Repository navigation
Prepare release 0.1.0: versioning policy, changelog, security notes, Swift Package Index settings, code owners, issue templates, adopters and release notes (#65) - #145
Merged
Conversation
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The release still reports 0.1.0-dev, and the compatibility form needs a private-data redaction warning.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Prepares OpenJevSwift 0.1.0 with release documentation, security guidance, and repository configuration.
Changes:
- Adds versioning policy, changelog, release notes, and adopter documentation.
- Documents security, installation, supported backends, and release status.
- Adds Swift Package Index, CODEOWNERS, and issue-template configuration.
| File | Description |
|---|---|
Sources/OpenJevCore/Documentation.docc/GettingStarted.md |
Updates backend and SwiftPM guidance. |
SECURITY.md |
Documents reporting, networking, secrets, and downloads. |
README.md |
Adds release installation and status information. |
docs/release-notes/0.1.0.md |
Adds 0.1.0 release notes. |
docs/README.md |
Links release documentation. |
docs/development.md |
Defines versioning and release policy. |
CHANGELOG.md |
Adds version policy and 0.1.0 changes. |
ADOPTERS.md |
Adds the adopter-list process. |
.spi.yml |
Configures Package Index documentation and iOS builds. |
.github/ISSUE_TEMPLATE/config.yml |
Adds security reporting guidance. |
.github/ISSUE_TEMPLATE/compatibility_report.yml |
Adds compatibility-report fields. |
.github/ISSUE_TEMPLATE/bug_report.yml |
Adds structured bug reporting. |
.github/CODEOWNERS |
Assigns repository ownership. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+159
to
+161
| - **Version strings.** Every module's `Version.swift` holds the same version, which | ||
| `openjev --version` prints: the next release with `-dev` between releases, and the release itself | ||
| at its tag. |
…rning before requesting request/response logs' Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Refs #65.
Prepares release 0.1.0 without publishing anything: no tag, GitHub release or Swift Package Index submission is made here. The commands for those, run after the merge, are at the end. Docs and config only;
Package.swiftdid not need a change (item 8).Dependencies: #64, #31 and #39 are closed (2026-10-02, 2026-10-02 and 2026-10-01), and so are milestones 0 to 5, which the issue's "once milestones 2 and 3 are complete" asks for.
What this adds
0.1.0;-devversion strings between releases; dependencies only by versionCHANGELOG.mdheader,docs/development.md"Versioning and releases"openjevtool, apps on iOS and macOS, compatibility, documentation, and the known gaps (CLM #59; #100, #101, #102). Every line links the doc that backs it; no timing figuresCHANGELOG.md{"enabled":true}), supported versions, the listener and its routes, every outgoing connection, no telemetry, the variables that hold keys and that none is loggedSECURITY.md--exclude-extended-types, and the scheme iOS builds.spi.yml.github/CODEOWNERS,.github/ISSUE_TEMPLATE/ADOPTERS.md,README.mdfrom: "0.1.0"and buildingopenjevdocs/release-notes/0.1.0.mdREADME.md(status: milestones 0 to 5, 0.1.0 released, "Not there yet" without #65; a SwiftPM line; links to the new files),Sources/OpenJevCore/Documentation.docc/GettingStarted.md(its "no release yet, depend onbranch: "main"" section and the stale mlx-swift-lm paragraph becomefrom: "0.1.0"; the backend table gains JevK5),docs/README.md(points at the release notes and the changelog)Checks on the new config:
.spi.ymlloads with SPIManifest 1.13.0, the Swift Package Index's own parser (836 of its 1,500-byte limit; the five documentation targets, the parameter, and schemeOpenJevCore-iOSfor iOS). The two issue forms andconfig.ymlvalidate against SchemaStore'sgithub-issue-formsandgithub-issue-configschemas with no errors. Every relative link and heading anchor in the changed Markdown resolves, and none of the files has an em dash.Network call sites
Searched in
Sources/forURLSession,URLRequest,URL(string:,URLComponents,HTTPClient,HubApi,snapshot(,AutoTokenizer,from(pretrained,ModelFactory,loadModel,ClientBootstrap,ServerBootstrap,NWConnection,NWListener,import Network,socket(,connect(,bind(,Process(,curl,huggingface.co,github.com,https?://,MetricsSystem,InstrumentationSystem,LoggingSystem,.bootstrap,telemetryandanalytics, and read every match.OpenJevServer/OpenJevApplication.swift:96-105address: .hostname(settings.host, port: settings.port), HTTP/1.1 without TLS; routes at :58-69 (/health,/v1/models,/v1/systemone,/v1/chat/completionswhen the model generates text)openjev serve, onOPENJEV_HOST:OPENJEV_PORT,127.0.0.1:8080by defaultOpenJevEncoders/Store/EncoderPackageStore.swift:312URLSession.shared(:90,:105)download(from:)of each manifest file: package files fromhttps://github.com/Algorythm-Canada/openjev-models/releases/download/<tag>/<asset>and tokenizer and calibrator files fromhttps://huggingface.co/<repo>/resolve/<pinned commit>/<file>(EncoderPackageManifest+Verdict.swift:57-69,EncoderPackageManifest+Laya.swift:245-257); no token; size and SHA-256 checked before useverdictorlaya, andLayaBackend.prefetch(lengths:)on an iPhone, for files that are missing or unchecked; never withOPENJEV_ENCODER_MODELSOpenJevDiffusionGemma/Download/ModelResolver.swift:251URLSession(:133-141) tohttps://huggingface.co:GET /api/models/<repo>/revision/<rev>(:575-588, branch or tag only) andGET /api/models/<repo>/tree/<commit>?recursive=true(:591-636, every load of a Hub source; a next page on another origin is refused at:624-629)mlx(DiffusionGemmaRuntime.swift:237) andjevk5(JevK5Checkpoint.swift:199) with a Hub source; never with a folderOpenJevDiffusionGemma/Download/ModelResolver.swift:314dataTaskper missing file,GET /<repo>/resolve/<commit>/<path>, resumed withRange, checked by SHA-256 or git blob SHA-1 (:735-841);Authorizationdropped when a redirect changes host (:337-349)OpenJevServer/ModelRouter.swift:96-103<route url>/v1/systemonewith the client'sauthorization,x-origin-secretandcontent-type, and Basic authorization from credentials in the URL (:84-94); no redirects, HTTP/1.1, one client per request (:124-139); the answer read whole (:104)OPENJEV_MODEL_ROUTES, for a routed model this server does not serveopenjev-bench/Targets.swift:55,69URLSessionPOSTs to the server--urlnamesopenjev-stub-server/StubServer.swiftChecked and not a connection:
AutoTokenizer.from(modelFolder:)(OpenJevEncoders/TokenizerFolder.swift:22,OpenJevLetterReadout/MLX/JevK5Tokenizer.swift:30) andLanguageModelConfigurationFromHub(modelFolder:)(OpenJevDiffusionGemma/Tokenization/SwiftTransformersTokenizer.swift:293) read local files only (swift-transformers 1.3.4,Hub.swift:247); creating the sharedHubApithey default to starts anNWPathMonitor(HubApi.swift:1159-1186), which sends nothing.openjev-bench/BenchCommand.swift:134runs/usr/bin/pmset. Images are base64 ordata:URLs (OpenJevCore/Images/ImageValidation.swift), never fetched.PillowJPEGHeader.swift:186andSystemOneService.swift:127-154hold URLs as text (an XMP namespace and model descriptions).Telemetry: no
MetricsSystem.bootstrap,InstrumentationSystem.bootstrap, analytics or telemetry code inSources/; no metrics or tracing middleware is installed; the tool logs throughStreamLogHandler.standardError(openjev/CommandContext.swift:51), and mlx-swift's own logger writes to the unified log by default (mlx-swift/Source/MLX/Logging.swift:43-44). So SECURITY.md says "no telemetry", and it lists the model routes and the listener beside the downloads rather than the issue's "no network calls except model download".Keys:
OPENJEV_API_KEYandOPENJEV_ORIGIN_SECRET(ServerSettings.swift:226-227), compared in constant time (AuthenticationMiddleware.swift:64-85) and logged only assetorunset(ServeCommand.swift:187-193); route URLs are logged without credentials (ServeCommand.swift:95-97,ServerSettings.swift:297-334);HF_TOKEN(ModelSource.swift:86,:124-129, passed atBackendRegistry.swift:152and:218) goes only to the Hub's requests, and its errors name the variable. One case quotes a secret: a malformedOPENJEV_MODEL_ROUTESentry is echoed whole in upstream's startup error (ServerSettings.swift:279-286,:408-411), credentials included; SECURITY.md says so.Dependency check (item 8)
Every requirement in
Package.swiftis a version, so nothing changed:from: "2.23.0"from: "1.8.0"from: "1.8.0"from: "1.15.1"from: "2.103.0"from: "2.12.0"from: "1.36.2"from: "1.5.0"exact: "0.32.3"exact: "3.32.3".upToNextMinor(from: "1.3.0")from: "2.4.2"All 35 pins in
Package.resolvedare versions; none is a branch. The fresh packages below prove the transitive side: SwiftPM resolved this package by version and every package under it.Fresh packages: the acceptance criteria, with nothing published
In a scratch folder outside the repository,
S=/private/tmp/claude-501/<session>/scratchpad/release-proof, with Swift 6.4 (Xcode 27.0, Swift Build) on macOS 27.0, Apple silicon.$WORKTREEis this branch's worktree. The tag exists only in the scratch clone, whose only remote is the local worktree; nothing was pushed. The clone is commit62c20ef.The commits after the tested one change Markdown only:
The clone and its tag
A package that uses
OpenJevCoreThe same package without
platformsdoes not build, which is why the install docs name them:A package that uses
OpenJevDiffusionGemmaBoth packages resolved the same 36 pins, every one a version (
Package.resolvedof each):swift package dump-packagein the tagged clone prints valid JSON (5 products, 12 dependencies, macOS 14 and iOS 17, tools 6.2), which the Swift Package Index requires.In the worktree,
swift build(Build complete),make lint(no findings) andmake docs(the five modules, every DocC warning an error) pass.Package.swiftdid not change, so the fullswift testwas not run.Contradictions and open points
0.1.0-dev, so a tag of this merge reports 0.1.0-dev. All fiveVersion.swiftconstants hold"0.1.0-dev", their doc comment says the suffix "marks unreleased work toward 0.1.0",openjev --versionprints it, and six tests expect it (Tests/OpenJevCoreTests/VersionTests.swift:6,Tests/OpenJevServerTests/VersionTests.swift:6,Tests/OpenJevDiffusionGemmaTests/VersionTests.swift:6,Tests/OpenJevEncodersTests/EncoderPackageSpecTests.swift:220,Tests/OpenJevCLITests/ArgumentParsingTests.swift:170,Tests/OpenJevCLITests/BinaryTests.swift:20). The fresh package above printedOpenJevCore 0.1.0-devfrom the local0.1.0tag. Changing them is a Swift change, which this PR's scope (docs and config) leaves out. Either a small PR sets the five constants and six tests to0.1.0before the tag and another moves them to the next-devafter it, as the new "Version strings" rule in development.md says, or the tag goes ahead with0.1.0-dev.Linuxjob builds and testsOpenJevCore, the server and the tool inswift:6.2-noble, and it runs on this PR because.spi.ymland the issue forms are not Markdown (ci.yml's paths are**without!**.md); the Documentation workflow runs too, for the DocC article. That job builds the package as the root, not through a version requirement; on Linux the manifest declares only the eightfrom:dependencies, a subset of the graph that resolved by version here, andOpenJevCoredepends on none of them.OPENJEV_MODEL_ROUTES). SECURITY.md lists all three and says "no telemetry", which the search supports.ghp api repos/Algorythm-Canada/OpenJevSwift/private-vulnerability-reportinganswers{"enabled":true}, so SECURITY.md's link works now.compatibilitylabel (the bug form usesbug).Package.resolved: swift-nio 2.104.0, swift-service-lifecycle 2.12.1, swift-async-algorithms 1.1.7, swift-configuration 1.2.2 and swift-huggingface 0.13.0, against 2.103.0, 2.12.0, 1.1.6, 1.2.1 and 0.11.0 in this repository's file. The two fresh packages built with them, so a consumer gets a working set today.docs/development.md:317says the upstream live file'sthink, chat and stream tests fail "until The think option: thought generation before a read, prefix continuation, billing #52 and /v1/chat/completions: OpenAI-compatible generation with streaming, JSON mode and cancellation #53 land" (both landed in Generate text, think and chat on the MLX backend: the diffusion sampler, the block loop, think and the chat model (#50, #51, #52, #53, D-059) #137);docs/development.md:100-101lists mlx-swift-lm's products asMLXLMCommon,MLXVLMand swift-transformers' asTokenizers, whilePackage.swiftalso usesMLXLLM,MLXHuggingFaceandHub;CONTRIBUTING.md:3says the project is "in its research and planning phase";docs/development.md:90says autogenerated schemes are never written to disk, while eight are committed (known, and your call).After the merge
Run from the main checkout once this PR has merged (and, if you take point 1 above, once the version PR has merged too, tagging its commit instead).
Check that
origin/mainis the commit to release:git log -1 --format='%h %s' origin/mainTag it and push the tag:
git tag -a 0.1.0 -m "OpenJevSwift 0.1.0" origin/mainCreate the GitHub release from the notes file on
main(--verify-tagrefuses to run if the tag is not on GitHub yet):Submit the package to the Swift Package Index: https://swiftpackageindex.com/add-a-package, then Add Package(s), which opens an issue on SwiftPackageIndex/PackageList; give it
https://github.com/Algorythm-Canada/OpenJevSwift.git. The index needs thehttpsURL with.gitand at least one semantic version tag, which0.1.0is.Then close the issue: