • Document the superseded uv, Just, and cargo-update policies.

Fixed

  • Guard Cargo pin publication and Windows notebook sync
    f28204b

    • Recheck source content and symlink targets after staging Cargo pin updates, refusing publication when either has changed.
    • Start notebook-sync with managed Python to prevent Windows from replacing the environment while its CLI is running.
  • Require a cargo-edit pin for cargo upgrade 0dc0034

    • Reject cargo upgrade through toolchain run when cargo-edit is undeclared, even if an unmanaged copy is available on PATH.
    • Direct consumers to declare an exact pin and run just setup to install and verify the tool before upgrading dependencies.
  • Enforce cargo-edit pins for direct upgrades bd74456

    • Require a declared cargo-edit pin for direct cargo-upgrade calls and clarify exact version and setup requirements.
    • Exercise real Cargo requirement and lockfile updates from installed wheels in Linux, macOS, and Windows CI.
    • Prevent false Windows failures when comparing executable paths.

Maintenance

v0.1.1

Choose a tag to compare

@acgetchell acgetchell released this 19 Sep 03:27
60c6eb1

Added

  • Add CodeRabbit review and publish verified release assets to PyPI
    e9f9b7d

    • Add shared branch and uncommitted review commands with thin Just recipes, verified origin/main freshness, and streamed CodeRabbit output.
    • Require repository instructions and unambiguous review configuration; keep live reviews opt-in and outside routine validation.
    • Attach validated distributions and signed provenance to draft GitHub releases, then publish the verified assets to PyPI without rebuilding.
    • Preserve environment approval and verify release identity, asset inventory, and provenance before upload.
    • Add release-update and tag-preview recipes, and consolidate metadata, changelog, tagging, and publication guidance in docs/RELEASING.md.

Fixed

  • Preserve authored history and stabilize regeneration
    c22d1be

    • Retain declared release dates instead of replacing them with Git dates.
    • Preserve squash-entry structure and wording without promoting embedded headings or removing semantically similar content.
    • Compare archives through the same formatter to make regeneration idempotent while retaining genuine conflict detection.
    • Validate extracted notes against the requested release, rejecting duplicate targets, ambiguous boundaries, and conflicting references.
    • Add changelog check and just changelog-check for strict validation of the root changelog and all archives.