From d184a0c4e455e8378f1937df8203a3492f46ecb3 Mon Sep 17 00:00:00 2001 From: SteveBot <1153461+unbraind@users.noreply.github.com> Date: Sun, 27 Sep 2026 10:04:37 +0200 Subject: [PATCH 1/8] Certify pm-jira on CLI 2026.9.27 and pinned GitHub extension Upgrade the package development toolchain to the latest published PM CLI/SDK, pm-ops, and pm-changelog versions. Install managed pm-github 2026.9.26 through the project-local CLI and pin the same source in CI and the still-disabled issue-sync workflow. Refresh the canonical published merge-driver launcher and record the 173-test release-gate and strict-health evidence in the package PM issue. --- .../pm/extensions/.managed-extensions.json | 10 +-- .agents/pm/history/pm-jira-b0n8.jsonl | 5 ++ .agents/pm/issues/pm-jira-b0n8.toon | 27 +++++++ .github/workflows/ci.yml | 13 +--- .github/workflows/pm-github-sync.yml | 12 +--- package-lock.json | 72 +++++++++---------- package.json | 6 +- scripts/prepare-merge-driver.ts | 13 +++- 8 files changed, 90 insertions(+), 68 deletions(-) create mode 100644 .agents/pm/history/pm-jira-b0n8.jsonl create mode 100644 .agents/pm/issues/pm-jira-b0n8.toon diff --git a/.agents/pm/extensions/.managed-extensions.json b/.agents/pm/extensions/.managed-extensions.json index 1919bbd..a0d850e 100644 --- a/.agents/pm/extensions/.managed-extensions.json +++ b/.agents/pm/extensions/.managed-extensions.json @@ -1,12 +1,12 @@ { "version": 1, - "updated_at": "2026-08-28T20:03:25.465Z", + "updated_at": "2026-09-27T07:59:03.646Z", "entries": [ { "name": "pm-github", "directory": "pm-github", "scope": "project", - "manifest_version": "2026.8.18", + "manifest_version": "2026.9.26", "manifest_entry": "./dist/index.js", "capabilities": [ "commands", @@ -94,13 +94,13 @@ ] }, "installed_at": "2026-08-28T20:03:25.135Z", - "updated_at": "2026-08-28T20:03:25.135Z", + "updated_at": "2026-09-27T07:59:03.540Z", "source": { "kind": "npm", - "input": "npm:pm-github", + "input": "npm:pm-github@2026.9.26", "location": "package", "package": "pm-github", - "version": "2026.8.18" + "version": "2026.9.26" } } ] diff --git a/.agents/pm/history/pm-jira-b0n8.jsonl b/.agents/pm/history/pm-jira-b0n8.jsonl new file mode 100644 index 0000000..0e5e93a --- /dev/null +++ b/.agents/pm/history/pm-jira-b0n8.jsonl @@ -0,0 +1,5 @@ +{"hash_algorithm":"sha256","ts":"2026-09-27T08:01:14.699Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"create","patch":[{"op":"add","path":"/metadata/id","value":"pm-jira-b0n8"},{"op":"add","path":"/metadata/title","value":"Certify pm-jira on CLI 2026.9.27 and pinned GitHub extension"},{"op":"add","path":"/metadata/description","value":"The main checkout pins PM CLI, pm-ops, and pm-changelog 2026.9.23 and manages pm-github 2026.8.18. Host CLI 2026.9.27 reports extension SDK-link skew. CI and disabled scheduled sync install an unversioned extension through an obsolete npm 10 shim and rewrite its manifest. Align the package toolchain and tracked extension metadata with current published versions, and use the exact managed extension source in both workflows."},{"op":"add","path":"/metadata/type","value":"Issue"},{"op":"add","path":"/metadata/status","value":"in_progress"},{"op":"add","path":"/metadata/priority","value":1},{"op":"add","path":"/metadata/tags","value":["agent-ux","area:github","area:release"]},{"op":"add","path":"/metadata/created_at","value":"2026-09-27T08:01:14.699Z"},{"op":"add","path":"/metadata/updated_at","value":"2026-09-27T08:01:14.699Z"},{"op":"add","path":"/metadata/assignee","value":"codex"},{"op":"add","path":"/metadata/author","value":"codex"},{"op":"add","path":"/metadata/acceptance_criteria","value":"Exact package/lock pins for current CLI, pm-ops, and pm-changelog; tracked managed pm-github 2026.9.26; local strict health and full release gate pass; CI uses exact source; disabled sync stays disabled; staged privacy scan and exact-head review complete."},{"op":"add","path":"/metadata/repro_steps","value":"Run pm health --strict-exit --json on main with host CLI 2026.9.27; observe extension_host_pm_cli_version_skew. Inspect both workflows for npm:pm-github without a version and the npm 10 / manifest-rewrite steps."},{"op":"add","path":"/metadata/expected_result","value":"Strict health passes with the project-local CLI/SDK 2026.9.27; both workflows install exact pm-github 2026.9.26; the package release gate passes; the sync workflow stays disabled until a separate pre-push privacy gate exists."},{"op":"add","path":"/metadata/actual_result","value":"Main reports SDK-link skew and both workflow installs can drift to future unreviewed extension versions."}],"before_hash":"3cc22dff72be7b14824654a7a64ea62b04799939b2fee54c1b5f52ca60bf6df0","after_hash":"8378e5c506883fa28d14098a284c155f56dcbd3b1ec6c54bef1459e1bffb04b4","item_hash_version":3,"message":"Track pm-jira SDK and managed GitHub extension certification","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"c289fd5d4da7087a42c99dfe0aeffcc9a7f156c414894912eafc24913aecfdc0"} +{"hash_algorithm":"sha256","ts":"2026-09-27T08:02:51.137Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"note_add","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:02:51.137Z"},{"op":"add","path":"/metadata/notes","value":[{"created_at":"2026-09-27T08:02:51.137Z","author":"codex","text":"2026-09-27: First full release gate failed at the package launcher byte-identity assertion after upgrading published pm-ops to 2026.9.26. Copied the exact canonical launcher from installed pm-ops 2026.9.26 to scripts/prepare-merge-driver.ts; this includes its broken local-install guard. The full gate must rerun. The disabled GitHub sync workflow remains disabled."}]}],"before_hash":"8378e5c506883fa28d14098a284c155f56dcbd3b1ec6c54bef1459e1bffb04b4","after_hash":"f0e2f9b70e71aa8ef5396b0eaf56389731d9f4e32b823823faf5e180776104e7","item_hash_version":3,"message":"Record initial launcher gate failure and canonical repair","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"e3aa7a54acbaa86bc233f0dedb782611c5b4ecdaa95ca009526eb10cd11f062e"} +{"hash_algorithm":"sha256","ts":"2026-09-27T08:04:19.777Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"files_add","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:04:19.777Z"},{"op":"add","path":"/metadata/files","value":[{"path":".agents/pm/extensions/.managed-extensions.json","scope":"project","note":"Exact managed pm-github source"},{"path":".github/workflows/ci.yml","scope":"project","note":"CI installs pinned extension"},{"path":".github/workflows/pm-github-sync.yml","scope":"project","note":"Disabled sync installs pinned extension"},{"path":"package.json","scope":"project","note":"Published CLI and quality-tool pins"},{"path":"scripts/prepare-merge-driver.ts","scope":"project","note":"Published pm-ops launcher copy"}]}],"before_hash":"f0e2f9b70e71aa8ef5396b0eaf56389731d9f4e32b823823faf5e180776104e7","after_hash":"1590f46a217800b61bf23d08558da32b45c33de4ee5892c518b1df8d0b9852f2","item_hash_version":3,"message":"Link certification implementation files","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"9e98bf7c82da0dc1b0ea9fcd8ea41b671923b7288a9c1a74a18756c1fb665168"} +{"hash_algorithm":"sha256","ts":"2026-09-27T08:04:20.927Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"tests_add","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:04:20.927Z"},{"op":"add","path":"/metadata/tests","value":[{"command":"npm run release:check","scope":"project","timeout_seconds":600,"provenance":{"author":"codex","created_at":"2026-09-27T08:04:20.900Z","source_kind":"local_mutation","source_ref":"fix/pm-jira-cli-2026-09-27-github-pin"}}]}],"before_hash":"1590f46a217800b61bf23d08558da32b45c33de4ee5892c518b1df8d0b9852f2","after_hash":"9ceb268ea1de55fe57716c9e5abeff6fa59f3aafc3f2db2bc94b6c0431672b70","item_hash_version":3,"message":"Link complete package release gate","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"b5c210d7c73193d6b1c6c5fd09b45c84f405d29211d7a186748742ef13024b8b"} +{"hash_algorithm":"sha256","ts":"2026-09-27T08:04:22.372Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"note_add","patch":[{"op":"add","path":"/metadata/notes/1","value":{"created_at":"2026-09-27T08:04:22.372Z","author":"codex","text":"2026-09-27 08:04 UTC: Full local release gate passed after copying the exact published pm-ops 2026.9.26 launcher: 173/173 tests, zero skips, 100% measured lines/branches/functions across two production source files, 51/51 declarations documented, zero production audit vulnerabilities, current changelog and attestation checks. Strict PM health passes on CLI 2026.9.27 with stale_in_progress_items:1 advisory. A real pm-github 2026.9.26 project install activated and an open-issue dry run found no public Jira issues; no tracker import was applied. Scheduled sync remains disabled_manually pending pre-push privacy gating. GitHub CI, reviewer evidence, and statement coverage remain separate gates."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:04:22.372Z"}],"before_hash":"9ceb268ea1de55fe57716c9e5abeff6fa59f3aafc3f2db2bc94b6c0431672b70","after_hash":"d8ebcd77eaed0854b6c2d078f7c85ddc7374e6c2c3afacd9499444c03d4e90a8","item_hash_version":3,"message":"Record package gate and live extension dry-run evidence","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"2b1240f0563b00e441c66da7a0b75f2f9dcfe2b86d6d486c517946331795077f"} diff --git a/.agents/pm/issues/pm-jira-b0n8.toon b/.agents/pm/issues/pm-jira-b0n8.toon new file mode 100644 index 0000000..8024eba --- /dev/null +++ b/.agents/pm/issues/pm-jira-b0n8.toon @@ -0,0 +1,27 @@ +id: pm-jira-b0n8 +title: Certify pm-jira on CLI 2026.9.27 and pinned GitHub extension +description: "The main checkout pins PM CLI, pm-ops, and pm-changelog 2026.9.23 and manages pm-github 2026.8.18. Host CLI 2026.9.27 reports extension SDK-link skew. CI and disabled scheduled sync install an unversioned extension through an obsolete npm 10 shim and rewrite its manifest. Align the package toolchain and tracked extension metadata with current published versions, and use the exact managed extension source in both workflows." +type: Issue +status: in_progress +priority: 1 +tags[3]: agent-ux,"area:github","area:release" +created_at: "2026-09-27T08:01:14.699Z" +updated_at: "2026-09-27T08:04:22.372Z" +assignee: codex +author: codex +acceptance_criteria: "Exact package/lock pins for current CLI, pm-ops, and pm-changelog; tracked managed pm-github 2026.9.26; local strict health and full release gate pass; CI uses exact source; disabled sync stays disabled; staged privacy scan and exact-head review complete." +repro_steps: "Run pm health --strict-exit --json on main with host CLI 2026.9.27; observe extension_host_pm_cli_version_skew. Inspect both workflows for npm:pm-github without a version and the npm 10 / manifest-rewrite steps." +expected_result: Strict health passes with the project-local CLI/SDK 2026.9.27; both workflows install exact pm-github 2026.9.26; the package release gate passes; the sync workflow stays disabled until a separate pre-push privacy gate exists. +actual_result: Main reports SDK-link skew and both workflow installs can drift to future unreviewed extension versions. +notes[2]{created_at,author,text}: + "2026-09-27T08:02:51.137Z",codex,"2026-09-27: First full release gate failed at the package launcher byte-identity assertion after upgrading published pm-ops to 2026.9.26. Copied the exact canonical launcher from installed pm-ops 2026.9.26 to scripts/prepare-merge-driver.ts; this includes its broken local-install guard. The full gate must rerun. The disabled GitHub sync workflow remains disabled." + "2026-09-27T08:04:22.372Z",codex,"2026-09-27 08:04 UTC: Full local release gate passed after copying the exact published pm-ops 2026.9.26 launcher: 173/173 tests, zero skips, 100% measured lines/branches/functions across two production source files, 51/51 declarations documented, zero production audit vulnerabilities, current changelog and attestation checks. Strict PM health passes on CLI 2026.9.27 with stale_in_progress_items:1 advisory. A real pm-github 2026.9.26 project install activated and an open-issue dry run found no public Jira issues; no tracker import was applied. Scheduled sync remains disabled_manually pending pre-push privacy gating. GitHub CI, reviewer evidence, and statement coverage remain separate gates." +files[5]{path,scope,note}: + .agents/pm/extensions/.managed-extensions.json,project,Exact managed pm-github source + .github/workflows/ci.yml,project,CI installs pinned extension + .github/workflows/pm-github-sync.yml,project,Disabled sync installs pinned extension + package.json,project,Published CLI and quality-tool pins + scripts/prepare-merge-driver.ts,project,Published pm-ops launcher copy +tests[1]{command,scope,timeout_seconds,provenance{author,created_at,source_kind,source_ref}}: + "npm run release:check",project,600,codex,"2026-09-27T08:04:20.900Z",local_mutation,fix/pm-jira-cli-2026-09-27-github-pin +body: "" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index f7f2a71..8444c45 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -41,17 +41,8 @@ jobs: shell: bash run: | set -euo pipefail - # npm 12 emits object-shaped `npm pack --json` output, while the - # current pm installer accepts npm 10's array-shaped response. - npm10_root="${RUNNER_TEMP}/pm-npm10" - npm install --prefix "${npm10_root}" --no-save --ignore-scripts npm@10.9.3 - PATH="${npm10_root}/node_modules/.bin:${PATH}" ./node_modules/.bin/pm install npm:pm-github --project - # The published 2026.8.18 artifact still carries the obsolete `pm` - # manifest key. Normalize it to the source manifest's enforced floor - # before the strict health gate; the installed artifact is ignored. - extension_manifest=".agents/pm/extensions/pm-github/manifest.json" - jq 'del(.pm) | .pm_min_version = "2026.8.20"' "${extension_manifest}" > "${RUNNER_TEMP}/pm-github-manifest.json" - mv "${RUNNER_TEMP}/pm-github-manifest.json" "${extension_manifest}" + ./node_modules/.bin/pm package install npm:pm-github@2026.9.26 --project + node -e 'if (require("./.agents/pm/extensions/pm-github/package.json").version !== "2026.9.26") process.exit(1)' managed_registry=".agents/pm/extensions/.managed-extensions.json" if git ls-files --error-unmatch "${managed_registry}" > /dev/null 2>&1; then git restore -- "${managed_registry}" diff --git a/.github/workflows/pm-github-sync.yml b/.github/workflows/pm-github-sync.yml index 15f2984..869ecfd 100644 --- a/.github/workflows/pm-github-sync.yml +++ b/.github/workflows/pm-github-sync.yml @@ -56,16 +56,8 @@ jobs: shell: bash run: | set -euo pipefail - # npm 12 emits object-shaped `npm pack --json` output, while the - # current pm installer accepts npm 10's array-shaped response. - npm10_root="${RUNNER_TEMP}/pm-npm10" - npm install --prefix "${npm10_root}" --no-save --ignore-scripts npm@10.9.3 - PATH="${npm10_root}/node_modules/.bin:${PATH}" ./node_modules/.bin/pm install npm:pm-github --project - # The published 2026.8.18 artifact still carries the obsolete `pm` - # manifest key. Normalize it to the source manifest's enforced floor. - extension_manifest=".agents/pm/extensions/pm-github/manifest.json" - jq 'del(.pm) | .pm_min_version = "2026.8.20"' "${extension_manifest}" > "${RUNNER_TEMP}/pm-github-manifest.json" - mv "${RUNNER_TEMP}/pm-github-manifest.json" "${extension_manifest}" + ./node_modules/.bin/pm package install npm:pm-github@2026.9.26 --project + node -e 'if (require("./.agents/pm/extensions/pm-github/package.json").version !== "2026.9.26") process.exit(1)' managed_registry=".agents/pm/extensions/.managed-extensions.json" if git ls-files --error-unmatch "${managed_registry}" > /dev/null 2>&1; then git restore -- "${managed_registry}" diff --git a/package-lock.json b/package-lock.json index 71f5945..8e5bd7a 100644 --- a/package-lock.json +++ b/package-lock.json @@ -10,9 +10,9 @@ "license": "MIT", "devDependencies": { "@types/node": "^26.1.1", - "@unbrained/pm-cli": "2026.9.23", - "pm-changelog": "2026.9.23", - "pm-ops": "2026.9.23", + "@unbrained/pm-cli": "2026.9.27", + "pm-changelog": "2026.9.25", + "pm-ops": "2026.9.26", "typescript": "^7.0.2" }, "engines": { @@ -205,9 +205,9 @@ } }, "node_modules/@sentry/core": { - "version": "10.75.0", - "resolved": "https://registry.npmjs.org/@sentry/core/-/core-10.75.0.tgz", - "integrity": "sha512-5wDQpQqjJ6RHdPR+z6Q+47XlwoxRKBv0yyB0LKHqL/1azPOQbR+nllyLmmQDcoJpaksuLSmLA1q6hFX7gjDT2w==", + "version": "10.75.1", + "resolved": "https://registry.npmjs.org/@sentry/core/-/core-10.75.1.tgz", + "integrity": "sha512-+/+UanewqPK+oJvDQIHWKLUqnsa0iymEThOPCaFBA8ulbQh9k8lsz8V+NtJwP4G3ncclfzp15tzqVwn6iugV4Q==", "dev": true, "license": "MIT", "dependencies": { @@ -218,9 +218,9 @@ } }, "node_modules/@sentry/node": { - "version": "10.75.0", - "resolved": "https://registry.npmjs.org/@sentry/node/-/node-10.75.0.tgz", - "integrity": "sha512-XdYW+SEiscQnuugh1hMldfnHurmleKSTSDqgfro6Y1yd7s0r2csnZ5/SEYxIeL4lSl1QXg1lIA1pBmAXjcdnKA==", + "version": "10.75.1", + "resolved": "https://registry.npmjs.org/@sentry/node/-/node-10.75.1.tgz", + "integrity": "sha512-qiWGwh0KiBoq4vEl0FbxFKw0xnOKxuKCaEVdtwMZLAGw1ef77NOCdie7e/Fmcsk9c++Ck4D8NmIjQm6BidRVSQ==", "dev": true, "license": "MIT", "dependencies": { @@ -228,10 +228,10 @@ "@opentelemetry/instrumentation": "^0.220.0", "@opentelemetry/sdk-trace-base": "^2.9.0", "@sentry/conventions": "^0.16.0", - "@sentry/core": "10.75.0", - "@sentry/node-core": "10.75.0", - "@sentry/opentelemetry": "10.75.0", - "@sentry/server-utils": "10.75.0", + "@sentry/core": "10.75.1", + "@sentry/node-core": "10.75.1", + "@sentry/opentelemetry": "10.75.1", + "@sentry/server-utils": "10.75.1", "import-in-the-middle": "^3.0.0" }, "engines": { @@ -239,15 +239,15 @@ } }, "node_modules/@sentry/node-core": { - "version": "10.75.0", - "resolved": "https://registry.npmjs.org/@sentry/node-core/-/node-core-10.75.0.tgz", - "integrity": "sha512-+E3KSX1oMqhpWQ23hj6NblIVUzLy3T2oceU7DfMX1s1ar+npaQZxR5K0/cMGcQgS1LLm8Jqwqo/lrZlKTCDm5A==", + "version": "10.75.1", + "resolved": "https://registry.npmjs.org/@sentry/node-core/-/node-core-10.75.1.tgz", + "integrity": "sha512-HR0Iy7oNFOP26cwaRi33ZZnvlUSMFzXbZoRgYtBAkqUHDNQA6LWG1N1OoIdKNRJzDkGu/zefbM50Amqgyy1u1Q==", "dev": true, "license": "MIT", "dependencies": { "@sentry/conventions": "^0.16.0", - "@sentry/core": "10.75.0", - "@sentry/opentelemetry": "10.75.0", + "@sentry/core": "10.75.1", + "@sentry/opentelemetry": "10.75.1", "import-in-the-middle": "^3.0.0" }, "engines": { @@ -279,14 +279,14 @@ } }, "node_modules/@sentry/opentelemetry": { - "version": "10.75.0", - "resolved": "https://registry.npmjs.org/@sentry/opentelemetry/-/opentelemetry-10.75.0.tgz", - "integrity": "sha512-reJoMtuHMuaiztoDVoaeitc22eHlTAvz2qpFhibWyzukJlF8oXB+o8EvDN9mmDDMedU89c//cXRcnPBlJvUxcw==", + "version": "10.75.1", + "resolved": "https://registry.npmjs.org/@sentry/opentelemetry/-/opentelemetry-10.75.1.tgz", + "integrity": "sha512-leRKyFkEgV47Qo2wKCMEIYxPgnp67C+wYFg0GPreX5owRde0l18F5BEmsYUU57WAjBKBDo2idrrEEQaU15uH8g==", "dev": true, "license": "MIT", "dependencies": { "@sentry/conventions": "^0.16.0", - "@sentry/core": "10.75.0" + "@sentry/core": "10.75.1" }, "engines": { "node": ">=18" @@ -298,14 +298,14 @@ } }, "node_modules/@sentry/server-utils": { - "version": "10.75.0", - "resolved": "https://registry.npmjs.org/@sentry/server-utils/-/server-utils-10.75.0.tgz", - "integrity": "sha512-7fIa9vFGNzB13hmxl8Sip3xImSkqpc4wETzuQ7CLzVOwPvwI6y/gVEm0pxRhtJSq8SzfOp26eJWl80u8v78Osg==", + "version": "10.75.1", + "resolved": "https://registry.npmjs.org/@sentry/server-utils/-/server-utils-10.75.1.tgz", + "integrity": "sha512-HuA/bCtthA5x/AjYD5WUbG6CBcYJb0WAWKNgrgNkUWtll6eMqG3+7LO4PBcGRbZtlg1OFgClJm4iQFgRN7+ZZg==", "dev": true, "license": "MIT", "dependencies": { "@sentry/conventions": "^0.16.0", - "@sentry/core": "10.75.0" + "@sentry/core": "10.75.1" }, "engines": { "node": ">=18" @@ -669,13 +669,13 @@ } }, "node_modules/@unbrained/pm-cli": { - "version": "2026.9.23", - "resolved": "https://registry.npmjs.org/@unbrained/pm-cli/-/pm-cli-2026.9.23.tgz", - "integrity": "sha512-tL1u+NDa6UkJyJaJR3j7noqi6byFlQdgWSZsFDG/k6k31LTBCQJNfX42EhgBE8kR100O61DleJSaMCtPq+LT9g==", + "version": "2026.9.27", + "resolved": "https://registry.npmjs.org/@unbrained/pm-cli/-/pm-cli-2026.9.27.tgz", + "integrity": "sha512-l7m3GIm50oMecjXYnzA+RuzHgFD/uAOZko3eRJXfT+pYV9pceh4xvJ9dbD+35p2mY/zvUNiZjggCOOrWVuswSA==", "dev": true, "license": "MIT", "dependencies": { - "@sentry/node": "10.75.0", + "@sentry/node": "10.75.1", "@toon-format/toon": "^4.1.1", "@types/node": ">=22", "commander": "^15.0.0", @@ -982,9 +982,9 @@ } }, "node_modules/pm-changelog": { - "version": "2026.9.23", - "resolved": "https://registry.npmjs.org/pm-changelog/-/pm-changelog-2026.9.23.tgz", - "integrity": "sha512-hrHFbRgz/LyiCBN9ic0I1C//SRL/zjU5fxcyCeCAnM2qTrz14A7f9ayMXeiu/ChDkVFMxfz8Ps2j3TuUG6K1QA==", + "version": "2026.9.25", + "resolved": "https://registry.npmjs.org/pm-changelog/-/pm-changelog-2026.9.25.tgz", + "integrity": "sha512-j2l97jlJIfuMiB7KDi7oIr9MWxdQvqnDx/JwE3pxC31fDw3MywnSmaTcE9/gV6sVlZbQkOSxnxooHzDwRo+1+g==", "dev": true, "license": "MIT", "bin": { @@ -998,9 +998,9 @@ } }, "node_modules/pm-ops": { - "version": "2026.9.23", - "resolved": "https://registry.npmjs.org/pm-ops/-/pm-ops-2026.9.23.tgz", - "integrity": "sha512-FglZHOXjsuG8WWf9Ca90/IX1u4ZCxVTvHpwMaiA0TAWBx/lLalM2Ic12gtWZvm3OAJsMMuXvfRBHWxwYLzESsg==", + "version": "2026.9.26", + "resolved": "https://registry.npmjs.org/pm-ops/-/pm-ops-2026.9.26.tgz", + "integrity": "sha512-X2z5lGodCa35DNgKLwhaA5kX+oHZjlgwz4lIhBQ7vsbynCPOBODZEMddcARgcH+gatWpLmhtmMcjrnAsyppnMg==", "dev": true, "license": "MIT", "dependencies": { diff --git a/package.json b/package.json index 5a5c2a0..b4bf83e 100644 --- a/package.json +++ b/package.json @@ -62,9 +62,9 @@ }, "devDependencies": { "@types/node": "^26.1.1", - "@unbrained/pm-cli": "2026.9.23", - "pm-changelog": "2026.9.23", - "pm-ops": "2026.9.23", + "@unbrained/pm-cli": "2026.9.27", + "pm-changelog": "2026.9.25", + "pm-ops": "2026.9.26", "typescript": "^7.0.2" }, "keywords": [ diff --git a/scripts/prepare-merge-driver.ts b/scripts/prepare-merge-driver.ts index 66e512e..336f1f0 100644 --- a/scripts/prepare-merge-driver.ts +++ b/scripts/prepare-merge-driver.ts @@ -7,13 +7,15 @@ * therefore imports nothing from pm-ops: it resolves the installer entry from * the package root and runs it in a child process. Only a missing pm-ops package skips, with one * notice; any other resolution failure (for example a pm-ops too old to export - * the entry) and any installer failure fail the install. + * the entry, or a `pm-ops` directory whose package.json is gone) and any + * installer failure fail the install. * * Canonical copy: `pm-ops/templates/prepare-merge-driver.ts`. Copy it * unchanged to `scripts/prepare-merge-driver.ts`. */ import { spawnSync } from "node:child_process"; +import { lstatSync } from "node:fs"; import { createRequire } from "node:module"; import { join } from "node:path"; @@ -26,12 +28,17 @@ try { // Only an absent pm-ops package may skip. Probing its package.json tells that // apart from an installed pm-ops that cannot serve the entry (exports without // it, no exports map, a missing file): those resolve or fail differently, and - // the original error is rethrown. + // the original error is rethrown. A probe that finds no package.json is not + // yet proof of absence: a broken install can leave `node_modules/pm-ops` (a + // directory or a dangling link) with no package.json, which fails the probe + // the same way, so an entry there also counts as present. let packagePresent = true; try { resolver.resolve("pm-ops/package.json"); } catch (probe) { - packagePresent = !(probe instanceof Error && "code" in probe && probe.code === "MODULE_NOT_FOUND"); + packagePresent = + !(probe instanceof Error && "code" in probe && probe.code === "MODULE_NOT_FOUND") || + lstatSync(join(process.cwd(), "node_modules", "pm-ops"), { throwIfNoEntry: false }) !== undefined; } if (packagePresent) throw error; } From 464877cd86403bd586aa6135d6573028a373ef0d Mon Sep 17 00:00:00 2001 From: SteveBot <1153461+unbraind@users.noreply.github.com> Date: Sun, 27 Sep 2026 10:19:26 +0200 Subject: [PATCH 2/8] Guard pm-jira issue sync and test broken merge-driver installs Address exact-head Greptile and CodeRabbit findings. Real child checkouts now assert incomplete and dangling pm-ops installs fail without silently skipping merge-driver registration. Keep the scheduled GitHub issue-sync job inert in its checked-in workflow until the separate fail-closed pre-push privacy gate is delivered. The complete package gate passes 174/174 with zero skips and strict PM health passes. --- .agents/pm/history/pm-jira-b0n8.jsonl | 5 +++++ .agents/pm/issues/pm-jira-b0n8.toon | 13 +++++++++---- .github/workflows/pm-github-sync.yml | 2 ++ test/prepare-merge-driver.test.ts | 21 +++++++++++++++++++-- 4 files changed, 35 insertions(+), 6 deletions(-) diff --git a/.agents/pm/history/pm-jira-b0n8.jsonl b/.agents/pm/history/pm-jira-b0n8.jsonl index 0e5e93a..e3cd66e 100644 --- a/.agents/pm/history/pm-jira-b0n8.jsonl +++ b/.agents/pm/history/pm-jira-b0n8.jsonl @@ -3,3 +3,8 @@ {"hash_algorithm":"sha256","ts":"2026-09-27T08:04:19.777Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"files_add","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:04:19.777Z"},{"op":"add","path":"/metadata/files","value":[{"path":".agents/pm/extensions/.managed-extensions.json","scope":"project","note":"Exact managed pm-github source"},{"path":".github/workflows/ci.yml","scope":"project","note":"CI installs pinned extension"},{"path":".github/workflows/pm-github-sync.yml","scope":"project","note":"Disabled sync installs pinned extension"},{"path":"package.json","scope":"project","note":"Published CLI and quality-tool pins"},{"path":"scripts/prepare-merge-driver.ts","scope":"project","note":"Published pm-ops launcher copy"}]}],"before_hash":"f0e2f9b70e71aa8ef5396b0eaf56389731d9f4e32b823823faf5e180776104e7","after_hash":"1590f46a217800b61bf23d08558da32b45c33de4ee5892c518b1df8d0b9852f2","item_hash_version":3,"message":"Link certification implementation files","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"9e98bf7c82da0dc1b0ea9fcd8ea41b671923b7288a9c1a74a18756c1fb665168"} {"hash_algorithm":"sha256","ts":"2026-09-27T08:04:20.927Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"tests_add","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:04:20.927Z"},{"op":"add","path":"/metadata/tests","value":[{"command":"npm run release:check","scope":"project","timeout_seconds":600,"provenance":{"author":"codex","created_at":"2026-09-27T08:04:20.900Z","source_kind":"local_mutation","source_ref":"fix/pm-jira-cli-2026-09-27-github-pin"}}]}],"before_hash":"1590f46a217800b61bf23d08558da32b45c33de4ee5892c518b1df8d0b9852f2","after_hash":"9ceb268ea1de55fe57716c9e5abeff6fa59f3aafc3f2db2bc94b6c0431672b70","item_hash_version":3,"message":"Link complete package release gate","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"b5c210d7c73193d6b1c6c5fd09b45c84f405d29211d7a186748742ef13024b8b"} {"hash_algorithm":"sha256","ts":"2026-09-27T08:04:22.372Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"note_add","patch":[{"op":"add","path":"/metadata/notes/1","value":{"created_at":"2026-09-27T08:04:22.372Z","author":"codex","text":"2026-09-27 08:04 UTC: Full local release gate passed after copying the exact published pm-ops 2026.9.26 launcher: 173/173 tests, zero skips, 100% measured lines/branches/functions across two production source files, 51/51 declarations documented, zero production audit vulnerabilities, current changelog and attestation checks. Strict PM health passes on CLI 2026.9.27 with stale_in_progress_items:1 advisory. A real pm-github 2026.9.26 project install activated and an open-issue dry run found no public Jira issues; no tracker import was applied. Scheduled sync remains disabled_manually pending pre-push privacy gating. GitHub CI, reviewer evidence, and statement coverage remain separate gates."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:04:22.372Z"}],"before_hash":"9ceb268ea1de55fe57716c9e5abeff6fa59f3aafc3f2db2bc94b6c0431672b70","after_hash":"d8ebcd77eaed0854b6c2d078f7c85ddc7374e6c2c3afacd9499444c03d4e90a8","item_hash_version":3,"message":"Record package gate and live extension dry-run evidence","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"2b1240f0563b00e441c66da7a0b75f2f9dcfe2b86d6d486c517946331795077f"} +{"hash_algorithm":"sha256","ts":"2026-09-27T08:10:16.028Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"tests_add","patch":[{"op":"add","path":"/metadata/tests/1","value":{"command":"node --test test/prepare-merge-driver.test.ts","scope":"project","timeout_seconds":120,"provenance":{"author":"codex","created_at":"2026-09-27T08:10:16.001Z","source_kind":"local_mutation","source_ref":"fix/pm-jira-cli-2026-09-27-github-pin"}}},{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:10:16.028Z"}],"before_hash":"d8ebcd77eaed0854b6c2d078f7c85ddc7374e6c2c3afacd9499444c03d4e90a8","after_hash":"e18e326908ccb90d8282f9bcfa39e9125486b5c55373c8a6e55deab606dfa404","item_hash_version":3,"message":"Link Greptile broken-install child-checkout regression","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"a5ac52115faabf48b886f9629b45264d34c5ea5e98a6b1f5c65d6d5d3394b044"} +{"hash_algorithm":"sha256","ts":"2026-09-27T08:10:16.839Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"files_add","patch":[{"op":"add","path":"/metadata/files/5","value":{"path":"test/prepare-merge-driver.test.ts","scope":"project","note":"Incomplete directory and dangling-link real child checkouts"}},{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:10:16.839Z"}],"before_hash":"e18e326908ccb90d8282f9bcfa39e9125486b5c55373c8a6e55deab606dfa404","after_hash":"67f84b3f3231470cbadeea2781fa003c12eb2fc1227b09c28768895c556f4f9e","item_hash_version":3,"message":"Link launcher regression file","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"5c36aea5d2f787ee55ba245c0293adf7cf1e6e524bf7e7454ca1e75a99902656"} +{"hash_algorithm":"sha256","ts":"2026-09-27T08:10:17.650Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"note_add","patch":[{"op":"add","path":"/metadata/notes/2","value":{"created_at":"2026-09-27T08:10:17.650Z","author":"codex","text":"2026-09-27: Greptile on PR #119 head d184a0c found the copied canonical launcher gained a broken-install branch without consumer regression coverage. The finding is valid. Added real child-checkout cases for an incomplete pm-ops directory and dangling link; both fail without the omit-dev notice and without merge drivers. Focused suite passes 7/7 with zero skips. Inline finding was voted and acknowledged; full release gate and exact-head rereview remain pending."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:10:17.650Z"}],"before_hash":"67f84b3f3231470cbadeea2781fa003c12eb2fc1227b09c28768895c556f4f9e","after_hash":"88f8779a6b94d6adb564580dc893f9b954d5f30029a87f4c58a51c58afbd1489","item_hash_version":3,"message":"Record Greptile launcher coverage finding and fix","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"0b6ee059113c3109e20cef45769f38d850c7df8d7b1483e8a26534fbe6967148"} +{"hash_algorithm":"sha256","ts":"2026-09-27T08:17:04.429Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"note_add","patch":[{"op":"add","path":"/metadata/notes/3","value":{"created_at":"2026-09-27T08:17:04.429Z","author":"codex","text":"2026-09-27: CodeRabbit on PR #119 head d184a0c found the disabled GitHub issue-sync workflow still had runnable schedule/manual triggers and write permissions if re-enabled before a fail-closed imported-content privacy gate. The finding is valid. Added a checked-in job-level if: false guard and confirmed GitHub workflow remains disabled_manually. The same defense is being added to the pm-graph and pm-todos pilot candidates. This does not implement the privacy gate or authorize enabling sync. Review was voted and answered inline; full release gate and new-head CI/review remain pending."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:17:04.429Z"}],"before_hash":"88f8779a6b94d6adb564580dc893f9b954d5f30029a87f4c58a51c58afbd1489","after_hash":"c20d1e8b3fb0c5a3df42e19fddad4b1adcd63bbaecab7aaf8d879013f99621cd","item_hash_version":3,"message":"Record CodeRabbit privacy guard finding and fix","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"2b17d8b4a40114354f9a1acfa33be10ac3f52f54e4fed61c96cdfd0eefd85f7d"} +{"hash_algorithm":"sha256","ts":"2026-09-27T08:19:09.910Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"note_add","patch":[{"op":"add","path":"/metadata/notes/4","value":{"created_at":"2026-09-27T08:19:09.910Z","author":"codex","text":"2026-09-27 08:19 UTC: After both first-head review fixes, the full npm run release:check gate passes 174/174 tests with zero skips; measured lines/branches/functions are 100/100/100, 51/51 declarations documented, and production audit reports zero vulnerabilities. The real child-checkout launcher suite passes 7/7. The scheduled issue-sync job has a checked-in if: false guard, and GitHub API still reports disabled_manually. The separate content privacy gate, statement coverage, GitHub CI, and fresh exact-head bot reviews remain open."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:19:09.910Z"}],"before_hash":"c20d1e8b3fb0c5a3df42e19fddad4b1adcd63bbaecab7aaf8d879013f99621cd","after_hash":"46116edd26303c7bea561cebdfd445120ce215cdd6d213ee581a8dcd8ed75f9e","item_hash_version":3,"message":"Record full gate after Greptile and CodeRabbit review fixes","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"cbacfe065783cd9ce9c9828141eb59857a4418b85108ae402dff246b190255b6"} diff --git a/.agents/pm/issues/pm-jira-b0n8.toon b/.agents/pm/issues/pm-jira-b0n8.toon index 8024eba..a926c3e 100644 --- a/.agents/pm/issues/pm-jira-b0n8.toon +++ b/.agents/pm/issues/pm-jira-b0n8.toon @@ -6,22 +6,27 @@ status: in_progress priority: 1 tags[3]: agent-ux,"area:github","area:release" created_at: "2026-09-27T08:01:14.699Z" -updated_at: "2026-09-27T08:04:22.372Z" +updated_at: "2026-09-27T08:19:09.910Z" assignee: codex author: codex acceptance_criteria: "Exact package/lock pins for current CLI, pm-ops, and pm-changelog; tracked managed pm-github 2026.9.26; local strict health and full release gate pass; CI uses exact source; disabled sync stays disabled; staged privacy scan and exact-head review complete." repro_steps: "Run pm health --strict-exit --json on main with host CLI 2026.9.27; observe extension_host_pm_cli_version_skew. Inspect both workflows for npm:pm-github without a version and the npm 10 / manifest-rewrite steps." expected_result: Strict health passes with the project-local CLI/SDK 2026.9.27; both workflows install exact pm-github 2026.9.26; the package release gate passes; the sync workflow stays disabled until a separate pre-push privacy gate exists. actual_result: Main reports SDK-link skew and both workflow installs can drift to future unreviewed extension versions. -notes[2]{created_at,author,text}: +notes[5]{created_at,author,text}: "2026-09-27T08:02:51.137Z",codex,"2026-09-27: First full release gate failed at the package launcher byte-identity assertion after upgrading published pm-ops to 2026.9.26. Copied the exact canonical launcher from installed pm-ops 2026.9.26 to scripts/prepare-merge-driver.ts; this includes its broken local-install guard. The full gate must rerun. The disabled GitHub sync workflow remains disabled." "2026-09-27T08:04:22.372Z",codex,"2026-09-27 08:04 UTC: Full local release gate passed after copying the exact published pm-ops 2026.9.26 launcher: 173/173 tests, zero skips, 100% measured lines/branches/functions across two production source files, 51/51 declarations documented, zero production audit vulnerabilities, current changelog and attestation checks. Strict PM health passes on CLI 2026.9.27 with stale_in_progress_items:1 advisory. A real pm-github 2026.9.26 project install activated and an open-issue dry run found no public Jira issues; no tracker import was applied. Scheduled sync remains disabled_manually pending pre-push privacy gating. GitHub CI, reviewer evidence, and statement coverage remain separate gates." -files[5]{path,scope,note}: + "2026-09-27T08:10:17.650Z",codex,"2026-09-27: Greptile on PR #119 head d184a0c found the copied canonical launcher gained a broken-install branch without consumer regression coverage. The finding is valid. Added real child-checkout cases for an incomplete pm-ops directory and dangling link; both fail without the omit-dev notice and without merge drivers. Focused suite passes 7/7 with zero skips. Inline finding was voted and acknowledged; full release gate and exact-head rereview remain pending." + "2026-09-27T08:17:04.429Z",codex,"2026-09-27: CodeRabbit on PR #119 head d184a0c found the disabled GitHub issue-sync workflow still had runnable schedule/manual triggers and write permissions if re-enabled before a fail-closed imported-content privacy gate. The finding is valid. Added a checked-in job-level if: false guard and confirmed GitHub workflow remains disabled_manually. The same defense is being added to the pm-graph and pm-todos pilot candidates. This does not implement the privacy gate or authorize enabling sync. Review was voted and answered inline; full release gate and new-head CI/review remain pending." + "2026-09-27T08:19:09.910Z",codex,"2026-09-27 08:19 UTC: After both first-head review fixes, the full npm run release:check gate passes 174/174 tests with zero skips; measured lines/branches/functions are 100/100/100, 51/51 declarations documented, and production audit reports zero vulnerabilities. The real child-checkout launcher suite passes 7/7. The scheduled issue-sync job has a checked-in if: false guard, and GitHub API still reports disabled_manually. The separate content privacy gate, statement coverage, GitHub CI, and fresh exact-head bot reviews remain open." +files[6]{path,scope,note}: .agents/pm/extensions/.managed-extensions.json,project,Exact managed pm-github source .github/workflows/ci.yml,project,CI installs pinned extension .github/workflows/pm-github-sync.yml,project,Disabled sync installs pinned extension package.json,project,Published CLI and quality-tool pins scripts/prepare-merge-driver.ts,project,Published pm-ops launcher copy -tests[1]{command,scope,timeout_seconds,provenance{author,created_at,source_kind,source_ref}}: + test/prepare-merge-driver.test.ts,project,Incomplete directory and dangling-link real child checkouts +tests[2]{command,scope,timeout_seconds,provenance{author,created_at,source_kind,source_ref}}: "npm run release:check",project,600,codex,"2026-09-27T08:04:20.900Z",local_mutation,fix/pm-jira-cli-2026-09-27-github-pin + node --test test/prepare-merge-driver.test.ts,project,120,codex,"2026-09-27T08:10:16.001Z",local_mutation,fix/pm-jira-cli-2026-09-27-github-pin body: "" diff --git a/.github/workflows/pm-github-sync.yml b/.github/workflows/pm-github-sync.yml index 869ecfd..80da7d2 100644 --- a/.github/workflows/pm-github-sync.yml +++ b/.github/workflows/pm-github-sync.yml @@ -15,6 +15,8 @@ concurrency: jobs: sync: + # Imported issue bodies need a fail-closed pre-push privacy gate first. + if: ${{ false }} runs-on: ubuntu-latest env: GH_TOKEN: ${{ github.token }} diff --git a/test/prepare-merge-driver.test.ts b/test/prepare-merge-driver.test.ts index c3bb230..e2760c8 100644 --- a/test/prepare-merge-driver.test.ts +++ b/test/prepare-merge-driver.test.ts @@ -33,9 +33,9 @@ const declaredDrivers = [ * Create a consumer checkout: a fresh Git repository carrying this * repository's `.gitattributes` and tracker settings. `pmOps` selects what * `node_modules/pm-ops` is: absent (an omit-dev install), the pinned package, - * or a stale pm-ops whose exports predate the launcher entry. + * a stale package, an incomplete directory, or a dangling directory link. */ -function checkout(name: string, pmOps: "absent" | "pinned" | "stale"): string { +function checkout(name: string, pmOps: "absent" | "pinned" | "stale" | "incomplete" | "dangling"): string { const directory = join(scratch, name); mkdirSync(join(directory, ".agents", "pm"), { recursive: true }); assert.equal(spawnSync("git", ["init", "-q"], { cwd: directory }).status, 0); @@ -53,6 +53,13 @@ function checkout(name: string, pmOps: "absent" | "pinned" | "stale"): string { JSON.stringify({ name: "pm-ops", type: "module", exports: { "./merge-driver": "./merge-driver.js" } }), ); } + if (pmOps === "incomplete") { + mkdirSync(join(directory, "node_modules", "pm-ops"), { recursive: true }); + } + if (pmOps === "dangling") { + mkdirSync(join(directory, "node_modules"), { recursive: true }); + symlinkSync(join(directory, "missing-pm-ops"), join(directory, "node_modules", "pm-ops"), "dir"); + } return directory; } @@ -109,6 +116,16 @@ test("a pm-ops too old to export the launcher entry fails the install", posixOnl assert.match(result.stderr, /ERR_PACKAGE_PATH_NOT_EXPORTED/); }); +test("incomplete and dangling pm-ops installs fail without silently skipping merge drivers", posixOnly, () => { + for (const variant of ["incomplete", "dangling"] as const) { + const directory = checkout(variant, variant); + const result = prepare(directory, hostPath); + assert.notEqual(result.status, 0, `${variant} install was treated as absent`); + assert.doesNotMatch(result.stderr, /is not installed \(omit-dev install\)/); + assert.deepEqual(registeredDrivers(directory), []); + } +}); + test("a failing pm merge install fails the install with the same status", posixOnly, () => { const result = prepare(checkout("failing-pm", "pinned"), stubPm("failing-pm", 7)); assert.equal(result.status, 7, result.stderr); From 7af5dc5277a8b858835ac9b4681dd1d6049da59e Mon Sep 17 00:00:00 2001 From: SteveBot <1153461+unbraind@users.noreply.github.com> Date: Sun, 27 Sep 2026 10:36:24 +0200 Subject: [PATCH 3/8] Track canonical hoisted launcher release blocker in pm-jira Link the package PM issue to pm-ops ops-jzp5 and PR #124 after a downstream Greptile P1 proved the published launcher can miss an incomplete hoisted installation. Keep this consumer PR open until the canonical fix is published, pinned, and retested. --- .agents/pm/history/pm-jira-b0n8.jsonl | 1 + .agents/pm/issues/pm-jira-b0n8.toon | 8 ++++++-- 2 files changed, 7 insertions(+), 2 deletions(-) diff --git a/.agents/pm/history/pm-jira-b0n8.jsonl b/.agents/pm/history/pm-jira-b0n8.jsonl index e3cd66e..2089305 100644 --- a/.agents/pm/history/pm-jira-b0n8.jsonl +++ b/.agents/pm/history/pm-jira-b0n8.jsonl @@ -8,3 +8,4 @@ {"hash_algorithm":"sha256","ts":"2026-09-27T08:10:17.650Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"note_add","patch":[{"op":"add","path":"/metadata/notes/2","value":{"created_at":"2026-09-27T08:10:17.650Z","author":"codex","text":"2026-09-27: Greptile on PR #119 head d184a0c found the copied canonical launcher gained a broken-install branch without consumer regression coverage. The finding is valid. Added real child-checkout cases for an incomplete pm-ops directory and dangling link; both fail without the omit-dev notice and without merge drivers. Focused suite passes 7/7 with zero skips. Inline finding was voted and acknowledged; full release gate and exact-head rereview remain pending."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:10:17.650Z"}],"before_hash":"67f84b3f3231470cbadeea2781fa003c12eb2fc1227b09c28768895c556f4f9e","after_hash":"88f8779a6b94d6adb564580dc893f9b954d5f30029a87f4c58a51c58afbd1489","item_hash_version":3,"message":"Record Greptile launcher coverage finding and fix","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"0b6ee059113c3109e20cef45769f38d850c7df8d7b1483e8a26534fbe6967148"} {"hash_algorithm":"sha256","ts":"2026-09-27T08:17:04.429Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"note_add","patch":[{"op":"add","path":"/metadata/notes/3","value":{"created_at":"2026-09-27T08:17:04.429Z","author":"codex","text":"2026-09-27: CodeRabbit on PR #119 head d184a0c found the disabled GitHub issue-sync workflow still had runnable schedule/manual triggers and write permissions if re-enabled before a fail-closed imported-content privacy gate. The finding is valid. Added a checked-in job-level if: false guard and confirmed GitHub workflow remains disabled_manually. The same defense is being added to the pm-graph and pm-todos pilot candidates. This does not implement the privacy gate or authorize enabling sync. Review was voted and answered inline; full release gate and new-head CI/review remain pending."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:17:04.429Z"}],"before_hash":"88f8779a6b94d6adb564580dc893f9b954d5f30029a87f4c58a51c58afbd1489","after_hash":"c20d1e8b3fb0c5a3df42e19fddad4b1adcd63bbaecab7aaf8d879013f99621cd","item_hash_version":3,"message":"Record CodeRabbit privacy guard finding and fix","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"2b17d8b4a40114354f9a1acfa33be10ac3f52f54e4fed61c96cdfd0eefd85f7d"} {"hash_algorithm":"sha256","ts":"2026-09-27T08:19:09.910Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"note_add","patch":[{"op":"add","path":"/metadata/notes/4","value":{"created_at":"2026-09-27T08:19:09.910Z","author":"codex","text":"2026-09-27 08:19 UTC: After both first-head review fixes, the full npm run release:check gate passes 174/174 tests with zero skips; measured lines/branches/functions are 100/100/100, 51/51 declarations documented, and production audit reports zero vulnerabilities. The real child-checkout launcher suite passes 7/7. The scheduled issue-sync job has a checked-in if: false guard, and GitHub API still reports disabled_manually. The separate content privacy gate, statement coverage, GitHub CI, and fresh exact-head bot reviews remain open."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:19:09.910Z"}],"before_hash":"c20d1e8b3fb0c5a3df42e19fddad4b1adcd63bbaecab7aaf8d879013f99621cd","after_hash":"46116edd26303c7bea561cebdfd445120ce215cdd6d213ee581a8dcd8ed75f9e","item_hash_version":3,"message":"Record full gate after Greptile and CodeRabbit review fixes","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"cbacfe065783cd9ce9c9828141eb59857a4418b85108ae402dff246b190255b6"} +{"hash_algorithm":"sha256","ts":"2026-09-27T08:35:53.489Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"update","patch":[{"op":"add","path":"/metadata/notes/5","value":{"created_at":"2026-09-27T08:35:53.468Z","author":"codex","text":"2026-09-27 downstream Greptile P1 on pm-todos #103 revealed the published pm-ops 2026.9.26 launcher copied here misses incomplete hoisted installs in ancestor node_modules. Canonical source issue ops-jzp5 and unmerged pm-ops #124 already fix and test this path. This PR is blocked until the reviewed source is published, this package pins and copies its new template byte for byte, full release gate and strict health pass, and exact-head bot review repeats. Earlier green CI/Greptile status does not certify this edge case."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:35:53.489Z"},{"op":"add","path":"/metadata/docs","value":[{"path":"https://github.com/unbraind/pm-ops/blob/main/.agents/pm/issues/ops-jzp5.toon","scope":"global","note":"Canonical hoisted broken-install source issue"},{"path":"https://github.com/unbraind/pm-ops/pull/124","scope":"global","note":"Canonical source fix candidate pending publication"}]}],"before_hash":"46116edd26303c7bea561cebdfd445120ce215cdd6d213ee581a8dcd8ed75f9e","after_hash":"32eda260943e9b20beab1aff66d36f8d65518a6f8b4708c5baf6b3b1afaadc70","item_hash_version":3,"message":"Track valid downstream hoisted-launcher blocker","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"1acd24c02bf8c1f62198e2c78148c0a840e38dcee299218369aca2b25263ba32"} diff --git a/.agents/pm/issues/pm-jira-b0n8.toon b/.agents/pm/issues/pm-jira-b0n8.toon index a926c3e..968b878 100644 --- a/.agents/pm/issues/pm-jira-b0n8.toon +++ b/.agents/pm/issues/pm-jira-b0n8.toon @@ -6,19 +6,20 @@ status: in_progress priority: 1 tags[3]: agent-ux,"area:github","area:release" created_at: "2026-09-27T08:01:14.699Z" -updated_at: "2026-09-27T08:19:09.910Z" +updated_at: "2026-09-27T08:35:53.489Z" assignee: codex author: codex acceptance_criteria: "Exact package/lock pins for current CLI, pm-ops, and pm-changelog; tracked managed pm-github 2026.9.26; local strict health and full release gate pass; CI uses exact source; disabled sync stays disabled; staged privacy scan and exact-head review complete." repro_steps: "Run pm health --strict-exit --json on main with host CLI 2026.9.27; observe extension_host_pm_cli_version_skew. Inspect both workflows for npm:pm-github without a version and the npm 10 / manifest-rewrite steps." expected_result: Strict health passes with the project-local CLI/SDK 2026.9.27; both workflows install exact pm-github 2026.9.26; the package release gate passes; the sync workflow stays disabled until a separate pre-push privacy gate exists. actual_result: Main reports SDK-link skew and both workflow installs can drift to future unreviewed extension versions. -notes[5]{created_at,author,text}: +notes[6]{created_at,author,text}: "2026-09-27T08:02:51.137Z",codex,"2026-09-27: First full release gate failed at the package launcher byte-identity assertion after upgrading published pm-ops to 2026.9.26. Copied the exact canonical launcher from installed pm-ops 2026.9.26 to scripts/prepare-merge-driver.ts; this includes its broken local-install guard. The full gate must rerun. The disabled GitHub sync workflow remains disabled." "2026-09-27T08:04:22.372Z",codex,"2026-09-27 08:04 UTC: Full local release gate passed after copying the exact published pm-ops 2026.9.26 launcher: 173/173 tests, zero skips, 100% measured lines/branches/functions across two production source files, 51/51 declarations documented, zero production audit vulnerabilities, current changelog and attestation checks. Strict PM health passes on CLI 2026.9.27 with stale_in_progress_items:1 advisory. A real pm-github 2026.9.26 project install activated and an open-issue dry run found no public Jira issues; no tracker import was applied. Scheduled sync remains disabled_manually pending pre-push privacy gating. GitHub CI, reviewer evidence, and statement coverage remain separate gates." "2026-09-27T08:10:17.650Z",codex,"2026-09-27: Greptile on PR #119 head d184a0c found the copied canonical launcher gained a broken-install branch without consumer regression coverage. The finding is valid. Added real child-checkout cases for an incomplete pm-ops directory and dangling link; both fail without the omit-dev notice and without merge drivers. Focused suite passes 7/7 with zero skips. Inline finding was voted and acknowledged; full release gate and exact-head rereview remain pending." "2026-09-27T08:17:04.429Z",codex,"2026-09-27: CodeRabbit on PR #119 head d184a0c found the disabled GitHub issue-sync workflow still had runnable schedule/manual triggers and write permissions if re-enabled before a fail-closed imported-content privacy gate. The finding is valid. Added a checked-in job-level if: false guard and confirmed GitHub workflow remains disabled_manually. The same defense is being added to the pm-graph and pm-todos pilot candidates. This does not implement the privacy gate or authorize enabling sync. Review was voted and answered inline; full release gate and new-head CI/review remain pending." "2026-09-27T08:19:09.910Z",codex,"2026-09-27 08:19 UTC: After both first-head review fixes, the full npm run release:check gate passes 174/174 tests with zero skips; measured lines/branches/functions are 100/100/100, 51/51 declarations documented, and production audit reports zero vulnerabilities. The real child-checkout launcher suite passes 7/7. The scheduled issue-sync job has a checked-in if: false guard, and GitHub API still reports disabled_manually. The separate content privacy gate, statement coverage, GitHub CI, and fresh exact-head bot reviews remain open." + "2026-09-27T08:35:53.468Z",codex,"2026-09-27 downstream Greptile P1 on pm-todos #103 revealed the published pm-ops 2026.9.26 launcher copied here misses incomplete hoisted installs in ancestor node_modules. Canonical source issue ops-jzp5 and unmerged pm-ops #124 already fix and test this path. This PR is blocked until the reviewed source is published, this package pins and copies its new template byte for byte, full release gate and strict health pass, and exact-head bot review repeats. Earlier green CI/Greptile status does not certify this edge case." files[6]{path,scope,note}: .agents/pm/extensions/.managed-extensions.json,project,Exact managed pm-github source .github/workflows/ci.yml,project,CI installs pinned extension @@ -29,4 +30,7 @@ files[6]{path,scope,note}: tests[2]{command,scope,timeout_seconds,provenance{author,created_at,source_kind,source_ref}}: "npm run release:check",project,600,codex,"2026-09-27T08:04:20.900Z",local_mutation,fix/pm-jira-cli-2026-09-27-github-pin node --test test/prepare-merge-driver.test.ts,project,120,codex,"2026-09-27T08:10:16.001Z",local_mutation,fix/pm-jira-cli-2026-09-27-github-pin +docs[2]{path,scope,note}: + "https://github.com/unbraind/pm-ops/blob/main/.agents/pm/issues/ops-jzp5.toon",global,Canonical hoisted broken-install source issue + "https://github.com/unbraind/pm-ops/pull/124",global,Canonical source fix candidate pending publication body: "" From d9b82032f084b658fe741504f07abab82cd97b87 Mon Sep 17 00:00:00 2001 From: SteveBot <1153461+unbraind@users.noreply.github.com> Date: Mon, 28 Sep 2026 08:02:10 +0200 Subject: [PATCH 4/8] Pin pm-ops 2026.9.28 and re-copy its merge-driver launcher pm-ops 2026.9.28 (pm-ops#124) fixes the guarded launcher's omit-dev skip: it now checks every directory Node resolves pm-ops from, so a hoisted pm-ops with no package.json fails the prepare step instead of being read as an omit-dev install that silently skips the field-aware merge drivers. scripts/prepare-merge-driver.ts is the published template byte for byte, as test/prepare-merge-driver.test.ts requires. Tracker: pm-jira-b0n8 (comment with evidence). release:check and changelog:check pass. --- .agents/pm/history/pm-jira-b0n8.jsonl | 1 + .agents/pm/issues/pm-jira-b0n8.toon | 4 +++- package-lock.json | 8 ++++---- package.json | 2 +- scripts/prepare-merge-driver.ts | 9 ++++++--- 5 files changed, 15 insertions(+), 9 deletions(-) diff --git a/.agents/pm/history/pm-jira-b0n8.jsonl b/.agents/pm/history/pm-jira-b0n8.jsonl index 2089305..a61efe7 100644 --- a/.agents/pm/history/pm-jira-b0n8.jsonl +++ b/.agents/pm/history/pm-jira-b0n8.jsonl @@ -9,3 +9,4 @@ {"hash_algorithm":"sha256","ts":"2026-09-27T08:17:04.429Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"note_add","patch":[{"op":"add","path":"/metadata/notes/3","value":{"created_at":"2026-09-27T08:17:04.429Z","author":"codex","text":"2026-09-27: CodeRabbit on PR #119 head d184a0c found the disabled GitHub issue-sync workflow still had runnable schedule/manual triggers and write permissions if re-enabled before a fail-closed imported-content privacy gate. The finding is valid. Added a checked-in job-level if: false guard and confirmed GitHub workflow remains disabled_manually. The same defense is being added to the pm-graph and pm-todos pilot candidates. This does not implement the privacy gate or authorize enabling sync. Review was voted and answered inline; full release gate and new-head CI/review remain pending."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:17:04.429Z"}],"before_hash":"88f8779a6b94d6adb564580dc893f9b954d5f30029a87f4c58a51c58afbd1489","after_hash":"c20d1e8b3fb0c5a3df42e19fddad4b1adcd63bbaecab7aaf8d879013f99621cd","item_hash_version":3,"message":"Record CodeRabbit privacy guard finding and fix","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"2b17d8b4a40114354f9a1acfa33be10ac3f52f54e4fed61c96cdfd0eefd85f7d"} {"hash_algorithm":"sha256","ts":"2026-09-27T08:19:09.910Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"note_add","patch":[{"op":"add","path":"/metadata/notes/4","value":{"created_at":"2026-09-27T08:19:09.910Z","author":"codex","text":"2026-09-27 08:19 UTC: After both first-head review fixes, the full npm run release:check gate passes 174/174 tests with zero skips; measured lines/branches/functions are 100/100/100, 51/51 declarations documented, and production audit reports zero vulnerabilities. The real child-checkout launcher suite passes 7/7. The scheduled issue-sync job has a checked-in if: false guard, and GitHub API still reports disabled_manually. The separate content privacy gate, statement coverage, GitHub CI, and fresh exact-head bot reviews remain open."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:19:09.910Z"}],"before_hash":"c20d1e8b3fb0c5a3df42e19fddad4b1adcd63bbaecab7aaf8d879013f99621cd","after_hash":"46116edd26303c7bea561cebdfd445120ce215cdd6d213ee581a8dcd8ed75f9e","item_hash_version":3,"message":"Record full gate after Greptile and CodeRabbit review fixes","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"cbacfe065783cd9ce9c9828141eb59857a4418b85108ae402dff246b190255b6"} {"hash_algorithm":"sha256","ts":"2026-09-27T08:35:53.489Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"update","patch":[{"op":"add","path":"/metadata/notes/5","value":{"created_at":"2026-09-27T08:35:53.468Z","author":"codex","text":"2026-09-27 downstream Greptile P1 on pm-todos #103 revealed the published pm-ops 2026.9.26 launcher copied here misses incomplete hoisted installs in ancestor node_modules. Canonical source issue ops-jzp5 and unmerged pm-ops #124 already fix and test this path. This PR is blocked until the reviewed source is published, this package pins and copies its new template byte for byte, full release gate and strict health pass, and exact-head bot review repeats. Earlier green CI/Greptile status does not certify this edge case."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:35:53.489Z"},{"op":"add","path":"/metadata/docs","value":[{"path":"https://github.com/unbraind/pm-ops/blob/main/.agents/pm/issues/ops-jzp5.toon","scope":"global","note":"Canonical hoisted broken-install source issue"},{"path":"https://github.com/unbraind/pm-ops/pull/124","scope":"global","note":"Canonical source fix candidate pending publication"}]}],"before_hash":"46116edd26303c7bea561cebdfd445120ce215cdd6d213ee581a8dcd8ed75f9e","after_hash":"32eda260943e9b20beab1aff66d36f8d65518a6f8b4708c5baf6b3b1afaadc70","item_hash_version":3,"message":"Track valid downstream hoisted-launcher blocker","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"1acd24c02bf8c1f62198e2c78148c0a840e38dcee299218369aca2b25263ba32"} +{"hash_algorithm":"sha256","ts":"2026-09-28T06:02:04.602Z","author":"claude-hub","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"acec329f9c06ecc0d6dbecd4","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":null,"topic":null,"version":{"value":"2.1.283","source":"probe"}},"op":"comment_add","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-09-28T06:02:04.602Z"},{"op":"add","path":"/metadata/comments","value":[{"created_at":"2026-09-28T06:02:04.601Z","author":"claude-hub","text":"2026-09-28: pinned pm-ops 2026.9.28 and re-copied its templates/prepare-merge-driver.ts (pm-ops#124: the omit-dev skip now checks every Node resolution path for an incomplete hoisted pm-ops, so a broken ancestor install fails instead of silently skipping the merge drivers). release:check and changelog:check pass on this branch."}]}],"before_hash":"32eda260943e9b20beab1aff66d36f8d65518a6f8b4708c5baf6b3b1afaadc70","after_hash":"91b616673006597cae3ee37d6a51521548062e86b1f2015a961d29e0c3d59a7e","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"a8015e8227401793caecfbaa50fdebaedfdba84a34cbba72225cef4bfa2b3b5e"} diff --git a/.agents/pm/issues/pm-jira-b0n8.toon b/.agents/pm/issues/pm-jira-b0n8.toon index 968b878..aa4b72f 100644 --- a/.agents/pm/issues/pm-jira-b0n8.toon +++ b/.agents/pm/issues/pm-jira-b0n8.toon @@ -6,13 +6,15 @@ status: in_progress priority: 1 tags[3]: agent-ux,"area:github","area:release" created_at: "2026-09-27T08:01:14.699Z" -updated_at: "2026-09-27T08:35:53.489Z" +updated_at: "2026-09-28T06:02:04.602Z" assignee: codex author: codex acceptance_criteria: "Exact package/lock pins for current CLI, pm-ops, and pm-changelog; tracked managed pm-github 2026.9.26; local strict health and full release gate pass; CI uses exact source; disabled sync stays disabled; staged privacy scan and exact-head review complete." repro_steps: "Run pm health --strict-exit --json on main with host CLI 2026.9.27; observe extension_host_pm_cli_version_skew. Inspect both workflows for npm:pm-github without a version and the npm 10 / manifest-rewrite steps." expected_result: Strict health passes with the project-local CLI/SDK 2026.9.27; both workflows install exact pm-github 2026.9.26; the package release gate passes; the sync workflow stays disabled until a separate pre-push privacy gate exists. actual_result: Main reports SDK-link skew and both workflow installs can drift to future unreviewed extension versions. +comments[1]{created_at,author,text}: + "2026-09-28T06:02:04.601Z",claude-hub,"2026-09-28: pinned pm-ops 2026.9.28 and re-copied its templates/prepare-merge-driver.ts (pm-ops#124: the omit-dev skip now checks every Node resolution path for an incomplete hoisted pm-ops, so a broken ancestor install fails instead of silently skipping the merge drivers). release:check and changelog:check pass on this branch." notes[6]{created_at,author,text}: "2026-09-27T08:02:51.137Z",codex,"2026-09-27: First full release gate failed at the package launcher byte-identity assertion after upgrading published pm-ops to 2026.9.26. Copied the exact canonical launcher from installed pm-ops 2026.9.26 to scripts/prepare-merge-driver.ts; this includes its broken local-install guard. The full gate must rerun. The disabled GitHub sync workflow remains disabled." "2026-09-27T08:04:22.372Z",codex,"2026-09-27 08:04 UTC: Full local release gate passed after copying the exact published pm-ops 2026.9.26 launcher: 173/173 tests, zero skips, 100% measured lines/branches/functions across two production source files, 51/51 declarations documented, zero production audit vulnerabilities, current changelog and attestation checks. Strict PM health passes on CLI 2026.9.27 with stale_in_progress_items:1 advisory. A real pm-github 2026.9.26 project install activated and an open-issue dry run found no public Jira issues; no tracker import was applied. Scheduled sync remains disabled_manually pending pre-push privacy gating. GitHub CI, reviewer evidence, and statement coverage remain separate gates." diff --git a/package-lock.json b/package-lock.json index 8e5bd7a..7b253ff 100644 --- a/package-lock.json +++ b/package-lock.json @@ -12,7 +12,7 @@ "@types/node": "^26.1.1", "@unbrained/pm-cli": "2026.9.27", "pm-changelog": "2026.9.25", - "pm-ops": "2026.9.26", + "pm-ops": "2026.9.28", "typescript": "^7.0.2" }, "engines": { @@ -998,9 +998,9 @@ } }, "node_modules/pm-ops": { - "version": "2026.9.26", - "resolved": "https://registry.npmjs.org/pm-ops/-/pm-ops-2026.9.26.tgz", - "integrity": "sha512-X2z5lGodCa35DNgKLwhaA5kX+oHZjlgwz4lIhBQ7vsbynCPOBODZEMddcARgcH+gatWpLmhtmMcjrnAsyppnMg==", + "version": "2026.9.28", + "resolved": "https://registry.npmjs.org/pm-ops/-/pm-ops-2026.9.28.tgz", + "integrity": "sha512-MjsVk6uGYz8X3OxVuBHuBUEjcoUb3ubqSCG/hWvYOlj8AI8gbc3IPsIUGfDECH6WYP63B8hYjvc6Ahv3DdbIyQ==", "dev": true, "license": "MIT", "dependencies": { diff --git a/package.json b/package.json index b4bf83e..921baa2 100644 --- a/package.json +++ b/package.json @@ -64,7 +64,7 @@ "@types/node": "^26.1.1", "@unbrained/pm-cli": "2026.9.27", "pm-changelog": "2026.9.25", - "pm-ops": "2026.9.26", + "pm-ops": "2026.9.28", "typescript": "^7.0.2" }, "keywords": [ diff --git a/scripts/prepare-merge-driver.ts b/scripts/prepare-merge-driver.ts index 336f1f0..728ece4 100644 --- a/scripts/prepare-merge-driver.ts +++ b/scripts/prepare-merge-driver.ts @@ -30,15 +30,18 @@ try { // it, no exports map, a missing file): those resolve or fail differently, and // the original error is rethrown. A probe that finds no package.json is not // yet proof of absence: a broken install can leave `node_modules/pm-ops` (a - // directory or a dangling link) with no package.json, which fails the probe - // the same way, so an entry there also counts as present. + // directory or a dangling link) with no package.json in any ancestor Node + // searches. Such an entry also counts as present. Node returns null paths + // only for built-in modules; pm-ops/package.json is a package specifier. let packagePresent = true; try { resolver.resolve("pm-ops/package.json"); } catch (probe) { packagePresent = !(probe instanceof Error && "code" in probe && probe.code === "MODULE_NOT_FOUND") || - lstatSync(join(process.cwd(), "node_modules", "pm-ops"), { throwIfNoEntry: false }) !== undefined; + resolver.resolve.paths("pm-ops/package.json")!.some( + (directory) => lstatSync(join(directory, "pm-ops"), { throwIfNoEntry: false }) !== undefined, + ); } if (packagePresent) throw error; } From 39409056e819fac1ccd2c0721594dc36d4aea360 Mon Sep 17 00:00:00 2001 From: SteveBot <1153461+unbraind@users.noreply.github.com> Date: Mon, 28 Sep 2026 08:32:27 +0200 Subject: [PATCH 5/8] Take over the certification item from the finished codex agent and align it with pm-ops 2026.9.28 The codex agent that opened this PR held the item's claim; its session has ended. With the user's approval (2026-09-28) claude-hub force-claimed it, and the reason is recorded in the item's history. Where the acceptance criteria or description still named pm-ops 2026.9.26, they now name 2026.9.28, the version this branch pins. --- .agents/pm/history/pm-jira-b0n8.jsonl | 1 + .agents/pm/issues/pm-jira-b0n8.toon | 5 +++-- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/.agents/pm/history/pm-jira-b0n8.jsonl b/.agents/pm/history/pm-jira-b0n8.jsonl index a61efe7..ba161b1 100644 --- a/.agents/pm/history/pm-jira-b0n8.jsonl +++ b/.agents/pm/history/pm-jira-b0n8.jsonl @@ -10,3 +10,4 @@ {"hash_algorithm":"sha256","ts":"2026-09-27T08:19:09.910Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"note_add","patch":[{"op":"add","path":"/metadata/notes/4","value":{"created_at":"2026-09-27T08:19:09.910Z","author":"codex","text":"2026-09-27 08:19 UTC: After both first-head review fixes, the full npm run release:check gate passes 174/174 tests with zero skips; measured lines/branches/functions are 100/100/100, 51/51 declarations documented, and production audit reports zero vulnerabilities. The real child-checkout launcher suite passes 7/7. The scheduled issue-sync job has a checked-in if: false guard, and GitHub API still reports disabled_manually. The separate content privacy gate, statement coverage, GitHub CI, and fresh exact-head bot reviews remain open."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:19:09.910Z"}],"before_hash":"c20d1e8b3fb0c5a3df42e19fddad4b1adcd63bbaecab7aaf8d879013f99621cd","after_hash":"46116edd26303c7bea561cebdfd445120ce215cdd6d213ee581a8dcd8ed75f9e","item_hash_version":3,"message":"Record full gate after Greptile and CodeRabbit review fixes","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"cbacfe065783cd9ce9c9828141eb59857a4418b85108ae402dff246b190255b6"} {"hash_algorithm":"sha256","ts":"2026-09-27T08:35:53.489Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"update","patch":[{"op":"add","path":"/metadata/notes/5","value":{"created_at":"2026-09-27T08:35:53.468Z","author":"codex","text":"2026-09-27 downstream Greptile P1 on pm-todos #103 revealed the published pm-ops 2026.9.26 launcher copied here misses incomplete hoisted installs in ancestor node_modules. Canonical source issue ops-jzp5 and unmerged pm-ops #124 already fix and test this path. This PR is blocked until the reviewed source is published, this package pins and copies its new template byte for byte, full release gate and strict health pass, and exact-head bot review repeats. Earlier green CI/Greptile status does not certify this edge case."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:35:53.489Z"},{"op":"add","path":"/metadata/docs","value":[{"path":"https://github.com/unbraind/pm-ops/blob/main/.agents/pm/issues/ops-jzp5.toon","scope":"global","note":"Canonical hoisted broken-install source issue"},{"path":"https://github.com/unbraind/pm-ops/pull/124","scope":"global","note":"Canonical source fix candidate pending publication"}]}],"before_hash":"46116edd26303c7bea561cebdfd445120ce215cdd6d213ee581a8dcd8ed75f9e","after_hash":"32eda260943e9b20beab1aff66d36f8d65518a6f8b4708c5baf6b3b1afaadc70","item_hash_version":3,"message":"Track valid downstream hoisted-launcher blocker","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"1acd24c02bf8c1f62198e2c78148c0a840e38dcee299218369aca2b25263ba32"} {"hash_algorithm":"sha256","ts":"2026-09-28T06:02:04.602Z","author":"claude-hub","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"acec329f9c06ecc0d6dbecd4","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":null,"topic":null,"version":{"value":"2.1.283","source":"probe"}},"op":"comment_add","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-09-28T06:02:04.602Z"},{"op":"add","path":"/metadata/comments","value":[{"created_at":"2026-09-28T06:02:04.601Z","author":"claude-hub","text":"2026-09-28: pinned pm-ops 2026.9.28 and re-copied its templates/prepare-merge-driver.ts (pm-ops#124: the omit-dev skip now checks every Node resolution path for an incomplete hoisted pm-ops, so a broken ancestor install fails instead of silently skipping the merge drivers). release:check and changelog:check pass on this branch."}]}],"before_hash":"32eda260943e9b20beab1aff66d36f8d65518a6f8b4708c5baf6b3b1afaadc70","after_hash":"91b616673006597cae3ee37d6a51521548062e86b1f2015a961d29e0c3d59a7e","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"a8015e8227401793caecfbaa50fdebaedfdba84a34cbba72225cef4bfa2b3b5e"} +{"hash_algorithm":"sha256","ts":"2026-09-28T06:30:26.878Z","author":"claude-hub","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"acec329f9c06ecc0d6dbecd4","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.283","source":"probe"}},"op":"claim","patch":[{"op":"replace","path":"/metadata/assignee","value":"claude-hub"},{"op":"replace","path":"/metadata/updated_at","value":"2026-09-28T06:30:26.878Z"},{"op":"add","path":"/metadata/claim_principal","value":"claude-hub"}],"before_hash":"91b616673006597cae3ee37d6a51521548062e86b1f2015a961d29e0c3d59a7e","after_hash":"5bcf08d4fc166fbdd7602501806fed0c9549d7b962abe718b6cdf230c128d949","item_hash_version":3,"message":"Takeover approved by the user on 2026-09-28: the codex certify agent that held this claim (2026-09-26/27 session) is no longer running; claude-hub continues this item's PR.","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"23a07cd77dee78c8c8b6294ec9560b7de5c5efd5a2e470e6db99947b90a1b6db"} diff --git a/.agents/pm/issues/pm-jira-b0n8.toon b/.agents/pm/issues/pm-jira-b0n8.toon index aa4b72f..fd218aa 100644 --- a/.agents/pm/issues/pm-jira-b0n8.toon +++ b/.agents/pm/issues/pm-jira-b0n8.toon @@ -6,8 +6,9 @@ status: in_progress priority: 1 tags[3]: agent-ux,"area:github","area:release" created_at: "2026-09-27T08:01:14.699Z" -updated_at: "2026-09-28T06:02:04.602Z" -assignee: codex +updated_at: "2026-09-28T06:30:26.878Z" +assignee: claude-hub +claim_principal: claude-hub author: codex acceptance_criteria: "Exact package/lock pins for current CLI, pm-ops, and pm-changelog; tracked managed pm-github 2026.9.26; local strict health and full release gate pass; CI uses exact source; disabled sync stays disabled; staged privacy scan and exact-head review complete." repro_steps: "Run pm health --strict-exit --json on main with host CLI 2026.9.27; observe extension_host_pm_cli_version_skew. Inspect both workflows for npm:pm-github without a version and the npm 10 / manifest-rewrite steps." From acf6918a45adcac09177a5d6432fc19c4771750f Mon Sep 17 00:00:00 2001 From: SteveBot <1153461+unbraind@users.noreply.github.com> Date: Sat, 3 Oct 2026 01:14:10 +0200 Subject: [PATCH 6/8] docs(jira): record resumed PR #119 verification --- .agents/pm/history/pm-jira-b0n8.jsonl | 11 ++++++ .agents/pm/issues/pm-jira-b0n8.toon | 54 +++++++++++++++++++-------- 2 files changed, 49 insertions(+), 16 deletions(-) diff --git a/.agents/pm/history/pm-jira-b0n8.jsonl b/.agents/pm/history/pm-jira-b0n8.jsonl index ba161b1..6882e0a 100644 --- a/.agents/pm/history/pm-jira-b0n8.jsonl +++ b/.agents/pm/history/pm-jira-b0n8.jsonl @@ -11,3 +11,14 @@ {"hash_algorithm":"sha256","ts":"2026-09-27T08:35:53.489Z","author":"codex","author_source":"configured","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"fb64a4867f43e1382591a8cb","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"update","patch":[{"op":"add","path":"/metadata/notes/5","value":{"created_at":"2026-09-27T08:35:53.468Z","author":"codex","text":"2026-09-27 downstream Greptile P1 on pm-todos #103 revealed the published pm-ops 2026.9.26 launcher copied here misses incomplete hoisted installs in ancestor node_modules. Canonical source issue ops-jzp5 and unmerged pm-ops #124 already fix and test this path. This PR is blocked until the reviewed source is published, this package pins and copies its new template byte for byte, full release gate and strict health pass, and exact-head bot review repeats. Earlier green CI/Greptile status does not certify this edge case."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-09-27T08:35:53.489Z"},{"op":"add","path":"/metadata/docs","value":[{"path":"https://github.com/unbraind/pm-ops/blob/main/.agents/pm/issues/ops-jzp5.toon","scope":"global","note":"Canonical hoisted broken-install source issue"},{"path":"https://github.com/unbraind/pm-ops/pull/124","scope":"global","note":"Canonical source fix candidate pending publication"}]}],"before_hash":"46116edd26303c7bea561cebdfd445120ce215cdd6d213ee581a8dcd8ed75f9e","after_hash":"32eda260943e9b20beab1aff66d36f8d65518a6f8b4708c5baf6b3b1afaadc70","item_hash_version":3,"message":"Track valid downstream hoisted-launcher blocker","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"1acd24c02bf8c1f62198e2c78148c0a840e38dcee299218369aca2b25263ba32"} {"hash_algorithm":"sha256","ts":"2026-09-28T06:02:04.602Z","author":"claude-hub","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"acec329f9c06ecc0d6dbecd4","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":null,"topic":null,"version":{"value":"2.1.283","source":"probe"}},"op":"comment_add","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-09-28T06:02:04.602Z"},{"op":"add","path":"/metadata/comments","value":[{"created_at":"2026-09-28T06:02:04.601Z","author":"claude-hub","text":"2026-09-28: pinned pm-ops 2026.9.28 and re-copied its templates/prepare-merge-driver.ts (pm-ops#124: the omit-dev skip now checks every Node resolution path for an incomplete hoisted pm-ops, so a broken ancestor install fails instead of silently skipping the merge drivers). release:check and changelog:check pass on this branch."}]}],"before_hash":"32eda260943e9b20beab1aff66d36f8d65518a6f8b4708c5baf6b3b1afaadc70","after_hash":"91b616673006597cae3ee37d6a51521548062e86b1f2015a961d29e0c3d59a7e","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"a8015e8227401793caecfbaa50fdebaedfdba84a34cbba72225cef4bfa2b3b5e"} {"hash_algorithm":"sha256","ts":"2026-09-28T06:30:26.878Z","author":"claude-hub","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"acec329f9c06ecc0d6dbecd4","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.283","source":"probe"}},"op":"claim","patch":[{"op":"replace","path":"/metadata/assignee","value":"claude-hub"},{"op":"replace","path":"/metadata/updated_at","value":"2026-09-28T06:30:26.878Z"},{"op":"add","path":"/metadata/claim_principal","value":"claude-hub"}],"before_hash":"91b616673006597cae3ee37d6a51521548062e86b1f2015a961d29e0c3d59a7e","after_hash":"5bcf08d4fc166fbdd7602501806fed0c9549d7b962abe718b6cdf230c128d949","item_hash_version":3,"message":"Takeover approved by the user on 2026-09-28: the codex certify agent that held this claim (2026-09-26/27 session) is no longer running; claude-hub continues this item's PR.","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"23a07cd77dee78c8c8b6294ec9560b7de5c5efd5a2e470e6db99947b90a1b6db"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:13:21.486Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"claim","patch":[{"op":"replace","path":"/metadata/claim_principal","value":"codex-sol-land"},{"op":"replace","path":"/metadata/assignee","value":"codex-sol-land"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:13:21.486Z"}],"before_hash":"5bcf08d4fc166fbdd7602501806fed0c9549d7b962abe718b6cdf230c128d949","after_hash":"940ca46d41684a3a0416ce4ffb042e0823462320a5abe5d29b54f4f9a96d37d0","item_hash_version":3,"message":"Authorized restart of fleet PR preparation; earlier stopped-agent history and dispositions are retained.","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"fc68f003a012952ff0b736f682f3990ae508f0b6894a8873c640d9f8c5caacf9"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:13:22.459Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"comment_add","patch":[{"op":"add","path":"/metadata/comments/1","value":{"created_at":"2026-10-02T23:13:22.459Z","author":"codex-sol-land","text":"Resumed PR #119 from 39409056e819fac1ccd2c0721594dc36d4aea360. Rebase onto current main yields 39409056e819fac1ccd2c0721594dc36d4aea360. All existing bot artifacts and restart-era owner replies inspected; no new actionable finding. Preserve earlier fixes and technical refusals. Verifying unchanged CI gates under the shared heavy lock; no merge, release or closure."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:13:22.459Z"}],"before_hash":"940ca46d41684a3a0416ce4ffb042e0823462320a5abe5d29b54f4f9a96d37d0","after_hash":"bc19c819d67d2e380c041585e31ecd6e62ea1cf680f6cbbb53b5e35a58f7e3ad","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"6dfb1bbca0afd5b5c9f00248c4a7d3b355ba3c1ef4b82a89799d4732cc5b6fa9"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:13:23.098Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"files_add","patch":[{"op":"add","path":"/metadata/files/6","value":{"path":"test/release-workflow.test.ts","scope":"project"}},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:13:23.098Z"}],"before_hash":"bc19c819d67d2e380c041585e31ecd6e62ea1cf680f6cbbb53b5e35a58f7e3ad","after_hash":"43e96cc1940afdc6a3ddb68e64219e0447369d086438812ea0d8d08ddb0383ca","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"9022d915d0636bbae4eccac092878cb277a48f264dd2e16bbd5d552ab370ca35"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:13:23.750Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"docs_add","patch":[{"op":"add","path":"/metadata/docs/2","value":{"path":"https://github.com/unbraind/pm-jira/pull/119","scope":"project"}},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:13:23.750Z"}],"before_hash":"43e96cc1940afdc6a3ddb68e64219e0447369d086438812ea0d8d08ddb0383ca","after_hash":"9ef17d8e348656d133abf1530a2cd954c5befcf746efaf4eb20987bd8ddcd3c6","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"b37f7addeefabe736e042ac7979732bd9ebdac939650869f4e502aefb621e491"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:13:25.068Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"tests_add","patch":[{"op":"add","path":"/metadata/tests/2","value":{"command":"node --test test/release-workflow.test.ts","scope":"project","timeout_seconds":120,"provenance":{"author":"codex-sol-land","created_at":"2026-10-02T23:13:24.983Z","source_kind":"local_mutation","source_ref":"fix/pm-jira-cli-2026-09-27-github-pin"}}},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:13:25.068Z"}],"before_hash":"9ef17d8e348656d133abf1530a2cd954c5befcf746efaf4eb20987bd8ddcd3c6","after_hash":"94821b3ff7293ff26be2d932011b304a9f46c7263271f46e58016725a6afb82a","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"8a7c6fd49b170a92764beb3da952212c25511e8558fd894d6e7e8c24246e1d64"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:13:25.699Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"docs_add","patch":[{"op":"remove","path":"/metadata/docs/2"},{"op":"remove","path":"/metadata/docs/1/note"},{"op":"replace","path":"/metadata/docs/1/scope","value":"project"},{"op":"replace","path":"/metadata/docs/1/path","value":"https://github.com/unbraind/pm-jira/pull/119"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:13:25.699Z"}],"before_hash":"94821b3ff7293ff26be2d932011b304a9f46c7263271f46e58016725a6afb82a","after_hash":"63ea7772f73fc811a4517c60feca40fef80f2a15f796b3d5b4e019f2889851fa","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"3a71d6b9a6f3be0503914f0ebad640846d6eb47174efa894383386feb9394354"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:13:26.243Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"docs_add","patch":[{"op":"add","path":"/metadata/docs/1/note","value":"Already published canonical launcher source included in pinned pm-ops 2026.9.28"},{"op":"replace","path":"/metadata/docs/1/scope","value":"global"},{"op":"replace","path":"/metadata/docs/1/path","value":"https://github.com/unbraind/pm-ops/pull/124"},{"op":"add","path":"/metadata/docs/2","value":{"path":"https://github.com/unbraind/pm-jira/pull/119","scope":"project"}},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:13:26.243Z"}],"before_hash":"63ea7772f73fc811a4517c60feca40fef80f2a15f796b3d5b4e019f2889851fa","after_hash":"fef86de9c8b2613ffee08ecbb8567e3eec2dedbf7aa75f2c9c72783abb242d18","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"c175db464f91dccc7556630ea4f1d64050ae49807c997088d4f7b4b1950cf08e"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:13:26.769Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"comment_add","patch":[{"op":"add","path":"/metadata/comments/2","value":{"created_at":"2026-10-02T23:13:26.769Z","author":"codex-sol-land","text":"Corrected the linked source note: pm-ops#124 is already published in the pinned 2026.9.28 package, as the existing September 28 comment records. Preserve every dated note and append-only history line."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:13:26.769Z"}],"before_hash":"fef86de9c8b2613ffee08ecbb8567e3eec2dedbf7aa75f2c9c72783abb242d18","after_hash":"b4995691f0b1281f6ccac9eb8547b919e67668764bd1ecbf694d431ae86b5fe1","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"8b7b7820d5e37c8db1a8f31515f290cf390f296311f5c6d37037e2b8087f53b8"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:14:08.171Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"comment_add","patch":[{"op":"add","path":"/metadata/comments/3","value":{"created_at":"2026-10-02T23:14:08.171Z","author":"codex-sol-land","text":"Resumed verification: npm ci, current-base rebase, fresh committed-dist comparison, strict local tracker health with required merge drivers, npm run release:check, and bun install --no-save all passed. Full gate: 174 tests, 174 pass, 0 skips; configured coverage thresholds unchanged. PM-linked test/release-workflow.test.ts passed. Earlier findings and technical refusals retained; no new source fix was needed in this restart. Exact pushed-head CI and substantive reviewer availability remain separate checks; no merge, release, publication or item closure."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:14:08.171Z"}],"before_hash":"b4995691f0b1281f6ccac9eb8547b919e67668764bd1ecbf694d431ae86b5fe1","after_hash":"cb49aeaba2fbebceb5d798901299b915cb173c921205d7dc503717d43430c9e8","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"a65e0f0dd29ae01f4456a590743406281b15df368d67b026f367200494fc13e4"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:14:09.024Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"update","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:14:09.024Z"},{"op":"replace","path":"/metadata/status","value":"blocked"}],"before_hash":"cb49aeaba2fbebceb5d798901299b915cb173c921205d7dc503717d43430c9e8","after_hash":"ba803ee9c7dcea22d7325c812e2314d5c0d4106c3163df0767b3b8c4176d8fd0","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"fb07f80901449f1ac0886325285566b9b3150b93248b42e43b8b53d41d30013e"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:14:09.869Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"release","patch":[{"op":"remove","path":"/metadata/claim_principal"},{"op":"remove","path":"/metadata/assignee"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:14:09.869Z"}],"before_hash":"ba803ee9c7dcea22d7325c812e2314d5c0d4106c3163df0767b3b8c4176d8fd0","after_hash":"23502afac45178fd04f13df48c4eb5f2d51c57a1db8d3e37b7260f5708e3f639","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"dc90e59c84b2376bac2aa8514935036121d7e8ecdf6aed9ef3b74091679b48f7"} diff --git a/.agents/pm/issues/pm-jira-b0n8.toon b/.agents/pm/issues/pm-jira-b0n8.toon index fd218aa..c3386fb 100644 --- a/.agents/pm/issues/pm-jira-b0n8.toon +++ b/.agents/pm/issues/pm-jira-b0n8.toon @@ -2,20 +2,21 @@ id: pm-jira-b0n8 title: Certify pm-jira on CLI 2026.9.27 and pinned GitHub extension description: "The main checkout pins PM CLI, pm-ops, and pm-changelog 2026.9.23 and manages pm-github 2026.8.18. Host CLI 2026.9.27 reports extension SDK-link skew. CI and disabled scheduled sync install an unversioned extension through an obsolete npm 10 shim and rewrite its manifest. Align the package toolchain and tracked extension metadata with current published versions, and use the exact managed extension source in both workflows." type: Issue -status: in_progress +status: blocked priority: 1 tags[3]: agent-ux,"area:github","area:release" created_at: "2026-09-27T08:01:14.699Z" -updated_at: "2026-09-28T06:30:26.878Z" -assignee: claude-hub -claim_principal: claude-hub +updated_at: "2026-10-02T23:14:09.869Z" author: codex acceptance_criteria: "Exact package/lock pins for current CLI, pm-ops, and pm-changelog; tracked managed pm-github 2026.9.26; local strict health and full release gate pass; CI uses exact source; disabled sync stays disabled; staged privacy scan and exact-head review complete." repro_steps: "Run pm health --strict-exit --json on main with host CLI 2026.9.27; observe extension_host_pm_cli_version_skew. Inspect both workflows for npm:pm-github without a version and the npm 10 / manifest-rewrite steps." expected_result: Strict health passes with the project-local CLI/SDK 2026.9.27; both workflows install exact pm-github 2026.9.26; the package release gate passes; the sync workflow stays disabled until a separate pre-push privacy gate exists. actual_result: Main reports SDK-link skew and both workflow installs can drift to future unreviewed extension versions. -comments[1]{created_at,author,text}: +comments[4]{created_at,author,text}: "2026-09-28T06:02:04.601Z",claude-hub,"2026-09-28: pinned pm-ops 2026.9.28 and re-copied its templates/prepare-merge-driver.ts (pm-ops#124: the omit-dev skip now checks every Node resolution path for an incomplete hoisted pm-ops, so a broken ancestor install fails instead of silently skipping the merge drivers). release:check and changelog:check pass on this branch." + "2026-10-02T23:13:22.459Z",codex-sol-land,"Resumed PR #119 from 39409056e819fac1ccd2c0721594dc36d4aea360. Rebase onto current main yields 39409056e819fac1ccd2c0721594dc36d4aea360. All existing bot artifacts and restart-era owner replies inspected; no new actionable finding. Preserve earlier fixes and technical refusals. Verifying unchanged CI gates under the shared heavy lock; no merge, release or closure." + "2026-10-02T23:13:26.769Z",codex-sol-land,"Corrected the linked source note: pm-ops#124 is already published in the pinned 2026.9.28 package, as the existing September 28 comment records. Preserve every dated note and append-only history line." + "2026-10-02T23:14:08.171Z",codex-sol-land,"Resumed verification: npm ci, current-base rebase, fresh committed-dist comparison, strict local tracker health with required merge drivers, npm run release:check, and bun install --no-save all passed. Full gate: 174 tests, 174 pass, 0 skips; configured coverage thresholds unchanged. PM-linked test/release-workflow.test.ts passed. Earlier findings and technical refusals retained; no new source fix was needed in this restart. Exact pushed-head CI and substantive reviewer availability remain separate checks; no merge, release, publication or item closure." notes[6]{created_at,author,text}: "2026-09-27T08:02:51.137Z",codex,"2026-09-27: First full release gate failed at the package launcher byte-identity assertion after upgrading published pm-ops to 2026.9.26. Copied the exact canonical launcher from installed pm-ops 2026.9.26 to scripts/prepare-merge-driver.ts; this includes its broken local-install guard. The full gate must rerun. The disabled GitHub sync workflow remains disabled." "2026-09-27T08:04:22.372Z",codex,"2026-09-27 08:04 UTC: Full local release gate passed after copying the exact published pm-ops 2026.9.26 launcher: 173/173 tests, zero skips, 100% measured lines/branches/functions across two production source files, 51/51 declarations documented, zero production audit vulnerabilities, current changelog and attestation checks. Strict PM health passes on CLI 2026.9.27 with stale_in_progress_items:1 advisory. A real pm-github 2026.9.26 project install activated and an open-issue dry run found no public Jira issues; no tracker import was applied. Scheduled sync remains disabled_manually pending pre-push privacy gating. GitHub CI, reviewer evidence, and statement coverage remain separate gates." @@ -23,17 +24,38 @@ notes[6]{created_at,author,text}: "2026-09-27T08:17:04.429Z",codex,"2026-09-27: CodeRabbit on PR #119 head d184a0c found the disabled GitHub issue-sync workflow still had runnable schedule/manual triggers and write permissions if re-enabled before a fail-closed imported-content privacy gate. The finding is valid. Added a checked-in job-level if: false guard and confirmed GitHub workflow remains disabled_manually. The same defense is being added to the pm-graph and pm-todos pilot candidates. This does not implement the privacy gate or authorize enabling sync. Review was voted and answered inline; full release gate and new-head CI/review remain pending." "2026-09-27T08:19:09.910Z",codex,"2026-09-27 08:19 UTC: After both first-head review fixes, the full npm run release:check gate passes 174/174 tests with zero skips; measured lines/branches/functions are 100/100/100, 51/51 declarations documented, and production audit reports zero vulnerabilities. The real child-checkout launcher suite passes 7/7. The scheduled issue-sync job has a checked-in if: false guard, and GitHub API still reports disabled_manually. The separate content privacy gate, statement coverage, GitHub CI, and fresh exact-head bot reviews remain open." "2026-09-27T08:35:53.468Z",codex,"2026-09-27 downstream Greptile P1 on pm-todos #103 revealed the published pm-ops 2026.9.26 launcher copied here misses incomplete hoisted installs in ancestor node_modules. Canonical source issue ops-jzp5 and unmerged pm-ops #124 already fix and test this path. This PR is blocked until the reviewed source is published, this package pins and copies its new template byte for byte, full release gate and strict health pass, and exact-head bot review repeats. Earlier green CI/Greptile status does not certify this edge case." -files[6]{path,scope,note}: - .agents/pm/extensions/.managed-extensions.json,project,Exact managed pm-github source - .github/workflows/ci.yml,project,CI installs pinned extension - .github/workflows/pm-github-sync.yml,project,Disabled sync installs pinned extension - package.json,project,Published CLI and quality-tool pins - scripts/prepare-merge-driver.ts,project,Published pm-ops launcher copy - test/prepare-merge-driver.test.ts,project,Incomplete directory and dangling-link real child checkouts -tests[2]{command,scope,timeout_seconds,provenance{author,created_at,source_kind,source_ref}}: +files[7]: + - path: .agents/pm/extensions/.managed-extensions.json + scope: project + note: Exact managed pm-github source + - path: .github/workflows/ci.yml + scope: project + note: CI installs pinned extension + - path: .github/workflows/pm-github-sync.yml + scope: project + note: Disabled sync installs pinned extension + - path: package.json + scope: project + note: Published CLI and quality-tool pins + - path: scripts/prepare-merge-driver.ts + scope: project + note: Published pm-ops launcher copy + - path: test/prepare-merge-driver.test.ts + scope: project + note: Incomplete directory and dangling-link real child checkouts + - path: test/release-workflow.test.ts + scope: project +tests[3]{command,scope,timeout_seconds,provenance{author,created_at,source_kind,source_ref}}: "npm run release:check",project,600,codex,"2026-09-27T08:04:20.900Z",local_mutation,fix/pm-jira-cli-2026-09-27-github-pin node --test test/prepare-merge-driver.test.ts,project,120,codex,"2026-09-27T08:10:16.001Z",local_mutation,fix/pm-jira-cli-2026-09-27-github-pin -docs[2]{path,scope,note}: - "https://github.com/unbraind/pm-ops/blob/main/.agents/pm/issues/ops-jzp5.toon",global,Canonical hoisted broken-install source issue - "https://github.com/unbraind/pm-ops/pull/124",global,Canonical source fix candidate pending publication + node --test test/release-workflow.test.ts,project,120,codex-sol-land,"2026-10-02T23:13:24.983Z",local_mutation,fix/pm-jira-cli-2026-09-27-github-pin +docs[3]: + - path: "https://github.com/unbraind/pm-ops/blob/main/.agents/pm/issues/ops-jzp5.toon" + scope: global + note: Canonical hoisted broken-install source issue + - path: "https://github.com/unbraind/pm-ops/pull/124" + scope: global + note: Already published canonical launcher source included in pinned pm-ops 2026.9.28 + - path: "https://github.com/unbraind/pm-jira/pull/119" + scope: project body: "" From 2961c67f4ddac1b1f0aa222010e3cd51b5b4f658 Mon Sep 17 00:00:00 2001 From: SteveBot <1153461+unbraind@users.noreply.github.com> Date: Sat, 3 Oct 2026 01:37:35 +0200 Subject: [PATCH 7/8] docs(jira): record resumed PR #119 verification --- .agents/pm/history/pm-jira-b0n8.jsonl | 7 +++++++ .agents/pm/issues/pm-jira-b0n8.toon | 11 ++++++++--- 2 files changed, 15 insertions(+), 3 deletions(-) diff --git a/.agents/pm/history/pm-jira-b0n8.jsonl b/.agents/pm/history/pm-jira-b0n8.jsonl index 6882e0a..b127038 100644 --- a/.agents/pm/history/pm-jira-b0n8.jsonl +++ b/.agents/pm/history/pm-jira-b0n8.jsonl @@ -22,3 +22,10 @@ {"hash_algorithm":"sha256","ts":"2026-10-02T23:14:08.171Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"comment_add","patch":[{"op":"add","path":"/metadata/comments/3","value":{"created_at":"2026-10-02T23:14:08.171Z","author":"codex-sol-land","text":"Resumed verification: npm ci, current-base rebase, fresh committed-dist comparison, strict local tracker health with required merge drivers, npm run release:check, and bun install --no-save all passed. Full gate: 174 tests, 174 pass, 0 skips; configured coverage thresholds unchanged. PM-linked test/release-workflow.test.ts passed. Earlier findings and technical refusals retained; no new source fix was needed in this restart. Exact pushed-head CI and substantive reviewer availability remain separate checks; no merge, release, publication or item closure."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:14:08.171Z"}],"before_hash":"b4995691f0b1281f6ccac9eb8547b919e67668764bd1ecbf694d431ae86b5fe1","after_hash":"cb49aeaba2fbebceb5d798901299b915cb173c921205d7dc503717d43430c9e8","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"a65e0f0dd29ae01f4456a590743406281b15df368d67b026f367200494fc13e4"} {"hash_algorithm":"sha256","ts":"2026-10-02T23:14:09.024Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"update","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:14:09.024Z"},{"op":"replace","path":"/metadata/status","value":"blocked"}],"before_hash":"cb49aeaba2fbebceb5d798901299b915cb173c921205d7dc503717d43430c9e8","after_hash":"ba803ee9c7dcea22d7325c812e2314d5c0d4106c3163df0767b3b8c4176d8fd0","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"fb07f80901449f1ac0886325285566b9b3150b93248b42e43b8b53d41d30013e"} {"hash_algorithm":"sha256","ts":"2026-10-02T23:14:09.869Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"release","patch":[{"op":"remove","path":"/metadata/claim_principal"},{"op":"remove","path":"/metadata/assignee"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:14:09.869Z"}],"before_hash":"ba803ee9c7dcea22d7325c812e2314d5c0d4106c3163df0767b3b8c4176d8fd0","after_hash":"23502afac45178fd04f13df48c4eb5f2d51c57a1db8d3e37b7260f5708e3f639","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"dc90e59c84b2376bac2aa8514935036121d7e8ecdf6aed9ef3b74091679b48f7"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:28:05.443Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"claim","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:28:05.443Z"},{"op":"add","path":"/metadata/assignee","value":"codex-sol-land"},{"op":"add","path":"/metadata/claim_principal","value":"codex-sol-land"}],"before_hash":"23502afac45178fd04f13df48c4eb5f2d51c57a1db8d3e37b7260f5708e3f639","after_hash":"4a50664066b5abcccd05c89dd0722f11deb10608c69c0c32ed2fae90cf195bb9","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"8de7a1b4f56965aba3b6f95651e79f270d7ede15a79cd0ad68f8015e849077c6"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:28:06.180Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"update","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:28:06.180Z"},{"op":"replace","path":"/metadata/status","value":"in_progress"}],"before_hash":"4a50664066b5abcccd05c89dd0722f11deb10608c69c0c32ed2fae90cf195bb9","after_hash":"ee6dcbf2bbe8697b51f4d0557b00e8ac0d7eabd4687c6e2ae27aa7d89a127b30","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"0eee70e92a15e5f381510b9ba60e1ac0485069ac64214e9a2f4c31422f88cdda"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:28:07.013Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"comment_add","patch":[{"op":"add","path":"/metadata/comments/4","value":{"created_at":"2026-10-02T23:28:07.013Z","author":"codex-sol-land","text":"New Cubic finding 4170603509 is refused: Refused for this exact head: the completed Node 26 job used Node v26.10.0 and npm 11.19.1, not npm 12. Its real project-local pm package install of pm-github@2026.9.26, installed-version assertion, strict health and full CI gate all passed at acf6918. The statement that CI had not run is also contradicted by that completed job. Evidence: https://github.com/unbraind/pm-jira/actions/runs/37076601628/job/111067793577 . This is current-runner certification; no npm-12 certification is claimed and the obsolete npm-10 shim is not required for this verified job."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:28:07.013Z"}],"before_hash":"ee6dcbf2bbe8697b51f4d0557b00e8ac0d7eabd4687c6e2ae27aa7d89a127b30","after_hash":"c7d35b518103257ae2dc37f09bedbe1f0bcbd065573ba87101df12858b6672dc","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"adffc5e4b16552b7b27d832ad78be390fb1effe53f09561e3d1704e6221d2aa0"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:28:07.693Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"docs_add","patch":[{"op":"add","path":"/metadata/docs/2/note","value":"Already published canonical launcher source included in pinned pm-ops 2026.9.28"},{"op":"replace","path":"/metadata/docs/2/scope","value":"global"},{"op":"replace","path":"/metadata/docs/2/path","value":"https://github.com/unbraind/pm-ops/pull/124"},{"op":"replace","path":"/metadata/docs/1/note","value":"Canonical hoisted broken-install source issue"},{"op":"replace","path":"/metadata/docs/1/path","value":"https://github.com/unbraind/pm-ops/blob/main/.agents/pm/issues/ops-jzp5.toon"},{"op":"replace","path":"/metadata/docs/0/note","value":"Exact-head Node 26 CI proves bundled npm 11.19.1 and successful pinned extension installation"},{"op":"replace","path":"/metadata/docs/0/path","value":"https://github.com/unbraind/pm-jira/actions/runs/37076601628/job/111067793577"},{"op":"add","path":"/metadata/docs/3","value":{"path":"https://github.com/unbraind/pm-jira/pull/119","scope":"project"}},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:28:07.693Z"}],"before_hash":"c7d35b518103257ae2dc37f09bedbe1f0bcbd065573ba87101df12858b6672dc","after_hash":"0e35328eeba9ce2d000e6462c7f1ab87a1143a46f1f4919490cca2881318d901","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"1149b4329777567359a7782390d4e9109da707a606b751669c43b9e0c7dedee8"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:37:33.721Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"comment_add","patch":[{"op":"add","path":"/metadata/comments/5","value":{"created_at":"2026-10-02T23:37:33.721Z","author":"codex-sol-land","text":"Resumed verification: npm ci, current-base rebase, fresh committed-dist comparison, strict local tracker health with required merge drivers, npm run release:check, and bun install --no-save all passed. Full gate: 174 tests, 174 pass, 0 skips; configured coverage thresholds unchanged. PM-linked test/release-workflow.test.ts passed. Earlier findings and technical refusals retained; no new source fix was needed in this restart. Exact pushed-head CI and substantive reviewer availability remain separate checks; no merge, release, publication or item closure."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:37:33.721Z"}],"before_hash":"0e35328eeba9ce2d000e6462c7f1ab87a1143a46f1f4919490cca2881318d901","after_hash":"84377f3b21a7d3b7ca9d047d234dcde2531bb0f83ce117e723f8299ec3c7c738","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"a82832aeea7f8859e9bb9fb551d386d074f7994e92ea85562ee97f9a137dad6b"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:37:34.420Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"update","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:37:34.420Z"},{"op":"replace","path":"/metadata/status","value":"blocked"}],"before_hash":"84377f3b21a7d3b7ca9d047d234dcde2531bb0f83ce117e723f8299ec3c7c738","after_hash":"253dd2ccaf4d824dbd8fafb5d1e86e0907f07ab76dcf9da20df79f516adfe55c","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"367482fc58c26674b562f4ff46c58aae23700b50086fcd6054790ea884942c8a"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:37:35.133Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"release","patch":[{"op":"remove","path":"/metadata/claim_principal"},{"op":"remove","path":"/metadata/assignee"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:37:35.133Z"}],"before_hash":"253dd2ccaf4d824dbd8fafb5d1e86e0907f07ab76dcf9da20df79f516adfe55c","after_hash":"38997657ce3326d668d2f270d344c2cc7f597b1dbff9329950150fd3a2bc7088","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"c3bc3a5d858a05e7a912b81a7619a59a9129c9359de88b8ff9d0c7c5611796c1"} diff --git a/.agents/pm/issues/pm-jira-b0n8.toon b/.agents/pm/issues/pm-jira-b0n8.toon index c3386fb..a1808c1 100644 --- a/.agents/pm/issues/pm-jira-b0n8.toon +++ b/.agents/pm/issues/pm-jira-b0n8.toon @@ -6,17 +6,19 @@ status: blocked priority: 1 tags[3]: agent-ux,"area:github","area:release" created_at: "2026-09-27T08:01:14.699Z" -updated_at: "2026-10-02T23:14:09.869Z" +updated_at: "2026-10-02T23:37:35.133Z" author: codex acceptance_criteria: "Exact package/lock pins for current CLI, pm-ops, and pm-changelog; tracked managed pm-github 2026.9.26; local strict health and full release gate pass; CI uses exact source; disabled sync stays disabled; staged privacy scan and exact-head review complete." repro_steps: "Run pm health --strict-exit --json on main with host CLI 2026.9.27; observe extension_host_pm_cli_version_skew. Inspect both workflows for npm:pm-github without a version and the npm 10 / manifest-rewrite steps." expected_result: Strict health passes with the project-local CLI/SDK 2026.9.27; both workflows install exact pm-github 2026.9.26; the package release gate passes; the sync workflow stays disabled until a separate pre-push privacy gate exists. actual_result: Main reports SDK-link skew and both workflow installs can drift to future unreviewed extension versions. -comments[4]{created_at,author,text}: +comments[6]{created_at,author,text}: "2026-09-28T06:02:04.601Z",claude-hub,"2026-09-28: pinned pm-ops 2026.9.28 and re-copied its templates/prepare-merge-driver.ts (pm-ops#124: the omit-dev skip now checks every Node resolution path for an incomplete hoisted pm-ops, so a broken ancestor install fails instead of silently skipping the merge drivers). release:check and changelog:check pass on this branch." "2026-10-02T23:13:22.459Z",codex-sol-land,"Resumed PR #119 from 39409056e819fac1ccd2c0721594dc36d4aea360. Rebase onto current main yields 39409056e819fac1ccd2c0721594dc36d4aea360. All existing bot artifacts and restart-era owner replies inspected; no new actionable finding. Preserve earlier fixes and technical refusals. Verifying unchanged CI gates under the shared heavy lock; no merge, release or closure." "2026-10-02T23:13:26.769Z",codex-sol-land,"Corrected the linked source note: pm-ops#124 is already published in the pinned 2026.9.28 package, as the existing September 28 comment records. Preserve every dated note and append-only history line." "2026-10-02T23:14:08.171Z",codex-sol-land,"Resumed verification: npm ci, current-base rebase, fresh committed-dist comparison, strict local tracker health with required merge drivers, npm run release:check, and bun install --no-save all passed. Full gate: 174 tests, 174 pass, 0 skips; configured coverage thresholds unchanged. PM-linked test/release-workflow.test.ts passed. Earlier findings and technical refusals retained; no new source fix was needed in this restart. Exact pushed-head CI and substantive reviewer availability remain separate checks; no merge, release, publication or item closure." + "2026-10-02T23:28:07.013Z",codex-sol-land,"New Cubic finding 4170603509 is refused: Refused for this exact head: the completed Node 26 job used Node v26.10.0 and npm 11.19.1, not npm 12. Its real project-local pm package install of pm-github@2026.9.26, installed-version assertion, strict health and full CI gate all passed at acf6918. The statement that CI had not run is also contradicted by that completed job. Evidence: https://github.com/unbraind/pm-jira/actions/runs/37076601628/job/111067793577 . This is current-runner certification; no npm-12 certification is claimed and the obsolete npm-10 shim is not required for this verified job." + "2026-10-02T23:37:33.721Z",codex-sol-land,"Resumed verification: npm ci, current-base rebase, fresh committed-dist comparison, strict local tracker health with required merge drivers, npm run release:check, and bun install --no-save all passed. Full gate: 174 tests, 174 pass, 0 skips; configured coverage thresholds unchanged. PM-linked test/release-workflow.test.ts passed. Earlier findings and technical refusals retained; no new source fix was needed in this restart. Exact pushed-head CI and substantive reviewer availability remain separate checks; no merge, release, publication or item closure." notes[6]{created_at,author,text}: "2026-09-27T08:02:51.137Z",codex,"2026-09-27: First full release gate failed at the package launcher byte-identity assertion after upgrading published pm-ops to 2026.9.26. Copied the exact canonical launcher from installed pm-ops 2026.9.26 to scripts/prepare-merge-driver.ts; this includes its broken local-install guard. The full gate must rerun. The disabled GitHub sync workflow remains disabled." "2026-09-27T08:04:22.372Z",codex,"2026-09-27 08:04 UTC: Full local release gate passed after copying the exact published pm-ops 2026.9.26 launcher: 173/173 tests, zero skips, 100% measured lines/branches/functions across two production source files, 51/51 declarations documented, zero production audit vulnerabilities, current changelog and attestation checks. Strict PM health passes on CLI 2026.9.27 with stale_in_progress_items:1 advisory. A real pm-github 2026.9.26 project install activated and an open-issue dry run found no public Jira issues; no tracker import was applied. Scheduled sync remains disabled_manually pending pre-push privacy gating. GitHub CI, reviewer evidence, and statement coverage remain separate gates." @@ -49,7 +51,10 @@ tests[3]{command,scope,timeout_seconds,provenance{author,created_at,source_kind, "npm run release:check",project,600,codex,"2026-09-27T08:04:20.900Z",local_mutation,fix/pm-jira-cli-2026-09-27-github-pin node --test test/prepare-merge-driver.test.ts,project,120,codex,"2026-09-27T08:10:16.001Z",local_mutation,fix/pm-jira-cli-2026-09-27-github-pin node --test test/release-workflow.test.ts,project,120,codex-sol-land,"2026-10-02T23:13:24.983Z",local_mutation,fix/pm-jira-cli-2026-09-27-github-pin -docs[3]: +docs[4]: + - path: "https://github.com/unbraind/pm-jira/actions/runs/37076601628/job/111067793577" + scope: global + note: Exact-head Node 26 CI proves bundled npm 11.19.1 and successful pinned extension installation - path: "https://github.com/unbraind/pm-ops/blob/main/.agents/pm/issues/ops-jzp5.toon" scope: global note: Canonical hoisted broken-install source issue From 78caa84c381efef28039e9580d7a327b504051fa Mon Sep 17 00:00:00 2001 From: SteveBot <1153461+unbraind@users.noreply.github.com> Date: Sat, 3 Oct 2026 01:44:04 +0200 Subject: [PATCH 8/8] docs(jira): record review delta without repeated verification --- .agents/pm/history/pm-jira-b0n8.jsonl | 5 +++++ .agents/pm/issues/pm-jira-b0n8.toon | 29 +++++++++++++++++++-------- 2 files changed, 26 insertions(+), 8 deletions(-) diff --git a/.agents/pm/history/pm-jira-b0n8.jsonl b/.agents/pm/history/pm-jira-b0n8.jsonl index b127038..0c83a6b 100644 --- a/.agents/pm/history/pm-jira-b0n8.jsonl +++ b/.agents/pm/history/pm-jira-b0n8.jsonl @@ -29,3 +29,8 @@ {"hash_algorithm":"sha256","ts":"2026-10-02T23:37:33.721Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"comment_add","patch":[{"op":"add","path":"/metadata/comments/5","value":{"created_at":"2026-10-02T23:37:33.721Z","author":"codex-sol-land","text":"Resumed verification: npm ci, current-base rebase, fresh committed-dist comparison, strict local tracker health with required merge drivers, npm run release:check, and bun install --no-save all passed. Full gate: 174 tests, 174 pass, 0 skips; configured coverage thresholds unchanged. PM-linked test/release-workflow.test.ts passed. Earlier findings and technical refusals retained; no new source fix was needed in this restart. Exact pushed-head CI and substantive reviewer availability remain separate checks; no merge, release, publication or item closure."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:37:33.721Z"}],"before_hash":"0e35328eeba9ce2d000e6462c7f1ab87a1143a46f1f4919490cca2881318d901","after_hash":"84377f3b21a7d3b7ca9d047d234dcde2531bb0f83ce117e723f8299ec3c7c738","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"a82832aeea7f8859e9bb9fb551d386d074f7994e92ea85562ee97f9a137dad6b"} {"hash_algorithm":"sha256","ts":"2026-10-02T23:37:34.420Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"update","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:37:34.420Z"},{"op":"replace","path":"/metadata/status","value":"blocked"}],"before_hash":"84377f3b21a7d3b7ca9d047d234dcde2531bb0f83ce117e723f8299ec3c7c738","after_hash":"253dd2ccaf4d824dbd8fafb5d1e86e0907f07ab76dcf9da20df79f516adfe55c","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"367482fc58c26674b562f4ff46c58aae23700b50086fcd6054790ea884942c8a"} {"hash_algorithm":"sha256","ts":"2026-10-02T23:37:35.133Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"release","patch":[{"op":"remove","path":"/metadata/claim_principal"},{"op":"remove","path":"/metadata/assignee"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:37:35.133Z"}],"before_hash":"253dd2ccaf4d824dbd8fafb5d1e86e0907f07ab76dcf9da20df79f516adfe55c","after_hash":"38997657ce3326d668d2f270d344c2cc7f597b1dbff9329950150fd3a2bc7088","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"c3bc3a5d858a05e7a912b81a7619a59a9129c9359de88b8ff9d0c7c5611796c1"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:43:57.284Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"claim","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:43:57.284Z"},{"op":"add","path":"/metadata/assignee","value":"codex-sol-land"},{"op":"add","path":"/metadata/claim_principal","value":"codex-sol-land"}],"before_hash":"38997657ce3326d668d2f270d344c2cc7f597b1dbff9329950150fd3a2bc7088","after_hash":"3c08ba26c5c08bf56258f7c0448254a34afd6bbaf8b5ba829ea1c7c64ff4ab60","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"2134aaf8aae02a8fc92b487da90bcf7188f2e5061ab1c036d7d68d96f882b65a"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:43:58.563Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"update","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:43:58.563Z"},{"op":"replace","path":"/metadata/status","value":"in_progress"}],"before_hash":"3c08ba26c5c08bf56258f7c0448254a34afd6bbaf8b5ba829ea1c7c64ff4ab60","after_hash":"e900032b45a066c6e032d6169768d6a86c2bc4ed68f4c0abf164b0f363ece8f3","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"1fdf15f6bd8dc09e82cdfbbc022d96c0ee51a428d0403d60c3f1cecd66f76fa9"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:43:59.450Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":null,"topic":null},"op":"comment_edit","patch":[{"op":"replace","path":"/metadata/comments/5/text","value":"Delta from the 23:14 verification receipt: recorded refusal of Cubic 4170603509 using the completed Node 26 CI job (Node v26.10.0, npm 11.19.1), and linked that job alongside the already-published pm-ops#124 source. No runtime source or dependency changed. The unchanged release gate was re-run at 23:35: 174/174 tests, zero skips, strict health, fresh dist equality and Bun install passed. This comment replaces the repeated receipt wording identified by Cubic 4170717496; every prior append-only history line remains intact."},{"op":"add","path":"/metadata/comments/5/edited_at","value":"2026-10-02T23:43:59.449Z"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:43:59.450Z"}],"before_hash":"e900032b45a066c6e032d6169768d6a86c2bc4ed68f4c0abf164b0f363ece8f3","after_hash":"ac5b9d87fdc1a0707e4b77166590b33028b6924abd1d0b11c8c1e5114999614f","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"fb5def075baf59f9c74b3d8dd11523fe6f2acb5e89a170d74563e199f0ac203b"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:44:00.425Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"update","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:44:00.425Z"},{"op":"replace","path":"/metadata/status","value":"blocked"}],"before_hash":"ac5b9d87fdc1a0707e4b77166590b33028b6924abd1d0b11c8c1e5114999614f","after_hash":"4515a23190a1dd7ce8a3f08f0357534e91468154f8eb4b78ba6e1c7f54554a29","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"d69c2871d45a0e738e7a505fccba3ce9a7fa940eccbae18f938452a913822797"} +{"hash_algorithm":"sha256","ts":"2026-10-02T23:44:01.293Z","author":"codex-sol-land","author_source":"asserted","agent_harness":"codex","agent_model":"gpt-6.1-sol","agent_model_source":"probe","agent_instance":"6edbeed2935f1e5c041f14f3","agent_provenance":{"model":{"value":"gpt-6.1-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"release","patch":[{"op":"remove","path":"/metadata/claim_principal"},{"op":"remove","path":"/metadata/assignee"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-02T23:44:01.293Z"}],"before_hash":"4515a23190a1dd7ce8a3f08f0357534e91468154f8eb4b78ba6e1c7f54554a29","after_hash":"424bd0fa0555cc64b1d6edf3f46ee5bca4d998e444e66643cc436d65bf888f6b","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"2062972429ad92093712d734fd5f98a42034ef75ffc425f8c57f23997434cf9e"} diff --git a/.agents/pm/issues/pm-jira-b0n8.toon b/.agents/pm/issues/pm-jira-b0n8.toon index a1808c1..a9ab8ef 100644 --- a/.agents/pm/issues/pm-jira-b0n8.toon +++ b/.agents/pm/issues/pm-jira-b0n8.toon @@ -6,19 +6,32 @@ status: blocked priority: 1 tags[3]: agent-ux,"area:github","area:release" created_at: "2026-09-27T08:01:14.699Z" -updated_at: "2026-10-02T23:37:35.133Z" +updated_at: "2026-10-02T23:44:01.293Z" author: codex acceptance_criteria: "Exact package/lock pins for current CLI, pm-ops, and pm-changelog; tracked managed pm-github 2026.9.26; local strict health and full release gate pass; CI uses exact source; disabled sync stays disabled; staged privacy scan and exact-head review complete." repro_steps: "Run pm health --strict-exit --json on main with host CLI 2026.9.27; observe extension_host_pm_cli_version_skew. Inspect both workflows for npm:pm-github without a version and the npm 10 / manifest-rewrite steps." expected_result: Strict health passes with the project-local CLI/SDK 2026.9.27; both workflows install exact pm-github 2026.9.26; the package release gate passes; the sync workflow stays disabled until a separate pre-push privacy gate exists. actual_result: Main reports SDK-link skew and both workflow installs can drift to future unreviewed extension versions. -comments[6]{created_at,author,text}: - "2026-09-28T06:02:04.601Z",claude-hub,"2026-09-28: pinned pm-ops 2026.9.28 and re-copied its templates/prepare-merge-driver.ts (pm-ops#124: the omit-dev skip now checks every Node resolution path for an incomplete hoisted pm-ops, so a broken ancestor install fails instead of silently skipping the merge drivers). release:check and changelog:check pass on this branch." - "2026-10-02T23:13:22.459Z",codex-sol-land,"Resumed PR #119 from 39409056e819fac1ccd2c0721594dc36d4aea360. Rebase onto current main yields 39409056e819fac1ccd2c0721594dc36d4aea360. All existing bot artifacts and restart-era owner replies inspected; no new actionable finding. Preserve earlier fixes and technical refusals. Verifying unchanged CI gates under the shared heavy lock; no merge, release or closure." - "2026-10-02T23:13:26.769Z",codex-sol-land,"Corrected the linked source note: pm-ops#124 is already published in the pinned 2026.9.28 package, as the existing September 28 comment records. Preserve every dated note and append-only history line." - "2026-10-02T23:14:08.171Z",codex-sol-land,"Resumed verification: npm ci, current-base rebase, fresh committed-dist comparison, strict local tracker health with required merge drivers, npm run release:check, and bun install --no-save all passed. Full gate: 174 tests, 174 pass, 0 skips; configured coverage thresholds unchanged. PM-linked test/release-workflow.test.ts passed. Earlier findings and technical refusals retained; no new source fix was needed in this restart. Exact pushed-head CI and substantive reviewer availability remain separate checks; no merge, release, publication or item closure." - "2026-10-02T23:28:07.013Z",codex-sol-land,"New Cubic finding 4170603509 is refused: Refused for this exact head: the completed Node 26 job used Node v26.10.0 and npm 11.19.1, not npm 12. Its real project-local pm package install of pm-github@2026.9.26, installed-version assertion, strict health and full CI gate all passed at acf6918. The statement that CI had not run is also contradicted by that completed job. Evidence: https://github.com/unbraind/pm-jira/actions/runs/37076601628/job/111067793577 . This is current-runner certification; no npm-12 certification is claimed and the obsolete npm-10 shim is not required for this verified job." - "2026-10-02T23:37:33.721Z",codex-sol-land,"Resumed verification: npm ci, current-base rebase, fresh committed-dist comparison, strict local tracker health with required merge drivers, npm run release:check, and bun install --no-save all passed. Full gate: 174 tests, 174 pass, 0 skips; configured coverage thresholds unchanged. PM-linked test/release-workflow.test.ts passed. Earlier findings and technical refusals retained; no new source fix was needed in this restart. Exact pushed-head CI and substantive reviewer availability remain separate checks; no merge, release, publication or item closure." +comments[6]: + - created_at: "2026-09-28T06:02:04.601Z" + author: claude-hub + text: "2026-09-28: pinned pm-ops 2026.9.28 and re-copied its templates/prepare-merge-driver.ts (pm-ops#124: the omit-dev skip now checks every Node resolution path for an incomplete hoisted pm-ops, so a broken ancestor install fails instead of silently skipping the merge drivers). release:check and changelog:check pass on this branch." + - created_at: "2026-10-02T23:13:22.459Z" + author: codex-sol-land + text: "Resumed PR #119 from 39409056e819fac1ccd2c0721594dc36d4aea360. Rebase onto current main yields 39409056e819fac1ccd2c0721594dc36d4aea360. All existing bot artifacts and restart-era owner replies inspected; no new actionable finding. Preserve earlier fixes and technical refusals. Verifying unchanged CI gates under the shared heavy lock; no merge, release or closure." + - created_at: "2026-10-02T23:13:26.769Z" + author: codex-sol-land + text: "Corrected the linked source note: pm-ops#124 is already published in the pinned 2026.9.28 package, as the existing September 28 comment records. Preserve every dated note and append-only history line." + - created_at: "2026-10-02T23:14:08.171Z" + author: codex-sol-land + text: "Resumed verification: npm ci, current-base rebase, fresh committed-dist comparison, strict local tracker health with required merge drivers, npm run release:check, and bun install --no-save all passed. Full gate: 174 tests, 174 pass, 0 skips; configured coverage thresholds unchanged. PM-linked test/release-workflow.test.ts passed. Earlier findings and technical refusals retained; no new source fix was needed in this restart. Exact pushed-head CI and substantive reviewer availability remain separate checks; no merge, release, publication or item closure." + - created_at: "2026-10-02T23:28:07.013Z" + author: codex-sol-land + text: "New Cubic finding 4170603509 is refused: Refused for this exact head: the completed Node 26 job used Node v26.10.0 and npm 11.19.1, not npm 12. Its real project-local pm package install of pm-github@2026.9.26, installed-version assertion, strict health and full CI gate all passed at acf6918. The statement that CI had not run is also contradicted by that completed job. Evidence: https://github.com/unbraind/pm-jira/actions/runs/37076601628/job/111067793577 . This is current-runner certification; no npm-12 certification is claimed and the obsolete npm-10 shim is not required for this verified job." + - created_at: "2026-10-02T23:37:33.721Z" + author: codex-sol-land + text: "Delta from the 23:14 verification receipt: recorded refusal of Cubic 4170603509 using the completed Node 26 CI job (Node v26.10.0, npm 11.19.1), and linked that job alongside the already-published pm-ops#124 source. No runtime source or dependency changed. The unchanged release gate was re-run at 23:35: 174/174 tests, zero skips, strict health, fresh dist equality and Bun install passed. This comment replaces the repeated receipt wording identified by Cubic 4170717496; every prior append-only history line remains intact." + edited_at: "2026-10-02T23:43:59.449Z" notes[6]{created_at,author,text}: "2026-09-27T08:02:51.137Z",codex,"2026-09-27: First full release gate failed at the package launcher byte-identity assertion after upgrading published pm-ops to 2026.9.26. Copied the exact canonical launcher from installed pm-ops 2026.9.26 to scripts/prepare-merge-driver.ts; this includes its broken local-install guard. The full gate must rerun. The disabled GitHub sync workflow remains disabled." "2026-09-27T08:04:22.372Z",codex,"2026-09-27 08:04 UTC: Full local release gate passed after copying the exact published pm-ops 2026.9.26 launcher: 173/173 tests, zero skips, 100% measured lines/branches/functions across two production source files, 51/51 declarations documented, zero production audit vulnerabilities, current changelog and attestation checks. Strict PM health passes on CLI 2026.9.27 with stale_in_progress_items:1 advisory. A real pm-github 2026.9.26 project install activated and an open-issue dry run found no public Jira issues; no tracker import was applied. Scheduled sync remains disabled_manually pending pre-push privacy gating. GitHub CI, reviewer evidence, and statement coverage remain separate gates."