Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions .agents/pm/extensions/.managed-extensions.json
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
{
"version": 1,
"updated_at": "2026-08-28T20:03:25.465Z",
"updated_at": "2026-09-27T07:59:03.646Z",
"entries": [
{
"name": "pm-github",
"directory": "pm-github",
"scope": "project",
"manifest_version": "2026.8.18",
"manifest_version": "2026.9.26",
"manifest_entry": "./dist/index.js",
"capabilities": [
"commands",
Expand Down Expand Up @@ -94,13 +94,13 @@
]
},
"installed_at": "2026-08-28T20:03:25.135Z",
"updated_at": "2026-08-28T20:03:25.135Z",
"updated_at": "2026-09-27T07:59:03.540Z",
"source": {
"kind": "npm",
"input": "npm:pm-github",
"input": "npm:pm-github@2026.9.26",
"location": "package",
"package": "pm-github",
"version": "2026.8.18"
"version": "2026.9.26"
}
}
]
Expand Down
36 changes: 36 additions & 0 deletions .agents/pm/history/pm-jira-b0n8.jsonl

Large diffs are not rendered by default.

79 changes: 79 additions & 0 deletions .agents/pm/issues/pm-jira-b0n8.toon
Original file line number Diff line number Diff line change
@@ -0,0 +1,79 @@
id: pm-jira-b0n8
title: Certify pm-jira on CLI 2026.9.27 and pinned GitHub extension
description: "The main checkout pins PM CLI, pm-ops, and pm-changelog 2026.9.23 and manages pm-github 2026.8.18. Host CLI 2026.9.27 reports extension SDK-link skew. CI and disabled scheduled sync install an unversioned extension through an obsolete npm 10 shim and rewrite its manifest. Align the package toolchain and tracked extension metadata with current published versions, and use the exact managed extension source in both workflows."
type: Issue
status: blocked
priority: 1
tags[3]: agent-ux,"area:github","area:release"
created_at: "2026-09-27T08:01:14.699Z"
updated_at: "2026-10-02T23:44:01.293Z"
author: codex
acceptance_criteria: "Exact package/lock pins for current CLI, pm-ops, and pm-changelog; tracked managed pm-github 2026.9.26; local strict health and full release gate pass; CI uses exact source; disabled sync stays disabled; staged privacy scan and exact-head review complete."
repro_steps: "Run pm health --strict-exit --json on main with host CLI 2026.9.27; observe extension_host_pm_cli_version_skew. Inspect both workflows for npm:pm-github without a version and the npm 10 / manifest-rewrite steps."
expected_result: Strict health passes with the project-local CLI/SDK 2026.9.27; both workflows install exact pm-github 2026.9.26; the package release gate passes; the sync workflow stays disabled until a separate pre-push privacy gate exists.
actual_result: Main reports SDK-link skew and both workflow installs can drift to future unreviewed extension versions.
comments[6]:
- created_at: "2026-09-28T06:02:04.601Z"
author: claude-hub
text: "2026-09-28: pinned pm-ops 2026.9.28 and re-copied its templates/prepare-merge-driver.ts (pm-ops#124: the omit-dev skip now checks every Node resolution path for an incomplete hoisted pm-ops, so a broken ancestor install fails instead of silently skipping the merge drivers). release:check and changelog:check pass on this branch."
- created_at: "2026-10-02T23:13:22.459Z"
author: codex-sol-land
text: "Resumed PR #119 from 39409056e819fac1ccd2c0721594dc36d4aea360. Rebase onto current main yields 39409056e819fac1ccd2c0721594dc36d4aea360. All existing bot artifacts and restart-era owner replies inspected; no new actionable finding. Preserve earlier fixes and technical refusals. Verifying unchanged CI gates under the shared heavy lock; no merge, release or closure."
- created_at: "2026-10-02T23:13:26.769Z"
author: codex-sol-land
text: "Corrected the linked source note: pm-ops#124 is already published in the pinned 2026.9.28 package, as the existing September 28 comment records. Preserve every dated note and append-only history line."
- created_at: "2026-10-02T23:14:08.171Z"
author: codex-sol-land
text: "Resumed verification: npm ci, current-base rebase, fresh committed-dist comparison, strict local tracker health with required merge drivers, npm run release:check, and bun install --no-save all passed. Full gate: 174 tests, 174 pass, 0 skips; configured coverage thresholds unchanged. PM-linked test/release-workflow.test.ts passed. Earlier findings and technical refusals retained; no new source fix was needed in this restart. Exact pushed-head CI and substantive reviewer availability remain separate checks; no merge, release, publication or item closure."
- created_at: "2026-10-02T23:28:07.013Z"
author: codex-sol-land
text: "New Cubic finding 4170603509 is refused: Refused for this exact head: the completed Node 26 job used Node v26.10.0 and npm 11.19.1, not npm 12. Its real project-local pm package install of pm-github@2026.9.26, installed-version assertion, strict health and full CI gate all passed at acf6918. The statement that CI had not run is also contradicted by that completed job. Evidence: https://github.com/unbraind/pm-jira/actions/runs/37076601628/job/111067793577 . This is current-runner certification; no npm-12 certification is claimed and the obsolete npm-10 shim is not required for this verified job."
- created_at: "2026-10-02T23:37:33.721Z"
author: codex-sol-land
text: "Delta from the 23:14 verification receipt: recorded refusal of Cubic 4170603509 using the completed Node 26 CI job (Node v26.10.0, npm 11.19.1), and linked that job alongside the already-published pm-ops#124 source. No runtime source or dependency changed. The unchanged release gate was re-run at 23:35: 174/174 tests, zero skips, strict health, fresh dist equality and Bun install passed. This comment replaces the repeated receipt wording identified by Cubic 4170717496; every prior append-only history line remains intact."
edited_at: "2026-10-02T23:43:59.449Z"
notes[6]{created_at,author,text}:
"2026-09-27T08:02:51.137Z",codex,"2026-09-27: First full release gate failed at the package launcher byte-identity assertion after upgrading published pm-ops to 2026.9.26. Copied the exact canonical launcher from installed pm-ops 2026.9.26 to scripts/prepare-merge-driver.ts; this includes its broken local-install guard. The full gate must rerun. The disabled GitHub sync workflow remains disabled."
"2026-09-27T08:04:22.372Z",codex,"2026-09-27 08:04 UTC: Full local release gate passed after copying the exact published pm-ops 2026.9.26 launcher: 173/173 tests, zero skips, 100% measured lines/branches/functions across two production source files, 51/51 declarations documented, zero production audit vulnerabilities, current changelog and attestation checks. Strict PM health passes on CLI 2026.9.27 with stale_in_progress_items:1 advisory. A real pm-github 2026.9.26 project install activated and an open-issue dry run found no public Jira issues; no tracker import was applied. Scheduled sync remains disabled_manually pending pre-push privacy gating. GitHub CI, reviewer evidence, and statement coverage remain separate gates."
"2026-09-27T08:10:17.650Z",codex,"2026-09-27: Greptile on PR #119 head d184a0c found the copied canonical launcher gained a broken-install branch without consumer regression coverage. The finding is valid. Added real child-checkout cases for an incomplete pm-ops directory and dangling link; both fail without the omit-dev notice and without merge drivers. Focused suite passes 7/7 with zero skips. Inline finding was voted and acknowledged; full release gate and exact-head rereview remain pending."
"2026-09-27T08:17:04.429Z",codex,"2026-09-27: CodeRabbit on PR #119 head d184a0c found the disabled GitHub issue-sync workflow still had runnable schedule/manual triggers and write permissions if re-enabled before a fail-closed imported-content privacy gate. The finding is valid. Added a checked-in job-level if: false guard and confirmed GitHub workflow remains disabled_manually. The same defense is being added to the pm-graph and pm-todos pilot candidates. This does not implement the privacy gate or authorize enabling sync. Review was voted and answered inline; full release gate and new-head CI/review remain pending."
"2026-09-27T08:19:09.910Z",codex,"2026-09-27 08:19 UTC: After both first-head review fixes, the full npm run release:check gate passes 174/174 tests with zero skips; measured lines/branches/functions are 100/100/100, 51/51 declarations documented, and production audit reports zero vulnerabilities. The real child-checkout launcher suite passes 7/7. The scheduled issue-sync job has a checked-in if: false guard, and GitHub API still reports disabled_manually. The separate content privacy gate, statement coverage, GitHub CI, and fresh exact-head bot reviews remain open."
"2026-09-27T08:35:53.468Z",codex,"2026-09-27 downstream Greptile P1 on pm-todos #103 revealed the published pm-ops 2026.9.26 launcher copied here misses incomplete hoisted installs in ancestor node_modules. Canonical source issue ops-jzp5 and unmerged pm-ops #124 already fix and test this path. This PR is blocked until the reviewed source is published, this package pins and copies its new template byte for byte, full release gate and strict health pass, and exact-head bot review repeats. Earlier green CI/Greptile status does not certify this edge case."
files[7]:
- path: .agents/pm/extensions/.managed-extensions.json
scope: project
note: Exact managed pm-github source
- path: .github/workflows/ci.yml
scope: project
note: CI installs pinned extension
- path: .github/workflows/pm-github-sync.yml
scope: project
note: Disabled sync installs pinned extension
- path: package.json
scope: project
note: Published CLI and quality-tool pins
- path: scripts/prepare-merge-driver.ts
scope: project
note: Published pm-ops launcher copy
- path: test/prepare-merge-driver.test.ts
scope: project
note: Incomplete directory and dangling-link real child checkouts
- path: test/release-workflow.test.ts
scope: project
tests[3]{command,scope,timeout_seconds,provenance{author,created_at,source_kind,source_ref}}:
"npm run release:check",project,600,codex,"2026-09-27T08:04:20.900Z",local_mutation,fix/pm-jira-cli-2026-09-27-github-pin
node --test test/prepare-merge-driver.test.ts,project,120,codex,"2026-09-27T08:10:16.001Z",local_mutation,fix/pm-jira-cli-2026-09-27-github-pin
node --test test/release-workflow.test.ts,project,120,codex-sol-land,"2026-10-02T23:13:24.983Z",local_mutation,fix/pm-jira-cli-2026-09-27-github-pin
docs[4]:
- path: "https://github.com/unbraind/pm-jira/actions/runs/37076601628/job/111067793577"
scope: global
note: Exact-head Node 26 CI proves bundled npm 11.19.1 and successful pinned extension installation
- path: "https://github.com/unbraind/pm-ops/blob/main/.agents/pm/issues/ops-jzp5.toon"
scope: global
note: Canonical hoisted broken-install source issue
- path: "https://github.com/unbraind/pm-ops/pull/124"
scope: global
note: Already published canonical launcher source included in pinned pm-ops 2026.9.28
- path: "https://github.com/unbraind/pm-jira/pull/119"
scope: project
body: ""
13 changes: 2 additions & 11 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -41,17 +41,8 @@ jobs:
shell: bash
run: |
set -euo pipefail
# npm 12 emits object-shaped `npm pack --json` output, while the
# current pm installer accepts npm 10's array-shaped response.
npm10_root="${RUNNER_TEMP}/pm-npm10"
npm install --prefix "${npm10_root}" --no-save --ignore-scripts npm@10.9.3
PATH="${npm10_root}/node_modules/.bin:${PATH}" ./node_modules/.bin/pm install npm:pm-github --project
# The published 2026.8.18 artifact still carries the obsolete `pm`
# manifest key. Normalize it to the source manifest's enforced floor
# before the strict health gate; the installed artifact is ignored.
extension_manifest=".agents/pm/extensions/pm-github/manifest.json"
jq 'del(.pm) | .pm_min_version = "2026.8.20"' "${extension_manifest}" > "${RUNNER_TEMP}/pm-github-manifest.json"
mv "${RUNNER_TEMP}/pm-github-manifest.json" "${extension_manifest}"
./node_modules/.bin/pm package install npm:pm-github@2026.9.26 --project
Comment thread
unbraind marked this conversation as resolved.
node -e 'if (require("./.agents/pm/extensions/pm-github/package.json").version !== "2026.9.26") process.exit(1)'
managed_registry=".agents/pm/extensions/.managed-extensions.json"
if git ls-files --error-unmatch "${managed_registry}" > /dev/null 2>&1; then
git restore -- "${managed_registry}"
Expand Down
14 changes: 4 additions & 10 deletions .github/workflows/pm-github-sync.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,8 @@ concurrency:

jobs:
sync:
# Imported issue bodies need a fail-closed pre-push privacy gate first.
if: ${{ false }}
runs-on: ubuntu-latest
env:
GH_TOKEN: ${{ github.token }}
Expand Down Expand Up @@ -56,16 +58,8 @@ jobs:
shell: bash
run: |
set -euo pipefail
# npm 12 emits object-shaped `npm pack --json` output, while the
# current pm installer accepts npm 10's array-shaped response.
npm10_root="${RUNNER_TEMP}/pm-npm10"
npm install --prefix "${npm10_root}" --no-save --ignore-scripts npm@10.9.3
PATH="${npm10_root}/node_modules/.bin:${PATH}" ./node_modules/.bin/pm install npm:pm-github --project
# The published 2026.8.18 artifact still carries the obsolete `pm`
# manifest key. Normalize it to the source manifest's enforced floor.
extension_manifest=".agents/pm/extensions/pm-github/manifest.json"
jq 'del(.pm) | .pm_min_version = "2026.8.20"' "${extension_manifest}" > "${RUNNER_TEMP}/pm-github-manifest.json"
mv "${RUNNER_TEMP}/pm-github-manifest.json" "${extension_manifest}"
./node_modules/.bin/pm package install npm:pm-github@2026.9.26 --project
node -e 'if (require("./.agents/pm/extensions/pm-github/package.json").version !== "2026.9.26") process.exit(1)'
managed_registry=".agents/pm/extensions/.managed-extensions.json"
if git ls-files --error-unmatch "${managed_registry}" > /dev/null 2>&1; then
git restore -- "${managed_registry}"
Comment thread
coderabbitai[bot] marked this conversation as resolved.
Expand Down
Loading
Loading