Skip to content

Submit a Launch v1.6.3

Choose a tag to compare

@programmable-infra programmable-infra released this 17 Aug 09:07
· 20 commits to main since this release
Immutable release. Only release title and notes can be modified.
261e390

Submit a Launch v1.6.3

Version 1.6.3 updates the protected Application V3.1 source resolver to the exact released Hookbuilder v0.10.3 skill
tree and fixes missing manifest source blobs during trusted intake.

What changed

  • Fetch every tree-derived blob object ID in one bounded anonymous Git batch.
  • Stop relying on sparse backfill reporting success before all declared blob objects are locally readable.
  • Keep exact repository ID, public URI, commit, tree, path, mode, blob object ID, file-size, and package bindings.
  • Preserve the existing file-count, byte, process, timeout, and temporary-storage limits.
  • Keep candidate code, Git hooks, filters, submodules, and workflows inert under protected-base validation.

Authority boundary

This patch changes only trusted source retrieval. A valid Application V3.1 package remains an unreviewed Applicant
Draft. It does not grant review, acceptance, approval, deployment, discovery, routing, funds, or launch authority.

Verify locally

Use Node.js 24 or newer:

npm ci --ignore-scripts
npm test