Repository navigation
[Spec 13] OSS Readiness for Early Adopters — v0.4.0 - #3
Merged
Merged
Conversation
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
… artifacts, and accepted feedback - Update plan to split into 2 phases (porch requirement) - Add phases JSON block for porch tracking - Incorporate accepted consultation feedback: * Upgrade security audit to gitleaks (covers git history) * Add workflow_dispatch and JJ_CONFIG=/dev/null to CI spec * Expand pyproject.toml metadata (classifiers, readme, requires-python) * Upgrade PyPI from deferred to included in this pass * Add SECURITY.md as new deliverable (1g) - Add spec consultation artifacts (iter1: codex, gemini, claude outputs + rebuttals) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…n feedback - Fix release.yml to include required OIDC permissions (id-token: write) - Use version-scoped release notes for gh release create - Use uv sync --frozen for deterministic CI - Move lint before tests in CI for fail-fast behavior - Add plan consultation artifacts (iter1: gemini, codex, claude + rebuttals) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…adata, CI, and lint fixes Phase 1: Documentation, Metadata & Scaffolding - pyproject.toml: bump to 0.4.0, add Apache-2.0 license, authors, readme, classifiers, project.urls - src/fava_trails/__init__.py: bump __version__ to 0.4.0 - README.md: fix broken examples — add trail_name to save_thought, propose_truth, recall; add Contributing/Changelog section links - .github/workflows/test.yml: CI with JJ install, uv sync --frozen, lint-first, JJ_CONFIG=/dev/null hermeticity, workflow_dispatch - .github/workflows/release.yml: Trusted Publishing with id-token: write OIDC - .github/ISSUE_TEMPLATE/bug_report.yml: JJ/OS/Python version fields, required marks - CONTRIBUTING.md: prerequisites, install, test, lint, PR expectations - CHANGELOG.md: v0.1.0 through v0.4.0 with upgrade notes - SECURITY.md: supported versions, GitHub Security Advisories disclosure Pre-existing ruff issues (59 auto-fixed, 6 manual): - UP042: StrEnum migration in models.py - UP045: Optional[X] → X | None across src/ - B904: raise ... from err in server.py - F841: unused variables in tests - F401/I001: unused imports and import ordering in tests All 128 tests pass after fixes. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…claim Per code review consultation feedback: - pyproject.toml: expand sdist include to add README.md, LICENSE, CHANGELOG.md, CONTRIBUTING.md, SECURITY.md (prevents broken builds-from-sdist on PyPI) - CHANGELOG.md: reword PyPI entry to say workflow was added, not package available (package not published until Phase 2) - Add phase_1 consultation artifacts (iter1: gemini, codex, claude, rebuttals) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…release prep documented Phase 2: Security Audit, PyPI Publishing & Release Prep Security audit (2a): - gitleaks scan: 88 commits scanned, no leaks found - .gitignore covers .env and .secrets - Targeted pattern scan: no credentials in src/, tests/, docs/ - Internal reference audit: CONTRIBUTING.md codev/ reference appropriate PyPI publishing (2b): - uv build: dist/fava_trails-0.4.0.tar.gz + .whl built successfully - Wheel: source + AGENTS_USAGE_INSTRUCTIONS.md + LICENSE - Sdist: README.md + LICENSE + CHANGELOG.md + CONTRIBUTING.md + SECURITY.md - Publish requires human action (UV_PUBLISH_TOKEN not in builder env) - release.yml ready for Trusted Publishing after first manual publish Post-merge commands (2c): - gh repo edit topics, gh release create v0.4.0 documented in audit file - Version-scoped release notes extraction documented All 128 tests pass. Build check passes. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…elease.yml Per Phase 2 code review: pypa/gh-action-pypi-publish with attestations:true requires attestations:write permission for SLSA provenance upload. Without it, the release job fails at the attestation step. Also update plan status to "complete" and add phase_2 consultation artifacts. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…and lessons learned Covers: - Spec vs implementation comparison (all items complete or human-deferred) - Issues found: pre-existing ruff failures, sdist incomplete, release.yml permissions, CHANGELOG premature claim - Architecture updates: CI/CD pipeline, package publishing setup - Lessons learned: 5 new lessons for the protocol - Post-merge human action checklist (PyPI publish, Trusted Publishing, topics, release) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
All three consultation models approved the PR. No remaining issues. 128 tests pass, ruff clean, gitleaks clean, all deliverables verified. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
timeleft--
added a commit
that referenced
this pull request
Feb 27, 2026
…ness [Spec 13] OSS Readiness for Early Adopters — v0.4.0
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implements Spec 13: OSS Readiness for Early Adopters. Prepares FAVA Trails for public release as a properly scaffolded open-source project.
Phase 1 — Documentation, Metadata & Scaffolding
trail_nameparameter tosave_thought,propose_truth,recall); added Contributing/Changelog links.github/workflows/test.yml): JJ install +uv sync --frozen+ lint-first +JJ_CONFIG: /dev/nullhermeticity +workflow_dispatch.github/workflows/release.yml): Trusted Publishing with OIDC (id-token: write+attestations: write) — no stored API keys.github/ISSUE_TEMPLATE/bug_report.yml): JJ/OS/Python version fields, required marks, security advisory redirectPhase 2 — Security Audit & Release Prep
uv build→ wheel + sdist, contents verifiedcodev/reviews/13-oss-readiness.mdTest plan
uv run pytest -v)ruff check src/ tests/)uv build)pyproject.tomlmetadata (license, version, URLs)test.ymlCI workflow (JJ install, JJ_CONFIG, lint-first)release.yml(OIDC permissions: id-token:write + attestations:write)trail_namePost-Merge Human Actions (before going public)
🤖 Generated with Claude Code