Qualify the MPL-2.0 EPAC v0.1.0 release candidate - #7
Conversation
|
@codex review Please review exact head CI now uses managed CPython3.11.15 and the pinned release builder in every Python3.10/3.11/3.12 job. Thus all six wheel/sdist installs will consume normalized release artifacts; independent acceptance requires every uploaded asset to match the same locally reproduced four-asset candidate. The full source/installed/manifest/checksum/XML/standing gates remain in force. Two local builds across umasks022/077, the fresh full matrix and prepublication Stack acceptance are being qualified. No release or authority transfer is claimed yet. Preceding625e537 had a clean exact-commit review, six209-test private installs without skips, independently accepted downloaded evidence, and a passing private Stack consumer covering nine molecules and14 FALSIFIED standings. That remains historical after the licensed source and CI changes. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
@codex review Please review exact head Scope remains MPL-2.0 licensing from the owner's weak-copyleft instruction and the normalized release-candidate CI described above. Fresh four-asset builds are being qualified at this exact source identity; prior8d865 artifact hashes are historical because commit identity and source epoch changed. No stable publication or authority transfer is claimed yet. |
|
@codex review Please review exact head |
|
Codex Review: Didn't find any major issues. What shall we delve into next? Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
EPAC now records the owner's weak-copyleft instruction as MPL-2.0, following the existing organization convention. It includes the official license text, SPDX metadata, distribution license files and a provenance record without transferring upstream rights.
CI uses the qualified CPython 3.11.15 builder to produce all four normalized release assets outside the source tree, then tests wheel and source installations under Python 3.10, 3.11 and 3.12. Independent acceptance compares every CI asset with the identical local candidate builds, and checks complete source, installed payloads, metadata, XML and the 14 retained FALSIFIED standings.
Current source
949cb1cb304927942966c9fb396caf6227120e7f(tree8c9acb943ea05cbe3305fd0a10dd6a38b2fa684f) has two identical licensed builds, a passing complete source/metadata gate and clean exact-head review. All six clean installations passed 209 tests each without skips; independent verification confirmed that every CI asset equals the local candidate. The same licensed candidate passed the clean pre-publication Stack check. Publication and the subsequent Stack retirement/authority receipt are separate authorized steps after qualification.Validation: current CI, clean exact-source review. Candidate wheel SHA-256
e871ce7940e963b73664a276cdd8ceea7ac1a5db568c26838cd57217e00adf45; source archivefb31e05b55f5cf3bae76e2bd70332507cca1051e71b58bb49f25bae136853460.