Repository navigation
Releases: wheakerd/axiom
Release list
Axiom v0.13.3
Added
- Added
local-web-searchfor searches and follow-up page access from a local browser or client, including a fallback from cloud search. - Added execution-location checks, limits on machine-information disclosure, serial browsing, and a stop-and-handoff boundary for challenges, CAPTCHAs, and rate limits.
Changed
- Moved the routing history index into
evals/and removed retired project-operation plans, launch copy, and article drafts from the release tree. Their original content remains in Git history. - Removed the duplicate distribution checker; CI and contributor instructions now use
scripts/check-publication.pyas the single aggregate validation entrypoint. - Aligned current documentation with implemented routing and runtime schema v2, separated historical design from current guidance, and corrected the required-check summary without changing installed behavior.
Removed
- Archived the v0.7.4 host snapshots and frozen no-Hook experiment in verified Git history. Retired their bundle builder, observation commands, tests, and CI source downloads; retained synthetic compatibility-schema regression coverage.
Fixed
- Made newly authored AGENTS and linked instruction-document prose default to English, with another language only when the user explicitly requests it for those documents.
- Added scoped output-language acceptance and regression coverage that distinguishes document language from conversation, explanation, and source language.
- Corrected compatibility evidence to select the matching runtime history and reject commits or digests that disagree with its canonical release subject. Preserved existing formats and historical records.
- Made malformed compatibility records report validation errors instead of Python exceptions, corrected outdated security guidance, and removed the obsolete attribute rule for retired experiment fixtures.
Behavioral impact
AGENTS authoring now explicitly rejects task language as an implicit document-language choice. Explicit document-language requests apply only to their requested scope; canonical identifiers, exact source literals, and unrelated content are preserved. This authoring rule stays in Axiom rather than being copied into target repositories. Local web research selects its own route before access; confirmed cloud-hosted search stays outside. The new workflow preserves browser identity and cannot guarantee that a site will not classify a request as automated. Action authority is unchanged. See the v0.13.3 notes.
Required action
Repository consumers must replace scripts/check-distribution-drift.py with scripts/check-publication.py, use evals/routing-history-v1.json for the history index, and retire links to the removed project/ documents. Consult Git history when those historical documents are needed. Retire no-Hook builder and observation command invocations; use the experiment archive for explicitly scoped historical reproduction. Plugin installation paths are unchanged. Request another language explicitly when it is intended for generated instruction documents. If a research site requires manual handling, resolve it yourself and explicitly indicate readiness before automated browsing can resume.
Axiom v0.13.2
Fixed
- Completed the prepared-release Git submission contract, retained separate fast-forward baselines for multiple destinations, and clarified network transport ownership.
- Corrected consolidation backup-ref validation and recovery after interrupted backup cleanup.
- Allowed bounded preparation of missing recovery material before restore validation, while retaining full rollback checks before later system changes.
- Made plugin release-readiness checks follow the target repository's release contract, including local marketplaces and non-GitHub flows.
Behavioral impact
These compatible corrections make existing Git, reversible-change, and plugin architecture workflows executable within their authorized scope. They add no public capability or implicit action authority. Unavailable evidence remains distinct from a check that does not apply. See the v0.13.2 notes.
Required action
None. Existing release and recovery records retain their original evidence; resume interrupted work only after the workflow's current-state checks pass.
Axiom v0.13.1
Fixed
- Corrected current optional routing observations to accept clarification, delegation, and task planning, with explicit separation from historical observation contracts.
- Allowed historical validation to use writable temporary-directory roots reached through symbolic links while preserving link checks within each copied tree.
Behavioral impact
These fixes change repository validation tools. Installed Skills, hooks, action authority, and the runtime digest match 0.13.0. This patch release distributes the corrections first recorded in repository policy revision 34; see the v0.13.1 notes for version and evidence details.
Required action
None for installed plugin workflows. Contributors collecting new optional routing observations should use the current contract in Routing Evaluations: codex-core-v3, observation schema v3, and response schema V4. Existing historical records retain their original contracts.
Axiom v0.13.0
Added
- Added
clarify-intentto resolve material ambiguity with plausible choices and a custom answer. - Added
delegate-simple-taskto assess bounded work against user-ordered subagent models while preserving the main session model.
Changed
- Synchronized Codex package validation guidance and project-level enable/disable instructions with official documentation while retaining the supported manifest format.
Removed
- Deprecated and removed the obsolete
plugin-creatorallowlist validator from Axiom's active validation workflow because it rejects supported Codex fields. The replacement is the repository's publication aggregate.
Behavioral impact
The routing gate resolves material intent ambiguity before selecting an action workflow or considering delegation. Eligible simple work in verified Full Access can be delegated within existing authority after announcing the exact model ID and faithful task brief. Other modes require existing assignment authority or confirmation. Model selection follows the user's model order; unavailable or unsuitable models never justify an unlisted fallback. The delegation skill does not directly invoke the clarification skill. See the v0.13.0 notes.
Required action
Provide exact model IDs in priority order to use model-aware delegation. Existing instructions to confirm assignments remain effective. Full Access does not expand task scope or authorize consequential actions.
Contributors must replace calls to the retired validator with python3 scripts/check-publication.py or the equivalent Python 3 launcher.
Axiom v0.12.0
Added
- Added
task-planningfor creating and revising actionable task and implementation plans from current requirements.
Behavioral impact
Plan revisions remove canceled work from goals, steps, dependencies, and acceptance criteria without carrying it forward as unnecessary exclusion text. Retained decisions and effective constraints stay consistent, and specialized workflows keep their existing ownership and authorization boundaries. See the v0.12.0 notes for details.
Required action
None. Update Axiom in Codex and start a new session to use the new skill.
Axiom v0.11.0
Removed
- Removed Axiom's Claude Code plugin and marketplace descriptors, SessionStart hook, and installation, update and removal guidance.
- Updated package validation and release automation to use the Codex manifest.
Changed
- Release verification now uses required repository checks and artifact integrity.
Behavioral impact
Axiom installs and runs in Codex. The plugin architecture skill retains guidance for designing Claude Code plugins in other projects. Runtime-contract schema v2 and repository policy revision 31 identify the Codex-only runtime. Historical experiment inputs and outcomes remain bound to their original versions.
Required action
Existing Claude Code users must disable or uninstall their old Axiom installation in that host; cached installations are not removed by a repository update. For continued Axiom use, follow the Codex installation guide and start a new session. See v0.11.0 notes for details.
Axiom v0.10.1 — GPT-5.4 validation unavailable
Warning
GPT-5.4 publication validation is unavailable for the frozen codex-core-v2 / gpt-5.4 / ChatGPT authentication combination. Full-profile publication validation is incomplete.
Each of the two release attempts ended with the first case UNKNOWN and the remaining sixteen NOT-RUN. Only the second attempt has a confirmed HTTP 400 model/authentication rejection; the first attempt's cause remains undetermined because its error text was not retained.
The maintainer accepts this disclosed release gap for v0.10.1 only. This release does not claim 17/17 PASS. The attached status/exception record is not a passing observation or a test-pass proof.
gpt-5.4 will no longer be used for new Axiom maintenance runs. The benchmark and historical contracts in this existing tag have not been rewritten or migrated, and no replacement model is validated by this release. This is not a claim that the entire Axiom product is unavailable.
Single-version release exception
This Release uses the existing GitHub-signed commit 79be4a893549c9b8e390f416cb5f8dad1739493e, tree b921cbc1e29d8ded5652fc6f93cdd7c8c20ef986, and unchanged v0.10.1 tag. The maintainer's exception replaces only this version's 17/17 business acceptance condition and the two standard proof assets that depend on it. Signatures, tag integrity, actual permissions, immutability and data protection are not waived. Future versions retain their own validation requirements; the generic validators and historical results are unchanged.
No passing codex-core-v2 observation or standard Axiom release-evidence attestation is supplied. The sole attached JSON records the validation status and exception. Any GitHub-native release attestation establishes release/asset integrity only, not model acceptance. GitHub Latest identifies the maintainer's selected release; it does not certify complete validation.
Fixed
- Clarified six canonical Skill discovery descriptions: compound requests retain prerequisite order, and mutually exclusive architecture or installation scopes require one clarification. Existing routes and action authority are unchanged.
- Advanced both manifests and the full-profile runtime identity for this compatible correction. Derived no-Hook packages bind the corrected canonical source; prior packages and observations retain their original identities and outcomes.
- Separated clarification before a material Git workflow choice from necessary questions after that workflow is selected. Plugin architecture or installation choices remain pending after asking, without a same-reply default based on read-only authority or current feasibility.
- Pinned historical builder regression inputs and clarified the shared front-door measurement definition. The no-Hook observer uses a supported native environment-context setting with unchanged read permissions and separately bound observations.
Behavioral impact
Descriptions expose existing ordering and ambiguity boundaries during native Skill discovery. Original case requests, classifications, expected routes and scoring are unchanged. Hooks and their wrappers are unchanged. Static validation and version-specific host observations remain distinct evidence categories.
Required action
None. See the v0.10.1 release notes for migration and compatibility evidence boundaries.
Preserved evidence limits
Integration uses separately bound no-Hook evidence, not a new 16/16 batch. A11 remains benchmark FAIL for execution 16c13a3056a463149d93080cdd9f6102f31b8a3f, result cbab9b393bc19801d4ceaae7bbf29b4669509d2064bc206e9c5bff9b5267477a. Only its no-route/unavailable classification difference was accepted; exact distinction between missing discovery and an available catalog with no match is not promised, and no other failure receives that waiver.
B13's limited PASS retains the selection and public reading of Skill guidance before the business-choice question, followed by a pending business workflow. It is not evidence that no Skill was selected before clarification or a native loading receipt. A5's complete intermediate messages, historical failures, and the scoped R4/FCR and R5 host limitations remain as disclosed in Field Validation. Historical documents at the frozen tag retain their original pre-publication state; this Release and its status attachment record the present exception.
Cumulative canonical attempts / observation CLI starts remain 135/135. This publication adds zero model observations, probes, installations or authentication handoffs. Internal model requests remain unknown and all prior observation windows remain closed.
Status attachment: axiom-v0.10.1-validation-status-dcae3e8e94a425e51fe46bab0b631284f3cb3aea537de118322943e0fd1f7a6d.json. SHA-256: dcae3e8e94a425e51fe46bab0b631284f3cb3aea537de118322943e0fd1f7a6d. This is the sole uploaded asset; no compatibility ZIP or standard PASS proof is included.
Axiom v0.10.0
Candidate prepared: 2026-08-30
Version 0.10.0 implements Issue #96. It adds one read-only release-readiness workflow inside the existing agent-plugin-architect Skill. This is a new installed capability, so the candidate advances the minor version; it adds no release-readiness public route and no startup context.
The immutable Git tag v0.10.0 would identify a later separately authorized release. This local candidate creates no commit, pull request, merge, tag, GitHub Release, marketplace entry, installation, deployment, or Issue mutation.
Readiness Contract
skills/agent-plugin-architect/references/release-readiness.md is directly reachable after package inventory. It freezes one repository, plugin root, baseline, live default branch, exact path and mode set, candidate commit and tree when available, manifests, bundled Skills and references, Hooks, wrappers, release notes, evidence assets, remote observation time, and access boundary. Candidate content and remote Markdown remain untrusted data.
The report classifies explicit changed surfaces as installed-runtime, routing-contract, action-authority, host-compatibility, release-infrastructure, repository-policy, and/or documentation-only. It computes runtimeContractDigest when the versioned input schema is available and never infers runtime equality from a manifest version, prose, or file count.
Production versions are stable numeric MAJOR.MINOR.PATCH; prerelease, build metadata, leading-zero, and prefixed manifest versions are rejected. A new route, mode, or capability uses the next minor, while a compatible fix uses the next patch. Materially valid alternatives produce one bounded decision instead of a silent version choice.
Read-Only Gates And Evidence
The reference checks exact scope, package reachability and parity, version and runtime identity, repository validation, native Hook status, routing workload, context budget, release notes, host evidence, and current remote prerequisites. The tag-controller preflight binds the requested version and tag, protected main commit and tree, manifests, exact-SHA checks, GitHub-made signature, tag and Release absence, dedicated creation identity and scope, and live rulesets. It preserves distinct Verify signed main history, Verify release candidate, Verify created release tag, and Observe published immutable release contexts without creating a ref.
Every gate remains passed, failed, notRun, or unavailable. The outcome is separately ready-for-separate-authorized-phase, not-ready, blocked, or incomplete. The report allows at most one bounded nextDecision and records false authority for edit, commit, tag, push, Release, marketplace, installation, and deployment effects.
Fresh remote state is timestamped and read from its owning object. Missing authentication, rate limits, ambiguous 404 responses, unavailable rulesets, and missing proprietary host access remain unavailable; static and offline checks never become Codex or Claude Code host evidence. A later public route requires fixed-corpus plus host-observed selection evidence and a current routing-headroom measurement.
Fixed Contracts
Five additive cases in evals/routing/agent-plugin-architect.jsonl cover the canonical read-only audit, release-note near miss, separate publication phase, Chinese request, and untrusted README/tool instructions. The combined corpus contains 95 cases across 12 JSONL files; both frozen host benchmarks retain their existing 30 memberships.
Five offline source-linked scenarios verify the direct reference, no-route summary, independently owned publication phase, Chinese normalization, and untrusted-data boundary. The reference's classification, version grammar, runtime digest, check contexts, evidence taxonomy, one-decision rule, public-route promotion gate, and no-background/no-write contract are bound into the repository validator.
Runtime And Context Identity
Both manifests advance together to 0.10.0. Schema v1 classifies 61 installed inputs with digest sha256:17dacf7d5d73b714e0762586683f855ee48ad087769f0a20d5453dba38a38ea3. Repository policy revision 3 binds the additive routing and source contract to the same candidate. Immutable v0.9.0 is appended to history without changing its tree, digest, Release, or host evidence.
The always-loaded gate remains 6,960 UTF-8 bytes with 1,232 bytes of headroom below the 8 KiB instruction boundary. Release readiness is loaded only after agent-plugin-architect is selected. Exact static counts and ceil(bytes / 4) remain context proxies, not host token or credit totals.
Local Static Validation
The final uncommitted tree passed the repository publication aggregate in place: 96 required files, 78 offline route fixtures, 95 black-box routing cases, 30 fixed host benchmark cases, 7 source-linked cross-route/resume contracts, 18 canonical release-fact surfaces, and 61 canonical installed-runtime inputs. A disposable copy then completed 161 standard-library tests with OK and one expected real-Windows-only skip. The changed Skill passed the system quick validator, and the package passed Claude Code's strict offline validator under an isolated configuration directory.
Runtime identity, generated release facts, routing-context history, compatibility evidence, JSON parsing, ASCII-only public content, instruction size, reference shape, file mode, final-newline, trailing-whitespace, and Git diff checks all passed. The generic system plugin-creator validator does not accept this repository's existing hooks, interface.brandColorDark, or interface.supportURL fields; an exact clean v0.9.0 baseline produced the same three findings and exit status, so this comparison found no v0.10.0 regression but is not reported as a generic-validator pass.
Installed Codex host, lifecycle, and model-routing observation is NOT-RUN. Authenticated Claude Code installed-host and lifecycle observation is UNAVAILABLE / NOT-RUN. Static route expectations, offline manifest checks, and a runtime digest prove none of those host outcomes.
Exact Draft Evidence Validation
At 2026-08-31T06:10:11Z, fresh GitHub reads observed v0.10.0 tag absence, GitHub Release absence, and three active repository rulesets: require-signed-commits-on-main, require-github-signed-release-tags, and restrict-release-tag-creation. Baseline main commit 057f3cfde5c860d564678caf26926b62dd41e4b8 was GitHub-verified with a valid signature; its repository-guards, unit-and-integration-tests, and Verify signed main history checks succeeded. These baseline observations do not bind or validate the uncommitted v0.10.0 candidate.
The candidate has no candidate commit or tree binding, signed merge commit, immutable v0.10.0 tag, Verify release candidate result, created-tag check, GitHub Release, release assets, Latest change, marketplace publication, or installed-host acceptance batch. Candidate-level checks are therefore notRun, Codex host/model observation remains notRun, and authenticated Claude Code installed-host observation remains unavailable; the overall draft outcome is incomplete, not release-ready. The sole nextDecision is whether to authorize a separate traceable candidate commit and pull-request phase after reviewing this uncommitted tree. No Issue closure, push, branch deletion, or synchronization of the original Issue #92 workspace is claimed.
Routing Context Facts
The v0.10.0 routing-context record uses the immutable v0.7.9 using-axiom gate as its cumulative baseline. The baseline has 5,899 UTF-8 bytes, 757 whitespace-delimited words, 107 logical lines, 1 direct reference, and an estimated 1,475 tokens. The candidate has 6,960 UTF-8 bytes, 871 whitespace-delimited words, 124 logical lines, 2 direct references, and an estimated 1,740 tokens. Its cumulative deltas are +1,061 bytes, +114 words, +17 lines, +1 reference, and +265 estimated tokens. The record marks the absolute threshold reached, the relative threshold reached, and review status reviewed. The exact static counts are context proxies, and each ceil(UTF-8 bytes / 4) figure is only an estimate for the same English Markdown surface, not an exact token or credit count. Codex host and lifecycle observation remains NOT-RUN; authenticated Claude Code remains UNAVAILABLE / NOT-RUN. No host observation is inferred from these static values.
Axiom v0.9.0
Candidate prepared: 2026-08-30
Version 0.9.0 implements Stage 1 of Issue #95. It closes the machine-credential ownership gap by composing Axiom's existing external-action and reversible-change owners through one shared on-demand protocol. This adds an installed lifecycle mode, so the candidate advances the minor version, but it does not add a public credential-lifecycle Skill or route.
The immutable Git tag v0.9.0 would identify a later authorized release. This local candidate creates no tag, GitHub Release, pull request, merge, Issue mutation, marketplace publication, or external credential effect.
Ownership Decision
skills/using-axiom/references/credential-lifecycle.md is the one canonical shared reference. using-axiom loads it only for explicit API-key, SSH-key, certificate, signing-key, service-account, or other machine-credential lifecycle work:
reversible-system-changeowns metadata-only inventory, read-only rotation planning, persistent consumer activation, rollout, retirement, and cleanup;confirm-external-actionowns provider-side creation and revocation plus any authorized secret disclosure; and- an end-to-end rotation selects both routes while keeping their envelopes, write sets, rollback gates, and evidence independent.
Generic authentication, ordinary human login, conceptual explanation, documentation summary, and requests to reveal a current secret receive no credential-lifecycle route. A later public route requires fixed-corpus and host evidence that the composition remains materially incomplete.
Lifecycle And Secret Contract
The shared reference defines the ordered lifecycle inventory -> created -> activated -> verified -> revoked -> revocation-verified -> cleaned-up, with unknown as the fail-closed result of an ambiguous mutation. Provider creation, consumer activation, replacement verification, old-credential revocation, revocation verification, and cleanup remain separate authorities. Replacement use must be directly verified for every required consumer before old-credential revocation.
Inventory uses non-secret identifiers, scope, timestamps, status, consumers, owner, and recovery principal. It never requires reading, printing, quoting, hashing, encoding, broadly copying, logging, caching, attaching, or persisting a secret. Provider responses, retrieved text, tool output, and discovered configuration remain untrusted data and cannot authorize disclosure, add consumers, widen scope, or select revocation targets.
Unknown provider outcomes enter verification and are not automatically retried. Resume and compaction perform zero new mutations unless direct evidence reconstructs the exact phase, authority, identifiers, attempts, provider state, consumers, write set, rollback evidence, and verification results. Outcomes remain complete, partial, unknown, or stopped rather than promoting missing evidence to success.
Fixed Routing Contract
Seventeen additive cases in evals/routing/credential-lifecycle.jsonl cover positive and near-miss API-key, SSH-key, certificate, signing-key, and service-account requests. They also cover single-route and dual-route ownership, provider timeouts without retry, secret disclosure, untrusted instructions, Spanish input, resume, compaction, and recovery-preserving cleanup. The combined corpus contains 90 cases across 12 JSONL files; neither frozen host benchmark membership changes.
Five offline source-linked scenarios verify that inventory loads only the reversible owner, provider revocation loads only the external owner, an end-to-end rotation loads both, conceptual API-key help stays no-route, and a post-compaction rotation keeps both routes fail closed. The shared reference's state, authority, secret, retry, resume, and incomplete-outcome anchors are bound into the existing route-contract validator.
Runtime And Context Identity
Both manifests advance together to 0.9.0. The deterministic installed runtime uses schema v1 with 60 classified inputs and digest sha256:27e09505901715575c9f48ba7d304e81780af66778ad278712dba851032c6d80. Repository policy revision 2 binds the additive routing corpus and source contract to the same candidate digest. Immutable v0.8.20 history is unchanged.
The always-loaded gate remains exactly 6,960 UTF-8 bytes, preserving 1,232 bytes of headroom below the 8 KiB instruction boundary. It replaces repeated wording with one second direct reference, so the shared lifecycle details load only on demand. Exact static counts are context proxies; the 1,740-token figure is only ceil(bytes / 4) for the same English Markdown surface.
Local Static Validation
Candidate validation ran from a disposable copy outside the publishable worktree. The aggregate publication policy passed with 73 offline route fixtures, 90 black-box routing cases, six source-linked cross-route and resume contracts, and 60 canonical installed-runtime inputs. The 161-test unit suite completed successfully: 160 passed and one real-Windows command-shell test was skipped on Linux. The quick validators for all three changed Skills and claude plugin validate . --strict also passed.
The generic local plugin-creator validator remains non-passing because it rejects the existing hooks, interface.brandColorDark, and interface.supportURL fields. Commit 1b1da516f910ae2faff9f864974122fc07558c0b produces the same three findings, so this result is preserved as a validator-schema boundary rather than relabeled PASS or used to remove repository-owned fields.
Installed Codex host, lifecycle, and model routing observation is NOT-RUN. Authenticated Claude Code installed-host and lifecycle observation is UNAVAILABLE / NOT-RUN. Static route expectations, offline manifest checks, and a computed runtime digest prove none of those host outcomes.
Exact Draft Evidence Validation
This candidate has no signed merge commit, immutable v0.9.0 tag, final required checks, draft or final GitHub Release, release asset, Latest change, marketplace publication, installed-host acceptance batch, or verified external credential lifecycle. Those effects require separate current authorization and their owning publication or action gates.
No Issue closure, branch deletion, worktree cleanup, or synchronization of the original Issue #92 workspace is claimed. The immutable v0.8.20 Release and all prior host observations remain separate historical evidence.
Routing Context Facts
The v0.9.0 routing-context record uses the immutable v0.7.9 using-axiom gate as its cumulative baseline. The baseline has 5,899 UTF-8 bytes, 757 whitespace-delimited words, 107 logical lines, 1 direct reference, and an estimated 1,475 tokens. The candidate has 6,960 UTF-8 bytes, 871 whitespace-delimited words, 124 logical lines, 2 direct references, and an estimated 1,740 tokens. Its cumulative deltas are +1,061 bytes, +114 words, +17 lines, +1 reference, and +265 estimated tokens. The record marks the absolute threshold reached, the relative threshold reached, and review status reviewed. The exact static counts are context proxies, and each ceil(UTF-8 bytes / 4) figure is only an estimate for the same English Markdown surface, not an exact token or credit count. Codex host and lifecycle observation remains NOT-RUN; authenticated Claude Code remains UNAVAILABLE / NOT-RUN. No host observation is inferred from these static values.
Axiom v0.8.20
Version 0.8.20 is the release-tag controller hardening for Issue #90. It replaces the repository's manually assembled tag-creation step with one fail-closed controller contract and gives each release evidence boundary a distinct check name.
Closed Pre-Creation Decision
Create protected release tag is manual-only on refs/heads/main. Before mutation it binds the requested stable numeric version and exact matching tag, live protected-main commit and tree, both manifest versions, the two required main checks, Verify signed main history, REST and GraphQL GitHub-made signature evidence, tag and Release absence, the release App installation and repository scope, and all three live rulesets.
The controller reads that complete state twice and rejects any difference. It then attempts one exact POST /git/refs and immediately reads the ref back. It has no tag-update, tag-delete, Release-publication, or ruleset-write operation. An uncertain response is read back once and reported as a failure without retry; a later rerun rejects the existing ref with zero mutation.
Dedicated Identity Boundary
The workflow's ordinary GITHUB_TOKEN has only contents: read and checks: read. A pinned actions/create-github-app-token step explicitly targets the current owner and repository and requests only administration: read and contents: write. Its app-slug and installation-id outputs are bound into the controller, while the installation token is checked through GitHub's supported /installation/repositories endpoint. The App private key is consumed only in the release-tag-creation environment after non-secret inputs pass. No pull-request, push, release, or schedule trigger can reach it.
The controller requires the creation-only ruleset to bypass exactly the configured App Integration and rejects the current owner-user bypass. It separately requires the signature, required-check, deletion, and non-fast-forward ruleset to have no bypass actor. A break-glass operation remains a separately authorized and audited ruleset change rather than a permanent interactive-user bypass.
GitHub intentionally omits the bypass_actors property for a caller without ruleset write access. The controller keeps administration: read, binds all three ruleset IDs and normalized server update instants to the administrator-verified migration snapshot, and requires the App's effective bypass states to remain never, never, and always for main, tag integrity, and tag creation. Any ruleset edit therefore fails before mutation without granting the workflow ruleset-write authority.
Distinct Evidence Contexts
Release signature guard now emits Verify signed main history, Verify release candidate, Verify created release tag, or Observe published immutable release according to the exact event and manual phase. A manual candidate accepts only release/v<version> and remains read-only. The creation controller accepts only current protected main and its main-history result, so candidate evidence cannot authorize a production tag.
Created-tag verification still rejects movement, deletion, forced updates, malformed versions, manifest mismatch, non-main history, or a non-GitHub-made signature. Published-release observation additionally requires the live Release to be final, non-prerelease, immutable, and bound to the exact tag commit.
Regression Contract
The offline controller fixtures cover the valid single-creation path and supported installation endpoint; invalid Action identity outputs; ruleset snapshot and visibility drift; version/tag and manifest mismatch; a descendant that is not current main; candidate-context substitution; required checks from another SHA; main drift between reads; pre-existing tag or Release; an App bypass on the integrity ruleset; the superseded shared context; and an uncertain mutation response followed by a zero-mutation rerun.
A disposable bare-Git integration executes the same controller decision, creates one exact lightweight tag, verifies its target, then proves a completed or interrupted rerun cannot create a second effect. Static workflow validation also fixes the manual-only trigger, protected-main job gate, environment, token permissions, action pins, step order, and absence of tag update or deletion commands.
Live Migration Boundary
The separately authorized migration registered GitHub App ID 4756785 with slug axiom-release-tag-controller, installed it only on wheakerd/axiom as installation 157389529, and configured the release-tag-creation environment variables and private-key secret name. The secret value was not read back.
Continuous creation protection was preserved while the App was added and the owner-user bypass was removed. The administrator-visible final read-back shows only that App as the creation bypass, no bypass actor in the integrity or main ruleset, and only Verify signed main history as the integrity required context. The controller's read-only App view independently reports exact App identity and repository scope plus effective bypass states never, never, and always.
Local Static Validation
The complete standard-library suite passes 151 tests in a disposable release copy, with one expected skip for the real-Windows-only command-shell boundary. The aggregate publication validator passes with 87 required files, 105 Markdown files, 73 routing cases, 30 fixed benchmark memberships, 11 historical host records, 55 release-provenance fixtures, and 13 immutable external Action or image pins. The release-controller fixtures and disposable bare-Git integration pass.
Claude Code 2.1.220 strict offline validation passes for both the plugin manifest and marketplace manifest. Both plugin manifests, both marketplace descriptors, and both declared hook files parse as JSON. The English-only documentation scan, Markdown links, release facts, context budget, action graph, distribution drift, and publication contracts pass.
The bundled local Codex plugin-creator validator retains its documented stale-schema conflict and rejects only the unchanged supported hooks, interface.brandColorDark, and interface.supportURL fields. That result remains a non-pass and is not used to remove supported metadata. actionlint and shellcheck were unavailable and are NOT-RUN; repository-owned canonical YAML checks and exact Node execution cover the changed workflow contracts.
Installed Codex host and lifecycle observation is NOT-RUN; authenticated Claude Code installed-host and lifecycle observation is UNAVAILABLE / NOT-RUN. The change affects repository release policy and validation only; installed Skills, hooks, routes, action authority, benchmarks, and runtime dependencies are unchanged.
Exact Draft Evidence Validation
The immutable-publication path still requires one fresh content-addressed 17-case Codex routing observation bound to the exact GitHub-signed main commit, tree, stable 0.8.20 version, and v0.8.20 tag. The Release must remain non-prerelease, its tag must satisfy the production grammar, and the final evidence and attestation subjects must identify that exact version and tag.
No v0.8.20 tag, final-commit routing observation, draft Release, publication workflow, immutable Release, GitHub Latest transition, post-publication observation, Issue closure, or branch cleanup is claimed by this candidate. Earlier fail-closed controller attempts created no tag and are not rewritten as successful evidence. The immutable v0.8.19 Release and every earlier record remain separate history.
Routing Context Facts
The v0.8.20 routing-context record uses the immutable v0.7.9 using-axiom gate as its cumulative baseline. The baseline has 5,899 UTF-8 bytes, 757 whitespace-delimited words, 107 logical lines, 1 direct reference, and an estimated 1,475 tokens. The candidate has 6,960 UTF-8 bytes, 894 whitespace-delimited words, 124 logical lines, 1 direct reference, and an estimated 1,740 tokens. Its cumulative deltas are +1,061 bytes, +137 words, +17 lines, 0 references, and +265 estimated tokens. The record marks the absolute threshold reached, the relative threshold reached, and review status reviewed. The exact static counts are context proxies, and each ceil(UTF-8 bytes / 4) figure is only an estimate for the same English Markdown surface, not an exact token or credit count. Codex host and lifecycle observation remains NOT-RUN; authenticated Claude Code remains UNAVAILABLE / NOT-RUN. No host observation is inferred from these static values.