diff --git a/.engineering/evidence/task/prepare-release-0-19-2/20261003T155832Z-000-865eeab321fb.json b/.engineering/evidence/task/prepare-release-0-19-2/20261003T155832Z-000-865eeab321fb.json new file mode 100644 index 0000000..009b7fa --- /dev/null +++ b/.engineering/evidence/task/prepare-release-0-19-2/20261003T155832Z-000-865eeab321fb.json @@ -0,0 +1,12 @@ +{ + "at": "2026-10-03T15:58:32Z", + "actor": "human:timo", + "artifact": "task:prepare-release-0-19-2", + "kind": "task", + "revision": 3, + "change": { + "change": "evidence", + "kind": "test_result", + "source": "Rust 1.99 task check passed: 145 tests, plugin version alignment and offline eval gate" + } +} diff --git a/.engineering/planning/task/prepare-release-0-19-2.md b/.engineering/planning/task/prepare-release-0-19-2.md new file mode 100644 index 0000000..48edef4 --- /dev/null +++ b/.engineering/planning/task/prepare-release-0-19-2.md @@ -0,0 +1,25 @@ +--- +format: aep.planning-md/3 +id: task:prepare-release-0-19-2 +kind: task +status: implemented +title: Prepare Agentplugins 0.19.2 and bot-owned publication +relations: +- delivers: task:cleanup-request-authorization +revision: 4 +transitions: +- {from: "draft", to: "proposed", at: "2026-10-03T15:57:29Z", actor: "human:timo", revision: 2} +- {from: "proposed", to: "active", at: "2026-10-03T15:57:29Z", actor: "human:timo", revision: 3} +- {from: "active", to: "implemented", at: "2026-10-03T15:58:32Z", actor: "human:timo", revision: 4, decided_on: {"recorded":{"test_result":1}}} +--- +## Context + +The operator requested a release carrying the completed cleanup authorization fix. Release versions must agree, the tag must name remote main, and publication must use the organization bot. The existing workflow publishes through the default Actions token, while this repository has no bot App credentials in Actions. + +## Acceptance + +The 0.19.2 candidate has aligned workspace, lockfile, plugin and skill versions, a dated changelog, passing gates, and a read-only workflow that prepares all release assets for bot-authenticated publication. + +## Delivery + +Merge the candidate through a green PR; tag exact remote main through the bot; verify the release workflow; download and verify its four archives, checksums and setup guide; create and publish the GitHub Release through the bot; verify the published assets and retire the managed worktree. Documentation delivery remains asynchronous. diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index e452b1d..bfe6c6f 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -86,11 +86,11 @@ jobs: if-no-files-found: error publish: - name: Publish GitHub release + name: Prepare release publication needs: [gate, package] runs-on: ubuntu-latest permissions: - contents: write + contents: read steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: @@ -111,12 +111,10 @@ jobs: sha256sum b10x-*.tar.gz > SHA256SUMS sha256sum --check SHA256SUMS cat SHA256SUMS - - name: Publish the annotated tag as a release with its assets - env: - GH_TOKEN: ${{ github.token }} + - name: Extract release notes from the annotated tag run: | set -euo pipefail - notes_file="${RUNNER_TEMP}/release-notes.md" + notes_file="dist/release-notes.md" # The version's CHANGELOG.md section, without its heading; the tag message if it has none. awk -v heading="## [${GITHUB_REF_NAME}]" ' index($0, heading) == 1 { found = 1; next } @@ -126,10 +124,9 @@ jobs: if ! grep -q '[^[:space:]]' "$notes_file"; then git for-each-ref --format='%(contents)' "refs/tags/${GITHUB_REF_NAME}" > "$notes_file" fi - if gh release view "${GITHUB_REF_NAME}" >/dev/null 2>&1; then - gh release edit "${GITHUB_REF_NAME}" --verify-tag --title "Agent Plugins ${GITHUB_REF_NAME}" --notes-file "$notes_file" - else - gh release create "${GITHUB_REF_NAME}" --verify-tag --draft --title "Agent Plugins ${GITHUB_REF_NAME}" --notes-file "$notes_file" - fi - gh release upload "${GITHUB_REF_NAME}" dist/* --clobber - gh release edit "${GITHUB_REF_NAME}" --draft=false + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: release-publication + path: dist/* + if-no-files-found: error + retention-days: 30 diff --git a/AGENTS.md b/AGENTS.md index fc66b9e..9a32b42 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -57,8 +57,12 @@ Commit and push through `b10x-gates bot --repo . -- ` as `b10x-bot[ No credential or token machinery lives in this repository. A release is a bare annotated tag on `main` after `CHANGELOG.md`, the workspace version, every carried plugin manifest and every `**Skill version**` line agree; the -release workflow reruns the gate and publishes the `b10x` archives, `SHA256SUMS` and `SETUP.md`, -with the version's `CHANGELOG.md` section as the release notes. +release workflow reruns the gate and retains the four `b10x` archives, `SHA256SUMS`, `SETUP.md` +and the version's changelog notes in its `release-publication` artifact. Download that exact tag +run's artifact, verify the checksums and archive contents, then publish the release and those six +assets through `b10x-gates api` and `b10x-gates gh` as the organization bot. The workflow has +read-only permissions and does not publish through the default Actions identity. Verify the +published release's author, tag and assets before reporting completion. Source publication needs no Atlas checkout. diff --git a/CHANGELOG.md b/CHANGELOG.md index 431e6e0..e9bd25b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,18 @@ # Changelog +## [0.19.2] — 2026-10-03 + +- An explicit Worktree cleanup request authorizes exact eligible removals without a second + approval prompt. Inspection-only requests remain read-only; recovery and lease checks remain. +- Restore the Rust 1.99 gate without weakening test assertions, and remove obsolete AEP command + inventory entries. +- Verify the skills against AEP 0.68.0, ESS 0.52.0 and Worktree 0.8.2. Two isolated ESS + full-package trials produced all nine outputs and passed 24 and 15 scenarios without failures + or skips; the recorded trial evidence states the limits of those observations. +- Clarify Rust and Go implementation synthesis and Go conformance package placement. +- The release workflow prepares checksummed artifacts with read-only permissions; publication + uses the organization bot rather than the default Actions identity. + ## [0.19.1] — 2026-09-29 The ess skills now say where implementation code comes from: the specification, through diff --git a/Cargo.lock b/Cargo.lock index df6c904..9fa3efb 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -4,7 +4,7 @@ version = 4 [[package]] name = "agentplugins-check" -version = "0.19.1" +version = "0.19.2" dependencies = [ "clap", "serde", @@ -76,7 +76,7 @@ dependencies = [ [[package]] name = "b10x" -version = "0.19.1" +version = "0.19.2" dependencies = [ "clap", "serde", diff --git a/Cargo.toml b/Cargo.toml index 8b99e32..98ad7fe 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -3,7 +3,7 @@ resolver = "2" members = ["crates/agentplugins-check", "crates/b10x"] [workspace.package] -version = "0.19.1" +version = "0.19.2" edition = "2021" rust-version = "1.85" license = "Apache-2.0" diff --git a/plugins/aep/.claude-plugin/plugin.json b/plugins/aep/.claude-plugin/plugin.json index 44fe649..1dfe9a4 100644 --- a/plugins/aep/.claude-plugin/plugin.json +++ b/plugins/aep/.claude-plugin/plugin.json @@ -2,7 +2,7 @@ "name": "aep", "displayName": "AEP", "description": "Plan governed work in the AEP artifact store and deliver it in reviewed waves: decomposition, plan critique, reverse engineering, story scoping, implementation and adversarial review.", - "version": "0.19.1", + "version": "0.19.2", "author": { "name": "Beyond10x" }, diff --git a/plugins/aep/.codex-plugin/plugin.json b/plugins/aep/.codex-plugin/plugin.json index 1fa977b..1f0c3a2 100644 --- a/plugins/aep/.codex-plugin/plugin.json +++ b/plugins/aep/.codex-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "aep", - "version": "0.19.1", + "version": "0.19.2", "description": "Plan governed work in the AEP artifact store and deliver it in reviewed waves.", "author": { "name": "Beyond10x" diff --git a/plugins/aep/skills/diagnosing/SKILL.md b/plugins/aep/skills/diagnosing/SKILL.md index 3877205..df5e376 100644 --- a/plugins/aep/skills/diagnosing/SKILL.md +++ b/plugins/aep/skills/diagnosing/SKILL.md @@ -3,7 +3,7 @@ name: diagnosing description: Diagnose a hard bug or a performance regression by building a red-capable feedback loop before any hypothesis, then ranked falsifiable hypotheses, one-variable probes, a regression test at the right seam, and evidence recorded in the AEP store. Use when the user says diagnose, debug, "why is this failing", "this is slow", or reports something broken, throwing, flaky or slower than before. Not for a production incident that cannot be re-run, which is `aep:investigating`; not for a failing CI job whose cause is already named in its log; and not for raising conformance coverage, which is `ess:testing-conformance`. --- -**Skill version 0.19.1** — the version in `.claude-plugin/plugin.json`. +**Skill version 0.19.2** — the version in `.claude-plugin/plugin.json`. # Diagnosing a failure diff --git a/plugins/aep/skills/implementing/SKILL.md b/plugins/aep/skills/implementing/SKILL.md index b880045..ab9b9e3 100644 --- a/plugins/aep/skills/implementing/SKILL.md +++ b/plugins/aep/skills/implementing/SKILL.md @@ -3,7 +3,7 @@ name: implementing description: Implement accepted AEP work, in one of two modes. A wave picks the stories that can be implemented at once, proposes the wave for approval, dispatches one implementor per story into its own worktree, sends each result to the adversary and merges what goes green. A drive hands one story to a governed `metaharness aep drive` run and reports the run id. Use when the operator asks to implement, build or deliver planned stories, to pick or start the next wave, to implement several stories in parallel or fan out across sub-agents, to drive a story or start a governed run, or asks why a wave's rules are instructions and a drive's are enforced. A wave proposes first and stops; a drive starts one run and reports; neither moves an artifact itself. --- -**Skill version 0.19.1** — the version in `.claude-plugin/plugin.json`; a wave's stage-1 proposal quotes it. +**Skill version 0.19.2** — the version in `.claude-plugin/plugin.json`; a wave's stage-1 proposal quotes it. # Implementing accepted work diff --git a/plugins/aep/skills/investigating/SKILL.md b/plugins/aep/skills/investigating/SKILL.md index 84e13eb..21d7c7d 100644 --- a/plugins/aep/skills/investigating/SKILL.md +++ b/plugins/aep/skills/investigating/SKILL.md @@ -4,7 +4,7 @@ description: >- Investigate a production incident, an outage or a question about a running system from evidence that can be cited — capture state before anyone remediates, build a sourced UTC timeline, date an onset from an instrument that can see a negative, compare against a healthy peer, and label every claim verified or inferred, with a catalogue of ten techniques. Use when the user says investigate, "what happened", "when did this start", "is it still happening", "has this shipped", "is this deployed", reports an alert, an outage, a hung or crashing process or a customer-visible failure, or asks for an incident report or a postmortem. Not for a defect that can be reproduced on demand, which is `aep:diagnosing`; not for checking a change before it merges, which is `aep:implementing`. --- -**Skill version 0.19.1** — the version in `.claude-plugin/plugin.json`. +**Skill version 0.19.2** — the version in `.claude-plugin/plugin.json`. # Investigating a live system diff --git a/plugins/aep/skills/migrating/SKILL.md b/plugins/aep/skills/migrating/SKILL.md index 8e91097..b70a624 100644 --- a/plugins/aep/skills/migrating/SKILL.md +++ b/plugins/aep/skills/migrating/SKILL.md @@ -3,7 +3,7 @@ name: migrating description: Migrate a repository's legacy work tracking — story trees, TODO.md, plan and issue documents — into the governed AEP planning store, without deleting or rewriting the sources. Use when the user asks to migrate, import, port or convert an existing backlog into AEP, when a repository is adopting AEP and already has work written down somewhere, or when a store has been adopted beside a legacy backlog nobody retired. Read it before creating the first artifact in a repository that already tracks work in markdown. --- -**Skill version 0.19.1** — the version in `.claude-plugin/plugin.json`. +**Skill version 0.19.2** — the version in `.claude-plugin/plugin.json`. # Migrating legacy tracking into the store diff --git a/plugins/aep/skills/planning/SKILL.md b/plugins/aep/skills/planning/SKILL.md index 5cea8e5..341771d 100644 --- a/plugins/aep/skills/planning/SKILL.md +++ b/plugins/aep/skills/planning/SKILL.md @@ -3,7 +3,7 @@ name: planning description: Plan engineering work in a governed markdown artifact store — create, relate, move and validate epics, stories, tasks and initiatives through the `aep` CLI. Use when the user mentions planning, a backlog, an epic, a story, a task, decomposing or breaking down work, an artifact's status ("move this to active", "what is still in draft?", "why can't this be implemented?"), or when the project contains a `.engineering/planning/` directory. Use it at adoption too — the user asks to adopt AEP, to migrate from or replace the track plugin, to start a first backlog, or works in a repository with no `.engineering/` directory at all — because § 5 says how a first store is populated and it is worth nothing after one has been hand-written. Also use before editing any file under `.engineering/planning/`. --- -**Skill version 0.19.1** — the version in `.claude-plugin/plugin.json`. +**Skill version 0.19.2** — the version in `.claude-plugin/plugin.json`. # Planning in a governed artifact store diff --git a/plugins/b10x/.claude-plugin/plugin.json b/plugins/b10x/.claude-plugin/plugin.json index a9a7027..05ec27f 100644 --- a/plugins/b10x/.claude-plugin/plugin.json +++ b/plugins/b10x/.claude-plugin/plugin.json @@ -2,7 +2,7 @@ "name": "b10x", "displayName": "Beyond10x", "description": "Set up, upgrade and check the Beyond10x plugins and binaries, route work to them, and create portable plugins.", - "version": "0.19.1", + "version": "0.19.2", "author": { "name": "Beyond10x" }, diff --git a/plugins/b10x/.codex-plugin/plugin.json b/plugins/b10x/.codex-plugin/plugin.json index 0ef2df8..0749af0 100644 --- a/plugins/b10x/.codex-plugin/plugin.json +++ b/plugins/b10x/.codex-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "b10x", - "version": "0.19.1", + "version": "0.19.2", "description": "Set up, upgrade and check the Beyond10x plugins and binaries, route work to them, and create portable plugins.", "author": { "name": "Beyond10x" diff --git a/plugins/connectors/.claude-plugin/plugin.json b/plugins/connectors/.claude-plugin/plugin.json index 61a2a1b..54dbee3 100644 --- a/plugins/connectors/.claude-plugin/plugin.json +++ b/plugins/connectors/.claude-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "connectors", - "version": "0.19.1", + "version": "0.19.2", "description": "Set up, inspect, and invoke governed integrations through the connectors CLI.", "author": { "name": "Beyond10x" }, "license": "Apache-2.0", diff --git a/plugins/connectors/.codex-plugin/plugin.json b/plugins/connectors/.codex-plugin/plugin.json index 3e24209..cb845ef 100644 --- a/plugins/connectors/.codex-plugin/plugin.json +++ b/plugins/connectors/.codex-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "connectors", - "version": "0.19.1", + "version": "0.19.2", "description": "Set up, inspect, and invoke governed integrations through the connectors CLI.", "author": { "name": "Beyond10x" }, "license": "Apache-2.0", diff --git a/plugins/ess/.claude-plugin/plugin.json b/plugins/ess/.claude-plugin/plugin.json index 85f5c23..5e07c16 100644 --- a/plugins/ess/.claude-plugin/plugin.json +++ b/plugins/ess/.claude-plugin/plugin.json @@ -2,7 +2,7 @@ "name": "ess", "displayName": "ESS", "description": "Write, retrofit, validate and project Executable System Specifications, and hold implementations to them with conformance suites.", - "version": "0.19.1", + "version": "0.19.2", "author": { "name": "Beyond10x" }, diff --git a/plugins/ess/.codex-plugin/plugin.json b/plugins/ess/.codex-plugin/plugin.json index 31c93c7..ebcfad1 100644 --- a/plugins/ess/.codex-plugin/plugin.json +++ b/plugins/ess/.codex-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "ess", - "version": "0.19.1", + "version": "0.19.2", "description": "Write, retrofit, validate and project Executable System Specifications, and hold implementations to them with conformance suites.", "author": { "name": "Beyond10x" diff --git a/plugins/worktree/.claude-plugin/plugin.json b/plugins/worktree/.claude-plugin/plugin.json index 89318d6..5b926ec 100644 --- a/plugins/worktree/.claude-plugin/plugin.json +++ b/plugins/worktree/.claude-plugin/plugin.json @@ -2,7 +2,7 @@ "name": "worktree", "displayName": "Worktree", "description": "Create, lease, finish, audit and safely clean isolated Git worktrees through the worktree CLI.", - "version": "0.19.1", + "version": "0.19.2", "author": { "name": "Beyond10x" }, diff --git a/plugins/worktree/.codex-plugin/plugin.json b/plugins/worktree/.codex-plugin/plugin.json index bc93600..33c4b80 100644 --- a/plugins/worktree/.codex-plugin/plugin.json +++ b/plugins/worktree/.codex-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "worktree", - "version": "0.19.1", + "version": "0.19.2", "description": "Create, lease, finish, audit and safely clean isolated Git worktrees through the worktree CLI.", "author": { "name": "Beyond10x"