Releases: davidahmann/mill
Release list
Mill v0.3.1 (Public alpha)
Mill v0.3.1
0.3.1 is a qualified public-alpha maintenance release. It updates the pinned
artifact actions used by Mill's immutable release workflow and updates the
development test toolchain to Vitest 5.0.0 and typescript-eslint 8.69.0.
The release workflow preserves its independent-build, exact-artifact,
qualification, provenance, registry-readback, and GitHub-asset checks. Its
GitHub Release is a normal release titled Public alpha, allowing GitHub to
select it as Latest without expanding Mill's qualified support tuple.
Install
npm install --save-dev --ignore-scripts @davidahmann/mill@0.3.1
npx --no-install millctl --versionPin the exact version. The npm latest channel is a distribution pointer, not
an automatic-update instruction; an existing repository must deliberately
requalify changed delivery machinery.
The public-alpha limits remain unchanged. This release does not add a supported
stack, grant autonomous merge or deployment authority, or change the release
trust boundary.
Mill v0.3.0
Mill v0.3.0
0.3.0 is the current qualified public alpha. It adds truthful brownfield
continuation and recovery evidence, deterministic harness evaluation,
provider-measured cache-token observations, and an explicit trusted-host
isolation boundary. It documents—but does not implement—a revision-bound symbol
context adapter and a governed improvement record. The release does not add a
graph service, arbitrary-stack support, autonomous merge/deployment, or a claim
of hostile-host builder isolation.
Install
npm install --save-dev --ignore-scripts @davidahmann/mill@0.3.0
npx --no-install millctl --versionPin the exact version. The latest channel is a distribution pointer, not an
automatic-update instruction; an existing repository must deliberately requalify
changed delivery machinery.
Exact qualification
- Tag commit:
9d8105100845b306e508538257832d2c13ea31cc. - Reviewed and resulting-main tree:
ebe2ba513d713a01754d24c88b0d6ea06c1e4f95. - Annotated tag object:
f9ae5f652270e54140eb6161c98fe336d002bc40. - Preserved tarball SHA-256:
887c39e859e233e3ace6f06d6bb00c8d9760ccf3d58a28137a751b656e8b1922. - npm integrity:
sha512-6wXxLdhBgwF5Hj4W0UXvxHV7VXLPbm1lpRM4w1XeyoxUnibNaivQfKYDMwQbhTkr+W4SlivKTsC0EnTUkBFF5A==. - Canonical qualification digest:
sha256:f7f832a3e06e971c9fd6c649778e1cfb39f892627f9b3299aff4b23c92145cfb. - Candidate run 33975289594
passed two clean, byte-identical builds; the complete native gate; the
exact-tag audit; packed greenfield and adoption canaries; and the separately
pinned v0.1.5 independent policy and downstream canary. - Its qualification binds the macOS arm64 / Node 24.20.0 / npm 11.19.0 / Docker
29.7.2 / Codex CLI 0.153.4 tuple, observed at2026-09-05T15:35:52.039Zand
expiring at2026-10-05T15:35:52.039Z. It does not qualify another host,
harness, model identity, forge, or recipe.
Publication and recovery
Publish run 33975771369
published the preserved tarball once through the protected npm environment, then
verified npm provenance/signatures and requalified the registry-downloaded
package. The run stopped before GitHub Release creation because the immutable
tag predated this release record. npm publication is never replayed for that
failure. The attended recovery created the release from the exact preserved
candidate assets, downloaded the GitHub tarball again, and bound the resulting
provider readback. It did not rebuild or republish the package.
- GitHub Release
carries the tarball, checksum, SBOM, prepublication evidence, and final
evidence. The final-evidence file SHA-256 is
b5fd8cf5b5042a4d1b0b6a456b19f6c76c6ad74842ecad272adfd6e6ae7d1e3d. - npm provenance,
signature readback, exact integrity, and the registry-package full canary
passed before recovery created the GitHub Release. - Separate attended channel promotion made GitHub Latest and npm
alphaand
latestselect0.3.0. Provider readback confirms those pointers and the
unchanged immutable package integrity.
The documentation and workflow closure following the immutable tag adds an
immediate candidate-stage gate for a regular, non-symlink, nonempty release
record with a real docs/ and docs/releases/ parent-directory chain. It
prevents this ordering error in future releases; it does not alter the 0.3.0
tarball, tag, candidate evidence, or trust-root history.
Mill v0.2.1
Mill v0.2.1
The latest Mill release on GitHub. Mill remains a qualified public alpha, not a general enterprise-stack or production-readiness certification. GitHub's Latest designation is a distribution setting; it does not expand the qualified support tuple.
What changed
- Source-backed follow-up plans compile into dependency-aware bounded tasks.
- Brownfield discovery supplies bounded task and review context; native Node adoption remains experimental.
- Local review covers the complete base-to-candidate diff, including preparation changes.
- Committed validation failures permit one bounded, scope-preserving repair generation.
- Attended merge plans support separately approved exact-head merges; draft-only remains the default. Builders and reviewers never receive forge mutation authority.
- Privacy, effect reconciliation, phase-specific producer-bound CI, status, and usage reporting are strengthened.
- Release runners explicitly prepare the digest-pinned verifier before publication, guarded by native workflow-policy tests.
Install
npm install --save-dev --ignore-scripts @davidahmann/mill@0.2.1
npx --no-install millctl --versionnpm alpha and latest both point to 0.2.1. The owner separately approved the latest dist-tag promotion; registry readback verified the unchanged artifact integrity. Pin the exact version deliberately. Existing repositories must requalify after updating their Mill pin. Do not assume an older binary can interpret newer approval state.
Qualification and provenance
- Reviewed source PR: #23, following architecture PR #22.
- Exact tagged commit:
a2dcd27fa01df9a609b3d057d14dca25c0895262. - Reviewed and resulting-main tree:
477d6f7fbca7502a5d6aea6545c2f34bd85c8665. - Candidate qualification run 33957390470 passed two independent clean builds, packed-artifact qualification, and the separately pinned v0.1.5 verifier.
- Source native validation passed 270 tests with 81.31% branch coverage. All five dependent live canary steps passed; a separate seeded regression was rejected and recovery verified.
- Preserved package SHA-256:
dfa6e6415145db46479caf8168730d31fee7668de180ac119b3f4a169a660dbe. - npm provenance, registry signatures, registry-downloaded package qualification, and GitHub asset readback were verified. No package was rebuilt or republished during recovery.
- Attached
qualification.jsondefines the exact macOS arm64 / Node 24.20.0 / npm 11.19.0 / Docker 29.7.2 / Codex CLI 0.153.1 tuple and bundled Node/TypeScript/Next.js recipe. Qualification was exercised on September 5, 2026 and expires October 5, 2026 at 09:11:04 UTC. Other tuples and arbitrary-stack/pnpm adoption are not qualified. - Attached
release-evidence-final.jsonbinds the reviewed source, two builds, preserved artifact, qualification, SBOM, registry, and GitHub release. Keep the v0.1.5 trust-root artifacts.
Publication recovery record
OIDC publish run 33957855919 successfully published the preserved package, verified npm signatures, and passed registry-package qualification. Its final GitHub readback failed because an already-public, empty release and a separate workflow draft shared tag v0.2.1; tag-based download selected the empty public release.
After explicit owner approval, the attended maintainer attached the same verified artifacts to public release ID 383198362, downloaded and checked every asset, and assembled final evidence using the tagged release tools. The workflow remains failed as historical evidence; it was not rerun. Duplicate draft ID 383199322 remains untouched. GitHub Latest promotion was separately approved by the owner. The annotated tag and npm version were not changed.
The v0.2.0 tag is retained as held prepublication evidence; no 0.2.0 npm publication or GitHub Release was attempted.
Known limits
Native Node ESM/npm adoption is experimental, not arbitrary-stack or pnpm support. Five live steps do not establish statistical reliability, productivity gains, or enterprise production readiness. Provider currency cost was unavailable and is not estimated.
Known maintainer-disposition P2: run state purge from a surviving original checkout, not an authority worktree scheduled for deletion. Preserve an external state backup and committed Git branches first. Using a deletable worktree as the command root can leave cleanup incomplete.
Full changelog: v0.1.5...v0.2.1
Mill v0.1.5
Mill v0.1.5 public alpha
Mill is a local-first, repo-native software factory for taking approved product
intent through a bounded Codex build, native validation, exact-candidate review,
and an attended draft GitHub pull request.
This first alpha supports one exact Node.js/TypeScript/Next.js web recipe and
compatible adoption on the support tuple named in the attached qualification
evidence. All other combinations are experimental or unsupported.
The release assets include the exact npm tarball, SHA-256 checksum, CycloneDX
SBOM, and release-evidence record. Install the exact version with lifecycle
scripts disabled:
npm install --save-dev --ignore-scripts @davidahmann/mill@0.1.5
npx --no-install millctl --versionVersions 0.1.0 through 0.1.3 were never published. Version 0.1.4 created
the npm package identity but is not the supported alpha because that bootstrap
publication has no CI provenance or GitHub Release. Version 0.1.5 runs the
complete protected OIDC publication and readback chain.
Read README.md for the supported path, AGENTS.md for coding-agent operation,
and docs/release.md for verification and withdrawal. Mill remains attended,
single-repository, and single-writer. It does not auto-merge, deploy, provision
repositories, or contain a hostile coding agent from the host.