Skip to content

Code Mower v1.5.0

Choose a tag to compare

@jeffhuber jeffhuber released this 19 Sep 14:44
· 24 commits to main since this release
v1.5.0
197c0c6

Code Mower v1.5.0 Release Notes

v1.5.0 adds the basic supervised private-workspace Slack boundary and the
Graphify compatibility changes below. The install identity is
code-mower==1.5.0. Claude + Codex remain the default. Default dependencies are
only PyYAML and packaging: no Slack SDK, login, network setup, service, Graphify
installation or provider dispatch is added by installing Code Mower.

Included behavior

  • Explicit code-mower slack setup --manifest slack-app.json --yes creates the
    hosted manifest privately and exclusively. slack doctor and doctor --slack
    provide bounded, redacted diagnostics. An offline snapshot cannot establish
    live readiness or authorize dispatch (#1024).
  • Supervisor v2 retains the original claim, lease, provider binding and
    cumulative caps across checkpointed clarification/fix requests (#1017).
    The v1 contract remains frozen. Public code is the contract/setup surface;
    hosted administration, credentials and deployment remain separately owned.
  • Exact-head audit publication is reliable across repository dispatch, with
    bounded refusal diagnostics (#1025 / #1026 / #1030).
  • Explicit headless Codex campaign file authentication, clearer setup-drift
    operands, concise adoption doctor guidance, bounded Board startup observation
    and canonical local-lane writer identities carry forward the accepted fixes
    listed in the 1.5.0 CHANGELOG.

Graphify compatibility and upgrade

PR #1007 contributes four behaviors:

  1. A separate bounded 16 MiB provider inventory reader, retaining the
    256 KiB generation-manifest bound and existing hash/coverage checks.
    Oversized provider inventories refuse publication explicitly.
  2. doc_ref nodes are declared non-code exclusions; their incident edges cannot
    become code query results or citations. Unknown types still fail validation.
  3. Related-test queries recognize JavaScript/TypeScript .test, .spec and
    __tests__ conventions and follow import relationships. Import evidence
    does not establish execution coverage.
  4. Acquisition guidance covers language parser extras, supported runtime
    ownership and the single-worker option without weakening containment.

Merged PR #1031 (#1029) additionally makes build/refresh/status/connection-status
readiness agree with the installed query reader. Compatibility diagnostics name
the upgrade/rebuild action without disclosing graph content or local paths.
Generation completeness and query completeness are separate: a bounded partial
answer remains available and discloses its limits; it does not make a complete
generation incomplete.

The separate provider pin remains graphifyy==0.9.58. Upgrading Code Mower does
not rewrite existing graphs. Inspect code-mower context-graph status --json
and explicitly code-mower context-graph refresh affected/partial generations
(for example, a refused oversized inventory or inputs skipped for missing
parsers). A usable unaffected generation needs no rebuild merely because its
query reached a traversal limit. See Graphify setup.

Qualification and boundaries

The qualification contract separates pre-merge rehearsal,
the immutable merge-SHA candidate, private acceptance (#918), one accepted
completion and one accepted confirmed-cancellation outcome (#920), with every
attempt and reservation count-preserved, and publication/reinstall (#923).
The final candidate normally supplies the paid canary bytes. For this v1.5.0
closeout, the contract also permits a machine-verified carry-forward from a
retained ancestor candidate only when every wheel member outside the closed
audit/release/documentation set is byte-identical, both immutable audit receipts
replay successfully, and the exact final wheel repeats private no-provider
acceptance. Any Slack, supervisor, provider, CLI, persistence, state, dependency
or entry-point difference requires newly authorized canaries.
Only explicitly observed outcomes count. Sanitized outcomes belong on #923 and
the GitHub Release rather than in the qualified source.
These notes claim no paid or live hosted result. Canaries require numeric task
and aggregate authorization.

Slack scope is one private workspace, one private unshared channel, authorized
repository aliases, private replies, start/status/answer/confirmed cancellation,
qualified Codex supervision and bounded hosted Devin execution. Registration is
not qualification; acknowledgement is not provider exit or settled billing.
Slack telemetry/Board/cloud links and richer UX remain v1.5.1. No Slack Connect,
public channel, unrestricted execution or peer-orchestrator Devin is implied.

Disposable package rollback to exact 1.4.2 is an installation rehearsal only.
Never downgrade live durable v2 state. Disable admission, reconcile original
work and confirmed exits, preserve claims/receipts/reservations, and restore only
a reviewed compatible deployment through its owner-controlled rollback. Follow
Slack upgrade, disable, rollback and uninstall.

No private graph, query, source, task prose, credentials, mappings, provider
output or adoption evidence belongs in public artifacts. Historical v1.4.x
release notes, qualification records and published artifacts remain unchanged.

The immutable v1.5.0 candidate must be built from the final reviewed release
source after every required qualification ancestor, including #1043 and the
final closeout change. Publication attaches that retained artifact pair to the
GitHub Release, verifies the non-publishing release-event run and assets, and
removes the temporary candidate-run repository variable.

Observed release evidence

  • Final reviewed release source: PR #1049, merge 197c0c6080afe2a7625d22b897f4027112cf4a01; exact-head Codex and Claude audits, full CI and the authoritative gate passed.
  • Immutable candidate: run 35447905132, first attempt on main; wheel SHA-256 4f2451a7801980a74c34908166cdba7f2e44e15f12a610733cef37bc8f483e06; sdist SHA-256 6d52d398237a5096fa23fbd496c9816f44a8f97b28de6f8c6ea43b948f5c7a19; inventory and all ten installed-wheel rehearsals passed.
  • Private installation and Slack administration: #918 final acceptance passed against the exact final wheel with no provider or GitHub calls.
  • Hosted completion and confirmed-cancellation outcomes: #920 campaign closeout passed with all attempts, reservations, failure/recovery history, exits and unsettled usage count-preserved.
  • Canary carry-forward: #923 equivalence evidence passed; 335 wheel members were byte-identical and the complete ten-member audit/release/documentation delta was within the closed allowlist. Both immutable audit receipts were replayed successfully at the accepted completion head.
  • Owner release decision: #923.
  • No-publish verification: run 35449469067 passed candidate retrieval, identity and distribution verification; both index publication jobs were skipped.
  • Production PyPI publication: run 35449515374 passed; TestPyPI was skipped.
  • Canonical PyPI verification: both production files matched the retained candidate digests. A fresh Python 3.12 environment installed code-mower==1.5.0 from canonical PyPI, both CLI entrypoints reported 1.5.0, and pip check passed. The canonical wheel then passed all ten offline install, Slack opt-in/disabled, Graphify, 1.4.2 upgrade, rollback, uninstall and synthetic-state-preservation checks.

Raw credentials, private identities, mappings, logs, source context, task prose and provider output are excluded from this release record.

  • GitHub Release event verification: run 35449662780 passed candidate retrieval and distribution verification; both publication jobs were skipped.
  • Final release verification: GitHub Release assets are byte-identical to both the retained candidate and canonical PyPI files; the release is public, non-prerelease and selected by the latest-release endpoint. The temporary candidate-run variable was removed, while both release-event publication switches remain explicitly false.