Documentation and package-metadata release. The published CLI also includes the post-v1 read-only evidence implementation merged before this release; no mutating provider, MCP, extension-installation, or dependency behavior was introduced.
Changed
- Made the GitHub Pages site the canonical public documentation destination in the repository and npm-facing READMEs.
- Updated the GitHub and npm project description to describe the local, vendor-neutral framework and CLI.
- Published intentloom@1.0.2 through the protected npm trusted-publishing workflow with SLSA v1 provenance.
- Included bounded live GitHub/GitLab provider reads and the untrusted external-MCP evidence boundary from PR #160.
Verification
- GitHub Pages root and key documentation routes return HTTP 200.
- Full local verification passed: 851 tests passed, 3 skipped.
- Compatibility, CodeQL, dependency-review, governance, and release workflow checks passed.
- The remaining Dependabot alert is glib@0.18.5 in the Tauri GTK3 stack; a direct glib@0.20.0 update is incompatible with gtk@0.18.2 and remains tracked under the expiring exception.
The read-only provider/MCP hardening gate remains active. Full changelog: https://github.com/vitala89/Intentloom/blob/main/CHANGELOG.md