Skip to content

Qualify the MPL-2.0 EPAC v0.1.0 release candidate - #7

Merged
erinepshovel-code merged 39 commits into
mainfrom
graduate/package-release-20260912
Sep 12, 2026
Merged

Qualify the MPL-2.0 EPAC v0.1.0 release candidate#7
erinepshovel-code merged 39 commits into
mainfrom
graduate/package-release-20260912

Conversation

@erinepshovel-code

@erinepshovel-code erinepshovel-code commented Sep 12, 2026

Copy link
Copy Markdown
Collaborator

EPAC now records the owner's weak-copyleft instruction as MPL-2.0, following the existing organization convention. It includes the official license text, SPDX metadata, distribution license files and a provenance record without transferring upstream rights.

CI uses the qualified CPython 3.11.15 builder to produce all four normalized release assets outside the source tree, then tests wheel and source installations under Python 3.10, 3.11 and 3.12. Independent acceptance compares every CI asset with the identical local candidate builds, and checks complete source, installed payloads, metadata, XML and the 14 retained FALSIFIED standings.

Current source 949cb1cb304927942966c9fb396caf6227120e7f (tree 8c9acb943ea05cbe3305fd0a10dd6a38b2fa684f) has two identical licensed builds, a passing complete source/metadata gate and clean exact-head review. All six clean installations passed 209 tests each without skips; independent verification confirmed that every CI asset equals the local candidate. The same licensed candidate passed the clean pre-publication Stack check. Publication and the subsequent Stack retirement/authority receipt are separate authorized steps after qualification.

Validation: current CI, clean exact-source review. Candidate wheel SHA-256 e871ce7940e963b73664a276cdd8ceea7ac1a5db568c26838cd57217e00adf45; source archive fb31e05b55f5cf3bae76e2bd70332507cca1051e71b58bb49f25bae136853460.

@erinepshovel-code

Copy link
Copy Markdown
Collaborator Author

@codex review

Please review exact head 8d865fd14b797ce5eefa8d1b771c1f52e5f425b7. The owner specified weak copyleft. This is resolved as MPL-2.0 using the existing skill-lib/metapat/edcm convention, with the interpretation disclosed before execution. The official unmodified license, its digest and selection provenance are recorded. Explicit SPDX/license-files metadata replaces the unresolved license status. No upstream license or scientific authority transfers.

CI now uses managed CPython3.11.15 and the pinned release builder in every Python3.10/3.11/3.12 job. Thus all six wheel/sdist installs will consume normalized release artifacts; independent acceptance requires every uploaded asset to match the same locally reproduced four-asset candidate. The full source/installed/manifest/checksum/XML/standing gates remain in force. Two local builds across umasks022/077, the fresh full matrix and prepublication Stack acceptance are being qualified. No release or authority transfer is claimed yet.

Preceding625e537 had a clean exact-commit review, six209-test private installs without skips, independently accepted downloaded evidence, and a passing private Stack consumer covering nine molecules and14 FALSIFIED standings. That remains historical after the licensed source and CI changes.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 12, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-09-12T23:23:30.199316Z 949cb1c Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@erinepshovel-code

Copy link
Copy Markdown
Collaborator Author

@codex review

Please review exact head c8d51a7ade39473919e2278a4dd669cdc3fece15. Its source tree is identical to 8d865fd (40cfbea0ea48f64b2347281b0bbd7ec6197063a0). The history reconciliation incorporates the externally squashed #6 baseline aecf04a, whose tree exactly equals accepted625e537, without changing any licensed source files. The PR can now merge against current main and run its qualification workflow.

Scope remains MPL-2.0 licensing from the owner's weak-copyleft instruction and the normalized release-candidate CI described above. Fresh four-asset builds are being qualified at this exact source identity; prior8d865 artifact hashes are historical because commit identity and source epoch changed. No stable publication or authority transfer is claimed yet.

@erinepshovel-code

Copy link
Copy Markdown
Collaborator Author

@codex review

Please review exact head 949cb1cb304927942966c9fb396caf6227120e7f. CI candidate output now stays outside the source tree in build, Twine, replay, and artifact collection. The previous failure correctly enforced the builder boundary; the gate is unchanged. MPL-2.0 licensing, immutable release qualification and scoped upstream non-transfer remain as described. Check for live P1/P2 issues.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. What shall we delve into next?

Reviewed commit: 949cb1cb30

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@erinepshovel-code erinepshovel-code changed the title License EPAC under MPL-2.0 and qualify v0.1.0 release bytes Qualify the MPL-2.0 EPAC v0.1.0 release candidate Sep 12, 2026
@erinepshovel-code
erinepshovel-code marked this pull request as ready for review September 12, 2026 23:22
@erinepshovel-code
erinepshovel-code merged commit 0b75288 into main Sep 12, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant