Skip to content

Project Delivery v1.3.0

Choose a tag to compare

@sealad886 sealad886 released this 19 Jul 10:06
f491e68

Project Delivery 1.3.0

Project Delivery 1.3.0 hardens the independent thirteen-skill lifecycle for public marketplace distribution and evidence-based replacement of fragmented generic delivery workflows.

Highlights

  • Adds reproducible source and versioned-cache validation, seven regression tests, and 17 machine-readable route contracts that are explicitly classified as static—not behavioral—evidence.
  • Makes the Awesome Codex Plugins mirror self-contained by carrying the operating model, templates, and provider contract inside the manifest-declared skill tree.
  • Strengthens security-finding suppression, risk and decision traceability, external-system authority, decommission routing, and bounded subagent delegation.
  • Adds public security, contribution, support, issue, pull-request, changelog, Dependabot, validation, and SHA-pinned scanner workflows.
  • Expands the marketplace landing page with lifecycle routing, prompts, artifacts, trust boundaries, installation, migration, and validation guidance.
  • Preserves all existing skill names and adds no MCP server, app, hook, telemetry, provider, package, or legacy-plugin dependency.

Release evidence

  • Release commit: f491e688cbfb400329af96dfad21fd1613414adf
  • Plugin Creator validation: pass
  • Skill Creator validation: 13/13 pass
  • Source validation: 87 files and 13 skills, pass
  • Validator regressions: 7/7 pass, including installed version-cache layout
  • Static route contracts: 17 scenarios covering all 13 skills, pass
  • Marketplace mirror simulation: 63 selected files, 13 skills, and three shared runtime documents, pass
  • Local HOL public-marketplace scan: 97/100 (A), with zero critical, high, medium, or low findings
  • Hosted plugin validation: pass on the release commit
  • Hosted HOL Plugin Scanner: pass on the release commit, including hosted Python 3.12/Cisco scanner availability
  • Independent release review: approve, with no unresolved source-candidate finding

Adoption boundary

This release is suitable for publication and marketplace review. It does not claim that static routes prove fresh-agent behavior or that every consumer is ready to uninstall prior workflows. Before uninstalling a superseded generic workflow, neutralize active legacy instructions, capture reinstall/rollback identity, run fresh small and medium canaries with candidates disabled one at a time, observe the result, and obtain explicit confirmation of the uninstall set. Specialist provider, platform, security, CI/CD, signing, deployment, observability, and communication tools remain evidence or access adapters rather than lifecycle competitors.

See the changelog, validation report, and migration guide for details.