Skip to content

[Spec 13] OSS Readiness for Early Adopters — v0.4.0 - #3

Merged
timeleft-- merged 9 commits into
mainfrom
builder/aspir-13-oss-readiness
Feb 24, 2026
Merged

timeleft-- merged 9 commits into
mainfrom
builder/aspir-13-oss-readiness

Conversation

@timeleft--

Copy link
Copy Markdown
Member

Summary

Implements Spec 13: OSS Readiness for Early Adopters. Prepares FAVA Trails for public release as a properly scaffolded open-source project.

Phase 1 — Documentation, Metadata & Scaffolding

  • pyproject.toml: Apache-2.0 license, authors, readme, classifiers, project URLs, version 0.4.0
  • README.md: Fixed 3 broken examples (added required trail_name parameter to save_thought, propose_truth, recall); added Contributing/Changelog links
  • GitHub Actions CI (.github/workflows/test.yml): JJ install + uv sync --frozen + lint-first + JJ_CONFIG: /dev/null hermeticity + workflow_dispatch
  • GitHub Actions Release (.github/workflows/release.yml): Trusted Publishing with OIDC (id-token: write + attestations: write) — no stored API keys
  • Issue template (.github/ISSUE_TEMPLATE/bug_report.yml): JJ/OS/Python version fields, required marks, security advisory redirect
  • CONTRIBUTING.md: Prerequisites, install, test, lint, PR expectations, codev/ explanation
  • CHANGELOG.md: v0.1.0–v0.4.0 with upgrade notes table (fava-trail → fava-trails rename)
  • SECURITY.md: Supported versions, GitHub Security Advisories private disclosure
  • Pre-existing ruff fixes: 65 lint errors (59 auto-fixed, 6 manual: StrEnum migration, raise...from err, unused vars)

Phase 2 — Security Audit & Release Prep

  • Security audit: gitleaks v8.22.1 scanned 88 commits — no leaks found
  • Package build: uv build → wheel + sdist, contents verified
  • PyPI first publish: Requires human action (see merge checklist below)
  • Post-merge commands: Documented in codev/reviews/13-oss-readiness.md

Test plan

  • All 128 tests pass (uv run pytest -v)
  • Ruff clean (ruff check src/ tests/)
  • Package builds (uv build)
  • Review pyproject.toml metadata (license, version, URLs)
  • Review test.yml CI workflow (JJ install, JJ_CONFIG, lint-first)
  • Review release.yml (OIDC permissions: id-token:write + attestations:write)
  • README examples now include trail_name

Post-Merge Human Actions (before going public)

# 1. First PyPI publish
UV_PUBLISH_TOKEN=<your-token> uv publish

# 2. Set up Trusted Publishing on PyPI
# https://pypi.org/manage/account/publishing/
# owner=MachineWisdomAI, repo=fava-trails, workflow=release.yml

# 3. GitHub topics
gh repo edit --add-topic mcp,ai-agents,memory,jujutsu,python,mcp-server

# 4. GitHub release (version-scoped notes)
sed -n '/^## \[0\.4\.0\]/,/^## \[/p' CHANGELOG.md | sed '$d' > /tmp/release-notes.md
gh release create v0.4.0 --title "v0.4.0 — FAVA Trails" --notes-file /tmp/release-notes.md

# 5. Flip repo public
gh repo edit --visibility public

🤖 Generated with Claude Code

timeleft-- and others added 9 commits February 24, 2026 12:42
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
… artifacts, and accepted feedback

- Update plan to split into 2 phases (porch requirement)
- Add phases JSON block for porch tracking
- Incorporate accepted consultation feedback:
  * Upgrade security audit to gitleaks (covers git history)
  * Add workflow_dispatch and JJ_CONFIG=/dev/null to CI spec
  * Expand pyproject.toml metadata (classifiers, readme, requires-python)
  * Upgrade PyPI from deferred to included in this pass
  * Add SECURITY.md as new deliverable (1g)
- Add spec consultation artifacts (iter1: codex, gemini, claude outputs + rebuttals)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…n feedback

- Fix release.yml to include required OIDC permissions (id-token: write)
- Use version-scoped release notes for gh release create
- Use uv sync --frozen for deterministic CI
- Move lint before tests in CI for fail-fast behavior
- Add plan consultation artifacts (iter1: gemini, codex, claude + rebuttals)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…adata, CI, and lint fixes

Phase 1: Documentation, Metadata & Scaffolding

- pyproject.toml: bump to 0.4.0, add Apache-2.0 license, authors, readme,
  classifiers, project.urls
- src/fava_trails/__init__.py: bump __version__ to 0.4.0
- README.md: fix broken examples — add trail_name to save_thought, propose_truth,
  recall; add Contributing/Changelog section links
- .github/workflows/test.yml: CI with JJ install, uv sync --frozen, lint-first,
  JJ_CONFIG=/dev/null hermeticity, workflow_dispatch
- .github/workflows/release.yml: Trusted Publishing with id-token: write OIDC
- .github/ISSUE_TEMPLATE/bug_report.yml: JJ/OS/Python version fields, required marks
- CONTRIBUTING.md: prerequisites, install, test, lint, PR expectations
- CHANGELOG.md: v0.1.0 through v0.4.0 with upgrade notes
- SECURITY.md: supported versions, GitHub Security Advisories disclosure

Pre-existing ruff issues (59 auto-fixed, 6 manual):
- UP042: StrEnum migration in models.py
- UP045: Optional[X] → X | None across src/
- B904: raise ... from err in server.py
- F841: unused variables in tests
- F401/I001: unused imports and import ordering in tests
All 128 tests pass after fixes.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…claim

Per code review consultation feedback:
- pyproject.toml: expand sdist include to add README.md, LICENSE, CHANGELOG.md,
  CONTRIBUTING.md, SECURITY.md (prevents broken builds-from-sdist on PyPI)
- CHANGELOG.md: reword PyPI entry to say workflow was added, not package available
  (package not published until Phase 2)
- Add phase_1 consultation artifacts (iter1: gemini, codex, claude, rebuttals)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…release prep documented

Phase 2: Security Audit, PyPI Publishing & Release Prep

Security audit (2a):
- gitleaks scan: 88 commits scanned, no leaks found
- .gitignore covers .env and .secrets
- Targeted pattern scan: no credentials in src/, tests/, docs/
- Internal reference audit: CONTRIBUTING.md codev/ reference appropriate

PyPI publishing (2b):
- uv build: dist/fava_trails-0.4.0.tar.gz + .whl built successfully
- Wheel: source + AGENTS_USAGE_INSTRUCTIONS.md + LICENSE
- Sdist: README.md + LICENSE + CHANGELOG.md + CONTRIBUTING.md + SECURITY.md
- Publish requires human action (UV_PUBLISH_TOKEN not in builder env)
- release.yml ready for Trusted Publishing after first manual publish

Post-merge commands (2c):
- gh repo edit topics, gh release create v0.4.0 documented in audit file
- Version-scoped release notes extraction documented

All 128 tests pass. Build check passes.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…elease.yml

Per Phase 2 code review: pypa/gh-action-pypi-publish with attestations:true
requires attestations:write permission for SLSA provenance upload. Without it,
the release job fails at the attestation step.

Also update plan status to "complete" and add phase_2 consultation artifacts.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…and lessons learned

Covers:
- Spec vs implementation comparison (all items complete or human-deferred)
- Issues found: pre-existing ruff failures, sdist incomplete, release.yml permissions,
  CHANGELOG premature claim
- Architecture updates: CI/CD pipeline, package publishing setup
- Lessons learned: 5 new lessons for the protocol
- Post-merge human action checklist (PyPI publish, Trusted Publishing, topics, release)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
All three consultation models approved the PR. No remaining issues.
128 tests pass, ruff clean, gitleaks clean, all deliverables verified.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@timeleft--
timeleft-- merged commit a5bca47 into main Feb 24, 2026
0 of 2 checks passed
timeleft-- added a commit that referenced this pull request Feb 27, 2026
…ness

[Spec 13] OSS Readiness for Early Adopters — v0.4.0
@timeleft--
timeleft-- deleted the builder/aspir-13-oss-readiness branch March 4, 2026 17:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant