Releases: sealad886/project-delivery
Release list
Project Delivery v1.4.0-rc.1
Project Delivery v1.4.0-rc.1 is the first release candidate for the standalone Codex plugin that replaces fragmented generic project-management and software-delivery workflows with one repository-grounded lifecycle.
Highlights
- 13 coherent skills covering context, requirements, design, planning, coordination, implementation, quality, documentation, review, security/operations, release, and learning.
- One risk-scaled orchestrator for small fixes, medium features, large or multi-PR initiatives, review-only, design-only, release-only, incident, and workflow-decommission requests.
- 24 semantic route profiles with explicit authority, ownership, gates, evidence, stop conditions, and no runtime dependency on Boss, Epic/Epic Harness, Superpowers, or another workflow plugin.
- Complete plugin and per-skill icon family.
- Exact 64-file installable package boundary, MIT license, local personal-marketplace support, and Git
git-subdirmarketplace metadata.
Validation
- 155/155 regression tests passed.
- Plugin Creator and 13/13 skill validations passed.
- Hosted validation, HOL scanner, plugin-scanner, and GitGuardian checks passed on the tagged main revision.
- Prepared source and installed personal-cache payload matched exactly.
- Fresh-process smoke task reported the exact installed cachebuster version and selected the expected lightweight planning route.
RC limitations
- Use this prerelease in normal small and medium work before promoting stable
1.4.0. - Icon files and references validate, but protected Codex UI pixels were not directly automated; fully relaunch Codex Desktop if an existing task retains stale cards.
- Keep a rollback source for superseded generic workflow plugins until adoption is confirmed.
See the repository README, migration guide, and concise validation report for installation and adoption details.
Project Delivery v1.3.2
Project Delivery v1.3.2 presents the plugin as a self-contained, source-installed Codex delivery workflow.
Highlights
- Rewrites installation and usage guidance around a stable local source checkout and the system Plugin Creator workflow.
- Uses fully qualified Project Delivery skill names in quick-start examples.
- Renames the installable-distribution validator and aligns contributor, CI, template, audit, and validation terminology.
- Keeps the runtime self-contained: 13 skills, shared runtime documents, agent manifests, and referenced icons, with no package or service dependency.
Verification
- Source structure: 87 files and 13 skills.
- Route contracts: 17 scenarios across all 13 skills.
- Standalone distribution: 63 files, 13 skills, and three shared runtime documents.
- Validator regression suite: 7 of 7 tests passed.
- Exact-commit validation run 29686657123: passed.
- Exact-commit scanner run 29686657135: passed with zero critical, high, medium, or low findings.
Release commit: c46a849.
Project Delivery v1.3.1
Project Delivery v1.3.1 is a metadata-hardening patch for the public marketplace candidate.
Changed
- Declares
license: MITin every one of the 13 skill manifests. - Keeps the canonical root MIT license byte-identical, including the standard copyright notice for Andrew Cox.
- Updates version, changelog, and validation-scope records to 1.3.1.
Verification
- Exact release commit:
fe3919407339ca973454bd7ff0e2afde3cd0a812 - Validate plugin: passed structure, route contracts, marketplace-mirror simulation, and regression tests.
- HOL Plugin Scanner: passed the configured score and severity gates, uploaded SARIF, and automatically fixed all 13 prior missing-skill-license alerts.
- Independent review: no release-blocking finding.
Informational scanner context
The remaining open SARIF notes are 26 binary-file notices for required PNG interface icons and three notices for intentionally absent optional privacy-policy, terms, and screenshot metadata. No fabricated policy URLs or screenshots were added.
Project Delivery v1.3.0
Project Delivery 1.3.0
Project Delivery 1.3.0 hardens the independent thirteen-skill lifecycle for public marketplace distribution and evidence-based replacement of fragmented generic delivery workflows.
Highlights
- Adds reproducible source and versioned-cache validation, seven regression tests, and 17 machine-readable route contracts that are explicitly classified as static—not behavioral—evidence.
- Makes the Awesome Codex Plugins mirror self-contained by carrying the operating model, templates, and provider contract inside the manifest-declared skill tree.
- Strengthens security-finding suppression, risk and decision traceability, external-system authority, decommission routing, and bounded subagent delegation.
- Adds public security, contribution, support, issue, pull-request, changelog, Dependabot, validation, and SHA-pinned scanner workflows.
- Expands the marketplace landing page with lifecycle routing, prompts, artifacts, trust boundaries, installation, migration, and validation guidance.
- Preserves all existing skill names and adds no MCP server, app, hook, telemetry, provider, package, or legacy-plugin dependency.
Release evidence
- Release commit:
f491e688cbfb400329af96dfad21fd1613414adf - Plugin Creator validation: pass
- Skill Creator validation: 13/13 pass
- Source validation: 87 files and 13 skills, pass
- Validator regressions: 7/7 pass, including installed version-cache layout
- Static route contracts: 17 scenarios covering all 13 skills, pass
- Marketplace mirror simulation: 63 selected files, 13 skills, and three shared runtime documents, pass
- Local HOL public-marketplace scan: 97/100 (A), with zero critical, high, medium, or low findings
- Hosted plugin validation: pass on the release commit
- Hosted HOL Plugin Scanner: pass on the release commit, including hosted Python 3.12/Cisco scanner availability
- Independent release review: approve, with no unresolved source-candidate finding
Adoption boundary
This release is suitable for publication and marketplace review. It does not claim that static routes prove fresh-agent behavior or that every consumer is ready to uninstall prior workflows. Before uninstalling a superseded generic workflow, neutralize active legacy instructions, capture reinstall/rollback identity, run fresh small and medium canaries with candidates disabled one at a time, observe the result, and obtain explicit confirmation of the uninstall set. Specialist provider, platform, security, CI/CD, signing, deployment, observability, and communication tools remain evidence or access adapters rather than lifecycle competitors.
See the changelog, validation report, and migration guide for details.