Project Delivery v1.3.0
Project Delivery 1.3.0
Project Delivery 1.3.0 hardens the independent thirteen-skill lifecycle for public marketplace distribution and evidence-based replacement of fragmented generic delivery workflows.
Highlights
- Adds reproducible source and versioned-cache validation, seven regression tests, and 17 machine-readable route contracts that are explicitly classified as static—not behavioral—evidence.
- Makes the Awesome Codex Plugins mirror self-contained by carrying the operating model, templates, and provider contract inside the manifest-declared skill tree.
- Strengthens security-finding suppression, risk and decision traceability, external-system authority, decommission routing, and bounded subagent delegation.
- Adds public security, contribution, support, issue, pull-request, changelog, Dependabot, validation, and SHA-pinned scanner workflows.
- Expands the marketplace landing page with lifecycle routing, prompts, artifacts, trust boundaries, installation, migration, and validation guidance.
- Preserves all existing skill names and adds no MCP server, app, hook, telemetry, provider, package, or legacy-plugin dependency.
Release evidence
- Release commit:
f491e688cbfb400329af96dfad21fd1613414adf - Plugin Creator validation: pass
- Skill Creator validation: 13/13 pass
- Source validation: 87 files and 13 skills, pass
- Validator regressions: 7/7 pass, including installed version-cache layout
- Static route contracts: 17 scenarios covering all 13 skills, pass
- Marketplace mirror simulation: 63 selected files, 13 skills, and three shared runtime documents, pass
- Local HOL public-marketplace scan: 97/100 (A), with zero critical, high, medium, or low findings
- Hosted plugin validation: pass on the release commit
- Hosted HOL Plugin Scanner: pass on the release commit, including hosted Python 3.12/Cisco scanner availability
- Independent release review: approve, with no unresolved source-candidate finding
Adoption boundary
This release is suitable for publication and marketplace review. It does not claim that static routes prove fresh-agent behavior or that every consumer is ready to uninstall prior workflows. Before uninstalling a superseded generic workflow, neutralize active legacy instructions, capture reinstall/rollback identity, run fresh small and medium canaries with candidates disabled one at a time, observe the result, and obtain explicit confirmation of the uninstall set. Specialist provider, platform, security, CI/CD, signing, deployment, observability, and communication tools remain evidence or access adapters rather than lifecycle competitors.
See the changelog, validation report, and migration guide for details.