v0.19.0 — Severity rubric + deterministic CHANGELOG severity
Incorporates feedback from a downstream agent that ran ~24 Sentinel reviews (2 genuine 🔴 blocks of broken PRs; 0 bad merges). Net: the review depth is the asset — keep it. The gaps were severity reproducibility across fresh-agent reviewers and non-behavioral noise. Triaged for general-case value (downstream feedback is advisory, not prescriptive); reviewed by a 2-model panel (GPT-5.5, Gemini 3.1 Pro).
Added
- Severity rubric companion (
template/docs/sentinel/SEVERITY-RUBRIC.md): a version-pinned orchestrator Phase 3 calibration reference — an ordered decision procedure plus golden worked-examples across all 7 dimensions drawn from the real reviewed cases. Makes the same finding class yield the same severity regardless of which agent orchestrates. Includes disambiguating contrast pairs (injection→🔴 vs UIMath.random()→🟢; typosquat/postinstall→🔴 vs unused dev-dep→🟢). Companion file keepsSENTINEL.mdat 176 lines.
Changed
- Missing CHANGELOG is now deterministically 🟢 — never 🟡/CONDITIONAL (
SENTINEL.mdPhase 3 +dim-f). Closes the "user-impact requirement" loophole that produced repeated APPROVED→CONDITIONAL churn for a non-behavioral convention. - CHANGELOG implementer nudge: the template AGENTS.md CHANGELOG row is marked
(TDD-exempt; include in the PR)so it is rarely even a finding. - Report persistence clarified (
SENTINEL.mdPhase 5): durable PR-comment default; a committed.sentinel/reports/<id>.mdfallback must land on a persisted branch — never inside a throwaway/ephemeral verification worktree. Platform-neutral (no hardcoded temp-dir policy).
Deferred
- Presentational-surface-only dispatch lane (#14,
sentinel:deferred): a diff-aware skip of A1/A2 on pure CSS/copy diffs. Deferred pending a Dim-E-tight positive surface definition;style/docscommits already skip A1/A2 via selective dispatch.
Rejected (logged for traceability)
- Blanket content-based A1/A2 security-dim skip (reverses v0.17.0 hardening + Dim-E "never skip" principle).
- Upstream mutation-testing / coverage-diff gate (imposes tooling on every adopter).
- Dropping the report "Agent ID" column (already handled —
N/A+ platform-limitation note is explicitly permitted).
Metrics: SENTINEL.md 176/178 · AGENTS.md 133/135 post-setup · new companion file.
Downstream sync (follow-up, user-driven): gitnotate, Arbol, Council, stream-deck-ical, stream-deck-github-utilities, stream-deck-cloudflare-utilities, obsidian-subtitles-md, github-dashboard.