Skip to content

Releases: zrk222/code-factory

Code Factory v0.20.0 - Governed Missions and BYOK Routing

Choose a tag to compare

@zrk222 zrk222 released this 20 Jul 05:28
8831019

Code Factory v0.20.0 — Governed Missions and BYOK Routing

Code Factory v0.20.0 turns Product Missions into a durable, inspectable state
machine and adds a secret-free control plane for choosing providers and models
across CLI, Studio, VS Code, and JetBrains.

Highlights

  • Transactional SQLite mission ledger with canonical, hash-linked events and
    idempotent transitions.
  • Independent creator/validator identities, exact milestone coverage, bounded
    retries, and hard token/cost/time/iteration exhaustion.
  • Human pause, plan revision, and fresh-context resume as first-class receipts.
  • Optional LangGraph adapter with local SQLite checkpoints while Code Factory
    remains the evidence authority.
  • BYOK provider policies containing only environment-variable references,
    provider/model allowlists, IDE selection, quality floors, price metadata,
    routing bias, and cache rails.
  • JetBrains 0.5.0 Mission Operations with workspace-contained paths and output
    redaction.
  • Governed instruction-learning packets with distinct worker, validator, and
    human promotion identities.

Verified release evidence

  • Python regression suite: 262 passed, 2 skipped.
  • JetBrains test, plugin build, and Marketplace metadata preflight: passed.
  • SpecLine requirement mutations: 34 of 34 killed.
  • ForgeLine implementation mutants: 2 of 2 killed.
  • ForgeLine QA: A, composite 96.5, security 100, maximum complexity 10.

These measurements describe the tested repository state. Provider routing is a
recommendation and policy-verification boundary; an external runtime remains
responsible for credential injection, provider calls, and spend authorization.

Code Factory v0.19.0 — Supervised Hosted Tenant Control

Choose a tag to compare

@zrk222 zrk222 released this 20 Jul 01:04
90dab71

Code Factory 0.19.0 adds a supervised hosted tenant lifecycle on top of authenticated pull-request assurance.

Highlights:

  • Bootstrap-only tenant creation with per-tenant OIDC/JWKS configuration
  • Atomic directory-group role mapping and runtime-only env secret references
  • 600-second one-time GitHub installation state and immutable installation binding
  • Forced PostgreSQL RLS and serialized hash-linked administrative audit
  • Redacted responsive operator console with in-memory-only Bearer use
  • PostgreSQL 17 integration proof, 244 local tests, multi-OS Python CI, and full JetBrains compatibility matrix

Evidence boundary: this is a deployable supervised reference, not a claim of SCIM/SAML enrollment, managed HA/DR, external KMS, SOC 2, or an SLA. See CHANGELOG.md and docs/HOSTED_CONTROL_PLANE.md for the complete contract.

Code Factory v0.18.0 — hosted enterprise PR assurance

Choose a tag to compare

@zrk222 zrk222 released this 19 Jul 14:31
b9df5fb

Code Factory 0.18.0 adds authenticated pull-request assurance and an optional self-hosted PostgreSQL/GitHub adapter.

Highlights:

  • GitHub HMAC webhook verification and durable replay rejection
  • Immutable installation-to-tenant routing with PostgreSQL forced RLS
  • Offline RS256 OIDC approval verification with replay protection
  • Transactional approval + GitHub Check outbox and short-lived App credentials
  • Freshness-bounded HTTPS JWKS rotation, health/readiness routes, and secret-free events
  • VS Code and JetBrains packages updated to 0.4.0

The hosted component is a deployable reference, not a managed HA, SCIM, SOC 2, or SLA claim. See CHANGELOG.md and docs/HOSTED_PR_ASSURANCE.md for the complete contract and evidence boundary.

Code Factory v0.17.3 — auditability hardening

Choose a tag to compare

@zrk222 zrk222 released this 18 Jul 12:02
f5bcf92

Auditability hardening

  • Adds the offline factory verify-receipts mutation gate with canonical evidence.
  • Rejects payload, signature, identity, and back-dated revocation mutations with exact error codes.
  • Adds Hypothesis canonicalization properties and 100% public Python API docstring enforcement.
  • Adds hostile Studio decision and migration evidence tests.
  • Updates Gradle Actions to official v6.2.0 and corrects the Marketplace release default.

Verified release evidence

  • 215 local tests passed, including Hypothesis.
  • All 12 pull-request checks passed across Ubuntu, macOS, Windows, Python 3.10-3.12, package contract, offline foundation, and five-brick proof.
  • Post-merge CI, enterprise receipts, and signed receipts passed at f5bcf92.
  • Wheel and sdist built and passed twine check; clean wheel rejected all 4/4 receipt mutations.

Install: pip install factoryline-code-factory==0.17.3

JetBrains Marketplace publication remains fail-closed until the separately scoped JETBRAINS_MARKETPLACE_TOKEN is configured; the GitHub release still packages the verified plugin artifact.

Code Factory v0.17.2 — visual proof line

Choose a tag to compare

@zrk222 zrk222 released this 18 Jul 09:29
c8e8b27

Code Factory 0.17.2 — visual proof line

This patch release adds a truthful, accessible nine-stage concept gallery for the Code Factory workflow while preserving the existing exact-UI walkthrough as the product evidence anchor.

Added

  • Nine owner-supplied concept illustrations: idea intake through verified release.
  • SHA-256, dimensions, order, alt text, captions, and provenance in one packaged manifest.
  • A complete visual walkthrough for GitHub, PyPI source copy, Product Hunt preparation, and Zenodo archives.
  • A three-panel storefront preview and a copy-ready Product Hunt upload order.
  • All nine illustrations as versioned GitHub release assets.

Evidence boundary

The new artwork is labeled Concept illustrations. It is not presented as shipped UI or measured outcome evidence. The exact Factory Studio video remains separately labeled Exact shipped UI.

The supplied infographic with unsupported outcome numbers was intentionally excluded from public surfaces.

Verification

  • 194 tests passed locally.
  • CI passed across Python 3.10–3.12 on Linux, macOS, and Windows.
  • Wheel and source distribution passed twine check.
  • The source archive contains all nine PNGs, both gallery documents, and the SHA-256 manifest.
  • Strict Code Factory doctor, HSF topology, Forge smoke/challenge, and publication-contract checks passed.

Full visual walkthrough: https://github.com/zrk222/code-factory/blob/main/docs/HOW_IT_WORKS_VISUAL.md

Code Factory v0.17.1 - Trusted Publishing Proof

Choose a tag to compare

@zrk222 zrk222 released this 17 Jul 19:43
090d3ad

Code Factory v0.17.1

Supply-chain hardening release proving the package delivery path introduced in PR #4.

  • PyPI Trusted Publishing via GitHub OIDC; no stored PyPI token
  • protected pypi deployment environment
  • validation and privileged publishing split into separate jobs
  • immutable artifact handoff from validation to deployment
  • PyPI provenance attestations enabled
  • PR package contract builds, checks, clean-installs, and exercises the wheel
  • 60-second exact-UI quick start and matching cover attached as release assets

Watch or download the 60-second quick start

Validation before release: 190 tests passed; wheel and sdist passed Twine checks.

Code Factory v0.17.0 - Composable Product Engineering

Choose a tag to compare

@zrk222 zrk222 released this 17 Jul 15:49
f66a66d

Code Factory 0.17 expands the project from release verification into governed product engineering.

Highlights:

  • Compile PRDs into stable Product Graphs and vertical value slices.
  • Run bounded no-finish Missions with independent creator/verifier roles and evidence-bound completion.
  • Compose 29 signed, mutation-tested capability packs into seven runnable target classes: CLI, API, MCP, worker, web, mobile, and agent UI.
  • Use deterministic target adapters, actionable failure guidance, AutoWiki/Lore context, and live Meter v2 telemetry.
  • Operate from the CLI, Factory Studio, VS Code, or eight verified JetBrains IDE families.
  • Review evidence-linked PR drafts; Code Factory never auto-merges or grants itself release authority.

Release proof:

  • 188 Python tests passed locally.
  • Cross-platform Python 3.10-3.12 CI passed on Ubuntu, Windows, and macOS.
  • ProofLab, offline foundation, VS Code packaging, and IntelliJ/PyCharm/WebStorm/Rider/CLion/GoLand/RustRover/DataGrip compatibility passed.
  • Wheel and sdist passed twine check and clean-wheel strict doctor verification.

Code Factory v0.16.0

Choose a tag to compare

@zrk222 zrk222 released this 17 Jul 12:15
c8e6ad6

Code Factory v0.16.0

Code Factory now turns product intent and operational signals into bounded, approval-ready Product Missions with independent deterministic verification.

What shipped

  • Product Graph and Product Mission compiler with explicit journeys, risks, budgets, worktrees, and completion contracts.
  • No-finish enforcement: completion requires independent evidence for every declared criterion.
  • Signal Loop and compact Opinion Dock for supervised signal-to-mission triage.
  • Factory Studio live control room with actionable failure guidance, approval/defer/reject controls, and local telemetry.
  • Signed, mutation-tested capability packs for workers, web apps, Expo mobile apps, and agentic UIs.
  • AutoWiki and Lore repository context, migration-readiness assessment, and creator/verifier context isolation.
  • VS Code and JetBrains control rooms covering IntelliJ IDEA, PyCharm, WebStorm, Rider, CLion, GoLand, RustRover, and DataGrip.
  • Canonical provenance and corrected PyPI identity: Richard Katz, canonical GitHub homepage, source, issues, and changelog links.

Release proof

  • 180 local Python tests passed.
  • GitHub CI passed Python 3.10-3.12 on Ubuntu, Windows, and macOS.
  • All eight declared JetBrains IDE compatibility lanes passed.
  • Four signed capability packs verified; 20 of 20 validator mutations were rejected.
  • Wheel and source distribution passed twine check; clean-wheel provenance and pack verification passed outside the checkout.

Visuals

The attached 60-second narrated quick-start video shows the exact Factory Studio UI and mission flow. Updated color architecture diagrams cover the system topology, editor control room, PRD-to-app path, Product Missions, and Signal Loop.

Code Factory remains proof-oriented: verified local artifacts do not grant merge, deploy, publish, credential, connector, or external-message authority.

Code Factory v0.14.0

Choose a tag to compare

@zrk222 zrk222 released this 17 Jul 00:06

Target compiler and local Studio

  • Compile one prompt or UTF-8 PRD into a blocked worker, web, Expo mobile, or supervised agent-UI starter.
  • Bind source, manifest, and generated files into a SHA-256 receipt with SSAT, smoke, coverage, ForgeLine state, and Mermaid evidence.
  • Open the loopback-only Factory Studio from the CLI, VS Code 0.2.0, or JetBrains 0.2.0 after explicit workspace confirmation.
  • Refuse non-empty outputs and withhold deploy, publish, signing, connector, credential, and external-message authority.
  • Refresh Next.js, React, Expo, TypeScript, and dependency overrides using clean install/build checks.

Evidence: 139 Python tests; ForgeLine Grade A with all 3 hollow-test mutants killed; VS Code tests/package; JetBrains tests and Marketplace preflight; Twine checks; clean installed-wheel generation of all four targets.

Boundary: the compiler and Studio make zero model calls. Generated applications are blocked starters, not production-ready products, and may add models only through product-specific implementation and review.

Code Factory 0.13.6

Choose a tag to compare

@zrk222 zrk222 released this 16 Jul 06:14

Complete source provenance for installed wheels and synchronized compatible package pins.