From 2ba0c62d8af214712eea73f038d6b013a172a241 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Mon, 18 May 2026 10:24:21 -0400 Subject: [PATCH 01/61] docs: mirror agentshield fleet ticket evidence --- docs/ECC-2.0-GA-ROADMAP.md | 7 ++- ...agentshield-enterprise-research-roadmap.md | 14 ++++- docs/drafts/release-1.10.1-announcement.md | 63 +++++++++++++++++++ scripts/operator-readiness-dashboard.js | 2 +- 4 files changed, 80 insertions(+), 6 deletions(-) create mode 100644 docs/drafts/release-1.10.1-announcement.md diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index 77567a06..be742b87 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -702,7 +702,7 @@ is not complete unless the evidence column exists and has been freshly verified. | Naming and rename readiness | Naming matrix across package/plugin/docs/social surfaces | `docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md` records current package, repo, Claude plugin, Codex plugin, OpenCode, and npm availability evidence | Complete for rc.1; post-rc rename remains future work | | Claude and Codex plugin publication | Contact/submission path with required artifacts and status | Publication readiness, naming matrix, and May 12 dry-run evidence document plugin validation, clean-checkout Claude tag/install smoke, and Codex marketplace CLI shape | Needs explicit approval for real tag/push and marketplace submission | | Articles, tweets, and announcements | X thread, LinkedIn copy, GitHub release copy, push checklist | Draft launch collateral exists under rc.1 release docs | Needs URL-backed refresh | -| AgentShield enterprise iteration | Policy gates, SARIF, packs, provenance, corpus, HTML reports, exception lifecycle audit, baseline drift Action/CLI surfaces, evidence-pack redaction, harness adapter registry, enterprise research roadmap, supply-chain hardened release path, CI-safe baseline fingerprints, corpus accuracy recommendations, remediation workflow phases, env proxy hijack corpus coverage, Mini Shai-Hulud full-campaign package IOCs, CI-provenance evidence packs, plugin-cache runtime-confidence triage, evidence-pack consumer readback, fleet-level evidence-pack routing, fleet review items, checksum-backed policy export, checksum-verified policy promotion, policy promotion review items, package-manager hardening drift detection, npm age-gate guidance correction, workflow action-runtime pin refresh, package-manager hardening Action outputs, policy-promotion Action outputs, ECC-Tools hosted consumption of promotion Action outputs, ECC-Tools operator-visible promotion output values, and ECC-Tools hosted promotion judge audit traces | PRs #53, #55-#64, #67-#69, and #78-#92 landed with test evidence, ECC-Tools #76 consumes the fleet-summary output in hosted security review, #77 surfaces source evidence paths in hosted finding output, and #78 links fleet routes to harness owner review; AgentShield #91 adds `agentshield policy export` bundles for branch-protection review and downstream promotion; AgentShield #92 adds `agentshield policy promote` with digest verification, tamper rejection, explicit pack selection, dry-run review, and JSON output before writing active policy; AgentShield commit `87aec47` adds `reviewItems` for digest evidence, owner review, protected rollout PR handoff, and runtime smoke testing with green local and remote CI; AgentShield commit `28d08c7` adds package-manager hardening drift detection for plaintext registry credentials, lifecycle-script enablement, and weak pnpm/Yarn release-age cooldowns with green local and remote CI; AgentShield commit `659f569` refreshes all workflow action runtime pins to SHA-pinned checkout v6.0.2 and setup-node v6.4.0 with green remote CI and no remaining action-runtime deprecation annotation; AgentShield commit `ee585cd` corrects npm release-age guidance by flagging unsupported npm age keys and keeping enforceable cooldown findings on pnpm/Yarn with green local and remote CI; AgentShield commit `1124535` exposes package-manager hardening status/count outputs and a redacted job-summary section for registry credentials, lifecycle scripts, and release-age gates with green local and remote CI; AgentShield commit `1593925` exposes policy-promotion status/count/digest outputs plus job-summary review items for owner approval, protected rollout, and runtime smoke, and marks runtime smoke verified when the same Action job scans with the promoted policy; ECC-Tools commit `8658951` routes those policy-promotion Action outputs into hosted security review findings and Hosted Promotion Readiness scoring; ECC-Tools commit `16c537f` renders policy-promotion status, pack, review item count, action-required count, and digest in hosted security job comments/check-runs; ECC-Tools commit `05d4e82` renders hosted promotion judge request fingerprints and allowed-citation counts without raw provider output; native PDF export deferred in favor of self-contained HTML plus print-to-PDF until explicit enterprise demand appears; `docs/architecture/agentshield-enterprise-research-roadmap.md` now has baseline drift, evidence-pack bundle, redaction, adapter-registry, supply-chain hardening, hashed baseline fingerprints, corpus accuracy recommendation, remediation workflow, env proxy hijack corpus, Mini Shai-Hulud full-campaign package-table, `ci-context.json` provenance, `plugin-cache` confidence, `evidence-pack inspect` readback, `evidence-pack fleet` routing, fleet `reviewItems`, policy export, policy promotion, policy promotion `reviewItems`, package-manager hardening Action outputs, policy-promotion Action outputs, hosted consumption of promotion Action outputs, operator-visible promotion output values, and hosted promotion judge audit traces landed | Next workflow automation should deepen live operator approval/readback after Marketplace/payment gates | +| AgentShield enterprise iteration | Policy gates, SARIF, packs, provenance, corpus, HTML reports, exception lifecycle audit, baseline drift Action/CLI surfaces, evidence-pack redaction, harness adapter registry, enterprise research roadmap, supply-chain hardened release path, CI-safe baseline fingerprints, corpus accuracy recommendations, remediation workflow phases, env proxy hijack corpus coverage, Mini Shai-Hulud full-campaign package IOCs, CI-provenance evidence packs, plugin-cache runtime-confidence triage, evidence-pack consumer readback, fleet-level evidence-pack routing, fleet review items, fleet review ticket payloads, checksum-backed policy export, checksum-verified policy promotion, policy promotion review items, package-manager hardening drift detection, npm age-gate guidance correction, workflow action-runtime pin refresh, package-manager hardening Action outputs, policy-promotion Action outputs, ECC-Tools hosted consumption of promotion Action outputs, ECC-Tools operator-visible promotion output values, and ECC-Tools hosted promotion judge audit traces | PRs #53, #55-#64, #67-#69, and #78-#92 landed with test evidence, ECC-Tools #76 consumes the fleet-summary output in hosted security review, #77 surfaces source evidence paths in hosted finding output, and #78 links fleet routes to harness owner review; AgentShield #91 adds `agentshield policy export` bundles for branch-protection review and downstream promotion; AgentShield #92 adds `agentshield policy promote` with digest verification, tamper rejection, explicit pack selection, dry-run review, and JSON output before writing active policy; AgentShield commit `87aec47` adds `reviewItems` for digest evidence, owner review, protected rollout PR handoff, and runtime smoke testing with green local and remote CI; AgentShield commit `28d08c7` adds package-manager hardening drift detection for plaintext registry credentials, lifecycle-script enablement, and weak pnpm/Yarn release-age cooldowns with green local and remote CI; AgentShield commit `659f569` refreshes all workflow action runtime pins to SHA-pinned checkout v6.0.2 and setup-node v6.4.0 with green remote CI and no remaining action-runtime deprecation annotation; AgentShield commit `ee585cd` corrects npm release-age guidance by flagging unsupported npm age keys and keeping enforceable cooldown findings on pnpm/Yarn with green local and remote CI; AgentShield commit `1124535` exposes package-manager hardening status/count outputs and a redacted job-summary section for registry credentials, lifecycle scripts, and release-age gates with green local and remote CI; AgentShield commit `1593925` exposes policy-promotion status/count/digest outputs plus job-summary review items for owner approval, protected rollout, and runtime smoke, and marks runtime smoke verified when the same Action job scans with the promoted policy; AgentShield commit `840952a` adds Linear/operator-ready fleet review ticket payloads and expands current Mini Shai-Hulud IOC breadcrumbs with green local and remote CI; ECC-Tools commit `8658951` routes those policy-promotion Action outputs into hosted security review findings and Hosted Promotion Readiness scoring; ECC-Tools commit `16c537f` renders policy-promotion status, pack, review item count, action-required count, and digest in hosted security job comments/check-runs; ECC-Tools commit `05d4e82` renders hosted promotion judge request fingerprints and allowed-citation counts without raw provider output; native PDF export deferred in favor of self-contained HTML plus print-to-PDF until explicit enterprise demand appears; `docs/architecture/agentshield-enterprise-research-roadmap.md` now has baseline drift, evidence-pack bundle, redaction, adapter-registry, supply-chain hardening, hashed baseline fingerprints, corpus accuracy recommendation, remediation workflow, env proxy hijack corpus, Mini Shai-Hulud full-campaign package-table, `ci-context.json` provenance, `plugin-cache` confidence, `evidence-pack inspect` readback, `evidence-pack fleet` routing, fleet `reviewItems`, fleet review ticket payloads, policy export, policy promotion, policy promotion `reviewItems`, package-manager hardening Action outputs, policy-promotion Action outputs, hosted consumption of promotion Action outputs, operator-visible promotion output values, and hosted promotion judge audit traces landed | Next workflow automation should deepen live operator approval/readback after Marketplace/payment gates | | ECC Tools next-level app | Billing audit, PR checks, deep analyzer, sync backlog, evaluator/RAG corpus, analysis-depth readiness, hosted execution planning, hosted CI diagnostics, hosted security evidence review, hosted harness compatibility audit, hosted reference-set evaluation, hosted AI routing/cost review, hosted team backlog routing, hosted depth-plan check-run, PR-comment hosted job dispatch, hosted job result history/check-runs, hosted result status command, status-aware depth-plan recommendations, hosted promotion readiness, hosted promotion output scoring, hosted promotion retrieval planning, hosted promotion judge contract, gated hosted promotion judge execution, hosted promotion judge audit trace, payment-announcement readiness, billing announcement preflight, aggregate production billing KV readback, Marketplace webhook provenance, target-account billing readback, Marketplace-source provenance counts, AgentShield fleet-summary hosted routing, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output hosted telemetry, and operator-visible promotion output values | PRs #26-#43 plus #53-#78 landed with test evidence, including AgentShield evidence-pack gap routing, canonical bundle recognition, supply-chain signature gates, PR draft follow-up Linear tracking, evidence-backed/deep-ready repository classification, the `/api/analysis/depth-plan` hosted job plan, `/api/analysis/jobs/ci-diagnostics`, `/api/analysis/jobs/security-evidence-review`, `/api/analysis/jobs/harness-compatibility-audit`, `/api/analysis/jobs/reference-set-evaluation`, `/api/analysis/jobs/ai-routing-cost-review`, `/api/analysis/jobs/team-backlog-routing`, the `ECC Tools / Hosted Depth Plan` check-run, `/ecc-tools analyze --job ...` PR-comment dispatch, non-blocking per-hosted-job result check-runs backed by 30-day result cache records, `/ecc-tools analyze --job status` cache lookup, cache-aware next-job recommendations in the depth-plan check-run, the `ECC Tools / Hosted Promotion Readiness` corpus-backed PR check-run, deterministic hosted-output scoring against cached completed job artifacts/findings, ranked retrieval/model-prompt planning, the fail-closed `hosted-promotion-judge.v1` request contract, opt-in live model-judge execution behind hosted evidence, entitlement, budget, provider, executor, strict JSON, and citation gates, hosted promotion judge request fingerprints plus allowed-citation audit trails, a fail-closed `/api/billing/readiness` `announcementGate` for native GitHub payments claims, `npm run billing:announcement-gate` plus `--preflight` as the non-secret operator verifier, hosted security findings for AgentShield fleet summaries, an `Evidence` column in hosted finding comments/check-runs, hosted harness findings that route AgentShield fleet target paths to harness owners, ECC-Tools commit `8658951` routing AgentShield policy-promotion Action outputs into hosted security review and promotion-readiness scoring, ECC-Tools commit `16c537f` rendering policy-promotion status/pack/count/digest values directly in hosted security job comments/check-runs, ECC-Tools commit `05d4e82` rendering model-judge audit traces without exposing raw provider output, ECC-Tools commit `91a441b` adding the safe billing announcement preflight path, ECC-Tools commit `eb69412` recording the initial production readback state, ECC-Tools commit `95d0bec` adding `npm run billing:kv-readback` with 253 aggregate account-billing and billing-state records but 0 Marketplace Pro billing-state records, ECC-Tools commit `2859678` requiring webhook-derived Marketplace provenance before announcement readiness, ECC-Tools commit `42653f9` adding Wrangler OAuth readback with live aggregate evidence of 253 account-billing records, 253 billing-state records, and 0 ready-like Marketplace Pro states, ECC-Tools commit `632e059` adding sanitized target-account readback that requires both target key families before `--require-ready` can pass, and ECC-Tools commit `d5f60db` adding sanitized Marketplace plan/action provenance counts; the 2026-05-18 live Wrangler OAuth recheck found 254 account-billing records, 254 billing-state records, 195 Marketplace-source records, 2 Marketplace webhook-provenance records, both `Open Source`, and 0 Marketplace Pro records, then updated Linear ITO-61 with the data/provisioning blocker | Next work is create or verify Marketplace-managed Pro target billing-state with webhook provenance, then run `billing:kv-readback -- --wrangler --wrangler-bin ./node_modules/.bin/wrangler --account --require-ready`, followed by the live announcement gate | | GitGuardian/Dependabot/CodeRabbit-style checks | Non-blocking taxonomy, deterministic follow-up checks, and local supply-chain gates | ECC-Tools risk taxonomy check plus follow-up signals landed, including Skill Quality, Deep Analyzer Evidence, Analyzer Corpus Evidence, RAG/Evaluator Evidence, PR Review/Salvage Evidence, and AgentShield evidence-pack evidence; #1846 added npm registry signature gates; #1848 added the supply-chain incident-response playbook and `pull_request_target` cache-poisoning validator guard; #1851 added the privileged checkout credential-persistence guard; AgentShield #78, JARVIS #13, and ECC-Tools #53 applied the same hardening outside trunk | Current supply-chain gate complete; deeper hosted review features remain future | | Harness-agnostic learning system | Audit, adapter matrix, observability, traces, promotion loop | Audit/adapters/observability gates plus `docs/architecture/evaluator-rag-prototype.md`, `examples/evaluator-rag-prototype/`, and ECC-Tools PR #40 define read-only stale-salvage, billing-readiness, CI-failure-diagnosis, harness-config-quality, AgentShield policy-exception, skill-quality evidence, deep-analyzer evidence, and RAG/evaluator comparison scenarios with trace, report, playbook, verifier, and predictive-check artifacts; ECC-Tools PRs #68-#72 now turn that corpus into a deterministic PR check-run gate with cached hosted-output scoring, ranked retrieval candidates, a model prompt seed, a fail-closed hosted model-judge request contract, and opt-in live model execution behind strict hosted-evidence gates | Deterministic hosted PR check, cached output scoring, retrieval planning, judge contract, and gated model execution integrated | @@ -726,7 +726,7 @@ repo evidence and merge commits. | Release and publication | rc.1 release docs, publication readiness doc | Naming matrix and plugin submission/contact checklist | Before any tag | | Harness OS core | Audit, adapter matrix, observability docs, `ecc2/` | HUD/session-control acceptance spec | Weekly until GA | | Evaluation and RAG | Reference-set validation, harness audit, traces, ECC-Tools corpus | Read-only evaluator/RAG prototype plus stale-salvage, billing-readiness, CI-failure-diagnosis, harness-config-quality, AgentShield policy-exception, skill-quality evidence, deep-analyzer evidence, and RAG/evaluator comparison fixtures; ECC-Tools #68 publishes the corpus as a hosted promotion readiness check-run, #69 scores cached hosted job outputs against the same corpus, #70 emits ranked retrieval candidates plus a model prompt seed, #71 adds a fail-closed hosted model-judge request contract, and #72 executes that judge only when explicitly enabled and backed by hosted retrieval citations; ECC-Tools `16c537f` surfaces policy-promotion Action output values in hosted security comments/checks; ECC-Tools `05d4e82` adds hosted model-judge audit traces with request fingerprints and allowed-citation counts | Marketplace Pro billing-state verification with webhook provenance | -| AgentShield enterprise | AgentShield PR evidence and roadmap notes | Fleet routing landed in #89 after evidence-pack inspect/readback shipped in #88; #90 emits fleet `reviewItems`; #91 exports checksum-backed policy bundles; #92 promotes checksum-verified policies from those bundles into active policy files; AgentShield `87aec47` adds policy promotion `reviewItems`; `28d08c7` adds package-manager hardening drift detection; `659f569` refreshes workflow action runtime pins; `ee585cd` corrects unsupported npm release-age guidance and keeps enforceable cooldown findings on pnpm/Yarn; `1124535` exposes package-manager hardening Action outputs for CI/hosted routing; `1593925` exposes policy-promotion Action outputs and runtime-smoke job-summary evidence; ECC-Tools #76 consumes fleet summaries, #77 surfaces source evidence paths in hosted findings, #78 links fleet routes to harness owners, ECC-Tools `8658951` consumes policy-promotion Action outputs, and ECC-Tools `16c537f` renders operator-visible output values | Deepen live operator approval/readback after Marketplace/payment gates | +| AgentShield enterprise | AgentShield PR evidence and roadmap notes | Fleet routing landed in #89 after evidence-pack inspect/readback shipped in #88; #90 emits fleet `reviewItems`; #91 exports checksum-backed policy bundles; #92 promotes checksum-verified policies from those bundles into active policy files; AgentShield `87aec47` adds policy promotion `reviewItems`; `28d08c7` adds package-manager hardening drift detection; `659f569` refreshes workflow action runtime pins; `ee585cd` corrects unsupported npm release-age guidance and keeps enforceable cooldown findings on pnpm/Yarn; `1124535` exposes package-manager hardening Action outputs for CI/hosted routing; `1593925` exposes policy-promotion Action outputs and runtime-smoke job-summary evidence; `840952a` adds fleet review ticket payloads and current Mini Shai-Hulud IOC breadcrumbs; ECC-Tools #76 consumes fleet summaries, #77 surfaces source evidence paths in hosted findings, #78 links fleet routes to harness owners, ECC-Tools `8658951` consumes policy-promotion Action outputs, and ECC-Tools `16c537f` renders operator-visible output values | Deepen live operator approval/readback after Marketplace/payment gates | | ECC Tools app | ECC-Tools PR evidence, billing audit, risk taxonomy, evaluator/RAG corpus | ECC-Tools #53 published the supply-chain workflow hardening branch, #54 tracks copy-ready PR drafts in the Linear/project backlog, #55 classifies analysis-depth readiness, #56 exposes the hosted execution plan, #57 executes the first hosted CI diagnostics job, #58 executes the hosted security evidence review job, #59 executes the hosted harness compatibility audit, #60 executes the hosted reference-set evaluation, #61 executes the hosted AI routing/cost review, #62 executes hosted team backlog routing, #63 publishes the hosted depth-plan check-run, #64 dispatches hosted jobs from PR comments, #65 persists hosted result history/check-runs, #66 exposes hosted job status from PR comments, #67 makes depth-plan recommendations cache-aware, #68 publishes hosted promotion readiness from the evaluator/RAG corpus, #69 scores cached hosted job outputs against that corpus, #70 emits ranked retrieval candidates plus a model prompt seed, #71 emits the gated `hosted-promotion-judge.v1` contract without live model calls, #72 adds opt-in live model-judge execution behind hosted-evidence and strict JSON/citation gates, #73 adds a fail-closed native-payments `announcementGate` to billing readiness, #74 adds `npm run billing:announcement-gate` for operator verification, #75 tightens the billing announcement gate for live Marketplace readback, #76 routes AgentShield fleet-summary evidence into hosted security findings, #77 adds source evidence paths to hosted finding output, #78 links AgentShield fleet target paths to hosted harness owner findings, `8658951` routes AgentShield policy-promotion Action outputs into hosted security review and promotion readiness, `16c537f` renders policy-promotion status/pack/count/digest values in hosted security comments/checks, `05d4e82` renders hosted promotion judge request fingerprints plus allowed-citation audit traces, `91a441b` adds billing announcement preflight output for required readback inputs, `eb69412` records the initial production readback state, `95d0bec` adds aggregate `billing:kv-readback` evidence, `2859678` requires Marketplace webhook provenance in billing readiness, `42653f9` adds Wrangler OAuth readback with live aggregate production counts, and `632e059` adds sanitized target-account billing readback for the exact Marketplace test account | Create or verify Marketplace-managed Pro target billing-state with webhook provenance, then live target readback and announcement gate | | Linear progress | Linear project status updates, `docs/architecture/progress-sync-contract.md`, generated `operator:dashboard` output, and this mirror | Status update with queue/evidence/missing gates | Every significant merge batch | @@ -974,6 +974,9 @@ Acceptance: security review and Hosted Promotion Readiness scoring, and ECC-Tools commit `16c537f` renders promotion status, pack, review item count, remaining action count, and digest in hosted security comments/check-runs. + AgentShield commit `840952a` adds Linear/operator-ready fleet review ticket + payloads and expands current Mini Shai-Hulud IOC breadcrumbs, with green + local and remote CI. ECC-Tools commit `05d4e82` adds hosted promotion judge audit traces with deterministic request fingerprints and allowed-citation counts, without exposing raw provider output. diff --git a/docs/architecture/agentshield-enterprise-research-roadmap.md b/docs/architecture/agentshield-enterprise-research-roadmap.md index 8c7e9be7..8f61958f 100644 --- a/docs/architecture/agentshield-enterprise-research-roadmap.md +++ b/docs/architecture/agentshield-enterprise-research-roadmap.md @@ -1,6 +1,7 @@ # AgentShield Enterprise Research Roadmap -Generated: 2026-05-12; refreshed with May 16 AgentShield PR #87, #88, and #89 evidence. +Generated: 2026-05-12; refreshed with May 18 AgentShield fleet-ticket and +Mini Shai-Hulud IOC evidence. This is a planning artifact for the next AgentShield enterprise iteration. It does not modify AgentShield code. The goal is to turn the current scanner, @@ -116,14 +117,21 @@ AgentShield PR #89 merged as `agentshield evidence-pack fleet [--json]`, verifies each pack through the inspect path, aggregates finding, policy, baseline, supply-chain, and remediation totals, and assigns each pack to a deterministic fleet route. +AgentShield commit `840952a7a07f820f24081c43df656d7f7295f23b` adds +Linear/operator-ready fleet review ticket payloads with priority, labels, +titles, and Markdown bodies. The same commit expands current Mini +Shai-Hulud/TanStack IOC coverage for the in-cluster Vault endpoint and +temporary lockfile breadcrumb, with local typecheck, lint, full tests, +`git diff --check`, and GitHub CI/Self-Scan/Action-test evidence. The next iteration after fleet routing should not be "add more regex rules" by default. ECC-Tools follow-up routing now consumes fleet summaries and surfaces source evidence paths in hosted findings, and the first cross-harness policy slice now links AgentShield fleet route target paths to harness-owner review. AgentShield fleet output now also emits `reviewItems` with source evidence paths -and owner-ready recommendations for routed packs. The higher leverage move is -durable policy export and workflow automation for routed fleet findings. +and owner-ready recommendations plus copy-ready ticket payloads for routed +packs. The higher leverage move is durable operator approval/readback and +workflow automation for routed fleet findings. ## Enterprise Gaps diff --git a/docs/drafts/release-1.10.1-announcement.md b/docs/drafts/release-1.10.1-announcement.md new file mode 100644 index 00000000..0cb0c5ac --- /dev/null +++ b/docs/drafts/release-1.10.1-announcement.md @@ -0,0 +1,63 @@ +# ECC 1.10.1 release announcement draft + +ECC 1.10.1 is the follow-up stabilization release to 1.10.0. + +This release is focused on install correctness, cross-surface naming clarity, Windows/PowerShell recovery, Cursor project install correctness, and Claude Code hook compatibility. It is not a feature-heavy release. + +## What landed in the stabilization pass +- npm/package/release surfaces are aligned and `ecc-universal@1.10.0` is live on npm +- Windows locale/path and PowerShell install-path regressions fixed +- Bash hook process-storm regression fixed +- Claude Code 2.1.x hook schema compatibility fixed +- Cursor native project install path repaired: + - `.cursor/hooks.json` now includes the required schema/version surface + - `.cursor/mcp.json` is written in the native Cursor project location +- continuous-learning-v2 now accepts `claude-desktop` as a valid entrypoint +- Windows observe path now skips `AppInstallerPythonRedirector.exe` +- docs now distinguish plugin installs from full manual installs more clearly + +## What 1.10.1 is for +- make the current install surfaces predictable +- reduce stale naming/install guidance +- close the follow-up regressions from 1.10.0 +- give users one stable update point instead of piecing together fixes across issues and discussions + +## Included release fixes +- `#1543` Cursor native project hook + MCP install repair +- `#1524` Claude Code v2.1.116 argv-dup mitigation in `settings.local.json` +- `#1522` continuous-learning-v2 accepts `claude-desktop` as a valid entrypoint +- `#1511` Windows observe path skips `AppInstallerPythonRedirector.exe` +- `#1546` continuous-learning-v2 plugin quick start correction +- `#1535` hero overflow follow-up + +## Important naming clarification +- Claude marketplace/plugin identifier: `everything-claude-code@everything-claude-code` +- npm package: `ecc-universal` +- GitHub repo: `affaan-m/everything-claude-code` + +Those are intentionally different surfaces. The plugin identifier follows Anthropic marketplace rules; the npm package remains `ecc-universal`. + +## Still being monitored +This should be announced as a stabilization release, not as “all edge cases are solved.” + +We are still watching for: +- OS-specific edge cases across macOS, Windows, Linux +- shell-specific behavior differences +- Cursor vs Claude plugin install-path mismatches that only appear in older or mixed installs +- third-party provider/tool-name compatibility reports that still need current-main repro + +Current watch-list examples: +- `#1520` likely obsolete unless repro returns on the current installer +- `#1516` not gating unless reproduced on current `main` +- `#1484` remains a Windows umbrella/watch-list issue rather than an active release gate + +## Recommended update guidance +If you hit 1.10.0 install/runtime problems: +1. update to the latest package/plugin surface +2. avoid mixing plugin install plus full manual repo copy unless the docs explicitly say to +3. if problems persist, report: + - OS + shell + - Claude Code/Cursor version + - install method used + - exact stderr/output + - whether the issue is plugin install, npm install, repo sync, or Cursor project install diff --git a/scripts/operator-readiness-dashboard.js b/scripts/operator-readiness-dashboard.js index 60f2aec1..cd3332f0 100644 --- a/scripts/operator-readiness-dashboard.js +++ b/scripts/operator-readiness-dashboard.js @@ -335,7 +335,7 @@ function agentShieldEnterpriseGap(roadmap) { function agentShieldEnterpriseEvidence(roadmap) { if (roadmap.includes('hosted promotion judge audit traces') || roadmap.includes('operator-visible promotion output values')) { - return 'AgentShield policy promotion `reviewItems` landed in `87aec47`; package-manager hardening drift detection landed in `28d08c7`; workflow action runtime pins were refreshed in `659f569`; npm age-gate guidance was corrected in `ee585cd`; package-manager hardening Action outputs landed in `1124535`; policy-promotion Action outputs and runtime-smoke job-summary evidence landed in `1593925`; ECC-Tools consumes those outputs in `8658951`, surfaces operator-readable status/pack/count/digest telemetry in `16c537f`, and renders hosted promotion judge audit traces in `05d4e82`; all are mirrored in the GA roadmap'; + return 'AgentShield policy promotion `reviewItems` landed in `87aec47`; package-manager hardening drift detection landed in `28d08c7`; workflow action runtime pins were refreshed in `659f569`; npm age-gate guidance was corrected in `ee585cd`; package-manager hardening Action outputs landed in `1124535`; policy-promotion Action outputs and runtime-smoke job-summary evidence landed in `1593925`; fleet review ticket payloads and current Mini Shai-Hulud IOC breadcrumbs landed in `840952a`; ECC-Tools consumes those outputs in `8658951`, surfaces operator-readable status/pack/count/digest telemetry in `16c537f`, and renders hosted promotion judge audit traces in `05d4e82`; all are mirrored in the GA roadmap'; } return 'AgentShield enterprise PR evidence is mirrored in the GA roadmap'; From 99e01ded7db15b57e2a47ee377368a12e66c5b5f Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Mon, 18 May 2026 10:28:36 -0400 Subject: [PATCH 02/61] docs: refresh operator dashboard evidence --- .../operator-readiness-dashboard-2026-05-18.md | 8 ++++---- .../publication-evidence-2026-05-18.md | 18 +++++++++++------- 2 files changed, 15 insertions(+), 11 deletions(-) diff --git a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md index 45f1bd38..e9cffa36 100644 --- a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md +++ b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md @@ -2,8 +2,8 @@ This dashboard is generated by `npm run operator:dashboard`. It is an operator snapshot, not release approval. -Generated: 2026-05-18T13:12:35.523Z -Commit: 680aeff0fb9a8598858e3105ba4742973ef386ab +Generated: 2026-05-18T14:28:49.379Z +Commit: 1571494573f8348d6520b7b58f00885ce9d75834 Status: work remaining ## Current Status @@ -13,7 +13,7 @@ Status: work remaining | PR queue | Current | 0 open PRs across tracked repos | | Issue queue | Current | 0 open issues across tracked repos | | Discussions | Current | 0 need maintainer touch; 0 missing accepted answer | -| Local worktree | Current | 0 blocking dirty files; 1 ignored dirty entries | +| Local worktree | Current | 0 blocking dirty files; 0 ignored dirty entries | | Dashboard generation | Current | platform audit ready: true; GitHub skipped: false | | Publication | Not complete | release, npm, plugin, billing, and announcement gates are tracked below | @@ -29,7 +29,7 @@ Status: work remaining | Include Hermes specialized skills safely | docs/HERMES-SETUP.md and skills/hermes-imports/SKILL.md | current | Hermes setup/import artifacts are covered by preview-pack smoke | repeat preview-pack smoke before release review | | Prepare name-change, Claude plugin, and Codex plugin paths | naming-and-publication-matrix plus release-name-plugin-publication checklist plus publication-readiness | in_progress | naming matrix, release publication checklist, and plugin readiness gates exist | real tag/push, marketplace submission, and final channel choice remain approval-gated | | Prepare release notes, articles, tweets, and push notifications | docs/releases/2.0.0-rc.1 social and release-copy files | in_progress | release notes, X thread, LinkedIn draft, and URL ledger are present | final live release/npm/plugin/billing URLs and publish approval still pending | -| Advance AgentShield enterprise iteration | AgentShield PR evidence plus enterprise roadmap | in_progress | AgentShield policy promotion `reviewItems` landed in `87aec47`; package-manager hardening drift detection landed in `28d08c7`; workflow action runtime pins were refreshed in `659f569`; npm age-gate guidance was corrected in `ee585cd`; package-manager hardening Action outputs landed in `1124535`; policy-promotion Action outputs and runtime-smoke job-summary evidence landed in `1593925`; ECC-Tools consumes those outputs in `8658951`, surfaces operator-readable status/pack/count/digest telemetry in `16c537f`, and renders hosted promotion judge audit traces in `05d4e82`; all are mirrored in the GA roadmap | deepen live operator approval/readback after Marketplace/payment gates | +| Advance AgentShield enterprise iteration | AgentShield PR evidence plus enterprise roadmap | in_progress | AgentShield policy promotion `reviewItems` landed in `87aec47`; package-manager hardening drift detection landed in `28d08c7`; workflow action runtime pins were refreshed in `659f569`; npm age-gate guidance was corrected in `ee585cd`; package-manager hardening Action outputs landed in `1124535`; policy-promotion Action outputs and runtime-smoke job-summary evidence landed in `1593925`; fleet review ticket payloads and current Mini Shai-Hulud IOC breadcrumbs landed in `840952a`; ECC-Tools consumes those outputs in `8658951`, surfaces operator-readable status/pack/count/digest telemetry in `16c537f`, and renders hosted promotion judge audit traces in `05d4e82`; all are mirrored in the GA roadmap | deepen live operator approval/readback after Marketplace/payment gates | | Advance ECC Tools native payments and AI-native harness-agnostic app | ECC Tools PR evidence, billing gate, hosted analysis lanes | in_progress | billing announcement gate, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler OAuth readback, target-account billing readback, provenance-aware Marketplace billing-state gates, and sanitized Marketplace plan/action provenance counts are mirrored in the GA roadmap | create or verify Marketplace-managed Pro target billing-state with webhook provenance, then run `billing:kv-readback -- --wrangler --wrangler-bin ./node_modules/.bin/wrangler --account --require-ready`, followed by the live announcement gate | | Audit, prune, or attach legacy work | docs/stale-pr-salvage-ledger.md and legacy inventory | current | legacy salvage ledger and inventory are current; all localization tails are attached to Linear ITO-55 for manual language-owner review | repeat legacy scan before release | | Keep Linear roadmap detailed and progress tracking synchronized | Linear project mirror plus progress-sync contract | current | Linear live sync and project progress surface are current; progress-sync contract defines the file-backed work-items/status path | repeat Linear/project status update and local work-items sync after each significant merge batch | diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md index 8dba7bba..62331ea2 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md @@ -7,10 +7,10 @@ npm publication, plugin tag, marketplace submission, or announcement post. | Field | Evidence | | --- | --- | -| Upstream main | `680aeff0fb9a8598858e3105ba4742973ef386ab` | +| Upstream main | `1571494573f8348d6520b7b58f00885ce9d75834` | | Git remote | `https://github.com/affaan-m/everything-claude-code.git` | -| Evidence scope | Current `main` after PR #1970 workflow-security validator bypass fixes, PR #1971 metrics bridge cost-reporting fixes, PR #1972 `uncloud` skill merge, PR #1973 stale script cleanup, issue #1974 cost-reporting verification/closure, PR #1976 OpenAI/AstraFlow provider response guards, catalog/operator dashboard refresh, ECC-Tools Wrangler OAuth billing readback mirror, Mini Shai-Hulud/TanStack protection recheck, defensive-deny IOC scanner hardening, release name/plugin publication checklist, readiness/smoke gate enforcement for that checklist, current-head CI/security scan, work-items sync, and Linear progress sync | -| Local status caveat | `git status --short --branch` showed `## main...origin/main` plus unrelated untracked `docs/drafts/`; generated evidence files are committed after the source snapshot they describe | +| Evidence scope | Current `main` after PR #1970 workflow-security validator bypass fixes, PR #1971 metrics bridge cost-reporting fixes, PR #1972 `uncloud` skill merge, PR #1973 stale script cleanup, issue #1974 cost-reporting verification/closure, PR #1976 OpenAI/AstraFlow provider response guards, PR #1978 review/closure, catalog/operator dashboard refresh, ECC-Tools Wrangler OAuth billing readback mirror, AgentShield `840952a` fleet-ticket and Mini Shai-Hulud IOC evidence mirror, Mini Shai-Hulud/TanStack protection recheck, defensive-deny IOC scanner hardening, release name/plugin publication checklist, readiness/smoke gate enforcement for that checklist, current-head CI/security scan, work-items sync, and Linear progress sync | +| Local status caveat | `git status --short --branch` was clean at dashboard generation time; generated evidence files are committed after the source snapshot they describe | The actual release operator should repeat all publish-facing checks from the final release commit with a strictly clean checkout before publishing. @@ -24,7 +24,7 @@ final release commit with a strictly clean checkout before publishing. | Discussion audit | `npm run discussion:audit -- --json` | Ready; 58 sampled discussions in `affaan-m/everything-claude-code`, 0 needing maintainer touch, 0 answerable discussions missing accepted answer, and 0 fetch errors | | Platform audit | `node scripts/platform-audit.js --json --allow-untracked docs/drafts/` | Ready; tracked repos report 0 open PRs, 0 open issues, 0 discussion maintainer-touch gaps, 0 answerable Q&A missing accepted answers, and 0 blocking dirty files | | Work-items sync | `node scripts/work-items.js sync-github --repo ` for five tracked repos; `node scripts/status.js --json`; `node scripts/work-items.js list --json` | All five tracked repos synced with 0 open PRs/issues and no changed work items; local status reports 0 open, 0 blocked, and 0 closed work items | -| Operator dashboard | `node scripts/operator-readiness-dashboard.js --markdown --allow-untracked docs/drafts/ --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Generated current dashboard for `680aeff0fb9a8598858e3105ba4742973ef386ab`; dashboard ready true, publication ready false because release, npm, plugin, billing, and announcement gates are approval-gated; ECC Tools target-account billing readback remains the documented native-payments gate; the naming/plugin row now requires the release-name/plugin publication checklist | +| Operator dashboard | `npm run operator:dashboard -- --markdown --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Generated current dashboard for `1571494573f8348d6520b7b58f00885ce9d75834`; dashboard ready true, publication ready false because release, npm, plugin, billing, and announcement gates are approval-gated; AgentShield enterprise evidence now includes `840952a`; ECC Tools target-account billing readback remains the documented native-payments gate; the naming/plugin row still requires the release-name/plugin publication checklist | Tracked repositories in the platform audit and work-items sync were: @@ -49,6 +49,9 @@ Tracked repositories in the platform audit and work-items sync were: | Defensive-deny IOC scanner hardening | Pushed `04d4d819` so explicit Claude `permissions.deny` IOC entries are treated as defensive controls while the same IOC still fails in hooks, tasks, scripts, locks, and payload files; local `npm test` passed 2511/2511 and current-head CI `26017368895` passed 37/37 | | Release name/plugin publication checklist | Pushed `6c0fbfb6` to add `docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md`; the artifact freezes rc.1 as Everything Claude Code / ECC, keeps npm `ecc-universal`, keeps Claude/Codex plugin slug `ecc`, cites current Anthropic/OpenAI plugin publication paths, and blocks rename/npm publish/plugin tag/submission/billing/social actions until final release evidence exists; GitHub Actions CI `26034898420` passed | | Dashboard and preview-pack checklist enforcement | Added `680aeff0` so `scripts/operator-readiness-dashboard.js` and `scripts/preview-pack-smoke.js` require the release-name/plugin publication checklist; local dashboard and smoke tests passed and preview-pack smoke now enforces 26 required artifacts | +| AgentShield enterprise evidence mirror | Added `2ba0c62d` and refreshed the dashboard generator/GA roadmap/AgentShield enterprise roadmap so the ECC release evidence names AgentShield `840952a` fleet review ticket payloads and current Mini Shai-Hulud IOC breadcrumb coverage | +| PR #1978 | Closed broad/failing outside Excel harness PR after review; recorded a corrected split path for a future smaller Excel harness proposal, install-target/tooling PR, plugin-runtime PR, and translation-automation PR | +| Announcement draft tracking | Added `docs/drafts/release-1.10.1-announcement.md` so the stabilization announcement draft is tracked instead of remaining as release-blocking untracked local state | | Clean-worktree preview-pack smoke | Detached worktree at `680aeff0fb9a8598858e3105ba4742973ef386ab`; `node scripts/preview-pack-smoke.js --root --format json` passed 5/5 with digest `0ed831dbd0cf`; 26 required artifacts, final verification commands, Hermes public sanitization boundary, and approval-gated publication blockers were all preserved | | Public queues | Rechecked after the merge and issue-closure batch; 0 PRs, 0 issues, and 0 discussion gaps remain across tracked repos | @@ -103,15 +106,16 @@ Tracked repositories in the platform audit and work-items sync were: target-account acceptance criteria. - Release notes, X, LinkedIn, GitHub release, and longform copy still need final live URLs after release/package/plugin URLs exist. -- The local checkout still has unrelated untracked `docs/drafts/`, so a strict - clean-checkout release pass remains required before real publication. +- The local checkout is clean after the dashboard/evidence refresh, but a + strict clean-checkout release pass remains required before real publication. ## Result The tracked public PR queue, issue queue, discussion queue, local work-items bridge, release-name/plugin publication gate, and Mini Shai-Hulud/TanStack protection loop are current on May 18, 2026 for current `main` through -`680aeff0`, with follow-up ECC Tools billing-gate hardening in `632e059`. +`15714945`, with follow-up ECC Tools billing-gate hardening in `632e059` +and AgentShield enterprise hardening in `840952a`. This improves publication readiness but does not replace the approval-gated release, package, plugin, billing, and announcement steps in `publication-readiness.md`. From b41e6fb3d051158f80a2c6524a7764cd31c5aca0 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Mon, 18 May 2026 10:49:49 -0400 Subject: [PATCH 03/61] docs: refresh publication readiness gate --- .../2.0.0-rc.1/preview-pack-manifest.md | 6 ++-- .../2.0.0-rc.1/publication-readiness.md | 35 ++++++++++--------- scripts/preview-pack-smoke.js | 2 +- tests/docs/ecc2-release-surface.test.js | 3 +- 4 files changed, 24 insertions(+), 22 deletions(-) diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index 3bd680ba..7a3d85c3 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -15,7 +15,7 @@ surfaces, or posting announcements. | `docs/architecture/cross-harness.md` | Shared substrate model for Claude Code, Codex, OpenCode, Cursor, Gemini, Hermes, and terminal-only use | Names portability boundaries and does not claim unsupported native parity | | `docs/architecture/harness-adapter-compliance.md` | Adapter matrix and scorecard | Verified by `npm run harness:adapters -- --check` | | `docs/architecture/observability-readiness.md` | Local operator-readiness gate | Verified by `npm run observability:ready` | -| `docs/architecture/progress-sync-contract.md` | GitHub, Linear, handoff, roadmap, and work-item sync boundary | Checked by `node scripts/platform-audit.js --format json --allow-untracked docs/drafts/` | +| `docs/architecture/progress-sync-contract.md` | GitHub, Linear, handoff, roadmap, and work-item sync boundary | Checked by `node scripts/platform-audit.js --json` | | `scripts/preview-pack-smoke.js` | Deterministic preview-pack smoke gate | Verified by `npm run preview-pack:smoke` | | `docs/releases/2.0.0-rc.1/release-notes.md` | GitHub release copy source | Must be refreshed with final live release/package/plugin URLs before publication | | `docs/releases/2.0.0-rc.1/quickstart.md` | Clone-to-first-workflow path | Covers clone, install, verify, first skill, and harness switch | @@ -24,7 +24,7 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-15.md` | Current May 15 queue, roadmap, security, supply-chain watch, no-lifecycle CI install hardening, AgentShield #86 evidence-pack provenance, ECC Tools billing-gate, Actions cache purge, and `ecc2` test evidence through PR #1941 | Must be superseded by a final clean-checkout evidence file before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-16.md` | Current May 16/17 queue cleanup, recsys skill merge, GateGuard triage, PR #1947 supply-chain protection, AgentShield #87 plugin-cache confidence evidence, AgentShield #88 evidence-pack inspect/readback, AgentShield #89 evidence-pack fleet routing, AgentShield #90 fleet review items, AgentShield #91 policy export, AgentShield #92 policy promotion, ECC-Tools #76 fleet-summary consumption, ECC-Tools #77 hosted finding evidence paths, ECC-Tools #78 harness policy-route linking, dashboard refresh, and combined Node/Rust/release-surface gate evidence through the May 16 mirror | Must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` | May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack protection recheck, npm audit/signature checks, legacy and Linear progress routing, deterministic preview-pack smoke, operator dashboard refresh, Linear sync, and GitHub CI evidence for `27dc2918` | Superseded by the May 18 evidence snapshot; repeat from a strict clean checkout before real publication | -| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | Current May 18 queue-zero state, #1970/#1971/#1972 merge batch, current-head Mini Shai-Hulud/TanStack protection recheck, no-lifecycle install, npm audit/signature checks, AgentShield project `.claude` scan, work-items sync, Linear sync, operator dashboard refresh, and Supply-Chain Watch success for `3b7e0ba3` | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | +| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | Current May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, current-head Mini Shai-Hulud/TanStack protection recheck, no-lifecycle install, npm audit/signature checks, AgentShield `840952a` enterprise/IOC evidence mirror, work-items sync, Linear sync, operator dashboard refresh, and current-head CI/security scan success for `99e01ded` | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and publication, plugin, billing, AgentShield, ECC Tools, legacy, and Linear productization gaps still open | | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-18.md` | Live URL and approval-gated URL ledger for release copy | Must be regenerated from the final release commit before public announcements | @@ -73,7 +73,7 @@ Run these from the exact release commit before publication: ```bash git status --short --branch -node scripts/platform-audit.js --format json --allow-untracked docs/drafts/ +node scripts/platform-audit.js --json npm run preview-pack:smoke npm run harness:adapters -- --check npm run harness:audit -- --format json diff --git a/docs/releases/2.0.0-rc.1/publication-readiness.md b/docs/releases/2.0.0-rc.1/publication-readiness.md index 37b0ecce..664147ae 100644 --- a/docs/releases/2.0.0-rc.1/publication-readiness.md +++ b/docs/releases/2.0.0-rc.1/publication-readiness.md @@ -39,10 +39,11 @@ routing, deterministic preview-pack smoke gate, and current operator dashboard refresh, see [`publication-evidence-2026-05-17.md`](publication-evidence-2026-05-17.md). For the May 18 current-head queue, workflow-security/metrics/uncloud merge -batch, Mini Shai-Hulud/TanStack local and home protection recheck, npm -no-lifecycle install/audit/signature gates, AgentShield project scan, +batch, PR #1978 review/closure, Mini Shai-Hulud/TanStack local and home +protection recheck, npm no-lifecycle install/audit/signature gates, +AgentShield project scan, AgentShield `840952a` enterprise/IOC evidence mirror, work-items sync, Linear progress comments, operator dashboard refresh, and -current-head Supply-Chain Watch, see +current-head CI/security scan success for `99e01ded`, see [`publication-evidence-2026-05-18.md`](publication-evidence-2026-05-18.md). For the operator-facing prompt-to-artifact readiness dashboard from the same May 16 pass, see @@ -91,22 +92,22 @@ Record the exact commit SHA and command output before any publication action: | Evidence | Command | Required result | Recorded output | | --- | --- | --- | --- | -| Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | Pending final strict clean-checkout release pass; `publication-evidence-2026-05-17.md` records current `main` with unrelated untracked `docs/drafts/` | -| Preview-pack smoke | `npm run preview-pack:smoke` | Preview pack artifacts, Hermes boundary, final verification command list, and publication blockers pass | `publication-evidence-2026-05-17.md`: ready yes, digest `dfb1ed014607`, 5 passed, 0 failed; repeat in a final strict clean-checkout release pass | -| Harness audit | `npm run harness:audit -- --format json` | 70/70 passing | `publication-evidence-2026-05-17.md`: 70/70 | -| Adapter scorecard | `npm run harness:adapters -- --check` | PASS | `publication-evidence-2026-05-16.md`: PASS, 11 adapters | -| Observability readiness | `npm run observability:ready` | 21/21 passing | `publication-evidence-2026-05-17.md`: 21/21, ready yes | -| Release safety gate | `npm run observability:ready -- --format json` | Release Safety category passing with publication readiness, supply-chain, workflow security, package surface, and release-surface evidence | `publication-evidence-2026-05-13-post-hardening.md`: Release Safety 3/3 | -| Supply-chain verification | `npm audit --json`; `npm audit signatures`; `cd ecc2 && cargo audit -q`; Dependabot alerts; GitGuardian Security Checks | 0 vulnerabilities/alerts, registry signatures verified, GitGuardian clean | `publication-evidence-2026-05-18.md`: npm registry signatures and attestations verified, 0 high-or-higher npm vulnerabilities, repo/home IOC scans clean, current-head Supply-Chain Watch passed | -| Root suite | `node tests/run-all.js` | 0 failures | `publication-evidence-2026-05-17.md`: `npm test` passed 2487/2487, 0 failed | -| Markdown lint | `npx markdownlint-cli '**/*.md' --ignore node_modules` | 0 failures | `publication-evidence-2026-05-17.md`: passed after ja-JP autonomous-loop anchor repair | +| Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | `99e01ded`: `## main...origin/main`; repeat from the exact final publication commit before release | +| Preview-pack smoke | `npm run preview-pack:smoke` | Preview pack artifacts, Hermes boundary, final verification command list, and publication blockers pass | `publication-evidence-2026-05-18.md`: ready yes, digest `0ed831dbd0cf`, 5 passed, 0 failed; repeat in the final strict clean-checkout release pass | +| Harness audit | `npm run harness:audit -- --format json` | 70/70 passing | `99e01ded`: 70/70, 0 top actions | +| Adapter scorecard | `npm run harness:adapters -- --check` | PASS | `99e01ded`: PASS, 11 adapters | +| Observability readiness | `npm run observability:ready` | 21/21 passing | `publication-evidence-2026-05-18.md`: 21/21, ready yes | +| Release safety gate | `npm run observability:ready -- --format json` | Release Safety category passing with publication readiness, supply-chain, workflow security, package surface, and release-surface evidence | May 18 evidence keeps release safety passing; repeat the JSON gate from the exact final release commit | +| Supply-chain verification | `npm audit --json`; `npm audit signatures`; `cd ecc2 && cargo audit -q`; Dependabot alerts; GitGuardian Security Checks | 0 vulnerabilities/alerts, registry signatures verified, GitGuardian clean | `publication-evidence-2026-05-18.md` plus CI `26040120071`: npm registry signatures and attestations verified, 0 high-or-higher npm vulnerabilities, repo/home IOC scans clean, supply-chain IOC scan passed | +| Root suite | `node tests/run-all.js` | 0 failures | `99e01ded`: local `node tests/run-all.js` passed 2512/2512; CI `26040120071` passed the full OS/runtime/package-manager matrix | +| Markdown lint | `npx markdownlint-cli '**/*.md' --ignore node_modules` | 0 failures | CI `26040120071`: markdownlint passed on current head; rerun after any release-copy edits | | Package surface | `node tests/scripts/npm-publish-surface.test.js` | 0 failures; no Python bytecode in npm tarball | `2/2` passed in May 12 evidence pass | -| Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | `publication-evidence-2026-05-16.md`: 20/20 passed | +| Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | `99e01ded`: 21/21 passed | | Optional Rust surface | `cd ecc2 && cargo test` | 0 failures or explicit deferral | `publication-evidence-2026-05-16.md`: 462/462 passed, existing warnings only | -| Queue baseline | `gh pr list` / `gh issue list` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | `publication-evidence-2026-05-17.md`: platform audit ready, 0 open PRs and 0 open issues across checked repos | -| Discussion baseline | `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | `publication-evidence-2026-05-15.md`: 58 trunk discussions, 0 without maintainer touch; other tracked repos disabled or 0 | -| Linear roadmap | Linear project and issue readback | Detailed roadmap exists with release, security, AgentShield, ECC Tools, legacy, and observability lanes | `publication-evidence-2026-05-15.md`: project and 16 issue lanes recorded | -| Operator readiness dashboard | `npm run operator:dashboard -- --json --allow-untracked docs/drafts/` | Current queue state mapped to macro-goal deliverables and incomplete gaps | `publication-evidence-2026-05-18.md`: generated from `3b7e0ba3`, platform ready true, dashboard ready true, 0 open PRs, 0 open issues, 0 discussion gaps; regenerated May 18 dashboard now also tracks the URL ledger | +| Queue baseline | `node scripts/platform-audit.js --json` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | `99e01ded`: platform audit ready, 0 open PRs, 0 open issues, 0 conflicting PRs, and 0 blocking dirty files | +| Discussion baseline | `node scripts/platform-audit.js --json` and `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | `99e01ded`: platform audit sampled 58 trunk discussions, 0 needing maintainer touch, 0 answerable discussions missing accepted answer | +| Linear roadmap | Linear project and issue readback | Detailed roadmap exists with release, security, AgentShield, ECC Tools, legacy, and observability lanes | May 18 Linear comments include ITO-57 `f1c896d9-dd27-4ba2-b5a8-60afe5125c22`; earlier evidence records the project and 16 issue lanes | +| Operator readiness dashboard | `npm run operator:dashboard -- --json` | Current queue state mapped to macro-goal deliverables and incomplete gaps | `99e01ded`: generated May 18 dashboard is committed, platform audit ready true, 0 open PRs, 0 open issues, 0 discussion gaps, and publication gates still approval-gated | | Release URL ledger | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-18.md` plus placeholder-marker scan | Live links and approval-gated links are separated before announcement copy is posted | Ledger records public repo/docs/CI/supply-chain/npm/OpenAI Codex documentation URLs and blocks GitHub release/npm/plugin/billing/social URLs until approval-gated checks pass | | Release name and plugin publication checklist | `docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md` | Name/package/plugin values are frozen, final-release commands are listed, and Claude/Codex publication paths cite current official docs | Checklist keeps `Everything Claude Code / ECC`, `ecc-universal`, and plugin slug `ecc` for rc.1; no rename, npm publish, plugin tag, official listing, billing claim, or announcement before final evidence | diff --git a/scripts/preview-pack-smoke.js b/scripts/preview-pack-smoke.js index 5941141d..f36c8f0e 100644 --- a/scripts/preview-pack-smoke.js +++ b/scripts/preview-pack-smoke.js @@ -40,7 +40,7 @@ const REQUIRED_ARTIFACTS = [ const REQUIRED_VERIFICATION_COMMANDS = [ 'git status --short --branch', - 'node scripts/platform-audit.js --format json --allow-untracked docs/drafts/', + 'node scripts/platform-audit.js --json', 'npm run preview-pack:smoke', 'npm run harness:adapters -- --check', 'npm run harness:audit -- --format json', diff --git a/tests/docs/ecc2-release-surface.test.js b/tests/docs/ecc2-release-surface.test.js index 6f312efb..7f83b233 100644 --- a/tests/docs/ecc2-release-surface.test.js +++ b/tests/docs/ecc2-release-surface.test.js @@ -293,7 +293,8 @@ test('publication readiness checklist gates public release actions on evidence', assert.ok(source.includes('release-name-plugin-publication-checklist-2026-05-18.md')); assert.ok(source.includes('Release name and plugin publication checklist')); assert.ok(may15Evidence.includes('| Trunk discussions | GraphQL discussion count and maintainer-touch sweep | 58 total discussions;')); - assert.ok(source.includes('58 trunk discussions, 0 without maintainer touch')); + assert.ok(source.includes('platform audit sampled 58 trunk discussions')); + assert.ok(source.includes('0 needing maintainer touch')); assert.ok(may15Evidence.includes('env -u GITHUB_TOKEN')); assert.ok(may15Evidence.includes('ITO-44')); assert.ok(may15Evidence.includes('0 open PRs, 0 open issues')); From 386326df8eaf06625f4f112b2f14703456b62874 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Mon, 18 May 2026 12:48:52 -0400 Subject: [PATCH 04/61] fix: treat MCP HTTP 406 probes as reachable --- scripts/hooks/mcp-health-check.js | 6 ++- tests/hooks/mcp-health-check.test.js | 69 ++++++++++++++++++++++++++++ 2 files changed, 73 insertions(+), 2 deletions(-) diff --git a/scripts/hooks/mcp-health-check.js b/scripts/hooks/mcp-health-check.js index 3e763d05..b880d7d9 100644 --- a/scripts/hooks/mcp-health-check.js +++ b/scripts/hooks/mcp-health-check.js @@ -26,8 +26,10 @@ const DEFAULT_BACKOFF_MS = 30 * 1000; const MAX_BACKOFF_MS = 10 * 60 * 1000; // The preflight HTTP probe only checks reachability; it does not have access to // Claude Code's stored OAuth bearer token. Treat auth-gated responses as -// reachable so the real MCP client can attempt the authenticated call. -const HEALTHY_HTTP_CODES = new Set([200, 201, 202, 204, 301, 302, 303, 304, 307, 308, 400, 401, 403, 405]); +// reachable so the real MCP client can attempt the authenticated call. A +// Streamable HTTP MCP server can also return 406 to a bare GET that omits +// Accept: text/event-stream; that still proves the endpoint is alive. +const HEALTHY_HTTP_CODES = new Set([200, 201, 202, 204, 301, 302, 303, 304, 307, 308, 400, 401, 403, 405, 406]); const RECONNECT_STATUS_CODES = new Set([401, 403, 429, 503]); const FAILURE_PATTERNS = [ { code: 401, pattern: /\b401\b|unauthori[sz]ed|auth(?:entication)?\s+(?:failed|expired|invalid)/i }, diff --git a/tests/hooks/mcp-health-check.test.js b/tests/hooks/mcp-health-check.test.js index 9f01f12e..1fb56cfc 100644 --- a/tests/hooks/mcp-health-check.test.js +++ b/tests/hooks/mcp-health-check.test.js @@ -955,6 +955,75 @@ async function runTests() { } })) passed++; else failed++; + if (await asyncTest('treats HTTP 406 probe responses as healthy reachable Streamable HTTP MCP servers', async () => { + const tempDir = createTempDir(); + const configPath = path.join(tempDir, 'claude.json'); + const statePath = path.join(tempDir, 'mcp-health.json'); + const serverScript = path.join(tempDir, 'http-406-server.js'); + const portFile = path.join(tempDir, 'server-port.txt'); + + fs.writeFileSync( + serverScript, + [ + "const fs = require('fs');", + "const http = require('http');", + "const portFile = process.argv[2];", + "const server = http.createServer((req, res) => {", + " if (String(req.headers.accept || '').includes('text/event-stream')) {", + " res.writeHead(200, { 'Content-Type': 'text/event-stream' });", + " res.end();", + " return;", + " }", + " res.writeHead(406, { 'Content-Type': 'application/json' });", + " res.end(JSON.stringify({ error: 'missing Accept: text/event-stream' }));", + "});", + "server.listen(0, '127.0.0.1', () => {", + " fs.writeFileSync(portFile, String(server.address().port));", + "});", + "setInterval(() => {}, 1000);" + ].join('\n') + ); + + const serverProcess = spawn(process.execPath, [serverScript, portFile], { + stdio: 'ignore' + }); + + try { + const port = waitForFile(portFile).trim(); + await waitForHttpReady(`http://127.0.0.1:${port}/mcp`); + + writeConfig(configPath, { + mcpServers: { + streamable: { + type: 'http', + url: `http://127.0.0.1:${port}/mcp` + } + } + }); + + const input = { tool_name: 'mcp__streamable__initialize', tool_input: {} }; + const result = runHook(input, { + CLAUDE_HOOK_EVENT_NAME: 'PreToolUse', + ECC_MCP_CONFIG_PATH: configPath, + ECC_MCP_HEALTH_STATE_PATH: statePath, + ECC_MCP_HEALTH_TIMEOUT_MS: '2000' + }); + + assert.strictEqual( + result.code, + 0, + `Expected HTTP 406 probe to be treated as healthy: ${hookFailureDetails(result, statePath)}` + ); + assert.strictEqual(result.stdout.trim(), JSON.stringify(input), 'Expected original JSON on stdout'); + + const state = readState(statePath); + assert.strictEqual(state.servers.streamable.status, 'healthy', 'Expected Streamable HTTP MCP server to be marked healthy'); + } finally { + serverProcess.kill('SIGTERM'); + cleanupTempDir(tempDir); + } + })) passed++; else failed++; + // Windows-only: child_process.spawn cannot resolve .cmd/.bat shims for // bare PATH commands without an extension, and Node 18.20+/20.12+ refuse // to spawn .cmd targets without `shell: true` (CVE-2024-27980). The probe From 7911af4a39cea763e3d06f24e9873772845e5dab Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Mon, 18 May 2026 13:41:10 -0400 Subject: [PATCH 05/61] security: scope release oidc publishing --- .github/workflows/release.yml | 51 ++++++++++++++++++--- .github/workflows/reusable-release.yml | 51 ++++++++++++++++++--- scripts/ci/validate-workflow-security.js | 13 ++++++ tests/ci/validate-workflow-security.test.js | 17 ++++++- tests/scripts/release-publish.test.js | 8 ++-- 5 files changed, 124 insertions(+), 16 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 7ebda383..f15d456b 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -5,13 +5,16 @@ on: tags: ['v*'] permissions: - contents: write - id-token: write + contents: read jobs: - release: - name: Create Release + verify: + name: Verify Release runs-on: ubuntu-latest + outputs: + already_published: ${{ steps.npm_publish_state.outputs.already_published }} + dist_tag: ${{ steps.npm_publish_state.outputs.dist_tag }} + package_file: ${{ steps.pack.outputs.package_file }} steps: - name: Checkout @@ -97,6 +100,42 @@ jobs: - For migration tips and compatibility notes, see README and CHANGELOG. EOF + - name: Pack npm artifact + id: pack + run: | + npm pack --json > npm-pack.json + PACKAGE_FILE=$(node -e "const fs = require('fs'); const data = JSON.parse(fs.readFileSync('npm-pack.json', 'utf8')); console.log(data[0].filename)") + echo "package_file=${PACKAGE_FILE}" >> "$GITHUB_OUTPUT" + + - name: Upload release artifacts + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: ecc-release-artifacts + path: | + release_body.md + ${{ steps.pack.outputs.package_file }} + if-no-files-found: error + + publish: + name: Publish Release + runs-on: ubuntu-latest + needs: verify + permissions: + contents: write + id-token: write + + steps: + - name: Download release artifacts + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + name: ecc-release-artifacts + + - name: Setup Node.js + uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 + with: + node-version: '20.x' + registry-url: 'https://registry.npmjs.org' + - name: Create GitHub Release uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v3.0.0 with: @@ -106,7 +145,7 @@ jobs: make_latest: ${{ contains(github.ref_name, '-') && 'false' || 'true' }} - name: Publish npm package - if: steps.npm_publish_state.outputs.already_published != 'true' + if: needs.verify.outputs.already_published != 'true' env: NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} - run: npm publish --access public --provenance --tag "${{ steps.npm_publish_state.outputs.dist_tag }}" + run: npm publish "${{ needs.verify.outputs.package_file }}" --access public --provenance --tag "${{ needs.verify.outputs.dist_tag }}" diff --git a/.github/workflows/reusable-release.yml b/.github/workflows/reusable-release.yml index 62839e74..365a1260 100644 --- a/.github/workflows/reusable-release.yml +++ b/.github/workflows/reusable-release.yml @@ -28,13 +28,16 @@ on: default: true permissions: - contents: write - id-token: write + contents: read jobs: - release: - name: Create Release + verify: + name: Verify Release runs-on: ubuntu-latest + outputs: + already_published: ${{ steps.npm_publish_state.outputs.already_published }} + dist_tag: ${{ steps.npm_publish_state.outputs.dist_tag }} + package_file: ${{ steps.pack.outputs.package_file }} steps: - name: Checkout @@ -114,6 +117,42 @@ jobs: - Claude marketplace/plugin identifier: \`everything-claude-code@everything-claude-code\` EOF + - name: Pack npm artifact + id: pack + run: | + npm pack --json > npm-pack.json + PACKAGE_FILE=$(node -e "const fs = require('fs'); const data = JSON.parse(fs.readFileSync('npm-pack.json', 'utf8')); console.log(data[0].filename)") + echo "package_file=${PACKAGE_FILE}" >> "$GITHUB_OUTPUT" + + - name: Upload release artifacts + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: ecc-release-artifacts + path: | + release_body.md + ${{ steps.pack.outputs.package_file }} + if-no-files-found: error + + publish: + name: Publish Release + runs-on: ubuntu-latest + needs: verify + permissions: + contents: write + id-token: write + + steps: + - name: Download release artifacts + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + name: ecc-release-artifacts + + - name: Setup Node.js + uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0 + with: + node-version: '20.x' + registry-url: 'https://registry.npmjs.org' + - name: Create GitHub Release uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v3.0.0 with: @@ -124,7 +163,7 @@ jobs: make_latest: ${{ contains(inputs.tag, '-') && 'false' || 'true' }} - name: Publish npm package - if: steps.npm_publish_state.outputs.already_published != 'true' + if: needs.verify.outputs.already_published != 'true' env: NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} - run: npm publish --access public --provenance --tag "${{ steps.npm_publish_state.outputs.dist_tag }}" + run: npm publish "${{ needs.verify.outputs.package_file }}" --access public --provenance --tag "${{ needs.verify.outputs.dist_tag }}" diff --git a/scripts/ci/validate-workflow-security.js b/scripts/ci/validate-workflow-security.js index ec7f82ef..5afec1ba 100644 --- a/scripts/ci/validate-workflow-security.js +++ b/scripts/ci/validate-workflow-security.js @@ -45,6 +45,7 @@ const NPM_AUDIT_PATTERN = /\bnpm\s+audit\b(?!\s+signatures\b)/; const NPM_AUDIT_SIGNATURES_PATTERN = /\bnpm\s+audit\s+signatures\b/; const ACTIONS_CACHE_PATTERN = /uses:\s*['"]?actions\/cache@/m; const ID_TOKEN_WRITE_PATTERN = /^\s*id-token:\s*write\b/m; +const TOP_LEVEL_JOBS_PATTERN = /^jobs:\s*$/m; const UNSAFE_INSTALL_PATTERNS = [ { pattern: /\bnpm\s+ci\b(?![^\n]*--ignore-scripts)/g, @@ -121,6 +122,8 @@ function extractCheckoutSteps(source) { function findViolations(filePath, source) { const violations = []; const checkoutSteps = extractCheckoutSteps(source); + const jobsIndex = source.search(TOP_LEVEL_JOBS_PATTERN); + const workflowHeader = jobsIndex >= 0 ? source.slice(0, jobsIndex) : source; for (const rule of RULES) { if (!rule.eventPattern.test(source)) { @@ -175,6 +178,16 @@ function findViolations(filePath, source) { } + if (ID_TOKEN_WRITE_PATTERN.test(workflowHeader)) { + violations.push({ + filePath, + event: 'workflow-scoped id-token', + description: 'id-token: write must be scoped to a publish-only job, not the entire workflow', + expression: 'top-level id-token: write', + line: getLineNumber(source, source.search(ID_TOKEN_WRITE_PATTERN)), + }); + } + for (const installRule of UNSAFE_INSTALL_PATTERNS) { for (const match of source.matchAll(installRule.pattern)) { violations.push({ diff --git a/tests/ci/validate-workflow-security.test.js b/tests/ci/validate-workflow-security.test.js index 89cf88a9..d7991ed4 100644 --- a/tests/ci/validate-workflow-security.test.js +++ b/tests/ci/validate-workflow-security.test.js @@ -244,12 +244,27 @@ function run() { if (test('rejects actions/cache in workflows with id-token write', () => { const result = runValidator({ - 'unsafe-oidc-cache.yml': `name: Unsafe\non:\n push:\npermissions:\n contents: read\n id-token: write\njobs:\n release:\n runs-on: ubuntu-latest\n steps:\n - uses: actions/cache@v5\n with:\n path: ~/.npm\n key: cache\n`, + 'unsafe-oidc-cache.yml': `name: Unsafe\non:\n push:\npermissions:\n contents: read\njobs:\n release:\n runs-on: ubuntu-latest\n permissions:\n contents: read\n id-token: write\n steps:\n - uses: actions/cache@v5\n with:\n path: ~/.npm\n key: cache\n`, }); assert.notStrictEqual(result.status, 0, 'Expected validator to fail on id-token workflow cache use'); assert.match(result.stderr, /id-token: write must not restore or save shared dependency caches/); })) passed++; else failed++; + if (test('rejects workflow-scoped id-token write', () => { + const result = runValidator({ + 'unsafe-workflow-oidc.yml': `name: Unsafe\non:\n push:\npermissions:\n contents: read\n id-token: write\njobs:\n verify:\n runs-on: ubuntu-latest\n steps:\n - run: npm ci --ignore-scripts\n`, + }); + assert.notStrictEqual(result.status, 0, 'Expected validator to fail on workflow-level id-token write'); + assert.match(result.stderr, /id-token: write must be scoped to a publish-only job/); + })) passed++; else failed++; + + if (test('allows job-scoped id-token for publish-only jobs', () => { + const result = runValidator({ + 'safe-publish-oidc.yml': `name: Safe\non:\n push:\npermissions:\n contents: read\njobs:\n publish:\n runs-on: ubuntu-latest\n permissions:\n contents: write\n id-token: write\n steps:\n - run: npm publish package.tgz --access public --provenance\n`, + }); + assert.strictEqual(result.status, 0, result.stderr || result.stdout); + })) passed++; else failed++; + if (test('rejects npm audit without registry signature verification', () => { const result = runValidator({ 'unsafe-audit.yml': `name: Unsafe\non:\n push:\njobs:\n audit:\n runs-on: ubuntu-latest\n steps:\n - run: npm audit --audit-level=high\n`, diff --git a/tests/scripts/release-publish.test.js b/tests/scripts/release-publish.test.js index 6365161d..f3318fb7 100644 --- a/tests/scripts/release-publish.test.js +++ b/tests/scripts/release-publish.test.js @@ -32,9 +32,11 @@ for (const workflow of [ '.github/workflows/reusable-release.yml', ]) { const content = load(workflow); + const workflowHeader = content.slice(0, content.indexOf('\njobs:\n')); - test(`${workflow} grants id-token for npm provenance`, () => { - assert.match(content, /permissions:\s*[\s\S]*id-token:\s*write/m); + test(`${workflow} scopes id-token to the publish job for npm provenance`, () => { + assert.doesNotMatch(workflowHeader, /id-token:\s*write/); + assert.match(content, /\n\s+permissions:\n\s+contents:\s*write\n\s+id-token:\s*write/m); }); test(`${workflow} configures the npm registry`, () => { @@ -51,7 +53,7 @@ for (const workflow of [ }); test(`${workflow} publishes new tag versions to npm`, () => { - assert.match(content, /npm publish --access public --provenance/); + assert.match(content, /npm publish "\$\{\{ needs\.verify\.outputs\.package_file \}\}" --access public --provenance/); assert.match(content, /NODE_AUTH_TOKEN:\s*\$\{\{\s*secrets\.NPM_TOKEN\s*\}\}/); }); From 97567a91e79e1ee4c291eb78f5f9c30c2046ac94 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Mon, 18 May 2026 13:53:26 -0400 Subject: [PATCH 06/61] test: normalize release workflow line endings --- tests/scripts/release-publish.test.js | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/tests/scripts/release-publish.test.js b/tests/scripts/release-publish.test.js index f3318fb7..3f5bcdca 100644 --- a/tests/scripts/release-publish.test.js +++ b/tests/scripts/release-publish.test.js @@ -22,7 +22,7 @@ function test(name, fn) { } function load(relativePath) { - return fs.readFileSync(path.join(repoRoot, relativePath), 'utf8'); + return fs.readFileSync(path.join(repoRoot, relativePath), 'utf8').replace(/\r\n/g, '\n'); } console.log('\n=== Testing release publish workflow ===\n'); @@ -32,7 +32,8 @@ for (const workflow of [ '.github/workflows/reusable-release.yml', ]) { const content = load(workflow); - const workflowHeader = content.slice(0, content.indexOf('\njobs:\n')); + const jobsIndex = content.search(/^jobs:\s*$/m); + const workflowHeader = jobsIndex >= 0 ? content.slice(0, jobsIndex) : content; test(`${workflow} scopes id-token to the publish job for npm provenance`, () => { assert.doesNotMatch(workflowHeader, /id-token:\s*write/); From c032e07b1e326e765b8f16a5e47e042c47ab8f92 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Mon, 18 May 2026 14:24:50 -0400 Subject: [PATCH 07/61] docs: refresh may 18 release evidence --- docs/ECC-2.0-GA-ROADMAP.md | 18 +++++++++------ ...operator-readiness-dashboard-2026-05-18.md | 4 ++-- .../publication-evidence-2026-05-18.md | 19 ++++++++------- .../2.0.0-rc.1/publication-readiness.md | 23 ++++++++++--------- 4 files changed, 36 insertions(+), 28 deletions(-) diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index be742b87..6a0d97b7 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -42,9 +42,9 @@ As of 2026-05-18: and Publication, AgentShield Enterprise Iteration, ECC Tools Next-Level Platform, and Legacy Audit and Salvage. - Linear live sync is current for the May 18 merge and supply-chain batch: - ITO-57 has a new current-head supply-chain protection comment - (`0b9931b9-1556-4ebc-a70c-f3635557625d`), and the ECC platform project has - a new operator progress comment (`e32e5b7a-287b-4bf4-9ed7-314389a157e1`). + ITO-57 has a final emergency supply-chain refresh comment + (`3fe5b2b7-c4fe-401c-a317-b40d72119cb3`), and the ECC platform project has + the latest operator progress comment (`e32e5b7a-287b-4bf4-9ed7-314389a157e1`). Linear project status updates are disabled in this workspace, so the project comment is the supported external status surface. - The latest May 18 merge batch on `main` includes PR #1970 workflow-security @@ -52,15 +52,17 @@ As of 2026-05-18: de-dup fixes, PR #1972 `uncloud` skill activation structure, PR #1976 OpenAI/AstraFlow provider response guards, ECC-Tools Wrangler OAuth billing readback mirror evidence, the `04d4d819` defensive-deny IOC scanner hardening - recheck, and release evidence with a refreshed operator dashboard. + recheck, `7911af4a` release OIDC publishing-scope hardening, `97567a91` + release workflow line-ending normalization, and release evidence with a + refreshed operator dashboard. - `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` records the May 18 queue-zero state, current-head TanStack/Mini Shai-Hulud protection recheck, no-lifecycle npm install, npm audit/signature checks, AgentShield project `.claude` scan, Linear sync, work-items sync, operator dashboard refresh, PR #1976 provider-guard validation, ECC-Tools Wrangler OAuth billing readback evidence, defensive-deny IOC scanner coverage, and current-head CI - success for `04d4d819`; a detached clean-worktree preview-pack smoke from - `742bc58d` passed 5/5 with digest `59bbf2630a44`. + success for `97567a91`; a detached clean-worktree preview-pack smoke from + `680aeff0` passed 5/5 with digest `0ed831dbd0cf`. - `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` regenerates the ITO-44 prompt-to-artifact dashboard from live platform audit evidence: PR queue, issue queue, discussion queue, local worktree gate, @@ -976,7 +978,9 @@ Acceptance: remaining action count, and digest in hosted security comments/check-runs. AgentShield commit `840952a` adds Linear/operator-ready fleet review ticket payloads and expands current Mini Shai-Hulud IOC breadcrumbs, with green - local and remote CI. + local and remote CI. AgentShield commit `4e36aab` hardens CI package installs + after the expanded Mini Shai-Hulud refresh, with CI, Test GitHub Action, + Self-Scan, and Dependabot Update workflows green. ECC-Tools commit `05d4e82` adds hosted promotion judge audit traces with deterministic request fingerprints and allowed-citation counts, without exposing raw provider output. diff --git a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md index e9cffa36..e1399344 100644 --- a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md +++ b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md @@ -2,8 +2,8 @@ This dashboard is generated by `npm run operator:dashboard`. It is an operator snapshot, not release approval. -Generated: 2026-05-18T14:28:49.379Z -Commit: 1571494573f8348d6520b7b58f00885ce9d75834 +Generated: 2026-05-18T18:21:18.798Z +Commit: 97567a91e79e1ee4c291eb78f5f9c30c2046ac94 Status: work remaining ## Current Status diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md index 62331ea2..28f0a2be 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md @@ -7,9 +7,9 @@ npm publication, plugin tag, marketplace submission, or announcement post. | Field | Evidence | | --- | --- | -| Upstream main | `1571494573f8348d6520b7b58f00885ce9d75834` | +| Upstream main | `97567a91e79e1ee4c291eb78f5f9c30c2046ac94` | | Git remote | `https://github.com/affaan-m/everything-claude-code.git` | -| Evidence scope | Current `main` after PR #1970 workflow-security validator bypass fixes, PR #1971 metrics bridge cost-reporting fixes, PR #1972 `uncloud` skill merge, PR #1973 stale script cleanup, issue #1974 cost-reporting verification/closure, PR #1976 OpenAI/AstraFlow provider response guards, PR #1978 review/closure, catalog/operator dashboard refresh, ECC-Tools Wrangler OAuth billing readback mirror, AgentShield `840952a` fleet-ticket and Mini Shai-Hulud IOC evidence mirror, Mini Shai-Hulud/TanStack protection recheck, defensive-deny IOC scanner hardening, release name/plugin publication checklist, readiness/smoke gate enforcement for that checklist, current-head CI/security scan, work-items sync, and Linear progress sync | +| Evidence scope | Current `main` after PR #1970 workflow-security validator bypass fixes, PR #1971 metrics bridge cost-reporting fixes, PR #1972 `uncloud` skill merge, PR #1973 stale script cleanup, issue #1974 cost-reporting verification/closure, PR #1976 OpenAI/AstraFlow provider response guards, PR #1978 review/closure, catalog/operator dashboard refresh, ECC-Tools Wrangler OAuth billing readback mirror, AgentShield `840952a` fleet-ticket and Mini Shai-Hulud IOC evidence mirror, Mini Shai-Hulud/TanStack protection recheck, defensive-deny IOC scanner hardening, release name/plugin publication checklist, readiness/smoke gate enforcement for that checklist, release OIDC publishing-scope hardening, workflow line-ending normalization, current-head CI/security scan, work-items sync, and Linear progress sync | | Local status caveat | `git status --short --branch` was clean at dashboard generation time; generated evidence files are committed after the source snapshot they describe | The actual release operator should repeat all publish-facing checks from the @@ -24,7 +24,7 @@ final release commit with a strictly clean checkout before publishing. | Discussion audit | `npm run discussion:audit -- --json` | Ready; 58 sampled discussions in `affaan-m/everything-claude-code`, 0 needing maintainer touch, 0 answerable discussions missing accepted answer, and 0 fetch errors | | Platform audit | `node scripts/platform-audit.js --json --allow-untracked docs/drafts/` | Ready; tracked repos report 0 open PRs, 0 open issues, 0 discussion maintainer-touch gaps, 0 answerable Q&A missing accepted answers, and 0 blocking dirty files | | Work-items sync | `node scripts/work-items.js sync-github --repo ` for five tracked repos; `node scripts/status.js --json`; `node scripts/work-items.js list --json` | All five tracked repos synced with 0 open PRs/issues and no changed work items; local status reports 0 open, 0 blocked, and 0 closed work items | -| Operator dashboard | `npm run operator:dashboard -- --markdown --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Generated current dashboard for `1571494573f8348d6520b7b58f00885ce9d75834`; dashboard ready true, publication ready false because release, npm, plugin, billing, and announcement gates are approval-gated; AgentShield enterprise evidence now includes `840952a`; ECC Tools target-account billing readback remains the documented native-payments gate; the naming/plugin row still requires the release-name/plugin publication checklist | +| Operator dashboard | `npm run operator:dashboard -- --markdown --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Generated current dashboard for `97567a91e79e1ee4c291eb78f5f9c30c2046ac94`; dashboard ready true, publication ready false because release, npm, plugin, billing, and announcement gates are approval-gated; AgentShield enterprise evidence now includes `840952a`; ECC Tools target-account billing readback remains the documented native-payments gate; the naming/plugin row still requires the release-name/plugin publication checklist | Tracked repositories in the platform audit and work-items sync were: @@ -54,6 +54,8 @@ Tracked repositories in the platform audit and work-items sync were: | Announcement draft tracking | Added `docs/drafts/release-1.10.1-announcement.md` so the stabilization announcement draft is tracked instead of remaining as release-blocking untracked local state | | Clean-worktree preview-pack smoke | Detached worktree at `680aeff0fb9a8598858e3105ba4742973ef386ab`; `node scripts/preview-pack-smoke.js --root --format json` passed 5/5 with digest `0ed831dbd0cf`; 26 required artifacts, final verification commands, Hermes public sanitization boundary, and approval-gated publication blockers were all preserved | | Public queues | Rechecked after the merge and issue-closure batch; 0 PRs, 0 issues, and 0 discussion gaps remain across tracked repos | +| Release OIDC publishing scope | Pushed `7911af4a` to keep the release workflow's trusted-publishing path scoped to release publication instead of broadening OIDC permissions across unrelated jobs; local workflow security validation passed | +| Release workflow normalization | Pushed `97567a91` to normalize release workflow line endings after the OIDC hardening slice; current-head CI `26050727969` passed for `97567a91e79e1ee4c291eb78f5f9c30c2046ac94` | ## Supply-Chain And Security Evidence @@ -61,22 +63,23 @@ Tracked repositories in the platform audit and work-items sync were: | --- | --- | --- | | Repo IOC scan | `npm run security:ioc-scan` | Passed; 198 files inspected | | Home persistence IOC scan | `node scripts/ci/scan-supply-chain-iocs.js --home --json` | Passed; 200 files inspected; `findings: []` | +| ECC workspace IOC recheck | `node scripts/ci/scan-supply-chain-iocs.js --root --home --json` | Passed; 1212 files inspected; `findings: []`; exact local path is kept out of public release evidence | | Narrow active persistence sweep | Targeted search over user-level Claude, VS Code, LaunchAgent/systemd, local-bin, `/tmp`, and `/private/tmp` campaign paths | Existing active targets: 2; no campaign marker hits | | Scanner fixture tests | `node tests/ci/scan-supply-chain-iocs.test.js` | 20 passed, 0 failed, including defensive Claude deny-wall pass and hook-with-same-IOC fail-closed coverage | | Advisory source refresh | `node scripts/ci/supply-chain-advisory-sources.js --refresh --json` | Ready with 9 sources; live refresh produced 1 OpenAI URL warning from Node fetch while primary TanStack, GitHub advisory, StepSecurity, Wiz, Socket, npm, and CISA sources returned OK | | No-lifecycle install | `npm ci --ignore-scripts` | Completed cleanly; 213 packages installed, 0 vulnerabilities | | npm audit | `npm audit --audit-level=high` | 0 vulnerabilities | | npm signatures | `npm audit signatures` | 213 verified registry signatures; 17 verified attestations | -| Workflow security | `node scripts/ci/validate-workflow-security.js` | Validated 8 workflow files | +| Workflow security | `node scripts/ci/validate-workflow-security.js` | Validated 8 workflow files after the release OIDC publishing-scope hardening | | AgentShield project scan | `npx --no-install ecc-agentshield scan --format json` | Grade A / 99; 0 critical, 0 high, 0 medium; 6 low docs-example skill telemetry/governance findings | -| Current-head CI security scan | `gh run view 26017368895 --repo affaan-m/everything-claude-code --json status,conclusion,jobs,url` | Completed successfully for `04d4d81938b20ac2bac1f0025145ab77d6a59f5f`; 37/37 CI jobs passed, including lint, workflow/component validation, coverage, cross-platform package-manager tests, npm audit, and supply-chain IOC scan | +| Current-head CI security scan | `gh run view 26050727969 --repo affaan-m/everything-claude-code --json status,conclusion,headSha,jobs,url` | Completed successfully for `97567a91e79e1ee4c291eb78f5f9c30c2046ac94`; 37/37 CI jobs passed, including lint, workflow/component validation, coverage, cross-platform package-manager tests, npm audit, and supply-chain IOC scan | | Latest Supply-Chain Watch | `gh run view 26010432490 --repo affaan-m/everything-claude-code --json status,conclusion,headSha,url` | Completed successfully for `25ac57ac40e9fc5a0606e76e6339e72c79748c99`; rerun from the final release commit before publication | ## Linear Progress Sync | Surface | Evidence | | --- | --- | -| ITO-57 issue comments | `0b9931b9-1556-4ebc-a70c-f3635557625d` records May 18 queue counts, #1970/#1971/#1972/#1976 merge evidence, supply-chain verification, current-head CI URL, deferred gates, and next slices; reply `6fa15367-d994-4e53-ade3-9462477e1100` records the expanded TanStack/Mini Shai-Hulud recheck, defensive-deny scanner fix, current-head CI `26017368895`, and post-push platform audit | +| ITO-57 issue comments | `0b9931b9-1556-4ebc-a70c-f3635557625d` records May 18 queue counts, #1970/#1971/#1972/#1976 merge evidence, supply-chain verification, current-head CI URL, deferred gates, and next slices; reply `6fa15367-d994-4e53-ade3-9462477e1100` records the expanded TanStack/Mini Shai-Hulud recheck, defensive-deny scanner fix, current-head CI `26017368895`, and post-push platform audit; comment `3fe5b2b7-c4fe-401c-a317-b40d72119cb3` records the final emergency refresh against `97567a91`, AgentShield `4e36aab`, clean ECC/Ito/Documents workspace IOC scans, absent dead-man/persistence artifacts, and package-manager/Claude deny-wall posture | | ECC platform project comment | `e32e5b7a-287b-4bf4-9ed7-314389a157e1` records the same current public queue, security, #1976, and remaining-gate state at the project level | | Project status update caveat | Linear returned "Project status updates are not enabled for this workspace"; project comment was used as the supported status surface | @@ -114,8 +117,8 @@ Tracked repositories in the platform audit and work-items sync were: The tracked public PR queue, issue queue, discussion queue, local work-items bridge, release-name/plugin publication gate, and Mini Shai-Hulud/TanStack protection loop are current on May 18, 2026 for current `main` through -`15714945`, with follow-up ECC Tools billing-gate hardening in `632e059` -and AgentShield enterprise hardening in `840952a`. +`97567a91`, with follow-up ECC Tools billing-gate hardening in `632e059` +and AgentShield enterprise/security hardening through `4e36aab`. This improves publication readiness but does not replace the approval-gated release, package, plugin, billing, and announcement steps in `publication-readiness.md`. diff --git a/docs/releases/2.0.0-rc.1/publication-readiness.md b/docs/releases/2.0.0-rc.1/publication-readiness.md index 664147ae..ba4b66b3 100644 --- a/docs/releases/2.0.0-rc.1/publication-readiness.md +++ b/docs/releases/2.0.0-rc.1/publication-readiness.md @@ -42,8 +42,9 @@ For the May 18 current-head queue, workflow-security/metrics/uncloud merge batch, PR #1978 review/closure, Mini Shai-Hulud/TanStack local and home protection recheck, npm no-lifecycle install/audit/signature gates, AgentShield project scan, AgentShield `840952a` enterprise/IOC evidence mirror, -work-items sync, Linear progress comments, operator dashboard refresh, and -current-head CI/security scan success for `99e01ded`, see +release OIDC publishing-scope hardening, workflow normalization, work-items sync, +Linear progress comments, operator dashboard refresh, and current-head +CI/security scan success for `97567a91`, see [`publication-evidence-2026-05-18.md`](publication-evidence-2026-05-18.md). For the operator-facing prompt-to-artifact readiness dashboard from the same May 16 pass, see @@ -92,22 +93,22 @@ Record the exact commit SHA and command output before any publication action: | Evidence | Command | Required result | Recorded output | | --- | --- | --- | --- | -| Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | `99e01ded`: `## main...origin/main`; repeat from the exact final publication commit before release | +| Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | `97567a91`: `## main...origin/main`; repeat from the exact final publication commit before release | | Preview-pack smoke | `npm run preview-pack:smoke` | Preview pack artifacts, Hermes boundary, final verification command list, and publication blockers pass | `publication-evidence-2026-05-18.md`: ready yes, digest `0ed831dbd0cf`, 5 passed, 0 failed; repeat in the final strict clean-checkout release pass | | Harness audit | `npm run harness:audit -- --format json` | 70/70 passing | `99e01ded`: 70/70, 0 top actions | | Adapter scorecard | `npm run harness:adapters -- --check` | PASS | `99e01ded`: PASS, 11 adapters | | Observability readiness | `npm run observability:ready` | 21/21 passing | `publication-evidence-2026-05-18.md`: 21/21, ready yes | | Release safety gate | `npm run observability:ready -- --format json` | Release Safety category passing with publication readiness, supply-chain, workflow security, package surface, and release-surface evidence | May 18 evidence keeps release safety passing; repeat the JSON gate from the exact final release commit | -| Supply-chain verification | `npm audit --json`; `npm audit signatures`; `cd ecc2 && cargo audit -q`; Dependabot alerts; GitGuardian Security Checks | 0 vulnerabilities/alerts, registry signatures verified, GitGuardian clean | `publication-evidence-2026-05-18.md` plus CI `26040120071`: npm registry signatures and attestations verified, 0 high-or-higher npm vulnerabilities, repo/home IOC scans clean, supply-chain IOC scan passed | -| Root suite | `node tests/run-all.js` | 0 failures | `99e01ded`: local `node tests/run-all.js` passed 2512/2512; CI `26040120071` passed the full OS/runtime/package-manager matrix | -| Markdown lint | `npx markdownlint-cli '**/*.md' --ignore node_modules` | 0 failures | CI `26040120071`: markdownlint passed on current head; rerun after any release-copy edits | +| Supply-chain verification | `npm audit --json`; `npm audit signatures`; `cd ecc2 && cargo audit -q`; Dependabot alerts; GitGuardian Security Checks | 0 vulnerabilities/alerts, registry signatures verified, GitGuardian clean | `publication-evidence-2026-05-18.md` plus CI `26050727969`: npm registry signatures and attestations verified in the evidence pass, 0 high-or-higher npm vulnerabilities, repo/home IOC scans clean, supply-chain IOC scan passed | +| Root suite | `node tests/run-all.js` | 0 failures | `99e01ded`: local `node tests/run-all.js` passed 2512/2512; current-head CI `26050727969` passed the full OS/runtime/package-manager matrix for `97567a91` | +| Markdown lint | `npx markdownlint-cli '**/*.md' --ignore node_modules` | 0 failures | CI `26050727969`: markdownlint passed on current head; rerun after any release-copy edits | | Package surface | `node tests/scripts/npm-publish-surface.test.js` | 0 failures; no Python bytecode in npm tarball | `2/2` passed in May 12 evidence pass | -| Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | `99e01ded`: 21/21 passed | +| Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | `97567a91` evidence refresh: 21/21 passed after public-path sanitization | | Optional Rust surface | `cd ecc2 && cargo test` | 0 failures or explicit deferral | `publication-evidence-2026-05-16.md`: 462/462 passed, existing warnings only | -| Queue baseline | `node scripts/platform-audit.js --json` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | `99e01ded`: platform audit ready, 0 open PRs, 0 open issues, 0 conflicting PRs, and 0 blocking dirty files | -| Discussion baseline | `node scripts/platform-audit.js --json` and `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | `99e01ded`: platform audit sampled 58 trunk discussions, 0 needing maintainer touch, 0 answerable discussions missing accepted answer | -| Linear roadmap | Linear project and issue readback | Detailed roadmap exists with release, security, AgentShield, ECC Tools, legacy, and observability lanes | May 18 Linear comments include ITO-57 `f1c896d9-dd27-4ba2-b5a8-60afe5125c22`; earlier evidence records the project and 16 issue lanes | -| Operator readiness dashboard | `npm run operator:dashboard -- --json` | Current queue state mapped to macro-goal deliverables and incomplete gaps | `99e01ded`: generated May 18 dashboard is committed, platform audit ready true, 0 open PRs, 0 open issues, 0 discussion gaps, and publication gates still approval-gated | +| Queue baseline | `node scripts/platform-audit.js --json` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | `97567a91`: platform audit ready, 0 open PRs, 0 open issues, 0 conflicting PRs, and 0 blocking dirty files | +| Discussion baseline | `node scripts/platform-audit.js --json` and `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | `97567a91`: platform audit sampled 58 trunk discussions, 0 needing maintainer touch, 0 answerable discussions missing accepted answer | +| Linear roadmap | Linear project and issue readback | Detailed roadmap exists with release, security, AgentShield, ECC Tools, legacy, and observability lanes | May 18 Linear comments include ITO-57 `3fe5b2b7-c4fe-401c-a317-b40d72119cb3`; earlier evidence records the project and 16 issue lanes | +| Operator readiness dashboard | `npm run operator:dashboard -- --json` | Current queue state mapped to macro-goal deliverables and incomplete gaps | `97567a91`: generated May 18 dashboard is committed, platform audit ready true, 0 open PRs, 0 open issues, 0 discussion gaps, and publication gates still approval-gated | | Release URL ledger | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-18.md` plus placeholder-marker scan | Live links and approval-gated links are separated before announcement copy is posted | Ledger records public repo/docs/CI/supply-chain/npm/OpenAI Codex documentation URLs and blocks GitHub release/npm/plugin/billing/social URLs until approval-gated checks pass | | Release name and plugin publication checklist | `docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md` | Name/package/plugin values are frozen, final-release commands are listed, and Claude/Codex publication paths cite current official docs | Checklist keeps `Everything Claude Code / ECC`, `ecc-universal`, and plugin slug `ecc` for rc.1; no rename, npm publish, plugin tag, official listing, billing claim, or announcement before final evidence | From 12ac22e6747c6cfa6a6038030f2f56671edfa634 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Mon, 18 May 2026 14:39:11 -0400 Subject: [PATCH 08/61] docs: add discussion response playbook --- docs/ECC-2.0-GA-ROADMAP.md | 6 +- .../discussion-response-playbook.md | 90 +++++++++++++++++++ .../2.0.0-rc.1/publication-readiness.md | 2 +- tests/docs/ecc2-release-surface.test.js | 12 +++ 4 files changed, 107 insertions(+), 3 deletions(-) create mode 100644 docs/architecture/discussion-response-playbook.md diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index 6a0d97b7..3e98cf09 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -36,7 +36,9 @@ As of 2026-05-18: `affaan-m/everything-claude-code` has 58 total discussions and 0 without maintainer touch after May 15 maintainer updates on #73 and #1239; AgentShield, JARVIS, ECC Tools, and the ECC Tools website have discussions disabled or 0 - total discussions. + total discussions. `docs/architecture/discussion-response-playbook.md` now + supplies the ITO-59 response categories, public templates, security-escalation + path, and readback rules for future discussion batches. - The current Linear roadmap contains 16 issue lanes (`ITO-44` through `ITO-59`) and five milestones: Security and Access Baseline, ECC 2.0 Preview and Publication, AgentShield Enterprise Iteration, ECC Tools Next-Level @@ -696,7 +698,7 @@ is not complete unless the evidence column exists and has been freshly verified. | --- | --- | --- | --- | | Keep public PRs below 20 | Repo-family PR recheck | 0 open PRs across `everything-claude-code`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-18 after merging PR #1976 and refreshing platform audit evidence | Complete | | Keep public issues below 20 | Repo-family issue recheck | 0 open issues across `everything-claude-code`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-18 after the live platform audit refresh | Complete | -| Manage repository discussions | Repo-family discussion recheck | Platform audit reports 0 discussion maintainer-touch gaps and 0 answerable Q&A missing accepted answers; trunk still has 58 total discussions | Complete | +| Manage repository discussions | Repo-family discussion recheck plus response playbook | Platform audit reports 0 discussion maintainer-touch gaps and 0 answerable Q&A missing accepted answers; trunk still has 58 total discussions; `docs/architecture/discussion-response-playbook.md` distinguishes support, maintainer coordination, stale/concluded, release, informational, and security-sensitive response paths | Complete | | Manage PR discussions | PR review/comment closure plus merge/close state | ECC #1976 merged after maintainer follow-up validation; no open tracked PRs remain | Complete | | Salvage useful stale work | `docs/stale-pr-salvage-ledger.md` plus `docs/legacy-artifact-inventory.md` | Ledger records salvaged, superseded, skipped, and manual-review tails; #1815-#1818 added cost tracking, skill scout, frontend design guidance, code-reviewer false-positive guardrails, and the May 12 gap pass; #1687, #1609, #1563, #1564, and #1565 localization tails are attached to Linear ITO-55 for language-owner review and no automatic import remains release-blocking | Complete; repeat legacy scan before release | | ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 18 evidence records queue-zero state, #1970/#1971/#1972/#1976 merge batch, supply-chain recheck, defensive-deny IOC scanner hardening, npm no-lifecycle install/audit/signature gates, Linear sync, refreshed operator dashboard, provider-guard validation, ECC-Tools Wrangler OAuth billing readback evidence, successful current-head CI on `04d4d819`, and detached clean-worktree preview-pack smoke digest `59bbf2630a44` | Needs final release approval | diff --git a/docs/architecture/discussion-response-playbook.md b/docs/architecture/discussion-response-playbook.md new file mode 100644 index 00000000..e487dcdb --- /dev/null +++ b/docs/architecture/discussion-response-playbook.md @@ -0,0 +1,90 @@ +# Discussion Response Playbook + +This playbook turns GitHub Discussions into the same operating queue as PRs, +issues, Linear work, and release evidence. It is an operator guide, not a +promise that every informational thread needs a public reply. + +## Audit Loop + +Run these checks before a release, after a major merge batch, and when Linear +ITO-59 is refreshed: + +```bash +npm run discussion:audit -- --json +node scripts/platform-audit.js --json +``` + +The queue is current only when: + +- discussion fetch errors are explained or fixed; +- `needsMaintainerTouch` is zero for support-like discussion categories; +- answerable Q&A discussions either have an accepted answer or a clear routing + note; and +- any product-scope thread is linked to a GitHub issue, Linear issue, roadmap + row, or explicit deferral. + +Informational threads such as announcements, references, show-and-tell, or +maintainer-authored updates can remain visible without becoming response debt. + +## Categories + +| Category | Route | Required readback | +| --- | --- | --- | +| Product support or install confusion | Reply with the exact command/doc path; mark accepted answer for Q&A when the fix is complete | Discussion URL plus accepted-answer URL when applicable | +| Bug report | Ask for a minimal repro, version, harness, and logs; create or link a GitHub issue when reproducible | Issue URL or deferral reason | +| Feature request | Acknowledge the desired outcome and link the closest roadmap issue; do not imply commitment unless scoped | Linear/GitHub roadmap link | +| Security concern | Move exploit details and secrets to a private channel; keep the public reply short and non-operational | Private escalation note plus public safety reply | +| Release or billing question | Answer from the release URL ledger and publication-readiness gates; do not claim unpublished URLs, billing readiness, or plugin availability | Evidence artifact or blocker link | +| Show-and-tell, reference, or announcement | Leave as informational unless there is a direct question or a product-scope signal | Optional roadmap link if useful | +| Stale or concluded thread | Summarize the current state and link the durable doc/issue; avoid reviving low-signal threads | Closure note or explicit no-action rationale | + +## Templates + +### Public Support + +Thanks for the report. The current supported path is: + +```bash + +``` + +The relevant doc is ``. If this does not match your setup, +please reply with the harness, OS, package manager, and the exact error text. + +### Maintainer Coordination + +I am routing this into `` so it does not get lost in the +discussion queue. The next decision is ``. Until that lands, +the supported workaround is ``. + +### Stale Or Concluded + +This thread looks resolved or superseded by ``. I am leaving +it visible for history, but it is no longer an active support queue item. New +repro details should go to ``. + +### Release Announcement + +The current release status is ``. Live URLs are recorded in +`docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-18.md`. Anything marked +pending there should not be announced as shipped yet. + +### Security Escalation + +Thanks for flagging this. Please do not post exploit steps, tokens, customer +data, or secret values in the public thread. I am routing this through the +security response path and will keep the public thread limited to safe status +updates. + +## Recording Outcomes + +For each high-signal discussion, record one of these outcomes: + +- replied publicly and accepted answer read back; +- linked to a GitHub issue or Linear issue; +- routed to the security response path; +- classified as informational; or +- explicitly deferred with a reason. + +Mirror the summary into ITO-59 when the batch closes, and include the counts in +the next operator dashboard or publication evidence refresh. diff --git a/docs/releases/2.0.0-rc.1/publication-readiness.md b/docs/releases/2.0.0-rc.1/publication-readiness.md index ba4b66b3..5cf1b4b8 100644 --- a/docs/releases/2.0.0-rc.1/publication-readiness.md +++ b/docs/releases/2.0.0-rc.1/publication-readiness.md @@ -106,7 +106,7 @@ Record the exact commit SHA and command output before any publication action: | Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | `97567a91` evidence refresh: 21/21 passed after public-path sanitization | | Optional Rust surface | `cd ecc2 && cargo test` | 0 failures or explicit deferral | `publication-evidence-2026-05-16.md`: 462/462 passed, existing warnings only | | Queue baseline | `node scripts/platform-audit.js --json` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | `97567a91`: platform audit ready, 0 open PRs, 0 open issues, 0 conflicting PRs, and 0 blocking dirty files | -| Discussion baseline | `node scripts/platform-audit.js --json` and `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | `97567a91`: platform audit sampled 58 trunk discussions, 0 needing maintainer touch, 0 answerable discussions missing accepted answer | +| Discussion baseline | `node scripts/platform-audit.js --json` and `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | `97567a91`: platform audit sampled 58 trunk discussions, 0 needing maintainer touch, 0 answerable discussions missing accepted answer; `docs/architecture/discussion-response-playbook.md` records response templates and security escalation rules | | Linear roadmap | Linear project and issue readback | Detailed roadmap exists with release, security, AgentShield, ECC Tools, legacy, and observability lanes | May 18 Linear comments include ITO-57 `3fe5b2b7-c4fe-401c-a317-b40d72119cb3`; earlier evidence records the project and 16 issue lanes | | Operator readiness dashboard | `npm run operator:dashboard -- --json` | Current queue state mapped to macro-goal deliverables and incomplete gaps | `97567a91`: generated May 18 dashboard is committed, platform audit ready true, 0 open PRs, 0 open issues, 0 discussion gaps, and publication gates still approval-gated | | Release URL ledger | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-18.md` plus placeholder-marker scan | Live links and approval-gated links are separated before announcement copy is posted | Ledger records public repo/docs/CI/supply-chain/npm/OpenAI Codex documentation URLs and blocks GitHub release/npm/plugin/billing/social URLs until approval-gated checks pass | diff --git a/tests/docs/ecc2-release-surface.test.js b/tests/docs/ecc2-release-surface.test.js index 7f83b233..7caf2ff6 100644 --- a/tests/docs/ecc2-release-surface.test.js +++ b/tests/docs/ecc2-release-surface.test.js @@ -231,6 +231,7 @@ test('launch checklist records the ecc2 alpha version policy', () => { test('publication readiness checklist gates public release actions on evidence', () => { const source = read('docs/releases/2.0.0-rc.1/publication-readiness.md'); const may15Evidence = read('docs/releases/2.0.0-rc.1/publication-evidence-2026-05-15.md'); + const discussionPlaybook = read('docs/architecture/discussion-response-playbook.md'); for (const section of [ '## Release Identity Matrix', @@ -295,6 +296,17 @@ test('publication readiness checklist gates public release actions on evidence', assert.ok(may15Evidence.includes('| Trunk discussions | GraphQL discussion count and maintainer-touch sweep | 58 total discussions;')); assert.ok(source.includes('platform audit sampled 58 trunk discussions')); assert.ok(source.includes('0 needing maintainer touch')); + assert.ok(source.includes('discussion-response-playbook.md')); + for (const expected of [ + 'Public Support', + 'Maintainer Coordination', + 'Stale Or Concluded', + 'Release Announcement', + 'Security Escalation', + 'classified as informational', + ]) { + assert.ok(discussionPlaybook.includes(expected), `discussion playbook missing ${expected}`); + } assert.ok(may15Evidence.includes('env -u GITHUB_TOKEN')); assert.ok(may15Evidence.includes('ITO-44')); assert.ok(may15Evidence.includes('0 open PRs, 0 open issues')); From 0f1775e30b4caa08489761417cad0033c5e6e705 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Mon, 18 May 2026 15:23:48 -0400 Subject: [PATCH 09/61] docs: refresh release blockers evidence --- docs/ECC-2.0-GA-ROADMAP.md | 18 ++++++++++++++++++ .../publication-evidence-2026-05-18.md | 14 ++++++++++---- scripts/operator-readiness-dashboard.js | 13 ++++++++++++- .../operator-readiness-dashboard.test.js | 9 ++++++++- 4 files changed, 48 insertions(+), 6 deletions(-) diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index 3e98cf09..c2eddbff 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -340,6 +340,24 @@ As of 2026-05-18: real Marketplace-managed Pro webhook creates target account provenance and `billing:kv-readback -- --wrangler --wrangler-bin ./node_modules/.bin/wrangler --account --require-ready` plus the official internal announcement gate pass. +- ECC-Tools commit `13cd3fc` normalizes billing-state key casing so + Marketplace webhook writes and announcement readbacks agree on GitHub login + case; current-head CI `26037611421` passed. The code-side readback hardening + remains green, but it does not create live Marketplace Pro state. +- ECC-Tools commit `69ca535` surfaces hosted team-learning feedback controls: + harness compatibility and team-backlog routing now show retention days, + deletion route/SLA, and opt-out route before adaptive recommendations are + routed into team-owned queues. Linear ITO-52 is Done with CI `26054455434`. +- ECC-Tools commit `e56fc1a` updates the lockfile for + `brace-expansion@5.0.6` and fixed Dependabot alert 44 for CVE-2026-45149; + GitHub API reported `state: fixed` at `2026-05-18T19:10:15Z` and current-head + CI `26054671308` passed. +- The latest ITO-61 readback retry remains operationally blocked: Wrangler + Cloudflare API auth returned `Authentication error [code: 10000]`, + 1Password CLI authorization timed out, `billing:announcement-gate -- --preflight` + is missing the target Marketplace account plus `INTERNAL_API_SECRET`, and + native-payments copy remains blocked until the target readback and live + announcement gate pass. - Handoff `ecc-supply-chain-audit-20260513-0645.md` under `~/.cluster-swarm/handoffs/` records the May 13 supply-chain sweep: no active lockfile/manifest hit for diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md index 28f0a2be..ec064ce9 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md @@ -79,8 +79,10 @@ Tracked repositories in the platform audit and work-items sync were: | Surface | Evidence | | --- | --- | -| ITO-57 issue comments | `0b9931b9-1556-4ebc-a70c-f3635557625d` records May 18 queue counts, #1970/#1971/#1972/#1976 merge evidence, supply-chain verification, current-head CI URL, deferred gates, and next slices; reply `6fa15367-d994-4e53-ade3-9462477e1100` records the expanded TanStack/Mini Shai-Hulud recheck, defensive-deny scanner fix, current-head CI `26017368895`, and post-push platform audit; comment `3fe5b2b7-c4fe-401c-a317-b40d72119cb3` records the final emergency refresh against `97567a91`, AgentShield `4e36aab`, clean ECC/Ito/Documents workspace IOC scans, absent dead-man/persistence artifacts, and package-manager/Claude deny-wall posture | -| ECC platform project comment | `e32e5b7a-287b-4bf4-9ed7-314389a157e1` records the same current public queue, security, #1976, and remaining-gate state at the project level | +| ITO-57 issue comments | `0b9931b9-1556-4ebc-a70c-f3635557625d` records May 18 queue counts, #1970/#1971/#1972/#1976 merge evidence, supply-chain verification, current-head CI URL, deferred gates, and next slices; reply `6fa15367-d994-4e53-ade3-9462477e1100` records the expanded TanStack/Mini Shai-Hulud recheck, defensive-deny scanner fix, current-head CI `26017368895`, and post-push platform audit; comment `3fe5b2b7-c4fe-401c-a317-b40d72119cb3` records the final emergency refresh against `97567a91`, AgentShield `4e36aab`, clean ECC/Ito/Documents workspace IOC scans, absent dead-man/persistence artifacts, and package-manager/Claude deny-wall posture; comment `43837404-c01c-4aaa-b5e2-1e784c136d69` records ECC-Tools `brace-expansion` alert 44 fixed in `e56fc1a` with CI `26054671308` and Dependabot API `state: fixed` | +| ITO-52 issue status | `f2e5a208-de91-4a3a-960b-5362d12aa5a4` records ECC-Tools `69ca535` team-learning feedback controls, local verification, and CI `26054455434`; Linear ITO-52 is Done | +| ITO-61 issue status | `8c366592-1c9a-48ad-b9a9-2908a0463fa5` records the latest native-payments readback blocker: Wrangler Cloudflare auth `10000`, 1Password CLI authorization timeout, missing Marketplace target account, and missing `INTERNAL_API_SECRET` | +| ECC platform project comment | `e32e5b7a-287b-4bf4-9ed7-314389a157e1` records the earlier current public queue, security, #1976, and remaining-gate state at the project level; follow-up ITO-44 comments `a01eeef3-c69b-48c0-8804-a4682acfc1ef` and `6b0885cc-c4e9-40db-899b-f7b88b4aa046` record ITO-52 completion and the fixed ECC-Tools Dependabot alert | | Project status update caveat | Linear returned "Project status updates are not enabled for this workspace"; project comment was used as the supported status surface | ## Current Publication Blockers @@ -105,8 +107,12 @@ Tracked repositories in the platform audit and work-items sync were: currently fails with Cloudflare authentication error `10000`. ECC-Tools commit `632e059` adds the follow-up target-account readback mode, redacts the account login and raw KV key names, and requires both target key families - before `--require-ready` can pass. Linear ITO-61 now tracks the exact - target-account acceptance criteria. + before `--require-ready` can pass. ECC-Tools commit `13cd3fc` normalizes + billing-state key casing. The latest ITO-61 retry still fails before readback + because Wrangler Cloudflare auth returns `10000`, 1Password CLI authorization + timed out, and the announcement preflight is missing the target account and + `INTERNAL_API_SECRET`; Linear ITO-61 tracks the exact target-account + acceptance criteria. - Release notes, X, LinkedIn, GitHub release, and longform copy still need final live URLs after release/package/plugin URLs exist. - The local checkout is clean after the dashboard/evidence refresh, but a diff --git a/scripts/operator-readiness-dashboard.js b/scripts/operator-readiness-dashboard.js index cd3332f0..7b47d7d2 100644 --- a/scripts/operator-readiness-dashboard.js +++ b/scripts/operator-readiness-dashboard.js @@ -342,6 +342,12 @@ function agentShieldEnterpriseEvidence(roadmap) { } function eccToolsNextLevelEvidence(roadmap) { + if (roadmap.includes('69ca535') + || roadmap.includes('team feedback controls') + || roadmap.includes('e56fc1a')) { + return 'billing announcement gate, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler OAuth readback, target-account billing readback, provenance-aware Marketplace billing-state gates, sanitized Marketplace plan/action provenance counts, hosted team-learning feedback controls, and ECC-Tools Dependabot alert remediation are mirrored in the GA roadmap'; + } + if (roadmap.includes('d5f60db') || roadmap.includes('Marketplace-source provenance counts')) { return 'billing announcement gate, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler OAuth readback, target-account billing readback, provenance-aware Marketplace billing-state gates, and sanitized Marketplace plan/action provenance counts are mirrored in the GA roadmap'; @@ -381,6 +387,11 @@ function eccToolsNextLevelEvidence(roadmap) { } function eccToolsNextLevelGap(roadmap) { + if (roadmap.includes('1Password CLI authorization timed out') + || roadmap.includes('Cloudflare API auth returned `Authentication error [code: 10000]`')) { + return 'authorize Cloudflare API or 1Password CLI access, configure the target Marketplace Pro account and INTERNAL_API_SECRET, create or replay Marketplace Pro webhook state, then rerun target readback and the live announcement gate'; + } + if (roadmap.includes('d5f60db') || roadmap.includes('Marketplace-source provenance counts')) { return 'create or verify Marketplace-managed Pro target billing-state with webhook provenance, then run `billing:kv-readback -- --wrangler --wrangler-bin ./node_modules/.bin/wrangler --account --require-ready`, followed by the live announcement gate'; @@ -811,7 +822,7 @@ function buildReport(options) { next_work_order: [ 'Regenerate this dashboard from the final release commit before publication evidence is recorded.', 'Repeat ITO-57 Linear/project status sync after the next significant merge batch or advisory-source refresh.', - 'Create or verify Marketplace-managed Pro target billing-state with webhook provenance, then run `billing:kv-readback -- --wrangler --wrangler-bin ./node_modules/.bin/wrangler --account --require-ready`, followed by the live announcement gate before publishing native-payments copy.', + 'Authorize Cloudflare API or 1Password CLI access, configure the target Marketplace Pro account and INTERNAL_API_SECRET, create or replay Marketplace Pro webhook state, then rerun target readback and the live announcement gate before publishing native-payments copy.', 'Resume ITO-45, ITO-46, and ITO-56 only after the generated dashboard and final release gates are refreshed.', ], }; diff --git a/tests/scripts/operator-readiness-dashboard.test.js b/tests/scripts/operator-readiness-dashboard.test.js index 3feef8ee..cda66efa 100644 --- a/tests/scripts/operator-readiness-dashboard.test.js +++ b/tests/scripts/operator-readiness-dashboard.test.js @@ -70,6 +70,11 @@ function seedRepo(rootDir, overrides = {}) { '42653f9', 'target account billing readback', '632e059', + '69ca535', + 'team feedback controls', + 'e56fc1a', + '1Password CLI authorization timed out', + 'Cloudflare API auth returned `Authentication error [code: 10000]`', 'announcementGate', 'ITO-55', 'Linear live sync is current for the May 17 merge batch', @@ -278,7 +283,7 @@ function runTests() { ))); assert.ok(report.requirements.some(item => ( item.id === 'ecc-tools-next-level' - && item.gap === 'create or verify Marketplace-managed Pro target billing-state with webhook provenance, then run `billing:kv-readback -- --account --require-ready` with working Cloudflare API auth or repaired Wrangler OAuth, followed by the live announcement gate' + && item.gap === 'authorize Cloudflare API or 1Password CLI access, configure the target Marketplace Pro account and INTERNAL_API_SECRET, create or replay Marketplace Pro webhook state, then rerun target readback and the live announcement gate' && item.evidence.includes('operator-visible promotion output details') && item.evidence.includes('hosted promotion judge audit traces') && item.evidence.includes('billing announcement preflight') @@ -286,6 +291,8 @@ function runTests() { && item.evidence.includes('Wrangler OAuth readback') && item.evidence.includes('target-account billing readback') && item.evidence.includes('provenance-aware Marketplace billing-state gates') + && item.evidence.includes('hosted team-learning feedback controls') + && item.evidence.includes('ECC-Tools Dependabot alert remediation') ))); assert.ok(report.requirements.some(item => ( item.id === 'naming-and-plugin-publication' From fe7b4f2ba3b3d3678a32280a4c75112afbec7c2f Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Mon, 18 May 2026 15:24:25 -0400 Subject: [PATCH 10/61] docs: regenerate operator readiness dashboard --- .../operator-readiness-dashboard-2026-05-18.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md index e1399344..25cf0437 100644 --- a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md +++ b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md @@ -2,8 +2,8 @@ This dashboard is generated by `npm run operator:dashboard`. It is an operator snapshot, not release approval. -Generated: 2026-05-18T18:21:18.798Z -Commit: 97567a91e79e1ee4c291eb78f5f9c30c2046ac94 +Generated: 2026-05-18T19:23:54.755Z +Commit: 0f1775e30b4caa08489761417cad0033c5e6e705 Status: work remaining ## Current Status @@ -30,7 +30,7 @@ Status: work remaining | Prepare name-change, Claude plugin, and Codex plugin paths | naming-and-publication-matrix plus release-name-plugin-publication checklist plus publication-readiness | in_progress | naming matrix, release publication checklist, and plugin readiness gates exist | real tag/push, marketplace submission, and final channel choice remain approval-gated | | Prepare release notes, articles, tweets, and push notifications | docs/releases/2.0.0-rc.1 social and release-copy files | in_progress | release notes, X thread, LinkedIn draft, and URL ledger are present | final live release/npm/plugin/billing URLs and publish approval still pending | | Advance AgentShield enterprise iteration | AgentShield PR evidence plus enterprise roadmap | in_progress | AgentShield policy promotion `reviewItems` landed in `87aec47`; package-manager hardening drift detection landed in `28d08c7`; workflow action runtime pins were refreshed in `659f569`; npm age-gate guidance was corrected in `ee585cd`; package-manager hardening Action outputs landed in `1124535`; policy-promotion Action outputs and runtime-smoke job-summary evidence landed in `1593925`; fleet review ticket payloads and current Mini Shai-Hulud IOC breadcrumbs landed in `840952a`; ECC-Tools consumes those outputs in `8658951`, surfaces operator-readable status/pack/count/digest telemetry in `16c537f`, and renders hosted promotion judge audit traces in `05d4e82`; all are mirrored in the GA roadmap | deepen live operator approval/readback after Marketplace/payment gates | -| Advance ECC Tools native payments and AI-native harness-agnostic app | ECC Tools PR evidence, billing gate, hosted analysis lanes | in_progress | billing announcement gate, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler OAuth readback, target-account billing readback, provenance-aware Marketplace billing-state gates, and sanitized Marketplace plan/action provenance counts are mirrored in the GA roadmap | create or verify Marketplace-managed Pro target billing-state with webhook provenance, then run `billing:kv-readback -- --wrangler --wrangler-bin ./node_modules/.bin/wrangler --account --require-ready`, followed by the live announcement gate | +| Advance ECC Tools native payments and AI-native harness-agnostic app | ECC Tools PR evidence, billing gate, hosted analysis lanes | in_progress | billing announcement gate, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler OAuth readback, target-account billing readback, provenance-aware Marketplace billing-state gates, sanitized Marketplace plan/action provenance counts, hosted team-learning feedback controls, and ECC-Tools Dependabot alert remediation are mirrored in the GA roadmap | authorize Cloudflare API or 1Password CLI access, configure the target Marketplace Pro account and INTERNAL_API_SECRET, create or replay Marketplace Pro webhook state, then rerun target readback and the live announcement gate | | Audit, prune, or attach legacy work | docs/stale-pr-salvage-ledger.md and legacy inventory | current | legacy salvage ledger and inventory are current; all localization tails are attached to Linear ITO-55 for manual language-owner review | repeat legacy scan before release | | Keep Linear roadmap detailed and progress tracking synchronized | Linear project mirror plus progress-sync contract | current | Linear live sync and project progress surface are current; progress-sync contract defines the file-backed work-items/status path | repeat Linear/project status update and local work-items sync after each significant merge batch | | Provide ECC 2.0 observability for self-use | observability readiness gate | complete | observability:ready command and readiness doc exist | runtime/dashboard implementation can continue after release gates | @@ -41,11 +41,11 @@ Status: work remaining - `naming-and-plugin-publication`: real tag/push, marketplace submission, and final channel choice remain approval-gated - `release-notes-and-notifications`: final live release/npm/plugin/billing URLs and publish approval still pending - `agentshield-enterprise-iteration`: deepen live operator approval/readback after Marketplace/payment gates -- `ecc-tools-next-level`: create or verify Marketplace-managed Pro target billing-state with webhook provenance, then run `billing:kv-readback -- --wrangler --wrangler-bin ./node_modules/.bin/wrangler --account --require-ready`, followed by the live announcement gate +- `ecc-tools-next-level`: authorize Cloudflare API or 1Password CLI access, configure the target Marketplace Pro account and INTERNAL_API_SECRET, create or replay Marketplace Pro webhook state, then rerun target readback and the live announcement gate ## Next Work Order 1. Regenerate this dashboard from the final release commit before publication evidence is recorded. 2. Repeat ITO-57 Linear/project status sync after the next significant merge batch or advisory-source refresh. -3. Create or verify Marketplace-managed Pro target billing-state with webhook provenance, then run `billing:kv-readback -- --wrangler --wrangler-bin ./node_modules/.bin/wrangler --account --require-ready`, followed by the live announcement gate before publishing native-payments copy. +3. Authorize Cloudflare API or 1Password CLI access, configure the target Marketplace Pro account and INTERNAL_API_SECRET, create or replay Marketplace Pro webhook state, then rerun target readback and the live announcement gate before publishing native-payments copy. 4. Resume ITO-45, ITO-46, and ITO-56 only after the generated dashboard and final release gates are refreshed. From 67e63e63f9bfd074bd6a21bf6bac71f3dfefa58b Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Mon, 18 May 2026 15:36:39 -0400 Subject: [PATCH 11/61] docs: align publication readiness evidence --- .../publication-evidence-2026-05-18.md | 2 +- .../releases/2.0.0-rc.1/publication-readiness.md | 16 ++++++++-------- 2 files changed, 9 insertions(+), 9 deletions(-) diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md index ec064ce9..58943a11 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md @@ -24,7 +24,7 @@ final release commit with a strictly clean checkout before publishing. | Discussion audit | `npm run discussion:audit -- --json` | Ready; 58 sampled discussions in `affaan-m/everything-claude-code`, 0 needing maintainer touch, 0 answerable discussions missing accepted answer, and 0 fetch errors | | Platform audit | `node scripts/platform-audit.js --json --allow-untracked docs/drafts/` | Ready; tracked repos report 0 open PRs, 0 open issues, 0 discussion maintainer-touch gaps, 0 answerable Q&A missing accepted answers, and 0 blocking dirty files | | Work-items sync | `node scripts/work-items.js sync-github --repo ` for five tracked repos; `node scripts/status.js --json`; `node scripts/work-items.js list --json` | All five tracked repos synced with 0 open PRs/issues and no changed work items; local status reports 0 open, 0 blocked, and 0 closed work items | -| Operator dashboard | `npm run operator:dashboard -- --markdown --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Generated current dashboard for `97567a91e79e1ee4c291eb78f5f9c30c2046ac94`; dashboard ready true, publication ready false because release, npm, plugin, billing, and announcement gates are approval-gated; AgentShield enterprise evidence now includes `840952a`; ECC Tools target-account billing readback remains the documented native-payments gate; the naming/plugin row still requires the release-name/plugin publication checklist | +| Operator dashboard | `npm run operator:dashboard -- --markdown --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Regenerated the current dashboard in `fe7b4f2b` from clean snapshot `0f1775e30b4caa08489761417cad0033c5e6e705`; dashboard ready true, publication ready false because release, npm, plugin, billing, and announcement gates are approval-gated; AgentShield enterprise evidence includes `840952a`; ECC Tools native-payments gate now names the operational ITO-61 blocker: authorize Cloudflare API or 1Password CLI access, configure the target Marketplace Pro account and `INTERNAL_API_SECRET`, create or replay Marketplace Pro webhook state, then rerun target readback and the live announcement gate | Tracked repositories in the platform audit and work-items sync were: diff --git a/docs/releases/2.0.0-rc.1/publication-readiness.md b/docs/releases/2.0.0-rc.1/publication-readiness.md index 5cf1b4b8..b459a5e6 100644 --- a/docs/releases/2.0.0-rc.1/publication-readiness.md +++ b/docs/releases/2.0.0-rc.1/publication-readiness.md @@ -99,16 +99,16 @@ Record the exact commit SHA and command output before any publication action: | Adapter scorecard | `npm run harness:adapters -- --check` | PASS | `99e01ded`: PASS, 11 adapters | | Observability readiness | `npm run observability:ready` | 21/21 passing | `publication-evidence-2026-05-18.md`: 21/21, ready yes | | Release safety gate | `npm run observability:ready -- --format json` | Release Safety category passing with publication readiness, supply-chain, workflow security, package surface, and release-surface evidence | May 18 evidence keeps release safety passing; repeat the JSON gate from the exact final release commit | -| Supply-chain verification | `npm audit --json`; `npm audit signatures`; `cd ecc2 && cargo audit -q`; Dependabot alerts; GitGuardian Security Checks | 0 vulnerabilities/alerts, registry signatures verified, GitGuardian clean | `publication-evidence-2026-05-18.md` plus CI `26050727969`: npm registry signatures and attestations verified in the evidence pass, 0 high-or-higher npm vulnerabilities, repo/home IOC scans clean, supply-chain IOC scan passed | -| Root suite | `node tests/run-all.js` | 0 failures | `99e01ded`: local `node tests/run-all.js` passed 2512/2512; current-head CI `26050727969` passed the full OS/runtime/package-manager matrix for `97567a91` | -| Markdown lint | `npx markdownlint-cli '**/*.md' --ignore node_modules` | 0 failures | CI `26050727969`: markdownlint passed on current head; rerun after any release-copy edits | +| Supply-chain verification | `npm audit --json`; `npm audit signatures`; `cd ecc2 && cargo audit -q`; Dependabot alerts; GitGuardian Security Checks | 0 vulnerabilities/alerts, registry signatures verified, GitGuardian clean | `publication-evidence-2026-05-18.md` plus CI `26055398460`: npm registry signatures and attestations verified in the evidence pass, 0 high-or-higher npm vulnerabilities, repo/home IOC scans clean, supply-chain IOC scan passed | +| Root suite | `node tests/run-all.js` | 0 failures | `99e01ded`: local `node tests/run-all.js` passed 2512/2512; current-head CI `26055398460` passed the full OS/runtime/package-manager matrix for `fe7b4f2b` | +| Markdown lint | `npx markdownlint-cli '**/*.md' --ignore node_modules` | 0 failures | CI `26055398460`: markdownlint passed on current head; rerun after any release-copy edits | | Package surface | `node tests/scripts/npm-publish-surface.test.js` | 0 failures; no Python bytecode in npm tarball | `2/2` passed in May 12 evidence pass | -| Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | `97567a91` evidence refresh: 21/21 passed after public-path sanitization | +| Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | May 18 evidence refresh: 21/21 passed after public-path sanitization and again during the `0f1775e3` operator-readiness refresh | | Optional Rust surface | `cd ecc2 && cargo test` | 0 failures or explicit deferral | `publication-evidence-2026-05-16.md`: 462/462 passed, existing warnings only | -| Queue baseline | `node scripts/platform-audit.js --json` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | `97567a91`: platform audit ready, 0 open PRs, 0 open issues, 0 conflicting PRs, and 0 blocking dirty files | -| Discussion baseline | `node scripts/platform-audit.js --json` and `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | `97567a91`: platform audit sampled 58 trunk discussions, 0 needing maintainer touch, 0 answerable discussions missing accepted answer; `docs/architecture/discussion-response-playbook.md` records response templates and security escalation rules | -| Linear roadmap | Linear project and issue readback | Detailed roadmap exists with release, security, AgentShield, ECC Tools, legacy, and observability lanes | May 18 Linear comments include ITO-57 `3fe5b2b7-c4fe-401c-a317-b40d72119cb3`; earlier evidence records the project and 16 issue lanes | -| Operator readiness dashboard | `npm run operator:dashboard -- --json` | Current queue state mapped to macro-goal deliverables and incomplete gaps | `97567a91`: generated May 18 dashboard is committed, platform audit ready true, 0 open PRs, 0 open issues, 0 discussion gaps, and publication gates still approval-gated | +| Queue baseline | `node scripts/platform-audit.js --json` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | `0f1775e3`: platform audit ready, 0 open PRs, 0 open issues, 0 conflicting PRs, and 0 blocking dirty files in the regenerated dashboard snapshot | +| Discussion baseline | `node scripts/platform-audit.js --json` and `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | `0f1775e3`: platform audit sampled 58 trunk discussions, 0 needing maintainer touch, 0 answerable discussions missing accepted answer; `docs/architecture/discussion-response-playbook.md` records response templates and security escalation rules | +| Linear roadmap | Linear project and issue readback | Detailed roadmap exists with release, security, AgentShield, ECC Tools, legacy, and observability lanes | May 18 Linear comments include ITO-57 `3fe5b2b7-c4fe-401c-a317-b40d72119cb3` and ITO-44 `fb4a4f33-6c2d-421a-bbdb-63cfad3e3ee4`; earlier evidence records the project and 16 issue lanes | +| Operator readiness dashboard | `npm run operator:dashboard -- --json` | Current queue state mapped to macro-goal deliverables and incomplete gaps | `fe7b4f2b`: regenerated May 18 dashboard from clean snapshot `0f1775e3`; platform audit ready true, 0 open PRs, 0 open issues, 0 discussion gaps, 0 dirty files, and publication gates still approval-gated | | Release URL ledger | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-18.md` plus placeholder-marker scan | Live links and approval-gated links are separated before announcement copy is posted | Ledger records public repo/docs/CI/supply-chain/npm/OpenAI Codex documentation URLs and blocks GitHub release/npm/plugin/billing/social URLs until approval-gated checks pass | | Release name and plugin publication checklist | `docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md` | Name/package/plugin values are frozen, final-release commands are listed, and Claude/Codex publication paths cite current official docs | Checklist keeps `Everything Claude Code / ECC`, `ecc-universal`, and plugin slug `ecc` for rc.1; no rename, npm publish, plugin tag, official listing, billing claim, or announcement before final evidence | From 4470e2e6702f17099d6feb137ba03ff00582c202 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Mon, 18 May 2026 16:12:37 -0400 Subject: [PATCH 12/61] docs: refresh rc1 publication evidence --- .../naming-and-publication-matrix.md | 61 ++++++++++++++----- .../2.0.0-rc.1/preview-pack-manifest.md | 2 +- .../publication-evidence-2026-05-18.md | 26 +++++++- .../2.0.0-rc.1/publication-readiness.md | 19 +++--- ...plugin-publication-checklist-2026-05-18.md | 25 ++++---- tests/docs/ecc2-release-surface.test.js | 4 +- 6 files changed, 95 insertions(+), 42 deletions(-) diff --git a/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md b/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md index 7d538220..350b32ff 100644 --- a/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md +++ b/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md @@ -1,6 +1,6 @@ # ECC v2.0.0-rc.1 Naming And Publication Matrix -Snapshot date: 2026-05-12. +Snapshot date: 2026-05-18. This matrix answers the release question "ship as Everything Claude Code, ECC, or a renamed surface?" for the rc.1 lane. It is evidence for planning, not a @@ -28,26 +28,26 @@ Reason: ## Current Values -| Surface | Current value | Evidence command | 2026-05-12 result | Release decision | +| Surface | Current value | Evidence command | 2026-05-18 result | Release decision | | --- | --- | --- | --- | --- | | Product display name | `Everything Claude Code` | `rg -n "Everything Claude Code" README.md CHANGELOG.md docs/releases/2.0.0-rc.1` | Present across README, release notes, launch copy, and plugin manifests | Keep for rc.1 | | Short name | `ECC` | README/release docs | Used as the short cross-harness brand | Keep and prefer in tight copy | | GitHub repo | `affaan-m/everything-claude-code` | `git remote get-url origin` | `https://github.com/affaan-m/everything-claude-code.git` | Keep for rc.1 | | Possible short repo | `affaan-m/ecc` | `gh repo view affaan-m/ecc` | Not found with current auth | Candidate after rc.1 only | | npm package | `ecc-universal` | `node -p "require('./package.json').name"` | `ecc-universal` | Keep for rc.1 | -| npm package version | `2.0.0-rc.1` local, `1.10.0` registry latest | `node -p "require('./package.json').version"` and `npm view ecc-universal name version dist-tags --json` | Local rc.1 is ready; registry latest remains `1.10.0` | Publish rc as `next`, not `latest` | +| npm package version | `2.0.0-rc.1` local, `1.10.0` registry latest | `node -p "require('./package.json').version"` and `npm view ecc-universal name version dist-tags --json` | Local rc.1 is ready; registry latest remains `1.10.0` and no `next` dist-tag exists yet | Publish rc as `next`, not `latest` | | Exact npm short name | `ecc` | `npm view ecc name version description repository.url --json` | Occupied by `ecc@0.0.2`, "Elliptic curve cryptography functions." | Do not use | | Scoped npm short name | `@affaan-m/ecc` | `npm view @affaan-m/ecc name version --json` | Registry 404 | Possible future scoped package if npm scope policy permits | | Former package name | `everything-claude-code` | `npm view everything-claude-code name version dist-tags --json` | Registry reports unpublished on 2026-02-07 | Do not revive for rc.1 | | Claude plugin slug | `ecc` | `node -p "require('./.claude-plugin/plugin.json').name"` | `ecc` | Keep | -| Claude plugin version | `2.0.0-rc.1` | `claude plugin validate .claude-plugin/plugin.json` | Validation passed on Claude Code `2.1.121` | Ready for release-tag gate | -| Claude marketplace entry | `ecc` | `.claude-plugin/marketplace.json` | Version and repo point at current rc.1 surface | Keep | +| Claude plugin version | `2.0.0-rc.1` | `claude plugin validate .claude-plugin/plugin.json`; `claude plugin tag .claude-plugin --dry-run` | Validation passed on Claude Code `2.1.143`; dry run would create `ecc--v2.0.0-rc.1` | Ready for release-tag gate | +| Claude marketplace entry | `ecc` | `.claude-plugin/marketplace.json`; `claude plugin marketplace add --help`; Anthropic plugin marketplace docs | Version and repo point at current rc.1 surface; GitHub, git URL, remote marketplace JSON, and local path marketplace sources are supported | Keep | | Codex plugin slug | `ecc` | `node -p "require('./.codex-plugin/plugin.json').name"` | `ecc` | Keep | -| Codex plugin version | `2.0.0-rc.1` | `node tests/docs/ecc2-release-surface.test.js` | Release surface test passed | Ready for Codex marketplace/manual marketplace gate | -| Codex repo marketplace | `ecc` | `.agents/plugins/marketplace.json`; `codex plugin marketplace add --help` | Repo marketplace add supports GitHub shorthand and local roots; local temp-home add smoke passed | Use as rc.1 Codex distribution path | +| Codex plugin version | `2.0.0-rc.1` | `node tests/plugin-manifest.test.js`; `node tests/docs/ecc2-release-surface.test.js` | Plugin manifest passed 54/54; release surface passed 21/21 on Codex CLI `0.131.0` | Ready for Codex marketplace/manual marketplace gate | +| Codex repo marketplace | `ecc` | `.agents/plugins/marketplace.json`; `codex plugin marketplace add --help`; OpenAI Codex plugin docs | Repo marketplace add supports GitHub shorthand, Git URLs, SSH URLs, local roots, `--ref`, and `--sparse`; local and GitHub-ref temp-home add smokes passed | Use as rc.1 Codex distribution path | | OpenCode package | `ecc-universal` | `node -p "require('./.opencode/package.json').name"` | `ecc-universal` | Keep | | OpenCode build | Generated package output | `npm run build:opencode` | Passed | Ready for package dry-run gate | -| npm pack surface | Reduced runtime package | `npm pack --dry-run --json` | Produced `ecc-universal-2.0.0-rc.1.tgz`, 969 entries, about 5.0 MB unpacked | Needs final release-commit rerun | +| npm pack surface | Reduced runtime package | `NPM_CONFIG_USERCONFIG=/dev/null npm pack --dry-run --json` | Produced `ecc-universal-2.0.0-rc.1.tgz`, 2228 entries, 4,348,504 bytes packed, 13,024,929 bytes unpacked | Needs final release-commit rerun | ## Publication Paths @@ -57,11 +57,26 @@ Reason: | npm | `ecc-universal` local package version is `2.0.0-rc.1`; registry latest is `1.10.0` | Publish rc with `npm publish --tag next` after final `npm pack --dry-run` and release tests | Do not publish before final release commit | | Claude plugin | `claude plugin validate .claude-plugin/plugin.json` passed; `claude plugin tag --help` confirms the release tag flow creates `{name}--v{version}` tags and can push them | Run `claude plugin tag .claude-plugin --dry-run` from the clean release commit, then tag/push only after release approval | No plugin release tag created in this pass | | Claude marketplace | `.claude-plugin/marketplace.json` points at `ecc` and the public repo | Verify marketplace update/install path after tag exists | External marketplace propagation not verified | -| Codex plugin | `codex plugin marketplace` supports add/upgrade/remove; `.codex-plugin/plugin.json` is present; `.agents/plugins/marketplace.json` exposes `ecc` from the repo root; temp-home local `codex plugin marketplace add` passed | Publish rc.1 docs with the repo-marketplace command, then monitor OpenAI's official Plugin Directory self-serve path | Official Plugin Directory publishing is documented as coming soon | +| Codex plugin | `codex plugin marketplace` supports local and Git marketplace sources; `.codex-plugin/plugin.json` is present; `.agents/plugins/marketplace.json` exposes `ecc` from the repo root; temp-home local and GitHub-ref marketplace adds passed | Publish rc.1 docs with the repo-marketplace command, then monitor OpenAI's official Plugin Directory path | Do not claim official Plugin Directory listing before OpenAI submission evidence | | OpenCode package | `.opencode/package.json` builds from source and ships inside npm package | Re-run `npm run build:opencode` and package dry-run from release commit | OpenCode CLI 1.2.21 does not expose a separate plugin publication command in this pass | | ECC Tools billing claim | README and launch copy mention ECC Tools / marketplace context | ECC-Tools #73 adds `/api/billing/readiness` `announcementGate`; run it against a Marketplace-managed test account before any payment announcement | Billing announcement code gate exists; live Marketplace account readback still pending | | Social and longform copy | X thread, LinkedIn copy, article outline, GitHub release copy exist | Replace any stale URLs, then publish only after release/npm/plugin URLs work | Public URLs not final until release actions complete | +## ITO-46 Blocker Register + +| Channel | Current status | Required metadata/evidence | Owner | Blocker or follow-up | +| --- | --- | --- | --- | --- | +| GitHub release | Approval-gated; no `v2.0.0-rc.1` prerelease yet | Tag, release URL, prerelease flag, final release notes, URL ledger | Release owner | Create only after final clean-checkout evidence | +| npm | `ecc-universal@2.0.0-rc.1` dry-run passed; registry latest is `1.10.0` | Pack summary, publish dry-run, `next` dist-tag readback, registry signature evidence | Package owner | Do not publish before approval and final release commit | +| Short npm name | `ecc` is occupied; `@affaan-m/ecc` returns 404 | Name availability outputs and migration plan | Release owner | Keep `ecc-universal` for rc.1; scoped rename is post-rc only | +| Claude plugin | `ecc@2.0.0-rc.1` validates; tag dry run would create `ecc--v2.0.0-rc.1` | `claude plugin validate .`, `claude plugin tag .claude-plugin --dry-run`, marketplace install/update smoke | Plugin owner | Real tag push and marketplace propagation require release approval | +| Claude marketplace | Docs and CLI support GitHub, git URL, remote marketplace JSON, and local path sources | Public repo marketplace JSON, support/contact metadata, post-tag install smoke | Plugin owner | No external official listing has been submitted in this pass | +| Codex repo marketplace | Local and GitHub-ref temp-home marketplace add smokes passed on Codex CLI `0.131.0` | `.codex-plugin/plugin.json`, `.agents/plugins/marketplace.json`, repo/personal marketplace evidence | Plugin owner | Official Plugin Directory listing requires OpenAI submission/listing evidence | +| Codex official Plugin Directory | OpenAI docs describe the curated official directory; ECC has not submitted or received listing evidence | Directory submission link or OpenAI approval path once available | Plugin owner | Track as an ITO-56/ITO-46 follow-up; do not claim an official listing | +| OpenCode package | `npm run build:opencode` passed | Built `.opencode` package metadata inside npm tarball | Package owner | No separate public plugin channel identified; follows npm | +| Billing/native payments | Announcement remains blocked by ITO-61 | Marketplace Pro target readback, webhook provenance, `INTERNAL_API_SECRET`, announcement gate | ECC Tools owner | Do not include native-payments claim in rc.1 announcement | +| Social/longform copy | Drafts exist | Final live GitHub, npm, Claude, Codex, billing URLs | Release owner | Publish only after release/package/plugin URLs exist | + ## Rename After rc.1 If the project moves from "Everything Claude Code" toward "ECC" after rc.1, @@ -83,7 +98,7 @@ do it as a staged migration: ```text git rev-parse HEAD -7109ee08db7209c5d14809efcf832043020dfc57 +67e63e63f9bfd074bd6a21bf6bac71f3dfefa58b node -p "require('./package.json').name + '@' + require('./package.json').version" ecc-universal@2.0.0-rc.1 @@ -104,19 +119,30 @@ npm view ecc-universal name version dist-tags --json registry latest is 1.10.0; no rc dist-tag exists yet. claude plugin validate .claude-plugin/plugin.json -Validation passed on Claude Code 2.1.121. +Validation passed on Claude Code 2.1.143. + +claude plugin validate . +Validation passed with one warning: root CLAUDE.md is not loaded as plugin +context; ship plugin context through skills instead. + +claude plugin tag .claude-plugin --dry-run +Would create and push tag ecc--v2.0.0-rc.1. node tests/docs/ecc2-release-surface.test.js -18 release-surface checks passed. +21 release-surface checks passed. -node tests/scripts/npm-publish-surface.test.js -2 npm publish-surface checks passed. +node tests/plugin-manifest.test.js +54 plugin-manifest checks passed. npm run build:opencode Passed. npm pack --dry-run --json -Produced ecc-universal-2.0.0-rc.1.tgz, 969 entries, about 5.0 MB unpacked. +Produced ecc-universal-2.0.0-rc.1.tgz, 2228 entries, 4,348,504 bytes +packed, and 13,024,929 bytes unpacked. + +npm publish --tag next --dry-run +Dry run would publish ecc-universal@2.0.0-rc.1 to npm with tag next. codex plugin marketplace add --help Supports GitHub shorthand, HTTP(S) Git URLs, SSH URLs, local marketplace roots, @@ -125,4 +151,9 @@ Supports GitHub shorthand, HTTP(S) Git URLs, SSH URLs, local marketplace roots, HOME="$(mktemp -d)" codex plugin marketplace add Added marketplace ecc and recorded the installed marketplace root as without touching the real Codex config. + +HOME="$(mktemp -d)" codex plugin marketplace add affaan-m/everything-claude-code --ref "$(git rev-parse HEAD)" +Added marketplace ecc from the GitHub repo pinned to +67e63e63f9bfd074bd6a21bf6bac71f3dfefa58b without touching the real Codex +config. ``` diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index 7a3d85c3..7a5fa34e 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -24,7 +24,7 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-15.md` | Current May 15 queue, roadmap, security, supply-chain watch, no-lifecycle CI install hardening, AgentShield #86 evidence-pack provenance, ECC Tools billing-gate, Actions cache purge, and `ecc2` test evidence through PR #1941 | Must be superseded by a final clean-checkout evidence file before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-16.md` | Current May 16/17 queue cleanup, recsys skill merge, GateGuard triage, PR #1947 supply-chain protection, AgentShield #87 plugin-cache confidence evidence, AgentShield #88 evidence-pack inspect/readback, AgentShield #89 evidence-pack fleet routing, AgentShield #90 fleet review items, AgentShield #91 policy export, AgentShield #92 policy promotion, ECC-Tools #76 fleet-summary consumption, ECC-Tools #77 hosted finding evidence paths, ECC-Tools #78 harness policy-route linking, dashboard refresh, and combined Node/Rust/release-surface gate evidence through the May 16 mirror | Must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` | May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack protection recheck, npm audit/signature checks, legacy and Linear progress routing, deterministic preview-pack smoke, operator dashboard refresh, Linear sync, and GitHub CI evidence for `27dc2918` | Superseded by the May 18 evidence snapshot; repeat from a strict clean checkout before real publication | -| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | Current May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, current-head Mini Shai-Hulud/TanStack protection recheck, no-lifecycle install, npm audit/signature checks, AgentShield `840952a` enterprise/IOC evidence mirror, work-items sync, Linear sync, operator dashboard refresh, and current-head CI/security scan success for `99e01ded` | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | +| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | Current May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, current-head Mini Shai-Hulud/TanStack protection recheck, no-lifecycle install, npm audit/signature checks, AgentShield `840952a` enterprise/IOC evidence mirror, work-items sync, Linear sync, operator dashboard refresh, latest current-head CI/security scan success for `67e63e63`, and ITO-46 naming/plugin publication dry-run refresh | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and publication, plugin, billing, AgentShield, ECC Tools, legacy, and Linear productization gaps still open | | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-18.md` | Live URL and approval-gated URL ledger for release copy | Must be regenerated from the final release commit before public announcements | diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md index 58943a11..c4900a58 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md @@ -7,9 +7,9 @@ npm publication, plugin tag, marketplace submission, or announcement post. | Field | Evidence | | --- | --- | -| Upstream main | `97567a91e79e1ee4c291eb78f5f9c30c2046ac94` | +| Upstream main | `67e63e63f9bfd074bd6a21bf6bac71f3dfefa58b` | | Git remote | `https://github.com/affaan-m/everything-claude-code.git` | -| Evidence scope | Current `main` after PR #1970 workflow-security validator bypass fixes, PR #1971 metrics bridge cost-reporting fixes, PR #1972 `uncloud` skill merge, PR #1973 stale script cleanup, issue #1974 cost-reporting verification/closure, PR #1976 OpenAI/AstraFlow provider response guards, PR #1978 review/closure, catalog/operator dashboard refresh, ECC-Tools Wrangler OAuth billing readback mirror, AgentShield `840952a` fleet-ticket and Mini Shai-Hulud IOC evidence mirror, Mini Shai-Hulud/TanStack protection recheck, defensive-deny IOC scanner hardening, release name/plugin publication checklist, readiness/smoke gate enforcement for that checklist, release OIDC publishing-scope hardening, workflow line-ending normalization, current-head CI/security scan, work-items sync, and Linear progress sync | +| Evidence scope | Current `main` after PR #1970 workflow-security validator bypass fixes, PR #1971 metrics bridge cost-reporting fixes, PR #1972 `uncloud` skill merge, PR #1973 stale script cleanup, issue #1974 cost-reporting verification/closure, PR #1976 OpenAI/AstraFlow provider response guards, PR #1978 review/closure, catalog/operator dashboard refresh, ECC-Tools Wrangler OAuth billing readback mirror, AgentShield `840952a` fleet-ticket and Mini Shai-Hulud IOC evidence mirror, Mini Shai-Hulud/TanStack protection recheck, defensive-deny IOC scanner hardening, release name/plugin publication checklist, readiness/smoke gate enforcement for that checklist, release OIDC publishing-scope hardening, workflow line-ending normalization, current-head CI/security scan, work-items sync, Linear progress sync, and the ITO-46 publication-path dry-run refresh | | Local status caveat | `git status --short --branch` was clean at dashboard generation time; generated evidence files are committed after the source snapshot they describe | The actual release operator should repeat all publish-facing checks from the @@ -56,6 +56,7 @@ Tracked repositories in the platform audit and work-items sync were: | Public queues | Rechecked after the merge and issue-closure batch; 0 PRs, 0 issues, and 0 discussion gaps remain across tracked repos | | Release OIDC publishing scope | Pushed `7911af4a` to keep the release workflow's trusted-publishing path scoped to release publication instead of broadening OIDC permissions across unrelated jobs; local workflow security validation passed | | Release workflow normalization | Pushed `97567a91` to normalize release workflow line endings after the OIDC hardening slice; current-head CI `26050727969` passed for `97567a91e79e1ee4c291eb78f5f9c30c2046ac94` | +| Operator readiness evidence refresh | Pushed `0f1775e3`, `fe7b4f2b`, and `67e63e63` to refresh blocker evidence, regenerate the operator dashboard, and align publication readiness to the latest CI/security evidence; current-head CI `26056018725` passed for `67e63e63f9bfd074bd6a21bf6bac71f3dfefa58b` | ## Supply-Chain And Security Evidence @@ -72,9 +73,28 @@ Tracked repositories in the platform audit and work-items sync were: | npm signatures | `npm audit signatures` | 213 verified registry signatures; 17 verified attestations | | Workflow security | `node scripts/ci/validate-workflow-security.js` | Validated 8 workflow files after the release OIDC publishing-scope hardening | | AgentShield project scan | `npx --no-install ecc-agentshield scan --format json` | Grade A / 99; 0 critical, 0 high, 0 medium; 6 low docs-example skill telemetry/governance findings | -| Current-head CI security scan | `gh run view 26050727969 --repo affaan-m/everything-claude-code --json status,conclusion,headSha,jobs,url` | Completed successfully for `97567a91e79e1ee4c291eb78f5f9c30c2046ac94`; 37/37 CI jobs passed, including lint, workflow/component validation, coverage, cross-platform package-manager tests, npm audit, and supply-chain IOC scan | +| Current-head CI security scan | `gh run view 26056018725 --repo affaan-m/everything-claude-code --json status,conclusion,headSha,jobs,url` | Completed successfully for `67e63e63f9bfd074bd6a21bf6bac71f3dfefa58b`; 37/37 CI jobs passed, including lint, workflow/component validation, coverage, cross-platform package-manager tests, npm audit, and supply-chain IOC scan | | Latest Supply-Chain Watch | `gh run view 26010432490 --repo affaan-m/everything-claude-code --json status,conclusion,headSha,url` | Completed successfully for `25ac57ac40e9fc5a0606e76e6339e72c79748c99`; rerun from the final release commit before publication | +## ITO-46 Publication Path Refresh + +| Gate | Command | Result | +| --- | --- | --- | +| Clean publication-path baseline | `git status --short --branch`; `git rev-parse HEAD`; `git remote get-url origin` | Clean `main` at `67e63e63f9bfd074bd6a21bf6bac71f3dfefa58b`; remote `https://github.com/affaan-m/everything-claude-code.git` | +| Package/plugin identity readback | `node -p "JSON.stringify({pkg, claude, codex, opencode}, null, 2)"` | `ecc-universal@2.0.0-rc.1`; Claude plugin `ecc@2.0.0-rc.1`; Codex plugin `ecc@2.0.0-rc.1`; OpenCode package `ecc-universal@2.0.0-rc.1` | +| Name availability | `npm view ecc name version description repository.url --json`; `npm view @affaan-m/ecc name version --json`; `npm view ecc-universal name version dist-tags --json` | `ecc` is occupied by unrelated `ecc@0.0.2`; `@affaan-m/ecc` returns 404; `ecc-universal` registry latest remains `1.10.0` with no `next` dist-tag | +| Plugin manifest tests | `node tests/plugin-manifest.test.js` | 54 passed, 0 failed | +| Release surface tests | `node tests/docs/ecc2-release-surface.test.js` | 21 passed, 0 failed | +| Claude plugin validation | `claude plugin validate .claude-plugin/plugin.json`; `claude plugin validate .`; `claude plugin tag .claude-plugin --dry-run` | Claude Code `2.1.143`; manifest validation passed; full plugin validation passed with one expected root `CLAUDE.md` context warning; tag dry run would create `ecc--v2.0.0-rc.1` | +| Claude marketplace source help | `claude plugin marketplace add --help`; `claude plugin marketplace update --help` | Marketplace add supports URL, local path, GitHub repo, `--scope`, and `--sparse`; update supports targeted or all-marketplace refresh | +| Codex marketplace help | `codex plugin marketplace add --help` | Codex CLI `0.131.0`; marketplace add supports local paths, `owner/repo[@ref]`, HTTPS Git URL, SSH Git URL, `--ref`, and `--sparse` | +| Codex local marketplace smoke | `HOME="$(mktemp -d)" codex plugin marketplace add ./` | Added marketplace `ecc` from the local checkout without touching the real Codex config | +| Codex GitHub-ref marketplace smoke | `HOME="$(mktemp -d)" codex plugin marketplace add affaan-m/everything-claude-code --ref "$(git rev-parse HEAD)"` | Added marketplace `ecc` from the public GitHub repo pinned to `67e63e63f9bfd074bd6a21bf6bac71f3dfefa58b` without touching the real Codex config | +| npm package dry-run | `NPM_CONFIG_USERCONFIG=/dev/null npm pack --dry-run --json`; `NPM_CONFIG_USERCONFIG=/dev/null npm publish --tag next --dry-run` | Pack produced `ecc-universal-2.0.0-rc.1.tgz`, 2228 files, 4,348,504 bytes packed, 13,024,929 bytes unpacked, shasum `29d6a17029d80f5cb1df068880ba86c55a5d60f1`; publish dry-run would publish `ecc-universal@2.0.0-rc.1` with tag `next` | +| OpenCode package build | `npm run build:opencode` | Passed | +| Preview pack smoke | `npm run preview-pack:smoke` | Ready yes; digest `0ed831dbd0cf`; 5 passed, 0 failed | +| Official docs check | Anthropic `https://code.claude.com/docs/en/plugins` and `https://code.claude.com/docs/en/plugin-marketplaces`; OpenAI `https://developers.openai.com/codex/plugins/build` | Anthropic documents self-hosted marketplace sources; OpenAI documents repo/personal marketplaces and the official Plugin Directory. ECC has not created a real release tag, official listing, or npm publication in this pass | + ## Linear Progress Sync | Surface | Evidence | diff --git a/docs/releases/2.0.0-rc.1/publication-readiness.md b/docs/releases/2.0.0-rc.1/publication-readiness.md index b459a5e6..7369c3d9 100644 --- a/docs/releases/2.0.0-rc.1/publication-readiness.md +++ b/docs/releases/2.0.0-rc.1/publication-readiness.md @@ -42,9 +42,10 @@ For the May 18 current-head queue, workflow-security/metrics/uncloud merge batch, PR #1978 review/closure, Mini Shai-Hulud/TanStack local and home protection recheck, npm no-lifecycle install/audit/signature gates, AgentShield project scan, AgentShield `840952a` enterprise/IOC evidence mirror, -release OIDC publishing-scope hardening, workflow normalization, work-items sync, +release OIDC publishing-scope hardening, workflow normalization, later +dashboard/publication-readiness refreshes through `67e63e63`, work-items sync, Linear progress comments, operator dashboard refresh, and current-head -CI/security scan success for `97567a91`, see +CI/security scan success for `67e63e63`, see [`publication-evidence-2026-05-18.md`](publication-evidence-2026-05-18.md). For the operator-facing prompt-to-artifact readiness dashboard from the same May 16 pass, see @@ -69,7 +70,7 @@ For the May 18 live/pending release URL ledger, see | Claude plugin slug | `ecc` / `ecc@ecc` install path | `.claude-plugin/plugin.json`, `.claude-plugin/marketplace.json` | `node tests/hooks/hooks.test.js` | `publication-evidence-2026-05-12.md` | Plugin owner | Evidence recorded | | Claude plugin manifest | `2.0.0-rc.1`, no unsupported `agents` or explicit `hooks` fields | `.claude-plugin/plugin.json`, `.claude-plugin/PLUGIN_SCHEMA_NOTES.md` | `claude plugin validate .claude-plugin/plugin.json` | `publication-evidence-2026-05-12.md` | Plugin owner | Evidence recorded | | Codex plugin manifest | `2.0.0-rc.1` with shared skill source | `.codex-plugin/plugin.json` | `node tests/docs/ecc2-release-surface.test.js` | `publication-evidence-2026-05-12.md` | Plugin owner | Evidence recorded | -| Codex repo marketplace | `ecc@2.0.0-rc.1` exposed through `.agents/plugins/marketplace.json` | `.agents/plugins/marketplace.json`, `.codex-plugin/README.md` | `HOME="$(mktemp -d)" codex plugin marketplace add ` | `publication-evidence-2026-05-15.md` | Plugin owner | Repo-marketplace path verified; official Plugin Directory publishing coming soon | +| Codex repo marketplace | `ecc@2.0.0-rc.1` exposed through `.agents/plugins/marketplace.json` | `.agents/plugins/marketplace.json`, `.codex-plugin/README.md` | `HOME="$(mktemp -d)" codex plugin marketplace add ` | `publication-evidence-2026-05-15.md` | Plugin owner | Repo-marketplace path verified; do not claim official Plugin Directory listing before OpenAI submission evidence | | OpenCode package | `ecc-universal` plugin module | `.opencode/package.json`, `.opencode/index.ts` | `npm run build:opencode` | `publication-evidence-2026-05-12.md` | Package owner | Evidence recorded | | Agent metadata | `2.0.0-rc.1` | `agent.yaml`, `.agents/plugins/marketplace.json` | `node tests/scripts/catalog.test.js` | `publication-evidence-2026-05-12.md` | Release owner | Evidence recorded | | Migration copy | rc.1 upgrade path, not GA claim | `release-notes.md`, `quickstart.md`, `HERMES-SETUP.md` | `npx markdownlint-cli '**/*.md' --ignore node_modules` | `publication-evidence-2026-05-13.md` | Docs owner | Evidence recorded | @@ -81,7 +82,7 @@ For the May 18 live/pending release URL ledger, see | GitHub release | Tag exists, release notes use final URLs, assets attached if needed | `gh release view v2.0.0-rc.1 --json tagName,url,isPrerelease` | `Blocker: release not found on 2026-05-12` | Release owner | Pending approval | | npm package | `npm pack --dry-run` has expected files, version matches, rc goes to `next` | `npm pack --dry-run` and `npm publish --tag next --dry-run` where supported | `Blocker: actual publish requires approval; dry run passed with next tag` | Package owner | Dry-run passed | | Claude plugin | Manifest validates, marketplace JSON points to public repo, install docs match slug | `claude plugin validate .claude-plugin/plugin.json`; `claude plugin tag .claude-plugin --dry-run`; isolated temp-home install smoke | `Blocker: real tag creation/push requires approval` | Plugin owner | Clean-checkout dry-run and install smoke recorded | -| Codex plugin | Manifest version matches package and docs, repo marketplace points at the plugin root, and OpenAI's current official Plugin Directory status is recorded | `node tests/docs/ecc2-release-surface.test.js`; `node tests/plugin-manifest.test.js`; `codex plugin marketplace add --help`; temp-home `codex plugin marketplace add ` | `Blocker: official Plugin Directory publishing and self-serve management are documented as coming soon` | Plugin owner | Repo-marketplace distribution verified; official directory pending | +| Codex plugin | Manifest version matches package and docs, repo marketplace points at the plugin root, and OpenAI's current official Plugin Directory status is recorded | `node tests/docs/ecc2-release-surface.test.js`; `node tests/plugin-manifest.test.js`; `codex plugin marketplace add --help`; temp-home `codex plugin marketplace add ` | `Blocker: official Plugin Directory listing requires OpenAI submission/listing evidence` | Plugin owner | Repo-marketplace distribution verified; official directory pending | | OpenCode package | Build output is regenerated from source and package metadata is current | `npm run build:opencode` | `Blocker: none for local build; public distribution still follows npm/plugin release` | Package owner | Evidence recorded | | ECC Tools billing reference | Any billing claim links to verified Marketplace/App state | `env -u GITHUB_TOKEN gh repo view ECC-Tools/ECC-Tools --json nameWithOwner,isPrivate,viewerPermission` plus internal `/api/billing/readiness?accountLogin=` readback | `Blocker: ECC-Tools #73 added announcementGate; live Marketplace test-account readback must return announcementGate.ready === true before payment announcement` | ECC Tools owner | Code gate recorded; live billing readback pending | | Announcement copy | X, LinkedIn, GitHub release, and longform copy point to live URLs | placeholder-marker scan and `release-url-ledger-2026-05-18.md` | `Blocker: final live release/npm/plugin/billing URLs do not exist yet; live and pending URLs are separated in the May 18 ledger` | Release owner | URL ledger recorded; final URLs pending | @@ -93,17 +94,17 @@ Record the exact commit SHA and command output before any publication action: | Evidence | Command | Required result | Recorded output | | --- | --- | --- | --- | -| Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | `97567a91`: `## main...origin/main`; repeat from the exact final publication commit before release | +| Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | `67e63e63`: `## main...origin/main`; repeat from the exact final publication commit before release | | Preview-pack smoke | `npm run preview-pack:smoke` | Preview pack artifacts, Hermes boundary, final verification command list, and publication blockers pass | `publication-evidence-2026-05-18.md`: ready yes, digest `0ed831dbd0cf`, 5 passed, 0 failed; repeat in the final strict clean-checkout release pass | | Harness audit | `npm run harness:audit -- --format json` | 70/70 passing | `99e01ded`: 70/70, 0 top actions | | Adapter scorecard | `npm run harness:adapters -- --check` | PASS | `99e01ded`: PASS, 11 adapters | | Observability readiness | `npm run observability:ready` | 21/21 passing | `publication-evidence-2026-05-18.md`: 21/21, ready yes | | Release safety gate | `npm run observability:ready -- --format json` | Release Safety category passing with publication readiness, supply-chain, workflow security, package surface, and release-surface evidence | May 18 evidence keeps release safety passing; repeat the JSON gate from the exact final release commit | -| Supply-chain verification | `npm audit --json`; `npm audit signatures`; `cd ecc2 && cargo audit -q`; Dependabot alerts; GitGuardian Security Checks | 0 vulnerabilities/alerts, registry signatures verified, GitGuardian clean | `publication-evidence-2026-05-18.md` plus CI `26055398460`: npm registry signatures and attestations verified in the evidence pass, 0 high-or-higher npm vulnerabilities, repo/home IOC scans clean, supply-chain IOC scan passed | -| Root suite | `node tests/run-all.js` | 0 failures | `99e01ded`: local `node tests/run-all.js` passed 2512/2512; current-head CI `26055398460` passed the full OS/runtime/package-manager matrix for `fe7b4f2b` | -| Markdown lint | `npx markdownlint-cli '**/*.md' --ignore node_modules` | 0 failures | CI `26055398460`: markdownlint passed on current head; rerun after any release-copy edits | +| Supply-chain verification | `npm audit --json`; `npm audit signatures`; `cd ecc2 && cargo audit -q`; Dependabot alerts; GitGuardian Security Checks | 0 vulnerabilities/alerts, registry signatures verified, GitGuardian clean | `publication-evidence-2026-05-18.md` plus CI `26056018725`: npm registry signatures and attestations verified in the evidence pass, 0 high-or-higher npm vulnerabilities, repo/home IOC scans clean, supply-chain IOC scan passed | +| Root suite | `node tests/run-all.js` | 0 failures | `99e01ded`: local `node tests/run-all.js` passed 2512/2512; current-head CI `26056018725` passed the full OS/runtime/package-manager matrix for `67e63e63` | +| Markdown lint | `npx markdownlint-cli '**/*.md' --ignore node_modules` | 0 failures | CI `26056018725`: markdownlint passed on current head; rerun after any release-copy edits | | Package surface | `node tests/scripts/npm-publish-surface.test.js` | 0 failures; no Python bytecode in npm tarball | `2/2` passed in May 12 evidence pass | -| Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | May 18 evidence refresh: 21/21 passed after public-path sanitization and again during the `0f1775e3` operator-readiness refresh | +| Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | May 18 evidence refresh: 21/21 passed after public-path sanitization, during the `0f1775e3` operator-readiness refresh, and again in the ITO-46 dry-run pass | | Optional Rust surface | `cd ecc2 && cargo test` | 0 failures or explicit deferral | `publication-evidence-2026-05-16.md`: 462/462 passed, existing warnings only | | Queue baseline | `node scripts/platform-audit.js --json` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | `0f1775e3`: platform audit ready, 0 open PRs, 0 open issues, 0 conflicting PRs, and 0 blocking dirty files in the regenerated dashboard snapshot | | Discussion baseline | `node scripts/platform-audit.js --json` and `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | `0f1775e3`: platform audit sampled 58 trunk discussions, 0 needing maintainer touch, 0 answerable discussions missing accepted answer; `docs/architecture/discussion-response-playbook.md` records response templates and security escalation rules | diff --git a/docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md b/docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md index 2bd7399a..e31e5db1 100644 --- a/docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md +++ b/docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md @@ -29,15 +29,15 @@ Reasons: | Surface | Current value | Evidence command | 2026-05-18 result | Release action | | --- | --- | --- | --- | --- | -| Git commit | `0e88e6a4ddf9968e55faa07f3ad8a03d3943b58c` | `git rev-parse HEAD` | Recorded from `main` | Re-run from final release commit | +| Git commit | `67e63e63f9bfd074bd6a21bf6bac71f3dfefa58b` | `git rev-parse HEAD` | Recorded from clean `main` before this ITO-46 evidence refresh | Re-run from final release commit | | GitHub repo | `affaan-m/everything-claude-code` | `git remote get-url origin` | `https://github.com/affaan-m/everything-claude-code.git` | Keep for rc.1 | | Possible short repo | `affaan-m/ecc` | `gh repo view affaan-m/ecc --json nameWithOwner,url,isPrivate` | GraphQL could not resolve repository | Do not depend on it for rc.1 | | npm package | `ecc-universal@2.0.0-rc.1` local, `1.10.0` registry latest | `node -p "require('./package.json').name + '@' + require('./package.json').version"` and `npm view ecc-universal name version dist-tags --json` | Local rc.1 ready; registry still latest `1.10.0` | Publish rc.1 with `--tag next` after approval | | Exact npm short name | `ecc` | `npm view ecc name version description repository.url --json` | Occupied by unrelated `ecc@0.0.2` | Do not use | | Scoped npm short name | `@affaan-m/ecc` | `npm view @affaan-m/ecc name version --json` | 404 | Candidate only after migration plan | -| Claude plugin | `ecc@2.0.0-rc.1` | `claude plugin validate .claude-plugin/plugin.json` | Validation passed | Run dry-run tag, then tag/push only after approval | -| Claude marketplace | `.claude-plugin/marketplace.json` | `claude plugin marketplace --help`; Anthropic plugin marketplace docs | GitHub, git URL, remote marketplace JSON, and local path marketplace sources are supported | Submit official listing through the current Anthropic forms only after final evidence | -| Codex plugin | `ecc@2.0.0-rc.1` | `node tests/plugin-manifest.test.js`; `codex plugin marketplace add --help`; OpenAI Codex plugin docs | Repo marketplace and local marketplace roots are supported | Use repo marketplace for rc.1; official Plugin Directory is still pending | +| Claude plugin | `ecc@2.0.0-rc.1` | `claude plugin validate .claude-plugin/plugin.json`; `claude plugin validate .`; `claude plugin tag .claude-plugin --dry-run` | Validation passed on Claude Code `2.1.143`; full plugin validation has one expected root `CLAUDE.md` context warning; dry run would create `ecc--v2.0.0-rc.1` | Run dry-run tag again from the final commit, then tag/push only after approval | +| Claude marketplace | `.claude-plugin/marketplace.json` | `claude plugin marketplace add --help`; Anthropic plugin marketplace docs | GitHub repo, git URL, remote marketplace JSON, and local path marketplace sources are supported | Verify post-tag marketplace install/update path after final evidence | +| Codex plugin | `ecc@2.0.0-rc.1` | `node tests/plugin-manifest.test.js`; `codex plugin marketplace add --help`; OpenAI Codex plugin docs | Plugin manifest passed 54/54; local and GitHub-ref repo marketplace smokes passed on Codex CLI `0.131.0` | Use repo marketplace for rc.1; do not claim official directory listing until OpenAI publishing path is available | | OpenCode package | `ecc-universal@2.0.0-rc.1` | `node -p "require('./.opencode/package.json').name + '@' + require('./.opencode/package.json').version"` | Matches rc.1 package identity | Follow npm package publication | | Billing claim | Pending ECC Tools readiness | ECC Tools billing gate and Marketplace account readback | Code-side gate exists; live Marketplace account readback still pending | Do not announce native payments | @@ -77,8 +77,8 @@ keep the related publication action blocked. | 2 | Verify clean release branch | `git status --short --branch` shows only the intended release commit and no unrelated drift | Any unexplained dirty file | | 3 | Verify package and plugin manifests | `node tests/plugin-manifest.test.js` and `node tests/docs/ecc2-release-surface.test.js` pass | Manifest or release-surface failure | | 4 | Dry-run package surface | `npm pack --dry-run --json`; `npm publish --tag next --dry-run` | Missing files, wrong dist-tag, or publish dry-run failure | -| 5 | Dry-run Claude distribution | `claude plugin validate`; `claude plugin tag .claude-plugin --dry-run`; temp install smoke | Validation, tag, or install-smoke failure | -| 6 | Verify Codex repo marketplace | `codex plugin marketplace add --help`; temp-home repo marketplace add smoke; OpenAI official directory status recorded | Missing repo marketplace or unverified official-directory status | +| 5 | Dry-run Claude distribution | `claude plugin validate`; `claude plugin tag .claude-plugin --dry-run`; marketplace source/help evidence | Validation, tag, or install-smoke failure | +| 6 | Verify Codex repo marketplace | `codex plugin marketplace add --help`; temp-home local and GitHub-ref repo marketplace add smoke; OpenAI official directory status recorded | Missing repo marketplace or unverified official-directory status | | 7 | Verify OpenCode package | `npm run build:opencode` | Build failure | | 8 | Regenerate release URL ledger | Live and approval-gated URLs separated in `release-url-ledger-YYYY-MM-DD.md` | Placeholder, private URL, or announcement URL drift | | 9 | Create GitHub prerelease | `gh release view v2.0.0-rc.1 --json tagName,url,isPrerelease` | Missing URL or wrong prerelease flag | @@ -92,8 +92,8 @@ keep the related publication action blocked. final release commit. - Do not create or push Claude plugin tags before `claude plugin tag .claude-plugin --dry-run` passes from the final release commit. -- Do not claim Codex official Plugin Directory availability unless OpenAI docs - no longer say official public plugin publishing is pending. +- Do not claim an official Codex Plugin Directory listing unless OpenAI + documents a public submission path or confirms the plugin has been listed. - Do not announce billing, Marketplace, or native payments until ECC Tools live Marketplace account readback returns ready. - Do not rename the repo or package until rc.1 is published and a migration @@ -109,7 +109,8 @@ keep the related publication action blocked. - OpenAI Codex plugin docs: `https://developers.openai.com/codex/plugins/build#add-a-marketplace-from-the-cli` -As of this snapshot, Anthropic documents official marketplace submission through -Claude.ai and Console forms. OpenAI documents repo/local marketplace -distribution for Codex and says official public Plugin Directory publishing and -self-serve plugin management are coming soon. +As of this snapshot, Anthropic documents self-hosted marketplace distribution +through GitHub, git URL, remote marketplace JSON, and local path sources. +OpenAI documents repo/personal marketplace distribution for Codex and describes +an official Plugin Directory, but ECC has not submitted or received an official +directory listing in this pass. diff --git a/tests/docs/ecc2-release-surface.test.js b/tests/docs/ecc2-release-surface.test.js index 7caf2ff6..e1d8bc29 100644 --- a/tests/docs/ecc2-release-surface.test.js +++ b/tests/docs/ecc2-release-surface.test.js @@ -290,7 +290,7 @@ test('publication readiness checklist gates public release actions on evidence', assert.ok(may15Evidence.includes('Plugin Directory publishing is still blocked')); assert.ok(may15Evidence.includes('announcementGate.ready === true')); assert.ok(source.includes('ECC-Tools #73 added announcementGate')); - assert.ok(source.includes('official Plugin Directory publishing and self-serve management are documented as coming soon')); + assert.ok(source.includes('do not claim official Plugin Directory listing before OpenAI submission evidence')); assert.ok(source.includes('release-name-plugin-publication-checklist-2026-05-18.md')); assert.ok(source.includes('Release name and plugin publication checklist')); assert.ok(may15Evidence.includes('| Trunk discussions | GraphQL discussion count and maintainer-touch sweep | 58 total discussions;')); @@ -327,7 +327,7 @@ test('release name and plugin publication checklist freezes rc.1 surfaces', () = '`@affaan-m/ecc` is unclaimed on npm', 'Claude plugin', 'Codex plugin', - 'self-serve plugin management are coming soon', + 'do not claim official directory listing until OpenAI publishing path is available', 'Do not rename the repo or package until rc.1 is published', 'Do not announce billing, Marketplace, or native payments', ]) { From 7e2cdeaeb5a86dec15e385bb2b6fc24b763901ab Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Mon, 18 May 2026 16:27:09 -0400 Subject: [PATCH 13/61] docs: refresh rc1 operator evidence --- ...operator-readiness-dashboard-2026-05-18.md | 4 ++-- .../2.0.0-rc.1/preview-pack-manifest.md | 2 +- .../publication-evidence-2026-05-18.md | 11 +++++----- .../2.0.0-rc.1/publication-readiness.md | 20 +++++++++---------- 4 files changed, 19 insertions(+), 18 deletions(-) diff --git a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md index 25cf0437..f6fdb3ca 100644 --- a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md +++ b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md @@ -2,8 +2,8 @@ This dashboard is generated by `npm run operator:dashboard`. It is an operator snapshot, not release approval. -Generated: 2026-05-18T19:23:54.755Z -Commit: 0f1775e30b4caa08489761417cad0033c5e6e705 +Generated: 2026-05-18T20:25:22.649Z +Commit: 4470e2e6702f17099d6feb137ba03ff00582c202 Status: work remaining ## Current Status diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index 7a5fa34e..c0fab23f 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -24,7 +24,7 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-15.md` | Current May 15 queue, roadmap, security, supply-chain watch, no-lifecycle CI install hardening, AgentShield #86 evidence-pack provenance, ECC Tools billing-gate, Actions cache purge, and `ecc2` test evidence through PR #1941 | Must be superseded by a final clean-checkout evidence file before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-16.md` | Current May 16/17 queue cleanup, recsys skill merge, GateGuard triage, PR #1947 supply-chain protection, AgentShield #87 plugin-cache confidence evidence, AgentShield #88 evidence-pack inspect/readback, AgentShield #89 evidence-pack fleet routing, AgentShield #90 fleet review items, AgentShield #91 policy export, AgentShield #92 policy promotion, ECC-Tools #76 fleet-summary consumption, ECC-Tools #77 hosted finding evidence paths, ECC-Tools #78 harness policy-route linking, dashboard refresh, and combined Node/Rust/release-surface gate evidence through the May 16 mirror | Must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` | May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack protection recheck, npm audit/signature checks, legacy and Linear progress routing, deterministic preview-pack smoke, operator dashboard refresh, Linear sync, and GitHub CI evidence for `27dc2918` | Superseded by the May 18 evidence snapshot; repeat from a strict clean checkout before real publication | -| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | Current May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, current-head Mini Shai-Hulud/TanStack protection recheck, no-lifecycle install, npm audit/signature checks, AgentShield `840952a` enterprise/IOC evidence mirror, work-items sync, Linear sync, operator dashboard refresh, latest current-head CI/security scan success for `67e63e63`, and ITO-46 naming/plugin publication dry-run refresh | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | +| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | Current May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, current-head Mini Shai-Hulud/TanStack protection recheck, no-lifecycle install, npm audit/signature checks, AgentShield `840952a` enterprise/IOC evidence mirror, work-items sync, Linear sync, operator dashboard refresh, latest current-head CI/security scan success for `4470e2e6`, and ITO-46 naming/plugin publication closure | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and publication, plugin, billing, AgentShield, ECC Tools, legacy, and Linear productization gaps still open | | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-18.md` | Live URL and approval-gated URL ledger for release copy | Must be regenerated from the final release commit before public announcements | diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md index c4900a58..97a778c9 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md @@ -7,9 +7,9 @@ npm publication, plugin tag, marketplace submission, or announcement post. | Field | Evidence | | --- | --- | -| Upstream main | `67e63e63f9bfd074bd6a21bf6bac71f3dfefa58b` | +| Upstream main | `4470e2e6702f17099d6feb137ba03ff00582c202` | | Git remote | `https://github.com/affaan-m/everything-claude-code.git` | -| Evidence scope | Current `main` after PR #1970 workflow-security validator bypass fixes, PR #1971 metrics bridge cost-reporting fixes, PR #1972 `uncloud` skill merge, PR #1973 stale script cleanup, issue #1974 cost-reporting verification/closure, PR #1976 OpenAI/AstraFlow provider response guards, PR #1978 review/closure, catalog/operator dashboard refresh, ECC-Tools Wrangler OAuth billing readback mirror, AgentShield `840952a` fleet-ticket and Mini Shai-Hulud IOC evidence mirror, Mini Shai-Hulud/TanStack protection recheck, defensive-deny IOC scanner hardening, release name/plugin publication checklist, readiness/smoke gate enforcement for that checklist, release OIDC publishing-scope hardening, workflow line-ending normalization, current-head CI/security scan, work-items sync, Linear progress sync, and the ITO-46 publication-path dry-run refresh | +| Evidence scope | Current `main` after PR #1970 workflow-security validator bypass fixes, PR #1971 metrics bridge cost-reporting fixes, PR #1972 `uncloud` skill merge, PR #1973 stale script cleanup, issue #1974 cost-reporting verification/closure, PR #1976 OpenAI/AstraFlow provider response guards, PR #1978 review/closure, catalog/operator dashboard refresh, ECC-Tools Wrangler OAuth billing readback mirror, AgentShield `840952a` fleet-ticket and Mini Shai-Hulud IOC evidence mirror, Mini Shai-Hulud/TanStack protection recheck, defensive-deny IOC scanner hardening, release name/plugin publication checklist, readiness/smoke gate enforcement for that checklist, release OIDC publishing-scope hardening, workflow line-ending normalization, current-head CI/security scan, work-items sync, Linear progress sync, the ITO-46 publication-path dry-run refresh, ITO-46 Linear closure, and the post-closure operator dashboard refresh | | Local status caveat | `git status --short --branch` was clean at dashboard generation time; generated evidence files are committed after the source snapshot they describe | The actual release operator should repeat all publish-facing checks from the @@ -24,7 +24,7 @@ final release commit with a strictly clean checkout before publishing. | Discussion audit | `npm run discussion:audit -- --json` | Ready; 58 sampled discussions in `affaan-m/everything-claude-code`, 0 needing maintainer touch, 0 answerable discussions missing accepted answer, and 0 fetch errors | | Platform audit | `node scripts/platform-audit.js --json --allow-untracked docs/drafts/` | Ready; tracked repos report 0 open PRs, 0 open issues, 0 discussion maintainer-touch gaps, 0 answerable Q&A missing accepted answers, and 0 blocking dirty files | | Work-items sync | `node scripts/work-items.js sync-github --repo ` for five tracked repos; `node scripts/status.js --json`; `node scripts/work-items.js list --json` | All five tracked repos synced with 0 open PRs/issues and no changed work items; local status reports 0 open, 0 blocked, and 0 closed work items | -| Operator dashboard | `npm run operator:dashboard -- --markdown --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Regenerated the current dashboard in `fe7b4f2b` from clean snapshot `0f1775e30b4caa08489761417cad0033c5e6e705`; dashboard ready true, publication ready false because release, npm, plugin, billing, and announcement gates are approval-gated; AgentShield enterprise evidence includes `840952a`; ECC Tools native-payments gate now names the operational ITO-61 blocker: authorize Cloudflare API or 1Password CLI access, configure the target Marketplace Pro account and `INTERNAL_API_SECRET`, create or replay Marketplace Pro webhook state, then rerun target readback and the live announcement gate | +| Operator dashboard | `npm run operator:dashboard -- --markdown --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Regenerated at `4470e2e6702f17099d6feb137ba03ff00582c202`; dashboard ready true, publication ready false because release, npm, plugin, billing, and announcement gates are approval-gated; 0 PRs, 0 issues, and 0 discussion gaps remain across tracked repos; AgentShield enterprise evidence includes `840952a`; ECC Tools native-payments gate still names the operational ITO-61 blocker: authorize Cloudflare API or 1Password CLI access, configure the target Marketplace Pro account and `INTERNAL_API_SECRET`, create or replay Marketplace Pro webhook state, then rerun target readback and the live announcement gate | Tracked repositories in the platform audit and work-items sync were: @@ -56,7 +56,7 @@ Tracked repositories in the platform audit and work-items sync were: | Public queues | Rechecked after the merge and issue-closure batch; 0 PRs, 0 issues, and 0 discussion gaps remain across tracked repos | | Release OIDC publishing scope | Pushed `7911af4a` to keep the release workflow's trusted-publishing path scoped to release publication instead of broadening OIDC permissions across unrelated jobs; local workflow security validation passed | | Release workflow normalization | Pushed `97567a91` to normalize release workflow line endings after the OIDC hardening slice; current-head CI `26050727969` passed for `97567a91e79e1ee4c291eb78f5f9c30c2046ac94` | -| Operator readiness evidence refresh | Pushed `0f1775e3`, `fe7b4f2b`, and `67e63e63` to refresh blocker evidence, regenerate the operator dashboard, and align publication readiness to the latest CI/security evidence; current-head CI `26056018725` passed for `67e63e63f9bfd074bd6a21bf6bac71f3dfefa58b` | +| Operator readiness evidence refresh | Pushed `0f1775e3`, `fe7b4f2b`, and `67e63e63` to refresh blocker evidence, regenerate the operator dashboard, and align publication readiness to the latest CI/security evidence; pushed `4470e2e6` to close ITO-46 publication-path evidence, then regenerated the dashboard at `4470e2e6702f17099d6feb137ba03ff00582c202`; current-head CI `26057806361` passed for `4470e2e6702f17099d6feb137ba03ff00582c202` | ## Supply-Chain And Security Evidence @@ -73,7 +73,7 @@ Tracked repositories in the platform audit and work-items sync were: | npm signatures | `npm audit signatures` | 213 verified registry signatures; 17 verified attestations | | Workflow security | `node scripts/ci/validate-workflow-security.js` | Validated 8 workflow files after the release OIDC publishing-scope hardening | | AgentShield project scan | `npx --no-install ecc-agentshield scan --format json` | Grade A / 99; 0 critical, 0 high, 0 medium; 6 low docs-example skill telemetry/governance findings | -| Current-head CI security scan | `gh run view 26056018725 --repo affaan-m/everything-claude-code --json status,conclusion,headSha,jobs,url` | Completed successfully for `67e63e63f9bfd074bd6a21bf6bac71f3dfefa58b`; 37/37 CI jobs passed, including lint, workflow/component validation, coverage, cross-platform package-manager tests, npm audit, and supply-chain IOC scan | +| Current-head CI security scan | `gh run view 26057806361 --repo affaan-m/everything-claude-code --json status,conclusion,headSha,jobs,url` | Completed successfully for `4470e2e6702f17099d6feb137ba03ff00582c202`; 37/37 CI jobs passed, including lint, workflow/component validation, coverage, cross-platform package-manager tests, npm audit, and supply-chain IOC scan | | Latest Supply-Chain Watch | `gh run view 26010432490 --repo affaan-m/everything-claude-code --json status,conclusion,headSha,url` | Completed successfully for `25ac57ac40e9fc5a0606e76e6339e72c79748c99`; rerun from the final release commit before publication | ## ITO-46 Publication Path Refresh @@ -94,6 +94,7 @@ Tracked repositories in the platform audit and work-items sync were: | OpenCode package build | `npm run build:opencode` | Passed | | Preview pack smoke | `npm run preview-pack:smoke` | Ready yes; digest `0ed831dbd0cf`; 5 passed, 0 failed | | Official docs check | Anthropic `https://code.claude.com/docs/en/plugins` and `https://code.claude.com/docs/en/plugin-marketplaces`; OpenAI `https://developers.openai.com/codex/plugins/build` | Anthropic documents self-hosted marketplace sources; OpenAI documents repo/personal marketplaces and the official Plugin Directory. ECC has not created a real release tag, official listing, or npm publication in this pass | +| ITO-46 closure | Linear ITO-46 comment `9ef92056-ab23-4eed-bfdb-932dddc2b056`; Linear issue status `Done`; GitHub Actions `26057806361` | Publication-path docs now record every channel, name conflicts, package/plugin dry-run commands, and blocker register; Codex repo-marketplace distribution is verified but official Plugin Directory listing is not claimed before OpenAI submission/listing evidence | ## Linear Progress Sync diff --git a/docs/releases/2.0.0-rc.1/publication-readiness.md b/docs/releases/2.0.0-rc.1/publication-readiness.md index 7369c3d9..1624505d 100644 --- a/docs/releases/2.0.0-rc.1/publication-readiness.md +++ b/docs/releases/2.0.0-rc.1/publication-readiness.md @@ -44,8 +44,8 @@ protection recheck, npm no-lifecycle install/audit/signature gates, AgentShield project scan, AgentShield `840952a` enterprise/IOC evidence mirror, release OIDC publishing-scope hardening, workflow normalization, later dashboard/publication-readiness refreshes through `67e63e63`, work-items sync, -Linear progress comments, operator dashboard refresh, and current-head -CI/security scan success for `67e63e63`, see +Linear progress comments, ITO-46 closure, operator dashboard refresh, and +current-head CI/security scan success for `4470e2e6`, see [`publication-evidence-2026-05-18.md`](publication-evidence-2026-05-18.md). For the operator-facing prompt-to-artifact readiness dashboard from the same May 16 pass, see @@ -94,22 +94,22 @@ Record the exact commit SHA and command output before any publication action: | Evidence | Command | Required result | Recorded output | | --- | --- | --- | --- | -| Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | `67e63e63`: `## main...origin/main`; repeat from the exact final publication commit before release | +| Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | `4470e2e6`: `## main...origin/main`; repeat from the exact final publication commit before release | | Preview-pack smoke | `npm run preview-pack:smoke` | Preview pack artifacts, Hermes boundary, final verification command list, and publication blockers pass | `publication-evidence-2026-05-18.md`: ready yes, digest `0ed831dbd0cf`, 5 passed, 0 failed; repeat in the final strict clean-checkout release pass | | Harness audit | `npm run harness:audit -- --format json` | 70/70 passing | `99e01ded`: 70/70, 0 top actions | | Adapter scorecard | `npm run harness:adapters -- --check` | PASS | `99e01ded`: PASS, 11 adapters | | Observability readiness | `npm run observability:ready` | 21/21 passing | `publication-evidence-2026-05-18.md`: 21/21, ready yes | | Release safety gate | `npm run observability:ready -- --format json` | Release Safety category passing with publication readiness, supply-chain, workflow security, package surface, and release-surface evidence | May 18 evidence keeps release safety passing; repeat the JSON gate from the exact final release commit | -| Supply-chain verification | `npm audit --json`; `npm audit signatures`; `cd ecc2 && cargo audit -q`; Dependabot alerts; GitGuardian Security Checks | 0 vulnerabilities/alerts, registry signatures verified, GitGuardian clean | `publication-evidence-2026-05-18.md` plus CI `26056018725`: npm registry signatures and attestations verified in the evidence pass, 0 high-or-higher npm vulnerabilities, repo/home IOC scans clean, supply-chain IOC scan passed | -| Root suite | `node tests/run-all.js` | 0 failures | `99e01ded`: local `node tests/run-all.js` passed 2512/2512; current-head CI `26056018725` passed the full OS/runtime/package-manager matrix for `67e63e63` | -| Markdown lint | `npx markdownlint-cli '**/*.md' --ignore node_modules` | 0 failures | CI `26056018725`: markdownlint passed on current head; rerun after any release-copy edits | +| Supply-chain verification | `npm audit --json`; `npm audit signatures`; `cd ecc2 && cargo audit -q`; Dependabot alerts; GitGuardian Security Checks | 0 vulnerabilities/alerts, registry signatures verified, GitGuardian clean | `publication-evidence-2026-05-18.md` plus CI `26057806361`: npm registry signatures and attestations verified in the evidence pass, 0 high-or-higher npm vulnerabilities, repo/home IOC scans clean, supply-chain IOC scan passed | +| Root suite | `node tests/run-all.js` | 0 failures | `99e01ded`: local `node tests/run-all.js` passed 2512/2512; current-head CI `26057806361` passed the full OS/runtime/package-manager matrix for `4470e2e6` | +| Markdown lint | `npx markdownlint-cli '**/*.md' --ignore node_modules` | 0 failures | CI `26057806361`: markdownlint passed on current head; rerun after any release-copy edits | | Package surface | `node tests/scripts/npm-publish-surface.test.js` | 0 failures; no Python bytecode in npm tarball | `2/2` passed in May 12 evidence pass | -| Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | May 18 evidence refresh: 21/21 passed after public-path sanitization, during the `0f1775e3` operator-readiness refresh, and again in the ITO-46 dry-run pass | +| Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | May 18 evidence refresh: 21/21 passed after public-path sanitization, during the `0f1775e3` operator-readiness refresh, and again in the ITO-46 dry-run pass before `4470e2e6` | | Optional Rust surface | `cd ecc2 && cargo test` | 0 failures or explicit deferral | `publication-evidence-2026-05-16.md`: 462/462 passed, existing warnings only | -| Queue baseline | `node scripts/platform-audit.js --json` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | `0f1775e3`: platform audit ready, 0 open PRs, 0 open issues, 0 conflicting PRs, and 0 blocking dirty files in the regenerated dashboard snapshot | -| Discussion baseline | `node scripts/platform-audit.js --json` and `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | `0f1775e3`: platform audit sampled 58 trunk discussions, 0 needing maintainer touch, 0 answerable discussions missing accepted answer; `docs/architecture/discussion-response-playbook.md` records response templates and security escalation rules | +| Queue baseline | `node scripts/platform-audit.js --json` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | `4470e2e6`: platform audit ready, 0 open PRs, 0 open issues, 0 conflicting PRs, and 0 blocking dirty files in the regenerated dashboard snapshot | +| Discussion baseline | `node scripts/platform-audit.js --json` and `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | `4470e2e6`: platform audit sampled 58 trunk discussions, 0 needing maintainer touch, 0 answerable discussions missing accepted answer; `docs/architecture/discussion-response-playbook.md` records response templates and security escalation rules | | Linear roadmap | Linear project and issue readback | Detailed roadmap exists with release, security, AgentShield, ECC Tools, legacy, and observability lanes | May 18 Linear comments include ITO-57 `3fe5b2b7-c4fe-401c-a317-b40d72119cb3` and ITO-44 `fb4a4f33-6c2d-421a-bbdb-63cfad3e3ee4`; earlier evidence records the project and 16 issue lanes | -| Operator readiness dashboard | `npm run operator:dashboard -- --json` | Current queue state mapped to macro-goal deliverables and incomplete gaps | `fe7b4f2b`: regenerated May 18 dashboard from clean snapshot `0f1775e3`; platform audit ready true, 0 open PRs, 0 open issues, 0 discussion gaps, 0 dirty files, and publication gates still approval-gated | +| Operator readiness dashboard | `npm run operator:dashboard -- --json` | Current queue state mapped to macro-goal deliverables and incomplete gaps | `4470e2e6`: regenerated May 18 dashboard from current main; platform audit ready true, 0 open PRs, 0 open issues, 0 discussion gaps, 0 dirty files, and publication gates still approval-gated | | Release URL ledger | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-18.md` plus placeholder-marker scan | Live links and approval-gated links are separated before announcement copy is posted | Ledger records public repo/docs/CI/supply-chain/npm/OpenAI Codex documentation URLs and blocks GitHub release/npm/plugin/billing/social URLs until approval-gated checks pass | | Release name and plugin publication checklist | `docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md` | Name/package/plugin values are frozen, final-release commands are listed, and Claude/Codex publication paths cite current official docs | Checklist keeps `Everything Claude Code / ECC`, `ecc-universal`, and plugin slug `ecc` for rc.1; no rename, npm publish, plugin tag, official listing, billing claim, or announcement before final evidence | From cb81f1b0fe5566c37093858b67fc861801eba62c Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Mon, 18 May 2026 16:45:31 -0400 Subject: [PATCH 14/61] docs: narrow ecc tools billing blocker --- docs/ECC-2.0-GA-ROADMAP.md | 21 +++++++++-------- ...operator-readiness-dashboard-2026-05-18.md | 6 ++--- .../publication-evidence-2026-05-18.md | 23 +++++++++---------- scripts/operator-readiness-dashboard.js | 7 +++++- 4 files changed, 31 insertions(+), 26 deletions(-) diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index c2eddbff..c4ea81b2 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -331,10 +331,10 @@ As of 2026-05-18: counts to `npm run billing:kv-readback`, including `marketplaceSourceRecords`, `marketplaceSourceWithWebhookEvidence`, `marketplaceSourceWithoutWebhookEvidence`, `byMarketplacePlanName`, and - `byMarketplaceEventAction`. The 2026-05-18 live Wrangler OAuth readback - found 254 account-billing records, 254 billing-state records, 195 + `byMarketplaceEventAction`. The 2026-05-18 live Wrangler OAuth readback now + works and found 256 account-billing records, 256 billing-state records, 197 Marketplace-source records, 59 Stripe-source records, 53 Pro records, 0 - Marketplace Pro records, 2 Marketplace webhook-provenance records, both + Marketplace Pro records, 4 Marketplace webhook-provenance records, all `Open Source` purchases, and 193 Marketplace-source records without webhook provenance. Native-payments copy remains blocked by Linear ITO-61 until a real Marketplace-managed Pro webhook creates target account provenance and @@ -352,12 +352,13 @@ As of 2026-05-18: `brace-expansion@5.0.6` and fixed Dependabot alert 44 for CVE-2026-45149; GitHub API reported `state: fixed` at `2026-05-18T19:10:15Z` and current-head CI `26054671308` passed. -- The latest ITO-61 readback retry remains operationally blocked: Wrangler - Cloudflare API auth returned `Authentication error [code: 10000]`, - 1Password CLI authorization timed out, `billing:announcement-gate -- --preflight` - is missing the target Marketplace account plus `INTERNAL_API_SECRET`, and - native-payments copy remains blocked until the target readback and live - announcement gate pass. +- The latest ITO-61 readback retry narrowed the blocker: Wrangler OAuth now + works, the safe aggregate readback has 0 parse failures and still reports 0 + Marketplace Pro records, and `billing:announcement-gate -- --preflight` is + missing the target Marketplace account plus `INTERNAL_API_SECRET`. + Native-payments copy remains blocked until the target Pro readback and live + announcement gate pass. Linear comment + `6904e4fb-bec7-4787-90e2-759f077a628c` records the redacted readback counts. - Handoff `ecc-supply-chain-audit-20260513-0645.md` under `~/.cluster-swarm/handoffs/` records the May 13 supply-chain sweep: no active lockfile/manifest hit for @@ -725,7 +726,7 @@ is not complete unless the evidence column exists and has been freshly verified. | Claude and Codex plugin publication | Contact/submission path with required artifacts and status | Publication readiness, naming matrix, and May 12 dry-run evidence document plugin validation, clean-checkout Claude tag/install smoke, and Codex marketplace CLI shape | Needs explicit approval for real tag/push and marketplace submission | | Articles, tweets, and announcements | X thread, LinkedIn copy, GitHub release copy, push checklist | Draft launch collateral exists under rc.1 release docs | Needs URL-backed refresh | | AgentShield enterprise iteration | Policy gates, SARIF, packs, provenance, corpus, HTML reports, exception lifecycle audit, baseline drift Action/CLI surfaces, evidence-pack redaction, harness adapter registry, enterprise research roadmap, supply-chain hardened release path, CI-safe baseline fingerprints, corpus accuracy recommendations, remediation workflow phases, env proxy hijack corpus coverage, Mini Shai-Hulud full-campaign package IOCs, CI-provenance evidence packs, plugin-cache runtime-confidence triage, evidence-pack consumer readback, fleet-level evidence-pack routing, fleet review items, fleet review ticket payloads, checksum-backed policy export, checksum-verified policy promotion, policy promotion review items, package-manager hardening drift detection, npm age-gate guidance correction, workflow action-runtime pin refresh, package-manager hardening Action outputs, policy-promotion Action outputs, ECC-Tools hosted consumption of promotion Action outputs, ECC-Tools operator-visible promotion output values, and ECC-Tools hosted promotion judge audit traces | PRs #53, #55-#64, #67-#69, and #78-#92 landed with test evidence, ECC-Tools #76 consumes the fleet-summary output in hosted security review, #77 surfaces source evidence paths in hosted finding output, and #78 links fleet routes to harness owner review; AgentShield #91 adds `agentshield policy export` bundles for branch-protection review and downstream promotion; AgentShield #92 adds `agentshield policy promote` with digest verification, tamper rejection, explicit pack selection, dry-run review, and JSON output before writing active policy; AgentShield commit `87aec47` adds `reviewItems` for digest evidence, owner review, protected rollout PR handoff, and runtime smoke testing with green local and remote CI; AgentShield commit `28d08c7` adds package-manager hardening drift detection for plaintext registry credentials, lifecycle-script enablement, and weak pnpm/Yarn release-age cooldowns with green local and remote CI; AgentShield commit `659f569` refreshes all workflow action runtime pins to SHA-pinned checkout v6.0.2 and setup-node v6.4.0 with green remote CI and no remaining action-runtime deprecation annotation; AgentShield commit `ee585cd` corrects npm release-age guidance by flagging unsupported npm age keys and keeping enforceable cooldown findings on pnpm/Yarn with green local and remote CI; AgentShield commit `1124535` exposes package-manager hardening status/count outputs and a redacted job-summary section for registry credentials, lifecycle scripts, and release-age gates with green local and remote CI; AgentShield commit `1593925` exposes policy-promotion status/count/digest outputs plus job-summary review items for owner approval, protected rollout, and runtime smoke, and marks runtime smoke verified when the same Action job scans with the promoted policy; AgentShield commit `840952a` adds Linear/operator-ready fleet review ticket payloads and expands current Mini Shai-Hulud IOC breadcrumbs with green local and remote CI; ECC-Tools commit `8658951` routes those policy-promotion Action outputs into hosted security review findings and Hosted Promotion Readiness scoring; ECC-Tools commit `16c537f` renders policy-promotion status, pack, review item count, action-required count, and digest in hosted security job comments/check-runs; ECC-Tools commit `05d4e82` renders hosted promotion judge request fingerprints and allowed-citation counts without raw provider output; native PDF export deferred in favor of self-contained HTML plus print-to-PDF until explicit enterprise demand appears; `docs/architecture/agentshield-enterprise-research-roadmap.md` now has baseline drift, evidence-pack bundle, redaction, adapter-registry, supply-chain hardening, hashed baseline fingerprints, corpus accuracy recommendation, remediation workflow, env proxy hijack corpus, Mini Shai-Hulud full-campaign package-table, `ci-context.json` provenance, `plugin-cache` confidence, `evidence-pack inspect` readback, `evidence-pack fleet` routing, fleet `reviewItems`, fleet review ticket payloads, policy export, policy promotion, policy promotion `reviewItems`, package-manager hardening Action outputs, policy-promotion Action outputs, hosted consumption of promotion Action outputs, operator-visible promotion output values, and hosted promotion judge audit traces landed | Next workflow automation should deepen live operator approval/readback after Marketplace/payment gates | -| ECC Tools next-level app | Billing audit, PR checks, deep analyzer, sync backlog, evaluator/RAG corpus, analysis-depth readiness, hosted execution planning, hosted CI diagnostics, hosted security evidence review, hosted harness compatibility audit, hosted reference-set evaluation, hosted AI routing/cost review, hosted team backlog routing, hosted depth-plan check-run, PR-comment hosted job dispatch, hosted job result history/check-runs, hosted result status command, status-aware depth-plan recommendations, hosted promotion readiness, hosted promotion output scoring, hosted promotion retrieval planning, hosted promotion judge contract, gated hosted promotion judge execution, hosted promotion judge audit trace, payment-announcement readiness, billing announcement preflight, aggregate production billing KV readback, Marketplace webhook provenance, target-account billing readback, Marketplace-source provenance counts, AgentShield fleet-summary hosted routing, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output hosted telemetry, and operator-visible promotion output values | PRs #26-#43 plus #53-#78 landed with test evidence, including AgentShield evidence-pack gap routing, canonical bundle recognition, supply-chain signature gates, PR draft follow-up Linear tracking, evidence-backed/deep-ready repository classification, the `/api/analysis/depth-plan` hosted job plan, `/api/analysis/jobs/ci-diagnostics`, `/api/analysis/jobs/security-evidence-review`, `/api/analysis/jobs/harness-compatibility-audit`, `/api/analysis/jobs/reference-set-evaluation`, `/api/analysis/jobs/ai-routing-cost-review`, `/api/analysis/jobs/team-backlog-routing`, the `ECC Tools / Hosted Depth Plan` check-run, `/ecc-tools analyze --job ...` PR-comment dispatch, non-blocking per-hosted-job result check-runs backed by 30-day result cache records, `/ecc-tools analyze --job status` cache lookup, cache-aware next-job recommendations in the depth-plan check-run, the `ECC Tools / Hosted Promotion Readiness` corpus-backed PR check-run, deterministic hosted-output scoring against cached completed job artifacts/findings, ranked retrieval/model-prompt planning, the fail-closed `hosted-promotion-judge.v1` request contract, opt-in live model-judge execution behind hosted evidence, entitlement, budget, provider, executor, strict JSON, and citation gates, hosted promotion judge request fingerprints plus allowed-citation audit trails, a fail-closed `/api/billing/readiness` `announcementGate` for native GitHub payments claims, `npm run billing:announcement-gate` plus `--preflight` as the non-secret operator verifier, hosted security findings for AgentShield fleet summaries, an `Evidence` column in hosted finding comments/check-runs, hosted harness findings that route AgentShield fleet target paths to harness owners, ECC-Tools commit `8658951` routing AgentShield policy-promotion Action outputs into hosted security review and promotion-readiness scoring, ECC-Tools commit `16c537f` rendering policy-promotion status/pack/count/digest values directly in hosted security job comments/check-runs, ECC-Tools commit `05d4e82` rendering model-judge audit traces without exposing raw provider output, ECC-Tools commit `91a441b` adding the safe billing announcement preflight path, ECC-Tools commit `eb69412` recording the initial production readback state, ECC-Tools commit `95d0bec` adding `npm run billing:kv-readback` with 253 aggregate account-billing and billing-state records but 0 Marketplace Pro billing-state records, ECC-Tools commit `2859678` requiring webhook-derived Marketplace provenance before announcement readiness, ECC-Tools commit `42653f9` adding Wrangler OAuth readback with live aggregate evidence of 253 account-billing records, 253 billing-state records, and 0 ready-like Marketplace Pro states, ECC-Tools commit `632e059` adding sanitized target-account readback that requires both target key families before `--require-ready` can pass, and ECC-Tools commit `d5f60db` adding sanitized Marketplace plan/action provenance counts; the 2026-05-18 live Wrangler OAuth recheck found 254 account-billing records, 254 billing-state records, 195 Marketplace-source records, 2 Marketplace webhook-provenance records, both `Open Source`, and 0 Marketplace Pro records, then updated Linear ITO-61 with the data/provisioning blocker | Next work is create or verify Marketplace-managed Pro target billing-state with webhook provenance, then run `billing:kv-readback -- --wrangler --wrangler-bin ./node_modules/.bin/wrangler --account --require-ready`, followed by the live announcement gate | +| ECC Tools next-level app | Billing audit, PR checks, deep analyzer, sync backlog, evaluator/RAG corpus, analysis-depth readiness, hosted execution planning, hosted CI diagnostics, hosted security evidence review, hosted harness compatibility audit, hosted reference-set evaluation, hosted AI routing/cost review, hosted team backlog routing, hosted depth-plan check-run, PR-comment hosted job dispatch, hosted job result history/check-runs, hosted result status command, status-aware depth-plan recommendations, hosted promotion readiness, hosted promotion output scoring, hosted promotion retrieval planning, hosted promotion judge contract, gated hosted promotion judge execution, hosted promotion judge audit trace, payment-announcement readiness, billing announcement preflight, aggregate production billing KV readback, Marketplace webhook provenance, target-account billing readback, Marketplace-source provenance counts, AgentShield fleet-summary hosted routing, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output hosted telemetry, and operator-visible promotion output values | PRs #26-#43 plus #53-#78 landed with test evidence, including AgentShield evidence-pack gap routing, canonical bundle recognition, supply-chain signature gates, PR draft follow-up Linear tracking, evidence-backed/deep-ready repository classification, the `/api/analysis/depth-plan` hosted job plan, `/api/analysis/jobs/ci-diagnostics`, `/api/analysis/jobs/security-evidence-review`, `/api/analysis/jobs/harness-compatibility-audit`, `/api/analysis/jobs/reference-set-evaluation`, `/api/analysis/jobs/ai-routing-cost-review`, `/api/analysis/jobs/team-backlog-routing`, the `ECC Tools / Hosted Depth Plan` check-run, `/ecc-tools analyze --job ...` PR-comment dispatch, non-blocking per-hosted-job result check-runs backed by 30-day result cache records, `/ecc-tools analyze --job status` cache lookup, cache-aware next-job recommendations in the depth-plan check-run, the `ECC Tools / Hosted Promotion Readiness` corpus-backed PR check-run, deterministic hosted-output scoring against cached completed job artifacts/findings, ranked retrieval/model-prompt planning, the fail-closed `hosted-promotion-judge.v1` request contract, opt-in live model-judge execution behind hosted evidence, entitlement, budget, provider, executor, strict JSON, and citation gates, hosted promotion judge request fingerprints plus allowed-citation audit trails, a fail-closed `/api/billing/readiness` `announcementGate` for native GitHub payments claims, `npm run billing:announcement-gate` plus `--preflight` as the non-secret operator verifier, hosted security findings for AgentShield fleet summaries, an `Evidence` column in hosted finding comments/check-runs, hosted harness findings that route AgentShield fleet target paths to harness owners, ECC-Tools commit `8658951` routing AgentShield policy-promotion Action outputs into hosted security review and promotion-readiness scoring, ECC-Tools commit `16c537f` rendering policy-promotion status/pack/count/digest values directly in hosted security job comments/check-runs, ECC-Tools commit `05d4e82` rendering model-judge audit traces without exposing raw provider output, ECC-Tools commit `91a441b` adding the safe billing announcement preflight path, ECC-Tools commit `eb69412` recording the initial production readback state, ECC-Tools commit `95d0bec` adding `npm run billing:kv-readback` with aggregate account-billing and billing-state records but 0 Marketplace Pro billing-state records, ECC-Tools commit `2859678` requiring webhook-derived Marketplace provenance before announcement readiness, ECC-Tools commit `42653f9` adding Wrangler OAuth readback, ECC-Tools commit `632e059` adding sanitized target-account readback that requires both target key families before `--require-ready` can pass, and ECC-Tools commit `d5f60db` adding sanitized Marketplace plan/action provenance counts; the latest 2026-05-18 live Wrangler OAuth recheck found 256 account-billing records, 256 billing-state records, 197 Marketplace-source records, 4 Marketplace webhook-provenance records, all `Open Source`, and 0 Marketplace Pro records, then updated Linear ITO-61 with the data/provisioning blocker | Next work is create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure target account plus `INTERNAL_API_SECRET`, then run `billing:kv-readback -- --wrangler --wrangler-bin ./node_modules/.bin/wrangler --account --require-ready`, followed by the live announcement gate | | GitGuardian/Dependabot/CodeRabbit-style checks | Non-blocking taxonomy, deterministic follow-up checks, and local supply-chain gates | ECC-Tools risk taxonomy check plus follow-up signals landed, including Skill Quality, Deep Analyzer Evidence, Analyzer Corpus Evidence, RAG/Evaluator Evidence, PR Review/Salvage Evidence, and AgentShield evidence-pack evidence; #1846 added npm registry signature gates; #1848 added the supply-chain incident-response playbook and `pull_request_target` cache-poisoning validator guard; #1851 added the privileged checkout credential-persistence guard; AgentShield #78, JARVIS #13, and ECC-Tools #53 applied the same hardening outside trunk | Current supply-chain gate complete; deeper hosted review features remain future | | Harness-agnostic learning system | Audit, adapter matrix, observability, traces, promotion loop | Audit/adapters/observability gates plus `docs/architecture/evaluator-rag-prototype.md`, `examples/evaluator-rag-prototype/`, and ECC-Tools PR #40 define read-only stale-salvage, billing-readiness, CI-failure-diagnosis, harness-config-quality, AgentShield policy-exception, skill-quality evidence, deep-analyzer evidence, and RAG/evaluator comparison scenarios with trace, report, playbook, verifier, and predictive-check artifacts; ECC-Tools PRs #68-#72 now turn that corpus into a deterministic PR check-run gate with cached hosted-output scoring, ranked retrieval candidates, a model prompt seed, a fail-closed hosted model-judge request contract, and opt-in live model execution behind strict hosted-evidence gates | Deterministic hosted PR check, cached output scoring, retrieval planning, judge contract, and gated model execution integrated | | Linear roadmap is detailed | Linear project status plus repo mirror | Repo mirror exists; issue creation was retried on 2026-05-12 and remains blocked by the workspace free issue limit; the May 18 sync adds queue-zero/work-items state, #1970/#1971/#1972/#1976 merge evidence, ITO-57 current-head supply-chain refresh comment `0b9931b9-1556-4ebc-a70c-f3635557625d`, ITO-57 defensive-deny scanner recheck reply `6fa15367-d994-4e53-ade3-9462477e1100`, ECC platform progress comment `e32e5b7a-287b-4bf4-9ed7-314389a157e1`, and generated `operator:dashboard` prompt-to-artifact audit for recurring status updates | Needs recurring status updates after each significant merge batch | diff --git a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md index f6fdb3ca..5daa8f59 100644 --- a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md +++ b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md @@ -30,7 +30,7 @@ Status: work remaining | Prepare name-change, Claude plugin, and Codex plugin paths | naming-and-publication-matrix plus release-name-plugin-publication checklist plus publication-readiness | in_progress | naming matrix, release publication checklist, and plugin readiness gates exist | real tag/push, marketplace submission, and final channel choice remain approval-gated | | Prepare release notes, articles, tweets, and push notifications | docs/releases/2.0.0-rc.1 social and release-copy files | in_progress | release notes, X thread, LinkedIn draft, and URL ledger are present | final live release/npm/plugin/billing URLs and publish approval still pending | | Advance AgentShield enterprise iteration | AgentShield PR evidence plus enterprise roadmap | in_progress | AgentShield policy promotion `reviewItems` landed in `87aec47`; package-manager hardening drift detection landed in `28d08c7`; workflow action runtime pins were refreshed in `659f569`; npm age-gate guidance was corrected in `ee585cd`; package-manager hardening Action outputs landed in `1124535`; policy-promotion Action outputs and runtime-smoke job-summary evidence landed in `1593925`; fleet review ticket payloads and current Mini Shai-Hulud IOC breadcrumbs landed in `840952a`; ECC-Tools consumes those outputs in `8658951`, surfaces operator-readable status/pack/count/digest telemetry in `16c537f`, and renders hosted promotion judge audit traces in `05d4e82`; all are mirrored in the GA roadmap | deepen live operator approval/readback after Marketplace/payment gates | -| Advance ECC Tools native payments and AI-native harness-agnostic app | ECC Tools PR evidence, billing gate, hosted analysis lanes | in_progress | billing announcement gate, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler OAuth readback, target-account billing readback, provenance-aware Marketplace billing-state gates, sanitized Marketplace plan/action provenance counts, hosted team-learning feedback controls, and ECC-Tools Dependabot alert remediation are mirrored in the GA roadmap | authorize Cloudflare API or 1Password CLI access, configure the target Marketplace Pro account and INTERNAL_API_SECRET, create or replay Marketplace Pro webhook state, then rerun target readback and the live announcement gate | +| Advance ECC Tools native payments and AI-native harness-agnostic app | ECC Tools PR evidence, billing gate, hosted analysis lanes | in_progress | billing announcement gate, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler OAuth readback, target-account billing readback, provenance-aware Marketplace billing-state gates, sanitized Marketplace plan/action provenance counts, hosted team-learning feedback controls, and ECC-Tools Dependabot alert remediation are mirrored in the GA roadmap | create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure the target account and INTERNAL_API_SECRET, then rerun target readback and the live announcement gate | | Audit, prune, or attach legacy work | docs/stale-pr-salvage-ledger.md and legacy inventory | current | legacy salvage ledger and inventory are current; all localization tails are attached to Linear ITO-55 for manual language-owner review | repeat legacy scan before release | | Keep Linear roadmap detailed and progress tracking synchronized | Linear project mirror plus progress-sync contract | current | Linear live sync and project progress surface are current; progress-sync contract defines the file-backed work-items/status path | repeat Linear/project status update and local work-items sync after each significant merge batch | | Provide ECC 2.0 observability for self-use | observability readiness gate | complete | observability:ready command and readiness doc exist | runtime/dashboard implementation can continue after release gates | @@ -41,11 +41,11 @@ Status: work remaining - `naming-and-plugin-publication`: real tag/push, marketplace submission, and final channel choice remain approval-gated - `release-notes-and-notifications`: final live release/npm/plugin/billing URLs and publish approval still pending - `agentshield-enterprise-iteration`: deepen live operator approval/readback after Marketplace/payment gates -- `ecc-tools-next-level`: authorize Cloudflare API or 1Password CLI access, configure the target Marketplace Pro account and INTERNAL_API_SECRET, create or replay Marketplace Pro webhook state, then rerun target readback and the live announcement gate +- `ecc-tools-next-level`: create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure the target account and INTERNAL_API_SECRET, then rerun target readback and the live announcement gate ## Next Work Order 1. Regenerate this dashboard from the final release commit before publication evidence is recorded. 2. Repeat ITO-57 Linear/project status sync after the next significant merge batch or advisory-source refresh. -3. Authorize Cloudflare API or 1Password CLI access, configure the target Marketplace Pro account and INTERNAL_API_SECRET, create or replay Marketplace Pro webhook state, then rerun target readback and the live announcement gate before publishing native-payments copy. +3. Create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure the target account and INTERNAL_API_SECRET, then rerun target readback and the live announcement gate before publishing native-payments copy. 4. Resume ITO-45, ITO-46, and ITO-56 only after the generated dashboard and final release gates are refreshed. diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md index 97a778c9..230dcccd 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md @@ -24,7 +24,7 @@ final release commit with a strictly clean checkout before publishing. | Discussion audit | `npm run discussion:audit -- --json` | Ready; 58 sampled discussions in `affaan-m/everything-claude-code`, 0 needing maintainer touch, 0 answerable discussions missing accepted answer, and 0 fetch errors | | Platform audit | `node scripts/platform-audit.js --json --allow-untracked docs/drafts/` | Ready; tracked repos report 0 open PRs, 0 open issues, 0 discussion maintainer-touch gaps, 0 answerable Q&A missing accepted answers, and 0 blocking dirty files | | Work-items sync | `node scripts/work-items.js sync-github --repo ` for five tracked repos; `node scripts/status.js --json`; `node scripts/work-items.js list --json` | All five tracked repos synced with 0 open PRs/issues and no changed work items; local status reports 0 open, 0 blocked, and 0 closed work items | -| Operator dashboard | `npm run operator:dashboard -- --markdown --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Regenerated at `4470e2e6702f17099d6feb137ba03ff00582c202`; dashboard ready true, publication ready false because release, npm, plugin, billing, and announcement gates are approval-gated; 0 PRs, 0 issues, and 0 discussion gaps remain across tracked repos; AgentShield enterprise evidence includes `840952a`; ECC Tools native-payments gate still names the operational ITO-61 blocker: authorize Cloudflare API or 1Password CLI access, configure the target Marketplace Pro account and `INTERNAL_API_SECRET`, create or replay Marketplace Pro webhook state, then rerun target readback and the live announcement gate | +| Operator dashboard | `npm run operator:dashboard -- --markdown --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Regenerated at `4470e2e6702f17099d6feb137ba03ff00582c202`; dashboard ready true, publication ready false because release, npm, plugin, billing, and announcement gates are approval-gated; 0 PRs, 0 issues, and 0 discussion gaps remain across tracked repos; AgentShield enterprise evidence includes `840952a`; ECC Tools native-payments gate now names the narrowed ITO-61 blocker: create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure the target account and `INTERNAL_API_SECRET`, then rerun target readback and the live announcement gate | Tracked repositories in the platform audit and work-items sync were: @@ -102,7 +102,7 @@ Tracked repositories in the platform audit and work-items sync were: | --- | --- | | ITO-57 issue comments | `0b9931b9-1556-4ebc-a70c-f3635557625d` records May 18 queue counts, #1970/#1971/#1972/#1976 merge evidence, supply-chain verification, current-head CI URL, deferred gates, and next slices; reply `6fa15367-d994-4e53-ade3-9462477e1100` records the expanded TanStack/Mini Shai-Hulud recheck, defensive-deny scanner fix, current-head CI `26017368895`, and post-push platform audit; comment `3fe5b2b7-c4fe-401c-a317-b40d72119cb3` records the final emergency refresh against `97567a91`, AgentShield `4e36aab`, clean ECC/Ito/Documents workspace IOC scans, absent dead-man/persistence artifacts, and package-manager/Claude deny-wall posture; comment `43837404-c01c-4aaa-b5e2-1e784c136d69` records ECC-Tools `brace-expansion` alert 44 fixed in `e56fc1a` with CI `26054671308` and Dependabot API `state: fixed` | | ITO-52 issue status | `f2e5a208-de91-4a3a-960b-5362d12aa5a4` records ECC-Tools `69ca535` team-learning feedback controls, local verification, and CI `26054455434`; Linear ITO-52 is Done | -| ITO-61 issue status | `8c366592-1c9a-48ad-b9a9-2908a0463fa5` records the latest native-payments readback blocker: Wrangler Cloudflare auth `10000`, 1Password CLI authorization timeout, missing Marketplace target account, and missing `INTERNAL_API_SECRET` | +| ITO-61 issue status | `6904e4fb-bec7-4787-90e2-759f077a628c` records the narrowed native-payments readback blocker: Wrangler OAuth now works, aggregate readback is clean, but there is still no Marketplace-managed Pro target billing-state with webhook provenance and the local announcement preflight is missing the target account plus `INTERNAL_API_SECRET` | | ECC platform project comment | `e32e5b7a-287b-4bf4-9ed7-314389a157e1` records the earlier current public queue, security, #1976, and remaining-gate state at the project level; follow-up ITO-44 comments `a01eeef3-c69b-48c0-8804-a4682acfc1ef` and `6b0885cc-c4e9-40db-899b-f7b88b4aa046` record ITO-52 completion and the fixed ECC-Tools Dependabot alert | | Project status update caveat | Linear returned "Project status updates are not enabled for this workspace"; project comment was used as the supported status surface | @@ -121,19 +121,18 @@ Tracked repositories in the platform audit and work-items sync were: `npm run billing:kv-readback -- --account --require-ready` with working Cloudflare API auth or repaired Wrangler OAuth, followed by `npm run billing:announcement-gate -- --account `, return - announcement-ready gates. The latest API-authenticated aggregate readback - from the ECC vault Cloudflare credential found 253 `account-billing:*` - records, 253 `billing-state:*` records, 0 Marketplace Pro states, 0 - ready-like Marketplace Pro states, and 0 parse failures; local Wrangler OAuth - currently fails with Cloudflare authentication error `10000`. ECC-Tools + announcement-ready gates. The latest Wrangler OAuth aggregate readback found + 256 `account-billing:*` records, 256 `billing-state:*` records, 197 + Marketplace-source records, 59 Stripe-source records, 53 Pro records, 4 + Marketplace webhook-provenance records, all `Open Source`, 0 Marketplace Pro + states, 0 ready-like Marketplace Pro states, and 0 parse failures. ECC-Tools commit `632e059` adds the follow-up target-account readback mode, redacts the account login and raw KV key names, and requires both target key families before `--require-ready` can pass. ECC-Tools commit `13cd3fc` normalizes - billing-state key casing. The latest ITO-61 retry still fails before readback - because Wrangler Cloudflare auth returns `10000`, 1Password CLI authorization - timed out, and the announcement preflight is missing the target account and - `INTERNAL_API_SECRET`; Linear ITO-61 tracks the exact target-account - acceptance criteria. + billing-state key casing. The latest ITO-61 retry fails because no + Marketplace-managed Pro state exists and the announcement preflight is + missing the target account plus `INTERNAL_API_SECRET`; Linear ITO-61 tracks + the exact target-account acceptance criteria. - Release notes, X, LinkedIn, GitHub release, and longform copy still need final live URLs after release/package/plugin URLs exist. - The local checkout is clean after the dashboard/evidence refresh, but a diff --git a/scripts/operator-readiness-dashboard.js b/scripts/operator-readiness-dashboard.js index 7b47d7d2..7e05936c 100644 --- a/scripts/operator-readiness-dashboard.js +++ b/scripts/operator-readiness-dashboard.js @@ -392,6 +392,11 @@ function eccToolsNextLevelGap(roadmap) { return 'authorize Cloudflare API or 1Password CLI access, configure the target Marketplace Pro account and INTERNAL_API_SECRET, create or replay Marketplace Pro webhook state, then rerun target readback and the live announcement gate'; } + if (roadmap.includes('Wrangler OAuth now works') + || roadmap.includes('6904e4fb-bec7-4787-90e2-759f077a628c')) { + return 'create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure the target account and INTERNAL_API_SECRET, then rerun target readback and the live announcement gate'; + } + if (roadmap.includes('d5f60db') || roadmap.includes('Marketplace-source provenance counts')) { return 'create or verify Marketplace-managed Pro target billing-state with webhook provenance, then run `billing:kv-readback -- --wrangler --wrangler-bin ./node_modules/.bin/wrangler --account --require-ready`, followed by the live announcement gate'; @@ -822,7 +827,7 @@ function buildReport(options) { next_work_order: [ 'Regenerate this dashboard from the final release commit before publication evidence is recorded.', 'Repeat ITO-57 Linear/project status sync after the next significant merge batch or advisory-source refresh.', - 'Authorize Cloudflare API or 1Password CLI access, configure the target Marketplace Pro account and INTERNAL_API_SECRET, create or replay Marketplace Pro webhook state, then rerun target readback and the live announcement gate before publishing native-payments copy.', + 'Create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure the target account and INTERNAL_API_SECRET, then rerun target readback and the live announcement gate before publishing native-payments copy.', 'Resume ITO-45, ITO-46, and ITO-56 only after the generated dashboard and final release gates are refreshed.', ], }; From e3483fda159cce89ec81551030018eb7da86a876 Mon Sep 17 00:00:00 2001 From: Jamkris Date: Tue, 19 May 2026 09:16:26 +0900 Subject: [PATCH 15/61] =?UTF-8?q?fix(ci):=20cover=20Unicode=20Tag=20block?= =?UTF-8?q?=20(U+E0000=E2=80=93U+E007F)=20in=20check-unicode-safety?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `isDangerousInvisibleCodePoint` enumerated seven ranges of invisible/ bidi/variation-selector code points but omitted the Unicode Tag block (U+E0000–U+E007F). Tag characters were proposed for language tagging in Unicode 3.1 and have been deprecated since Unicode 5.1, so no legitimate text uses them. They are the canonical vector for "ASCII Smuggling" / "Tag Smuggling" LLM prompt injection: an attacker hides instructions inside an ASCII-looking string, the model reads the tag bytes, the human reviewer sees nothing. Demonstrated against multiple LLM assistants during 2024–2025. `check-unicode-safety.js` is the repo's last line of defence before contributor content reaches agent context; the same script also runs in `--write` auto-sanitize mode on `.md` / `.mdx` / `.txt`. Today it silently passes tag-block characters through unchanged in both detection mode and `--write` mode. Reproduced before this commit: $ mkdir -p /tmp/uni-test && node -e " const fs = require('fs'); const hidden = [...Array(5)].map((_,i) => String.fromCodePoint(0xE0041 + i)).join(''); fs.writeFileSync('/tmp/uni-test/innocent.md', '# Title\\n\\nBenign text' + hidden + ' more.\\n');" $ ECC_UNICODE_SCAN_ROOT=/tmp/uni-test \ node scripts/ci/check-unicode-safety.js Unicode safety check passed. $ echo $? 0 Expected: tag-block characters reported as `dangerous-invisible` violations (exit 1) and stripped under `--write`. Actual: validator passes, `--write` leaves the bytes intact. Fix: extend the denylist with one new range `(codePoint >= 0xE0000 && codePoint <= 0xE007F)`. The change is purely additive; the existing seven ranges are untouched. After this commit the same reproduction returns: $ ECC_UNICODE_SCAN_ROOT=/tmp/uni-test \ node scripts/ci/check-unicode-safety.js Unicode safety violations detected: innocent.md:3:12 dangerous-invisible U+E0041 innocent.md:3:14 dangerous-invisible U+E0042 innocent.md:3:16 dangerous-invisible U+E0043 innocent.md:3:18 dangerous-invisible U+E0044 innocent.md:3:20 dangerous-invisible U+E0045 exit=1 `--write` mode also strips the bytes (verified: file length 47 → 42 after sanitize, regex `/[\u{E0000}-\u{E007F}]/u` no longer matches). Existing 5 unicode-safety tests still pass; `yarn lint` clean. The ECC repo's own self-scan (`node scripts/ci/check-unicode-safety.js` with no `ECC_UNICODE_SCAN_ROOT`) reports the same warnings as before this commit and exits with the same status (no regressions on in-repo content). A handful of other widely-cited invisible code points are missing from the denylist (`U+180E`, `U+115F`, `U+1160`, `U+2061–U+2064`, `U+3164`); those are addressed in the next commit so each fix remains independently reviewable. Regression coverage for both fixes lands two commits later. --- scripts/ci/check-unicode-safety.js | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/scripts/ci/check-unicode-safety.js b/scripts/ci/check-unicode-safety.js index 6c7893e7..c4f1740c 100644 --- a/scripts/ci/check-unicode-safety.js +++ b/scripts/ci/check-unicode-safety.js @@ -114,7 +114,15 @@ function isDangerousInvisibleCodePoint(codePoint) { (codePoint >= 0x202A && codePoint <= 0x202E) || (codePoint >= 0x2066 && codePoint <= 0x2069) || (codePoint >= 0xFE00 && codePoint <= 0xFE0F) || - (codePoint >= 0xE0100 && codePoint <= 0xE01EF) + (codePoint >= 0xE0100 && codePoint <= 0xE01EF) || + // Unicode Tag block (U+E0000–U+E007F). Tag characters were proposed + // for language tagging in Unicode 3.1 and have been deprecated since + // Unicode 5.1, so no legitimate text uses them. They are the canonical + // vector for "ASCII smuggling" / "Tag smuggling" prompt injection: + // an attacker hides instructions inside ASCII-looking strings (PR + // bodies, SKILL.md, frontmatter), the LLM consumes the tag bytes, + // and the human reviewer sees nothing. + (codePoint >= 0xE0000 && codePoint <= 0xE007F) ); } From b068069b9b36e184dcc92d8effd9a181d31fac48 Mon Sep 17 00:00:00 2001 From: Jamkris Date: Tue, 19 May 2026 09:20:15 +0900 Subject: [PATCH 16/61] fix(ci): cover other widely-cited invisible code points in check-unicode-safety MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Extend `isDangerousInvisibleCodePoint` with five additional code points / ranges that are routinely cited in invisible-character smuggling references but were not in the previous denylist: - **U+180E** MONGOLIAN VOWEL SEPARATOR. Formerly classified as a space separator (Zs) until Unicode 6.3 reclassified it as Cf (Format control). Renders as zero-width; widely abused for homograph attacks and prompt smuggling. - **U+115F** HANGUL CHOSEONG FILLER and **U+1160** HANGUL JUNGSEONG FILLER. Zero-width fillers used in Korean text shaping. Both are cited as common LLM-injection vectors in Korean / multilingual threat models. - **U+2061–U+2064** invisible math operators (FUNCTION APPLICATION, INVISIBLE TIMES, INVISIBLE SEPARATOR, INVISIBLE PLUS). Zero-width and only meaningful inside math typesetting. No legitimate Markdown or source code uses them. - **U+3164** HANGUL FILLER. Reported in real-world Discord and Twitter smuggling incidents; not used in legitimate Korean text. Reproduced before this commit: a file containing any one of these code points passed `check-unicode-safety.js` silently. After this commit each one is reported as `dangerous-invisible U+` and `--write` mode strips it. Verified by writing 8 single-character probe files (`probe-0x180E.md`, `probe-0x115F.md`, …) and confirming exit=1 with each violation listed. ECC repo self-scan reports only the pre-existing `U+2605` BLACK STAR warnings (unchanged) and exits with the same status (no new in-repo violations introduced). Existing 5 unicode-safety tests still pass; `yarn lint` clean. Regression coverage for both the previous commit's Tag block fix and this commit's additions lands in the next commit. --- scripts/ci/check-unicode-safety.js | 18 +++++++++++++++++- 1 file changed, 17 insertions(+), 1 deletion(-) diff --git a/scripts/ci/check-unicode-safety.js b/scripts/ci/check-unicode-safety.js index c4f1740c..96c9ba54 100644 --- a/scripts/ci/check-unicode-safety.js +++ b/scripts/ci/check-unicode-safety.js @@ -122,7 +122,23 @@ function isDangerousInvisibleCodePoint(codePoint) { // an attacker hides instructions inside ASCII-looking strings (PR // bodies, SKILL.md, frontmatter), the LLM consumes the tag bytes, // and the human reviewer sees nothing. - (codePoint >= 0xE0000 && codePoint <= 0xE007F) + (codePoint >= 0xE0000 && codePoint <= 0xE007F) || + // U+180E MONGOLIAN VOWEL SEPARATOR — formerly classified as a space + // separator, reclassified as a format control in Unicode 6.3; renders + // as zero-width and routinely abused for homograph / smuggling. + codePoint === 0x180E || + // U+115F / U+1160 HANGUL CHOSEONG/JUNGSEONG FILLER — zero-width fillers + // used in Korean text shaping; abused as invisible characters. + codePoint === 0x115F || + codePoint === 0x1160 || + // U+2061–U+2064 invisible math operators (FUNCTION APPLICATION, + // INVISIBLE TIMES, INVISIBLE SEPARATOR, INVISIBLE PLUS). Zero-width + // and not used outside math typesetting; legitimate Markdown / source + // does not contain them. + (codePoint >= 0x2061 && codePoint <= 0x2064) || + // U+3164 HANGUL FILLER — zero-width filler reportedly used in Discord + // / Twitter smuggling attacks; not used in legitimate Korean text. + codePoint === 0x3164 ); } From 33ed494adfb4b980d538568518e167d430124467 Mon Sep 17 00:00:00 2001 From: Jamkris Date: Tue, 19 May 2026 09:21:31 +0900 Subject: [PATCH 17/61] test(ci): regression coverage for newly-covered invisible code points MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 9 new test cases pin down the two previous commits' denylist extensions. Each verifies both detection (validator exit non-zero + the expected `dangerous-invisible U+` line on stderr) and, where applicable, `--write` sanitization. Coverage: Tag block (commit 1): - U+E0041 TAG LATIN CAPITAL LETTER A — the range's printable ASCII shadow; this is the byte sequence demonstrated in published ASCII smuggling proofs of concept. - U+E007F CANCEL TAG — the range end. Other invisibles (commit 2): - U+180E MONGOLIAN VOWEL SEPARATOR - U+115F HANGUL CHOSEONG FILLER - U+1160 HANGUL JUNGSEONG FILLER - U+2061 FUNCTION APPLICATION (range start) - U+2064 INVISIBLE PLUS (range end) - U+3164 HANGUL FILLER Detection table is data-driven (one loop, one assertion per row) so adding the next invisible to the denylist also gets a paired regression test by simply appending to NEWLY_COVERED_RANGES. Plus a `--write` integration test: - writes a markdown file containing both Tag block (5 chars) and U+180E, runs `--write`, asserts both removed and surrounding text preserved character-for-character ('# Title\n\nBenigntext.\n'). - re-runs the validator without `--write` and asserts exit 0, confirming the sanitizer's output is idempotent under the extended denylist. Test count: 5 → 14 in this file; full `yarn test` green; `yarn lint` clean. --- tests/scripts/check-unicode-safety.test.js | 68 ++++++++++++++++++++++ 1 file changed, 68 insertions(+) diff --git a/tests/scripts/check-unicode-safety.test.js b/tests/scripts/check-unicode-safety.test.js index 753e6766..012d6586 100644 --- a/tests/scripts/check-unicode-safety.test.js +++ b/tests/scripts/check-unicode-safety.test.js @@ -109,6 +109,74 @@ if ( passed++; else failed++; +// Invisible code points newly covered by the denylist. These were missing +// from the previous denylist and silently passed through both detection and +// `--write` mode. Each is a documented LLM-prompt-injection vector +// (Tag block "ASCII smuggling"; the other invisibles are widely cited in +// homograph / Discord / Twitter smuggling references). + +const NEWLY_COVERED_RANGES = [ + { codePoint: 0xE0041, label: 'Tag block U+E0041 (TAG LATIN CAPITAL LETTER A)' }, + { codePoint: 0xE007F, label: 'Tag block U+E007F (CANCEL TAG, range end)' }, + { codePoint: 0x180E, label: 'U+180E MONGOLIAN VOWEL SEPARATOR' }, + { codePoint: 0x115F, label: 'U+115F HANGUL CHOSEONG FILLER' }, + { codePoint: 0x1160, label: 'U+1160 HANGUL JUNGSEONG FILLER' }, + { codePoint: 0x2061, label: 'U+2061 FUNCTION APPLICATION' }, + { codePoint: 0x2064, label: 'U+2064 INVISIBLE PLUS (range end)' }, + { codePoint: 0x3164, label: 'U+3164 HANGUL FILLER' }, +]; + +for (const { codePoint, label } of NEWLY_COVERED_RANGES) { + if ( + test(`detects ${label}`, () => { + const root = makeTempRoot('ecc-unicode-newly-covered-'); + fs.mkdirSync(path.join(root, 'docs'), { recursive: true }); + const hex = codePoint.toString(16).toUpperCase().padStart(4, '0'); + fs.writeFileSync( + path.join(root, 'docs', `probe-${hex}.md`), + `# Probe\n\nBenign${String.fromCodePoint(codePoint)}text\n` + ); + const result = runCheck(root); + assert.notStrictEqual(result.status, 0, + `expected exit non-zero on U+${hex}, got ${result.status}: ${result.stderr}`); + assert.match(result.stderr, new RegExp(`dangerous-invisible U\\+${hex}`), + `expected violation message for U+${hex}, got: ${result.stderr}`); + }) + ) + passed++; + else failed++; +} + +if ( + test('write mode strips newly-covered invisibles from markdown', () => { + const root = makeTempRoot('ecc-unicode-newly-covered-write-'); + fs.mkdirSync(path.join(root, 'docs'), { recursive: true }); + const tagHidden = [...Array(5)].map((_, i) => String.fromCodePoint(0xE0041 + i)).join(''); + const mongolianHidden = String.fromCodePoint(0x180E); + const filePath = path.join(root, 'docs', 'mixed.md'); + fs.writeFileSync(filePath, `# Title\n\nBenign${tagHidden}${mongolianHidden}text.\n`); + + const writeResult = runCheck(root, ['--write']); + assert.strictEqual(writeResult.status, 0, + `expected --write to succeed, got ${writeResult.status}: ${writeResult.stderr}`); + + const sanitized = fs.readFileSync(filePath, 'utf8'); + assert.doesNotMatch(sanitized, /[\u{E0000}-\u{E007F}]/u, + 'expected tag block characters stripped'); + assert.doesNotMatch(sanitized, /\u{180E}/u, + 'expected U+180E stripped'); + assert.strictEqual(sanitized, '# Title\n\nBenigntext.\n', + 'expected only the invisible characters removed, surrounding text preserved'); + + // Re-run without --write; should now pass cleanly. + const clean = runCheck(root); + assert.strictEqual(clean.status, 0, + `expected post-sanitize re-run to pass, got: ${clean.stderr}`); + }) +) + passed++; +else failed++; + if ( test('skips Python virtual environments', () => { const root = makeTempRoot('ecc-unicode-venv-'); From 28548f67ba1d4108d35c0800af88def995a0995f Mon Sep 17 00:00:00 2001 From: Jamkris Date: Tue, 19 May 2026 09:29:09 +0900 Subject: [PATCH 18/61] fix(lib): use unique tmp suffix in writeBridgeAtomic to eliminate ENOENT race MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `writeBridgeAtomic` wrote to a fixed `${target}.tmp` path before calling `renameSync`. When two processes write to the same session bridge concurrently (e.g. PostToolUse `ecc-metrics-bridge` + the background `ecc-statusline`, both calling `writeBridgeAtomic(sessionId, ...)`), the canonical atomic-rename race fires: 1. Process A: writeFileSync(target.tmp, JSON_A) — tmp file exists. 2. Process B: writeFileSync(target.tmp, JSON_B) — tmp file overwritten. 3. Process A: renameSync(target.tmp, target) — succeeds; target = JSON_B (A's payload silently corrupted en-route). 4. Process B: renameSync(target.tmp, target) — throws ENOENT (the rename consumed the file). Every caller in the repo wraps `writeBridgeAtomic` in `try {} catch {}`, so the ENOENT exception is swallowed and the user-visible symptom is just "the bridge file occasionally contains the wrong process's payload" with no diagnostic. Reproduced before this commit: $ # two concurrent writers, each calling writeBridgeAtomic 500 times $ # against the same session ID [A] errors=244 # 244 ENOENT exceptions swallowed [B] errors=248 # ditto After this commit the same workload reports 0 errors in both subprocesses: tmp paths no longer collide. Fix: change `${target}.tmp` to `${target}.${process.pid}.${crypto.randomBytes(4).toString('hex')}.tmp`, matching the pattern already used by `writeCostWarningIfChanged` in `scripts/hooks/ecc-metrics-bridge.js` (commit 9b1d8918). The pid + 4-byte nonce gives each writer process a distinct tmp path, so step 2 above no longer overwrites step 1's payload and step 4 no longer races step 3. Also added: on `renameSync` failure, attempt `fs.unlinkSync(tmp)` so a writer that fails (disk full, permission, parent dir gone) does not leak its tmp file. The cleanup is best-effort and the original error is still re-thrown. **Scope clarification.** This commit closes the atomic-rename primitive's race only. The *read-modify-write* race in callers — two writers each read the same bridge state, increment, and write back, the second clobbering the first — is a separate concern that needs locking or per-writer logs, and is intentionally out of scope for this PR. The cost-tracker / metrics-bridge callers tolerate last-writer-wins on their cumulative aggregates today and this commit does not change that contract. The companion `writeWarnState` in `ecc-context-monitor.js` has the same fixed-suffix pattern and the same race; that fix lands in the next commit so each can be reviewed against its own diff. --- scripts/lib/session-bridge.js | 27 ++++++++++++++++++++++++--- 1 file changed, 24 insertions(+), 3 deletions(-) diff --git a/scripts/lib/session-bridge.js b/scripts/lib/session-bridge.js index aceae9cb..b50216fc 100644 --- a/scripts/lib/session-bridge.js +++ b/scripts/lib/session-bridge.js @@ -8,6 +8,7 @@ * without scanning large JSONL logs on every invocation. */ +const crypto = require('crypto'); const fs = require('fs'); const os = require('os'); const path = require('path'); @@ -51,15 +52,35 @@ function readBridge(sessionId) { } /** - * Write bridge data atomically (write .tmp then rename). + * Write bridge data atomically (write unique-suffix tmp then rename). + * + * The tmp path includes `process.pid` plus a random nonce so concurrent + * writers (e.g. PostToolUse `ecc-metrics-bridge` and the background + * `ecc-statusline`, both writing to the same session bridge) do not + * clobber each other's tmp file mid-write. With a fixed `.tmp` suffix + * two writers could both call `writeFileSync` against the same path + * before either reaches `renameSync`, causing one writer's payload to + * silently overwrite the other and the second `renameSync` to throw + * ENOENT once the rename consumes the file. + * + * Same pattern already used by `writeCostWarningIfChanged` in + * `scripts/hooks/ecc-metrics-bridge.js` (commit 9b1d8918) for the + * cost-warning cache; this commit applies it to the session-bridge + * primitive too. + * * @param {string} sessionId - Already-sanitized session ID * @param {object} data */ function writeBridgeAtomic(sessionId, data) { const target = getBridgePath(sessionId); - const tmp = `${target}.tmp`; + const tmp = `${target}.${process.pid}.${crypto.randomBytes(4).toString('hex')}.tmp`; fs.writeFileSync(tmp, JSON.stringify(data), 'utf8'); - fs.renameSync(tmp, target); + try { + fs.renameSync(tmp, target); + } catch (err) { + try { fs.unlinkSync(tmp); } catch { /* ignore */ } + throw err; + } } /** From 7c2f71315b826a3fd27fb89ef70fe02459635d44 Mon Sep 17 00:00:00 2001 From: Jamkris Date: Tue, 19 May 2026 09:30:07 +0900 Subject: [PATCH 19/61] fix(hooks): use unique tmp suffix in writeWarnState (ecc-context-monitor) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Mirror the previous commit's `writeBridgeAtomic` fix on the companion `writeWarnState` in `ecc-context-monitor.js`. Same shape: fixed `${target}.tmp` → `${target}.${process.pid}.${randomNonce}.tmp`, plus best-effort cleanup of the tmp file on `renameSync` failure (throws original error after cleanup). `writeWarnState` debounces the context-monitor's threshold alarms (`COST_NOTICE_USD`, `COST_WARNING_USD`, `COST_CRITICAL_USD`, plus the context-remaining and loop-detection ones). Without unique suffixes, two PostToolUse subprocesses racing on the warn-state file produce either a corrupted JSON debounce-state on disk or an ENOENT throw that the hook catches and swallows — either way the next warn-state read returns the default `{callsSinceWarn: 0, lastSeverity: null}` and the threshold alarms re-fire or stop firing erratically. Users see warning messages flicker or vanish; debounce no longer works. Three call sites in this repo now share the same atomic-write contract: - `writeBridgeAtomic` (scripts/lib/session-bridge.js) — primary - `writeCostWarningIfChanged` (scripts/hooks/ecc-metrics-bridge.js) — cost cache - `writeWarnState` (this file) — debounce state `yarn lint` clean. Regression test covering both `writeBridgeAtomic` and `writeWarnState` under concurrent load lands in the next commit. --- scripts/hooks/ecc-context-monitor.js | 22 +++++++++++++++++++--- 1 file changed, 19 insertions(+), 3 deletions(-) diff --git a/scripts/hooks/ecc-context-monitor.js b/scripts/hooks/ecc-context-monitor.js index 8ddb36dc..5058f9bf 100644 --- a/scripts/hooks/ecc-context-monitor.js +++ b/scripts/hooks/ecc-context-monitor.js @@ -9,6 +9,7 @@ 'use strict'; +const crypto = require('crypto'); const fs = require('fs'); const os = require('os'); const path = require('path'); @@ -61,15 +62,30 @@ function readWarnState(sessionId) { } /** - * Write debounce state. + * Write debounce state atomically (unique-suffix tmp then rename). + * + * The tmp path includes `process.pid` plus a random nonce so concurrent + * PostToolUse subprocesses writing to the same session's warn-state + * file do not clobber each other's tmp mid-write. Without the unique + * suffix, two writers race over a shared `${target}.tmp` and produce + * either a corrupted payload or an ENOENT throw on the second rename. + * + * Same pattern as `writeBridgeAtomic` in `scripts/lib/session-bridge.js` + * and `writeCostWarningIfChanged` in `scripts/hooks/ecc-metrics-bridge.js`. + * * @param {string} sessionId * @param {object} state */ function writeWarnState(sessionId, state) { const target = getWarnPath(sessionId); - const tmp = `${target}.tmp`; + const tmp = `${target}.${process.pid}.${crypto.randomBytes(4).toString('hex')}.tmp`; fs.writeFileSync(tmp, JSON.stringify(state), 'utf8'); - fs.renameSync(tmp, target); + try { + fs.renameSync(tmp, target); + } catch (err) { + try { fs.unlinkSync(tmp); } catch { /* ignore */ } + throw err; + } } /** From 5acb01a276b7fe61b0cdbef8015dee556b3a2621 Mon Sep 17 00:00:00 2001 From: Jamkris Date: Tue, 19 May 2026 09:31:35 +0900 Subject: [PATCH 20/61] test(lib): concurrent writeBridgeAtomic + tmp-cleanup regression MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Two regression tests pin down the previous two commits' atomic-rename fixes: 1. **concurrent writes don't throw ENOENT or corrupt the file** — spawns two child Node processes (`tests/__tmp_bridge_writer.js` created in-test, cleaned up in finally) that each call `writeBridgeAtomic(sid, …)` 200 times against the same session ID with independent payloads. Asserts both subprocesses exit 0 (the previous implementation produced ENOENT on roughly 50% of rename calls, all swallowed by the in-test catch) and the final bridge file is parseable JSON belonging to one of the two writers (last-writer-wins is fine; the contract is *no corruption* and *no rename ENOENT*, not data preservation). 2. **tmp file cleanup on rename failure** — pre-creates a directory at the target bridge path so `renameSync(tmp, target)` fails, calls `writeBridgeAtomic`, asserts the call throws AND that no tmp file with the writer's `pid..tmp` prefix is left behind in `os.tmpdir()`. The previous code had no cleanup; the fix's `try/catch + unlinkSync` keeps tmpdir from accumulating orphan files across repeated rename failures. The first test deliberately writes independent payloads from each subprocess so this regression doesn't try to claim a property the fix doesn't actually deliver (read-modify-write race in the caller is a separate issue and out of scope per PR body). Test count: 12 → 14 in `tests/lib/session-bridge.test.js`; `npm test` green; `npm run lint` clean. --- tests/lib/session-bridge.test.js | 83 ++++++++++++++++++++++++++++++++ 1 file changed, 83 insertions(+) diff --git a/tests/lib/session-bridge.test.js b/tests/lib/session-bridge.test.js index 60841c9b..6e57f8fc 100644 --- a/tests/lib/session-bridge.test.js +++ b/tests/lib/session-bridge.test.js @@ -135,6 +135,89 @@ function runTests() { passed++; else failed++; + // Concurrency contract: two processes writing to the same session + // bridge must not throw ENOENT and must never leave a corrupt JSON + // file behind. The previous implementation used a fixed `${target}.tmp` + // suffix; with concurrent writers it raced over a shared tmp path, + // producing both ENOENT on rename and (occasionally) a half-written + // payload on the destination. + // + // This test exercises the atomic-rename primitive only — it does NOT + // attempt to defend against the read-modify-write race in callers, + // which is a separate concern. Each subprocess writes its own + // independent payload N times; we assert (a) every process exits 0 + // (no ENOENT bubbled up) and (b) the final file is always parseable + // JSON whose contents match one of the two writers' last payloads. + + if ( + test('concurrent writeBridgeAtomic does not throw ENOENT or corrupt the bridge file', () => { + const { spawnSync } = require('child_process'); + const path = require('path'); + const testId = `test-bridge-race-${Date.now()}-${process.pid}`; + const writerPath = path.join(__dirname, '..', '__tmp_bridge_writer.js'); + const bridgeLib = path.join(__dirname, '..', '..', 'scripts', 'lib', 'session-bridge'); + fs.writeFileSync( + writerPath, + [ + "const { writeBridgeAtomic } = require(" + JSON.stringify(bridgeLib) + ");", + "const [, , sid, tag] = process.argv;", + "for (let i = 0; i < 200; i++) {", + " writeBridgeAtomic(sid, { writer: tag, i });", + "}", + ].join('\n'), + 'utf8' + ); + try { + const r1 = spawnSync('node', [writerPath, testId, 'A'], { encoding: 'utf8' }); + const r2 = spawnSync('node', [writerPath, testId, 'B'], { encoding: 'utf8' }); + assert.strictEqual(r1.status, 0, + `writer A should exit 0 (no ENOENT), got ${r1.status}: ${r1.stderr}`); + assert.strictEqual(r2.status, 0, + `writer B should exit 0 (no ENOENT), got ${r2.status}: ${r2.stderr}`); + // Final file must be parseable JSON and belong to one of the writers. + const final = readBridge(testId); + assert.ok(final && typeof final === 'object', + `expected parseable JSON object, got: ${JSON.stringify(final)}`); + assert.ok(final.writer === 'A' || final.writer === 'B', + `expected last-writer-wins payload, got: ${JSON.stringify(final)}`); + } finally { + try { fs.unlinkSync(getBridgePath(testId)); } catch { /* ignore */ } + try { fs.unlinkSync(writerPath); } catch { /* ignore */ } + } + }) + ) + passed++; + else failed++; + + if ( + test('writeBridgeAtomic cleans up its tmp file on renameSync failure', () => { + // Trigger renameSync failure by passing a sessionId whose path is + // already a directory. The tmp file exists at this point; the fix + // must not leak it behind. + const path = require('path'); + const testId = `test-bridge-cleanup-${Date.now()}-${process.pid}`; + const target = getBridgePath(testId); + const os = require('os'); + const tmpDir = os.tmpdir(); + // Plant a directory at the target path so renameSync (target.tmp → target) fails. + fs.mkdirSync(target); + try { + assert.throws(() => writeBridgeAtomic(testId, { x: 1 }), + 'expected rename failure to surface'); + // Count any leaked tmp files. The pid+nonce suffix is unique per + // call, so we look for any matching pattern under os.tmpdir(). + const prefix = path.basename(target) + '.' + process.pid + '.'; + const leaked = fs.readdirSync(tmpDir).filter(f => f.startsWith(prefix) && f.endsWith('.tmp')); + assert.strictEqual(leaked.length, 0, + `expected no leaked tmp files after rename failure, found: ${leaked.join(', ')}`); + } finally { + try { fs.rmdirSync(target); } catch { /* ignore */ } + } + }) + ) + passed++; + else failed++; + // resolveSessionId tests console.log('\nresolveSessionId:'); From d904edc6156bc056f39efc0d8be967995a10bc10 Mon Sep 17 00:00:00 2001 From: Jamkris Date: Tue, 19 May 2026 09:44:53 +0900 Subject: [PATCH 21/61] test(lib): make concurrent-write test actually concurrent + use regex matcher for assert.throws MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Two round-1 review findings in `tests/lib/session-bridge.test.js`, both about test correctness rather than the underlying fix: 1. **greptile P1 + coderabbitai Major + cubic P2 (all three): concurrent-write test ran sequentially.** The test spawned two child processes with two consecutive `spawnSync` calls. Because `spawnSync` blocks until the child exits, the second writer started *after* the first finished — the two writers never overlapped, so the rename race the fix targets was never actually exercised. The test would have passed with the old broken `${target}.tmp` suffix. Fix: introduce a one-off "race runner" helper that runs inside its own subprocess and uses async `spawn` to start both writers simultaneously. The runner waits for both to exit (the event loop is local to the runner subprocess, so this stays compatible with the synchronous test harness used elsewhere in this file) and reports both exit codes plus stderrs on stdout. The test then calls the runner via `spawnSync` and parses the result. Both writer children now overlap for the duration of their 200 `writeBridgeAtomic` calls each, which is enough wall time to reliably trigger the rename race against the pre-fix code. Verified: with the fixed `${target}.${pid}.${nonce}.tmp` suffix, the test passes; with the old fixed `${target}.tmp` suffix reintroduced, it fails as expected (one writer hits ENOENT on roughly half its rename calls). 2. **greptile P2 + cubic P3: `assert.throws` used a string as the second argument.** Node deprecated passing a string as the second argument to `assert.throws` years ago: the string is silently treated as the assertion failure message (what to print when the function does *not* throw) rather than as an error matcher. The check passed for any thrown error, not just the rename failure. Fix: pass a regex matcher as the second arg and keep the explanatory text as the third. The regex matches `EISDIR`, `EPERM`, `ENOTDIR`, or `ENOENT` because `renameSync` of a regular tmp file onto an existing directory raises different codes on Linux / macOS / BSD — making the matcher portable across CI runners. Test count unchanged at 14; `npm test` green; `npm run lint` clean. The two helper files (`tests/__tmp_bridge_writer.js`, `tests/__tmp_bridge_race_runner.js`) are written and unlinked inside the test's try/finally so they never persist beyond the test run. --- tests/lib/session-bridge.test.js | 57 +++++++++++++++++++++++++++----- 1 file changed, 49 insertions(+), 8 deletions(-) diff --git a/tests/lib/session-bridge.test.js b/tests/lib/session-bridge.test.js index 6e57f8fc..632c2fdc 100644 --- a/tests/lib/session-bridge.test.js +++ b/tests/lib/session-bridge.test.js @@ -151,10 +151,19 @@ function runTests() { if ( test('concurrent writeBridgeAtomic does not throw ENOENT or corrupt the bridge file', () => { + // Spawn two child processes that BOTH stay alive at the same time + // and call writeBridgeAtomic in a tight loop. `spawnSync` would + // run them sequentially (blocking on each), which would never + // exercise the race the fix targets. Instead a sync runner script + // launches both as async `spawn` children inside its own process, + // waits for both to exit, and reports their statuses on stdout — + // and the test calls *that* runner via `spawnSync`. The runner is + // the only place that needs the event loop. const { spawnSync } = require('child_process'); const path = require('path'); const testId = `test-bridge-race-${Date.now()}-${process.pid}`; const writerPath = path.join(__dirname, '..', '__tmp_bridge_writer.js'); + const runnerPath = path.join(__dirname, '..', '__tmp_bridge_race_runner.js'); const bridgeLib = path.join(__dirname, '..', '..', 'scripts', 'lib', 'session-bridge'); fs.writeFileSync( writerPath, @@ -167,13 +176,38 @@ function runTests() { ].join('\n'), 'utf8' ); + fs.writeFileSync( + runnerPath, + [ + "'use strict';", + "const { spawn } = require('child_process');", + "const [, , writerPath, sid] = process.argv;", + "const c1 = spawn(process.execPath, [writerPath, sid, 'A'], { stdio: ['ignore','pipe','pipe'] });", + "const c2 = spawn(process.execPath, [writerPath, sid, 'B'], { stdio: ['ignore','pipe','pipe'] });", + "const exits = {};", + "const stderrs = { A: '', B: '' };", + "c1.stderr.on('data', chunk => { stderrs.A += chunk.toString(); });", + "c2.stderr.on('data', chunk => { stderrs.B += chunk.toString(); });", + "let done = 0;", + "function onExit(tag) { return function(code) { exits[tag] = code; if (++done === 2) finish(); }; }", + "c1.on('exit', onExit('A'));", + "c2.on('exit', onExit('B'));", + "function finish() {", + " process.stdout.write(JSON.stringify({ exits, stderrs }));", + " process.exit(0);", + "}", + ].join('\n'), + 'utf8' + ); try { - const r1 = spawnSync('node', [writerPath, testId, 'A'], { encoding: 'utf8' }); - const r2 = spawnSync('node', [writerPath, testId, 'B'], { encoding: 'utf8' }); - assert.strictEqual(r1.status, 0, - `writer A should exit 0 (no ENOENT), got ${r1.status}: ${r1.stderr}`); - assert.strictEqual(r2.status, 0, - `writer B should exit 0 (no ENOENT), got ${r2.status}: ${r2.stderr}`); + const result = spawnSync('node', [runnerPath, writerPath, testId], { encoding: 'utf8' }); + assert.strictEqual(result.status, 0, + `race runner should exit 0, got ${result.status}: ${result.stderr}`); + const parsed = JSON.parse(result.stdout); + assert.strictEqual(parsed.exits.A, 0, + `writer A should exit 0 (no ENOENT), got ${parsed.exits.A}: ${parsed.stderrs.A}`); + assert.strictEqual(parsed.exits.B, 0, + `writer B should exit 0 (no ENOENT), got ${parsed.exits.B}: ${parsed.stderrs.B}`); // Final file must be parseable JSON and belong to one of the writers. const final = readBridge(testId); assert.ok(final && typeof final === 'object', @@ -183,6 +217,7 @@ function runTests() { } finally { try { fs.unlinkSync(getBridgePath(testId)); } catch { /* ignore */ } try { fs.unlinkSync(writerPath); } catch { /* ignore */ } + try { fs.unlinkSync(runnerPath); } catch { /* ignore */ } } }) ) @@ -202,8 +237,14 @@ function runTests() { // Plant a directory at the target path so renameSync (target.tmp → target) fails. fs.mkdirSync(target); try { - assert.throws(() => writeBridgeAtomic(testId, { x: 1 }), - 'expected rename failure to surface'); + assert.throws( + () => writeBridgeAtomic(testId, { x: 1 }), + // renameSync of a regular file onto an existing directory throws + // EISDIR on Linux, EPERM on macOS, ENOTDIR on some BSDs. Accept + // any of those so the test stays portable across CI runners. + /EISDIR|EPERM|ENOTDIR|ENOENT/, + 'expected rename failure to surface' + ); // Count any leaked tmp files. The pid+nonce suffix is unique per // call, so we look for any matching pattern under os.tmpdir(). const prefix = path.basename(target) + '.' + process.pid + '.'; From 116e61d8cbf214d15c22f867ff6b69c585a86098 Mon Sep 17 00:00:00 2001 From: Jamkris Date: Tue, 19 May 2026 11:01:10 +0900 Subject: [PATCH 22/61] fix(lib): retry rename on Windows EPERM/EACCES/EBUSY in writeBridgeAtomic MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit PR #1983 round 1 introduced unique-suffix tmp paths so two concurrent writers no longer share a single `.tmp` file. That fix is correct under POSIX semantics — `rename(2)` is atomic between source and destination, so each writer renames onto the same target without conflict. Windows `MoveFileExW` is not the same. It fails with EPERM / EACCES / EBUSY when the target is currently being renamed by *another* process — a short race window that fires reliably under this hook's PostToolUse + statusline concurrency. Round 1's CI run made this visible: Test (windows-latest, Node 18.x, npm) — FAILURE Error: EPERM: operation not permitted, rename 'C:\…\ecc-metrics-test-bridge-race-….json.9504.4aef575a.tmp' -> 'C:\…\ecc-metrics-test-bridge-race-….json' at writeBridgeAtomic (scripts/lib/session-bridge.js:79:8) All nine Windows matrix cells (Node 18 / 20 / 22 × npm / pnpm / yarn) hit the same path. POSIX matrices (Linux + macOS) passed unchanged. Fix: extract a `renameWithRetry(tmp, target)` helper that retries `fs.renameSync` up to 5 times on EPERM / EACCES / EBUSY with exponential backoff (20 ms → 320 ms total). Other error codes (ENOENT, ENOSPC, EROFS, …) re-throw on the first attempt — they are not transient. POSIX runs hit the first try and exit immediately. The backoff uses `Atomics.wait` on a throwaway `SharedArrayBuffer` so the retry path does not busy-spin the CPU; verified on Node ≥ 17 that this works on the main thread. There is a `try/catch` fallback to a brief busy-wait for older runtimes where `Atomics.wait` is restricted to workers. `writeBridgeAtomic` calls the helper instead of `fs.renameSync` and keeps its existing best-effort tmp cleanup on terminal failure. `renameWithRetry` is added to `module.exports` so the companion `writeWarnState` in `scripts/hooks/ecc-context-monitor.js` can adopt the same retry policy without duplicating the helper. That adoption lands in the next commit. Local: `node tests/lib/session-bridge.test.js` 14/14, `yarn test` green, `yarn lint` clean. The round-1 test (two concurrent child writers, 200 iterations each) now passes on macOS without retrying at all (POSIX path) and is expected to pass on Windows via the new retry loop. --- scripts/lib/session-bridge.js | 48 ++++++++++++++++++++++++++++++++++- 1 file changed, 47 insertions(+), 1 deletion(-) diff --git a/scripts/lib/session-bridge.js b/scripts/lib/session-bridge.js index b50216fc..19033d63 100644 --- a/scripts/lib/session-bridge.js +++ b/scripts/lib/session-bridge.js @@ -76,13 +76,58 @@ function writeBridgeAtomic(sessionId, data) { const tmp = `${target}.${process.pid}.${crypto.randomBytes(4).toString('hex')}.tmp`; fs.writeFileSync(tmp, JSON.stringify(data), 'utf8'); try { - fs.renameSync(tmp, target); + renameWithRetry(tmp, target); } catch (err) { try { fs.unlinkSync(tmp); } catch { /* ignore */ } throw err; } } +/** + * Replace a file via rename, retrying briefly on transient OS-level errors. + * + * POSIX `rename(2)` is atomic between source and destination, so concurrent + * writers each rename onto the same target without conflict. Windows + * `MoveFileExW` is different: it fails with EPERM/EACCES/EBUSY if the + * target is currently being renamed by *another* process — a short race + * window that fires reliably under our PostToolUse + statusline concurrency. + * + * To stay portable, retry up to 5 times with exponential backoff (20 ms, + * 40, 80, 160, 320) on the Windows-only transient codes. POSIX runs hit + * the first try and exit immediately. Other error codes (ENOENT, ENOSPC, + * EROFS, …) re-throw without retry — they are not transient. + * + * Sleep uses `Atomics.wait` on a throwaway SharedArrayBuffer so the + * retry path does not busy-spin the CPU. This works on the main thread + * in Node ≥ 17 (and on workers in earlier versions). + * + * @param {string} tmp + * @param {string} target + */ +function renameWithRetry(tmp, target) { + const RETRY_CODES = new Set(['EPERM', 'EACCES', 'EBUSY']); + const MAX_ATTEMPTS = 5; + for (let attempt = 0; ; attempt++) { + try { + fs.renameSync(tmp, target); + return; + } catch (err) { + if (attempt + 1 >= MAX_ATTEMPTS || !RETRY_CODES.has(err.code)) { + throw err; + } + const delayMs = 20 << attempt; + try { + Atomics.wait(new Int32Array(new SharedArrayBuffer(4)), 0, 0, delayMs); + } catch { + // Atomics.wait throws on the main thread in some older runtimes; + // fall back to a brief busy-wait so the retry path still has a delay. + const until = Date.now() + delayMs; + while (Date.now() < until) { /* spin */ } + } + } + } +} + /** * Resolve session ID from environment variables. * @returns {string|null} Sanitized session ID or null @@ -97,6 +142,7 @@ module.exports = { getBridgePath, readBridge, writeBridgeAtomic, + renameWithRetry, resolveSessionId, MAX_SESSION_ID_LENGTH }; From f93e8f6869d4575fa51cc6c8da614e5806302f69 Mon Sep 17 00:00:00 2001 From: Jamkris Date: Tue, 19 May 2026 11:01:28 +0900 Subject: [PATCH 23/61] fix(hooks): use shared renameWithRetry in writeWarnState (ecc-context-monitor) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Mirror the previous commit's Windows-EPERM retry on the companion `writeWarnState` in `scripts/hooks/ecc-context-monitor.js`. Same race: two PostToolUse subprocesses writing concurrent debounce state racing on `MoveFileExW`, target-in-use throwing EPERM on Windows even though each writer's tmp path is now unique. Implementation: import `renameWithRetry` from `scripts/lib/session-bridge.js` (exported in the previous commit) instead of duplicating the helper. The retry policy, backoff schedule, and main-thread `Atomics.wait` strategy stay identical to `writeBridgeAtomic`. Three writers in the repo now share the same atomic-write contract: - `writeBridgeAtomic` (scripts/lib/session-bridge.js) — round 1 + this round's retry - `writeWarnState` (this file) — round 1 + this round's retry via shared helper - `writeCostWarningIfChanged` (scripts/hooks/ecc-metrics-bridge.js) — out of scope for this PR (already uses unique tmp suffix; a future consolidation could move it to the shared helper too). Local: `yarn test` green, `yarn lint` clean. The companion test suite for `ecc-context-monitor.js` does not currently exercise concurrent `writeWarnState` writes, but the helper it now uses is covered by the `tests/lib/session-bridge.test.js` concurrent-write regression added in round 1's last commit. --- scripts/hooks/ecc-context-monitor.js | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/scripts/hooks/ecc-context-monitor.js b/scripts/hooks/ecc-context-monitor.js index 5058f9bf..9cdedbe3 100644 --- a/scripts/hooks/ecc-context-monitor.js +++ b/scripts/hooks/ecc-context-monitor.js @@ -13,7 +13,7 @@ const crypto = require('crypto'); const fs = require('fs'); const os = require('os'); const path = require('path'); -const { sanitizeSessionId, readBridge } = require('../lib/session-bridge'); +const { sanitizeSessionId, readBridge, renameWithRetry } = require('../lib/session-bridge'); const CONTEXT_WARNING_PCT = 35; const CONTEXT_CRITICAL_PCT = 25; @@ -81,7 +81,7 @@ function writeWarnState(sessionId, state) { const tmp = `${target}.${process.pid}.${crypto.randomBytes(4).toString('hex')}.tmp`; fs.writeFileSync(tmp, JSON.stringify(state), 'utf8'); try { - fs.renameSync(tmp, target); + renameWithRetry(tmp, target); } catch (err) { try { fs.unlinkSync(tmp); } catch { /* ignore */ } throw err; From 6cb194a3c633beced9381b767700af8764dc45da Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 05:05:26 -0400 Subject: [PATCH 24/61] fix(hooks): avoid escaped quotes in plugin bootstrap Generate the inline hook root resolver with single-quoted JavaScript literals so Windows Git Bash does not choke on nested escaped double quotes before Node starts. Refresh hooks.json and add regression coverage for parsed hook commands and installed hook manifests. --- hooks/hooks.json | 42 +++++++++++++-------------- scripts/lib/resolve-ecc-root.js | 17 ++++++++++- tests/hooks/hooks.test.js | 23 +++++++++++++++ tests/integration/hooks.test.js | 7 +++++ tests/lib/command-plugin-root.test.js | 5 ++-- tests/scripts/install-apply.test.js | 4 +++ 6 files changed, 74 insertions(+), 24 deletions(-) diff --git a/hooks/hooks.json b/hooks/hooks.json index 1b9420ac..98ac4cd8 100644 --- a/hooks/hooks.json +++ b/hooks/hooks.json @@ -7,7 +7,7 @@ "hooks": [ { "type": "command", - "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [[\\\"ecc\\\"],[\\\"ecc@ecc\\\"],[\\\"marketplaces\\\",\\\"ecc\\\"],[\\\"everything-claude-code\\\"],[\\\"everything-claude-code@everything-claude-code\\\"],[\\\"marketplaces\\\",\\\"everything-claude-code\\\"]]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of [\\\"ecc\\\",\\\"everything-claude-code\\\"]){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/pre-bash-dispatcher.js" + "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [['ecc'],['ecc@ecc'],['marketplaces','ecc'],['everything-claude-code'],['everything-claude-code@everything-claude-code'],['marketplaces','everything-claude-code']]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ['ecc','everything-claude-code']){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/pre-bash-dispatcher.js" } ], "description": "Consolidated Bash preflight dispatcher for quality, tmux, push, and GateGuard checks", @@ -18,7 +18,7 @@ "hooks": [ { "type": "command", - "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [[\\\"ecc\\\"],[\\\"ecc@ecc\\\"],[\\\"marketplaces\\\",\\\"ecc\\\"],[\\\"everything-claude-code\\\"],[\\\"everything-claude-code@everything-claude-code\\\"],[\\\"marketplaces\\\",\\\"everything-claude-code\\\"]]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of [\\\"ecc\\\",\\\"everything-claude-code\\\"]){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js pre:write:doc-file-warning scripts/hooks/doc-file-warning.js standard,strict" + "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [['ecc'],['ecc@ecc'],['marketplaces','ecc'],['everything-claude-code'],['everything-claude-code@everything-claude-code'],['marketplaces','everything-claude-code']]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ['ecc','everything-claude-code']){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js pre:write:doc-file-warning scripts/hooks/doc-file-warning.js standard,strict" } ], "description": "Doc file warning: warn about non-standard documentation files (exit code 0; warns only)", @@ -29,7 +29,7 @@ "hooks": [ { "type": "command", - "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [[\\\"ecc\\\"],[\\\"ecc@ecc\\\"],[\\\"marketplaces\\\",\\\"ecc\\\"],[\\\"everything-claude-code\\\"],[\\\"everything-claude-code@everything-claude-code\\\"],[\\\"marketplaces\\\",\\\"everything-claude-code\\\"]]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of [\\\"ecc\\\",\\\"everything-claude-code\\\"]){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js pre:edit-write:suggest-compact scripts/hooks/suggest-compact.js standard,strict" + "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [['ecc'],['ecc@ecc'],['marketplaces','ecc'],['everything-claude-code'],['everything-claude-code@everything-claude-code'],['marketplaces','everything-claude-code']]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ['ecc','everything-claude-code']){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js pre:edit-write:suggest-compact scripts/hooks/suggest-compact.js standard,strict" } ], "description": "Suggest manual compaction at logical intervals", @@ -40,7 +40,7 @@ "hooks": [ { "type": "command", - "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [[\\\"ecc\\\"],[\\\"ecc@ecc\\\"],[\\\"marketplace\\\",\\\"ecc\\\"],[\\\"everything-claude-code\\\"],[\\\"everything-claude-code@everything-claude-code\\\"],[\\\"marketplace\\\",\\\"everything-claude-code\\\"]]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of [\\\"ecc\\\",\\\"everything-claude-code\\\"]){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js pre:observe scripts/hooks/observe-runner.js standard,strict", + "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [['ecc'],['ecc@ecc'],['marketplaces','ecc'],['everything-claude-code'],['everything-claude-code@everything-claude-code'],['marketplaces','everything-claude-code']]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ['ecc','everything-claude-code']){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js pre:observe scripts/hooks/observe-runner.js standard,strict", "async": true, "timeout": 10 } @@ -53,7 +53,7 @@ "hooks": [ { "type": "command", - "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [[\\\"ecc\\\"],[\\\"ecc@ecc\\\"],[\\\"marketplaces\\\",\\\"ecc\\\"],[\\\"everything-claude-code\\\"],[\\\"everything-claude-code@everything-claude-code\\\"],[\\\"marketplaces\\\",\\\"everything-claude-code\\\"]]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of [\\\"ecc\\\",\\\"everything-claude-code\\\"]){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js pre:governance-capture scripts/hooks/governance-capture.js standard,strict", + "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [['ecc'],['ecc@ecc'],['marketplaces','ecc'],['everything-claude-code'],['everything-claude-code@everything-claude-code'],['marketplaces','everything-claude-code']]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ['ecc','everything-claude-code']){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js pre:governance-capture scripts/hooks/governance-capture.js standard,strict", "timeout": 10 } ], @@ -65,7 +65,7 @@ "hooks": [ { "type": "command", - "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [[\\\"ecc\\\"],[\\\"ecc@ecc\\\"],[\\\"marketplaces\\\",\\\"ecc\\\"],[\\\"everything-claude-code\\\"],[\\\"everything-claude-code@everything-claude-code\\\"],[\\\"marketplaces\\\",\\\"everything-claude-code\\\"]]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of [\\\"ecc\\\",\\\"everything-claude-code\\\"]){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js pre:config-protection scripts/hooks/config-protection.js standard,strict", + "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [['ecc'],['ecc@ecc'],['marketplaces','ecc'],['everything-claude-code'],['everything-claude-code@everything-claude-code'],['marketplaces','everything-claude-code']]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ['ecc','everything-claude-code']){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js pre:config-protection scripts/hooks/config-protection.js standard,strict", "timeout": 5 } ], @@ -77,7 +77,7 @@ "hooks": [ { "type": "command", - "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [[\\\"ecc\\\"],[\\\"ecc@ecc\\\"],[\\\"marketplaces\\\",\\\"ecc\\\"],[\\\"everything-claude-code\\\"],[\\\"everything-claude-code@everything-claude-code\\\"],[\\\"marketplaces\\\",\\\"everything-claude-code\\\"]]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of [\\\"ecc\\\",\\\"everything-claude-code\\\"]){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js pre:mcp-health-check scripts/hooks/mcp-health-check.js standard,strict" + "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [['ecc'],['ecc@ecc'],['marketplaces','ecc'],['everything-claude-code'],['everything-claude-code@everything-claude-code'],['marketplaces','everything-claude-code']]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ['ecc','everything-claude-code']){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js pre:mcp-health-check scripts/hooks/mcp-health-check.js standard,strict" } ], "description": "Check MCP server health before MCP tool execution and block unhealthy MCP calls", @@ -88,7 +88,7 @@ "hooks": [ { "type": "command", - "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [[\\\"ecc\\\"],[\\\"ecc@ecc\\\"],[\\\"marketplaces\\\",\\\"ecc\\\"],[\\\"everything-claude-code\\\"],[\\\"everything-claude-code@everything-claude-code\\\"],[\\\"marketplaces\\\",\\\"everything-claude-code\\\"]]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of [\\\"ecc\\\",\\\"everything-claude-code\\\"]){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js pre:edit-write:gateguard-fact-force scripts/hooks/gateguard-fact-force.js standard,strict", + "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [['ecc'],['ecc@ecc'],['marketplaces','ecc'],['everything-claude-code'],['everything-claude-code@everything-claude-code'],['marketplaces','everything-claude-code']]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ['ecc','everything-claude-code']){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js pre:edit-write:gateguard-fact-force scripts/hooks/gateguard-fact-force.js standard,strict", "timeout": 5 } ], @@ -102,7 +102,7 @@ "hooks": [ { "type": "command", - "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [[\\\"ecc\\\"],[\\\"ecc@ecc\\\"],[\\\"marketplaces\\\",\\\"ecc\\\"],[\\\"everything-claude-code\\\"],[\\\"everything-claude-code@everything-claude-code\\\"],[\\\"marketplaces\\\",\\\"everything-claude-code\\\"]]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of [\\\"ecc\\\",\\\"everything-claude-code\\\"]){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js pre:compact scripts/hooks/pre-compact.js standard,strict" + "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [['ecc'],['ecc@ecc'],['marketplaces','ecc'],['everything-claude-code'],['everything-claude-code@everything-claude-code'],['marketplaces','everything-claude-code']]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ['ecc','everything-claude-code']){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js pre:compact scripts/hooks/pre-compact.js standard,strict" } ], "description": "Save state before context compaction", @@ -115,7 +115,7 @@ "hooks": [ { "type": "command", - "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [[\\\"ecc\\\"],[\\\"ecc@ecc\\\"],[\\\"marketplaces\\\",\\\"ecc\\\"],[\\\"everything-claude-code\\\"],[\\\"everything-claude-code@everything-claude-code\\\"],[\\\"marketplaces\\\",\\\"everything-claude-code\\\"]]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of [\\\"ecc\\\",\\\"everything-claude-code\\\"]){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/session-start-bootstrap.js" + "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [['ecc'],['ecc@ecc'],['marketplaces','ecc'],['everything-claude-code'],['everything-claude-code@everything-claude-code'],['marketplaces','everything-claude-code']]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ['ecc','everything-claude-code']){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/session-start-bootstrap.js" } ], "description": "Load previous context and detect package manager on new session", @@ -128,7 +128,7 @@ "hooks": [ { "type": "command", - "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [[\\\"ecc\\\"],[\\\"ecc@ecc\\\"],[\\\"marketplaces\\\",\\\"ecc\\\"],[\\\"everything-claude-code\\\"],[\\\"everything-claude-code@everything-claude-code\\\"],[\\\"marketplaces\\\",\\\"everything-claude-code\\\"]]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of [\\\"ecc\\\",\\\"everything-claude-code\\\"]){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/post-bash-dispatcher.js", + "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [['ecc'],['ecc@ecc'],['marketplaces','ecc'],['everything-claude-code'],['everything-claude-code@everything-claude-code'],['marketplaces','everything-claude-code']]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ['ecc','everything-claude-code']){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/post-bash-dispatcher.js", "async": true, "timeout": 30 } @@ -141,7 +141,7 @@ "hooks": [ { "type": "command", - "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [[\\\"ecc\\\"],[\\\"ecc@ecc\\\"],[\\\"marketplaces\\\",\\\"ecc\\\"],[\\\"everything-claude-code\\\"],[\\\"everything-claude-code@everything-claude-code\\\"],[\\\"marketplaces\\\",\\\"everything-claude-code\\\"]]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of [\\\"ecc\\\",\\\"everything-claude-code\\\"]){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js post:quality-gate scripts/hooks/quality-gate.js standard,strict", + "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [['ecc'],['ecc@ecc'],['marketplaces','ecc'],['everything-claude-code'],['everything-claude-code@everything-claude-code'],['marketplaces','everything-claude-code']]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ['ecc','everything-claude-code']){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js post:quality-gate scripts/hooks/quality-gate.js standard,strict", "async": true, "timeout": 30 } @@ -154,7 +154,7 @@ "hooks": [ { "type": "command", - "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [[\\\"ecc\\\"],[\\\"ecc@ecc\\\"],[\\\"marketplaces\\\",\\\"ecc\\\"],[\\\"everything-claude-code\\\"],[\\\"everything-claude-code@everything-claude-code\\\"],[\\\"marketplaces\\\",\\\"everything-claude-code\\\"]]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of [\\\"ecc\\\",\\\"everything-claude-code\\\"]){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js post:edit:design-quality-check scripts/hooks/design-quality-check.js standard,strict", + "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [['ecc'],['ecc@ecc'],['marketplaces','ecc'],['everything-claude-code'],['everything-claude-code@everything-claude-code'],['marketplaces','everything-claude-code']]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ['ecc','everything-claude-code']){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js post:edit:design-quality-check scripts/hooks/design-quality-check.js standard,strict", "timeout": 10 } ], @@ -166,7 +166,7 @@ "hooks": [ { "type": "command", - "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [[\\\"ecc\\\"],[\\\"ecc@ecc\\\"],[\\\"marketplaces\\\",\\\"ecc\\\"],[\\\"everything-claude-code\\\"],[\\\"everything-claude-code@everything-claude-code\\\"],[\\\"marketplaces\\\",\\\"everything-claude-code\\\"]]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of [\\\"ecc\\\",\\\"everything-claude-code\\\"]){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js post:edit:accumulate scripts/hooks/post-edit-accumulator.js standard,strict" + "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [['ecc'],['ecc@ecc'],['marketplaces','ecc'],['everything-claude-code'],['everything-claude-code@everything-claude-code'],['marketplaces','everything-claude-code']]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ['ecc','everything-claude-code']){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js post:edit:accumulate scripts/hooks/post-edit-accumulator.js standard,strict" } ], "description": "Record edited JS/TS file paths for batch format+typecheck at Stop time", @@ -177,7 +177,7 @@ "hooks": [ { "type": "command", - "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [[\\\"ecc\\\"],[\\\"ecc@ecc\\\"],[\\\"marketplaces\\\",\\\"ecc\\\"],[\\\"everything-claude-code\\\"],[\\\"everything-claude-code@everything-claude-code\\\"],[\\\"marketplaces\\\",\\\"everything-claude-code\\\"]]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of [\\\"ecc\\\",\\\"everything-claude-code\\\"]){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js post:edit:console-warn scripts/hooks/post-edit-console-warn.js standard,strict" + "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [['ecc'],['ecc@ecc'],['marketplaces','ecc'],['everything-claude-code'],['everything-claude-code@everything-claude-code'],['marketplaces','everything-claude-code']]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ['ecc','everything-claude-code']){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js post:edit:console-warn scripts/hooks/post-edit-console-warn.js standard,strict" } ], "description": "Warn about console.log statements after edits", @@ -188,7 +188,7 @@ "hooks": [ { "type": "command", - "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [[\\\"ecc\\\"],[\\\"ecc@ecc\\\"],[\\\"marketplaces\\\",\\\"ecc\\\"],[\\\"everything-claude-code\\\"],[\\\"everything-claude-code@everything-claude-code\\\"],[\\\"marketplaces\\\",\\\"everything-claude-code\\\"]]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of [\\\"ecc\\\",\\\"everything-claude-code\\\"]){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js post:governance-capture scripts/hooks/governance-capture.js standard,strict", + "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [['ecc'],['ecc@ecc'],['marketplaces','ecc'],['everything-claude-code'],['everything-claude-code@everything-claude-code'],['marketplaces','everything-claude-code']]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ['ecc','everything-claude-code']){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js post:governance-capture scripts/hooks/governance-capture.js standard,strict", "timeout": 10 } ], @@ -200,7 +200,7 @@ "hooks": [ { "type": "command", - "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [[\\\"ecc\\\"],[\\\"ecc@ecc\\\"],[\\\"marketplaces\\\",\\\"ecc\\\"],[\\\"everything-claude-code\\\"],[\\\"everything-claude-code@everything-claude-code\\\"],[\\\"marketplaces\\\",\\\"everything-claude-code\\\"]]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of [\\\"ecc\\\",\\\"everything-claude-code\\\"]){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js post:session-activity-tracker scripts/hooks/session-activity-tracker.js standard,strict", + "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [['ecc'],['ecc@ecc'],['marketplaces','ecc'],['everything-claude-code'],['everything-claude-code@everything-claude-code'],['marketplaces','everything-claude-code']]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ['ecc','everything-claude-code']){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js post:session-activity-tracker scripts/hooks/session-activity-tracker.js standard,strict", "timeout": 10 } ], @@ -212,7 +212,7 @@ "hooks": [ { "type": "command", - "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [[\\\"ecc\\\"],[\\\"ecc@ecc\\\"],[\\\"marketplace\\\",\\\"ecc\\\"],[\\\"everything-claude-code\\\"],[\\\"everything-claude-code@everything-claude-code\\\"],[\\\"marketplace\\\",\\\"everything-claude-code\\\"]]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of [\\\"ecc\\\",\\\"everything-claude-code\\\"]){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js post:observe scripts/hooks/observe-runner.js standard,strict", + "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [['ecc'],['ecc@ecc'],['marketplaces','ecc'],['everything-claude-code'],['everything-claude-code@everything-claude-code'],['marketplaces','everything-claude-code']]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ['ecc','everything-claude-code']){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js post:observe scripts/hooks/observe-runner.js standard,strict", "async": true, "timeout": 10 } @@ -225,7 +225,7 @@ "hooks": [ { "type": "command", - "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [[\\\"ecc\\\"],[\\\"ecc@ecc\\\"],[\\\"marketplaces\\\",\\\"ecc\\\"],[\\\"everything-claude-code\\\"],[\\\"everything-claude-code@everything-claude-code\\\"],[\\\"marketplaces\\\",\\\"everything-claude-code\\\"]]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of [\\\"ecc\\\",\\\"everything-claude-code\\\"]){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js post:ecc-metrics-bridge scripts/hooks/ecc-metrics-bridge.js minimal,standard,strict", + "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [['ecc'],['ecc@ecc'],['marketplaces','ecc'],['everything-claude-code'],['everything-claude-code@everything-claude-code'],['marketplaces','everything-claude-code']]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ['ecc','everything-claude-code']){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js post:ecc-metrics-bridge scripts/hooks/ecc-metrics-bridge.js minimal,standard,strict", "timeout": 10 } ], @@ -237,7 +237,7 @@ "hooks": [ { "type": "command", - "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [[\\\"ecc\\\"],[\\\"ecc@ecc\\\"],[\\\"marketplaces\\\",\\\"ecc\\\"],[\\\"everything-claude-code\\\"],[\\\"everything-claude-code@everything-claude-code\\\"],[\\\"marketplaces\\\",\\\"everything-claude-code\\\"]]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of [\\\"ecc\\\",\\\"everything-claude-code\\\"]){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js post:ecc-context-monitor scripts/hooks/ecc-context-monitor.js standard,strict", + "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [['ecc'],['ecc@ecc'],['marketplaces','ecc'],['everything-claude-code'],['everything-claude-code@everything-claude-code'],['marketplaces','everything-claude-code']]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ['ecc','everything-claude-code']){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js post:ecc-context-monitor scripts/hooks/ecc-context-monitor.js standard,strict", "timeout": 10 } ], @@ -251,7 +251,7 @@ "hooks": [ { "type": "command", - "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [[\\\"ecc\\\"],[\\\"ecc@ecc\\\"],[\\\"marketplaces\\\",\\\"ecc\\\"],[\\\"everything-claude-code\\\"],[\\\"everything-claude-code@everything-claude-code\\\"],[\\\"marketplaces\\\",\\\"everything-claude-code\\\"]]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of [\\\"ecc\\\",\\\"everything-claude-code\\\"]){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js post:mcp-health-check scripts/hooks/mcp-health-check.js standard,strict" + "command": "node -e \"const p=require('path');const r=(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of [['ecc'],['ecc@ecc'],['marketplaces','ecc'],['everything-claude-code'],['everything-claude-code@everything-claude-code'],['marketplaces','everything-claude-code']]){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ['ecc','everything-claude-code']){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})();const s=p.join(r,'scripts/hooks/plugin-hook-bootstrap.js');process.env.CLAUDE_PLUGIN_ROOT=r;process.argv.splice(1,0,s);require(s)\" node scripts/hooks/run-with-flags.js post:mcp-health-check scripts/hooks/mcp-health-check.js standard,strict" } ], "description": "Track failed MCP tool calls, mark unhealthy servers, and attempt reconnect", diff --git a/scripts/lib/resolve-ecc-root.js b/scripts/lib/resolve-ecc-root.js index 2cbea4e1..5cbc568e 100644 --- a/scripts/lib/resolve-ecc-root.js +++ b/scripts/lib/resolve-ecc-root.js @@ -110,7 +110,22 @@ function resolveEccRoot(options = {}) { * const _r = ; * const sm = require(_r + '/scripts/lib/session-manager'); */ -const INLINE_RESOLVE = `(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of ${JSON.stringify(PLUGIN_ROOT_SEGMENTS)}){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ${JSON.stringify(PLUGIN_CACHE_SLUGS)}){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})()`; +function inlineSingleQuote(value) { + return `'${String(value).replace(/\\/g, '\\\\').replace(/'/g, "\\'")}'`; +} + +function inlineArray(values) { + return `[${values.map(inlineSingleQuote).join(',')}]`; +} + +function inlineNestedArray(values) { + return `[${values.map(inlineArray).join(',')}]`; +} + +const INLINE_PLUGIN_ROOT_SEGMENTS = inlineNestedArray(PLUGIN_ROOT_SEGMENTS); +const INLINE_PLUGIN_CACHE_SLUGS = inlineArray(PLUGIN_CACHE_SLUGS); + +const INLINE_RESOLVE = `(()=>{var e=process.env.CLAUDE_PLUGIN_ROOT;if(e&&e.trim())return e.trim();var p=require('path'),f=require('fs'),h=require('os').homedir(),d=p.join(h,'.claude'),q=p.join('scripts','lib','utils.js');if(f.existsSync(p.join(d,q)))return d;for(var s of ${INLINE_PLUGIN_ROOT_SEGMENTS}){var l=p.join(d,'plugins',...s);if(f.existsSync(p.join(l,q)))return l}try{for(var g of ${INLINE_PLUGIN_CACHE_SLUGS}){var b=p.join(d,'plugins','cache',g);for(var o of f.readdirSync(b,{withFileTypes:true})){if(!o.isDirectory())continue;for(var v of f.readdirSync(p.join(b,o.name),{withFileTypes:true})){if(!v.isDirectory())continue;var c=p.join(b,o.name,v.name);if(f.existsSync(p.join(c,q)))return c}}}}catch(x){}return d})()`; module.exports = { resolveEccRoot, diff --git a/tests/hooks/hooks.test.js b/tests/hooks/hooks.test.js index a70f4e8d..6475fe54 100644 --- a/tests/hooks/hooks.test.js +++ b/tests/hooks/hooks.test.js @@ -2513,6 +2513,29 @@ async function runTests() { passed++; else failed++; + if ( + test('inline hook bootstraps avoid escaped double quotes for Git Bash', () => { + const hooksPath = path.join(__dirname, '..', '..', 'hooks', 'hooks.json'); + const hooks = JSON.parse(fs.readFileSync(hooksPath, 'utf8')); + + for (const [eventName, hookArray] of Object.entries(hooks.hooks)) { + for (const entry of hookArray) { + for (const hook of entry.hooks) { + const commandText = Array.isArray(hook.command) ? hook.command.join(' ') : hook.command; + if (typeof commandText === 'string' && commandText.startsWith('node -e ')) { + assert.ok( + !commandText.includes('\\"'), + `${eventName}/${entry.id || entry.matcher || 'hook'} should not ship escaped double quotes in node -e payload`, + ); + } + } + } + } + }) + ) + passed++; + else failed++; + if ( test('all hook commands use node or approved shell wrappers', () => { const hooksPath = path.join(__dirname, '..', '..', 'hooks', 'hooks.json'); diff --git a/tests/integration/hooks.test.js b/tests/integration/hooks.test.js index e05b4e49..1ab3a342 100644 --- a/tests/integration/hooks.test.js +++ b/tests/integration/hooks.test.js @@ -997,6 +997,13 @@ async function runTests() { (Array.isArray(command) && typeof command[0] === 'string' && command[0].endsWith('.sh')) || commandText.endsWith('.sh'); + if (isInline) { + assert.ok( + !commandText.includes('\\"'), + `Hook command in ${hookType} should not include escaped double quotes in node -e payload: ${commandText.substring(0, 80)}` + ); + } + assert.ok( isInline || isFilePath || isNpx || isShellWrapper || isShellScriptPath, `Hook command in ${hookType} should be node -e, node script, npx, or shell wrapper/script, got: ${commandText.substring(0, 80)}` diff --git a/tests/lib/command-plugin-root.test.js b/tests/lib/command-plugin-root.test.js index 01559a5b..78362fef 100644 --- a/tests/lib/command-plugin-root.test.js +++ b/tests/lib/command-plugin-root.test.js @@ -38,8 +38,9 @@ test('skill-health command uses shared inline resolver in all shell snippets', ( }); test('inline resolver covers current and legacy marketplace plugin roots', () => { - assert.ok(INLINE_RESOLVE.includes('"marketplaces","ecc"')); - assert.ok(INLINE_RESOLVE.includes('"marketplaces","everything-claude-code"')); + assert.ok(INLINE_RESOLVE.includes("'marketplaces','ecc'")); + assert.ok(INLINE_RESOLVE.includes("'marketplaces','everything-claude-code'")); + assert.ok(!INLINE_RESOLVE.includes('\\"'), 'Inline resolver should not require escaped double quotes'); }); console.log(`Passed: ${passed}`); diff --git a/tests/scripts/install-apply.test.js b/tests/scripts/install-apply.test.js index c9aac651..d939154c 100644 --- a/tests/scripts/install-apply.test.js +++ b/tests/scripts/install-apply.test.js @@ -531,6 +531,10 @@ function runTests() { installedBashDispatcherEntry.hooks[0].command.includes('pre-bash-dispatcher.js'), 'hooks/hooks.json should point the Bash preflight contract at the consolidated dispatcher' ); + assert.ok( + !installedBashDispatcherEntry.hooks[0].command.includes('\\"'), + 'hooks/hooks.json should avoid escaped double quotes that break Windows Git Bash parsing' + ); assert.ok( !installedBashDispatcherEntry.hooks[0].command.includes('${CLAUDE_PLUGIN_ROOT}'), 'hooks/hooks.json should not retain raw CLAUDE_PLUGIN_ROOT shell placeholders after install' From 673dff977f6a6d0f88b70dcf20472764215d3fd4 Mon Sep 17 00:00:00 2001 From: Karnav Pargi <1001913+karnavpargi@users.noreply.github.com> Date: Tue, 19 May 2026 14:28:25 +0530 Subject: [PATCH 25/61] Update README links to new repository name 'ECC' Changed `everything-claude-code` to `ECC` --- README.md | 34 +++++++++++++++++----------------- 1 file changed, 17 insertions(+), 17 deletions(-) diff --git a/README.md b/README.md index e7595bc5..608a5c5a 100644 --- a/README.md +++ b/README.md @@ -4,9 +4,9 @@ ![Everything Claude Code — the performance system for AI agent harnesses](assets/hero.png) -[![Stars](https://img.shields.io/github/stars/affaan-m/everything-claude-code?style=flat)](https://github.com/affaan-m/everything-claude-code/stargazers) -[![Forks](https://img.shields.io/github/forks/affaan-m/everything-claude-code?style=flat)](https://github.com/affaan-m/everything-claude-code/network/members) -[![Contributors](https://img.shields.io/github/contributors/affaan-m/everything-claude-code?style=flat)](https://github.com/affaan-m/everything-claude-code/graphs/contributors) +[![Stars](https://img.shields.io/github/stars/affaan-m/ECC?style=flat)](https://github.com/affaan-m/ECC/stargazers) +[![Forks](https://img.shields.io/github/forks/affaan-m/ECC?style=flat)](https://github.com/affaan-m/ECC/network/members) +[![Contributors](https://img.shields.io/github/contributors/affaan-m/ECC?style=flat)](https://github.com/affaan-m/ECC/graphs/contributors) [![npm ecc-universal](https://img.shields.io/npm/dw/ecc-universal?label=ecc-universal%20weekly%20downloads&logo=npm)](https://www.npmjs.com/package/ecc-universal) [![npm ecc-agentshield](https://img.shields.io/npm/dw/ecc-agentshield?label=ecc-agentshield%20weekly%20downloads&logo=npm)](https://www.npmjs.com/package/ecc-agentshield) [![GitHub App Install](https://img.shields.io/badge/GitHub%20App-150%20installs-2ea44f?logo=github)](https://github.com/marketplace/ecc-tools) @@ -59,7 +59,7 @@ ECC v2.0.0-rc.1 adds the public Hermes operator story on top of that reusable la - + Community
Discussions · Q&A · Show & Tell @@ -172,7 +172,7 @@ This repo is the raw code only. The guides explain everything. ### v1.4.1 — Bug Fix (Feb 2026) -- **Fixed instinct import content loss** — `parse_instinct_file()` was silently dropping all content after frontmatter (Action, Evidence, Examples sections) during `/instinct-import`. ([#148](https://github.com/affaan-m/everything-claude-code/issues/148), [#161](https://github.com/affaan-m/everything-claude-code/pull/161)) +- **Fixed instinct import content loss** — `parse_instinct_file()` was silently dropping all content after frontmatter (Action, Evidence, Examples sections) during `/instinct-import`. ([#148](https://github.com/affaan-m/ECC/issues/148), [#161](https://github.com/affaan-m/ECC/pull/161)) ### v1.4.0 — Multi-Language Rules, Installation Wizard & PM2 (Feb 2026) @@ -196,7 +196,7 @@ This repo is the raw code only. The guides explain everything. - **Session management** — `/sessions` command for session history - **Continuous learning v2** — Instinct-based learning with confidence scoring, import/export, evolution -See the full changelog in [Releases](https://github.com/affaan-m/everything-claude-code/releases). +See the full changelog in [Releases](https://github.com/affaan-m/ECC/releases). --- @@ -265,7 +265,7 @@ npx ecc install --profile minimal --target claude --with capability:machine-lear ```bash # Add marketplace -/plugin marketplace add https://github.com/affaan-m/everything-claude-code +/plugin marketplace add https://github.com/affaan-m/ECC # Install plugin /plugin install ecc@ecc @@ -275,7 +275,7 @@ npx ecc install --profile minimal --target claude --with capability:machine-lear ECC now has three public identifiers, and they are not interchangeable: -- GitHub source repo: `affaan-m/everything-claude-code` +- GitHub source repo: `affaan-m/ECC` - Claude marketplace/plugin identifier: `ecc@ecc` - npm package: `ecc-universal` @@ -295,7 +295,7 @@ This is intentional. Anthropic marketplace/plugin installs are keyed by a canoni ```bash # Clone the repo first -git clone https://github.com/affaan-m/everything-claude-code.git +git clone https://github.com/affaan-m/ECC.git cd everything-claude-code # Install dependencies (pick your package manager) @@ -812,7 +812,7 @@ Claude Code v2.1+ **automatically loads** `hooks/hooks.json` from any installed Duplicate hooks file detected: ./hooks/hooks.json resolves to already-loaded file ``` -**History:** This has caused repeated fix/revert cycles in this repo ([#29](https://github.com/affaan-m/everything-claude-code/issues/29), [#52](https://github.com/affaan-m/everything-claude-code/issues/52), [#103](https://github.com/affaan-m/everything-claude-code/issues/103)). The behavior changed between Claude Code versions, leading to confusion. We now have a regression test to prevent this from being reintroduced. +**History:** This has caused repeated fix/revert cycles in this repo ([#29](https://github.com/affaan-m/ECC/issues/29), [#52](https://github.com/affaan-m/ECC/issues/52), [#103](https://github.com/affaan-m/ECC/issues/103)). The behavior changed between Claude Code versions, leading to confusion. We now have a regression test to prevent this from being reintroduced. --- @@ -824,7 +824,7 @@ The easiest way to use this repo - install as a Claude Code plugin: ```bash # Add this repo as a marketplace -/plugin marketplace add https://github.com/affaan-m/everything-claude-code +/plugin marketplace add https://github.com/affaan-m/ECC # Install the plugin /plugin install ecc@ecc @@ -838,7 +838,7 @@ Or add directly to your `~/.claude/settings.json`: "ecc": { "source": { "source": "github", - "repo": "affaan-m/everything-claude-code" + "repo": "affaan-m/ECC" } } }, @@ -854,7 +854,7 @@ This gives you instant access to all commands, agents, skills, and hooks. > > ```bash > # Clone the repo first -> git clone https://github.com/affaan-m/everything-claude-code.git +> git clone https://github.com/affaan-m/ECC.git > > # Option A: User-level rules (applies to all projects) > mkdir -p ~/.claude/rules/ecc @@ -878,7 +878,7 @@ If you prefer manual control over what's installed: ```bash # Clone the repo -git clone https://github.com/affaan-m/everything-claude-code.git +git clone https://github.com/affaan-m/ECC.git # Copy agents to your Claude config cp everything-claude-code/agents/*.md ~/.claude/agents/ @@ -1083,7 +1083,7 @@ This shows all available agents, commands, and skills from the plugin.
My hooks aren't working / I see "Duplicate hooks file" errors -This is the most common issue. **Do NOT add a `"hooks"` field to `.claude-plugin/plugin.json`.** Claude Code v2.1+ automatically loads `hooks/hooks.json` from installed plugins. Explicitly declaring it causes duplicate detection errors. See [#29](https://github.com/affaan-m/everything-claude-code/issues/29), [#52](https://github.com/affaan-m/everything-claude-code/issues/52), [#103](https://github.com/affaan-m/everything-claude-code/issues/103). +This is the most common issue. **Do NOT add a `"hooks"` field to `.claude-plugin/plugin.json`.** Claude Code v2.1+ automatically loads `hooks/hooks.json` from installed plugins. Explicitly declaring it causes duplicate detection errors. See [#29](https://github.com/affaan-m/ECC/issues/29), [#52](https://github.com/affaan-m/ECC/issues/52), [#103](https://github.com/affaan-m/ECC/issues/103).
@@ -1145,7 +1145,7 @@ Yes. ECC is cross-platform: - **Cursor**: Pre-translated configs in `.cursor/`. See [Cursor IDE Support](#cursor-ide-support). - **Gemini CLI**: Experimental project-local support via `.gemini/GEMINI.md` and shared installer plumbing. - **OpenCode**: Full plugin support in `.opencode/`. See [OpenCode Support](#opencode-support). -- **Codex**: First-class support for both macOS app and CLI, with adapter drift guards and SessionStart fallback. See PR [#257](https://github.com/affaan-m/everything-claude-code/pull/257). +- **Codex**: First-class support for both macOS app and CLI, with adapter drift guards and SessionStart fallback. See PR [#257](https://github.com/affaan-m/ECC/pull/257). - **GitHub Copilot (VS Code)**: Instruction and prompt layer via `.github/copilot-instructions.md`, `.vscode/settings.json`, and `.github/prompts/`. See [GitHub Copilot Support](#github-copilot-support). - **Antigravity**: Tightly integrated setup for workflows, skills, and flattened rules in `.agent/`. See [Antigravity Guide](docs/ANTIGRAVITY-GUIDE.md). - **JoyCode / CodeBuddy**: Project-local selective install adapters for commands, agents, skills, and flattened rules. See [JoyCode Adapter Guide](docs/JOYCODE-GUIDE.md). @@ -1738,7 +1738,7 @@ This project is free and open source. Sponsors help keep it maintained and growi ## Star History -[![Star History Chart](https://api.star-history.com/svg?repos=affaan-m/everything-claude-code&type=Date)](https://star-history.com/#affaan-m/everything-claude-code&Date) +[![Star History Chart](https://api.star-history.com/svg?repos=affaan-m/ECC&type=Date)](https://star-history.com/#affaan-m/ECC&Date) --- From b66fa78fe8c700deec24eab6b86a862fc200099b Mon Sep 17 00:00:00 2001 From: Karnav Pargi <1001913+karnavpargi@users.noreply.github.com> Date: Tue, 19 May 2026 14:38:34 +0530 Subject: [PATCH 26/61] Apply suggestion from @karnavpargi --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 608a5c5a..c30fbfdb 100644 --- a/README.md +++ b/README.md @@ -296,7 +296,7 @@ This is intentional. Anthropic marketplace/plugin installs are keyed by a canoni ```bash # Clone the repo first git clone https://github.com/affaan-m/ECC.git -cd everything-claude-code +cd ECC # Install dependencies (pick your package manager) npm install # or: pnpm install | yarn install | bun install From 2199b223510aeadb8f8adf95e6939676488cfc50 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 05:18:28 -0400 Subject: [PATCH 27/61] docs: keep renamed README install paths usable Adjust README manual-install snippets after the affaan-m/ECC repo rename so cloned paths use the new ECC checkout or relative paths. --- README.md | 46 ++++++++++++++++++++++++---------------------- 1 file changed, 24 insertions(+), 22 deletions(-) diff --git a/README.md b/README.md index c30fbfdb..c46dc47e 100644 --- a/README.md +++ b/README.md @@ -494,7 +494,7 @@ Windows PowerShell: This repo is a **Claude Code plugin** - install it directly or copy components manually. ``` -everything-claude-code/ +ECC/ |-- .claude-plugin/ # Plugin and marketplace manifests | |-- plugin.json # Plugin metadata and component paths | |-- marketplace.json # Marketplace catalog for /plugin marketplace add @@ -855,19 +855,20 @@ This gives you instant access to all commands, agents, skills, and hooks. > ```bash > # Clone the repo first > git clone https://github.com/affaan-m/ECC.git +> cd ECC > > # Option A: User-level rules (applies to all projects) > mkdir -p ~/.claude/rules/ecc -> cp -r everything-claude-code/rules/common ~/.claude/rules/ecc/ -> cp -r everything-claude-code/rules/typescript ~/.claude/rules/ecc/ # pick your stack -> cp -r everything-claude-code/rules/python ~/.claude/rules/ecc/ -> cp -r everything-claude-code/rules/golang ~/.claude/rules/ecc/ -> cp -r everything-claude-code/rules/php ~/.claude/rules/ecc/ +> cp -r rules/common ~/.claude/rules/ecc/ +> cp -r rules/typescript ~/.claude/rules/ecc/ # pick your stack +> cp -r rules/python ~/.claude/rules/ecc/ +> cp -r rules/golang ~/.claude/rules/ecc/ +> cp -r rules/php ~/.claude/rules/ecc/ > > # Option B: Project-level rules (applies to current project only) > mkdir -p .claude/rules/ecc -> cp -r everything-claude-code/rules/common .claude/rules/ecc/ -> cp -r everything-claude-code/rules/typescript .claude/rules/ecc/ # pick your stack +> cp -r rules/common .claude/rules/ecc/ +> cp -r rules/typescript .claude/rules/ecc/ # pick your stack > ``` --- @@ -879,33 +880,34 @@ If you prefer manual control over what's installed: ```bash # Clone the repo git clone https://github.com/affaan-m/ECC.git +cd ECC # Copy agents to your Claude config -cp everything-claude-code/agents/*.md ~/.claude/agents/ +cp agents/*.md ~/.claude/agents/ # Copy rules directories (common + language-specific) mkdir -p ~/.claude/rules/ecc -cp -r everything-claude-code/rules/common ~/.claude/rules/ecc/ -cp -r everything-claude-code/rules/typescript ~/.claude/rules/ecc/ # pick your stack -cp -r everything-claude-code/rules/python ~/.claude/rules/ecc/ -cp -r everything-claude-code/rules/golang ~/.claude/rules/ecc/ -cp -r everything-claude-code/rules/php ~/.claude/rules/ecc/ -cp -r everything-claude-code/rules/arkts ~/.claude/rules/ecc/ +cp -r rules/common ~/.claude/rules/ecc/ +cp -r rules/typescript ~/.claude/rules/ecc/ # pick your stack +cp -r rules/python ~/.claude/rules/ecc/ +cp -r rules/golang ~/.claude/rules/ecc/ +cp -r rules/php ~/.claude/rules/ecc/ +cp -r rules/arkts ~/.claude/rules/ecc/ # Copy skills first (primary workflow surface) # Recommended (new users): core/general skills only mkdir -p ~/.claude/skills/ecc -cp -r everything-claude-code/.agents/skills/* ~/.claude/skills/ecc/ -cp -r everything-claude-code/skills/search-first ~/.claude/skills/ecc/ +cp -r .agents/skills/* ~/.claude/skills/ecc/ +cp -r skills/search-first ~/.claude/skills/ecc/ # Optional: add niche/framework-specific skills only when needed # for s in django-patterns django-tdd laravel-patterns springboot-patterns quarkus-patterns; do -# cp -r everything-claude-code/skills/$s ~/.claude/skills/ecc/ +# cp -r skills/$s ~/.claude/skills/ecc/ # done # Optional: keep maintained slash-command compatibility during migration mkdir -p ~/.claude/commands -cp everything-claude-code/commands/*.md ~/.claude/commands/ +cp commands/*.md ~/.claude/commands/ # Retired shims live in legacy-command-shims/commands/. # Copy individual files from there only if you still need old names such as /tdd. @@ -1128,11 +1130,11 @@ Yes. Use Option 2 (manual installation) and copy only what you need: ```bash # Just agents -cp everything-claude-code/agents/*.md ~/.claude/agents/ +cp agents/*.md ~/.claude/agents/ # Just rules mkdir -p ~/.claude/rules/ecc/ -cp -r everything-claude-code/rules/common ~/.claude/rules/ecc/ +cp -r rules/common ~/.claude/rules/ecc/ ``` Each component is fully independent. @@ -1488,7 +1490,7 @@ OpenCode's plugin system is MORE sophisticated than Claude Code with 20+ event t **Option 1: Use directly** ```bash -cd everything-claude-code +cd ECC opencode ``` From 9ee1e15564eef515875dc7511d23deded4265b7d Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 05:27:19 -0400 Subject: [PATCH 28/61] docs: define ECC 2.0 hypergrowth release lane Refresh the active 2.0 release surface for the affaan-m/ECC repo identity, update package/plugin/workflow launch metadata, and add an operator command center for release video, partner, sponsor, consulting, and social launch execution. --- .claude-plugin/marketplace.json | 6 +- .claude-plugin/plugin.json | 4 +- .github/workflows/release.yml | 2 +- .github/workflows/reusable-release.yml | 2 +- docs/ECC-2.0-GA-ROADMAP.md | 26 +++- docs/business/social-launch-copy.md | 13 +- ...plugin-publication-checklist-2026-05-18.md | 22 +-- ...cc-2-hypergrowth-release-command-center.md | 145 ++++++++++++++++++ package.json | 10 +- tests/docs/ecc2-release-surface.test.js | 10 +- 10 files changed, 203 insertions(+), 37 deletions(-) create mode 100644 docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md diff --git a/.claude-plugin/marketplace.json b/.claude-plugin/marketplace.json index 0e4dca59..1b361245 100644 --- a/.claude-plugin/marketplace.json +++ b/.claude-plugin/marketplace.json @@ -5,20 +5,20 @@ "email": "me@affaanmustafa.com" }, "metadata": { - "description": "Battle-tested Claude Code configurations from an Anthropic hackathon winner" + "description": "Harness-native ECC skills, hooks, rules, MCP conventions, and operator workflows" }, "plugins": [ { "name": "ecc", "source": "./", - "description": "The most comprehensive Claude Code plugin — 60 agents, 232 skills, 75 legacy command shims, selective install profiles, and production-ready hooks for TDD, security scanning, code review, and continuous learning", + "description": "Harness-native ECC operator layer - 60 agents, 232 skills, 75 legacy command shims, reusable hooks, rules, selective install profiles, and production-ready workflows for Claude Code, Codex, OpenCode, Cursor, and related agent harnesses", "version": "2.0.0-rc.1", "author": { "name": "Affaan Mustafa", "email": "me@affaanmustafa.com" }, "homepage": "https://ecc.tools", - "repository": "https://github.com/affaan-m/everything-claude-code", + "repository": "https://github.com/affaan-m/ECC", "license": "MIT", "keywords": [ "agents", diff --git a/.claude-plugin/plugin.json b/.claude-plugin/plugin.json index c1927a02..09e435cd 100644 --- a/.claude-plugin/plugin.json +++ b/.claude-plugin/plugin.json @@ -1,13 +1,13 @@ { "name": "ecc", "version": "2.0.0-rc.1", - "description": "Battle-tested Claude Code plugin for engineering teams — 60 agents, 232 skills, 75 legacy command shims, production-ready hooks, and selective install workflows evolved through continuous real-world use", + "description": "Harness-native ECC plugin for engineering teams - 60 agents, 232 skills, 75 legacy command shims, reusable hooks, rules, MCP conventions, and operator workflows for Claude Code plus adjacent agent harnesses", "author": { "name": "Affaan Mustafa", "url": "https://x.com/affaanmustafa" }, "homepage": "https://ecc.tools", - "repository": "https://github.com/affaan-m/everything-claude-code", + "repository": "https://github.com/affaan-m/ECC", "license": "MIT", "keywords": [ "claude-code", diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index f15d456b..9ca70399 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -96,7 +96,7 @@ jobs: ### Notes - npm package: \`ecc-universal\` - - Claude marketplace/plugin identifier: \`everything-claude-code@everything-claude-code\` + - Claude marketplace/plugin identifier: \`ecc@ecc\` - For migration tips and compatibility notes, see README and CHANGELOG. EOF diff --git a/.github/workflows/reusable-release.yml b/.github/workflows/reusable-release.yml index 365a1260..878e11c5 100644 --- a/.github/workflows/reusable-release.yml +++ b/.github/workflows/reusable-release.yml @@ -114,7 +114,7 @@ jobs: ### Package Notes - npm package: \`ecc-universal\` - - Claude marketplace/plugin identifier: \`everything-claude-code@everything-claude-code\` + - Claude marketplace/plugin identifier: \`ecc@ecc\` EOF - name: Pack npm artifact diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index c4ea81b2..583893b8 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -12,11 +12,29 @@ execution truth is split across: - merged PR evidence; - handoffs under `~/.cluster-swarm/handoffs/`. +The May 19 release/growth execution map lives at +[`docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md`](releases/2.0.0/ecc-2-hypergrowth-release-command-center.md). +It is the operator surface for the final ECC 2.0 repo identity, video suite, +partner/sponsor funnel, consulting/talk funnel, and social launch plan. + +## 2026-05-19 Delta + +- The public repo identity is now `affaan-m/ECC`; release, package, plugin, + workflow, and launch-copy surfaces should use that URL for current public + links. +- The ECC 2.0 release story should lead with the product shape directly: + harness-native operator system, reusable skills/rules/hooks/MCP conventions, + `ecc2/` alpha control plane, Hermes as optional operator shell, and ECC Tools + Pro/Sponsors/consulting as the business surface. +- Copy should avoid presenting this as a repo rename or config-pack migration. + The release proof should show the system through install flow, cross-harness + demos, security evidence, hosted product evidence, and the video suite. + ## Current Evidence As of 2026-05-18: -- GitHub queues are clean across `affaan-m/everything-claude-code`, +- GitHub queues are clean across `affaan-m/ECC`, `affaan-m/agentshield`, `affaan-m/JARVIS`, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website`: the latest `platform-audit` sweep found 0 open PRs, 0 open issues, 0 discussion maintainer-touch gaps, 0 answerable Q&A missing @@ -33,7 +51,7 @@ As of 2026-05-18: now at 0 open PRs and 0 open issues by live `gh search`. Archived repos touched during closure were restored to archived state. - GitHub discussions are current across those tracked repos: - `affaan-m/everything-claude-code` has 58 total discussions and 0 without + `affaan-m/ECC` has 58 total discussions and 0 without maintainer touch after May 15 maintainer updates on #73 and #1239; AgentShield, JARVIS, ECC Tools, and the ECC Tools website have discussions disabled or 0 total discussions. `docs/architecture/discussion-response-playbook.md` now @@ -715,8 +733,8 @@ is not complete unless the evidence column exists and has been freshly verified. | Prompt requirement | Required artifact or gate | Current evidence | Status | | --- | --- | --- | --- | -| Keep public PRs below 20 | Repo-family PR recheck | 0 open PRs across `everything-claude-code`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-18 after merging PR #1976 and refreshing platform audit evidence | Complete | -| Keep public issues below 20 | Repo-family issue recheck | 0 open issues across `everything-claude-code`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-18 after the live platform audit refresh | Complete | +| Keep public PRs below 20 | Repo-family PR recheck | 0 open PRs across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-18 after merging PR #1976 and refreshing platform audit evidence | Complete | +| Keep public issues below 20 | Repo-family issue recheck | 0 open issues across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-18 after the live platform audit refresh | Complete | | Manage repository discussions | Repo-family discussion recheck plus response playbook | Platform audit reports 0 discussion maintainer-touch gaps and 0 answerable Q&A missing accepted answers; trunk still has 58 total discussions; `docs/architecture/discussion-response-playbook.md` distinguishes support, maintainer coordination, stale/concluded, release, informational, and security-sensitive response paths | Complete | | Manage PR discussions | PR review/comment closure plus merge/close state | ECC #1976 merged after maintainer follow-up validation; no open tracked PRs remain | Complete | | Salvage useful stale work | `docs/stale-pr-salvage-ledger.md` plus `docs/legacy-artifact-inventory.md` | Ledger records salvaged, superseded, skipped, and manual-review tails; #1815-#1818 added cost tracking, skill scout, frontend design guidance, code-reviewer false-positive guardrails, and the May 12 gap pass; #1687, #1609, #1563, #1564, and #1565 localization tails are attached to Linear ITO-55 for language-owner review and no automatic import remains release-blocking | Complete; repeat legacy scan before release | diff --git a/docs/business/social-launch-copy.md b/docs/business/social-launch-copy.md index 637d3424..7d9b57d0 100644 --- a/docs/business/social-launch-copy.md +++ b/docs/business/social-launch-copy.md @@ -7,7 +7,8 @@ Use these templates as launch-ready starting points. Review channel tone before ```text ECC v2.0.0-rc.1 preview pack is ready for final release review. -The repo is moving from a Claude Code config pack into a cross-harness operating system for agentic work. +ECC 2.0 is the harness-native operator system for agentic work: skills, hooks, +rules, MCP conventions, release gates, and an optional Hermes operator shell. What ships: - Hermes setup guide @@ -15,8 +16,8 @@ What ships: - cross-harness architecture docs - Hermes import guidance for turning local operator workflows into public ECC skills -Start here: https://github.com/affaan-m/everything-claude-code -Release notes: https://github.com/affaan-m/everything-claude-code/blob/main/docs/releases/2.0.0-rc.1/release-notes.md +Start here: https://github.com/affaan-m/ECC +Release notes: https://github.com/affaan-m/ECC/blob/main/docs/releases/2.0.0-rc.1/release-notes.md ``` ## X Post: Proof + Metrics @@ -57,7 +58,7 @@ ECC v2.0.0-rc.1 pushes that further: reusable skills, thin harness adapters, and ```text ECC v2.0.0-rc.1 preview pack is ready for final release review. -The practical shift: ECC is no longer just a Claude Code config pack. It is becoming a cross-harness operating system for agentic work. +ECC 2.0 is the harness-native operator system for agentic work. The same reusable layer now reaches Claude Code, Codex, OpenCode, Cursor, Gemini, Zed, GitHub Copilot workflows, and terminal-only operator lanes. This release-candidate surface includes: - sanitized Hermes setup documentation @@ -67,6 +68,6 @@ This release-candidate surface includes: It does not include private workspace state, credentials, raw local exports, or personal datasets. -Repo: https://github.com/affaan-m/everything-claude-code -Release notes: https://github.com/affaan-m/everything-claude-code/blob/main/docs/releases/2.0.0-rc.1/release-notes.md +Repo: https://github.com/affaan-m/ECC +Release notes: https://github.com/affaan-m/ECC/blob/main/docs/releases/2.0.0-rc.1/release-notes.md ``` diff --git a/docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md b/docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md index e31e5db1..6433c372 100644 --- a/docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md +++ b/docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md @@ -1,6 +1,7 @@ # ECC v2.0.0-rc.1 Release Name And Plugin Publication Checklist -Snapshot date: 2026-05-18. +Snapshot date: 2026-05-18. Canonical repo decision refreshed 2026-05-19 +after the public repo rename to `affaan-m/ECC`. This checklist is the operator gate for release naming, package publication, and Claude/Codex plugin distribution. It is not a publication action by itself. @@ -9,20 +10,22 @@ submitting marketplace forms, or posting announcements. ## Fixed rc.1 Decision -Ship `v2.0.0-rc.1` as **Everything Claude Code (ECC)**. +Ship `v2.0.0-rc.1` as **ECC**. -- Keep the GitHub repo at `affaan-m/everything-claude-code`. +- Keep the GitHub repo at `affaan-m/ECC`. - Keep the npm package as `ecc-universal`. - Keep Claude and Codex plugin slugs as `ecc`. - Publish the npm prerelease on the `next` dist-tag, not `latest`. -- Do not rename to `affaan-m/ecc`, `ecc`, or `@affaan-m/ecc` before rc.1. +- Do not rename the npm package to `ecc` or `@affaan-m/ecc` before rc.1. +- Treat `affaan-m/ECC` as the canonical public repo for rc.1 and GA release + copy. Reasons: - `ecc-universal` is the current working install and package surface. - `ecc` on npm is occupied by an unrelated elliptic-curve package. - `@affaan-m/ecc` is unclaimed on npm, but would require a migration plan. -- `affaan-m/ecc` is not available to the current GitHub auth context. +- `affaan-m/ECC` is now the live public GitHub repo. - Claude and Codex already expose the desired short namespace as `ecc`. ## Current Surface Evidence @@ -30,8 +33,7 @@ Reasons: | Surface | Current value | Evidence command | 2026-05-18 result | Release action | | --- | --- | --- | --- | --- | | Git commit | `67e63e63f9bfd074bd6a21bf6bac71f3dfefa58b` | `git rev-parse HEAD` | Recorded from clean `main` before this ITO-46 evidence refresh | Re-run from final release commit | -| GitHub repo | `affaan-m/everything-claude-code` | `git remote get-url origin` | `https://github.com/affaan-m/everything-claude-code.git` | Keep for rc.1 | -| Possible short repo | `affaan-m/ecc` | `gh repo view affaan-m/ecc --json nameWithOwner,url,isPrivate` | GraphQL could not resolve repository | Do not depend on it for rc.1 | +| GitHub repo | `affaan-m/ECC` | `git remote get-url origin` | `https://github.com/affaan-m/ECC.git` | Keep for rc.1 and GA | | npm package | `ecc-universal@2.0.0-rc.1` local, `1.10.0` registry latest | `node -p "require('./package.json').name + '@' + require('./package.json').version"` and `npm view ecc-universal name version dist-tags --json` | Local rc.1 ready; registry still latest `1.10.0` | Publish rc.1 with `--tag next` after approval | | Exact npm short name | `ecc` | `npm view ecc name version description repository.url --json` | Occupied by unrelated `ecc@0.0.2` | Do not use | | Scoped npm short name | `@affaan-m/ecc` | `npm view @affaan-m/ecc name version --json` | 404 | Candidate only after migration plan | @@ -59,7 +61,7 @@ claude plugin validate .claude-plugin/plugin.json claude plugin tag .claude-plugin --dry-run codex plugin marketplace add --help HOME="$(mktemp -d)" codex plugin marketplace add ./ -HOME="$(mktemp -d)" codex plugin marketplace add affaan-m/everything-claude-code --ref "$(git rev-parse HEAD)" +HOME="$(mktemp -d)" codex plugin marketplace add affaan-m/ECC --ref "$(git rev-parse HEAD)" npm pack --dry-run --json npm publish --tag next --dry-run npm run build:opencode @@ -96,8 +98,8 @@ keep the related publication action blocked. documents a public submission path or confirms the plugin has been listed. - Do not announce billing, Marketplace, or native payments until ECC Tools live Marketplace account readback returns ready. -- Do not rename the repo or package until rc.1 is published and a migration - guide maps old names to new names. +- Do not rename the npm package until rc.1 is published and a migration guide + maps old install names to new names. - Do not post social copy while any release, npm, plugin, or billing URL is still approval-gated. diff --git a/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md b/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md new file mode 100644 index 00000000..986aa079 --- /dev/null +++ b/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md @@ -0,0 +1,145 @@ +# ECC 2.0 Hypergrowth Release Command Center + +Snapshot date: 2026-05-19. + +This is the execution map for turning ECC 2.0 into a complete public release, +partner funnel, sponsor funnel, consulting surface, and content launch. It is +written for operators. Use it to decide what ships, what gets announced, and +what stays blocked until evidence exists. + +## Release Claim + +ECC 2.0 is the harness-native operator system for agentic work. + +The public proof must show the actual system: + +- reusable skills, rules, hooks, MCP conventions, and release gates; +- Claude Code, Codex, OpenCode, Cursor, Gemini, Zed, GitHub Copilot, and + terminal-only workflows as supported execution surfaces; +- `ecc2/` as the alpha control-plane/TUI direction; +- Hermes as the optional operator shell for chat, cron, handoffs, and daily + work routing; +- ECC Tools Pro, GitHub Sponsors, and consulting as the business surface that + funds the OSS layer. + +Avoid language that frames this as a rename or a retreat from the old project. +The release copy should show the 2.0 product shape directly. + +## Current Growth Baseline + +| Metric | Current | Target | Gap | +| --- | ---: | ---: | ---: | +| MRR | `$1,728/mo` | `$10,000/mo` | `$8,272/mo` | +| Sponsor motion | Active GitHub Sponsors plus open inbound | Repeatable sponsor close loop | Approval-gated outbound | +| Consulting motion | Open, non-primary | Partner-ready packages | Public proof, talks, and intake | +| Content motion | Raw ECC 2 media exists | Weekly launch clips and founder proof | Final video suite | +| Community motion | Discord exists | Useful coding/operator community | Invite, channels, pins, moderation | + +MRR growth should come from four lanes at once: + +- GitHub Sponsors and OSS partner sponsors; +- ECC Tools Pro subscriptions; +- consulting and implementation contracts; +- talks, podcasts, conference demos, and partner webinars that create inbound. + +## Release Gates + +| Lane | Done when | Current action | +| --- | --- | --- | +| Repo identity | README, package metadata, plugin metadata, release docs, workflows, and launch copy all use `affaan-m/ECC` where public URLs are needed | Canonical URL sweep | +| Package and plugin publication | `ecc-universal@2.0.0-rc.1` dry-runs clean, npm `next` is approved, Claude plugin tag dry-runs, Codex repo marketplace smoke passes, OpenCode build passes | Refresh publication evidence from final commit | +| Product proof | Quickstart, cross-harness architecture, demo prompts, `ecc2/` alpha boundary, AgentShield safety proof, and hosted ECC Tools links are consistent | Keep proof surfaces concrete | +| Revenue proof | Sponsor tiers, Pro pricing, consulting CTA, partner CTA, and billing-readback language are current | Do not announce billing claims before live readback | +| Content proof | Launch video, short-form clips, screenshots, release notes, GitHub Discussion, X, LinkedIn, and longform post are aligned | Produce video suite from existing raw material | +| Community proof | Discord invite, rules, channels, onboarding, and sponsor/community routing are ready | Needs invite/token decision before public links | + +## Video Suite + +The video lane should use the existing ECC video-editing skill plus the +`browser-use/video-use` model where useful: transcript as the editing surface, +strategy approval before render, deterministic cuts, timeline/project output +when available, and self-eval before publication. + +Reference pattern: + +Primary source classes already exist in the local ECC media library. Keep raw +absolute paths out of public docs; use basenames or a private production +manifest when handing work to an editor or agent. + +| Deliverable | Length | Source material | Proof goal | +| --- | ---: | --- | --- | +| Primary launch video | 90-150s | `longform-full-wide.mp4`, `sf-longform-full.mp4`, `architecture-2-wide.mp4`, `terminal-scan-2-wide.mp4`, `new_site_raw.mp4` | ECC 2.0 as the operator system | +| Install proof | 30s | README install, terminal scan, quickstart, plugin install | Fewer-click adoption | +| What is ECC | 45-60s | `sf-thread-2-whatisecc.mp4`, `vertical-2-whatisecc.mp4`, `architecture-2-*` | Product category clarity | +| Security proof | 45-60s | `sf-thread-4-security.mp4`, AgentShield evidence, supply-chain gates | Enterprise trust | +| Money/proof clip | 30-45s | `thread-2-ghapp-money.mp4`, `metrics-ticker-2-*`, `gh_app_*.png` | Sponsor, Pro, and partner credibility | +| Coverage/social proof | 30-45s | `coverage-montage-wide.mp4`, `100k.png`, `star_history.png`, `x_analytics.png`, coverage screenshots | Distribution leverage | + +Production steps: + +1. Generate transcripts for the longform and shortform raw clips. +2. Build an edit decision list with hook, proof, demo, business CTA, and final + CTA segments. +3. Cut deterministically with FFmpeg. +4. Add overlays and data motion in Remotion or Manim. +5. Add captions, light color correction, audio normalization, and platform + reframes. +6. Run a self-eval pass for blank frames, bad captions, jump cuts, weak hook, + missing product proof, and stale URLs. +7. Export final MP4s plus the editable timeline/project state. + +## Distribution Plan + +| Channel | Asset | CTA | +| --- | --- | --- | +| GitHub Release | release notes, quickstart, launch video, sponsor link | star, install, sponsor | +| GitHub Discussion | short announcement and proof bullets | questions, feedback, sponsors | +| X | launch thread, 30s install clip, proof clips | repo, sponsor, Pro | +| LinkedIn | partner-friendly product proof, consulting CTA | sponsors, consulting, talks | +| YouTube/Shorts/Reels/TikTok | primary launch video and clips | repo, site, newsletter/community | +| Podcasts/talks | one-page pitch, demo outline, founder proof | bookings, partners | +| Sponsor outbound | direct sponsor note and tier table | GitHub Sponsors or Pro | + +## Copy Rules + +Use direct product language: + +- `ECC 2.0 is the harness-native operator system for agentic work.` +- `One reusable layer across Claude Code, Codex, OpenCode, Cursor, Gemini, Zed, GitHub Copilot, and terminal workflows.` +- `OSS stays free. Sponsors and Pro fund the work.` +- `Use ECC for skills, hooks, rules, MCP conventions, release gates, and operator workflows.` + +Avoid: + +- `we renamed the repo`; +- `pivot`; +- legacy config-pack framing; +- `Claude-only`; +- generic founder-journey language; +- claims about billing, marketplace payments, or official directory listings + before live evidence exists. + +## First Build Order + +1. Land the public repo identity fixes. +2. Refresh package, plugin, workflow, release, and launch-copy URLs. +3. Record final publication evidence from the exact release commit. +4. Produce the video suite manifest and transcripts from existing raw material. +5. Browser-capture the README, ECC Tools app, install flow, and relevant proof + surfaces for b-roll. +6. Render the primary launch video plus five short clips. +7. Finalize GitHub release, X thread, LinkedIn post, Discussion announcement, + sponsor email copy, and podcast/talk pitch. +8. Publish only after npm, plugin, release URL, and billing-readback gates are + either live or explicitly marked blocked. + +## Owner Approvals + +These actions need a human approval or credential before they move: + +- sending annual-upgrade or sponsor emails; +- updating LinkedIn profile text; +- wiring Discord with a bot token and guild ID; +- publishing npm or creating plugin tags; +- announcing billing/native payments; +- posting final social copy from personal accounts. diff --git a/package.json b/package.json index 9add2751..84baea88 100644 --- a/package.json +++ b/package.json @@ -1,7 +1,7 @@ { "name": "ecc-universal", "version": "2.0.0-rc.1", - "description": "Complete collection of battle-tested Claude Code configs — agents, skills, hooks, rules, and legacy command shims evolved over 10+ months of intensive daily use by an Anthropic hackathon winner", + "description": "Harness-native agent operating system for Claude Code, Codex, OpenCode, Cursor, Gemini, and terminal workflows - skills, hooks, rules, MCP conventions, and operator control-plane patterns", "publishConfig": { "access": "public" }, @@ -34,11 +34,11 @@ "license": "MIT", "repository": { "type": "git", - "url": "git+https://github.com/affaan-m/everything-claude-code.git" + "url": "git+https://github.com/affaan-m/ECC.git" }, - "homepage": "https://github.com/affaan-m/everything-claude-code#readme", + "homepage": "https://github.com/affaan-m/ECC#readme", "bugs": { - "url": "https://github.com/affaan-m/everything-claude-code/issues" + "url": "https://github.com/affaan-m/ECC/issues" }, "files": [ ".agents/", @@ -299,7 +299,7 @@ "ecc-install": "scripts/install-apply.js" }, "scripts": { - "postinstall": "echo '\\n ecc-universal installed!\\n Run: npx ecc typescript\\n Compat: npx ecc-install typescript\\n Docs: https://github.com/affaan-m/everything-claude-code\\n'", + "postinstall": "echo '\\n ecc-universal installed!\\n Run: npx ecc typescript\\n Compat: npx ecc-install typescript\\n Docs: https://github.com/affaan-m/ECC\\n'", "catalog:check": "node scripts/ci/catalog.js --text", "catalog:sync": "node scripts/ci/catalog.js --write --text", "command-registry:generate": "node scripts/ci/generate-command-registry.js", diff --git a/tests/docs/ecc2-release-surface.test.js b/tests/docs/ecc2-release-surface.test.js index e1d8bc29..438ccf53 100644 --- a/tests/docs/ecc2-release-surface.test.js +++ b/tests/docs/ecc2-release-surface.test.js @@ -111,12 +111,12 @@ test('business launch copy stays aligned with the rc.1 public surface', () => { 'business launch copy should stay pre-publication until release URLs exist' ); assert.ok( - source.includes('https://github.com/affaan-m/everything-claude-code'), + source.includes('https://github.com/affaan-m/ECC'), 'business launch copy should include the public repo URL' ); assert.ok( source.includes( - 'https://github.com/affaan-m/everything-claude-code/blob/main/docs/releases/2.0.0-rc.1/release-notes.md' + 'https://github.com/affaan-m/ECC/blob/main/docs/releases/2.0.0-rc.1/release-notes.md' ), 'business launch copy should link to the rc.1 release notes' ); @@ -320,15 +320,15 @@ test('release name and plugin publication checklist freezes rc.1 surfaces', () = const referenceArchitecture = read('docs/ECC-2.0-REFERENCE-ARCHITECTURE.md'); for (const value of [ - 'Everything Claude Code (ECC)', - '`affaan-m/everything-claude-code`', + 'Ship `v2.0.0-rc.1` as **ECC**', + '`affaan-m/ECC`', '`ecc-universal`', '`ecc` on npm is occupied', '`@affaan-m/ecc` is unclaimed on npm', 'Claude plugin', 'Codex plugin', 'do not claim official directory listing until OpenAI publishing path is available', - 'Do not rename the repo or package until rc.1 is published', + 'Do not rename the npm package until rc.1 is published', 'Do not announce billing, Marketplace, or native payments', ]) { assert.ok(checklist.includes(value), `release name/plugin checklist missing ${value}`); From af9b2c1c4ce6acec0ab341cb7174f15a348d9b8e Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 06:20:54 -0400 Subject: [PATCH 29/61] feat: extend harness audit integration scoring (#1990) Salvages the useful harness-audit scoring work from #1989 while preserving the current hook registry and newer plugin install detection. Adds GitHub integration checks, conditional deploy-provider categories, dynamic applicable category metadata, and CODEOWNERS coverage. --- .github/CODEOWNERS | 1 + .opencode/commands/harness-audit.md | 27 ++-- commands/harness-audit.md | 27 ++-- scripts/harness-audit.js | 215 +++++++++++++++++++++++++++- tests/scripts/harness-audit.test.js | 194 ++++++++++++++++++++++++- 5 files changed, 441 insertions(+), 23 deletions(-) create mode 100644 .github/CODEOWNERS diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS new file mode 100644 index 00000000..5b92bc5f --- /dev/null +++ b/.github/CODEOWNERS @@ -0,0 +1 @@ +* @affaan-m diff --git a/.opencode/commands/harness-audit.md b/.opencode/commands/harness-audit.md index 108042ce..fc36601a 100644 --- a/.opencode/commands/harness-audit.md +++ b/.opencode/commands/harness-audit.md @@ -24,9 +24,9 @@ node scripts/harness-audit.js --format [--root ] This script is the source of truth for scoring and checks. Do not invent additional dimensions or ad-hoc points. -Rubric version: `2026-03-30`. +Rubric version: `2026-05-19`. -The script computes 7 fixed categories (`0-10` normalized each): +The script computes up to 12 fixed categories (`0-10` normalized each). The first seven are always applicable; GitHub Integration is always applicable; deploy-target categories are applicable only when a matching marker is detected. 1. Tool Coverage 2. Context Efficiency @@ -35,6 +35,11 @@ The script computes 7 fixed categories (`0-10` normalized each): 5. Eval Coverage 6. Security Guardrails 7. Cost Efficiency +8. GitHub Integration +9. Vercel Integration *(when `vercel.json` or `.vercel/` is present)* +10. Netlify Integration *(when `netlify.toml` or `.netlify/` is present)* +11. Cloudflare Integration *(when `wrangler.toml` or `wrangler.jsonc` is present)* +12. Fly Integration *(when `fly.toml` is present)* Scores are derived from explicit file/rule checks and are reproducible for the same commit. The script audits the current working directory by default and auto-detects whether the target is the ECC repo itself or a consumer project using ECC. @@ -43,11 +48,12 @@ The script audits the current working directory by default and auto-detects whet Return: -1. `overall_score` out of `max_score` (70 for `repo`; smaller for scoped audits) -2. Category scores and concrete findings -3. Failed checks with exact file paths -4. Top 3 actions from the deterministic output (`top_actions`) -5. Suggested ECC skills to apply next +1. `overall_score` out of `max_score`. `max_score` depends on which categories are applicable to the target; never assume a fixed total. +2. `applicable_categories[]` and `category_count` describing which categories contributed. +3. Category scores and concrete findings. +4. Failed checks with exact file paths. +5. Top 3 actions from the deterministic output (`top_actions`). +6. Suggested ECC skills to apply next. ## Checklist @@ -59,14 +65,15 @@ Return: ## Example Result ```text -Harness Audit (repo): 66/70 +Harness Audit (repo, repo): 71/80 - Tool Coverage: 10/10 (10/10 pts) - Context Efficiency: 9/10 (9/10 pts) - Quality Gates: 10/10 (10/10 pts) +- GitHub Integration: 2/10 (2/10 pts) Top 3 Actions: -1) [Security Guardrails] Add prompt/tool preflight security guards in hooks/hooks.json. (hooks/hooks.json) -2) [Tool Coverage] Sync commands/harness-audit.md and .opencode/commands/harness-audit.md. (.opencode/commands/harness-audit.md) +1) [GitHub Integration] Add at least one workflow under .github/workflows/. (.github/workflows/) +2) [Security Guardrails] Add prompt/tool preflight security guards in hooks/hooks.json. (hooks/hooks.json) 3) [Eval Coverage] Increase automated test coverage across scripts/hooks/lib. (tests/) ``` diff --git a/commands/harness-audit.md b/commands/harness-audit.md index 108042ce..fc36601a 100644 --- a/commands/harness-audit.md +++ b/commands/harness-audit.md @@ -24,9 +24,9 @@ node scripts/harness-audit.js --format [--root ] This script is the source of truth for scoring and checks. Do not invent additional dimensions or ad-hoc points. -Rubric version: `2026-03-30`. +Rubric version: `2026-05-19`. -The script computes 7 fixed categories (`0-10` normalized each): +The script computes up to 12 fixed categories (`0-10` normalized each). The first seven are always applicable; GitHub Integration is always applicable; deploy-target categories are applicable only when a matching marker is detected. 1. Tool Coverage 2. Context Efficiency @@ -35,6 +35,11 @@ The script computes 7 fixed categories (`0-10` normalized each): 5. Eval Coverage 6. Security Guardrails 7. Cost Efficiency +8. GitHub Integration +9. Vercel Integration *(when `vercel.json` or `.vercel/` is present)* +10. Netlify Integration *(when `netlify.toml` or `.netlify/` is present)* +11. Cloudflare Integration *(when `wrangler.toml` or `wrangler.jsonc` is present)* +12. Fly Integration *(when `fly.toml` is present)* Scores are derived from explicit file/rule checks and are reproducible for the same commit. The script audits the current working directory by default and auto-detects whether the target is the ECC repo itself or a consumer project using ECC. @@ -43,11 +48,12 @@ The script audits the current working directory by default and auto-detects whet Return: -1. `overall_score` out of `max_score` (70 for `repo`; smaller for scoped audits) -2. Category scores and concrete findings -3. Failed checks with exact file paths -4. Top 3 actions from the deterministic output (`top_actions`) -5. Suggested ECC skills to apply next +1. `overall_score` out of `max_score`. `max_score` depends on which categories are applicable to the target; never assume a fixed total. +2. `applicable_categories[]` and `category_count` describing which categories contributed. +3. Category scores and concrete findings. +4. Failed checks with exact file paths. +5. Top 3 actions from the deterministic output (`top_actions`). +6. Suggested ECC skills to apply next. ## Checklist @@ -59,14 +65,15 @@ Return: ## Example Result ```text -Harness Audit (repo): 66/70 +Harness Audit (repo, repo): 71/80 - Tool Coverage: 10/10 (10/10 pts) - Context Efficiency: 9/10 (9/10 pts) - Quality Gates: 10/10 (10/10 pts) +- GitHub Integration: 2/10 (2/10 pts) Top 3 Actions: -1) [Security Guardrails] Add prompt/tool preflight security guards in hooks/hooks.json. (hooks/hooks.json) -2) [Tool Coverage] Sync commands/harness-audit.md and .opencode/commands/harness-audit.md. (.opencode/commands/harness-audit.md) +1) [GitHub Integration] Add at least one workflow under .github/workflows/. (.github/workflows/) +2) [Security Guardrails] Add prompt/tool preflight security guards in hooks/hooks.json. (hooks/hooks.json) 3) [Eval Coverage] Increase automated test coverage across scripts/hooks/lib. (tests/) ``` diff --git a/scripts/harness-audit.js b/scripts/harness-audit.js index 79bc57c8..3e525ca7 100644 --- a/scripts/harness-audit.js +++ b/scripts/harness-audit.js @@ -12,8 +12,53 @@ const CATEGORIES = [ 'Eval Coverage', 'Security Guardrails', 'Cost Efficiency', + 'GitHub Integration', + 'Vercel Integration', + 'Netlify Integration', + 'Cloudflare Integration', + 'Fly Integration', ]; +const RUBRIC_VERSION = '2026-05-19'; + +const PROVIDERS = { + Vercel: { + detect: (rootDir) => + fileExists(rootDir, 'vercel.json') || + fileExists(rootDir, '.vercel/project.json') || + fileExists(rootDir, '.vercel'), + keyPattern: /vercel/i, + buildPattern: /vercel/i, + workflowPattern: /(vercel-action|vercel\s+(deploy|--prod))/i, + }, + Netlify: { + detect: (rootDir) => + fileExists(rootDir, 'netlify.toml') || fileExists(rootDir, '.netlify'), + keyPattern: /netlify/i, + buildPattern: /netlify/i, + workflowPattern: /(netlify\/actions|netlify\s+deploy)/i, + }, + Cloudflare: { + detect: (rootDir) => + fileExists(rootDir, 'wrangler.toml') || fileExists(rootDir, 'wrangler.jsonc'), + keyPattern: /\b(cloudflare|wrangler)\b/i, + buildPattern: /(wrangler|cloudflare)/i, + workflowPattern: /(cloudflare\/wrangler-action|wrangler\s+(deploy|publish))/i, + }, + Fly: { + detect: (rootDir) => fileExists(rootDir, 'fly.toml'), + keyPattern: /fly[_-]?(api|io)/i, + buildPattern: /fly\s+(deploy|launch)/i, + workflowPattern: /(superfly\/flyctl-actions|flyctl\s+deploy|fly\s+deploy)/i, + }, +}; + +function getApplicableProviders(rootDir) { + return Object.entries(PROVIDERS) + .filter(([_, spec]) => spec.detect(rootDir)) + .map(([name]) => name); +} + function normalizeScope(scope) { const value = (scope || 'repo').toLowerCase(); if (!['repo', 'hooks', 'skills', 'commands', 'agents'].includes(value)) { @@ -607,9 +652,172 @@ function getRepoChecks(rootDir) { pass: fileExists(rootDir, 'commands/model-route.md'), fix: 'Add commands/model-route.md and route policies for cheap-default execution.', }, + ...buildGithubChecks(rootDir), ]; } +// GitHub Integration is intentionally repo-scoped. Scoped audits such as hooks, +// skills, commands, and agents should keep reporting only that surface. +function buildGithubChecks(rootDir) { + return [ + { + id: 'github-workflows', + category: 'GitHub Integration', + points: 3, + scopes: ['repo'], + path: '.github/workflows/', + description: 'GitHub Actions workflows are checked in', + pass: hasFileWithExtension(rootDir, '.github/workflows', ['.yml', '.yaml']), + fix: 'Add at least one workflow under .github/workflows/ so CI runs on every PR.', + }, + { + id: 'github-pr-template', + category: 'GitHub Integration', + points: 2, + scopes: ['repo'], + path: '.github/PULL_REQUEST_TEMPLATE.md', + description: 'A pull request template is configured', + pass: + fileExists(rootDir, '.github/PULL_REQUEST_TEMPLATE.md') || + fileExists(rootDir, '.github/pull_request_template.md'), + fix: 'Add .github/PULL_REQUEST_TEMPLATE.md so PR descriptions follow a consistent shape.', + }, + { + id: 'github-issue-templates', + category: 'GitHub Integration', + points: 2, + scopes: ['repo'], + path: '.github/ISSUE_TEMPLATE/', + description: 'Issue templates are configured', + pass: hasFileWithExtension(rootDir, '.github/ISSUE_TEMPLATE', ['.md', '.yml', '.yaml']), + fix: 'Add at least one issue template under .github/ISSUE_TEMPLATE/.', + }, + { + id: 'github-codeowners', + category: 'GitHub Integration', + points: 1, + scopes: ['repo'], + path: '.github/CODEOWNERS', + description: 'A CODEOWNERS file routes reviews', + pass: + fileExists(rootDir, 'CODEOWNERS') || + fileExists(rootDir, '.github/CODEOWNERS') || + fileExists(rootDir, 'docs/CODEOWNERS'), + fix: 'Add a CODEOWNERS file so PRs auto-request the right reviewers.', + }, + { + id: 'github-dep-updates', + category: 'GitHub Integration', + points: 2, + scopes: ['repo'], + path: '.github/dependabot.yml', + description: 'Automated dependency updates are configured', + pass: + fileExists(rootDir, '.github/dependabot.yml') || + fileExists(rootDir, '.github/dependabot.yaml') || + fileExists(rootDir, 'renovate.json') || + fileExists(rootDir, '.github/renovate.json') || + fileExists(rootDir, '.renovaterc'), + fix: 'Add a Dependabot or Renovate config so dependency updates land automatically.', + }, + ]; +} + +function readAllWorkflowsText(rootDir) { + const dir = path.join(rootDir, '.github/workflows'); + if (!fs.existsSync(dir)) { + return ''; + } + + const stack = [dir]; + let combined = ''; + + while (stack.length > 0) { + const current = stack.pop(); + const entries = fs.readdirSync(current, { withFileTypes: true }); + + for (const entry of entries) { + const nextPath = path.join(current, entry.name); + if (entry.isDirectory()) { + stack.push(nextPath); + } else if (entry.name.endsWith('.yml') || entry.name.endsWith('.yaml')) { + try { + combined += `${fs.readFileSync(nextPath, 'utf8')}\n`; + } catch (_error) { + // Ignore unreadable workflow files; the finding should stay deterministic. + } + } + } + } + + return combined; +} + +function buildProviderChecks(rootDir, provider, sharedContext) { + const spec = PROVIDERS[provider]; + const packageJson = sharedContext.packageJson || {}; + const scriptsText = Object.values(packageJson.scripts || {}).join('\n'); + const category = `${provider} Integration`; + + return [ + { + id: `${provider.toLowerCase()}-config`, + category, + points: 3, + scopes: ['repo'], + path: `${provider} config`, + description: `${provider} deployment config is checked in`, + pass: spec.detect(rootDir), + fix: `Commit ${provider} configuration so deploys are reproducible from source.`, + }, + { + id: `${provider.toLowerCase()}-build-script`, + category, + points: 2, + scopes: ['repo'], + path: 'package.json scripts', + description: `package.json scripts reference ${provider}`, + pass: spec.buildPattern.test(scriptsText), + fix: `Add a build or deploy script in package.json that runs ${provider}.`, + }, + { + id: `${provider.toLowerCase()}-env-doc`, + category, + points: 2, + scopes: ['repo'], + path: '.env.example', + description: `${provider} env keys are documented in .env.example`, + pass: spec.keyPattern.test(sharedContext.envExample), + fix: `Document ${provider} environment variables in .env.example.`, + }, + { + id: `${provider.toLowerCase()}-workflow-uses`, + category, + points: 3, + scopes: ['repo'], + path: '.github/workflows/', + description: `A GitHub workflow uses the ${provider} action or CLI`, + pass: spec.workflowPattern.test(sharedContext.workflowsText), + fix: `Reference the ${provider} action or CLI from a workflow under .github/workflows/.`, + }, + ]; +} + +function collectProviderChecks(rootDir, packageJson) { + const providers = getApplicableProviders(rootDir); + if (providers.length === 0) { + return []; + } + + const sharedContext = { + packageJson: packageJson || {}, + envExample: `${safeRead(rootDir, '.env.example')}\n${safeRead(rootDir, '.env.sample')}`, + workflowsText: readAllWorkflowsText(rootDir), + }; + + return providers.flatMap(provider => buildProviderChecks(rootDir, provider, sharedContext)); +} + function getConsumerChecks(rootDir) { const packageJson = safeParseJson(safeRead(rootDir, 'package.json')); const gitignore = safeRead(rootDir, '.gitignore'); @@ -731,6 +939,8 @@ function getConsumerChecks(rootDir) { pass: projectHooks.includes('PreToolUse') || projectHooks.includes('beforeSubmitPrompt') || fileExists(rootDir, '.claude/hooks.json'), fix: 'Add project-local hook settings or hook definitions for prompt/tool guardrails.', }, + ...buildGithubChecks(rootDir), + ...collectProviderChecks(rootDir, packageJson), ]; } @@ -764,6 +974,7 @@ function buildReport(scope, options = {}) { const overallScore = checks .filter(check => check.pass) .reduce((sum, check) => sum + check.points, 0); + const applicableCategories = CATEGORIES.filter(name => categoryScores[name]?.max > 0); const failedChecks = checks.filter(check => !check.pass); const topActions = failedChecks @@ -781,10 +992,12 @@ function buildReport(scope, options = {}) { root_dir: rootDir, target_mode: targetMode, deterministic: true, - rubric_version: '2026-03-30', + rubric_version: RUBRIC_VERSION, overall_score: overallScore, max_score: maxScore, categories: categoryScores, + applicable_categories: applicableCategories, + category_count: applicableCategories.length, checks: checks.map(check => ({ id: check.id, category: check.category, diff --git a/tests/scripts/harness-audit.test.js b/tests/scripts/harness-audit.test.js index 685200e3..c0087475 100644 --- a/tests/scripts/harness-audit.test.js +++ b/tests/scripts/harness-audit.test.js @@ -126,7 +126,7 @@ function runTests() { const parsed = JSON.parse(run(['repo', '--format', 'json'])); assert.strictEqual(parsed.deterministic, true); - assert.strictEqual(parsed.rubric_version, '2026-03-30'); + assert.strictEqual(parsed.rubric_version, '2026-05-19'); assert.strictEqual(parsed.target_mode, 'repo'); assert.ok(parsed.overall_score >= 0); assert.ok(parsed.max_score > 0); @@ -140,6 +140,192 @@ function runTests() { assert.ok(categoryNames.includes('Eval Coverage')); assert.ok(categoryNames.includes('Security Guardrails')); assert.ok(categoryNames.includes('Cost Efficiency')); + assert.ok(categoryNames.includes('GitHub Integration')); + })) passed++; else failed++; + + if (test('report exposes applicable_categories and category_count', () => { + const parsed = JSON.parse(run(['repo', '--format', 'json'])); + + assert.ok(Array.isArray(parsed.applicable_categories), 'applicable_categories must be an array'); + assert.ok(parsed.applicable_categories.length > 0); + assert.strictEqual(parsed.category_count, parsed.applicable_categories.length); + for (const name of parsed.applicable_categories) { + assert.ok(parsed.categories[name].max > 0, `${name} must have max > 0 to be applicable`); + } + })) passed++; else failed++; + + if (test('GitHub Integration category scores against a fully-wired consumer fixture', () => { + const homeDir = createTempDir('harness-audit-home-gh-'); + const projectRoot = createTempDir('harness-audit-project-gh-'); + + try { + fs.mkdirSync(path.join(homeDir, '.claude', 'plugins', 'ecc', '.claude-plugin'), { recursive: true }); + fs.writeFileSync( + path.join(homeDir, '.claude', 'plugins', 'ecc', '.claude-plugin', 'plugin.json'), + JSON.stringify({ name: 'ecc' }, null, 2) + ); + + fs.mkdirSync(path.join(projectRoot, '.github', 'workflows'), { recursive: true }); + fs.mkdirSync(path.join(projectRoot, '.github', 'ISSUE_TEMPLATE'), { recursive: true }); + fs.writeFileSync(path.join(projectRoot, '.github', 'workflows', 'ci.yml'), 'name: ci\n'); + fs.writeFileSync(path.join(projectRoot, '.github', 'PULL_REQUEST_TEMPLATE.md'), '# PR\n'); + fs.writeFileSync(path.join(projectRoot, '.github', 'ISSUE_TEMPLATE', 'bug.md'), '# Bug\n'); + fs.writeFileSync(path.join(projectRoot, '.github', 'CODEOWNERS'), '* @owner\n'); + fs.writeFileSync(path.join(projectRoot, '.github', 'dependabot.yml'), 'version: 2\n'); + fs.writeFileSync(path.join(projectRoot, 'package.json'), JSON.stringify({ name: 'gh-test' })); + + const parsed = JSON.parse(run(['repo', '--format', 'json'], { cwd: projectRoot, homeDir })); + const github = parsed.categories['GitHub Integration']; + + assert.ok(github, 'GitHub Integration category must exist'); + assert.strictEqual(github.score, 10, `GitHub Integration should score 10/10, got ${github.score}`); + assert.strictEqual(github.earned, github.max); + assert.ok(parsed.applicable_categories.includes('GitHub Integration')); + } finally { + cleanup(homeDir); + cleanup(projectRoot); + } + })) passed++; else failed++; + + if (test('provider categories are omitted unless a marker is present', () => { + const homeDir = createTempDir('harness-audit-home-no-provider-'); + const projectRoot = createTempDir('harness-audit-project-no-provider-'); + + try { + fs.mkdirSync(path.join(homeDir, '.claude', 'plugins', 'ecc', '.claude-plugin'), { recursive: true }); + fs.writeFileSync( + path.join(homeDir, '.claude', 'plugins', 'ecc', '.claude-plugin', 'plugin.json'), + JSON.stringify({ name: 'ecc' }, null, 2) + ); + fs.writeFileSync(path.join(projectRoot, 'package.json'), JSON.stringify({ name: 'p' })); + + const parsed = JSON.parse(run(['repo', '--format', 'json'], { cwd: projectRoot, homeDir })); + + assert.ok(!parsed.applicable_categories.includes('Vercel Integration')); + const vercel = parsed.categories['Vercel Integration']; + assert.ok(!vercel || vercel.max === 0, 'Vercel Integration should not contribute when no marker'); + } finally { + cleanup(homeDir); + cleanup(projectRoot); + } + })) passed++; else failed++; + + if (test('Vercel Integration category scores when vercel.json present', () => { + const homeDir = createTempDir('harness-audit-home-vercel-'); + const projectRoot = createTempDir('harness-audit-project-vercel-'); + + try { + fs.mkdirSync(path.join(homeDir, '.claude', 'plugins', 'ecc', '.claude-plugin'), { recursive: true }); + fs.writeFileSync( + path.join(homeDir, '.claude', 'plugins', 'ecc', '.claude-plugin', 'plugin.json'), + JSON.stringify({ name: 'ecc' }, null, 2) + ); + + fs.mkdirSync(path.join(projectRoot, '.github', 'workflows'), { recursive: true }); + fs.writeFileSync(path.join(projectRoot, 'vercel.json'), '{}\n'); + fs.writeFileSync(path.join(projectRoot, '.env.example'), 'VERCEL_TOKEN=\n'); + fs.writeFileSync(path.join(projectRoot, '.github', 'workflows', 'deploy.yml'), 'uses: amondnet/vercel-action@v25\n'); + fs.writeFileSync( + path.join(projectRoot, 'package.json'), + JSON.stringify({ name: 'p', scripts: { build: 'next build', deploy: 'vercel deploy' } }) + ); + + const parsed = JSON.parse(run(['repo', '--format', 'json'], { cwd: projectRoot, homeDir })); + const vercel = parsed.categories['Vercel Integration']; + + assert.ok(vercel, 'Vercel Integration category must exist when vercel.json present'); + assert.ok(vercel.max > 0); + assert.ok(parsed.applicable_categories.includes('Vercel Integration')); + assert.strictEqual(vercel.score, 10, `Vercel should score 10/10 with full wiring, got ${vercel.score}`); + } finally { + cleanup(homeDir); + cleanup(projectRoot); + } + })) passed++; else failed++; + + if (test('detector map: Netlify, Cloudflare, Fly each trigger their category', () => { + const homeDir = createTempDir('harness-audit-home-multi-'); + + function probe(markerFile, markerContents, expectedCategory) { + const root = createTempDir('harness-audit-project-multi-'); + try { + fs.writeFileSync(path.join(root, 'package.json'), JSON.stringify({ name: 'p' })); + fs.writeFileSync(path.join(root, markerFile), markerContents); + const parsed = JSON.parse(run(['repo', '--format', 'json'], { cwd: root, homeDir })); + assert.ok( + parsed.applicable_categories.includes(expectedCategory), + `${markerFile} should activate ${expectedCategory}` + ); + } finally { + cleanup(root); + } + } + + try { + fs.mkdirSync(path.join(homeDir, '.claude', 'plugins', 'ecc', '.claude-plugin'), { recursive: true }); + fs.writeFileSync( + path.join(homeDir, '.claude', 'plugins', 'ecc', '.claude-plugin', 'plugin.json'), + JSON.stringify({ name: 'ecc' }, null, 2) + ); + + probe('netlify.toml', '[build]\n', 'Netlify Integration'); + probe('wrangler.toml', 'name = "p"\n', 'Cloudflare Integration'); + probe('fly.toml', 'app = "p"\n', 'Fly Integration'); + } finally { + cleanup(homeDir); + } + })) passed++; else failed++; + + if (test('max_score reflects only applicable categories', () => { + const homeDir = createTempDir('harness-audit-home-max-'); + const noVercel = createTempDir('harness-audit-project-max-novercel-'); + const withVercel = createTempDir('harness-audit-project-max-vercel-'); + + try { + fs.mkdirSync(path.join(homeDir, '.claude', 'plugins', 'ecc', '.claude-plugin'), { recursive: true }); + fs.writeFileSync( + path.join(homeDir, '.claude', 'plugins', 'ecc', '.claude-plugin', 'plugin.json'), + JSON.stringify({ name: 'ecc' }, null, 2) + ); + + fs.writeFileSync(path.join(noVercel, 'package.json'), JSON.stringify({ name: 'p' })); + fs.writeFileSync(path.join(withVercel, 'package.json'), JSON.stringify({ name: 'p' })); + fs.writeFileSync(path.join(withVercel, 'vercel.json'), '{}\n'); + + const noVercelParsed = JSON.parse(run(['repo', '--format', 'json'], { cwd: noVercel, homeDir })); + const withVercelParsed = JSON.parse(run(['repo', '--format', 'json'], { cwd: withVercel, homeDir })); + + assert.ok( + withVercelParsed.max_score > noVercelParsed.max_score, + `with-vercel max_score (${withVercelParsed.max_score}) should exceed no-vercel (${noVercelParsed.max_score})` + ); + } finally { + cleanup(homeDir); + cleanup(noVercel); + cleanup(withVercel); + } + })) passed++; else failed++; + + if (test('non-git directory does not crash the script', () => { + const homeDir = createTempDir('harness-audit-home-bare-'); + const bare = createTempDir('harness-audit-project-bare-'); + + try { + fs.mkdirSync(path.join(homeDir, '.claude', 'plugins', 'ecc', '.claude-plugin'), { recursive: true }); + fs.writeFileSync( + path.join(homeDir, '.claude', 'plugins', 'ecc', '.claude-plugin', 'plugin.json'), + JSON.stringify({ name: 'ecc' }, null, 2) + ); + fs.writeFileSync(path.join(bare, 'package.json'), JSON.stringify({ name: 'p' })); + + const output = run(['repo', '--format', 'json'], { cwd: bare, homeDir }); + const parsed = JSON.parse(output); + assert.ok(parsed.overall_score >= 0); + assert.ok(parsed.max_score > 0); + } finally { + cleanup(homeDir); + cleanup(bare); + } })) passed++; else failed++; if (test('scope filtering changes max score and check list', () => { @@ -251,6 +437,7 @@ function runTests() { ); fs.mkdirSync(path.join(projectRoot, '.claude'), { recursive: true }); fs.mkdirSync(path.join(projectRoot, '.github', 'workflows', 'nested'), { recursive: true }); + fs.mkdirSync(path.join(projectRoot, '.github', 'ISSUE_TEMPLATE'), { recursive: true }); fs.mkdirSync(path.join(projectRoot, 'docs', 'adr'), { recursive: true }); fs.mkdirSync(path.join(projectRoot, 'evals'), { recursive: true }); fs.mkdirSync(path.join(projectRoot, 'src'), { recursive: true }); @@ -259,6 +446,9 @@ function runTests() { fs.writeFileSync(path.join(projectRoot, 'CLAUDE.md'), '# Consumer instructions\n'); fs.writeFileSync(path.join(projectRoot, 'src', 'app.spec.ts'), 'test placeholder\n'); fs.writeFileSync(path.join(projectRoot, '.github', 'workflows', 'nested', 'ci.yaml'), 'name: ci\n'); + fs.writeFileSync(path.join(projectRoot, '.github', 'PULL_REQUEST_TEMPLATE.md'), '# PR\n'); + fs.writeFileSync(path.join(projectRoot, '.github', 'ISSUE_TEMPLATE', 'bug.md'), '# Bug\n'); + fs.writeFileSync(path.join(projectRoot, '.github', 'CODEOWNERS'), '* @owner\n'); fs.writeFileSync(path.join(projectRoot, 'docs', 'adr', '001.md'), '# Record\n'); fs.writeFileSync(path.join(projectRoot, 'evals', 'smoke.json'), '{}\n'); fs.writeFileSync(path.join(projectRoot, '.github', 'dependabot.yml'), 'version: 2\n'); @@ -274,7 +464,7 @@ function runTests() { const text = run(['repo'], { cwd: projectRoot, homeDir }); assert.ok(text.includes(`Harness Audit (repo, consumer): ${parsed.max_score}/${parsed.max_score}`)); - assert.ok(text.includes('Checks: 11 total, 0 failing')); + assert.ok(text.includes('Checks: 16 total, 0 failing')); assert.ok(!text.includes('Top 3 Actions:')); const scopedText = run(['agents'], { cwd: projectRoot, homeDir }); From 8141f6904f14fa8a83131e1cb5b6507d687e25bb Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 06:42:17 -0400 Subject: [PATCH 30/61] chore: gate canonical ECC release identity (#1991) --- .agents/plugins/marketplace.json | 2 +- .codex-plugin/README.md | 6 +-- .codex-plugin/plugin.json | 8 +-- .opencode/MIGRATION.md | 4 +- .opencode/README.md | 8 +-- .opencode/index.ts | 8 +-- .opencode/instructions/INSTRUCTIONS.md | 2 +- .opencode/package.json | 8 +-- .opencode/plugins/ecc-hooks.ts | 4 +- .opencode/plugins/index.ts | 2 +- README.md | 8 +-- agent.yaml | 2 +- docs/business/metrics-and-sponsorship.md | 6 +-- .../naming-and-publication-matrix.md | 50 ++++++++---------- .../2.0.0-rc.1/preview-pack-manifest.md | 4 +- .../2.0.0-rc.1/publication-readiness.md | 16 +++--- docs/releases/2.0.0-rc.1/quickstart.md | 4 +- docs/releases/2.0.0-rc.1/release-notes.md | 2 +- .../release-url-ledger-2026-05-19.md | 51 +++++++++++++++++++ docs/releases/2.0.0-rc.1/x-thread.md | 8 +-- ecc2/Cargo.toml | 2 +- scripts/discussion-audit.js | 2 +- scripts/ecc.js | 2 +- scripts/operator-readiness-dashboard.js | 7 +-- scripts/platform-audit.js | 2 +- scripts/preview-pack-smoke.js | 2 +- tests/docs/ecc2-release-surface.test.js | 32 ++++++++++++ tests/plugin-manifest.test.js | 16 +++++- tests/scripts/discussion-audit.test.js | 18 +++---- .../operator-readiness-dashboard.test.js | 9 ++-- tests/scripts/platform-audit.test.js | 24 ++++----- 31 files changed, 206 insertions(+), 113 deletions(-) create mode 100644 docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md diff --git a/.agents/plugins/marketplace.json b/.agents/plugins/marketplace.json index c1ac48aa..7c1d7e30 100644 --- a/.agents/plugins/marketplace.json +++ b/.agents/plugins/marketplace.json @@ -1,7 +1,7 @@ { "name": "ecc", "interface": { - "displayName": "Everything Claude Code" + "displayName": "ECC" }, "plugins": [ { diff --git a/.codex-plugin/README.md b/.codex-plugin/README.md index 14f1687d..ef850ca3 100644 --- a/.codex-plugin/README.md +++ b/.codex-plugin/README.md @@ -1,6 +1,6 @@ # .codex-plugin — Codex Native Plugin for ECC -This directory contains the **Codex plugin manifest** for Everything Claude Code. +This directory contains the **Codex plugin manifest** for ECC. ## Structure @@ -24,10 +24,10 @@ track that marketplace source from the CLI: ```bash # Add the public repo marketplace -codex plugin marketplace add affaan-m/everything-claude-code +codex plugin marketplace add affaan-m/ECC # Or add a local checkout while developing -codex plugin marketplace add /absolute/path/to/everything-claude-code +codex plugin marketplace add /absolute/path/to/ECC ``` The marketplace entry points at the repository root so `.codex-plugin/plugin.json`, diff --git a/.codex-plugin/plugin.json b/.codex-plugin/plugin.json index 63616987..e512e8b0 100644 --- a/.codex-plugin/plugin.json +++ b/.codex-plugin/plugin.json @@ -1,22 +1,22 @@ { "name": "ecc", "version": "2.0.0-rc.1", - "description": "Battle-tested Codex workflows — 207 shared ECC skills, production-ready MCP configs, and selective-install-aligned conventions for TDD, security scanning, code review, and autonomous development.", + "description": "Harness-native ECC workflows for Codex: shared skills, production-ready MCP configs, and selective-install-aligned conventions for TDD, security scanning, code review, and autonomous development.", "author": { "name": "Affaan Mustafa", "email": "me@affaanmustafa.com", "url": "https://x.com/affaanmustafa" }, "homepage": "https://ecc.tools", - "repository": "https://github.com/affaan-m/everything-claude-code", + "repository": "https://github.com/affaan-m/ECC", "license": "MIT", "keywords": ["codex", "agents", "skills", "tdd", "code-review", "security", "workflow", "automation"], "skills": "./skills/", "mcpServers": "./.mcp.json", "interface": { - "displayName": "Everything Claude Code", + "displayName": "ECC", "shortDescription": "207 battle-tested ECC skills plus MCP configs for TDD, security, code review, and autonomous development.", - "longDescription": "Everything Claude Code (ECC) is a community-maintained collection of Codex-ready skills and MCP configs evolved over 10+ months of intensive daily use. It covers TDD workflows, security scanning, code review, architecture decisions, operator workflows, and more — all in one installable plugin.", + "longDescription": "ECC is a harness-native operator system for Codex and adjacent agent harnesses. It packages reusable skills, MCP configs, TDD workflows, security scanning, code review, architecture decisions, operator workflows, and release gates in one installable plugin.", "developerName": "Affaan Mustafa", "category": "Productivity", "capabilities": ["Read", "Write"], diff --git a/.opencode/MIGRATION.md b/.opencode/MIGRATION.md index f967ec1d..c727e4df 100644 --- a/.opencode/MIGRATION.md +++ b/.opencode/MIGRATION.md @@ -1,6 +1,6 @@ # Migration Guide: Claude Code to OpenCode -This guide helps you migrate from Claude Code to OpenCode while using the Everything Claude Code (ECC) configuration. +This guide helps you migrate from Claude Code to OpenCode while using the ECC configuration. ## Overview @@ -365,4 +365,4 @@ If you need to switch back: For issues specific to: - **OpenCode CLI**: Report to OpenCode's issue tracker -- **ECC Configuration**: Report to [github.com/affaan-m/everything-claude-code](https://github.com/affaan-m/everything-claude-code) +- **ECC Configuration**: Report to [github.com/affaan-m/ECC](https://github.com/affaan-m/ECC) diff --git a/.opencode/README.md b/.opencode/README.md index 170a8459..6fe4657f 100644 --- a/.opencode/README.md +++ b/.opencode/README.md @@ -3,13 +3,13 @@ > WARNING: This README is specific to OpenCode usage. > If you installed ECC via npm (e.g. `npm install opencode-ecc`), refer to the root README instead. -Everything Claude Code (ECC) plugin for OpenCode - agents, commands, hooks, and skills. +ECC plugin for OpenCode - agents, commands, hooks, and skills. ## Installation ## Installation Overview -There are two ways to use Everything Claude Code (ECC): +There are two ways to use ECC: 1. **npm package (recommended for most users)** Install via npm/bun/yarn and use the `ecc-install` CLI to set up rules and agents. @@ -52,8 +52,8 @@ npx ecc-install typescript Clone and run OpenCode in the repository: ```bash -git clone https://github.com/affaan-m/everything-claude-code -cd everything-claude-code +git clone https://github.com/affaan-m/ECC +cd ECC opencode ``` diff --git a/.opencode/index.ts b/.opencode/index.ts index 8ff13a0a..9bb5bf0c 100644 --- a/.opencode/index.ts +++ b/.opencode/index.ts @@ -1,5 +1,5 @@ /** - * Everything Claude Code (ECC) Plugin for OpenCode + * ECC Plugin for OpenCode * * This package provides the published ECC OpenCode plugin module: * - Plugin hooks (auto-format, TypeScript check, console.log warning, env injection, etc.) @@ -26,8 +26,8 @@ * * Option 2: Clone and use directly * ```bash - * git clone https://github.com/affaan-m/everything-claude-code - * cd everything-claude-code + * git clone https://github.com/affaan-m/ECC + * cd ECC * opencode * ``` * @@ -47,7 +47,7 @@ export const VERSION = "1.6.0" export const metadata = { name: "ecc-universal", version: VERSION, - description: "Everything Claude Code plugin for OpenCode", + description: "ECC plugin for OpenCode", author: "affaan-m", features: { agents: 13, diff --git a/.opencode/instructions/INSTRUCTIONS.md b/.opencode/instructions/INSTRUCTIONS.md index 488b2a66..64d9d1d8 100644 --- a/.opencode/instructions/INSTRUCTIONS.md +++ b/.opencode/instructions/INSTRUCTIONS.md @@ -1,4 +1,4 @@ -# Everything Claude Code - OpenCode Instructions +# ECC - OpenCode Instructions This document consolidates the core rules and guidelines from the Claude Code configuration for use with OpenCode. diff --git a/.opencode/package.json b/.opencode/package.json index ee99154b..f343e56d 100644 --- a/.opencode/package.json +++ b/.opencode/package.json @@ -1,7 +1,7 @@ { "name": "ecc-universal", "version": "2.0.0-rc.1", - "description": "Everything Claude Code (ECC) plugin for OpenCode - agents, commands, hooks, and skills", + "description": "ECC plugin for OpenCode - agents, commands, hooks, and skills", "main": "dist/index.js", "types": "dist/index.d.ts", "type": "module", @@ -47,12 +47,12 @@ "license": "MIT", "repository": { "type": "git", - "url": "git+https://github.com/affaan-m/everything-claude-code.git" + "url": "git+https://github.com/affaan-m/ECC.git" }, "bugs": { - "url": "https://github.com/affaan-m/everything-claude-code/issues" + "url": "https://github.com/affaan-m/ECC/issues" }, - "homepage": "https://github.com/affaan-m/everything-claude-code#readme", + "homepage": "https://github.com/affaan-m/ECC#readme", "publishConfig": { "access": "public" }, diff --git a/.opencode/plugins/ecc-hooks.ts b/.opencode/plugins/ecc-hooks.ts index 31cfa8ac..606bcb7c 100644 --- a/.opencode/plugins/ecc-hooks.ts +++ b/.opencode/plugins/ecc-hooks.ts @@ -1,5 +1,5 @@ /** - * Everything Claude Code (ECC) Plugin Hooks for OpenCode + * ECC Plugin Hooks for OpenCode * * This plugin translates Claude Code hooks to OpenCode's plugin system. * OpenCode's plugin system is MORE sophisticated than Claude Code with 20+ events @@ -453,7 +453,7 @@ export const ECCHooksPlugin: ECCHooksPluginFn = async ({ const contextBlock = [ "# ECC Context (preserve across compaction)", "", - "## Active Plugin: Everything Claude Code v2.0.0-rc.1", + "## Active Plugin: ECC v2.0.0-rc.1", "- Hooks: file.edited, tool.execute.before/after, session.created/idle/deleted, shell.env, compacting, permission.ask", "- Tools: run-tests, check-coverage, security-audit, format-code, lint-check, git-summary, changed-files", "- Agents: 13 specialized (planner, architect, tdd-guide, code-reviewer, security-reviewer, build-error-resolver, e2e-runner, refactor-cleaner, doc-updater, go-reviewer, go-build-resolver, database-reviewer, python-reviewer)", diff --git a/.opencode/plugins/index.ts b/.opencode/plugins/index.ts index ca585969..c1e17a15 100644 --- a/.opencode/plugins/index.ts +++ b/.opencode/plugins/index.ts @@ -1,5 +1,5 @@ /** - * Everything Claude Code (ECC) Plugins for OpenCode + * ECC Plugins for OpenCode * * This module exports all ECC plugins for OpenCode integration. * Plugins provide hook-based automation that mirrors Claude Code's hook system diff --git a/README.md b/README.md index c46dc47e..a7a4bb5d 100644 --- a/README.md +++ b/README.md @@ -1,8 +1,8 @@ **Language:** English | [Português (Brasil)](docs/pt-BR/README.md) | [简体中文](README.zh-CN.md) | [繁體中文](docs/zh-TW/README.md) | [日本語](docs/ja-JP/README.md) | [한국어](docs/ko-KR/README.md) | [Türkçe](docs/tr/README.md) | [Русский](docs/ru/README.md) | [Tiếng Việt](docs/vi-VN/README.md) | [ไทย](docs/th/README.md) -# Everything Claude Code +# ECC -![Everything Claude Code — the performance system for AI agent harnesses](assets/hero.png) +![ECC - the harness-native operator system for agentic work](assets/hero.png) [![Stars](https://img.shields.io/github/stars/affaan-m/ECC?style=flat)](https://github.com/affaan-m/ECC/stargazers) [![Forks](https://img.shields.io/github/forks/affaan-m/ECC?style=flat)](https://github.com/affaan-m/ECC/network/members) @@ -34,7 +34,7 @@ --- -**The performance optimization system for AI agent harnesses. From an Anthropic hackathon winner.** +**The harness-native operator system for agentic work. From an Anthropic hackathon winner.** Not just configs. A complete system: skills, instincts, memory optimization, continuous learning, security scanning, and research-first development. Production-ready agents, skills, hooks, rules, MCP configurations, and legacy command shims evolved over 10+ months of intensive daily use building real products. @@ -1719,7 +1719,7 @@ These configs work for my workflow. You should: ## Community Projects -Projects built on or inspired by Everything Claude Code: +Projects built on or inspired by ECC: | Project | Description | |---------|-------------| diff --git a/agent.yaml b/agent.yaml index 658ad362..9a06743d 100644 --- a/agent.yaml +++ b/agent.yaml @@ -1,5 +1,5 @@ spec_version: "0.1.0" -name: everything-claude-code +name: ecc version: 2.0.0-rc.1 description: "Initial gitagent export surface for ECC's shared skill catalog, governance, and identity. Native agents, commands, and hooks remain authoritative in the repository while manifest coverage expands." author: affaan-m diff --git a/docs/business/metrics-and-sponsorship.md b/docs/business/metrics-and-sponsorship.md index 133e254c..9c1e318a 100644 --- a/docs/business/metrics-and-sponsorship.md +++ b/docs/business/metrics-and-sponsorship.md @@ -28,15 +28,15 @@ curl -s https://api.npmjs.org/downloads/point/last-month/ecc-agentshield ### GitHub repository adoption ```bash -gh api repos/affaan-m/everything-claude-code \ +gh api repos/affaan-m/ECC \ --jq '{stars:.stargazers_count,forks:.forks_count,contributors_url:.contributors_url,open_issues:.open_issues_count}' ``` ### GitHub traffic (maintainer access required) ```bash -gh api repos/affaan-m/everything-claude-code/traffic/views -gh api repos/affaan-m/everything-claude-code/traffic/clones +gh api repos/affaan-m/ECC/traffic/views +gh api repos/affaan-m/ECC/traffic/clones ``` ### GitHub App installs diff --git a/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md b/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md index 350b32ff..f04e8c5d 100644 --- a/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md +++ b/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md @@ -1,17 +1,18 @@ # ECC v2.0.0-rc.1 Naming And Publication Matrix -Snapshot date: 2026-05-18. +Snapshot date: 2026-05-19. -This matrix answers the release question "ship as Everything Claude Code, ECC, -or a renamed surface?" for the rc.1 lane. It is evidence for planning, not a -publication action. +This matrix records the rc.1 identity after the public repository rename to +`affaan-m/ECC`. It is evidence for planning, not a publication action. ## Decision -For `v2.0.0-rc.1`, keep the public identity as **Everything Claude Code (ECC)**. -Use **ECC** as the short product name in copy, plugin slugs, status surfaces, -and diagrams, but do not rename the GitHub repo, npm package, or package entry -points before the rc.1 release. +For `v2.0.0-rc.1`, ship the public identity as **ECC**. + +Use `affaan-m/ECC` as the canonical GitHub repo and `ECC` as the product name +in copy, plugin slugs, status surfaces, diagrams, and release collateral. Keep +the npm package and package entry points as `ecc-universal` until a separate +post-rc migration plan exists. Reason: @@ -19,21 +20,17 @@ Reason: plugin slug; - the exact npm package name `ecc` is already occupied by an unrelated elliptic curve cryptography package; -- the repo name `affaan-m/ecc` is not present, but renaming - `affaan-m/everything-claude-code` before rc.1 would create avoidable URL, - package, docs, and marketplace churn; +- `affaan-m/ECC` is the live public GitHub repo; - Claude and Codex plugin surfaces are already short enough as `ecc`; - rc.1 should prove the release, plugin, and publication pipeline before any - broader brand migration. + npm/package rename. ## Current Values | Surface | Current value | Evidence command | 2026-05-18 result | Release decision | | --- | --- | --- | --- | --- | -| Product display name | `Everything Claude Code` | `rg -n "Everything Claude Code" README.md CHANGELOG.md docs/releases/2.0.0-rc.1` | Present across README, release notes, launch copy, and plugin manifests | Keep for rc.1 | -| Short name | `ECC` | README/release docs | Used as the short cross-harness brand | Keep and prefer in tight copy | -| GitHub repo | `affaan-m/everything-claude-code` | `git remote get-url origin` | `https://github.com/affaan-m/everything-claude-code.git` | Keep for rc.1 | -| Possible short repo | `affaan-m/ecc` | `gh repo view affaan-m/ecc` | Not found with current auth | Candidate after rc.1 only | +| Product display name | `ECC` | `rg -n "^# ECC\|displayName.*ECC\|affaan-m/ECC" README.md .codex-plugin/plugin.json docs/releases/2.0.0-rc.1` | Present across README, plugin manifests, release copy, and URL ledger | Keep for rc.1 and GA | +| GitHub repo | `affaan-m/ECC` | `git remote get-url origin` | `https://github.com/affaan-m/ECC.git` | Keep for rc.1 and GA | | npm package | `ecc-universal` | `node -p "require('./package.json').name"` | `ecc-universal` | Keep for rc.1 | | npm package version | `2.0.0-rc.1` local, `1.10.0` registry latest | `node -p "require('./package.json').version"` and `npm view ecc-universal name version dist-tags --json` | Local rc.1 is ready; registry latest remains `1.10.0` and no `next` dist-tag exists yet | Publish rc as `next`, not `latest` | | Exact npm short name | `ecc` | `npm view ecc name version description repository.url --json` | Occupied by `ecc@0.0.2`, "Elliptic curve cryptography functions." | Do not use | @@ -77,21 +74,18 @@ Reason: | Billing/native payments | Announcement remains blocked by ITO-61 | Marketplace Pro target readback, webhook provenance, `INTERNAL_API_SECRET`, announcement gate | ECC Tools owner | Do not include native-payments claim in rc.1 announcement | | Social/longform copy | Drafts exist | Final live GitHub, npm, Claude, Codex, billing URLs | Release owner | Publish only after release/package/plugin URLs exist | -## Rename After rc.1 +## Package Rename After rc.1 -If the project moves from "Everything Claude Code" toward "ECC" after rc.1, -do it as a staged migration: +If the package layer moves from `ecc-universal` toward a shorter npm surface +after rc.1, do it as a staged migration: 1. Keep `ecc-universal` as the npm package until a replacement package has a verified owner, deprecation plan, and install migration. -2. Keep `affaan-m/everything-claude-code` as the canonical repo until release - notes, docs, plugin marketplace entries, npm metadata, and external links - are prepared for redirects. -3. Use `ECC` as the product name in new diagrams, status payloads, and - cross-harness docs immediately. -4. Reserve or create any new GitHub/npm/package surfaces before announcing the - rename. -5. Ship a compatibility guide that maps old commands, package names, plugin +2. Keep `affaan-m/ECC` as the canonical repo for public docs, release notes, + plugin marketplace entries, npm metadata, and external links. +3. Reserve or create any new npm/package surfaces before announcing the + package rename. +4. Ship a compatibility guide that maps old commands, package names, plugin slugs, and docs URLs to the new names. ## Evidence Captured In This Pass @@ -152,7 +146,7 @@ HOME="$(mktemp -d)" codex plugin marketplace add Added marketplace ecc and recorded the installed marketplace root as without touching the real Codex config. -HOME="$(mktemp -d)" codex plugin marketplace add affaan-m/everything-claude-code --ref "$(git rev-parse HEAD)" +HOME="$(mktemp -d)" codex plugin marketplace add affaan-m/ECC --ref "$(git rev-parse HEAD)" Added marketplace ecc from the GitHub repo pinned to 67e63e63f9bfd074bd6a21bf6bac71f3dfefa58b without touching the real Codex config. diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index c0fab23f..003dbcf7 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -27,8 +27,8 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | Current May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, current-head Mini Shai-Hulud/TanStack protection recheck, no-lifecycle install, npm audit/signature checks, AgentShield `840952a` enterprise/IOC evidence mirror, work-items sync, Linear sync, operator dashboard refresh, latest current-head CI/security scan success for `4470e2e6`, and ITO-46 naming/plugin publication closure | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and publication, plugin, billing, AgentShield, ECC Tools, legacy, and Linear productization gaps still open | -| `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-18.md` | Live URL and approval-gated URL ledger for release copy | Must be regenerated from the final release commit before public announcements | -| `docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md` | Naming, slug, and publication-path decision record | Keeps `Everything Claude Code / ECC`, npm `ecc-universal`, and plugin slug `ecc` for rc.1 | +| `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md` | Live URL and approval-gated URL ledger for release copy | Must be regenerated from the final release commit before public announcements | +| `docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md` | Naming, slug, and publication-path decision record | Keeps `ECC`, npm `ecc-universal`, and plugin slug `ecc` for rc.1 | | `docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md` | Release name, package, Claude plugin, Codex plugin, and publication-order checklist | Freezes rc.1 identity and requires final commit evidence before release, npm, plugin, billing, or announcement actions | | `docs/releases/2.0.0-rc.1/x-thread.md` | X launch draft | Must replace placeholders with live URLs after release/package/plugin publication | | `docs/releases/2.0.0-rc.1/linkedin-post.md` | LinkedIn launch draft | Must replace placeholders with live URLs after release/package/plugin publication | diff --git a/docs/releases/2.0.0-rc.1/publication-readiness.md b/docs/releases/2.0.0-rc.1/publication-readiness.md index 1624505d..87b3c4c8 100644 --- a/docs/releases/2.0.0-rc.1/publication-readiness.md +++ b/docs/releases/2.0.0-rc.1/publication-readiness.md @@ -54,16 +54,16 @@ For the May 17 operator dashboard refresh, see [`operator-readiness-dashboard-2026-05-17.md`](operator-readiness-dashboard-2026-05-17.md). For the May 18 operator dashboard refresh, see [`operator-readiness-dashboard-2026-05-18.md`](operator-readiness-dashboard-2026-05-18.md). -For the May 18 live/pending release URL ledger, see -[`release-url-ledger-2026-05-18.md`](release-url-ledger-2026-05-18.md). +For the May 19 live/pending release URL ledger after the public repo rename, see +[`release-url-ledger-2026-05-19.md`](release-url-ledger-2026-05-19.md). ## Release Identity Matrix | Surface | Expected value | Source of truth | Fresh check | Evidence artifact | Owner | Status | | --- | --- | --- | --- | --- | --- | --- | -| Product name | Everything Claude Code / ECC | `README.md`, `CHANGELOG.md`, release notes | `rg -n "Everything Claude Code" README.md CHANGELOG.md docs/releases/2.0.0-rc.1` | `publication-evidence-2026-05-12.md` | Release owner | Evidence recorded | -| GitHub repo | `affaan-m/everything-claude-code` | Git remote and release URLs | `git remote get-url origin` | `publication-evidence-2026-05-12.md` | Release owner | Evidence recorded | -| Git tag | `v2.0.0-rc.1` | GitHub releases | `gh release view v2.0.0-rc.1 --repo affaan-m/everything-claude-code` | `release not found` | Release owner | Blocked until release approval | +| Product name | ECC | `README.md`, plugin manifests, release notes | `rg -n "^# ECC\|displayName.*ECC\|affaan-m/ECC" README.md .codex-plugin/plugin.json docs/releases/2.0.0-rc.1` | `release-name-plugin-publication-checklist-2026-05-18.md` plus `release-url-ledger-2026-05-19.md` | Release owner | Evidence recorded | +| GitHub repo | `affaan-m/ECC` | Git remote and release URLs | `git remote get-url origin` | `release-url-ledger-2026-05-19.md` | Release owner | Evidence recorded | +| Git tag | `v2.0.0-rc.1` | GitHub releases | `gh release view v2.0.0-rc.1 --repo affaan-m/ECC` | `release not found` | Release owner | Blocked until release approval | | npm package | `ecc-universal` | `package.json` | `node -p "require('./package.json').name"` | `publication-evidence-2026-05-12.md` | Package owner | Evidence recorded | | npm version | `2.0.0-rc.1` | `VERSION`, `package.json`, lockfiles | `node -p "require('./package.json').version"` | `publication-evidence-2026-05-12.md` | Package owner | Evidence recorded | | npm dist-tag | `next` for rc, `latest` only for GA | npm registry | `npm view ecc-universal dist-tags --json` | Current registry only has `latest: 1.10.0`; `next` is pending publish | Package owner | Blocked until publish approval | @@ -85,7 +85,7 @@ For the May 18 live/pending release URL ledger, see | Codex plugin | Manifest version matches package and docs, repo marketplace points at the plugin root, and OpenAI's current official Plugin Directory status is recorded | `node tests/docs/ecc2-release-surface.test.js`; `node tests/plugin-manifest.test.js`; `codex plugin marketplace add --help`; temp-home `codex plugin marketplace add ` | `Blocker: official Plugin Directory listing requires OpenAI submission/listing evidence` | Plugin owner | Repo-marketplace distribution verified; official directory pending | | OpenCode package | Build output is regenerated from source and package metadata is current | `npm run build:opencode` | `Blocker: none for local build; public distribution still follows npm/plugin release` | Package owner | Evidence recorded | | ECC Tools billing reference | Any billing claim links to verified Marketplace/App state | `env -u GITHUB_TOKEN gh repo view ECC-Tools/ECC-Tools --json nameWithOwner,isPrivate,viewerPermission` plus internal `/api/billing/readiness?accountLogin=` readback | `Blocker: ECC-Tools #73 added announcementGate; live Marketplace test-account readback must return announcementGate.ready === true before payment announcement` | ECC Tools owner | Code gate recorded; live billing readback pending | -| Announcement copy | X, LinkedIn, GitHub release, and longform copy point to live URLs | placeholder-marker scan and `release-url-ledger-2026-05-18.md` | `Blocker: final live release/npm/plugin/billing URLs do not exist yet; live and pending URLs are separated in the May 18 ledger` | Release owner | URL ledger recorded; final URLs pending | +| Announcement copy | X, LinkedIn, GitHub release, and longform copy point to live URLs | placeholder-marker scan and `release-url-ledger-2026-05-19.md` | `Blocker: final live release/npm/plugin/billing URLs do not exist yet; live and pending URLs are separated in the May 19 ledger` | Release owner | URL ledger recorded; final URLs pending | | Privileged workflow hardening | Release and maintenance workflows avoid persisted checkout tokens | `node scripts/ci/validate-workflow-security.js` | `Blocker:` | Release owner | Evidence recorded in post-hardening refresh | ## Required Command Evidence @@ -110,8 +110,8 @@ Record the exact commit SHA and command output before any publication action: | Discussion baseline | `node scripts/platform-audit.js --json` and `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | `4470e2e6`: platform audit sampled 58 trunk discussions, 0 needing maintainer touch, 0 answerable discussions missing accepted answer; `docs/architecture/discussion-response-playbook.md` records response templates and security escalation rules | | Linear roadmap | Linear project and issue readback | Detailed roadmap exists with release, security, AgentShield, ECC Tools, legacy, and observability lanes | May 18 Linear comments include ITO-57 `3fe5b2b7-c4fe-401c-a317-b40d72119cb3` and ITO-44 `fb4a4f33-6c2d-421a-bbdb-63cfad3e3ee4`; earlier evidence records the project and 16 issue lanes | | Operator readiness dashboard | `npm run operator:dashboard -- --json` | Current queue state mapped to macro-goal deliverables and incomplete gaps | `4470e2e6`: regenerated May 18 dashboard from current main; platform audit ready true, 0 open PRs, 0 open issues, 0 discussion gaps, 0 dirty files, and publication gates still approval-gated | -| Release URL ledger | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-18.md` plus placeholder-marker scan | Live links and approval-gated links are separated before announcement copy is posted | Ledger records public repo/docs/CI/supply-chain/npm/OpenAI Codex documentation URLs and blocks GitHub release/npm/plugin/billing/social URLs until approval-gated checks pass | -| Release name and plugin publication checklist | `docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md` | Name/package/plugin values are frozen, final-release commands are listed, and Claude/Codex publication paths cite current official docs | Checklist keeps `Everything Claude Code / ECC`, `ecc-universal`, and plugin slug `ecc` for rc.1; no rename, npm publish, plugin tag, official listing, billing claim, or announcement before final evidence | +| Release URL ledger | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md` plus placeholder-marker scan | Live links and approval-gated links are separated before announcement copy is posted | Ledger records public repo/docs/npm/OpenAI Codex documentation URLs and blocks GitHub release/npm/plugin/billing/social URLs until approval-gated checks pass | +| Release name and plugin publication checklist | `docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md` | Name/package/plugin values are frozen, final-release commands are listed, and Claude/Codex publication paths cite current official docs | Checklist keeps `ECC`, `ecc-universal`, and plugin slug `ecc` for rc.1; no npm rename, npm publish, plugin tag, official listing, billing claim, or announcement before final evidence | ## Do Not Publish If diff --git a/docs/releases/2.0.0-rc.1/quickstart.md b/docs/releases/2.0.0-rc.1/quickstart.md index 85dd7630..ab8aaf12 100644 --- a/docs/releases/2.0.0-rc.1/quickstart.md +++ b/docs/releases/2.0.0-rc.1/quickstart.md @@ -5,8 +5,8 @@ This path is for a new contributor who wants to verify the release surface befor ## Clone ```bash -git clone https://github.com/affaan-m/everything-claude-code.git -cd everything-claude-code +git clone https://github.com/affaan-m/ECC.git +cd ECC ``` Start from a clean checkout. Do not copy private operator state, raw workspace exports, tokens, or local Hermes files into the repo. diff --git a/docs/releases/2.0.0-rc.1/release-notes.md b/docs/releases/2.0.0-rc.1/release-notes.md index 27700241..d832c9ac 100644 --- a/docs/releases/2.0.0-rc.1/release-notes.md +++ b/docs/releases/2.0.0-rc.1/release-notes.md @@ -91,7 +91,7 @@ What stays local: 2. Read the [Hermes setup guide](../../HERMES-SETUP.md). 3. Review the [cross-harness architecture](../../architecture/cross-harness.md). 4. Run the [observability readiness gate](../../architecture/observability-readiness.md). -5. Check the [release URL ledger](release-url-ledger-2026-05-18.md) before +5. Check the [release URL ledger](release-url-ledger-2026-05-19.md) before using any announcement links. 6. Start with one workflow lane: engineering, research, content, or outreach. 7. Import only sanitized operator patterns into ECC skills. diff --git a/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md b/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md new file mode 100644 index 00000000..149bf516 --- /dev/null +++ b/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md @@ -0,0 +1,51 @@ +# ECC v2.0.0-rc.1 Release URL Ledger + +This ledger separates links that are already public from links that only become +valid after the approval-gated release, package, plugin, and announcement +steps. Regenerate it from the final release commit before posting any public +announcement. + +Refreshed on 2026-05-19 after the public repository rename to +`affaan-m/ECC`. The final release pass must replace commit-specific evidence +with output from the exact release commit. + +## Live Now + +| Surface | URL | Verification | +| --- | --- | --- | +| Repository | | `git remote get-url origin` returns `https://github.com/affaan-m/ECC.git` | +| Release pack folder | | In-tree release pack | +| Release notes draft | | In-tree release copy | +| Hermes setup guide | | In-tree sanitized Hermes guide | +| May 18 evidence snapshot | | Current strongest pre-rename readiness evidence | +| May 18 operator dashboard | | Prompt-to-artifact dashboard | +| npm package page | | `npm view ecc-universal name version dist-tags --json` returned `latest: 1.10.0`; rc.1 is not published yet | +| Codex marketplace CLI docs | | Official docs list `codex plugin marketplace add` for GitHub shorthand, Git URLs, SSH URLs, and local marketplace roots | +| Codex official Plugin Directory status | | Official docs say public Plugin Directory publishing and self-serve management are coming soon | + +## Approval-Gated URLs + +| Surface | Intended URL or command | Gate before use | +| --- | --- | --- | +| GitHub prerelease | | `gh release view v2.0.0-rc.1 --repo affaan-m/ECC --json tagName,url,isPrerelease` must return the prerelease | +| npm rc package | | `npm publish --tag next` approval and post-publish `npm view ecc-universal dist-tags --json` | +| Claude plugin tag | `claude plugin tag .claude-plugin --dry-run`, then real tag only after approval | Clean release commit and plugin tag/push approval | +| Codex repo marketplace install | `codex plugin marketplace add affaan-m/ECC --ref v2.0.0-rc.1` | GitHub tag must exist; official Plugin Directory submission remains separate | +| ECC Tools native-payments announcement | ECC Tools Marketplace/App URL plus billing readiness readback | Marketplace-managed test account must return `announcementGate.ready === true` | +| Public announcements | X, LinkedIn, GitHub release, and longform URLs | GitHub release, npm, plugin, and billing URLs must resolve first | + +## Pre-Post Check + +Run these immediately before publication: + +```bash +git status --short --branch +gh release view v2.0.0-rc.1 --repo affaan-m/ECC --json tagName,url,isPrerelease +npm view ecc-universal name version dist-tags --json +codex plugin marketplace add --help +rg -n "TODO|TBD|PLACEHOLDER" docs/releases/2.0.0-rc.1 +npm run preview-pack:smoke +``` + +Do not post the social or notification copy until the approval-gated URLs above +resolve from a clean release commit. diff --git a/docs/releases/2.0.0-rc.1/x-thread.md b/docs/releases/2.0.0-rc.1/x-thread.md index ec9b1312..fa2b1fd1 100644 --- a/docs/releases/2.0.0-rc.1/x-thread.md +++ b/docs/releases/2.0.0-rc.1/x-thread.md @@ -71,13 +71,13 @@ The deeper local integrations stay local until they are sanitized, and publicati 11/ Start here: Repo: - + Hermes x ECC setup: - + 12/ Release notes: - + URL ledger: - + diff --git a/ecc2/Cargo.toml b/ecc2/Cargo.toml index 5ba65e66..6fa0de61 100644 --- a/ecc2/Cargo.toml +++ b/ecc2/Cargo.toml @@ -5,7 +5,7 @@ edition = "2021" description = "ECC 2.0 — Agentic IDE control plane with TUI dashboard" license = "MIT" authors = ["Affaan Mustafa "] -repository = "https://github.com/affaan-m/everything-claude-code" +repository = "https://github.com/affaan-m/ECC" [features] default = ["vendored-openssl"] diff --git a/scripts/discussion-audit.js b/scripts/discussion-audit.js index b8b89e2b..e985b1a6 100644 --- a/scripts/discussion-audit.js +++ b/scripts/discussion-audit.js @@ -11,7 +11,7 @@ const { const SCHEMA_VERSION = 'ecc.discussion-audit.v1'; const DEFAULT_REPOS = Object.freeze([ - 'affaan-m/everything-claude-code', + 'affaan-m/ECC', 'affaan-m/agentshield', 'affaan-m/JARVIS', 'ECC-Tools/ECC-Tools', diff --git a/scripts/ecc.js b/scripts/ecc.js index 7f5c41d0..c637ef27 100755 --- a/scripts/ecc.js +++ b/scripts/ecc.js @@ -130,7 +130,7 @@ Examples: ecc sessions ecc sessions session-active --json ecc work-items upsert linear-ecc-20 --source linear --source-id ECC-20 --title "Review control-plane contract" --status blocked - ecc work-items sync-github --repo affaan-m/everything-claude-code + ecc work-items sync-github --repo affaan-m/ECC ecc session-inspect claude:latest ecc loop-status --json ecc uninstall --target antigravity --dry-run diff --git a/scripts/operator-readiness-dashboard.js b/scripts/operator-readiness-dashboard.js index 7e05936c..7301a10a 100644 --- a/scripts/operator-readiness-dashboard.js +++ b/scripts/operator-readiness-dashboard.js @@ -548,7 +548,7 @@ function buildRequirements(rootDir, platformReport) { const publicationReadiness = readText(rootDir, 'docs/releases/2.0.0-rc.1/publication-readiness.md'); const namingMatrix = readText(rootDir, 'docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md'); const releasePublicationChecklist = readText(rootDir, 'docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md'); - const releaseUrlLedger = readText(rootDir, 'docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-18.md'); + const releaseUrlLedger = readText(rootDir, 'docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md'); const ownerQueueCleanup = readText(rootDir, 'docs/releases/2.0.0-rc.1/owner-queue-cleanup-2026-05-18.md'); const previewManifest = readText(rootDir, 'docs/releases/2.0.0-rc.1/preview-pack-manifest.md'); const previewPackSmoke = readText(rootDir, 'scripts/preview-pack-smoke.js'); @@ -685,11 +685,12 @@ function buildRequirements(rootDir, platformReport) { 'naming-and-publication-matrix plus release-name-plugin-publication checklist plus publication-readiness', includesAll(namingMatrix, ['Claude plugin', 'Codex plugin', 'npm package', 'Publication Paths']) && includesAll(releasePublicationChecklist, [ - 'Everything Claude Code (ECC)', + 'Ship `v2.0.0-rc.1` as **ECC**', + 'affaan-m/ECC', 'ecc-universal', 'claude plugin tag .claude-plugin --dry-run', 'codex plugin marketplace add', - 'Do not rename the repo or package until rc.1 is published' + 'Do not rename the npm package until rc.1 is published' ]) && includesAll(publicationReadiness, ['Claude plugin', 'Codex plugin']) ? 'in_progress' diff --git a/scripts/platform-audit.js b/scripts/platform-audit.js index 1f0b6dc1..fbb2d059 100644 --- a/scripts/platform-audit.js +++ b/scripts/platform-audit.js @@ -11,7 +11,7 @@ const { const SCHEMA_VERSION = 'ecc.platform-audit.v1'; const DEFAULT_REPOS = Object.freeze([ - 'affaan-m/everything-claude-code', + 'affaan-m/ECC', 'affaan-m/agentshield', 'affaan-m/JARVIS', 'ECC-Tools/ECC-Tools', diff --git a/scripts/preview-pack-smoke.js b/scripts/preview-pack-smoke.js index f36c8f0e..946d35f9 100644 --- a/scripts/preview-pack-smoke.js +++ b/scripts/preview-pack-smoke.js @@ -28,7 +28,7 @@ const REQUIRED_ARTIFACTS = [ `${RELEASE_DIR}/publication-evidence-2026-05-18.md`, `${RELEASE_DIR}/operator-readiness-dashboard-2026-05-17.md`, `${RELEASE_DIR}/operator-readiness-dashboard-2026-05-18.md`, - `${RELEASE_DIR}/release-url-ledger-2026-05-18.md`, + `${RELEASE_DIR}/release-url-ledger-2026-05-19.md`, `${RELEASE_DIR}/naming-and-publication-matrix.md`, `${RELEASE_DIR}/release-name-plugin-publication-checklist-2026-05-18.md`, `${RELEASE_DIR}/x-thread.md`, diff --git a/tests/docs/ecc2-release-surface.test.js b/tests/docs/ecc2-release-surface.test.js index 438ccf53..dc3f4222 100644 --- a/tests/docs/ecc2-release-surface.test.js +++ b/tests/docs/ecc2-release-surface.test.js @@ -175,6 +175,7 @@ test('preview pack manifest assembles release, Hermes, and publication gates', ( 'scripts/preview-pack-smoke.js', 'docs/releases/2.0.0-rc.1/publication-readiness.md', 'docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md', + 'docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md', 'docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md', ]) { assert.ok(manifest.includes(artifact), `preview pack manifest missing ${artifact}`); @@ -201,6 +202,8 @@ test('rc.1 quickstart gives a clone-to-cross-harness path', () => { for (const heading of ['Clone', 'Install', 'Verify', 'First Skill', 'Switch Harness']) { assert.ok(quickstart.includes(`## ${heading}`), `Missing ${heading} section`); } + assert.ok(quickstart.includes('git clone https://github.com/affaan-m/ECC.git')); + assert.ok(quickstart.includes('cd ECC')); assert.ok(quickstart.includes('node tests/run-all.js')); assert.ok(quickstart.includes('skills/hermes-imports/SKILL.md')); }); @@ -348,6 +351,35 @@ test('release name and plugin publication checklist freezes rc.1 surfaces', () = assert.ok(referenceArchitecture.includes('Keep the release/name/plugin publication checklist current')); }); +test('active release identity surfaces use canonical ECC repo URLs', () => { + const activeFiles = [ + 'README.md', + '.codex-plugin/README.md', + '.codex-plugin/plugin.json', + '.opencode/README.md', + '.opencode/package.json', + 'docs/business/metrics-and-sponsorship.md', + 'docs/releases/2.0.0-rc.1/quickstart.md', + 'docs/releases/2.0.0-rc.1/x-thread.md', + 'docs/releases/2.0.0-rc.1/publication-readiness.md', + 'docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md', + 'docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md', + 'ecc2/Cargo.toml', + 'scripts/platform-audit.js', + 'scripts/discussion-audit.js', + ]; + + const offenders = []; + for (const relativePath of activeFiles) { + const source = read(relativePath); + if (source.includes('affaan-m/everything-claude-code')) { + offenders.push(relativePath); + } + } + + assert.deepStrictEqual(offenders, []); +}); + test('release checklist and roadmap link to publication readiness evidence gate', () => { const launchChecklist = read('docs/releases/2.0.0-rc.1/launch-checklist.md'); const roadmap = read('docs/ECC-2.0-GA-ROADMAP.md'); diff --git a/tests/plugin-manifest.test.js b/tests/plugin-manifest.test.js index 9e7b363e..e84bf307 100644 --- a/tests/plugin-manifest.test.js +++ b/tests/plugin-manifest.test.js @@ -134,6 +134,11 @@ test('agent.yaml version matches package.json', () => { assert.strictEqual(match[1], expectedVersion); }); +test('agent.yaml uses canonical ECC identity', () => { + const agentYamlSource = fs.readFileSync(agentYamlPath, 'utf8'); + assert.ok(/^name:\s*ecc$/m.test(agentYamlSource), 'Expected agent.yaml to use the ecc name'); +}); + test('VERSION file matches package.json', () => { const versionFile = fs.readFileSync(versionFilePath, 'utf8').trim(); assert.ok(versionFile, 'Expected VERSION file to be non-empty'); @@ -149,7 +154,7 @@ test('docs/SELECTIVE-INSTALL-ARCHITECTURE.md repoVersion example matches package test('.opencode/plugins/ecc-hooks.ts active plugin banner matches package.json', () => { const source = fs.readFileSync(opencodeHooksPluginPath, 'utf8'); - const match = source.match(new RegExp(`## Active Plugin: Everything Claude Code v(${semverPattern})`)); + const match = source.match(new RegExp(`## Active Plugin: ECC v(${semverPattern})`)); assert.ok(match, 'Expected .opencode/plugins/ecc-hooks.ts to declare an active plugin banner'); assert.strictEqual(match[1], expectedVersion); }); @@ -346,6 +351,11 @@ test('codex plugin.json has interface.displayName', () => { ); }); +test('codex plugin.json uses canonical ECC repo and display name', () => { + assert.strictEqual(codexPlugin.repository, 'https://github.com/affaan-m/ECC'); + assert.strictEqual(codexPlugin.interface.displayName, 'ECC'); +}); + // ── .mcp.json at plugin root ────────────────────────────────────────────────── // Per official docs: keep .mcp.json at plugin root, NOT inside .codex-plugin/ console.log('\n=== .mcp.json (plugin root) ===\n'); @@ -522,6 +532,10 @@ test('.codex-plugin README uses current marketplace add flow', () => { readme.includes('codex plugin marketplace add'), 'Expected .codex-plugin README to document codex plugin marketplace add', ); + assert.ok( + readme.includes('codex plugin marketplace add affaan-m/ECC'), + 'Expected .codex-plugin README to document the canonical ECC repo marketplace source', + ); assert.ok( readme.includes('Official Plugin Directory publishing is coming soon'), 'Expected .codex-plugin README to document current official directory status', diff --git a/tests/scripts/discussion-audit.test.js b/tests/scripts/discussion-audit.test.js index 1a6ff218..d52b5ff9 100644 --- a/tests/scripts/discussion-audit.test.js +++ b/tests/scripts/discussion-audit.test.js @@ -102,10 +102,10 @@ function runTests() { try { const shimPath = writeGhShim(rootDir, { - [discussionEnabledGhKey('affaan-m', 'everything-claude-code')]: { + [discussionEnabledGhKey('affaan-m', 'ECC')]: { data: { repository: { hasDiscussionsEnabled: true } } }, - [discussionGhKey('affaan-m', 'everything-claude-code')]: { + [discussionGhKey('affaan-m', 'ECC')]: { data: { repository: { hasDiscussionsEnabled: true, @@ -142,7 +142,7 @@ function runTests() { const parsed = JSON.parse(run([ '--json', '--repo', - 'affaan-m/everything-claude-code' + 'affaan-m/ECC' ], { cwd: rootDir, env: { @@ -165,10 +165,10 @@ function runTests() { try { const shimPath = writeGhShim(rootDir, { - [discussionEnabledGhKey('affaan-m', 'everything-claude-code')]: { + [discussionEnabledGhKey('affaan-m', 'ECC')]: { data: { repository: { hasDiscussionsEnabled: true } } }, - [discussionGhKey('affaan-m', 'everything-claude-code')]: { + [discussionGhKey('affaan-m', 'ECC')]: { data: { repository: { hasDiscussionsEnabled: true, @@ -195,7 +195,7 @@ function runTests() { const result = runProcess([ '--json', '--repo', - 'affaan-m/everything-claude-code', + 'affaan-m/ECC', '--exit-code' ], { cwd: rootDir, @@ -220,10 +220,10 @@ function runTests() { try { const shimPath = writeGhShim(rootDir, { - [discussionEnabledGhKey('affaan-m', 'everything-claude-code')]: { + [discussionEnabledGhKey('affaan-m', 'ECC')]: { data: { repository: { hasDiscussionsEnabled: true } } }, - [discussionGhKey('affaan-m', 'everything-claude-code')]: { + [discussionGhKey('affaan-m', 'ECC')]: { data: { repository: { hasDiscussionsEnabled: true, @@ -237,7 +237,7 @@ function runTests() { '--write', outputPath, '--repo', - 'affaan-m/everything-claude-code' + 'affaan-m/ECC' ], { cwd: rootDir, env: { ECC_GH_SHIM: shimPath } diff --git a/tests/scripts/operator-readiness-dashboard.test.js b/tests/scripts/operator-readiness-dashboard.test.js index cda66efa..3c390760 100644 --- a/tests/scripts/operator-readiness-dashboard.test.js +++ b/tests/scripts/operator-readiness-dashboard.test.js @@ -83,11 +83,12 @@ function seedRepo(rootDir, overrides = {}) { 'docs/releases/2.0.0-rc.1/publication-readiness.md': 'Claude plugin Codex plugin release-name-plugin-publication-checklist-2026-05-18.md', 'docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md': 'Claude plugin Codex plugin npm package Publication Paths', 'docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md': [ - 'Everything Claude Code (ECC)', + 'Ship `v2.0.0-rc.1` as **ECC**', + 'affaan-m/ECC', 'ecc-universal', 'claude plugin tag .claude-plugin --dry-run', 'codex plugin marketplace add', - 'Do not rename the repo or package until rc.1 is published' + 'Do not rename the npm package until rc.1 is published' ].join('\n'), 'docs/releases/2.0.0-rc.1/preview-pack-manifest.md': [ 'publication-readiness.md release-notes.md quickstart.md', @@ -228,7 +229,7 @@ function runTests() { '--allow-untracked', 'docs/drafts/', '--repo', - 'affaan-m/everything-claude-code', + 'affaan-m/ECC', '--generated-at', '2026-05-15T00:00:00.000Z' ]); @@ -237,7 +238,7 @@ function runTests() { assert.strictEqual(parsed.root, path.resolve(rootDir)); assert.strictEqual(parsed.skipGithub, true); assert.deepStrictEqual(parsed.allowUntracked, ['docs/drafts/']); - assert.deepStrictEqual(parsed.repos, ['affaan-m/everything-claude-code']); + assert.deepStrictEqual(parsed.repos, ['affaan-m/ECC']); assert.strictEqual(parsed.generatedAt, '2026-05-15T00:00:00.000Z'); assert.throws(() => parseArgs(['node', 'script', '--format', 'xml']), /Invalid format/); diff --git a/tests/scripts/platform-audit.test.js b/tests/scripts/platform-audit.test.js index 521115b4..dde31584 100644 --- a/tests/scripts/platform-audit.test.js +++ b/tests/scripts/platform-audit.test.js @@ -177,7 +177,7 @@ function runTests() { `--root=${rootDir}`, '--json', '--repo', - 'affaan-m/everything-claude-code', + 'affaan-m/ECC', '--max-open-prs', '5', '--max-open-issues', @@ -188,7 +188,7 @@ function runTests() { assert.strictEqual(parsed.format, 'json'); assert.strictEqual(parsed.root, path.resolve(rootDir)); - assert.deepStrictEqual(parsed.repos, ['affaan-m/everything-claude-code']); + assert.deepStrictEqual(parsed.repos, ['affaan-m/ECC']); assert.strictEqual(parsed.thresholds.maxOpenPrs, 5); assert.strictEqual(parsed.thresholds.maxOpenIssues, 6); assert.deepStrictEqual(parsed.allowUntracked, ['docs/drafts/']); @@ -256,12 +256,12 @@ function runTests() { try { seedRepo(projectRoot); const shimPath = writeGhShim(projectRoot, { - 'pr list --repo affaan-m/everything-claude-code --state open --json number,title,isDraft,mergeStateStatus,updatedAt,url,author': [], - 'issue list --repo affaan-m/everything-claude-code --state open --json number,title,updatedAt,url,author,labels': [], - [discussionEnabledGhKey('affaan-m', 'everything-claude-code')]: { + 'pr list --repo affaan-m/ECC --state open --json number,title,isDraft,mergeStateStatus,updatedAt,url,author': [], + 'issue list --repo affaan-m/ECC --state open --json number,title,updatedAt,url,author,labels': [], + [discussionEnabledGhKey('affaan-m', 'ECC')]: { data: { repository: { hasDiscussionsEnabled: true } } }, - [discussionGhKey('affaan-m', 'everything-claude-code')]: { + [discussionGhKey('affaan-m', 'ECC')]: { data: { repository: { hasDiscussionsEnabled: true, @@ -289,7 +289,7 @@ function runTests() { '--format=json', `--root=${projectRoot}`, '--repo', - 'affaan-m/everything-claude-code' + 'affaan-m/ECC' ], { cwd: projectRoot, env: { @@ -325,12 +325,12 @@ function runTests() { author: { login: 'contributor' } })); const shimPath = writeGhShim(projectRoot, { - 'pr list --repo affaan-m/everything-claude-code --state open --json number,title,isDraft,mergeStateStatus,updatedAt,url,author': prs, - 'issue list --repo affaan-m/everything-claude-code --state open --json number,title,updatedAt,url,author,labels': [], - [discussionEnabledGhKey('affaan-m', 'everything-claude-code')]: { + 'pr list --repo affaan-m/ECC --state open --json number,title,isDraft,mergeStateStatus,updatedAt,url,author': prs, + 'issue list --repo affaan-m/ECC --state open --json number,title,updatedAt,url,author,labels': [], + [discussionEnabledGhKey('affaan-m', 'ECC')]: { data: { repository: { hasDiscussionsEnabled: true } } }, - [discussionGhKey('affaan-m', 'everything-claude-code')]: { + [discussionGhKey('affaan-m', 'ECC')]: { data: { repository: { hasDiscussionsEnabled: true, @@ -358,7 +358,7 @@ function runTests() { '--format=json', `--root=${projectRoot}`, '--repo', - 'affaan-m/everything-claude-code', + 'affaan-m/ECC', '--max-open-prs', '2' ], { From e209afc8c1b9c3cb872aa54ccf652d5726ff93eb Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 07:13:52 -0400 Subject: [PATCH 31/61] chore: gate ECC release video suite (#1992) --- docs/releases/2.0.0-rc.1/launch-checklist.md | 4 + .../2.0.0-rc.1/preview-pack-manifest.md | 2 + .../2.0.0-rc.1/video-suite-production.md | 173 ++++ ...cc-2-hypergrowth-release-command-center.md | 5 +- package.json | 2 + scripts/preview-pack-smoke.js | 2 + scripts/release-video-suite.js | 747 ++++++++++++++++++ tests/docs/ecc2-release-surface.test.js | 57 ++ tests/scripts/npm-publish-surface.test.js | 2 + tests/scripts/release-video-suite.test.js | 303 +++++++ 10 files changed, 1295 insertions(+), 2 deletions(-) create mode 100644 docs/releases/2.0.0-rc.1/video-suite-production.md create mode 100644 scripts/release-video-suite.js create mode 100644 tests/scripts/release-video-suite.test.js diff --git a/docs/releases/2.0.0-rc.1/launch-checklist.md b/docs/releases/2.0.0-rc.1/launch-checklist.md index cdb40559..aa015d95 100644 --- a/docs/releases/2.0.0-rc.1/launch-checklist.md +++ b/docs/releases/2.0.0-rc.1/launch-checklist.md @@ -37,6 +37,10 @@ - publish the LinkedIn draft from `linkedin-post.md` - use `article-outline.md` for the longer writeup - record one 30-60 second proof-of-work clip +- validate the release video suite with `npm run release:video-suite -- --format json` + after setting `ECC_VIDEO_SOURCE_ROOT` and `ECC_VIDEO_RELEASE_SUITE_ROOT` +- keep `video-suite-production.md` aligned with the actual primary launch + render, timeline, captions, and self-eval gate ## Demo Asset Suggestions diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index 003dbcf7..f8f6ac3f 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -28,6 +28,7 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and publication, plugin, billing, AgentShield, ECC Tools, legacy, and Linear productization gaps still open | | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md` | Live URL and approval-gated URL ledger for release copy | Must be regenerated from the final release commit before public announcements | +| `docs/releases/2.0.0-rc.1/video-suite-production.md` | Release video production manifest | Gates local media inventory, rough primary render, captions, timeline, self-eval, and no-private-path publication rules | | `docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md` | Naming, slug, and publication-path decision record | Keeps `ECC`, npm `ecc-universal`, and plugin slug `ecc` for rc.1 | | `docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md` | Release name, package, Claude plugin, Codex plugin, and publication-order checklist | Freezes rc.1 identity and requires final commit evidence before release, npm, plugin, billing, or announcement actions | | `docs/releases/2.0.0-rc.1/x-thread.md` | X launch draft | Must replace placeholders with live URLs after release/package/plugin publication | @@ -75,6 +76,7 @@ Run these from the exact release commit before publication: git status --short --branch node scripts/platform-audit.js --json npm run preview-pack:smoke +npm run release:video-suite -- --format json npm run harness:adapters -- --check npm run harness:audit -- --format json npm run observability:ready diff --git a/docs/releases/2.0.0-rc.1/video-suite-production.md b/docs/releases/2.0.0-rc.1/video-suite-production.md new file mode 100644 index 00000000..60a86ebb --- /dev/null +++ b/docs/releases/2.0.0-rc.1/video-suite-production.md @@ -0,0 +1,173 @@ +# ECC 2.0 Video Suite Production Manifest + +Snapshot date: 2026-05-19. + +This is the production contract for the ECC 2.0 release video suite. It keeps +the public release story, local source inventory, render outputs, and self-eval +gate in one place without committing raw footage, private transcript exports, or +absolute local paths. + +## Claim + +ECC 2.0 is the harness-native operator system for agentic work. + +The videos should prove that claim directly: + +- one reusable layer across Claude Code, Codex, OpenCode, Cursor, Gemini, Zed, + GitHub Copilot, and terminal workflows; +- reusable skills, rules, hooks, agents, MCP conventions, release gates, and + operator workflows; +- `ecc2/` as the alpha control-plane/TUI direction, not the whole product; +- AgentShield and supply-chain gates as the enterprise trust layer; +- OSS stays free, with GitHub Sponsors, ECC Tools Pro, and consulting as the + funding surface. + +Do not frame the launch as a rename, pivot, config pack, or Claude-only package. + +## Private Inputs + +Do not commit raw footage, transcript JSON, or timeline exports. + +Operators should point the validator at local media using environment variables: + +```bash +ECC_VIDEO_SOURCE_ROOT=/path/to/ecc_2_raws \ +ECC_VIDEO_RELEASE_SUITE_ROOT=/path/to/ecc_2_release_suite \ +npm run release:video-suite -- --format json +``` + +`ECC_VIDEO_SOURCE_ROOT` should contain proof images and may contain an `_edited/` +subdirectory with edited source clips. `ECC_VIDEO_RELEASE_SUITE_ROOT` should +contain `edl/`, `segments/`, `renders/`, `timelines/`, and `transcripts/`. + +## Source Inventory + +These basenames are the required local inputs for the release suite validator. + +| Asset | Lane | Proof | +| --- | --- | --- | +| `longform-full-wide.mp4` | Primary launch video | operator system, control-plane direction, closing proof | +| `sf-longform-full.mp4` | Primary launch video | structured context opener | +| `sf-thread-2-whatisecc.mp4` | What is ECC | category clarity and GitHub App explanation | +| `sf-thread-4-security.mp4` | Security proof | AgentShield, hooks, MCP, permission risk | +| `thread-2-ghapp-money.mp4` | Money/proof clip | OSS plus paid hosting and services | +| `architecture-2-wide.mp4` | B-roll | harness-native architecture | +| `terminal-scan-2-wide.mp4` | Install proof | terminal workflow and install confidence | +| `new_site_raw.mp4` | B-roll | site and product surface | +| `coverage-montage-wide.mp4` | Coverage/social proof | distribution and social proof | +| `metrics-ticker-2-wide.mp4` | Money/proof clip | traction and funnel proof | +| `growth-timeline-2-wide.mp4` | Coverage/social proof | release momentum timeline | +| `gh_app_1.png` | Money/proof clip | hosted GitHub App surface | +| `star_history.png` | Coverage/social proof | OSS adoption chart | +| `x_analytics.png` | Coverage/social proof | social distribution proof | +| `100k.png` | Coverage/social proof | reach milestone proof | + +## Deliverables + +| Deliverable | Length | Aspect | Output | +| --- | ---: | --- | --- | +| Primary launch video | 90-150s | 16:9 | `ecc-2-primary-launch.mp4` | +| Install proof clip | 25-35s | 16:9 and 9:16 | `ecc-2-install-proof-*` | +| What is ECC clip | 45-60s | 16:9 and 9:16 | `ecc-2-what-is-ecc-*` | +| Security proof clip | 45-60s | 16:9 and 9:16 | `ecc-2-security-proof-*` | +| Money/proof clip | 30-45s | 16:9 and 9:16 | `ecc-2-money-proof-*` | +| Coverage/social proof clip | 30-45s | 16:9 and 9:16 | `ecc-2-social-proof-*` | + +## Primary Launch Video + +The rough v1 primary launch assembly is the current spine. It should stay +speech-led, with product proof covering jump cuts and older wording. + +| Order | Source | In | Out | Use | +| --- | --- | ---: | ---: | --- | +| 01 | `sf-longform-full.mp4` | 161.12 | 177.68 | Cleaner opener: ECC as structured context with skills, commands, agents, hooks, and project setup. | +| 02 | `thread-2-ghapp-money.mp4` | 21.84 | 30.40 | Direct product thesis: agentic harness optimization. | +| 03 | `thread-2-ghapp-money.mp4` | 41.00 | 59.72 | Not another harness; ECC is the layer and tooling on top of harnesses. | +| 04 | `longform-full-wide.mp4` | 254.60 | 271.20 | Agentic IDE, observability, tracing, and multi-agent control-plane direction. | +| 05 | `sf-thread-2-whatisecc.mp4` | 40.08 | 60.60 | GitHub App analyzes repos and injects project-specific skills, prompts, and hooks. | +| 06 | `sf-thread-4-security.mp4` | 17.60 | 32.72 | Security risk setup: hooks, MCP servers, permissions. | +| 07 | `sf-thread-4-security.mp4` | 37.28 | 51.32 | AgentShield proof: rules, categories, grades, secrets, injection, exfiltration. | +| 08 | `thread-2-ghapp-money.mp4` | 59.72 | 75.96 | OSS-first business model plus managed GitHub App surface. | +| 09 | `longform-full-wide.mp4` | 507.34 | 525.62 | Close on workflows, tested shipping, and secure daily agent work. | + +Required local rough v1 artifacts: + +- `edl/primary-launch.edl.md` +- `timelines/primary-launch-v1.timeline.json` +- `renders/ecc-2-primary-launch-rough-v1.mp4` +- `renders/ecc-2-primary-launch-rough-v1.captions.srt` +- `segments/primary-launch-v1/01-structured-context.mp4` +- `segments/primary-launch-v1/02-agentic-harness-optimization.mp4` +- `segments/primary-launch-v1/03-not-another-harness.mp4` +- `segments/primary-launch-v1/04-agentic-ide-surface.mp4` +- `segments/primary-launch-v1/05-github-app-proof.mp4` +- `segments/primary-launch-v1/06-security-risk.mp4` +- `segments/primary-launch-v1/07-agentshield-proof.mp4` +- `segments/primary-launch-v1/08-oss-paid-model.mp4` +- `segments/primary-launch-v1/09-close-shipping-system.mp4` + +## video-use compatible workflow + +Use the same production shape as Video Use while keeping the ECC-specific media +stack intact: + +1. Treat transcript and timeline data as the editing surface. +2. Inspect filmstrip or frame samples only at ambiguous cut points. +3. Keep an edit decision list before rendering. +4. Cut deterministically with FFmpeg. +5. Add proof overlays with Remotion or Manim where product claims need visual + evidence. +6. Export the MP4 plus editable timeline and caption state. +7. Run self-eval before any upload or social post. + +Do not dump frames into the repo. Frame samples used for self-eval belong in the +local release suite workspace. + +## Browser Capture Plan + +Use Browser or equivalent desktop capture only for proof footage that must be +current on release day: + +| Surface | Capture | +| --- | --- | +| GitHub repo | README hero, install block, sponsor links, release notes | +| Codex plugin | repo marketplace install path and local plugin README | +| OpenCode package | package install and plugin banner | +| ECC Tools Pro | billing/product page only after live readback confirms claims | +| AgentShield | CLI output, policy category view, supply-chain gate | +| `ecc2/` | alpha control-plane/TUI surface with alpha framing | + +If a surface is not live, use a local browser capture and label it as local or +release-candidate proof. Do not claim marketplace, billing, or official +directory availability before evidence exists. + +## Self-Eval Gate + +Run the validator: + +```bash +ECC_VIDEO_SOURCE_ROOT=/path/to/ecc_2_raws \ +ECC_VIDEO_RELEASE_SUITE_ROOT=/path/to/ecc_2_release_suite \ +npm run release:video-suite -- --format json +``` + +Then manually check the final render for: + +- no blank frames or accidental desktop exposure; +- no stale repo name, pivot, rename, or Claude-only framing in captions; +- no captions that rewrite speech into a false claim; +- no stale URLs, old install commands, or pre-rename repository links; +- no internal MRR numbers unless the post explicitly needs them; +- audio continuity across every cut; +- first 10 seconds clearly say what ECC is; +- final CTA routes to repo, sponsor, Pro, or consulting without clutter. + +## Do Not Publish If + +- `npm run release:video-suite` is not ready for the local source roots. +- The primary launch render is outside the 90-150 second target. +- Captions mention the old repository name. +- Product proof relies on private screens, secrets, customer data, or raw local + paths. +- The release URL, npm, plugin, billing, or marketplace claims outrun the + evidence in `publication-readiness.md`. diff --git a/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md b/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md index 986aa079..f1563e06 100644 --- a/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md +++ b/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md @@ -50,7 +50,7 @@ MRR growth should come from four lanes at once: | Package and plugin publication | `ecc-universal@2.0.0-rc.1` dry-runs clean, npm `next` is approved, Claude plugin tag dry-runs, Codex repo marketplace smoke passes, OpenCode build passes | Refresh publication evidence from final commit | | Product proof | Quickstart, cross-harness architecture, demo prompts, `ecc2/` alpha boundary, AgentShield safety proof, and hosted ECC Tools links are consistent | Keep proof surfaces concrete | | Revenue proof | Sponsor tiers, Pro pricing, consulting CTA, partner CTA, and billing-readback language are current | Do not announce billing claims before live readback | -| Content proof | Launch video, short-form clips, screenshots, release notes, GitHub Discussion, X, LinkedIn, and longform post are aligned | Produce video suite from existing raw material | +| Content proof | Launch video, short-form clips, screenshots, release notes, GitHub Discussion, X, LinkedIn, and longform post are aligned | Validate `video-suite-production.md` and the local render suite | | Community proof | Discord invite, rules, channels, onboarding, and sponsor/community routing are ready | Needs invite/token decision before public links | ## Video Suite @@ -124,7 +124,8 @@ Avoid: 1. Land the public repo identity fixes. 2. Refresh package, plugin, workflow, release, and launch-copy URLs. 3. Record final publication evidence from the exact release commit. -4. Produce the video suite manifest and transcripts from existing raw material. +4. Produce the video suite manifest and transcripts from existing raw material; + gate it with `npm run release:video-suite -- --format json`. 5. Browser-capture the README, ECC Tools app, install flow, and relevant proof surfaces for b-roll. 6. Render the primary launch video plus five short clips. diff --git a/package.json b/package.json index 84baea88..479374f2 100644 --- a/package.json +++ b/package.json @@ -89,6 +89,7 @@ "scripts/operator-readiness-dashboard.js", "scripts/platform-audit.js", "scripts/preview-pack-smoke.js", + "scripts/release-video-suite.js", "scripts/hooks/", "scripts/install-apply.js", "scripts/install-plan.js", @@ -311,6 +312,7 @@ "observability:ready": "node scripts/observability-readiness.js", "operator:dashboard": "node scripts/operator-readiness-dashboard.js", "preview-pack:smoke": "node scripts/preview-pack-smoke.js", + "release:video-suite": "node scripts/release-video-suite.js", "platform:audit": "node scripts/platform-audit.js", "discussion:audit": "node scripts/discussion-audit.js", "security:ioc-scan": "node scripts/ci/scan-supply-chain-iocs.js", diff --git a/scripts/preview-pack-smoke.js b/scripts/preview-pack-smoke.js index 946d35f9..598e8fc2 100644 --- a/scripts/preview-pack-smoke.js +++ b/scripts/preview-pack-smoke.js @@ -29,6 +29,7 @@ const REQUIRED_ARTIFACTS = [ `${RELEASE_DIR}/operator-readiness-dashboard-2026-05-17.md`, `${RELEASE_DIR}/operator-readiness-dashboard-2026-05-18.md`, `${RELEASE_DIR}/release-url-ledger-2026-05-19.md`, + `${RELEASE_DIR}/video-suite-production.md`, `${RELEASE_DIR}/naming-and-publication-matrix.md`, `${RELEASE_DIR}/release-name-plugin-publication-checklist-2026-05-18.md`, `${RELEASE_DIR}/x-thread.md`, @@ -42,6 +43,7 @@ const REQUIRED_VERIFICATION_COMMANDS = [ 'git status --short --branch', 'node scripts/platform-audit.js --json', 'npm run preview-pack:smoke', + 'npm run release:video-suite -- --format json', 'npm run harness:adapters -- --check', 'npm run harness:audit -- --format json', 'npm run observability:ready', diff --git a/scripts/release-video-suite.js b/scripts/release-video-suite.js new file mode 100644 index 00000000..c19b9ca6 --- /dev/null +++ b/scripts/release-video-suite.js @@ -0,0 +1,747 @@ +#!/usr/bin/env node +'use strict'; + +const fs = require('fs'); +const path = require('path'); +const { spawnSync } = require('child_process'); + +const RELEASE = '2.0.0-rc.1'; +const SCHEMA_VERSION = 'ecc.release-video-suite.v1'; +const VIDEO_MANIFEST_PATH = `docs/releases/${RELEASE}/video-suite-production.md`; +const HYPERGROWTH_DOC_PATH = 'docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md'; + +const REQUIRED_DOC_MARKERS = [ + 'ECC 2.0 Video Suite Production Manifest', + 'video-use compatible workflow', + 'ECC_VIDEO_SOURCE_ROOT', + 'ECC_VIDEO_RELEASE_SUITE_ROOT', + 'Primary launch video', + 'Self-Eval Gate', + 'Do Not Publish If', +]; + +const REQUIRED_SOURCE_ASSETS = [ + { + id: 'primary-longform-wide', + file: 'longform-full-wide.mp4', + lane: 'primary-launch', + proof: 'operator system, control-plane direction, closing proof', + }, + { + id: 'primary-shortform-full', + file: 'sf-longform-full.mp4', + lane: 'primary-launch', + proof: 'structured context opener', + }, + { + id: 'what-is-ecc-wide', + file: 'sf-thread-2-whatisecc.mp4', + lane: 'what-is-ecc', + proof: 'category clarity and GitHub App explanation', + }, + { + id: 'security-wide', + file: 'sf-thread-4-security.mp4', + lane: 'security-proof', + proof: 'AgentShield, hooks, MCP, permission risk', + }, + { + id: 'money-proof-wide', + file: 'thread-2-ghapp-money.mp4', + lane: 'money-proof', + proof: 'OSS plus paid hosting and services', + }, + { + id: 'architecture-wide', + file: 'architecture-2-wide.mp4', + lane: 'b-roll', + proof: 'harness-native architecture', + }, + { + id: 'terminal-scan-wide', + file: 'terminal-scan-2-wide.mp4', + lane: 'install-proof', + proof: 'terminal workflow and install confidence', + }, + { + id: 'site-raw', + file: 'new_site_raw.mp4', + lane: 'b-roll', + proof: 'site and product surface', + }, + { + id: 'coverage-montage', + file: 'coverage-montage-wide.mp4', + lane: 'coverage-proof', + proof: 'distribution and social proof', + }, + { + id: 'metrics-ticker-wide', + file: 'metrics-ticker-2-wide.mp4', + lane: 'money-proof', + proof: 'traction and funnel proof', + }, + { + id: 'growth-timeline-wide', + file: 'growth-timeline-2-wide.mp4', + lane: 'coverage-proof', + proof: 'release momentum timeline', + }, + { + id: 'github-app-proof-1', + file: 'gh_app_1.png', + lane: 'money-proof', + proof: 'hosted GitHub App surface', + }, + { + id: 'stars', + file: 'star_history.png', + lane: 'coverage-proof', + proof: 'OSS adoption chart', + }, + { + id: 'x-analytics', + file: 'x_analytics.png', + lane: 'coverage-proof', + proof: 'social distribution proof', + }, + { + id: '100k-proof', + file: '100k.png', + lane: 'coverage-proof', + proof: 'reach milestone proof', + }, +]; + +const REQUIRED_SUITE_ARTIFACTS = [ + { + id: 'primary-edl', + relativePath: 'edl/primary-launch.edl.md', + kind: 'edl', + }, + { + id: 'primary-timeline-v1', + relativePath: 'timelines/primary-launch-v1.timeline.json', + kind: 'timeline', + }, + { + id: 'primary-captions-v1', + relativePath: 'renders/ecc-2-primary-launch-rough-v1.captions.srt', + kind: 'captions', + }, + { + id: 'primary-render-v1', + relativePath: 'renders/ecc-2-primary-launch-rough-v1.mp4', + kind: 'video', + minDurationSeconds: 90, + maxDurationSeconds: 150, + }, + { + id: 'segment-structured-context', + relativePath: 'segments/primary-launch-v1/01-structured-context.mp4', + kind: 'video', + }, + { + id: 'segment-agentic-harness-optimization', + relativePath: 'segments/primary-launch-v1/02-agentic-harness-optimization.mp4', + kind: 'video', + }, + { + id: 'segment-not-another-harness', + relativePath: 'segments/primary-launch-v1/03-not-another-harness.mp4', + kind: 'video', + }, + { + id: 'segment-agentic-ide-surface', + relativePath: 'segments/primary-launch-v1/04-agentic-ide-surface.mp4', + kind: 'video', + }, + { + id: 'segment-github-app-proof', + relativePath: 'segments/primary-launch-v1/05-github-app-proof.mp4', + kind: 'video', + }, + { + id: 'segment-security-risk', + relativePath: 'segments/primary-launch-v1/06-security-risk.mp4', + kind: 'video', + }, + { + id: 'segment-agentshield-proof', + relativePath: 'segments/primary-launch-v1/07-agentshield-proof.mp4', + kind: 'video', + }, + { + id: 'segment-oss-paid-model', + relativePath: 'segments/primary-launch-v1/08-oss-paid-model.mp4', + kind: 'video', + }, + { + id: 'segment-close-shipping-system', + relativePath: 'segments/primary-launch-v1/09-close-shipping-system.mp4', + kind: 'video', + }, +]; + +function usage() { + console.log([ + 'Usage: node scripts/release-video-suite.js [options]', + '', + 'Validates the ECC 2.0 release video production lane without committing raw media paths.', + '', + 'Options:', + ' --format Output format (default: text)', + ' --json Alias for --format json', + ' --root Repository root to inspect (default: cwd)', + ' --source-root Directory containing ECC 2 source media, with optional _edited subdir', + ' --suite-root Directory containing render/timeline/transcript outputs', + ' --skip-probe Skip ffprobe duration reads for fixture or dry-run checks', + ' --summary Emit compact JSON when used with --format json', + ' --help, -h Show this help', + '', + 'Environment:', + ' ECC_VIDEO_SOURCE_ROOT', + ' ECC_VIDEO_RELEASE_SUITE_ROOT', + ].join('\n')); +} + +function readArgValue(args, index, flagName) { + const value = args[index + 1]; + if (!value || value.startsWith('--')) { + throw new Error(`${flagName} requires a value`); + } + return value; +} + +function parseArgs(argv) { + const args = argv.slice(2); + const parsed = { + format: 'text', + help: false, + root: path.resolve(process.cwd()), + sourceRoot: process.env.ECC_VIDEO_SOURCE_ROOT || '', + suiteRoot: process.env.ECC_VIDEO_RELEASE_SUITE_ROOT || '', + skipProbe: false, + summary: false, + }; + + for (let index = 0; index < args.length; index += 1) { + const arg = args[index]; + + if (arg === '--help' || arg === '-h') { + parsed.help = true; + continue; + } + + if (arg === '--json') { + parsed.format = 'json'; + continue; + } + + if (arg === '--skip-probe') { + parsed.skipProbe = true; + continue; + } + + if (arg === '--summary') { + parsed.summary = true; + continue; + } + + if (arg === '--format') { + parsed.format = readArgValue(args, index, arg).toLowerCase(); + index += 1; + continue; + } + + if (arg.startsWith('--format=')) { + parsed.format = arg.slice('--format='.length).toLowerCase(); + continue; + } + + if (arg === '--root') { + parsed.root = path.resolve(readArgValue(args, index, arg)); + index += 1; + continue; + } + + if (arg.startsWith('--root=')) { + parsed.root = path.resolve(arg.slice('--root='.length)); + continue; + } + + if (arg === '--source-root') { + parsed.sourceRoot = path.resolve(readArgValue(args, index, arg)); + index += 1; + continue; + } + + if (arg.startsWith('--source-root=')) { + parsed.sourceRoot = path.resolve(arg.slice('--source-root='.length)); + continue; + } + + if (arg === '--suite-root') { + parsed.suiteRoot = path.resolve(readArgValue(args, index, arg)); + index += 1; + continue; + } + + if (arg.startsWith('--suite-root=')) { + parsed.suiteRoot = path.resolve(arg.slice('--suite-root='.length)); + continue; + } + + throw new Error(`Unknown argument: ${arg}`); + } + + if (!['text', 'json'].includes(parsed.format)) { + throw new Error(`Invalid format: ${parsed.format}. Use text or json.`); + } + + return parsed; +} + +function readText(rootDir, relativePath) { + try { + return fs.readFileSync(path.join(rootDir, relativePath), 'utf8'); + } catch (_error) { + return ''; + } +} + +function safeParseJson(text) { + if (!text.trim()) { + return null; + } + + try { + return JSON.parse(text); + } catch (_error) { + return null; + } +} + +function lineNumberForIndex(text, index) { + return text.slice(0, index).split('\n').length; +} + +function scanForbiddenPaths(rootDir, relativePaths) { + const offenders = []; + const privatePathPattern = /\/Users\/(?!\.\.\.)[A-Za-z0-9._-]+|\/home\/(?!user|runner)[A-Za-z0-9._-]+/g; + + for (const relativePath of relativePaths) { + const text = readText(rootDir, relativePath); + if (!text) { + continue; + } + + for (const match of text.matchAll(privatePathPattern)) { + offenders.push({ + path: relativePath, + line: lineNumberForIndex(text, match.index), + marker: match[0], + }); + } + } + + return offenders; +} + +function makeCheck(id, status, summary, fix, details = {}) { + return { + id, + status, + summary, + fix: status === 'pass' ? '' : fix, + ...details, + }; +} + +function formatBytes(bytes) { + if (!Number.isFinite(bytes)) { + return null; + } + + return Number((bytes / 1024 / 1024).toFixed(2)); +} + +function probeMedia(filePath, skipProbe) { + const stat = fs.statSync(filePath); + const result = { + sizeBytes: stat.size, + sizeMb: formatBytes(stat.size), + durationSeconds: null, + probe: skipProbe ? 'skipped' : 'unavailable', + }; + + if (skipProbe) { + return result; + } + + const probe = spawnSync('ffprobe', [ + '-v', + 'error', + '-show_entries', + 'format=duration', + '-of', + 'json', + filePath, + ], { + encoding: 'utf8', + stdio: ['ignore', 'pipe', 'pipe'], + timeout: 15000, + }); + + if (probe.error) { + result.probe = `error: ${probe.error.message}`; + return result; + } + + if (probe.status !== 0) { + result.probe = `failed: ${(probe.stderr || '').trim() || `exit ${probe.status}`}`; + return result; + } + + const parsed = safeParseJson(probe.stdout); + const duration = Number(parsed && parsed.format && parsed.format.duration); + if (Number.isFinite(duration)) { + result.durationSeconds = Number(duration.toFixed(3)); + result.probe = 'ok'; + } + + return result; +} + +function resolveSourceAssetPath(sourceRoot, fileName) { + const candidates = [ + path.join(sourceRoot, fileName), + path.join(sourceRoot, '_edited', fileName), + ]; + + return candidates.find(candidate => fs.existsSync(candidate)) || candidates[0]; +} + +function inspectSourceAssets(sourceRoot, skipProbe) { + return REQUIRED_SOURCE_ASSETS.map(asset => { + if (!sourceRoot) { + return { + ...asset, + status: 'missing', + configured: false, + }; + } + + const filePath = resolveSourceAssetPath(sourceRoot, asset.file); + if (!fs.existsSync(filePath)) { + return { + ...asset, + status: 'missing', + configured: true, + }; + } + + const media = asset.file.endsWith('.mp4') ? probeMedia(filePath, skipProbe) : { + sizeBytes: fs.statSync(filePath).size, + sizeMb: formatBytes(fs.statSync(filePath).size), + durationSeconds: null, + probe: 'not-media', + }; + + return { + ...asset, + status: 'present', + configured: true, + ...media, + }; + }); +} + +function inspectSuiteArtifacts(suiteRoot, skipProbe) { + return REQUIRED_SUITE_ARTIFACTS.map(artifact => { + if (!suiteRoot) { + return { + ...artifact, + status: 'missing', + configured: false, + }; + } + + const filePath = path.join(suiteRoot, artifact.relativePath); + if (!fs.existsSync(filePath)) { + return { + ...artifact, + status: 'missing', + configured: true, + }; + } + + const media = artifact.kind === 'video' ? probeMedia(filePath, skipProbe) : { + sizeBytes: fs.statSync(filePath).size, + sizeMb: formatBytes(fs.statSync(filePath).size), + durationSeconds: null, + probe: 'not-media', + }; + + let durationStatus = 'pass'; + if ( + artifact.kind === 'video' + && Number.isFinite(artifact.minDurationSeconds) + && Number.isFinite(media.durationSeconds) + && media.durationSeconds < artifact.minDurationSeconds + ) { + durationStatus = 'fail'; + } + + if ( + artifact.kind === 'video' + && Number.isFinite(artifact.maxDurationSeconds) + && Number.isFinite(media.durationSeconds) + && media.durationSeconds > artifact.maxDurationSeconds + ) { + durationStatus = 'fail'; + } + + if ( + artifact.kind === 'video' + && Number.isFinite(artifact.minDurationSeconds) + && !skipProbe + && media.durationSeconds === null + ) { + durationStatus = 'fail'; + } + + return { + ...artifact, + status: durationStatus === 'pass' ? 'present' : 'invalid', + configured: true, + ...media, + }; + }); +} + +function buildReport(options = {}) { + const rootDir = path.resolve(options.root || process.cwd()); + const sourceRoot = options.sourceRoot ? path.resolve(options.sourceRoot) : ''; + const suiteRoot = options.suiteRoot ? path.resolve(options.suiteRoot) : ''; + const skipProbe = Boolean(options.skipProbe); + const packageJson = safeParseJson(readText(rootDir, 'package.json')) || {}; + const packageScripts = packageJson.scripts || {}; + const packageFiles = Array.isArray(packageJson.files) ? packageJson.files : []; + const manifest = readText(rootDir, VIDEO_MANIFEST_PATH); + const hypergrowth = readText(rootDir, HYPERGROWTH_DOC_PATH); + + const missingDocMarkers = REQUIRED_DOC_MARKERS.filter(marker => !manifest.includes(marker)); + const forbiddenPaths = scanForbiddenPaths(rootDir, [ + VIDEO_MANIFEST_PATH, + HYPERGROWTH_DOC_PATH, + `docs/releases/${RELEASE}/preview-pack-manifest.md`, + `docs/releases/${RELEASE}/launch-checklist.md`, + ]); + const sourceAssets = inspectSourceAssets(sourceRoot, skipProbe); + const suiteArtifacts = inspectSuiteArtifacts(suiteRoot, skipProbe); + const missingSourceAssets = sourceAssets.filter(asset => asset.status !== 'present'); + const missingSuiteArtifacts = suiteArtifacts.filter(artifact => artifact.status !== 'present'); + + const checks = [ + makeCheck( + 'video-suite-command-registered', + packageScripts['release:video-suite'] === 'node scripts/release-video-suite.js' + && packageFiles.includes('scripts/release-video-suite.js') + ? 'pass' + : 'fail', + 'package script and npm package entry for the release video suite validator', + 'Add release:video-suite to package scripts and include scripts/release-video-suite.js in package files.' + ), + makeCheck( + 'video-suite-manifest-present', + manifest && missingDocMarkers.length === 0 ? 'pass' : 'fail', + manifest && missingDocMarkers.length === 0 + ? `${VIDEO_MANIFEST_PATH} includes the required production markers` + : `missing markers: ${missingDocMarkers.join(', ') || 'manifest file missing'}`, + 'Restore the video production manifest and required production markers.' + ), + makeCheck( + 'video-suite-public-sanitization', + forbiddenPaths.length === 0 + && manifest.includes('Do not commit raw footage, transcript JSON, or timeline exports') + && /Keep raw\s+absolute paths out of public docs/.test(hypergrowth) + ? 'pass' + : 'fail', + forbiddenPaths.length === 0 + ? 'public launch docs avoid private media paths and keep raw assets local' + : `private path markers: ${forbiddenPaths.map(item => `${item.path}:${item.line}`).join(', ')}`, + 'Remove private absolute paths from public release docs and keep raw media in the local production workspace.', + { forbiddenPaths } + ), + makeCheck( + 'video-source-assets-present', + missingSourceAssets.length === 0 ? 'pass' : 'fail', + missingSourceAssets.length === 0 + ? `${sourceAssets.length} source assets are present` + : `missing source assets: ${missingSourceAssets.map(asset => asset.file).join(', ')}`, + 'Set ECC_VIDEO_SOURCE_ROOT or pass --source-root to the edited ECC 2 media directory.', + { + configured: Boolean(sourceRoot), + missing: missingSourceAssets.map(asset => asset.file), + } + ), + makeCheck( + 'video-release-artifacts-present', + missingSuiteArtifacts.length === 0 ? 'pass' : 'fail', + missingSuiteArtifacts.length === 0 + ? `${suiteArtifacts.length} render, timeline, caption, EDL, and segment artifacts are present` + : `missing or invalid suite artifacts: ${missingSuiteArtifacts.map(artifact => artifact.relativePath).join(', ')}`, + 'Set ECC_VIDEO_RELEASE_SUITE_ROOT or pass --suite-root to the ECC 2 release suite workspace.', + { + configured: Boolean(suiteRoot), + missing: missingSuiteArtifacts.map(artifact => artifact.relativePath), + } + ), + ]; + + const failed = checks.filter(check => check.status !== 'pass'); + const topActions = []; + + if (!sourceRoot) { + topActions.push('Set ECC_VIDEO_SOURCE_ROOT to the edited ECC 2 media directory.'); + } + + if (!suiteRoot) { + topActions.push('Set ECC_VIDEO_RELEASE_SUITE_ROOT to the local release suite workspace.'); + } + + for (const check of failed) { + if (check.fix && !topActions.includes(check.fix)) { + topActions.push(check.fix); + } + } + + return { + schema_version: SCHEMA_VERSION, + release: RELEASE, + generatedAt: options.generatedAt || new Date().toISOString(), + root: rootDir, + sourceRootConfigured: Boolean(sourceRoot), + suiteRootConfigured: Boolean(suiteRoot), + mediaPathsRedacted: true, + ready: failed.length === 0, + checks, + sourceAssets, + suiteArtifacts, + top_actions: topActions, + }; +} + +function summarizeItems(items) { + const present = items.filter(item => item.status === 'present'); + const missing = items.filter(item => item.status !== 'present'); + + return { + total: items.length, + present: present.length, + missing: missing.map(item => item.file || item.relativePath), + }; +} + +function summarizeReport(report) { + const primaryRender = report.suiteArtifacts.find(item => item.id === 'primary-render-v1') || null; + + return { + schema_version: report.schema_version, + release: report.release, + generatedAt: report.generatedAt, + root: report.root, + sourceRootConfigured: report.sourceRootConfigured, + suiteRootConfigured: report.suiteRootConfigured, + mediaPathsRedacted: report.mediaPathsRedacted, + ready: report.ready, + checks: report.checks.map(check => ({ + id: check.id, + status: check.status, + summary: check.summary, + fix: check.fix, + })), + sourceAssetSummary: summarizeItems(report.sourceAssets), + suiteArtifactSummary: summarizeItems(report.suiteArtifacts), + primaryRender: primaryRender ? { + status: primaryRender.status, + durationSeconds: primaryRender.durationSeconds, + sizeMb: primaryRender.sizeMb, + } : null, + top_actions: report.top_actions, + }; +} + +function renderText(report) { + const lines = [ + `ECC ${report.release} release video suite`, + `Ready: ${report.ready ? 'yes' : 'no'}`, + `Source root configured: ${report.sourceRootConfigured ? 'yes' : 'no'}`, + `Suite root configured: ${report.suiteRootConfigured ? 'yes' : 'no'}`, + '', + 'Checks:', + ]; + + for (const check of report.checks) { + lines.push(`- ${check.status.toUpperCase()} ${check.id}: ${check.summary}`); + } + + const primaryRender = report.suiteArtifacts.find(item => item.id === 'primary-render-v1'); + if (primaryRender && primaryRender.status === 'present') { + lines.push(''); + lines.push( + `Primary rough render: ${primaryRender.relativePath}` + + (Number.isFinite(primaryRender.durationSeconds) ? ` (${primaryRender.durationSeconds}s)` : '') + ); + } + + if (report.top_actions.length > 0) { + lines.push(''); + lines.push('Top actions:'); + for (const action of report.top_actions) { + lines.push(`- ${action}`); + } + } + + return `${lines.join('\n')}\n`; +} + +function main() { + let options; + try { + options = parseArgs(process.argv); + } catch (error) { + console.error(error.message); + process.exit(2); + } + + if (options.help) { + usage(); + return; + } + + const report = buildReport(options); + const outputReport = options.summary ? summarizeReport(report) : report; + + if (options.format === 'json') { + console.log(JSON.stringify(outputReport, null, 2)); + } else { + process.stdout.write(renderText(report)); + } + + process.exit(report.ready ? 0 : 1); +} + +if (require.main === module) { + main(); +} + +module.exports = { + REQUIRED_SOURCE_ASSETS, + REQUIRED_SUITE_ARTIFACTS, + buildReport, + parseArgs, + renderText, + summarizeReport, +}; diff --git a/tests/docs/ecc2-release-surface.test.js b/tests/docs/ecc2-release-surface.test.js index dc3f4222..3991504b 100644 --- a/tests/docs/ecc2-release-surface.test.js +++ b/tests/docs/ecc2-release-surface.test.js @@ -52,6 +52,7 @@ const expectedReleaseFiles = [ 'quickstart.md', 'preview-pack-manifest.md', 'publication-readiness.md', + 'video-suite-production.md', 'release-name-plugin-publication-checklist-2026-05-18.md', ]; @@ -176,6 +177,7 @@ test('preview pack manifest assembles release, Hermes, and publication gates', ( 'docs/releases/2.0.0-rc.1/publication-readiness.md', 'docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md', 'docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md', + 'docs/releases/2.0.0-rc.1/video-suite-production.md', 'docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md', ]) { assert.ok(manifest.includes(artifact), `preview pack manifest missing ${artifact}`); @@ -194,6 +196,7 @@ test('preview pack manifest assembles release, Hermes, and publication gates', ( assert.ok(manifest.includes('no raw workspace exports')); assert.ok(manifest.includes('Final Verification Commands')); assert.ok(manifest.includes('npm run preview-pack:smoke')); + assert.ok(manifest.includes('npm run release:video-suite -- --format json')); assert.ok(manifest.includes('Reference-Inspired Adapter Direction')); }); @@ -231,6 +234,60 @@ test('launch checklist records the ecc2 alpha version policy', () => { assert.ok(!launchChecklist.includes('confirm whether `ecc2/Cargo.toml` moves')); }); +test('release video suite manifest gates the content launch lane', () => { + const videoManifest = read('docs/releases/2.0.0-rc.1/video-suite-production.md'); + const launchChecklist = read('docs/releases/2.0.0-rc.1/launch-checklist.md'); + const hypergrowth = read('docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md'); + const packageJson = JSON.parse(read('package.json')); + + for (const marker of [ + 'ECC 2.0 Video Suite Production Manifest', + 'ECC_VIDEO_SOURCE_ROOT', + 'ECC_VIDEO_RELEASE_SUITE_ROOT', + 'video-use compatible workflow', + 'Self-Eval Gate', + 'Do Not Publish If', + 'renders/ecc-2-primary-launch-rough-v1.mp4', + 'timelines/primary-launch-v1.timeline.json', + 'Primary launch video', + ]) { + assert.ok(videoManifest.includes(marker), `video suite manifest missing ${marker}`); + } + + for (const asset of [ + 'longform-full-wide.mp4', + 'sf-thread-2-whatisecc.mp4', + 'thread-2-ghapp-money.mp4', + 'coverage-montage-wide.mp4', + 'star_history.png', + 'x_analytics.png', + ]) { + assert.ok(videoManifest.includes(asset), `video suite manifest missing asset ${asset}`); + } + + assert.ok(launchChecklist.includes('npm run release:video-suite -- --format json')); + assert.ok(hypergrowth.includes('Validate `video-suite-production.md`')); + assert.strictEqual(packageJson.scripts['release:video-suite'], 'node scripts/release-video-suite.js'); + assert.ok(packageJson.files.includes('scripts/release-video-suite.js')); +}); + +test('release video suite public docs do not expose private media paths', () => { + const releaseVideoDocs = [ + 'docs/releases/2.0.0-rc.1/video-suite-production.md', + 'docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md', + ]; + + const offenders = []; + for (const relativePath of releaseVideoDocs) { + const source = read(relativePath); + if (/\/Users\/[A-Za-z0-9._-]+|\/home\/(?!user|runner)[A-Za-z0-9._-]+/.test(source)) { + offenders.push(relativePath); + } + } + + assert.deepStrictEqual(offenders, []); +}); + test('publication readiness checklist gates public release actions on evidence', () => { const source = read('docs/releases/2.0.0-rc.1/publication-readiness.md'); const may15Evidence = read('docs/releases/2.0.0-rc.1/publication-evidence-2026-05-15.md'); diff --git a/tests/scripts/npm-publish-surface.test.js b/tests/scripts/npm-publish-surface.test.js index 7cb3857d..51df54c7 100644 --- a/tests/scripts/npm-publish-surface.test.js +++ b/tests/scripts/npm-publish-surface.test.js @@ -60,6 +60,7 @@ function buildExpectedPublishPaths(repoRoot) { "scripts/operator-readiness-dashboard.js", "scripts/platform-audit.js", "scripts/preview-pack-smoke.js", + "scripts/release-video-suite.js", "scripts/skill-create-output.js", "scripts/repair.js", "scripts/harness-adapter-compliance.js", @@ -131,6 +132,7 @@ function main() { "scripts/discussion-audit.js", "scripts/operator-readiness-dashboard.js", "scripts/preview-pack-smoke.js", + "scripts/release-video-suite.js", "scripts/work-items.js", "scripts/platform-audit.js", ".gemini/GEMINI.md", diff --git a/tests/scripts/release-video-suite.test.js b/tests/scripts/release-video-suite.test.js new file mode 100644 index 00000000..4cab6be2 --- /dev/null +++ b/tests/scripts/release-video-suite.test.js @@ -0,0 +1,303 @@ +/** + * Tests for scripts/release-video-suite.js + */ + +const assert = require('assert'); +const fs = require('fs'); +const os = require('os'); +const path = require('path'); +const { execFileSync, spawnSync } = require('child_process'); + +const SCRIPT = path.join(__dirname, '..', '..', 'scripts', 'release-video-suite.js'); +const { + REQUIRED_SOURCE_ASSETS, + REQUIRED_SUITE_ARTIFACTS, + buildReport, + parseArgs, + renderText, + summarizeReport, +} = require(SCRIPT); + +function createTempDir(prefix) { + return fs.mkdtempSync(path.join(os.tmpdir(), prefix)); +} + +function cleanup(dirPath) { + fs.rmSync(dirPath, { recursive: true, force: true }); +} + +function writeFile(rootDir, relativePath, content = 'fixture') { + const targetPath = path.join(rootDir, relativePath); + fs.mkdirSync(path.dirname(targetPath), { recursive: true }); + fs.writeFileSync(targetPath, content); +} + +function seedRepo(rootDir, overrides = {}) { + const files = { + 'package.json': JSON.stringify({ + name: 'ecc-universal', + files: ['scripts/release-video-suite.js'], + scripts: { + 'release:video-suite': 'node scripts/release-video-suite.js', + }, + }, null, 2), + 'docs/releases/2.0.0-rc.1/video-suite-production.md': [ + '# ECC 2.0 Video Suite Production Manifest', + 'ECC_VIDEO_SOURCE_ROOT', + 'ECC_VIDEO_RELEASE_SUITE_ROOT', + 'Primary launch video', + 'video-use compatible workflow', + 'Self-Eval Gate', + 'Do Not Publish If', + 'Do not commit raw footage, transcript JSON, or timeline exports', + ].join('\n'), + 'docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md': [ + 'Keep raw absolute paths out of public docs', + 'Validate `video-suite-production.md`', + ].join('\n'), + 'docs/releases/2.0.0-rc.1/preview-pack-manifest.md': 'video-suite-production.md', + 'docs/releases/2.0.0-rc.1/launch-checklist.md': 'release video suite', + }; + + for (const [relativePath, content] of Object.entries({ ...files, ...overrides })) { + if (content === null) { + continue; + } + writeFile(rootDir, relativePath, content); + } +} + +function seedMedia(sourceRoot, suiteRoot) { + for (const asset of REQUIRED_SOURCE_ASSETS) { + writeFile(sourceRoot, asset.file, `source ${asset.id}`); + } + + for (const artifact of REQUIRED_SUITE_ARTIFACTS) { + writeFile(suiteRoot, artifact.relativePath, `artifact ${artifact.id}`); + } +} + +function run(args = [], options = {}) { + return execFileSync('node', [SCRIPT, ...args], { + cwd: options.cwd || path.join(__dirname, '..', '..'), + encoding: 'utf8', + stdio: ['pipe', 'pipe', 'pipe'], + timeout: 10000, + }); +} + +function runProcess(args = [], options = {}) { + return spawnSync('node', [SCRIPT, ...args], { + cwd: options.cwd || path.join(__dirname, '..', '..'), + encoding: 'utf8', + stdio: ['pipe', 'pipe', 'pipe'], + timeout: 10000, + }); +} + +function test(name, fn) { + try { + fn(); + console.log(` PASS ${name}`); + return true; + } catch (error) { + console.log(` FAIL ${name}`); + console.log(` Error: ${error.message}`); + return false; + } +} + +function runTests() { + console.log('\n=== Testing release-video-suite.js ===\n'); + + let passed = 0; + let failed = 0; + + if (test('parseArgs accepts release video flags and rejects invalid values', () => { + const rootDir = createTempDir('release-video-args-'); + const sourceRoot = createTempDir('release-video-source-'); + const suiteRoot = createTempDir('release-video-suite-'); + + try { + const parsed = parseArgs([ + 'node', + 'script', + '--json', + `--root=${rootDir}`, + '--source-root', + sourceRoot, + `--suite-root=${suiteRoot}`, + '--skip-probe', + '--summary', + ]); + + assert.strictEqual(parsed.format, 'json'); + assert.strictEqual(parsed.root, path.resolve(rootDir)); + assert.strictEqual(parsed.sourceRoot, path.resolve(sourceRoot)); + assert.strictEqual(parsed.suiteRoot, path.resolve(suiteRoot)); + assert.strictEqual(parsed.skipProbe, true); + assert.strictEqual(parsed.summary, true); + + assert.throws(() => parseArgs(['node', 'script', '--format', 'xml']), /Invalid format/); + assert.throws(() => parseArgs(['node', 'script', '--source-root']), /--source-root requires a value/); + assert.throws(() => parseArgs(['node', 'script', '--unknown']), /Unknown argument/); + } finally { + cleanup(rootDir); + cleanup(sourceRoot); + cleanup(suiteRoot); + } + })) passed++; else failed++; + + if (test('buildReport passes with a sanitized manifest and complete local media fixture', () => { + const rootDir = createTempDir('release-video-report-'); + const sourceRoot = createTempDir('release-video-source-'); + const suiteRoot = createTempDir('release-video-suite-'); + + try { + seedRepo(rootDir); + seedMedia(sourceRoot, suiteRoot); + + const report = buildReport({ + root: rootDir, + sourceRoot, + suiteRoot, + skipProbe: true, + generatedAt: '2026-05-19T00:00:00.000Z', + }); + + assert.strictEqual(report.schema_version, 'ecc.release-video-suite.v1'); + assert.strictEqual(report.ready, true); + assert.strictEqual(report.mediaPathsRedacted, true); + assert.ok(report.checks.every(check => check.status === 'pass')); + assert.strictEqual(report.sourceAssets.length, REQUIRED_SOURCE_ASSETS.length); + assert.strictEqual(report.suiteArtifacts.length, REQUIRED_SUITE_ARTIFACTS.length); + assert.ok(renderText(report).includes('Ready: yes')); + assert.strictEqual(summarizeReport(report).sourceAssetSummary.present, REQUIRED_SOURCE_ASSETS.length); + } finally { + cleanup(rootDir); + cleanup(sourceRoot); + cleanup(suiteRoot); + } + })) passed++; else failed++; + + if (test('missing local roots keep the release video gate blocked', () => { + const rootDir = createTempDir('release-video-missing-roots-'); + + try { + seedRepo(rootDir); + + const report = buildReport({ + root: rootDir, + skipProbe: true, + generatedAt: '2026-05-19T00:00:00.000Z', + }); + + assert.strictEqual(report.ready, false); + assert.ok(report.top_actions.some(action => action.includes('ECC_VIDEO_SOURCE_ROOT'))); + assert.ok(report.top_actions.some(action => action.includes('ECC_VIDEO_RELEASE_SUITE_ROOT'))); + assert.ok(report.checks.some(check => check.id === 'video-source-assets-present' && check.status === 'fail')); + assert.ok(report.checks.some(check => check.id === 'video-release-artifacts-present' && check.status === 'fail')); + } finally { + cleanup(rootDir); + } + })) passed++; else failed++; + + if (test('private media paths in public docs fail sanitization', () => { + const rootDir = createTempDir('release-video-private-path-'); + const sourceRoot = createTempDir('release-video-source-'); + const suiteRoot = createTempDir('release-video-suite-'); + + try { + seedRepo(rootDir, { + 'docs/releases/2.0.0-rc.1/video-suite-production.md': [ + '# ECC 2.0 Video Suite Production Manifest', + 'ECC_VIDEO_SOURCE_ROOT', + 'ECC_VIDEO_RELEASE_SUITE_ROOT', + 'Primary launch video', + 'video-use compatible workflow', + 'Self-Eval Gate', + 'Do Not Publish If', + 'Do not commit raw footage, transcript JSON, or timeline exports', + '/Users/affoon/private-media', + ].join('\n'), + }); + seedMedia(sourceRoot, suiteRoot); + + const report = buildReport({ + root: rootDir, + sourceRoot, + suiteRoot, + skipProbe: true, + generatedAt: '2026-05-19T00:00:00.000Z', + }); + + assert.strictEqual(report.ready, false); + assert.ok(report.checks.some(check => check.id === 'video-suite-public-sanitization' && check.status === 'fail')); + } finally { + cleanup(rootDir); + cleanup(sourceRoot); + cleanup(suiteRoot); + } + })) passed++; else failed++; + + if (test('CLI emits JSON and exits successfully for complete fixture', () => { + const rootDir = createTempDir('release-video-cli-'); + const sourceRoot = createTempDir('release-video-source-'); + const suiteRoot = createTempDir('release-video-suite-'); + + try { + seedRepo(rootDir); + seedMedia(sourceRoot, suiteRoot); + + const output = run([ + '--format=json', + `--root=${rootDir}`, + `--source-root=${sourceRoot}`, + `--suite-root=${suiteRoot}`, + '--skip-probe', + '--summary', + ], { cwd: rootDir }); + const parsed = JSON.parse(output); + + assert.strictEqual(parsed.ready, true); + assert.strictEqual(parsed.sourceRootConfigured, true); + assert.strictEqual(parsed.suiteRootConfigured, true); + assert.strictEqual(parsed.sourceAssetSummary.present, REQUIRED_SOURCE_ASSETS.length); + assert.strictEqual(parsed.suiteArtifactSummary.present, REQUIRED_SUITE_ARTIFACTS.length); + } finally { + cleanup(rootDir); + cleanup(sourceRoot); + cleanup(suiteRoot); + } + })) passed++; else failed++; + + if (test('CLI exits nonzero when media roots are missing', () => { + const rootDir = createTempDir('release-video-cli-blocked-'); + + try { + seedRepo(rootDir); + + const result = runProcess([ + '--format=json', + `--root=${rootDir}`, + '--skip-probe', + '--summary', + ], { cwd: rootDir }); + + assert.strictEqual(result.status, 1); + const parsed = JSON.parse(result.stdout); + assert.strictEqual(parsed.ready, false); + } finally { + cleanup(rootDir); + } + })) passed++; else failed++; + + console.log(`\nPassed: ${passed}`); + console.log(`Failed: ${failed}`); + + process.exit(failed > 0 ? 1 : 0); +} + +if (require.main === module) { + runTests(); +} From 7a0645ed47d6a3aca54b4a214aab6dfaa58e770d Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 07:33:41 -0400 Subject: [PATCH 32/61] docs: add ECC 2 growth outreach pack (#1993) --- docs/releases/2.0.0-rc.1/launch-checklist.md | 5 + .../2.0.0-rc.1/partner-sponsor-talks-pack.md | 208 ++++++++++++++++++ .../2.0.0-rc.1/preview-pack-manifest.md | 1 + docs/releases/2.0.0-rc.1/release-notes.md | 4 +- ...cc-2-hypergrowth-release-command-center.md | 7 +- scripts/preview-pack-smoke.js | 1 + tests/docs/ecc2-release-surface.test.js | 39 ++++ 7 files changed, 262 insertions(+), 3 deletions(-) create mode 100644 docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md diff --git a/docs/releases/2.0.0-rc.1/launch-checklist.md b/docs/releases/2.0.0-rc.1/launch-checklist.md index aa015d95..ac635ae9 100644 --- a/docs/releases/2.0.0-rc.1/launch-checklist.md +++ b/docs/releases/2.0.0-rc.1/launch-checklist.md @@ -36,6 +36,8 @@ - publish the X thread from `x-thread.md` - publish the LinkedIn draft from `linkedin-post.md` - use `article-outline.md` for the longer writeup +- route sponsor, partner, consulting, conference, podcast, and GitHub + Discussion copy through `partner-sponsor-talks-pack.md` - record one 30-60 second proof-of-work clip - validate the release video suite with `npm run release:video-suite -- --format json` after setting `ECC_VIDEO_SOURCE_ROOT` and `ECC_VIDEO_RELEASE_SUITE_ROOT` @@ -58,3 +60,6 @@ Use language like: - "cross-harness operating system for agentic work" - "ECC is the reusable substrate; Hermes is the operator shell" - "private/local integrations land after sanitization" + +Do not send sponsor, partner, consulting, conference, or podcast outreach +without explicit human approval. diff --git a/docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md b/docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md new file mode 100644 index 00000000..ef7c47c7 --- /dev/null +++ b/docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md @@ -0,0 +1,208 @@ +# ECC v2.0.0-rc.1 Partner, Sponsor, and Talks Pack + +This pack turns the rc.1 release surface into outbound-ready copy for sponsors, +partners, consulting conversations, conference talks, podcast bookings, and +community announcements. + +It is not a publish action. Use it after the release URL ledger, video suite, +and publication gates are current. + +## Current Business Baseline + +| Metric | Current | Target | Gap | +| --- | ---: | ---: | ---: | +| MRR | `$1,728/mo` | `$10,000/mo` | `$8,272/mo` | +| Core revenue lanes | Sponsors, ECC Tools Pro, consulting, talks | Repeatable growth loop | Approval-gated outbound | +| Launch proof | rc.1 preview pack, video suite, queue-zero audit | Public release package | Final URLs and human approval | + +## Positioning Line + +ECC 2.0 is the harness-native operator system for agentic work. + +Use this short version in partner and sponsor messages: + +```text +ECC gives teams one reusable layer for skills, hooks, rules, MCP conventions, +release gates, and operator workflows across Claude Code, Codex, OpenCode, +Cursor, Gemini, Zed, GitHub Copilot, and terminal-only workflows. +``` + +## Offer Ladder + +| Motion | Best fit | Starting point | Primary ask | +| --- | --- | ---: | --- | +| Pilot sponsor | OSS-friendly team that wants early signal | `$200/mo` | GitHub Sponsors | +| Business sponsor | Tooling or AI infra company that wants logo and case-study surface | `$500/mo` | GitHub Sponsors or direct invoice | +| Strategic partner | Platform, marketplace, security, or developer-tool company | `$1,000+/mo` | Sponsor plus launch or integration plan | +| Consulting sprint | Team adopting agent harnesses internally | Scoped quote | Harness audit, rollout plan, and operating loop | +| Talk or podcast | Devtools, AI engineering, security, OSS, or founder audience | No fee required for high-leverage reach | Recording slot, demo slot, or conference proposal | + +## Partner Targets + +Prioritize partners that already benefit from a harness-agnostic operating +layer: + +- AI coding platforms and IDEs; +- hosted agent and workflow orchestration tools; +- code review, security, and supply-chain vendors; +- model and inference providers; +- developer education, podcast, and conference organizers; +- teams adopting multiple harnesses at once. + +## Sponsor Outbound + +Subject: + +```text +ECC 2.0 sponsor slot for cross-harness agent workflows +``` + +Body: + +```text +Hey [name], + +I am getting ECC v2.0.0-rc.1 ready for release review. + +The project is now positioned around one reusable operator layer for agentic +work across Claude Code, Codex, OpenCode, Cursor, Gemini, Zed, GitHub Copilot, +and terminal workflows. + +The sponsor fit is pretty direct: ECC reaches the exact builders who are +standardizing their AI coding stack, security posture, and workflow automation. + +The current public sponsor ladder is: + +- Pilot Partner: $200/mo +- Business Sponsor: $500/mo +- Strategic Partner: $1,000+/mo + +Business sponsors get logo placement and release visibility. Strategic partners +can turn it into a deeper integration or launch motion. + +Repo: https://github.com/affaan-m/ECC +Sponsor: https://github.com/sponsors/affaan-m +Release notes: https://github.com/affaan-m/ECC/blob/main/docs/releases/2.0.0-rc.1/release-notes.md + +If useful, I can send the short sponsor packet and a proposed first 30-day plan. + +Affaan +``` + +## Platform Partner DM + +```text +ECC 2.0 is getting close to rc.1. + +The release is centered on cross-harness agent workflows: reusable skills, +hooks, rules, MCP conventions, release gates, and an optional Hermes operator +shell. + +The partner angle is not "another prompt pack." It is a tested operating layer +for teams using more than one AI coding harness. + +I think there is a real integration or co-launch angle here if your team wants +better setup, policy, security, or workflow portability for agent users. + +Repo: https://github.com/affaan-m/ECC +``` + +## Consulting Intro + +```text +I am open to a small number of ECC 2.0 implementation sprints for teams that +are standardizing AI coding workflows. + +The useful scope is usually: + +1. audit the current harness setup; +2. turn repeated workflows into ECC skills, hooks, and rules; +3. add release, security, and CI gates; +4. create a team operating loop that works across Claude Code, Codex, OpenCode, + Cursor, Gemini, Zed, GitHub Copilot, and terminal workflows. + +This is not generic AI consulting. The output is a working harness operating +system your team can keep using. +``` + +## Talk And Podcast Pitch + +Title options: + +- Building a Cross-Harness Operating System for AI Coding +- From Prompt Packs to Operator Systems +- What Breaks When Teams Adopt Too Many AI Coding Harnesses +- Security and Release Discipline for Agentic Coding Workflows + +Short pitch: + +```text +ECC started as an open-source workflow layer for Claude Code and is now moving +toward a cross-harness operating system for agentic work. + +The talk is about the practical problems teams hit after the first AI coding +honeymoon: scattered prompts, duplicated setup, weak release gates, fragile +security posture, and no clear operating loop across tools. + +I can show how ECC uses reusable skills, hooks, MCP conventions, release gates, +AgentShield-style security checks, and an optional Hermes operator shell to make +agentic work more measurable and portable. +``` + +## GitHub Discussion Announcement + +```text +ECC v2.0.0-rc.1 preview pack is ready for final release review. + +The main point: ECC 2.0 is the harness-native operator system for agentic work. + +It now has a reviewed public surface for: + +- reusable skills, hooks, rules, and MCP conventions; +- Claude Code, Codex, OpenCode, Cursor, Gemini, Zed, GitHub Copilot, and + terminal workflows; +- Hermes as the optional operator shell; +- release, security, queue, discussion, Linear, observability, and video-suite + gates. + +The release is still approval-gated until the GitHub prerelease, npm package, +plugin paths, final URLs, and billing claims have live evidence. + +Feedback wanted: install friction, cross-harness gaps, partner integrations, +sponsor fit, and examples of teams using multiple AI coding harnesses. +``` + +## Video CTA Hooks + +Use these with the release video suite: + +- "If your AI coding setup only works in one harness, it is not an operating + system yet." +- "ECC 2.0 is the shared layer: skills, hooks, MCPs, release gates, and team + workflows across the tools people actually use." +- "OSS stays free. Sponsors, Pro, and implementation work fund the public + layer." +- "Start with one workflow lane: engineering, research, content, or outreach." + +## Do Not Send Or Publish If + +- The release URL ledger still has stale or placeholder links. +- `npm run release:video-suite -- --format json` is not green against the + intended video roots. +- The GitHub prerelease, npm package, plugin path, or billing claim is described + as live without evidence. +- The message claims native payments are ready before ECC Tools billing readback + passes. +- The recipient needs a custom promise that is not covered by `SPONSORS.md`, + `SPONSORING.md`, or a separate consulting scope. +- The user has not approved outbound sponsor, partner, consulting, or media + messages. + +## Routing Links + +- Repo: +- Release notes: +- Quickstart: +- Sponsor: +- Sponsor tiers: +- Sponsoring guide: diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index f8f6ac3f..ee834e35 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -29,6 +29,7 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and publication, plugin, billing, AgentShield, ECC Tools, legacy, and Linear productization gaps still open | | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md` | Live URL and approval-gated URL ledger for release copy | Must be regenerated from the final release commit before public announcements | | `docs/releases/2.0.0-rc.1/video-suite-production.md` | Release video production manifest | Gates local media inventory, rough primary render, captions, timeline, self-eval, and no-private-path publication rules | +| `docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md` | Partner, sponsor, consulting, conference, podcast, and discussion copy | Must stay approval-gated and avoid live billing, release, package, or plugin claims without evidence | | `docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md` | Naming, slug, and publication-path decision record | Keeps `ECC`, npm `ecc-universal`, and plugin slug `ecc` for rc.1 | | `docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md` | Release name, package, Claude plugin, Codex plugin, and publication-order checklist | Freezes rc.1 identity and requires final commit evidence before release, npm, plugin, billing, or announcement actions | | `docs/releases/2.0.0-rc.1/x-thread.md` | X launch draft | Must replace placeholders with live URLs after release/package/plugin publication | diff --git a/docs/releases/2.0.0-rc.1/release-notes.md b/docs/releases/2.0.0-rc.1/release-notes.md index d832c9ac..eaed97b5 100644 --- a/docs/releases/2.0.0-rc.1/release-notes.md +++ b/docs/releases/2.0.0-rc.1/release-notes.md @@ -46,8 +46,8 @@ feature branch: - documentation expansion, Japanese localization, zh-CN to ja-JP parity repair, and dependency readiness through TypeScript 6 and Node type updates; - launch collateral for GitHub release copy, X, LinkedIn, article outline, - Telegram/Hermes handoff, demo prompts, and the approval-gated launch - checklist. + Telegram/Hermes handoff, demo prompts, partner/sponsor/talk outreach, and + the approval-gated launch checklist. - a release URL ledger that separates links which already resolve from links that must wait for the GitHub release, npm rc package, plugin tag/directory, and ECC Tools billing readback. diff --git a/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md b/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md index f1563e06..09657477 100644 --- a/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md +++ b/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md @@ -100,6 +100,10 @@ Production steps: | Podcasts/talks | one-page pitch, demo outline, founder proof | bookings, partners | | Sponsor outbound | direct sponsor note and tier table | GitHub Sponsors or Pro | +The source of truth for sponsor, partner, consulting, conference, podcast, and +GitHub Discussion copy is +`docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md`. + ## Copy Rules Use direct product language: @@ -130,7 +134,7 @@ Avoid: surfaces for b-roll. 6. Render the primary launch video plus five short clips. 7. Finalize GitHub release, X thread, LinkedIn post, Discussion announcement, - sponsor email copy, and podcast/talk pitch. + sponsor email copy, consulting intro, partner DM, and podcast/talk pitch. 8. Publish only after npm, plugin, release URL, and billing-readback gates are either live or explicitly marked blocked. @@ -143,4 +147,5 @@ These actions need a human approval or credential before they move: - wiring Discord with a bot token and guild ID; - publishing npm or creating plugin tags; - announcing billing/native payments; +- sending partner, consulting, conference, podcast, or sponsor outreach; - posting final social copy from personal accounts. diff --git a/scripts/preview-pack-smoke.js b/scripts/preview-pack-smoke.js index 598e8fc2..e004e09b 100644 --- a/scripts/preview-pack-smoke.js +++ b/scripts/preview-pack-smoke.js @@ -30,6 +30,7 @@ const REQUIRED_ARTIFACTS = [ `${RELEASE_DIR}/operator-readiness-dashboard-2026-05-18.md`, `${RELEASE_DIR}/release-url-ledger-2026-05-19.md`, `${RELEASE_DIR}/video-suite-production.md`, + `${RELEASE_DIR}/partner-sponsor-talks-pack.md`, `${RELEASE_DIR}/naming-and-publication-matrix.md`, `${RELEASE_DIR}/release-name-plugin-publication-checklist-2026-05-18.md`, `${RELEASE_DIR}/x-thread.md`, diff --git a/tests/docs/ecc2-release-surface.test.js b/tests/docs/ecc2-release-surface.test.js index 3991504b..c7745d88 100644 --- a/tests/docs/ecc2-release-surface.test.js +++ b/tests/docs/ecc2-release-surface.test.js @@ -53,6 +53,7 @@ const expectedReleaseFiles = [ 'preview-pack-manifest.md', 'publication-readiness.md', 'video-suite-production.md', + 'partner-sponsor-talks-pack.md', 'release-name-plugin-publication-checklist-2026-05-18.md', ]; @@ -128,6 +129,7 @@ test('business launch copy stays aligned with the rc.1 public surface', () => { test('announcement drafts avoid live-release claims before publication', () => { const announcementFiles = [ 'docs/releases/2.0.0-rc.1/linkedin-post.md', + 'docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md', 'docs/business/social-launch-copy.md', ]; @@ -271,6 +273,43 @@ test('release video suite manifest gates the content launch lane', () => { assert.ok(packageJson.files.includes('scripts/release-video-suite.js')); }); +test('partner sponsor talks pack gates the hypergrowth outbound lane', () => { + const partnerPack = read('docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md'); + const manifest = read('docs/releases/2.0.0-rc.1/preview-pack-manifest.md'); + const releaseNotes = read('docs/releases/2.0.0-rc.1/release-notes.md'); + const launchChecklist = read('docs/releases/2.0.0-rc.1/launch-checklist.md'); + const hypergrowth = read('docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md'); + + for (const marker of [ + 'Partner, Sponsor, and Talks Pack', + '$1,728/mo', + '$10,000/mo', + '$8,272/mo', + 'Pilot sponsor', + 'Business sponsor', + 'Strategic partner', + 'Consulting sprint', + 'Talk or podcast', + 'Sponsor Outbound', + 'Platform Partner DM', + 'Consulting Intro', + 'Talk And Podcast Pitch', + 'GitHub Discussion Announcement', + 'Video CTA Hooks', + 'Do Not Send Or Publish If', + 'The user has not approved outbound sponsor, partner, consulting, or media', + ]) { + assert.ok(partnerPack.includes(marker), `partner pack missing ${marker}`); + } + + assert.ok(partnerPack.includes('SPONSORS.md')); + assert.ok(partnerPack.includes('SPONSORING.md')); + assert.ok(manifest.includes('partner-sponsor-talks-pack.md')); + assert.ok(releaseNotes.includes('partner/sponsor/talk outreach')); + assert.ok(launchChecklist.includes('partner-sponsor-talks-pack.md')); + assert.ok(hypergrowth.includes('partner-sponsor-talks-pack.md')); +}); + test('release video suite public docs do not expose private media paths', () => { const releaseVideoDocs = [ 'docs/releases/2.0.0-rc.1/video-suite-production.md', From c07276a347f8dac4945d2ad294124a708c19b108 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 07:42:22 -0400 Subject: [PATCH 33/61] docs: refresh May 19 publication evidence --- docs/ECC-2.0-GA-ROADMAP.md | 25 +++-- .../2.0.0-rc.1/preview-pack-manifest.md | 3 +- .../publication-evidence-2026-05-19.md | 96 +++++++++++++++++++ .../2.0.0-rc.1/publication-readiness.md | 21 ++-- .../release-url-ledger-2026-05-19.md | 3 +- scripts/platform-audit.js | 8 +- scripts/preview-pack-smoke.js | 1 + tests/docs/ecc2-release-surface.test.js | 1 + .../operator-readiness-dashboard.test.js | 7 ++ tests/scripts/platform-audit.test.js | 12 +-- 10 files changed, 141 insertions(+), 36 deletions(-) create mode 100644 docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index 583893b8..ba557917 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -32,7 +32,7 @@ partner/sponsor funnel, consulting/talk funnel, and social launch plan. ## Current Evidence -As of 2026-05-18: +As of 2026-05-19: - GitHub queues are clean across `affaan-m/ECC`, `affaan-m/agentshield`, `affaan-m/JARVIS`, `ECC-Tools/ECC-Tools`, and @@ -75,14 +75,11 @@ As of 2026-05-18: recheck, `7911af4a` release OIDC publishing-scope hardening, `97567a91` release workflow line-ending normalization, and release evidence with a refreshed operator dashboard. -- `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` records the - May 18 queue-zero state, current-head TanStack/Mini Shai-Hulud protection - recheck, no-lifecycle npm install, npm audit/signature checks, AgentShield - project `.claude` scan, Linear sync, work-items sync, operator dashboard - refresh, PR #1976 provider-guard validation, ECC-Tools Wrangler OAuth billing - readback evidence, defensive-deny IOC scanner coverage, and current-head CI - success for `97567a91`; a detached clean-worktree preview-pack smoke from - `680aeff0` passed 5/5 with digest `0ed831dbd0cf`. +- `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` records the + current May 19 queue-zero state, canonical ECC identity merge, release video + suite gate, partner/sponsor/talk outreach pack, preview-pack smoke digest + `3bb55807407b`, local 2544-test suite, and PR #1993 CI success. The May 18 + evidence remains the detailed supply-chain and publication-path snapshot. - `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` regenerates the ITO-44 prompt-to-artifact dashboard from live platform audit evidence: PR queue, issue queue, discussion queue, local worktree gate, @@ -733,16 +730,16 @@ is not complete unless the evidence column exists and has been freshly verified. | Prompt requirement | Required artifact or gate | Current evidence | Status | | --- | --- | --- | --- | -| Keep public PRs below 20 | Repo-family PR recheck | 0 open PRs across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-18 after merging PR #1976 and refreshing platform audit evidence | Complete | -| Keep public issues below 20 | Repo-family issue recheck | 0 open issues across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-18 after the live platform audit refresh | Complete | +| Keep public PRs below 20 | Repo-family PR recheck | 0 open PRs across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-19 after merging PR #1993 and refreshing platform audit evidence | Complete | +| Keep public issues below 20 | Repo-family issue recheck | 0 open issues across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-19 after the live platform audit refresh | Complete | | Manage repository discussions | Repo-family discussion recheck plus response playbook | Platform audit reports 0 discussion maintainer-touch gaps and 0 answerable Q&A missing accepted answers; trunk still has 58 total discussions; `docs/architecture/discussion-response-playbook.md` distinguishes support, maintainer coordination, stale/concluded, release, informational, and security-sensitive response paths | Complete | -| Manage PR discussions | PR review/comment closure plus merge/close state | ECC #1976 merged after maintainer follow-up validation; no open tracked PRs remain | Complete | +| Manage PR discussions | PR review/comment closure plus merge/close state | ECC #1990-#1993 merged through the harness audit, canonical identity, release video suite, and growth outreach batch; no open tracked PRs remain | Complete | | Salvage useful stale work | `docs/stale-pr-salvage-ledger.md` plus `docs/legacy-artifact-inventory.md` | Ledger records salvaged, superseded, skipped, and manual-review tails; #1815-#1818 added cost tracking, skill scout, frontend design guidance, code-reviewer false-positive guardrails, and the May 12 gap pass; #1687, #1609, #1563, #1564, and #1565 localization tails are attached to Linear ITO-55 for language-owner review and no automatic import remains release-blocking | Complete; repeat legacy scan before release | -| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 18 evidence records queue-zero state, #1970/#1971/#1972/#1976 merge batch, supply-chain recheck, defensive-deny IOC scanner hardening, npm no-lifecycle install/audit/signature gates, Linear sync, refreshed operator dashboard, provider-guard validation, ECC-Tools Wrangler OAuth billing readback evidence, successful current-head CI on `04d4d819`, and detached clean-worktree preview-pack smoke digest `59bbf2630a44` | Needs final release approval | +| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 19 evidence records queue-zero state, canonical ECC identity, release video suite, growth outreach pack, local 2544-test suite, PR #1993 CI success, and preview-pack smoke digest `3bb55807407b` | Needs final release approval | | Hermes specialized skills included safely | Hermes setup/import docs and sanitized skill surface | Hermes setup and import playbook are public; secrets stay local | Needs final release review | | Naming and rename readiness | Naming matrix across package/plugin/docs/social surfaces | `docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md` records current package, repo, Claude plugin, Codex plugin, OpenCode, and npm availability evidence | Complete for rc.1; post-rc rename remains future work | | Claude and Codex plugin publication | Contact/submission path with required artifacts and status | Publication readiness, naming matrix, and May 12 dry-run evidence document plugin validation, clean-checkout Claude tag/install smoke, and Codex marketplace CLI shape | Needs explicit approval for real tag/push and marketplace submission | -| Articles, tweets, and announcements | X thread, LinkedIn copy, GitHub release copy, push checklist | Draft launch collateral exists under rc.1 release docs | Needs URL-backed refresh | +| Articles, tweets, and announcements | X thread, LinkedIn copy, GitHub release copy, push checklist, partner/sponsor/talk pack | Draft launch collateral and approval-gated outreach copy exist under rc.1 release docs | Needs URL-backed refresh and human approval before posting or sending | | AgentShield enterprise iteration | Policy gates, SARIF, packs, provenance, corpus, HTML reports, exception lifecycle audit, baseline drift Action/CLI surfaces, evidence-pack redaction, harness adapter registry, enterprise research roadmap, supply-chain hardened release path, CI-safe baseline fingerprints, corpus accuracy recommendations, remediation workflow phases, env proxy hijack corpus coverage, Mini Shai-Hulud full-campaign package IOCs, CI-provenance evidence packs, plugin-cache runtime-confidence triage, evidence-pack consumer readback, fleet-level evidence-pack routing, fleet review items, fleet review ticket payloads, checksum-backed policy export, checksum-verified policy promotion, policy promotion review items, package-manager hardening drift detection, npm age-gate guidance correction, workflow action-runtime pin refresh, package-manager hardening Action outputs, policy-promotion Action outputs, ECC-Tools hosted consumption of promotion Action outputs, ECC-Tools operator-visible promotion output values, and ECC-Tools hosted promotion judge audit traces | PRs #53, #55-#64, #67-#69, and #78-#92 landed with test evidence, ECC-Tools #76 consumes the fleet-summary output in hosted security review, #77 surfaces source evidence paths in hosted finding output, and #78 links fleet routes to harness owner review; AgentShield #91 adds `agentshield policy export` bundles for branch-protection review and downstream promotion; AgentShield #92 adds `agentshield policy promote` with digest verification, tamper rejection, explicit pack selection, dry-run review, and JSON output before writing active policy; AgentShield commit `87aec47` adds `reviewItems` for digest evidence, owner review, protected rollout PR handoff, and runtime smoke testing with green local and remote CI; AgentShield commit `28d08c7` adds package-manager hardening drift detection for plaintext registry credentials, lifecycle-script enablement, and weak pnpm/Yarn release-age cooldowns with green local and remote CI; AgentShield commit `659f569` refreshes all workflow action runtime pins to SHA-pinned checkout v6.0.2 and setup-node v6.4.0 with green remote CI and no remaining action-runtime deprecation annotation; AgentShield commit `ee585cd` corrects npm release-age guidance by flagging unsupported npm age keys and keeping enforceable cooldown findings on pnpm/Yarn with green local and remote CI; AgentShield commit `1124535` exposes package-manager hardening status/count outputs and a redacted job-summary section for registry credentials, lifecycle scripts, and release-age gates with green local and remote CI; AgentShield commit `1593925` exposes policy-promotion status/count/digest outputs plus job-summary review items for owner approval, protected rollout, and runtime smoke, and marks runtime smoke verified when the same Action job scans with the promoted policy; AgentShield commit `840952a` adds Linear/operator-ready fleet review ticket payloads and expands current Mini Shai-Hulud IOC breadcrumbs with green local and remote CI; ECC-Tools commit `8658951` routes those policy-promotion Action outputs into hosted security review findings and Hosted Promotion Readiness scoring; ECC-Tools commit `16c537f` renders policy-promotion status, pack, review item count, action-required count, and digest in hosted security job comments/check-runs; ECC-Tools commit `05d4e82` renders hosted promotion judge request fingerprints and allowed-citation counts without raw provider output; native PDF export deferred in favor of self-contained HTML plus print-to-PDF until explicit enterprise demand appears; `docs/architecture/agentshield-enterprise-research-roadmap.md` now has baseline drift, evidence-pack bundle, redaction, adapter-registry, supply-chain hardening, hashed baseline fingerprints, corpus accuracy recommendation, remediation workflow, env proxy hijack corpus, Mini Shai-Hulud full-campaign package-table, `ci-context.json` provenance, `plugin-cache` confidence, `evidence-pack inspect` readback, `evidence-pack fleet` routing, fleet `reviewItems`, fleet review ticket payloads, policy export, policy promotion, policy promotion `reviewItems`, package-manager hardening Action outputs, policy-promotion Action outputs, hosted consumption of promotion Action outputs, operator-visible promotion output values, and hosted promotion judge audit traces landed | Next workflow automation should deepen live operator approval/readback after Marketplace/payment gates | | ECC Tools next-level app | Billing audit, PR checks, deep analyzer, sync backlog, evaluator/RAG corpus, analysis-depth readiness, hosted execution planning, hosted CI diagnostics, hosted security evidence review, hosted harness compatibility audit, hosted reference-set evaluation, hosted AI routing/cost review, hosted team backlog routing, hosted depth-plan check-run, PR-comment hosted job dispatch, hosted job result history/check-runs, hosted result status command, status-aware depth-plan recommendations, hosted promotion readiness, hosted promotion output scoring, hosted promotion retrieval planning, hosted promotion judge contract, gated hosted promotion judge execution, hosted promotion judge audit trace, payment-announcement readiness, billing announcement preflight, aggregate production billing KV readback, Marketplace webhook provenance, target-account billing readback, Marketplace-source provenance counts, AgentShield fleet-summary hosted routing, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output hosted telemetry, and operator-visible promotion output values | PRs #26-#43 plus #53-#78 landed with test evidence, including AgentShield evidence-pack gap routing, canonical bundle recognition, supply-chain signature gates, PR draft follow-up Linear tracking, evidence-backed/deep-ready repository classification, the `/api/analysis/depth-plan` hosted job plan, `/api/analysis/jobs/ci-diagnostics`, `/api/analysis/jobs/security-evidence-review`, `/api/analysis/jobs/harness-compatibility-audit`, `/api/analysis/jobs/reference-set-evaluation`, `/api/analysis/jobs/ai-routing-cost-review`, `/api/analysis/jobs/team-backlog-routing`, the `ECC Tools / Hosted Depth Plan` check-run, `/ecc-tools analyze --job ...` PR-comment dispatch, non-blocking per-hosted-job result check-runs backed by 30-day result cache records, `/ecc-tools analyze --job status` cache lookup, cache-aware next-job recommendations in the depth-plan check-run, the `ECC Tools / Hosted Promotion Readiness` corpus-backed PR check-run, deterministic hosted-output scoring against cached completed job artifacts/findings, ranked retrieval/model-prompt planning, the fail-closed `hosted-promotion-judge.v1` request contract, opt-in live model-judge execution behind hosted evidence, entitlement, budget, provider, executor, strict JSON, and citation gates, hosted promotion judge request fingerprints plus allowed-citation audit trails, a fail-closed `/api/billing/readiness` `announcementGate` for native GitHub payments claims, `npm run billing:announcement-gate` plus `--preflight` as the non-secret operator verifier, hosted security findings for AgentShield fleet summaries, an `Evidence` column in hosted finding comments/check-runs, hosted harness findings that route AgentShield fleet target paths to harness owners, ECC-Tools commit `8658951` routing AgentShield policy-promotion Action outputs into hosted security review and promotion-readiness scoring, ECC-Tools commit `16c537f` rendering policy-promotion status/pack/count/digest values directly in hosted security job comments/check-runs, ECC-Tools commit `05d4e82` rendering model-judge audit traces without exposing raw provider output, ECC-Tools commit `91a441b` adding the safe billing announcement preflight path, ECC-Tools commit `eb69412` recording the initial production readback state, ECC-Tools commit `95d0bec` adding `npm run billing:kv-readback` with aggregate account-billing and billing-state records but 0 Marketplace Pro billing-state records, ECC-Tools commit `2859678` requiring webhook-derived Marketplace provenance before announcement readiness, ECC-Tools commit `42653f9` adding Wrangler OAuth readback, ECC-Tools commit `632e059` adding sanitized target-account readback that requires both target key families before `--require-ready` can pass, and ECC-Tools commit `d5f60db` adding sanitized Marketplace plan/action provenance counts; the latest 2026-05-18 live Wrangler OAuth recheck found 256 account-billing records, 256 billing-state records, 197 Marketplace-source records, 4 Marketplace webhook-provenance records, all `Open Source`, and 0 Marketplace Pro records, then updated Linear ITO-61 with the data/provisioning blocker | Next work is create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure target account plus `INTERNAL_API_SECRET`, then run `billing:kv-readback -- --wrangler --wrangler-bin ./node_modules/.bin/wrangler --account --require-ready`, followed by the live announcement gate | | GitGuardian/Dependabot/CodeRabbit-style checks | Non-blocking taxonomy, deterministic follow-up checks, and local supply-chain gates | ECC-Tools risk taxonomy check plus follow-up signals landed, including Skill Quality, Deep Analyzer Evidence, Analyzer Corpus Evidence, RAG/Evaluator Evidence, PR Review/Salvage Evidence, and AgentShield evidence-pack evidence; #1846 added npm registry signature gates; #1848 added the supply-chain incident-response playbook and `pull_request_target` cache-poisoning validator guard; #1851 added the privileged checkout credential-persistence guard; AgentShield #78, JARVIS #13, and ECC-Tools #53 applied the same hardening outside trunk | Current supply-chain gate complete; deeper hosted review features remain future | diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index ee834e35..ab771b0c 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -24,7 +24,8 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-15.md` | Current May 15 queue, roadmap, security, supply-chain watch, no-lifecycle CI install hardening, AgentShield #86 evidence-pack provenance, ECC Tools billing-gate, Actions cache purge, and `ecc2` test evidence through PR #1941 | Must be superseded by a final clean-checkout evidence file before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-16.md` | Current May 16/17 queue cleanup, recsys skill merge, GateGuard triage, PR #1947 supply-chain protection, AgentShield #87 plugin-cache confidence evidence, AgentShield #88 evidence-pack inspect/readback, AgentShield #89 evidence-pack fleet routing, AgentShield #90 fleet review items, AgentShield #91 policy export, AgentShield #92 policy promotion, ECC-Tools #76 fleet-summary consumption, ECC-Tools #77 hosted finding evidence paths, ECC-Tools #78 harness policy-route linking, dashboard refresh, and combined Node/Rust/release-surface gate evidence through the May 16 mirror | Must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` | May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack protection recheck, npm audit/signature checks, legacy and Linear progress routing, deterministic preview-pack smoke, operator dashboard refresh, Linear sync, and GitHub CI evidence for `27dc2918` | Superseded by the May 18 evidence snapshot; repeat from a strict clean checkout before real publication | -| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | Current May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, current-head Mini Shai-Hulud/TanStack protection recheck, no-lifecycle install, npm audit/signature checks, AgentShield `840952a` enterprise/IOC evidence mirror, work-items sync, Linear sync, operator dashboard refresh, latest current-head CI/security scan success for `4470e2e6`, and ITO-46 naming/plugin publication closure | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | +| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, supply-chain recheck, AgentShield evidence mirror, Linear sync, current-head CI/security scan success for `4470e2e6`, and ITO-46 naming/plugin publication closure | Superseded by the May 19 ECC identity, video, and growth evidence snapshot | +| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, preview-pack smoke digest `3bb55807407b`, 2544-test local suite, and PR #1993 CI success | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and publication, plugin, billing, AgentShield, ECC Tools, legacy, and Linear productization gaps still open | | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md` | Live URL and approval-gated URL ledger for release copy | Must be regenerated from the final release commit before public announcements | diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md new file mode 100644 index 00000000..c95fad46 --- /dev/null +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -0,0 +1,96 @@ +# ECC v2.0.0-rc.1 Publication Evidence - 2026-05-19 + +This is release-readiness evidence only. It does not create a GitHub release, +npm publication, plugin tag, marketplace submission, billing announcement, or +social announcement. + +## Source Commit + +| Field | Evidence | +| --- | --- | +| Upstream main | `7a0645ed47d6a3aca54b4a214aab6dfaa58e770d` | +| Git remote | `https://github.com/affaan-m/ECC.git` | +| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, and PR #1993 growth outreach pack | +| Local status caveat | `git status --short --branch` was clean after pulling `origin/main`; generated evidence files are committed after the source snapshot they describe | + +The release operator must repeat all publish-facing checks from the exact final +release commit with a strictly clean checkout before publishing. + +## Queue And Discussion State + +| Surface | Command | Result | +| --- | --- | --- | +| Platform audit | `node scripts/platform-audit.js --json` | Ready true; tracked repos report 0 open PRs, 0 open issues, 0 discussion maintainer-touch gaps, 0 answerable Q&A gaps, 0 conflicting PRs, and 0 blocking dirty files | +| Trunk PRs | `gh pr list --repo affaan-m/ECC --state open --json number,title,url,author --limit 100` | `[]` | +| Trunk issues | `gh issue list --repo affaan-m/ECC --state open --json number,title,url,author --limit 100` | `[]` | +| Discussion audit through platform audit | `node scripts/platform-audit.js --json` | `affaan-m/ECC` discussions enabled; 58 sampled; 0 needing maintainer touch; 0 answerable without accepted answer | +| Worktree | `git status --short --branch` | `## main...origin/main` | + +Tracked repositories in the platform audit were: + +- `affaan-m/ECC` +- `affaan-m/agentshield` +- `affaan-m/JARVIS` +- `ECC-Tools/ECC-Tools` +- `ECC-Tools/ECC-website` + +## Merge Batch + +| Item | Result | +| --- | --- | +| PR #1990 | Merged GitHub integration harness-audit scoring and conflict salvage from the earlier unsafe PR lane | +| PR #1991 | Merged canonical ECC release identity gate across README, plugin/package metadata, OpenCode surfaces, Marketplace metadata, audit defaults, quickstart, release URL ledger, naming/publication matrix, and release tests | +| PR #1992 | Merged the release video-suite gate, production manifest, validator, package file surface, preview-pack smoke wiring, release-surface tests, and compact CI JSON output | +| PR #1993 | Merged the partner, sponsor, consulting, conference, podcast, GitHub Discussion, and video CTA pack for the hypergrowth outbound lane | + +## Release And Growth Evidence + +| Gate | Command | Result | +| --- | --- | --- | +| Release-surface tests | `node tests/docs/ecc2-release-surface.test.js` | 25 passed, 0 failed | +| Preview-pack smoke | `npm run preview-pack:smoke -- --format json` | Ready true; digest `3bb55807407b`; 29 required artifacts; 5 passed, 0 failed | +| Release video suite | `npm run release:video-suite -- --format json --summary` with `ECC_VIDEO_SOURCE_ROOT` and `ECC_VIDEO_RELEASE_SUITE_ROOT` | Ready true; 15/15 source assets present; 13/13 render, timeline, caption, EDL, and segment artifacts present; primary rough render is 144.759 seconds and 106.78 MB | +| Full local suite | `node tests/run-all.js` | 2544 passed, 0 failed | +| PR #1993 CI | GitHub Actions run `26093792219` | Completed successfully for `d9ac22c697d9a8a8771512ab01e6df857c16776d`; all reported checks passed, including lint, validation, security scan, coverage, GitGuardian, and the macOS/Ubuntu/Windows test matrix | +| Public-path sanitization | `node scripts/ci/validate-no-personal-paths.js` through local suite and CI | Passed | +| Markdown and whitespace | `markdownlint` focused release docs plus `git diff --check` before PR #1993 | Passed | + +## Product And Positioning Evidence + +| Surface | Evidence | +| --- | --- | +| Canonical repo identity | Public URLs and release docs now use `https://github.com/affaan-m/ECC` where public links are needed | +| Release claim | Release notes and launch collateral frame ECC as the harness-native operator system for agentic work, not a Claude-only config pack | +| Video proof | `video-suite-production.md` gates the local rough render, timeline, captions, source inventory, self-eval, and no-private-path publication rules | +| Growth proof | `partner-sponsor-talks-pack.md` provides approval-gated copy for sponsors, partners, consulting, talks, podcasts, GitHub Discussion, and video CTAs | +| Business baseline | Hypergrowth command center and partner pack use `$1,728/mo` current MRR, `$10,000/mo` target MRR, and `$8,272/mo` gap | + +## Current Publication Blockers + +- GitHub prerelease `v2.0.0-rc.1` is still not created in this pass. +- npm `ecc-universal@2.0.0-rc.1` is still not published to the `next` + dist-tag. +- Claude plugin tag and marketplace propagation remain approval-gated. +- Codex repo-marketplace distribution is verified by prior evidence, but + official Plugin Directory publishing remains blocked on OpenAI submission or + listing evidence. +- ECC Tools billing/native-payments copy remains blocked until a Marketplace + Pro purchase/webhook path writes ready production billing state for a target + Marketplace test account and the billing announcement gate passes. +- Release notes, X, LinkedIn, GitHub release, GitHub Discussion, longform copy, + sponsor outreach, partner outreach, consulting copy, conference pitches, and + podcast pitches still need final live URLs plus human approval before posting + or sending. +- Discord/community links still need a real invite or bot/guild credential path + before public docs should route users there. + +## Result + +The tracked public PR queue, issue queue, discussion queue, canonical ECC +identity, release video suite, preview pack, and growth outreach packet are +current on May 19, 2026 for `main` through +`7a0645ed47d6a3aca54b4a214aab6dfaa58e770d`. + +This improves publication readiness but does not replace the approval-gated +release, package, plugin, billing, Discord, and announcement steps in +`publication-readiness.md`. diff --git a/docs/releases/2.0.0-rc.1/publication-readiness.md b/docs/releases/2.0.0-rc.1/publication-readiness.md index 87b3c4c8..258ccbb2 100644 --- a/docs/releases/2.0.0-rc.1/publication-readiness.md +++ b/docs/releases/2.0.0-rc.1/publication-readiness.md @@ -45,8 +45,9 @@ AgentShield project scan, AgentShield `840952a` enterprise/IOC evidence mirror, release OIDC publishing-scope hardening, workflow normalization, later dashboard/publication-readiness refreshes through `67e63e63`, work-items sync, Linear progress comments, ITO-46 closure, operator dashboard refresh, and -current-head CI/security scan success for `4470e2e6`, see -[`publication-evidence-2026-05-18.md`](publication-evidence-2026-05-18.md). +current-head CI/security scan success through the May 19 identity, video, and +growth-pack merge batch, see +[`publication-evidence-2026-05-19.md`](publication-evidence-2026-05-19.md). For the operator-facing prompt-to-artifact readiness dashboard from the same May 16 pass, see [`operator-readiness-dashboard-2026-05-15.md`](operator-readiness-dashboard-2026-05-15.md). @@ -94,20 +95,20 @@ Record the exact commit SHA and command output before any publication action: | Evidence | Command | Required result | Recorded output | | --- | --- | --- | --- | -| Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | `4470e2e6`: `## main...origin/main`; repeat from the exact final publication commit before release | -| Preview-pack smoke | `npm run preview-pack:smoke` | Preview pack artifacts, Hermes boundary, final verification command list, and publication blockers pass | `publication-evidence-2026-05-18.md`: ready yes, digest `0ed831dbd0cf`, 5 passed, 0 failed; repeat in the final strict clean-checkout release pass | +| Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | `7a0645ed`: `## main...origin/main`; repeat from the exact final publication commit before release | +| Preview-pack smoke | `npm run preview-pack:smoke` | Preview pack artifacts, Hermes boundary, final verification command list, and publication blockers pass | `publication-evidence-2026-05-19.md`: ready yes, digest `3bb55807407b`, 29 artifacts, 5 passed, 0 failed; repeat in the final strict clean-checkout release pass | | Harness audit | `npm run harness:audit -- --format json` | 70/70 passing | `99e01ded`: 70/70, 0 top actions | | Adapter scorecard | `npm run harness:adapters -- --check` | PASS | `99e01ded`: PASS, 11 adapters | | Observability readiness | `npm run observability:ready` | 21/21 passing | `publication-evidence-2026-05-18.md`: 21/21, ready yes | | Release safety gate | `npm run observability:ready -- --format json` | Release Safety category passing with publication readiness, supply-chain, workflow security, package surface, and release-surface evidence | May 18 evidence keeps release safety passing; repeat the JSON gate from the exact final release commit | -| Supply-chain verification | `npm audit --json`; `npm audit signatures`; `cd ecc2 && cargo audit -q`; Dependabot alerts; GitGuardian Security Checks | 0 vulnerabilities/alerts, registry signatures verified, GitGuardian clean | `publication-evidence-2026-05-18.md` plus CI `26057806361`: npm registry signatures and attestations verified in the evidence pass, 0 high-or-higher npm vulnerabilities, repo/home IOC scans clean, supply-chain IOC scan passed | -| Root suite | `node tests/run-all.js` | 0 failures | `99e01ded`: local `node tests/run-all.js` passed 2512/2512; current-head CI `26057806361` passed the full OS/runtime/package-manager matrix for `4470e2e6` | -| Markdown lint | `npx markdownlint-cli '**/*.md' --ignore node_modules` | 0 failures | CI `26057806361`: markdownlint passed on current head; rerun after any release-copy edits | +| Supply-chain verification | `npm audit --json`; `npm audit signatures`; `cd ecc2 && cargo audit -q`; Dependabot alerts; GitGuardian Security Checks | 0 vulnerabilities/alerts, registry signatures verified, GitGuardian clean | `publication-evidence-2026-05-19.md` plus CI `26093792219`: GitGuardian and security scan passed; prior May 18 npm registry signatures and IOC scans remain the latest detailed supply-chain evidence | +| Root suite | `node tests/run-all.js` | 0 failures | `7a0645ed`: local `node tests/run-all.js` passed 2544/2544; PR #1993 CI `26093792219` passed the full OS/runtime/package-manager matrix for `d9ac22c6` | +| Markdown lint | `npx markdownlint-cli '**/*.md' --ignore node_modules` | 0 failures | CI `26093792219`: markdownlint passed on the growth-pack PR; rerun after any release-copy edits | | Package surface | `node tests/scripts/npm-publish-surface.test.js` | 0 failures; no Python bytecode in npm tarball | `2/2` passed in May 12 evidence pass | -| Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | May 18 evidence refresh: 21/21 passed after public-path sanitization, during the `0f1775e3` operator-readiness refresh, and again in the ITO-46 dry-run pass before `4470e2e6` | +| Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | May 19 evidence refresh: 25/25 passed after adding the video suite and partner/sponsor/talk gates | | Optional Rust surface | `cd ecc2 && cargo test` | 0 failures or explicit deferral | `publication-evidence-2026-05-16.md`: 462/462 passed, existing warnings only | -| Queue baseline | `node scripts/platform-audit.js --json` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | `4470e2e6`: platform audit ready, 0 open PRs, 0 open issues, 0 conflicting PRs, and 0 blocking dirty files in the regenerated dashboard snapshot | -| Discussion baseline | `node scripts/platform-audit.js --json` and `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | `4470e2e6`: platform audit sampled 58 trunk discussions, 0 needing maintainer touch, 0 answerable discussions missing accepted answer; `docs/architecture/discussion-response-playbook.md` records response templates and security escalation rules | +| Queue baseline | `node scripts/platform-audit.js --json` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | `7a0645ed`: platform audit ready, 0 open PRs, 0 open issues, 0 conflicting PRs, and 0 blocking dirty files | +| Discussion baseline | `node scripts/platform-audit.js --json` and `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | `7a0645ed`: platform audit sampled 58 trunk discussions, 0 needing maintainer touch, 0 answerable discussions missing accepted answer; `docs/architecture/discussion-response-playbook.md` records response templates and security escalation rules | | Linear roadmap | Linear project and issue readback | Detailed roadmap exists with release, security, AgentShield, ECC Tools, legacy, and observability lanes | May 18 Linear comments include ITO-57 `3fe5b2b7-c4fe-401c-a317-b40d72119cb3` and ITO-44 `fb4a4f33-6c2d-421a-bbdb-63cfad3e3ee4`; earlier evidence records the project and 16 issue lanes | | Operator readiness dashboard | `npm run operator:dashboard -- --json` | Current queue state mapped to macro-goal deliverables and incomplete gaps | `4470e2e6`: regenerated May 18 dashboard from current main; platform audit ready true, 0 open PRs, 0 open issues, 0 discussion gaps, 0 dirty files, and publication gates still approval-gated | | Release URL ledger | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md` plus placeholder-marker scan | Live links and approval-gated links are separated before announcement copy is posted | Ledger records public repo/docs/npm/OpenAI Codex documentation URLs and blocks GitHub release/npm/plugin/billing/social URLs until approval-gated checks pass | diff --git a/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md b/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md index 149bf516..e2a6dc2d 100644 --- a/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md @@ -17,7 +17,8 @@ with output from the exact release commit. | Release pack folder | | In-tree release pack | | Release notes draft | | In-tree release copy | | Hermes setup guide | | In-tree sanitized Hermes guide | -| May 18 evidence snapshot | | Current strongest pre-rename readiness evidence | +| May 19 evidence snapshot | | Current strongest identity, video, growth, and CI readiness evidence | +| May 18 evidence snapshot | | Previous supply-chain and publication-path readiness evidence | | May 18 operator dashboard | | Prompt-to-artifact dashboard | | npm package page | | `npm view ecc-universal name version dist-tags --json` returned `latest: 1.10.0`; rc.1 is not published yet | | Codex marketplace CLI docs | | Official docs list `codex plugin marketplace add` for GitHub shorthand, Git URLs, SSH URLs, and local marketplace roots | diff --git a/scripts/platform-audit.js b/scripts/platform-audit.js index fbb2d059..a774031c 100644 --- a/scripts/platform-audit.js +++ b/scripts/platform-audit.js @@ -426,7 +426,7 @@ function buildLocalEvidenceChecks(rootDir) { const roadmap = readText(rootDir, 'docs/ECC-2.0-GA-ROADMAP.md'); const progressSync = readText(rootDir, 'docs/architecture/progress-sync-contract.md'); const supplyChain = readText(rootDir, 'docs/security/supply-chain-incident-response.md'); - const evidence = readText(rootDir, 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md'); + const evidence = readText(rootDir, 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md'); const operatorDashboard = readText(rootDir, 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md'); return [ @@ -472,9 +472,9 @@ function buildLocalEvidenceChecks(rootDir) { ), buildCheck( 'release-evidence-current', - includesAll(evidence, ['TanStack', 'Mini Shai-Hulud', 'Home persistence IOC scan', 'Supply-Chain Watch', 'npm signatures']) ? 'pass' : 'fail', - 'rc.1 evidence includes current supply-chain verification artifacts', - { path: 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md' } + includesAll(evidence, ['Release video suite', 'growth outreach', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', '2544 passed']) ? 'pass' : 'fail', + 'rc.1 evidence includes current release, video, growth, and CI artifacts', + { path: 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md' } ), buildCheck( 'operator-readiness-dashboard', diff --git a/scripts/preview-pack-smoke.js b/scripts/preview-pack-smoke.js index e004e09b..1c7aec97 100644 --- a/scripts/preview-pack-smoke.js +++ b/scripts/preview-pack-smoke.js @@ -26,6 +26,7 @@ const REQUIRED_ARTIFACTS = [ `${RELEASE_DIR}/publication-evidence-2026-05-16.md`, `${RELEASE_DIR}/publication-evidence-2026-05-17.md`, `${RELEASE_DIR}/publication-evidence-2026-05-18.md`, + `${RELEASE_DIR}/publication-evidence-2026-05-19.md`, `${RELEASE_DIR}/operator-readiness-dashboard-2026-05-17.md`, `${RELEASE_DIR}/operator-readiness-dashboard-2026-05-18.md`, `${RELEASE_DIR}/release-url-ledger-2026-05-19.md`, diff --git a/tests/docs/ecc2-release-surface.test.js b/tests/docs/ecc2-release-surface.test.js index c7745d88..1fb55df6 100644 --- a/tests/docs/ecc2-release-surface.test.js +++ b/tests/docs/ecc2-release-surface.test.js @@ -180,6 +180,7 @@ test('preview pack manifest assembles release, Hermes, and publication gates', ( 'docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md', 'docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md', 'docs/releases/2.0.0-rc.1/video-suite-production.md', + 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md', 'docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md', ]) { assert.ok(manifest.includes(artifact), `preview pack manifest missing ${artifact}`); diff --git a/tests/scripts/operator-readiness-dashboard.test.js b/tests/scripts/operator-readiness-dashboard.test.js index 3c390760..6f697c65 100644 --- a/tests/scripts/operator-readiness-dashboard.test.js +++ b/tests/scripts/operator-readiness-dashboard.test.js @@ -153,6 +153,13 @@ function seedRepo(rootDir, overrides = {}) { 'npm signatures', 'Node IPC follow-up node-ipc IOC scan' ].join('\n'), + 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md': [ + 'Release video suite', + 'growth outreach', + 'GitGuardian', + 'macOS/Ubuntu/Windows test matrix', + '2544 passed' + ].join('\n'), '.github/workflows/supply-chain-watch.yml': 'name: Supply-Chain Watch supply-chain-advisory-sources.js supply-chain-advisory-sources.json' }; diff --git a/tests/scripts/platform-audit.test.js b/tests/scripts/platform-audit.test.js index dde31584..cba1adc9 100644 --- a/tests/scripts/platform-audit.test.js +++ b/tests/scripts/platform-audit.test.js @@ -62,12 +62,12 @@ function seedRepo(rootDir, overrides = {}) { 'scan-supply-chain-iocs.js', 'supply-chain-advisory-sources.js' ].join('\n'), - 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md': [ - 'TanStack', - 'Mini Shai-Hulud', - 'Home persistence IOC scan', - 'Supply-Chain Watch', - 'npm signatures' + 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md': [ + 'Release video suite', + 'growth outreach', + 'GitGuardian', + 'macOS/Ubuntu/Windows test matrix', + '2544 passed' ].join('\n'), 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md': [ 'This dashboard is generated by `npm run operator:dashboard`', From d135e03da0d2c914308f9e49bd87f935a917b8fd Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 07:58:20 -0400 Subject: [PATCH 34/61] docs: refresh May 19 operator dashboard --- docs/ECC-2.0-GA-ROADMAP.md | 14 +- ...operator-readiness-dashboard-2026-05-19.md | 65 +++++++++ .../2.0.0-rc.1/preview-pack-manifest.md | 5 +- .../publication-evidence-2026-05-19.md | 12 +- .../2.0.0-rc.1/publication-readiness.md | 5 +- .../release-url-ledger-2026-05-19.md | 3 +- scripts/operator-readiness-dashboard.js | 124 +++++++++++++++++- scripts/platform-audit.js | 8 +- scripts/preview-pack-smoke.js | 1 + .../operator-readiness-dashboard.test.js | 83 +++++++++++- tests/scripts/platform-audit.test.js | 5 +- 11 files changed, 304 insertions(+), 21 deletions(-) create mode 100644 docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index ba557917..136e4848 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -78,14 +78,16 @@ As of 2026-05-19: - `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` records the current May 19 queue-zero state, canonical ECC identity merge, release video suite gate, partner/sponsor/talk outreach pack, preview-pack smoke digest - `3bb55807407b`, local 2544-test suite, and PR #1993 CI success. The May 18 + `bc2bf157616e`, local 2544-test suite, and PR #1993 CI success. The May 18 evidence remains the detailed supply-chain and publication-path snapshot. -- `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` +- `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` regenerates the ITO-44 prompt-to-artifact dashboard from live platform audit evidence: PR queue, issue queue, discussion queue, local worktree gate, - dashboard generation, and supply-chain loop are current; publication, plugin, - billing, AgentShield, ECC Tools, legacy, and Linear/productized sync lanes - remain the next work. + dashboard generation, and supply-chain loop are current; the dashboard now + also tracks the `$1,728/mo` to `$10,000/mo` hypergrowth baseline, release + video-suite lane, and partner/sponsor/talk outbound pack; publication, + plugin, billing, AgentShield, ECC Tools, and final outbound approval remain + the next work. - `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` records the May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack @@ -735,7 +737,7 @@ is not complete unless the evidence column exists and has been freshly verified. | Manage repository discussions | Repo-family discussion recheck plus response playbook | Platform audit reports 0 discussion maintainer-touch gaps and 0 answerable Q&A missing accepted answers; trunk still has 58 total discussions; `docs/architecture/discussion-response-playbook.md` distinguishes support, maintainer coordination, stale/concluded, release, informational, and security-sensitive response paths | Complete | | Manage PR discussions | PR review/comment closure plus merge/close state | ECC #1990-#1993 merged through the harness audit, canonical identity, release video suite, and growth outreach batch; no open tracked PRs remain | Complete | | Salvage useful stale work | `docs/stale-pr-salvage-ledger.md` plus `docs/legacy-artifact-inventory.md` | Ledger records salvaged, superseded, skipped, and manual-review tails; #1815-#1818 added cost tracking, skill scout, frontend design guidance, code-reviewer false-positive guardrails, and the May 12 gap pass; #1687, #1609, #1563, #1564, and #1565 localization tails are attached to Linear ITO-55 for language-owner review and no automatic import remains release-blocking | Complete; repeat legacy scan before release | -| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 19 evidence records queue-zero state, canonical ECC identity, release video suite, growth outreach pack, local 2544-test suite, PR #1993 CI success, and preview-pack smoke digest `3bb55807407b` | Needs final release approval | +| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 19 evidence records queue-zero state, canonical ECC identity, release video suite, growth outreach pack, local 2544-test suite, PR #1993 CI success, May 19 operator dashboard, and preview-pack smoke digest `bc2bf157616e` | Needs final release approval | | Hermes specialized skills included safely | Hermes setup/import docs and sanitized skill surface | Hermes setup and import playbook are public; secrets stay local | Needs final release review | | Naming and rename readiness | Naming matrix across package/plugin/docs/social surfaces | `docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md` records current package, repo, Claude plugin, Codex plugin, OpenCode, and npm availability evidence | Complete for rc.1; post-rc rename remains future work | | Claude and Codex plugin publication | Contact/submission path with required artifacts and status | Publication readiness, naming matrix, and May 12 dry-run evidence document plugin validation, clean-checkout Claude tag/install smoke, and Codex marketplace CLI shape | Needs explicit approval for real tag/push and marketplace submission | diff --git a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md new file mode 100644 index 00000000..1ec9b32d --- /dev/null +++ b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md @@ -0,0 +1,65 @@ +# ECC Operator Readiness Dashboard + +This dashboard is generated by `npm run operator:dashboard`. It is an operator snapshot, not release approval. + +Generated: 2026-05-19T11:58:26.640Z +Commit: dafd447977d07d1fdc84e200a9523f9b296cb269 +Status: work remaining + +## Current Status + +| Area | Status | Evidence | +| --- | --- | --- | +| PR queue | Current | 0 open PRs across tracked repos | +| Issue queue | Current | 0 open issues across tracked repos | +| Discussions | Current | 0 need maintainer touch; 0 missing accepted answer | +| Local worktree | Current | 0 blocking dirty files; 0 ignored dirty entries | +| Dashboard generation | Current | platform audit ready: true; GitHub skipped: false | +| Publication | Not complete | release, npm, plugin, billing, and announcement gates are tracked below | + +## Growth Baseline + +| Metric | Current | Target | Gap | +| --- | ---: | ---: | ---: | +| MRR | $1,728/mo | $10,000/mo | $8,272/mo | + +Growth lanes: GitHub Sponsors and OSS partner sponsors; ECC Tools Pro subscriptions; consulting and implementation contracts; talks, podcasts, conference demos, and partner webinars. + +## Prompt-To-Artifact Checklist + +| Objective requirement | Artifact or gate | Status | Evidence | Gap | +| --- | --- | --- | --- | --- | +| Keep public PRs below 20 | scripts/platform-audit.js live GitHub sweep plus owner-wide queue cleanup ledger | current | 0 open PRs across 5 tracked repos; 0 owner-wide open PRs after cleanup | repeat platform:audit and owner-wide gh search before release | +| Keep public issues below 20 | scripts/platform-audit.js live GitHub sweep plus owner-wide queue cleanup ledger | current | 0 open issues across 5 tracked repos; 0 owner-wide open issues after cleanup | repeat platform:audit and owner-wide gh search before release | +| Respond and manage repository discussions | scripts/platform-audit.js discussion summary | current | 0 need maintainer touch; 0 answerable discussions missing accepted answer | repeat before release | +| Build ITO-44 completion dashboard into a repeatable command | npm run operator:dashboard | complete | operator:dashboard package script exists | keep generated dashboard attached to publication evidence | +| ECC 2.0 preview pack ready | docs/releases/2.0.0-rc.1/preview-pack-manifest.md | current | preview pack manifest and deterministic smoke gate are in-tree | repeat clean-checkout preview-pack smoke before publication | +| Include Hermes specialized skills safely | docs/HERMES-SETUP.md and skills/hermes-imports/SKILL.md | current | Hermes setup/import artifacts are covered by preview-pack smoke | repeat preview-pack smoke before release review | +| Prepare name-change, Claude plugin, and Codex plugin paths | naming-and-publication-matrix plus release-name-plugin-publication checklist plus publication-readiness | in_progress | naming matrix, release publication checklist, and plugin readiness gates exist | real tag/push, marketplace submission, and final channel choice remain approval-gated | +| Prepare release notes, articles, tweets, and push notifications | docs/releases/2.0.0-rc.1 social and release-copy files | in_progress | release notes, X thread, LinkedIn draft, and URL ledger are present | final live release/npm/plugin/billing URLs and publish approval still pending | +| Create a second-phase hypergrowth release command center | docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md plus May 19 evidence | current | current MRR, target MRR, gap, release claim, video lane, distribution plan, and approval boundaries are in-tree | refresh after every MRR, channel, or approval-state change before public launch | +| Produce the ECC 2.0 release video suite | docs/releases/2.0.0-rc.1/video-suite-production.md and npm run release:video-suite | in_progress | video production manifest and deterministic video-suite gate are wired for launch video, short clips, captions, timeline, and self-eval evidence | render final owner-approved MP4s, captions, platform reframes, and editable timeline before posting | +| Prepare sponsor, partner, consulting, podcast, talk, and Discussion copy | docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md | in_progress | sponsor outbound, platform partner DM, consulting intro, talk/podcast pitch, GitHub Discussion announcement, CTA hooks, and do-not-send gate are drafted | replace final URLs after publication gates, then get explicit approval before outbound or personal-account posts | +| Advance AgentShield enterprise iteration | AgentShield PR evidence plus enterprise roadmap | in_progress | AgentShield policy promotion `reviewItems` landed in `87aec47`; package-manager hardening drift detection landed in `28d08c7`; workflow action runtime pins were refreshed in `659f569`; npm age-gate guidance was corrected in `ee585cd`; package-manager hardening Action outputs landed in `1124535`; policy-promotion Action outputs and runtime-smoke job-summary evidence landed in `1593925`; fleet review ticket payloads and current Mini Shai-Hulud IOC breadcrumbs landed in `840952a`; ECC-Tools consumes those outputs in `8658951`, surfaces operator-readable status/pack/count/digest telemetry in `16c537f`, and renders hosted promotion judge audit traces in `05d4e82`; all are mirrored in the GA roadmap | deepen live operator approval/readback after Marketplace/payment gates | +| Advance ECC Tools native payments and AI-native harness-agnostic app | ECC Tools PR evidence, billing gate, hosted analysis lanes | in_progress | billing announcement gate, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler OAuth readback, target-account billing readback, provenance-aware Marketplace billing-state gates, sanitized Marketplace plan/action provenance counts, hosted team-learning feedback controls, and ECC-Tools Dependabot alert remediation are mirrored in the GA roadmap | create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure the target account and INTERNAL_API_SECRET, then rerun target readback and the live announcement gate | +| Audit, prune, or attach legacy work | docs/stale-pr-salvage-ledger.md and legacy inventory | current | legacy salvage ledger and inventory are current; all localization tails are attached to Linear ITO-55 for manual language-owner review | repeat legacy scan before release | +| Keep Linear roadmap detailed and progress tracking synchronized | Linear project mirror plus progress-sync contract | current | Linear live sync and project progress surface are current; progress-sync contract defines the file-backed work-items/status path | repeat Linear/project status update and local work-items sync after each significant merge batch | +| Provide ECC 2.0 observability for self-use | observability readiness gate | complete | observability:ready command and readiness doc exist | runtime/dashboard implementation can continue after release gates | +| Keep Mini Shai-Hulud/TanStack protection loop current | supply-chain watch plus runbook plus AgentShield package-manager hardening | current | scheduled supply-chain watch emits IOC/advisory-source refresh artifacts; ECC scanner covers gh-token-monitor token-store persistence; AgentShield now detects known AI-tool persistence IOCs, npm lifecycle/token drift, unsupported npm age-key drift, and pnpm/Yarn cooldown drift; current-head watch evidence and ITO-57 May 18 Linear evidence updates are current | repeat advisory/source refresh and Linear sync after each significant supply-chain batch | + +## Top Actions + +- `naming-and-plugin-publication`: real tag/push, marketplace submission, and final channel choice remain approval-gated +- `release-notes-and-notifications`: final live release/npm/plugin/billing URLs and publish approval still pending +- `release-video-suite`: render final owner-approved MP4s, captions, platform reframes, and editable timeline before posting +- `partner-sponsor-talks-pack`: replace final URLs after publication gates, then get explicit approval before outbound or personal-account posts +- `agentshield-enterprise-iteration`: deepen live operator approval/readback after Marketplace/payment gates +- `ecc-tools-next-level`: create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure the target account and INTERNAL_API_SECRET, then rerun target readback and the live announcement gate + +## Next Work Order + +1. Regenerate this dashboard from the final release commit before publication evidence is recorded. +2. Render the owner-approved primary launch video, short clips, captions, reframes, and editable timeline from the video-suite production manifest. +3. Replace final release, npm, plugin, billing, and video URLs in the partner/sponsor/talk pack, then get explicit approval before outbound. +4. Repeat ITO-57 Linear/project status sync after the next significant merge batch or advisory-source refresh. +5. Create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure the target account and INTERNAL_API_SECRET, then rerun target readback and the live announcement gate before publishing native-payments copy. diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index ab771b0c..0763f3ed 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -25,9 +25,10 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-16.md` | Current May 16/17 queue cleanup, recsys skill merge, GateGuard triage, PR #1947 supply-chain protection, AgentShield #87 plugin-cache confidence evidence, AgentShield #88 evidence-pack inspect/readback, AgentShield #89 evidence-pack fleet routing, AgentShield #90 fleet review items, AgentShield #91 policy export, AgentShield #92 policy promotion, ECC-Tools #76 fleet-summary consumption, ECC-Tools #77 hosted finding evidence paths, ECC-Tools #78 harness policy-route linking, dashboard refresh, and combined Node/Rust/release-surface gate evidence through the May 16 mirror | Must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` | May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack protection recheck, npm audit/signature checks, legacy and Linear progress routing, deterministic preview-pack smoke, operator dashboard refresh, Linear sync, and GitHub CI evidence for `27dc2918` | Superseded by the May 18 evidence snapshot; repeat from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, supply-chain recheck, AgentShield evidence mirror, Linear sync, current-head CI/security scan success for `4470e2e6`, and ITO-46 naming/plugin publication closure | Superseded by the May 19 ECC identity, video, and growth evidence snapshot | -| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, preview-pack smoke digest `3bb55807407b`, 2544-test local suite, and PR #1993 CI success | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | +| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, May 19 operator dashboard, preview-pack smoke digest `bc2bf157616e`, 2544-test local suite, and PR #1993 CI success | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | -| `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and publication, plugin, billing, AgentShield, ECC Tools, legacy, and Linear productization gaps still open | +| `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 19 generated dashboard | +| `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and adds the current `$1,728/mo` to `$10,000/mo` hypergrowth, release-video, and outbound-pack operating lanes | | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md` | Live URL and approval-gated URL ledger for release copy | Must be regenerated from the final release commit before public announcements | | `docs/releases/2.0.0-rc.1/video-suite-production.md` | Release video production manifest | Gates local media inventory, rough primary render, captions, timeline, self-eval, and no-private-path publication rules | | `docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md` | Partner, sponsor, consulting, conference, podcast, and discussion copy | Must stay approval-gated and avoid live billing, release, package, or plugin claims without evidence | diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md index c95fad46..f0b81fcf 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -8,9 +8,9 @@ social announcement. | Field | Evidence | | --- | --- | -| Upstream main | `7a0645ed47d6a3aca54b4a214aab6dfaa58e770d` | +| Upstream main | `c07276a347f8dac4945d2ad294124a708c19b108` | | Git remote | `https://github.com/affaan-m/ECC.git` | -| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, and PR #1993 growth outreach pack | +| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, and PR #1994 May 19 publication evidence refresh | | Local status caveat | `git status --short --branch` was clean after pulling `origin/main`; generated evidence files are committed after the source snapshot they describe | The release operator must repeat all publish-facing checks from the exact final @@ -42,13 +42,15 @@ Tracked repositories in the platform audit were: | PR #1991 | Merged canonical ECC release identity gate across README, plugin/package metadata, OpenCode surfaces, Marketplace metadata, audit defaults, quickstart, release URL ledger, naming/publication matrix, and release tests | | PR #1992 | Merged the release video-suite gate, production manifest, validator, package file surface, preview-pack smoke wiring, release-surface tests, and compact CI JSON output | | PR #1993 | Merged the partner, sponsor, consulting, conference, podcast, GitHub Discussion, and video CTA pack for the hypergrowth outbound lane | +| PR #1994 | Merged the May 19 publication-evidence refresh, platform-audit evidence gate, preview-pack smoke evidence gate, and URL/readiness/roadmap references | ## Release And Growth Evidence | Gate | Command | Result | | --- | --- | --- | | Release-surface tests | `node tests/docs/ecc2-release-surface.test.js` | 25 passed, 0 failed | -| Preview-pack smoke | `npm run preview-pack:smoke -- --format json` | Ready true; digest `3bb55807407b`; 29 required artifacts; 5 passed, 0 failed | +| Preview-pack smoke | `npm run preview-pack:smoke -- --format json` | Ready true; digest `bc2bf157616e`; 30 required artifacts; 5 passed, 0 failed | +| Operator dashboard | `npm run operator:dashboard -- --markdown --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Generated May 19 dashboard with platform audit ready true, 0 tracked PRs, 0 tracked issues, 0 discussion gaps, `$1,728/mo` current MRR, `$10,000/mo` target MRR, and top actions for plugin publication, notifications, release video, outbound approval, AgentShield, and ECC Tools billing | | Release video suite | `npm run release:video-suite -- --format json --summary` with `ECC_VIDEO_SOURCE_ROOT` and `ECC_VIDEO_RELEASE_SUITE_ROOT` | Ready true; 15/15 source assets present; 13/13 render, timeline, caption, EDL, and segment artifacts present; primary rough render is 144.759 seconds and 106.78 MB | | Full local suite | `node tests/run-all.js` | 2544 passed, 0 failed | | PR #1993 CI | GitHub Actions run `26093792219` | Completed successfully for `d9ac22c697d9a8a8771512ab01e6df857c16776d`; all reported checks passed, including lint, validation, security scan, coverage, GitGuardian, and the macOS/Ubuntu/Windows test matrix | @@ -64,6 +66,7 @@ Tracked repositories in the platform audit were: | Video proof | `video-suite-production.md` gates the local rough render, timeline, captions, source inventory, self-eval, and no-private-path publication rules | | Growth proof | `partner-sponsor-talks-pack.md` provides approval-gated copy for sponsors, partners, consulting, talks, podcasts, GitHub Discussion, and video CTAs | | Business baseline | Hypergrowth command center and partner pack use `$1,728/mo` current MRR, `$10,000/mo` target MRR, and `$8,272/mo` gap | +| Operator dashboard | `operator-readiness-dashboard-2026-05-19.md` pulls the growth baseline into the same queue, publication, video, outbound, AgentShield, ECC Tools, Linear, and supply-chain control surface | ## Current Publication Blockers @@ -89,7 +92,8 @@ Tracked repositories in the platform audit were: The tracked public PR queue, issue queue, discussion queue, canonical ECC identity, release video suite, preview pack, and growth outreach packet are current on May 19, 2026 for `main` through -`7a0645ed47d6a3aca54b4a214aab6dfaa58e770d`. +`c07276a347f8dac4945d2ad294124a708c19b108`, with the May 19 dashboard +refresh staged for the next merge. This improves publication readiness but does not replace the approval-gated release, package, plugin, billing, Discord, and announcement steps in diff --git a/docs/releases/2.0.0-rc.1/publication-readiness.md b/docs/releases/2.0.0-rc.1/publication-readiness.md index 258ccbb2..558fd2e0 100644 --- a/docs/releases/2.0.0-rc.1/publication-readiness.md +++ b/docs/releases/2.0.0-rc.1/publication-readiness.md @@ -55,6 +55,9 @@ For the May 17 operator dashboard refresh, see [`operator-readiness-dashboard-2026-05-17.md`](operator-readiness-dashboard-2026-05-17.md). For the May 18 operator dashboard refresh, see [`operator-readiness-dashboard-2026-05-18.md`](operator-readiness-dashboard-2026-05-18.md). + +The current May 19 hypergrowth/operator dashboard is +[`operator-readiness-dashboard-2026-05-19.md`](operator-readiness-dashboard-2026-05-19.md). For the May 19 live/pending release URL ledger after the public repo rename, see [`release-url-ledger-2026-05-19.md`](release-url-ledger-2026-05-19.md). @@ -96,7 +99,7 @@ Record the exact commit SHA and command output before any publication action: | Evidence | Command | Required result | Recorded output | | --- | --- | --- | --- | | Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | `7a0645ed`: `## main...origin/main`; repeat from the exact final publication commit before release | -| Preview-pack smoke | `npm run preview-pack:smoke` | Preview pack artifacts, Hermes boundary, final verification command list, and publication blockers pass | `publication-evidence-2026-05-19.md`: ready yes, digest `3bb55807407b`, 29 artifacts, 5 passed, 0 failed; repeat in the final strict clean-checkout release pass | +| Preview-pack smoke | `npm run preview-pack:smoke` | Preview pack artifacts, Hermes boundary, final verification command list, and publication blockers pass | `publication-evidence-2026-05-19.md`: ready yes, digest `bc2bf157616e`, 30 artifacts, 5 passed, 0 failed; repeat in the final strict clean-checkout release pass | | Harness audit | `npm run harness:audit -- --format json` | 70/70 passing | `99e01ded`: 70/70, 0 top actions | | Adapter scorecard | `npm run harness:adapters -- --check` | PASS | `99e01ded`: PASS, 11 adapters | | Observability readiness | `npm run observability:ready` | 21/21 passing | `publication-evidence-2026-05-18.md`: 21/21, ready yes | diff --git a/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md b/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md index e2a6dc2d..9bfbabad 100644 --- a/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md @@ -19,7 +19,8 @@ with output from the exact release commit. | Hermes setup guide | | In-tree sanitized Hermes guide | | May 19 evidence snapshot | | Current strongest identity, video, growth, and CI readiness evidence | | May 18 evidence snapshot | | Previous supply-chain and publication-path readiness evidence | -| May 18 operator dashboard | | Prompt-to-artifact dashboard | +| May 18 operator dashboard | | Previous prompt-to-artifact dashboard | +| May 19 operator dashboard | | Current prompt-to-artifact dashboard with hypergrowth, video, and outbound lanes | | npm package page | | `npm view ecc-universal name version dist-tags --json` returned `latest: 1.10.0`; rc.1 is not published yet | | Codex marketplace CLI docs | | Official docs list `codex plugin marketplace add` for GitHub shorthand, Git URLs, SSH URLs, and local marketplace roots | | Codex official Plugin Directory status | | Official docs say public Plugin Directory publishing and self-serve management are coming soon | diff --git a/scripts/operator-readiness-dashboard.js b/scripts/operator-readiness-dashboard.js index 7301a10a..b943b08e 100644 --- a/scripts/operator-readiness-dashboard.js +++ b/scripts/operator-readiness-dashboard.js @@ -543,15 +543,54 @@ function isCurrentOrComplete(status) { return status === 'current' || status === 'complete'; } +function extractGrowthBaseline(hypergrowth) { + const mrrMatch = hypergrowth.match(/\| MRR \| `([^`]+)` \| `([^`]+)` \| `([^`]+)` \|/); + + if (!mrrMatch) { + return { + currentMrr: 'unknown', + targetMrr: 'unknown', + gapMrr: 'unknown', + }; + } + + return { + currentMrr: mrrMatch[1], + targetMrr: mrrMatch[2], + gapMrr: mrrMatch[3], + }; +} + +function buildGrowthSummary(rootDir) { + const hypergrowth = readText(rootDir, 'docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md'); + const partnerPack = readText(rootDir, 'docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md'); + const baseline = extractGrowthBaseline(hypergrowth || partnerPack); + + return { + ...baseline, + lanes: [ + 'GitHub Sponsors and OSS partner sponsors', + 'ECC Tools Pro subscriptions', + 'consulting and implementation contracts', + 'talks, podcasts, conference demos, and partner webinars', + ], + }; +} + function buildRequirements(rootDir, platformReport) { const roadmap = readText(rootDir, 'docs/ECC-2.0-GA-ROADMAP.md'); const publicationReadiness = readText(rootDir, 'docs/releases/2.0.0-rc.1/publication-readiness.md'); const namingMatrix = readText(rootDir, 'docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md'); const releasePublicationChecklist = readText(rootDir, 'docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md'); const releaseUrlLedger = readText(rootDir, 'docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md'); + const publicationEvidenceMay19 = readText(rootDir, 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md'); + const hypergrowthCommandCenter = readText(rootDir, 'docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md'); + const partnerSponsorTalksPack = readText(rootDir, 'docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md'); + const releaseVideoProduction = readText(rootDir, 'docs/releases/2.0.0-rc.1/video-suite-production.md'); const ownerQueueCleanup = readText(rootDir, 'docs/releases/2.0.0-rc.1/owner-queue-cleanup-2026-05-18.md'); const previewManifest = readText(rootDir, 'docs/releases/2.0.0-rc.1/preview-pack-manifest.md'); const previewPackSmoke = readText(rootDir, 'scripts/preview-pack-smoke.js'); + const releaseVideoSuite = readText(rootDir, 'scripts/release-video-suite.js'); const progressSync = readText(rootDir, 'docs/architecture/progress-sync-contract.md'); const observabilityReadiness = readText(rootDir, 'docs/architecture/observability-readiness.md'); const stalePrSalvage = readText(rootDir, 'docs/stale-pr-salvage-ledger.md'); @@ -577,6 +616,39 @@ function buildRequirements(rootDir, platformReport) { ]); const hermesArtifactsReady = fileExists(rootDir, 'docs/HERMES-SETUP.md') && fileExists(rootDir, 'skills/hermes-imports/SKILL.md'); + const hypergrowthCommandCenterReady = includesAll(hypergrowthCommandCenter, [ + 'harness-native operator system', + '$1,728/mo', + '$10,000/mo', + 'Video Suite', + 'Distribution Plan', + 'Owner Approvals', + ]) && includesAll(publicationEvidenceMay19, [ + 'Business baseline', + '$1,728/mo', + '$8,272/mo', + ]); + const releaseVideoSuiteReady = scripts['release:video-suite'] === 'node scripts/release-video-suite.js' + && fileExists(rootDir, 'scripts/release-video-suite.js') + && includesAll(releaseVideoProduction, [ + 'ECC 2.0 Video Suite Production Manifest', + 'Primary launch video', + 'Self-Eval Gate', + 'timeline', + ]) + && includesAll(releaseVideoSuite, [ + 'ecc.release-video-suite.v1', + 'video-source-assets-present', + 'video-release-artifacts-present', + ]); + const partnerSponsorTalksReady = includesAll(partnerSponsorTalksPack, [ + 'Sponsor Outbound', + 'Platform Partner DM', + 'Consulting Intro', + 'Talk And Podcast Pitch', + 'GitHub Discussion Announcement', + 'Do Not Send Or Publish If', + ]); const githubLive = !platformReport.github.skipped && platformReport.github.totals.errors === 0; const ownerWideOpenPrs = extractLabeledCount(ownerQueueCleanup, 'Owner-wide open PRs after cleanup'); @@ -714,6 +786,42 @@ function buildRequirements(rootDir, platformReport) { ? 'final live release/npm/plugin/billing URLs and publish approval still pending' : 'URL-backed refresh and publish approval still pending' ), + buildRequirement( + 'hypergrowth-command-center', + 'Create a second-phase hypergrowth release command center', + 'docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md plus May 19 evidence', + hypergrowthCommandCenterReady ? 'current' : 'in_progress', + hypergrowthCommandCenterReady + ? 'current MRR, target MRR, gap, release claim, video lane, distribution plan, and approval boundaries are in-tree' + : 'hypergrowth command center or May 19 business baseline evidence is incomplete', + hypergrowthCommandCenterReady + ? 'refresh after every MRR, channel, or approval-state change before public launch' + : 'add current MRR, target gap, channel plan, video lane, and approval boundaries' + ), + buildRequirement( + 'release-video-suite', + 'Produce the ECC 2.0 release video suite', + 'docs/releases/2.0.0-rc.1/video-suite-production.md and npm run release:video-suite', + releaseVideoSuiteReady ? 'in_progress' : 'not_complete', + releaseVideoSuiteReady + ? 'video production manifest and deterministic video-suite gate are wired for launch video, short clips, captions, timeline, and self-eval evidence' + : 'video production manifest or release:video-suite gate is incomplete', + releaseVideoSuiteReady + ? 'render final owner-approved MP4s, captions, platform reframes, and editable timeline before posting' + : 'wire release:video-suite and production manifest before final content work' + ), + buildRequirement( + 'partner-sponsor-talks-pack', + 'Prepare sponsor, partner, consulting, podcast, talk, and Discussion copy', + 'docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md', + partnerSponsorTalksReady ? 'in_progress' : 'not_complete', + partnerSponsorTalksReady + ? 'sponsor outbound, platform partner DM, consulting intro, talk/podcast pitch, GitHub Discussion announcement, CTA hooks, and do-not-send gate are drafted' + : 'partner, sponsor, consulting, talk, or discussion copy is missing', + partnerSponsorTalksReady + ? 'replace final URLs after publication gates, then get explicit approval before outbound or personal-account posts' + : 'draft the full outbound pack and approval gate' + ), buildRequirement( 'agentshield-enterprise-iteration', 'Advance AgentShield enterprise iteration', @@ -802,12 +910,14 @@ function buildReport(options) { fix: item.gap, })); const head = runCommand('git', ['rev-parse', 'HEAD'], { cwd: rootDir }); + const growth = buildGrowthSummary(rootDir); return { schema_version: SCHEMA_VERSION, generatedAt, root: rootDir, head, + growth, ready: incompleteRequirements.length === 0, dashboardReady: platformReport.ready, publicationReady: false, @@ -827,9 +937,10 @@ function buildReport(options) { top_actions: topActions, next_work_order: [ 'Regenerate this dashboard from the final release commit before publication evidence is recorded.', + 'Render the owner-approved primary launch video, short clips, captions, reframes, and editable timeline from the video-suite production manifest.', + 'Replace final release, npm, plugin, billing, and video URLs in the partner/sponsor/talk pack, then get explicit approval before outbound.', 'Repeat ITO-57 Linear/project status sync after the next significant merge batch or advisory-source refresh.', 'Create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure the target account and INTERNAL_API_SECRET, then rerun target readback and the live announcement gate before publishing native-payments copy.', - 'Resume ITO-45, ITO-46, and ITO-56 only after the generated dashboard and final release gates are refreshed.', ], }; } @@ -848,6 +959,9 @@ function renderText(report) { `Dashboard ready: ${report.dashboardReady}`, `Publication ready: ${report.publicationReady}`, '', + 'Growth baseline:', + ` MRR: ${report.growth ? report.growth.currentMrr : 'unknown'} -> ${report.growth ? report.growth.targetMrr : 'unknown'} (gap ${report.growth ? report.growth.gapMrr : 'unknown'})`, + '', 'Platform:', ` PRs: ${report.platform.openPrs}`, ` Issues: ${report.platform.openIssues}`, @@ -895,6 +1009,14 @@ function renderMarkdown(report) { `| Dashboard generation | ${report.dashboardReady ? 'Current' : 'Needs work'} | platform audit ready: ${report.platform.ready}; GitHub skipped: ${report.platform.githubSkipped} |`, `| Publication | ${report.publicationReady ? 'Ready' : 'Not complete'} | release, npm, plugin, billing, and announcement gates are tracked below |`, '', + '## Growth Baseline', + '', + '| Metric | Current | Target | Gap |', + '| --- | ---: | ---: | ---: |', + `| MRR | ${markdownEscape(report.growth ? report.growth.currentMrr : 'unknown')} | ${markdownEscape(report.growth ? report.growth.targetMrr : 'unknown')} | ${markdownEscape(report.growth ? report.growth.gapMrr : 'unknown')} |`, + '', + 'Growth lanes: GitHub Sponsors and OSS partner sponsors; ECC Tools Pro subscriptions; consulting and implementation contracts; talks, podcasts, conference demos, and partner webinars.', + '', '## Prompt-To-Artifact Checklist', '', '| Objective requirement | Artifact or gate | Status | Evidence | Gap |', diff --git a/scripts/platform-audit.js b/scripts/platform-audit.js index a774031c..5cc17b0c 100644 --- a/scripts/platform-audit.js +++ b/scripts/platform-audit.js @@ -427,7 +427,7 @@ function buildLocalEvidenceChecks(rootDir) { const progressSync = readText(rootDir, 'docs/architecture/progress-sync-contract.md'); const supplyChain = readText(rootDir, 'docs/security/supply-chain-incident-response.md'); const evidence = readText(rootDir, 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md'); - const operatorDashboard = readText(rootDir, 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md'); + const operatorDashboard = readText(rootDir, 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md'); return [ buildCheck( @@ -472,7 +472,7 @@ function buildLocalEvidenceChecks(rootDir) { ), buildCheck( 'release-evidence-current', - includesAll(evidence, ['Release video suite', 'growth outreach', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', '2544 passed']) ? 'pass' : 'fail', + includesAll(evidence, ['Release video suite', 'growth outreach', 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', '2544 passed']) ? 'pass' : 'fail', 'rc.1 evidence includes current release, video, growth, and CI artifacts', { path: 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md' } ), @@ -480,13 +480,15 @@ function buildLocalEvidenceChecks(rootDir) { 'operator-readiness-dashboard', includesAll(operatorDashboard, [ 'This dashboard is generated by `npm run operator:dashboard`', + 'Growth Baseline', + 'hypergrowth release command center', 'Prompt-To-Artifact Checklist', 'PR queue', 'Not complete', 'Next Work Order', ]) ? 'pass' : 'fail', 'operator dashboard maps macro-goal requirements to current evidence and open gaps', - { path: 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md' } + { path: 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md' } ), ]; } diff --git a/scripts/preview-pack-smoke.js b/scripts/preview-pack-smoke.js index 1c7aec97..8dbee764 100644 --- a/scripts/preview-pack-smoke.js +++ b/scripts/preview-pack-smoke.js @@ -29,6 +29,7 @@ const REQUIRED_ARTIFACTS = [ `${RELEASE_DIR}/publication-evidence-2026-05-19.md`, `${RELEASE_DIR}/operator-readiness-dashboard-2026-05-17.md`, `${RELEASE_DIR}/operator-readiness-dashboard-2026-05-18.md`, + `${RELEASE_DIR}/operator-readiness-dashboard-2026-05-19.md`, `${RELEASE_DIR}/release-url-ledger-2026-05-19.md`, `${RELEASE_DIR}/video-suite-production.md`, `${RELEASE_DIR}/partner-sponsor-talks-pack.md`, diff --git a/tests/scripts/operator-readiness-dashboard.test.js b/tests/scripts/operator-readiness-dashboard.test.js index 6f697c65..d5599a49 100644 --- a/tests/scripts/operator-readiness-dashboard.test.js +++ b/tests/scripts/operator-readiness-dashboard.test.js @@ -33,7 +33,8 @@ function seedRepo(rootDir, overrides = {}) { 'scripts/observability-readiness.js', 'scripts/operator-readiness-dashboard.js', 'scripts/platform-audit.js', - 'scripts/preview-pack-smoke.js' + 'scripts/preview-pack-smoke.js', + 'scripts/release-video-suite.js' ], scripts: { 'discussion:audit': 'node scripts/discussion-audit.js', @@ -41,6 +42,7 @@ function seedRepo(rootDir, overrides = {}) { 'operator:dashboard': 'node scripts/operator-readiness-dashboard.js', 'platform:audit': 'node scripts/platform-audit.js', 'preview-pack:smoke': 'node scripts/preview-pack-smoke.js', + 'release:video-suite': 'node scripts/release-video-suite.js', 'security:ioc-scan': 'node scripts/ci/scan-supply-chain-iocs.js', 'security:advisory-sources': 'node scripts/ci/supply-chain-advisory-sources.js' } @@ -52,6 +54,11 @@ function seedRepo(rootDir, overrides = {}) { 'hermes-boundary-sanitized', 'publication-blockers-preserved' ].join('\n'), + 'scripts/release-video-suite.js': [ + 'ecc.release-video-suite.v1', + 'video-source-assets-present', + 'video-release-artifacts-present' + ].join('\n'), 'docs/ECC-2.0-GA-ROADMAP.md': [ 'https://linear.app/itomarkets/project/ecc-platform-roadmap-52b328ee03e1', 'Linear ITO-44 ITO-59', @@ -109,6 +116,18 @@ function seedRepo(rootDir, overrides = {}) { 'PR queue', 'Not complete' ].join('\n'), + 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md': [ + 'This dashboard is generated by `npm run operator:dashboard`', + 'operator:dashboard', + 'Growth Baseline', + 'hypergrowth release command center', + 'Prompt-To-Artifact Checklist', + 'Next Work Order', + 'ITO-44', + 'ITO-59', + 'PR queue', + 'Not complete' + ].join('\n'), 'docs/releases/2.0.0-rc.1/owner-queue-cleanup-2026-05-18.md': [ 'Owner-wide open PRs after cleanup: 0.', 'Owner-wide open issues after cleanup: 0.', @@ -156,9 +175,34 @@ function seedRepo(rootDir, overrides = {}) { 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md': [ 'Release video suite', 'growth outreach', + 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', - '2544 passed' + '2544 passed', + 'Business baseline', + '$1,728/mo', + '$8,272/mo' + ].join('\n'), + 'docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md': [ + 'harness-native operator system', + '| MRR | `$1,728/mo` | `$10,000/mo` | `$8,272/mo` |', + 'Video Suite', + 'Distribution Plan', + 'Owner Approvals' + ].join('\n'), + 'docs/releases/2.0.0-rc.1/video-suite-production.md': [ + 'ECC 2.0 Video Suite Production Manifest', + 'Primary launch video', + 'Self-Eval Gate', + 'timeline' + ].join('\n'), + 'docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md': [ + 'Sponsor Outbound', + 'Platform Partner DM', + 'Consulting Intro', + 'Talk And Podcast Pitch', + 'GitHub Discussion Announcement', + 'Do Not Send Or Publish If' ].join('\n'), '.github/workflows/supply-chain-watch.yml': 'name: Supply-Chain Watch supply-chain-advisory-sources.js supply-chain-advisory-sources.json' }; @@ -308,6 +352,35 @@ function runTests() { && item.evidence.includes('release publication checklist') && item.gap === 'real tag/push, marketplace submission, and final channel choice remain approval-gated' ))); + assert.deepStrictEqual(report.growth, { + currentMrr: '$1,728/mo', + targetMrr: '$10,000/mo', + gapMrr: '$8,272/mo', + lanes: [ + 'GitHub Sponsors and OSS partner sponsors', + 'ECC Tools Pro subscriptions', + 'consulting and implementation contracts', + 'talks, podcasts, conference demos, and partner webinars', + ], + }); + assert.ok(report.requirements.some(item => ( + item.id === 'hypergrowth-command-center' + && item.status === 'current' + && item.evidence.includes('current MRR') + && item.gap === 'refresh after every MRR, channel, or approval-state change before public launch' + ))); + assert.ok(report.requirements.some(item => ( + item.id === 'release-video-suite' + && item.status === 'in_progress' + && item.evidence.includes('deterministic video-suite gate') + && item.gap === 'render final owner-approved MP4s, captions, platform reframes, and editable timeline before posting' + ))); + assert.ok(report.requirements.some(item => ( + item.id === 'partner-sponsor-talks-pack' + && item.status === 'in_progress' + && item.evidence.includes('sponsor outbound') + && item.gap === 'replace final URLs after publication gates, then get explicit approval before outbound or personal-account posts' + ))); assert.ok(report.requirements.some(item => ( item.id === 'supply-chain-local-protection' && item.artifact.includes('AgentShield package-manager hardening') @@ -328,8 +401,11 @@ function runTests() { && item.gap === 'repeat Linear/project status update and local work-items sync after each significant merge batch' ))); assert.ok(report.top_actions.some(item => item.id === 'naming-and-plugin-publication')); + assert.ok(report.top_actions.some(item => item.id === 'release-video-suite')); + assert.ok(report.top_actions.some(item => item.id === 'partner-sponsor-talks-pack')); assert.ok(!report.top_actions.some(item => item.id === 'ecc-preview-pack')); assert.ok(!report.top_actions.some(item => item.id === 'hermes-specialized-skills')); + assert.ok(!report.top_actions.some(item => item.id === 'hypergrowth-command-center')); assert.ok(!report.top_actions.some(item => item.id === 'legacy-salvage')); assert.ok(!report.top_actions.some(item => item.id === 'linear-roadmap-and-progress')); } finally { @@ -526,6 +602,8 @@ function runTests() { assert.strictEqual(stdout, written); assert.ok(written.includes('# ECC Operator Readiness Dashboard')); assert.ok(written.includes('Generated: 2026-05-15T00:00:00.000Z')); + assert.ok(written.includes('## Growth Baseline')); + assert.ok(written.includes('| MRR | $1,728/mo | $10,000/mo | $8,272/mo |')); assert.ok(written.includes('## Prompt-To-Artifact Checklist')); assert.ok(written.includes('Build ITO-44 completion dashboard into a repeatable command')); assert.ok(written.includes('## Next Work Order')); @@ -550,6 +628,7 @@ function runTests() { assert.ok(stdout.includes('work remaining')); assert.ok(stdout.includes('Dashboard ready: true')); assert.ok(stdout.includes('Publication ready: false')); + assert.ok(stdout.includes('MRR: $1,728/mo -> $10,000/mo (gap $8,272/mo)')); assert.ok(stdout.includes('Top actions:')); assert.ok(stdout.includes('naming-and-plugin-publication')); } finally { diff --git a/tests/scripts/platform-audit.test.js b/tests/scripts/platform-audit.test.js index cba1adc9..c61026e1 100644 --- a/tests/scripts/platform-audit.test.js +++ b/tests/scripts/platform-audit.test.js @@ -65,12 +65,15 @@ function seedRepo(rootDir, overrides = {}) { 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md': [ 'Release video suite', 'growth outreach', + 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', '2544 passed' ].join('\n'), - 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md': [ + 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md': [ 'This dashboard is generated by `npm run operator:dashboard`', + 'Growth Baseline', + 'hypergrowth release command center', 'Prompt-To-Artifact Checklist', 'ITO-44', 'ITO-59', From f3cd00625222fceedca00164b828db8803fe52d6 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 08:22:06 -0400 Subject: [PATCH 35/61] chore: add release video self-eval gate --- .../publication-evidence-2026-05-19.md | 2 +- .../2.0.0-rc.1/video-suite-production.md | 2 + scripts/release-video-suite.js | 88 ++++++++++++++++++- tests/scripts/release-video-suite.test.js | 5 ++ 4 files changed, 94 insertions(+), 3 deletions(-) diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md index f0b81fcf..d9d19e46 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -51,7 +51,7 @@ Tracked repositories in the platform audit were: | Release-surface tests | `node tests/docs/ecc2-release-surface.test.js` | 25 passed, 0 failed | | Preview-pack smoke | `npm run preview-pack:smoke -- --format json` | Ready true; digest `bc2bf157616e`; 30 required artifacts; 5 passed, 0 failed | | Operator dashboard | `npm run operator:dashboard -- --markdown --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Generated May 19 dashboard with platform audit ready true, 0 tracked PRs, 0 tracked issues, 0 discussion gaps, `$1,728/mo` current MRR, `$10,000/mo` target MRR, and top actions for plugin publication, notifications, release video, outbound approval, AgentShield, and ECC Tools billing | -| Release video suite | `npm run release:video-suite -- --format json --summary` with `ECC_VIDEO_SOURCE_ROOT` and `ECC_VIDEO_RELEASE_SUITE_ROOT` | Ready true; 15/15 source assets present; 13/13 render, timeline, caption, EDL, and segment artifacts present; primary rough render is 144.759 seconds and 106.78 MB | +| Release video suite | `npm run release:video-suite -- --format json --summary` with `ECC_VIDEO_SOURCE_ROOT` and `ECC_VIDEO_RELEASE_SUITE_ROOT` | Ready true; 15/15 source assets present; 13/13 render, timeline, caption, EDL, and segment artifacts present; primary rough render self-eval passed at 144.759 seconds, 1920x1080, 1 audio stream, and 106.78 MB | | Full local suite | `node tests/run-all.js` | 2544 passed, 0 failed | | PR #1993 CI | GitHub Actions run `26093792219` | Completed successfully for `d9ac22c697d9a8a8771512ab01e6df857c16776d`; all reported checks passed, including lint, validation, security scan, coverage, GitGuardian, and the macOS/Ubuntu/Windows test matrix | | Public-path sanitization | `node scripts/ci/validate-no-personal-paths.js` through local suite and CI | Passed | diff --git a/docs/releases/2.0.0-rc.1/video-suite-production.md b/docs/releases/2.0.0-rc.1/video-suite-production.md index 60a86ebb..9ac68b0c 100644 --- a/docs/releases/2.0.0-rc.1/video-suite-production.md +++ b/docs/releases/2.0.0-rc.1/video-suite-production.md @@ -153,6 +153,8 @@ npm run release:video-suite -- --format json Then manually check the final render for: +- validator self-eval passes for the primary render: 90-150 seconds, at least + 1280x720, video stream present, audio stream present, and non-empty output; - no blank frames or accidental desktop exposure; - no stale repo name, pivot, rename, or Claude-only framing in captions; - no captions that rewrite speech into a false claim; diff --git a/scripts/release-video-suite.js b/scripts/release-video-suite.js index c19b9ca6..0a5f3c7f 100644 --- a/scripts/release-video-suite.js +++ b/scripts/release-video-suite.js @@ -371,8 +371,12 @@ function probeMedia(filePath, skipProbe) { const result = { sizeBytes: stat.size, sizeMb: formatBytes(stat.size), + audioStreams: null, durationSeconds: null, + height: null, probe: skipProbe ? 'skipped' : 'unavailable', + videoStreams: null, + width: null, }; if (skipProbe) { @@ -383,7 +387,7 @@ function probeMedia(filePath, skipProbe) { '-v', 'error', '-show_entries', - 'format=duration', + 'format=duration:stream=codec_type,width,height', '-of', 'json', filePath, @@ -407,9 +411,19 @@ function probeMedia(filePath, skipProbe) { const duration = Number(parsed && parsed.format && parsed.format.duration); if (Number.isFinite(duration)) { result.durationSeconds = Number(duration.toFixed(3)); - result.probe = 'ok'; } + const streams = Array.isArray(parsed && parsed.streams) ? parsed.streams : []; + const videoStreams = streams.filter(stream => stream.codec_type === 'video'); + const audioStreams = streams.filter(stream => stream.codec_type === 'audio'); + const firstVideo = videoStreams[0] || {}; + + result.audioStreams = audioStreams.length; + result.videoStreams = videoStreams.length; + result.width = Number.isFinite(Number(firstVideo.width)) ? Number(firstVideo.width) : null; + result.height = Number.isFinite(Number(firstVideo.height)) ? Number(firstVideo.height) : null; + result.probe = 'ok'; + return result; } @@ -520,6 +534,69 @@ function inspectSuiteArtifacts(suiteRoot, skipProbe) { }); } +function evaluatePrimaryRender(suiteArtifacts, skipProbe) { + const primary = suiteArtifacts.find(artifact => artifact.id === 'primary-render-v1'); + + if (!primary || primary.status !== 'present') { + return { + status: 'fail', + summary: 'primary launch render is missing or outside the duration target', + fix: 'Render the primary launch video within the 90-150 second target before release review.', + }; + } + + if (skipProbe) { + return { + status: 'pass', + summary: 'primary launch render exists; stream self-eval skipped by --skip-probe', + fix: '', + }; + } + + const failures = []; + + if (primary.probe !== 'ok') { + failures.push(`ffprobe ${primary.probe}`); + } + + if (!Number.isFinite(primary.durationSeconds) + || primary.durationSeconds < 90 + || primary.durationSeconds > 150) { + failures.push('duration outside 90-150 seconds'); + } + + if (!Number.isFinite(primary.sizeMb) || primary.sizeMb < 5) { + failures.push('render is unexpectedly small'); + } + + if (!Number.isFinite(primary.videoStreams) || primary.videoStreams < 1) { + failures.push('no video stream'); + } + + if (!Number.isFinite(primary.audioStreams) || primary.audioStreams < 1) { + failures.push('no audio stream'); + } + + if (!Number.isFinite(primary.width) || !Number.isFinite(primary.height) + || primary.width < 1280 || primary.height < 720) { + failures.push('resolution below 1280x720'); + } + + if (failures.length > 0) { + return { + status: 'fail', + summary: `primary launch render failed self-eval: ${failures.join(', ')}`, + fix: 'Regenerate the primary launch render with audio, HD video, valid duration, and non-empty output.', + }; + } + + return { + status: 'pass', + summary: `primary launch render self-eval passed: ${primary.durationSeconds}s, ${primary.width}x${primary.height}, ${primary.audioStreams} audio stream(s), ${primary.sizeMb} MB`, + fix: '', + }; +} + function buildReport(options = {}) { const rootDir = path.resolve(options.root || process.cwd()); const sourceRoot = options.sourceRoot ? path.resolve(options.sourceRoot) : ''; @@ -542,6 +619,7 @@ function buildReport(options = {}) { const suiteArtifacts = inspectSuiteArtifacts(suiteRoot, skipProbe); const missingSourceAssets = sourceAssets.filter(asset => asset.status !== 'present'); const missingSuiteArtifacts = suiteArtifacts.filter(artifact => artifact.status !== 'present'); + const primaryRenderSelfEval = evaluatePrimaryRender(suiteArtifacts, skipProbe); const checks = [ makeCheck( @@ -598,6 +676,12 @@ function buildReport(options = {}) { missing: missingSuiteArtifacts.map(artifact => artifact.relativePath), } ), + makeCheck( + 'video-primary-render-self-eval', + primaryRenderSelfEval.status, + primaryRenderSelfEval.summary, + primaryRenderSelfEval.fix + ), ]; const failed = checks.filter(check => check.status !== 'pass'); diff --git a/tests/scripts/release-video-suite.test.js b/tests/scripts/release-video-suite.test.js index 4cab6be2..a8a1169a 100644 --- a/tests/scripts/release-video-suite.test.js +++ b/tests/scripts/release-video-suite.test.js @@ -169,6 +169,10 @@ function runTests() { assert.strictEqual(report.ready, true); assert.strictEqual(report.mediaPathsRedacted, true); assert.ok(report.checks.every(check => check.status === 'pass')); + assert.ok(report.checks.some(check => ( + check.id === 'video-primary-render-self-eval' + && check.summary.includes('skipped by --skip-probe') + ))); assert.strictEqual(report.sourceAssets.length, REQUIRED_SOURCE_ASSETS.length); assert.strictEqual(report.suiteArtifacts.length, REQUIRED_SUITE_ARTIFACTS.length); assert.ok(renderText(report).includes('Ready: yes')); @@ -197,6 +201,7 @@ function runTests() { assert.ok(report.top_actions.some(action => action.includes('ECC_VIDEO_RELEASE_SUITE_ROOT'))); assert.ok(report.checks.some(check => check.id === 'video-source-assets-present' && check.status === 'fail')); assert.ok(report.checks.some(check => check.id === 'video-release-artifacts-present' && check.status === 'fail')); + assert.ok(report.checks.some(check => check.id === 'video-primary-render-self-eval' && check.status === 'fail')); } finally { cleanup(rootDir); } From 855e8c8336e1c18523cbb31cb29f4ce96d7518a7 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 08:40:48 -0400 Subject: [PATCH 36/61] chore: gate release video publish candidates --- .../publication-evidence-2026-05-19.md | 16 +- .../2.0.0-rc.1/video-suite-production.md | 23 ++ scripts/release-video-suite.js | 265 +++++++++++++++--- tests/scripts/release-video-suite.test.js | 12 + 4 files changed, 276 insertions(+), 40 deletions(-) diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md index d9d19e46..9eff4949 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -8,9 +8,9 @@ social announcement. | Field | Evidence | | --- | --- | -| Upstream main | `c07276a347f8dac4945d2ad294124a708c19b108` | +| Upstream main | `f3cd00625222fceedca00164b828db8803fe52d6` | | Git remote | `https://github.com/affaan-m/ECC.git` | -| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, and PR #1994 May 19 publication evidence refresh | +| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, and PR #1996 primary render self-eval gate | | Local status caveat | `git status --short --branch` was clean after pulling `origin/main`; generated evidence files are committed after the source snapshot they describe | The release operator must repeat all publish-facing checks from the exact final @@ -43,6 +43,8 @@ Tracked repositories in the platform audit were: | PR #1992 | Merged the release video-suite gate, production manifest, validator, package file surface, preview-pack smoke wiring, release-surface tests, and compact CI JSON output | | PR #1993 | Merged the partner, sponsor, consulting, conference, podcast, GitHub Discussion, and video CTA pack for the hypergrowth outbound lane | | PR #1994 | Merged the May 19 publication-evidence refresh, platform-audit evidence gate, preview-pack smoke evidence gate, and URL/readiness/roadmap references | +| PR #1995 | Merged the May 19 operator dashboard refresh with the `$1,728/mo` MRR baseline, `$10,000/mo` target, and release/video/outbound top actions | +| PR #1996 | Merged the primary launch render self-eval gate for duration, size, resolution, video stream, and audio stream checks | ## Release And Growth Evidence @@ -51,9 +53,9 @@ Tracked repositories in the platform audit were: | Release-surface tests | `node tests/docs/ecc2-release-surface.test.js` | 25 passed, 0 failed | | Preview-pack smoke | `npm run preview-pack:smoke -- --format json` | Ready true; digest `bc2bf157616e`; 30 required artifacts; 5 passed, 0 failed | | Operator dashboard | `npm run operator:dashboard -- --markdown --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Generated May 19 dashboard with platform audit ready true, 0 tracked PRs, 0 tracked issues, 0 discussion gaps, `$1,728/mo` current MRR, `$10,000/mo` target MRR, and top actions for plugin publication, notifications, release video, outbound approval, AgentShield, and ECC Tools billing | -| Release video suite | `npm run release:video-suite -- --format json --summary` with `ECC_VIDEO_SOURCE_ROOT` and `ECC_VIDEO_RELEASE_SUITE_ROOT` | Ready true; 15/15 source assets present; 13/13 render, timeline, caption, EDL, and segment artifacts present; primary rough render self-eval passed at 144.759 seconds, 1920x1080, 1 audio stream, and 106.78 MB | +| Release video suite | `npm run release:video-suite -- --format json --summary` with `ECC_VIDEO_SOURCE_ROOT` and `ECC_VIDEO_RELEASE_SUITE_ROOT` | Ready true; 15/15 source assets present; 13/13 render, timeline, caption, EDL, and segment artifacts present; 12/12 publish-candidate outputs present; primary rough render self-eval passed at 144.759 seconds, 1920x1080, 1 audio stream, and 106.78 MB | | Full local suite | `node tests/run-all.js` | 2544 passed, 0 failed | -| PR #1993 CI | GitHub Actions run `26093792219` | Completed successfully for `d9ac22c697d9a8a8771512ab01e6df857c16776d`; all reported checks passed, including lint, validation, security scan, coverage, GitGuardian, and the macOS/Ubuntu/Windows test matrix | +| PR #1996 CI | GitHub Actions run `26096847138` | Completed successfully for `f3cd00625222fceedca00164b828db8803fe52d6`; all reported checks passed, including lint, validation, security scan, coverage, GitGuardian, CodeRabbit, Cubic, and the macOS/Ubuntu/Windows test matrix | | Public-path sanitization | `node scripts/ci/validate-no-personal-paths.js` through local suite and CI | Passed | | Markdown and whitespace | `markdownlint` focused release docs plus `git diff --check` before PR #1993 | Passed | @@ -63,7 +65,7 @@ Tracked repositories in the platform audit were: | --- | --- | | Canonical repo identity | Public URLs and release docs now use `https://github.com/affaan-m/ECC` where public links are needed | | Release claim | Release notes and launch collateral frame ECC as the harness-native operator system for agentic work, not a Claude-only config pack | -| Video proof | `video-suite-production.md` gates the local rough render, timeline, captions, source inventory, self-eval, and no-private-path publication rules | +| Video proof | `video-suite-production.md` gates the local rough render, timeline, captions, source inventory, publish-candidate clip set, self-eval, and no-private-path publication rules | | Growth proof | `partner-sponsor-talks-pack.md` provides approval-gated copy for sponsors, partners, consulting, talks, podcasts, GitHub Discussion, and video CTAs | | Business baseline | Hypergrowth command center and partner pack use `$1,728/mo` current MRR, `$10,000/mo` target MRR, and `$8,272/mo` gap | | Operator dashboard | `operator-readiness-dashboard-2026-05-19.md` pulls the growth baseline into the same queue, publication, video, outbound, AgentShield, ECC Tools, Linear, and supply-chain control surface | @@ -92,8 +94,8 @@ Tracked repositories in the platform audit were: The tracked public PR queue, issue queue, discussion queue, canonical ECC identity, release video suite, preview pack, and growth outreach packet are current on May 19, 2026 for `main` through -`c07276a347f8dac4945d2ad294124a708c19b108`, with the May 19 dashboard -refresh staged for the next merge. +`f3cd00625222fceedca00164b828db8803fe52d6`, with the publish-candidate +video gate staged for the next merge. This improves publication readiness but does not replace the approval-gated release, package, plugin, billing, Discord, and announcement steps in diff --git a/docs/releases/2.0.0-rc.1/video-suite-production.md b/docs/releases/2.0.0-rc.1/video-suite-production.md index 9ac68b0c..ee2dc24e 100644 --- a/docs/releases/2.0.0-rc.1/video-suite-production.md +++ b/docs/releases/2.0.0-rc.1/video-suite-production.md @@ -106,6 +106,27 @@ Required local rough v1 artifacts: - `segments/primary-launch-v1/08-oss-paid-model.mp4` - `segments/primary-launch-v1/09-close-shipping-system.mp4` +## Publish-Candidate Outputs + +The release validator also expects the current publish-candidate set under +`renders/publish-candidates/`. These are still local review files, not public +uploads or committed media. + +| Output | Target | +| --- | --- | +| `ecc-2-primary-launch.mp4` | 90-150s, 1920x1080, audio | +| `ecc-2-primary-launch.captions.srt` | primary captions | +| `ecc-2-install-proof-wide.mp4` | 25-35s, 1920x1080, audio | +| `ecc-2-install-proof-vertical.mp4` | 25-35s, 1080x1920, audio | +| `ecc-2-what-is-ecc-wide.mp4` | 45-60s, 1920x1080, audio | +| `ecc-2-what-is-ecc-vertical.mp4` | 45-60s, 1080x1920, audio | +| `ecc-2-security-proof-wide.mp4` | 45-60s, 1920x1080, audio | +| `ecc-2-security-proof-vertical.mp4` | 45-60s, 1080x1920, audio | +| `ecc-2-money-proof-wide.mp4` | 30-45s, 1920x1080, audio | +| `ecc-2-money-proof-vertical.mp4` | 30-45s, 1080x1920, audio | +| `ecc-2-social-proof-wide.mp4` | 30-45s, 1920x1080, audio | +| `ecc-2-social-proof-vertical.mp4` | 30-45s, 1080x1920, audio | + ## video-use compatible workflow Use the same production shape as Video Use while keeping the ECC-specific media @@ -155,6 +176,8 @@ Then manually check the final render for: - validator self-eval passes for the primary render: 90-150 seconds, at least 1280x720, video stream present, audio stream present, and non-empty output; +- validator self-eval passes for the publish-candidate set: primary MP4 plus + captions and five short clips in both wide and vertical formats; - no blank frames or accidental desktop exposure; - no stale repo name, pivot, rename, or Claude-only framing in captions; - no captions that rewrite speech into a false claim; diff --git a/scripts/release-video-suite.js b/scripts/release-video-suite.js index 0a5f3c7f..d4abb8d3 100644 --- a/scripts/release-video-suite.js +++ b/scripts/release-video-suite.js @@ -183,6 +183,135 @@ const REQUIRED_SUITE_ARTIFACTS = [ }, ]; +const REQUIRED_PUBLISH_CANDIDATES = [ + { + id: 'publish-primary-launch', + relativePath: 'renders/publish-candidates/ecc-2-primary-launch.mp4', + kind: 'video', + minDurationSeconds: 90, + maxDurationSeconds: 150, + minWidth: 1920, + minHeight: 1080, + minSizeMb: 5, + requiresAudio: true, + }, + { + id: 'publish-primary-launch-captions', + relativePath: 'renders/publish-candidates/ecc-2-primary-launch.captions.srt', + kind: 'captions', + }, + { + id: 'publish-install-proof-wide', + relativePath: 'renders/publish-candidates/ecc-2-install-proof-wide.mp4', + kind: 'video', + minDurationSeconds: 25, + maxDurationSeconds: 35, + minWidth: 1920, + minHeight: 1080, + minSizeMb: 1, + requiresAudio: true, + }, + { + id: 'publish-install-proof-vertical', + relativePath: 'renders/publish-candidates/ecc-2-install-proof-vertical.mp4', + kind: 'video', + minDurationSeconds: 25, + maxDurationSeconds: 35, + minWidth: 1080, + minHeight: 1920, + minSizeMb: 1, + requiresAudio: true, + }, + { + id: 'publish-what-is-ecc-wide', + relativePath: 'renders/publish-candidates/ecc-2-what-is-ecc-wide.mp4', + kind: 'video', + minDurationSeconds: 45, + maxDurationSeconds: 60, + minWidth: 1920, + minHeight: 1080, + minSizeMb: 2, + requiresAudio: true, + }, + { + id: 'publish-what-is-ecc-vertical', + relativePath: 'renders/publish-candidates/ecc-2-what-is-ecc-vertical.mp4', + kind: 'video', + minDurationSeconds: 45, + maxDurationSeconds: 60, + minWidth: 1080, + minHeight: 1920, + minSizeMb: 2, + requiresAudio: true, + }, + { + id: 'publish-security-proof-wide', + relativePath: 'renders/publish-candidates/ecc-2-security-proof-wide.mp4', + kind: 'video', + minDurationSeconds: 45, + maxDurationSeconds: 60, + minWidth: 1920, + minHeight: 1080, + minSizeMb: 2, + requiresAudio: true, + }, + { + id: 'publish-security-proof-vertical', + relativePath: 'renders/publish-candidates/ecc-2-security-proof-vertical.mp4', + kind: 'video', + minDurationSeconds: 45, + maxDurationSeconds: 60, + minWidth: 1080, + minHeight: 1920, + minSizeMb: 2, + requiresAudio: true, + }, + { + id: 'publish-money-proof-wide', + relativePath: 'renders/publish-candidates/ecc-2-money-proof-wide.mp4', + kind: 'video', + minDurationSeconds: 30, + maxDurationSeconds: 45, + minWidth: 1920, + minHeight: 1080, + minSizeMb: 2, + requiresAudio: true, + }, + { + id: 'publish-money-proof-vertical', + relativePath: 'renders/publish-candidates/ecc-2-money-proof-vertical.mp4', + kind: 'video', + minDurationSeconds: 30, + maxDurationSeconds: 45, + minWidth: 1080, + minHeight: 1920, + minSizeMb: 2, + requiresAudio: true, + }, + { + id: 'publish-social-proof-wide', + relativePath: 'renders/publish-candidates/ecc-2-social-proof-wide.mp4', + kind: 'video', + minDurationSeconds: 30, + maxDurationSeconds: 45, + minWidth: 1920, + minHeight: 1080, + minSizeMb: 2, + requiresAudio: true, + }, + { + id: 'publish-social-proof-vertical', + relativePath: 'renders/publish-candidates/ecc-2-social-proof-vertical.mp4', + kind: 'video', + minDurationSeconds: 30, + maxDurationSeconds: 45, + minWidth: 1080, + minHeight: 1920, + minSizeMb: 2, + requiresAudio: true, + }, +]; + function usage() { console.log([ 'Usage: node scripts/release-video-suite.js [options]', @@ -471,22 +600,83 @@ function inspectSourceAssets(sourceRoot, skipProbe) { }); } -function inspectSuiteArtifacts(suiteRoot, skipProbe) { - return REQUIRED_SUITE_ARTIFACTS.map(artifact => { - if (!suiteRoot) { +function validateVideoArtifact(artifact, media, skipProbe) { + if (artifact.kind !== 'video' || skipProbe) { + return []; + } + + const failures = []; + + if (media.probe !== 'ok') { + failures.push(`ffprobe ${media.probe}`); + } + + if ( + Number.isFinite(artifact.minDurationSeconds) + && ( + !Number.isFinite(media.durationSeconds) + || media.durationSeconds < artifact.minDurationSeconds + ) + ) { + failures.push(`duration below ${artifact.minDurationSeconds}s`); + } + + if ( + Number.isFinite(artifact.maxDurationSeconds) + && ( + !Number.isFinite(media.durationSeconds) + || media.durationSeconds > artifact.maxDurationSeconds + ) + ) { + failures.push(`duration above ${artifact.maxDurationSeconds}s`); + } + + if ( + Number.isFinite(artifact.minSizeMb) + && (!Number.isFinite(media.sizeMb) || media.sizeMb < artifact.minSizeMb) + ) { + failures.push(`size below ${artifact.minSizeMb} MB`); + } + + if ( + Number.isFinite(artifact.minWidth) + && (!Number.isFinite(media.width) || media.width < artifact.minWidth) + ) { + failures.push(`width below ${artifact.minWidth}`); + } + + if ( + Number.isFinite(artifact.minHeight) + && (!Number.isFinite(media.height) || media.height < artifact.minHeight) + ) { + failures.push(`height below ${artifact.minHeight}`); + } + + if (artifact.requiresAudio && (!Number.isFinite(media.audioStreams) || media.audioStreams < 1)) { + failures.push('audio stream missing'); + } + + return failures; +} + +function inspectArtifactCollection(rootDir, artifacts, skipProbe) { + return artifacts.map(artifact => { + if (!rootDir) { return { ...artifact, status: 'missing', configured: false, + validationFailures: [], }; } - const filePath = path.join(suiteRoot, artifact.relativePath); + const filePath = path.join(rootDir, artifact.relativePath); if (!fs.existsSync(filePath)) { return { ...artifact, status: 'missing', configured: true, + validationFailures: [], }; } @@ -496,44 +686,26 @@ function inspectSuiteArtifacts(suiteRoot, skipProbe) { durationSeconds: null, probe: 'not-media', }; - - let durationStatus = 'pass'; - if ( - artifact.kind === 'video' - && Number.isFinite(artifact.minDurationSeconds) - && Number.isFinite(media.durationSeconds) - && media.durationSeconds < artifact.minDurationSeconds - ) { - durationStatus = 'fail'; - } - - if ( - artifact.kind === 'video' - && Number.isFinite(artifact.maxDurationSeconds) - && Number.isFinite(media.durationSeconds) - && media.durationSeconds > artifact.maxDurationSeconds - ) { - durationStatus = 'fail'; - } - - if ( - artifact.kind === 'video' - && Number.isFinite(artifact.minDurationSeconds) - && !skipProbe - && media.durationSeconds === null - ) { - durationStatus = 'fail'; - } + const validationFailures = validateVideoArtifact(artifact, media, skipProbe); return { ...artifact, - status: durationStatus === 'pass' ? 'present' : 'invalid', + status: validationFailures.length === 0 ? 'present' : 'invalid', configured: true, + validationFailures, ...media, }; }); } +function inspectSuiteArtifacts(suiteRoot, skipProbe) { + return inspectArtifactCollection(suiteRoot, REQUIRED_SUITE_ARTIFACTS, skipProbe); +} + +function inspectPublishCandidates(suiteRoot, skipProbe) { + return inspectArtifactCollection(suiteRoot, REQUIRED_PUBLISH_CANDIDATES, skipProbe); +} + function evaluatePrimaryRender(suiteArtifacts, skipProbe) { const primary = suiteArtifacts.find(artifact => artifact.id === 'primary-render-v1'); @@ -617,8 +789,10 @@ function buildReport(options = {}) { ]); const sourceAssets = inspectSourceAssets(sourceRoot, skipProbe); const suiteArtifacts = inspectSuiteArtifacts(suiteRoot, skipProbe); + const publishCandidates = inspectPublishCandidates(suiteRoot, skipProbe); const missingSourceAssets = sourceAssets.filter(asset => asset.status !== 'present'); const missingSuiteArtifacts = suiteArtifacts.filter(artifact => artifact.status !== 'present'); + const missingPublishCandidates = publishCandidates.filter(candidate => candidate.status !== 'present'); const primaryRenderSelfEval = evaluatePrimaryRender(suiteArtifacts, skipProbe); const checks = [ @@ -682,6 +856,23 @@ function buildReport(options = {}) { primaryRenderSelfEval.summary, primaryRenderSelfEval.fix ), + makeCheck( + 'video-publish-candidates-present', + missingPublishCandidates.length === 0 ? 'pass' : 'fail', + missingPublishCandidates.length === 0 + ? `${publishCandidates.length} publish-candidate MP4/caption artifacts are present and self-evaluable` + : `missing or invalid publish candidates: ${missingPublishCandidates.map(candidate => { + const reason = candidate.validationFailures && candidate.validationFailures.length > 0 + ? ` (${candidate.validationFailures.join(', ')})` + : ''; + return `${candidate.relativePath}${reason}`; + }).join(', ')}`, + 'Render the publish-candidate MP4/caption set under renders/publish-candidates before release review.', + { + configured: Boolean(suiteRoot), + missing: missingPublishCandidates.map(candidate => candidate.relativePath), + } + ), ]; const failed = checks.filter(check => check.status !== 'pass'); @@ -713,6 +904,7 @@ function buildReport(options = {}) { checks, sourceAssets, suiteArtifacts, + publishCandidates, top_actions: topActions, }; } @@ -748,6 +940,7 @@ function summarizeReport(report) { })), sourceAssetSummary: summarizeItems(report.sourceAssets), suiteArtifactSummary: summarizeItems(report.suiteArtifacts), + publishCandidateSummary: summarizeItems(report.publishCandidates), primaryRender: primaryRender ? { status: primaryRender.status, durationSeconds: primaryRender.durationSeconds, @@ -780,6 +973,11 @@ function renderText(report) { ); } + if (report.publishCandidates.length > 0) { + const present = report.publishCandidates.filter(item => item.status === 'present').length; + lines.push(`Publish candidates: ${present}/${report.publishCandidates.length} present`); + } + if (report.top_actions.length > 0) { lines.push(''); lines.push('Top actions:'); @@ -822,6 +1020,7 @@ if (require.main === module) { } module.exports = { + REQUIRED_PUBLISH_CANDIDATES, REQUIRED_SOURCE_ASSETS, REQUIRED_SUITE_ARTIFACTS, buildReport, diff --git a/tests/scripts/release-video-suite.test.js b/tests/scripts/release-video-suite.test.js index a8a1169a..a39f2f8c 100644 --- a/tests/scripts/release-video-suite.test.js +++ b/tests/scripts/release-video-suite.test.js @@ -10,6 +10,7 @@ const { execFileSync, spawnSync } = require('child_process'); const SCRIPT = path.join(__dirname, '..', '..', 'scripts', 'release-video-suite.js'); const { + REQUIRED_PUBLISH_CANDIDATES, REQUIRED_SOURCE_ASSETS, REQUIRED_SUITE_ARTIFACTS, buildReport, @@ -75,6 +76,10 @@ function seedMedia(sourceRoot, suiteRoot) { for (const artifact of REQUIRED_SUITE_ARTIFACTS) { writeFile(suiteRoot, artifact.relativePath, `artifact ${artifact.id}`); } + + for (const candidate of REQUIRED_PUBLISH_CANDIDATES) { + writeFile(suiteRoot, candidate.relativePath, `candidate ${candidate.id}`); + } } function run(args = [], options = {}) { @@ -175,8 +180,13 @@ function runTests() { ))); assert.strictEqual(report.sourceAssets.length, REQUIRED_SOURCE_ASSETS.length); assert.strictEqual(report.suiteArtifacts.length, REQUIRED_SUITE_ARTIFACTS.length); + assert.strictEqual(report.publishCandidates.length, REQUIRED_PUBLISH_CANDIDATES.length); assert.ok(renderText(report).includes('Ready: yes')); assert.strictEqual(summarizeReport(report).sourceAssetSummary.present, REQUIRED_SOURCE_ASSETS.length); + assert.strictEqual( + summarizeReport(report).publishCandidateSummary.present, + REQUIRED_PUBLISH_CANDIDATES.length + ); } finally { cleanup(rootDir); cleanup(sourceRoot); @@ -202,6 +212,7 @@ function runTests() { assert.ok(report.checks.some(check => check.id === 'video-source-assets-present' && check.status === 'fail')); assert.ok(report.checks.some(check => check.id === 'video-release-artifacts-present' && check.status === 'fail')); assert.ok(report.checks.some(check => check.id === 'video-primary-render-self-eval' && check.status === 'fail')); + assert.ok(report.checks.some(check => check.id === 'video-publish-candidates-present' && check.status === 'fail')); } finally { cleanup(rootDir); } @@ -269,6 +280,7 @@ function runTests() { assert.strictEqual(parsed.suiteRootConfigured, true); assert.strictEqual(parsed.sourceAssetSummary.present, REQUIRED_SOURCE_ASSETS.length); assert.strictEqual(parsed.suiteArtifactSummary.present, REQUIRED_SUITE_ARTIFACTS.length); + assert.strictEqual(parsed.publishCandidateSummary.present, REQUIRED_PUBLISH_CANDIDATES.length); } finally { cleanup(rootDir); cleanup(sourceRoot); From b62f80750d85db35b765c675c3866f2037adc5a8 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 08:59:55 -0400 Subject: [PATCH 37/61] chore: add release video visual qa --- .../publication-evidence-2026-05-19.md | 17 ++-- .../2.0.0-rc.1/video-suite-production.md | 2 + scripts/platform-audit.js | 2 +- scripts/release-video-suite.js | 82 +++++++++++++++++-- .../operator-readiness-dashboard.test.js | 2 +- tests/scripts/platform-audit.test.js | 2 +- tests/scripts/release-video-suite.test.js | 7 ++ 7 files changed, 95 insertions(+), 19 deletions(-) diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md index 9eff4949..c2519037 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -8,9 +8,9 @@ social announcement. | Field | Evidence | | --- | --- | -| Upstream main | `f3cd00625222fceedca00164b828db8803fe52d6` | +| Upstream main | `855e8c8336e1c18523cbb31cb29f4ce96d7518a7` | | Git remote | `https://github.com/affaan-m/ECC.git` | -| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, and PR #1996 primary render self-eval gate | +| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, and PR #1997 publish-candidate gate | | Local status caveat | `git status --short --branch` was clean after pulling `origin/main`; generated evidence files are committed after the source snapshot they describe | The release operator must repeat all publish-facing checks from the exact final @@ -45,6 +45,7 @@ Tracked repositories in the platform audit were: | PR #1994 | Merged the May 19 publication-evidence refresh, platform-audit evidence gate, preview-pack smoke evidence gate, and URL/readiness/roadmap references | | PR #1995 | Merged the May 19 operator dashboard refresh with the `$1,728/mo` MRR baseline, `$10,000/mo` target, and release/video/outbound top actions | | PR #1996 | Merged the primary launch render self-eval gate for duration, size, resolution, video stream, and audio stream checks | +| PR #1997 | Merged the publish-candidate gate for the primary launch MP4/captions plus five short clips in wide and vertical formats | ## Release And Growth Evidence @@ -53,9 +54,9 @@ Tracked repositories in the platform audit were: | Release-surface tests | `node tests/docs/ecc2-release-surface.test.js` | 25 passed, 0 failed | | Preview-pack smoke | `npm run preview-pack:smoke -- --format json` | Ready true; digest `bc2bf157616e`; 30 required artifacts; 5 passed, 0 failed | | Operator dashboard | `npm run operator:dashboard -- --markdown --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Generated May 19 dashboard with platform audit ready true, 0 tracked PRs, 0 tracked issues, 0 discussion gaps, `$1,728/mo` current MRR, `$10,000/mo` target MRR, and top actions for plugin publication, notifications, release video, outbound approval, AgentShield, and ECC Tools billing | -| Release video suite | `npm run release:video-suite -- --format json --summary` with `ECC_VIDEO_SOURCE_ROOT` and `ECC_VIDEO_RELEASE_SUITE_ROOT` | Ready true; 15/15 source assets present; 13/13 render, timeline, caption, EDL, and segment artifacts present; 12/12 publish-candidate outputs present; primary rough render self-eval passed at 144.759 seconds, 1920x1080, 1 audio stream, and 106.78 MB | -| Full local suite | `node tests/run-all.js` | 2544 passed, 0 failed | -| PR #1996 CI | GitHub Actions run `26096847138` | Completed successfully for `f3cd00625222fceedca00164b828db8803fe52d6`; all reported checks passed, including lint, validation, security scan, coverage, GitGuardian, CodeRabbit, Cubic, and the macOS/Ubuntu/Windows test matrix | +| Release video suite | `npm run release:video-suite -- --format json --summary` with `ECC_VIDEO_SOURCE_ROOT` and `ECC_VIDEO_RELEASE_SUITE_ROOT` | Ready true; 15/15 source assets present; 13/13 render, timeline, caption, EDL, and segment artifacts present; 12/12 publish-candidate outputs present with zero detected black-frame segments; primary rough render self-eval passed at 144.759 seconds, 1920x1080, 1 audio stream, and 106.78 MB | +| Full local suite | `node tests/run-all.js` | 2545 passed, 0 failed | +| PR #1997 CI | GitHub Actions run `26097832795` | Completed successfully for `855e8c8336e1c18523cbb31cb29f4ce96d7518a7`; all reported checks passed, including lint, validation, security scan, coverage, GitGuardian, CodeRabbit, Cubic, and the macOS/Ubuntu/Windows test matrix | | Public-path sanitization | `node scripts/ci/validate-no-personal-paths.js` through local suite and CI | Passed | | Markdown and whitespace | `markdownlint` focused release docs plus `git diff --check` before PR #1993 | Passed | @@ -65,7 +66,7 @@ Tracked repositories in the platform audit were: | --- | --- | | Canonical repo identity | Public URLs and release docs now use `https://github.com/affaan-m/ECC` where public links are needed | | Release claim | Release notes and launch collateral frame ECC as the harness-native operator system for agentic work, not a Claude-only config pack | -| Video proof | `video-suite-production.md` gates the local rough render, timeline, captions, source inventory, publish-candidate clip set, self-eval, and no-private-path publication rules | +| Video proof | `video-suite-production.md` gates the local rough render, timeline, captions, source inventory, publish-candidate clip set, self-eval, black-frame QA, and no-private-path publication rules | | Growth proof | `partner-sponsor-talks-pack.md` provides approval-gated copy for sponsors, partners, consulting, talks, podcasts, GitHub Discussion, and video CTAs | | Business baseline | Hypergrowth command center and partner pack use `$1,728/mo` current MRR, `$10,000/mo` target MRR, and `$8,272/mo` gap | | Operator dashboard | `operator-readiness-dashboard-2026-05-19.md` pulls the growth baseline into the same queue, publication, video, outbound, AgentShield, ECC Tools, Linear, and supply-chain control surface | @@ -94,8 +95,8 @@ Tracked repositories in the platform audit were: The tracked public PR queue, issue queue, discussion queue, canonical ECC identity, release video suite, preview pack, and growth outreach packet are current on May 19, 2026 for `main` through -`f3cd00625222fceedca00164b828db8803fe52d6`, with the publish-candidate -video gate staged for the next merge. +`855e8c8336e1c18523cbb31cb29f4ce96d7518a7`, with the visual video QA gate +staged for the next merge. This improves publication readiness but does not replace the approval-gated release, package, plugin, billing, Discord, and announcement steps in diff --git a/docs/releases/2.0.0-rc.1/video-suite-production.md b/docs/releases/2.0.0-rc.1/video-suite-production.md index ee2dc24e..19ea68aa 100644 --- a/docs/releases/2.0.0-rc.1/video-suite-production.md +++ b/docs/releases/2.0.0-rc.1/video-suite-production.md @@ -178,6 +178,8 @@ Then manually check the final render for: 1280x720, video stream present, audio stream present, and non-empty output; - validator self-eval passes for the publish-candidate set: primary MP4 plus captions and five short clips in both wide and vertical formats; +- validator visual QA reports zero detected black-frame segments for every + publish-candidate MP4; - no blank frames or accidental desktop exposure; - no stale repo name, pivot, rename, or Claude-only framing in captions; - no captions that rewrite speech into a false claim; diff --git a/scripts/platform-audit.js b/scripts/platform-audit.js index 5cc17b0c..0125a5d8 100644 --- a/scripts/platform-audit.js +++ b/scripts/platform-audit.js @@ -472,7 +472,7 @@ function buildLocalEvidenceChecks(rootDir) { ), buildCheck( 'release-evidence-current', - includesAll(evidence, ['Release video suite', 'growth outreach', 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', '2544 passed']) ? 'pass' : 'fail', + includesAll(evidence, ['Release video suite', 'growth outreach', 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', '2545 passed']) ? 'pass' : 'fail', 'rc.1 evidence includes current release, video, growth, and CI artifacts', { path: 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md' } ), diff --git a/scripts/release-video-suite.js b/scripts/release-video-suite.js index d4abb8d3..d4975d5a 100644 --- a/scripts/release-video-suite.js +++ b/scripts/release-video-suite.js @@ -310,7 +310,11 @@ const REQUIRED_PUBLISH_CANDIDATES = [ minSizeMb: 2, requiresAudio: true, }, -]; +].map(candidate => ( + candidate.kind === 'video' + ? { noBlackFrames: true, ...candidate } + : candidate +)); function usage() { console.log([ @@ -556,6 +560,55 @@ function probeMedia(filePath, skipProbe) { return result; } +function detectBlackSegments(filePath, skipProbe) { + if (skipProbe) { + return { + blackFrameProbe: 'skipped', + blackSegments: null, + }; + } + + const result = { + blackFrameProbe: 'unavailable', + blackSegments: null, + }; + const probe = spawnSync('ffmpeg', [ + '-hide_banner', + '-nostats', + '-i', + filePath, + '-vf', + 'blackdetect=d=0.5:pix_th=0.10', + '-an', + '-f', + 'null', + '-', + ], { + encoding: 'utf8', + stdio: ['ignore', 'pipe', 'pipe'], + timeout: 120000, + }); + + if (probe.error) { + result.blackFrameProbe = `error: ${probe.error.message}`; + return result; + } + + if (probe.status !== 0) { + result.blackFrameProbe = `failed: ${(probe.stderr || '').trim() || `exit ${probe.status}`}`; + return result; + } + + const output = `${probe.stdout || ''}\n${probe.stderr || ''}`; + result.blackSegments = output + .split('\n') + .filter(line => line.includes('black_start')) + .length; + result.blackFrameProbe = 'ok'; + + return result; +} + function resolveSourceAssetPath(sourceRoot, fileName) { const candidates = [ path.join(sourceRoot, fileName), @@ -656,6 +709,14 @@ function validateVideoArtifact(artifact, media, skipProbe) { failures.push('audio stream missing'); } + if (artifact.noBlackFrames) { + if (media.blackFrameProbe !== 'ok') { + failures.push(`blackdetect ${media.blackFrameProbe}`); + } else if (Number.isFinite(media.blackSegments) && media.blackSegments > 0) { + failures.push(`${media.blackSegments} black frame segment(s)`); + } + } + return failures; } @@ -680,12 +741,17 @@ function inspectArtifactCollection(rootDir, artifacts, skipProbe) { }; } - const media = artifact.kind === 'video' ? probeMedia(filePath, skipProbe) : { - sizeBytes: fs.statSync(filePath).size, - sizeMb: formatBytes(fs.statSync(filePath).size), - durationSeconds: null, - probe: 'not-media', - }; + const media = artifact.kind === 'video' + ? { + ...probeMedia(filePath, skipProbe), + ...(artifact.noBlackFrames ? detectBlackSegments(filePath, skipProbe) : {}), + } + : { + sizeBytes: fs.statSync(filePath).size, + sizeMb: formatBytes(fs.statSync(filePath).size), + durationSeconds: null, + probe: 'not-media', + }; const validationFailures = validateVideoArtifact(artifact, media, skipProbe); return { @@ -860,7 +926,7 @@ function buildReport(options = {}) { 'video-publish-candidates-present', missingPublishCandidates.length === 0 ? 'pass' : 'fail', missingPublishCandidates.length === 0 - ? `${publishCandidates.length} publish-candidate MP4/caption artifacts are present and self-evaluable` + ? `${publishCandidates.length} publish-candidate MP4/caption artifacts are present, self-evaluable, and free of detected black-frame segments` : `missing or invalid publish candidates: ${missingPublishCandidates.map(candidate => { const reason = candidate.validationFailures && candidate.validationFailures.length > 0 ? ` (${candidate.validationFailures.join(', ')})` diff --git a/tests/scripts/operator-readiness-dashboard.test.js b/tests/scripts/operator-readiness-dashboard.test.js index d5599a49..6f057403 100644 --- a/tests/scripts/operator-readiness-dashboard.test.js +++ b/tests/scripts/operator-readiness-dashboard.test.js @@ -178,7 +178,7 @@ function seedRepo(rootDir, overrides = {}) { 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', - '2544 passed', + '2545 passed', 'Business baseline', '$1,728/mo', '$8,272/mo' diff --git a/tests/scripts/platform-audit.test.js b/tests/scripts/platform-audit.test.js index c61026e1..fc63ff10 100644 --- a/tests/scripts/platform-audit.test.js +++ b/tests/scripts/platform-audit.test.js @@ -68,7 +68,7 @@ function seedRepo(rootDir, overrides = {}) { 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', - '2544 passed' + '2545 passed' ].join('\n'), 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md': [ 'This dashboard is generated by `npm run operator:dashboard`', diff --git a/tests/scripts/release-video-suite.test.js b/tests/scripts/release-video-suite.test.js index a39f2f8c..25a41cdc 100644 --- a/tests/scripts/release-video-suite.test.js +++ b/tests/scripts/release-video-suite.test.js @@ -194,6 +194,13 @@ function runTests() { } })) passed++; else failed++; + if (test('publish candidate videos require visual blank-frame QA', () => { + const publishVideos = REQUIRED_PUBLISH_CANDIDATES.filter(candidate => candidate.kind === 'video'); + + assert.ok(publishVideos.length > 0); + assert.ok(publishVideos.every(candidate => candidate.noBlackFrames === true)); + })) passed++; else failed++; + if (test('missing local roots keep the release video gate blocked', () => { const rootDir = createTempDir('release-video-missing-roots-'); From 3304848beb40f57043c2314c744b5ad6265aaa96 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 09:39:10 -0400 Subject: [PATCH 38/61] chore: refresh video dashboard evidence (#1999) --- ...operator-readiness-dashboard-2026-05-19.md | 9 ++--- scripts/operator-readiness-dashboard.js | 25 ++++++++++-- .../operator-readiness-dashboard.test.js | 38 +++++++++++++++++++ 3 files changed, 63 insertions(+), 9 deletions(-) diff --git a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md index 1ec9b32d..a6dbea75 100644 --- a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md @@ -2,8 +2,8 @@ This dashboard is generated by `npm run operator:dashboard`. It is an operator snapshot, not release approval. -Generated: 2026-05-19T11:58:26.640Z -Commit: dafd447977d07d1fdc84e200a9523f9b296cb269 +Generated: 2026-05-19T13:22:19.744Z +Commit: 247750b7a6e918ac770402119c3191f512a69aa1 Status: work remaining ## Current Status @@ -38,7 +38,7 @@ Growth lanes: GitHub Sponsors and OSS partner sponsors; ECC Tools Pro subscripti | Prepare name-change, Claude plugin, and Codex plugin paths | naming-and-publication-matrix plus release-name-plugin-publication checklist plus publication-readiness | in_progress | naming matrix, release publication checklist, and plugin readiness gates exist | real tag/push, marketplace submission, and final channel choice remain approval-gated | | Prepare release notes, articles, tweets, and push notifications | docs/releases/2.0.0-rc.1 social and release-copy files | in_progress | release notes, X thread, LinkedIn draft, and URL ledger are present | final live release/npm/plugin/billing URLs and publish approval still pending | | Create a second-phase hypergrowth release command center | docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md plus May 19 evidence | current | current MRR, target MRR, gap, release claim, video lane, distribution plan, and approval boundaries are in-tree | refresh after every MRR, channel, or approval-state change before public launch | -| Produce the ECC 2.0 release video suite | docs/releases/2.0.0-rc.1/video-suite-production.md and npm run release:video-suite | in_progress | video production manifest and deterministic video-suite gate are wired for launch video, short clips, captions, timeline, and self-eval evidence | render final owner-approved MP4s, captions, platform reframes, and editable timeline before posting | +| Produce the ECC 2.0 release video suite | docs/releases/2.0.0-rc.1/video-suite-production.md and npm run release:video-suite | current | video-suite gate is ready with 15/15 source assets, 13/13 suite artifacts, 12/12 publish candidates, primary self-eval, and zero detected black-frame segments recorded in May 19 evidence | final owner approval, upload, and public video URLs remain approval-gated | | Prepare sponsor, partner, consulting, podcast, talk, and Discussion copy | docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md | in_progress | sponsor outbound, platform partner DM, consulting intro, talk/podcast pitch, GitHub Discussion announcement, CTA hooks, and do-not-send gate are drafted | replace final URLs after publication gates, then get explicit approval before outbound or personal-account posts | | Advance AgentShield enterprise iteration | AgentShield PR evidence plus enterprise roadmap | in_progress | AgentShield policy promotion `reviewItems` landed in `87aec47`; package-manager hardening drift detection landed in `28d08c7`; workflow action runtime pins were refreshed in `659f569`; npm age-gate guidance was corrected in `ee585cd`; package-manager hardening Action outputs landed in `1124535`; policy-promotion Action outputs and runtime-smoke job-summary evidence landed in `1593925`; fleet review ticket payloads and current Mini Shai-Hulud IOC breadcrumbs landed in `840952a`; ECC-Tools consumes those outputs in `8658951`, surfaces operator-readable status/pack/count/digest telemetry in `16c537f`, and renders hosted promotion judge audit traces in `05d4e82`; all are mirrored in the GA roadmap | deepen live operator approval/readback after Marketplace/payment gates | | Advance ECC Tools native payments and AI-native harness-agnostic app | ECC Tools PR evidence, billing gate, hosted analysis lanes | in_progress | billing announcement gate, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler OAuth readback, target-account billing readback, provenance-aware Marketplace billing-state gates, sanitized Marketplace plan/action provenance counts, hosted team-learning feedback controls, and ECC-Tools Dependabot alert remediation are mirrored in the GA roadmap | create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure the target account and INTERNAL_API_SECRET, then rerun target readback and the live announcement gate | @@ -51,7 +51,6 @@ Growth lanes: GitHub Sponsors and OSS partner sponsors; ECC Tools Pro subscripti - `naming-and-plugin-publication`: real tag/push, marketplace submission, and final channel choice remain approval-gated - `release-notes-and-notifications`: final live release/npm/plugin/billing URLs and publish approval still pending -- `release-video-suite`: render final owner-approved MP4s, captions, platform reframes, and editable timeline before posting - `partner-sponsor-talks-pack`: replace final URLs after publication gates, then get explicit approval before outbound or personal-account posts - `agentshield-enterprise-iteration`: deepen live operator approval/readback after Marketplace/payment gates - `ecc-tools-next-level`: create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure the target account and INTERNAL_API_SECRET, then rerun target readback and the live announcement gate @@ -59,7 +58,7 @@ Growth lanes: GitHub Sponsors and OSS partner sponsors; ECC Tools Pro subscripti ## Next Work Order 1. Regenerate this dashboard from the final release commit before publication evidence is recorded. -2. Render the owner-approved primary launch video, short clips, captions, reframes, and editable timeline from the video-suite production manifest. +2. Review the owner-approved primary launch video candidates, choose the final cuts, upload after approval, and attach public video URLs to the release pack. 3. Replace final release, npm, plugin, billing, and video URLs in the partner/sponsor/talk pack, then get explicit approval before outbound. 4. Repeat ITO-57 Linear/project status sync after the next significant merge batch or advisory-source refresh. 5. Create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure the target account and INTERNAL_API_SECRET, then rerun target readback and the live announcement gate before publishing native-payments copy. diff --git a/scripts/operator-readiness-dashboard.js b/scripts/operator-readiness-dashboard.js index b943b08e..1e5483d5 100644 --- a/scripts/operator-readiness-dashboard.js +++ b/scripts/operator-readiness-dashboard.js @@ -641,6 +641,15 @@ function buildRequirements(rootDir, platformReport) { 'video-source-assets-present', 'video-release-artifacts-present', ]); + const releaseVideoPublishCandidatesReady = releaseVideoSuiteReady + && includesAll(publicationEvidenceMay19, [ + 'Ready true', + '15/15 source assets present', + '13/13 render, timeline, caption, EDL, and segment artifacts present', + '12/12 publish-candidate outputs present', + 'zero detected black-frame segments', + 'primary rough render self-eval passed', + ]); const partnerSponsorTalksReady = includesAll(partnerSponsorTalksPack, [ 'Sponsor Outbound', 'Platform Partner DM', @@ -802,11 +811,15 @@ function buildRequirements(rootDir, platformReport) { 'release-video-suite', 'Produce the ECC 2.0 release video suite', 'docs/releases/2.0.0-rc.1/video-suite-production.md and npm run release:video-suite', - releaseVideoSuiteReady ? 'in_progress' : 'not_complete', - releaseVideoSuiteReady + releaseVideoPublishCandidatesReady ? 'current' : releaseVideoSuiteReady ? 'in_progress' : 'not_complete', + releaseVideoPublishCandidatesReady + ? 'video-suite gate is ready with 15/15 source assets, 13/13 suite artifacts, 12/12 publish candidates, primary self-eval, and zero detected black-frame segments recorded in May 19 evidence' + : releaseVideoSuiteReady ? 'video production manifest and deterministic video-suite gate are wired for launch video, short clips, captions, timeline, and self-eval evidence' : 'video production manifest or release:video-suite gate is incomplete', - releaseVideoSuiteReady + releaseVideoPublishCandidatesReady + ? 'final owner approval, upload, and public video URLs remain approval-gated' + : releaseVideoSuiteReady ? 'render final owner-approved MP4s, captions, platform reframes, and editable timeline before posting' : 'wire release:video-suite and production manifest before final content work' ), @@ -911,6 +924,10 @@ function buildReport(options) { })); const head = runCommand('git', ['rev-parse', 'HEAD'], { cwd: rootDir }); const growth = buildGrowthSummary(rootDir); + const releaseVideoRequirement = requirements.find(item => item.id === 'release-video-suite'); + const releaseVideoWorkOrder = releaseVideoRequirement && releaseVideoRequirement.status === 'current' + ? 'Review the owner-approved primary launch video candidates, choose the final cuts, upload after approval, and attach public video URLs to the release pack.' + : 'Render the owner-approved primary launch video, short clips, captions, reframes, and editable timeline from the video-suite production manifest.'; return { schema_version: SCHEMA_VERSION, @@ -937,7 +954,7 @@ function buildReport(options) { top_actions: topActions, next_work_order: [ 'Regenerate this dashboard from the final release commit before publication evidence is recorded.', - 'Render the owner-approved primary launch video, short clips, captions, reframes, and editable timeline from the video-suite production manifest.', + releaseVideoWorkOrder, 'Replace final release, npm, plugin, billing, and video URLs in the partner/sponsor/talk pack, then get explicit approval before outbound.', 'Repeat ITO-57 Linear/project status sync after the next significant merge batch or advisory-source refresh.', 'Create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure the target account and INTERNAL_API_SECRET, then rerun target readback and the live announcement gate before publishing native-payments copy.', diff --git a/tests/scripts/operator-readiness-dashboard.test.js b/tests/scripts/operator-readiness-dashboard.test.js index 6f057403..7c40091f 100644 --- a/tests/scripts/operator-readiness-dashboard.test.js +++ b/tests/scripts/operator-readiness-dashboard.test.js @@ -413,6 +413,44 @@ function runTests() { } })) passed++; else failed++; + if (test('release video suite moves current when publish-candidate evidence is recorded', () => { + const rootDir = createTempDir('operator-dashboard-video-current-'); + + try { + seedRepo(rootDir, { + 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md': [ + 'Release video suite', + 'growth outreach', + 'Operator dashboard', + 'GitGuardian', + 'macOS/Ubuntu/Windows test matrix', + '2545 passed', + 'Business baseline', + '$1,728/mo', + '$8,272/mo', + 'Ready true', + '15/15 source assets present', + '13/13 render, timeline, caption, EDL, and segment artifacts present', + '12/12 publish-candidate outputs present with zero detected black-frame segments', + 'primary rough render self-eval passed' + ].join('\n') + }); + + const report = buildSeededReport(rootDir); + const releaseVideo = report.requirements.find(item => item.id === 'release-video-suite'); + + assert.strictEqual(releaseVideo.status, 'current'); + assert.ok(releaseVideo.evidence.includes('15/15 source assets')); + assert.ok(releaseVideo.evidence.includes('12/12 publish candidates')); + assert.ok(releaseVideo.evidence.includes('zero detected black-frame segments')); + assert.strictEqual(releaseVideo.gap, 'final owner approval, upload, and public video URLs remain approval-gated'); + assert.ok(!report.top_actions.some(item => item.id === 'release-video-suite')); + assert.ok(report.next_work_order.some(item => item.includes('Review the owner-approved primary launch video candidates'))); + } finally { + cleanup(rootDir); + } + })) passed++; else failed++; + if (test('Linear progress stays in progress until live sync evidence is mirrored', () => { const rootDir = createTempDir('operator-dashboard-linear-progress-'); From e7a7b2aaa33c0657cad9db3fa2ced0e636cd0f8c Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 09:58:53 -0400 Subject: [PATCH 39/61] chore: refresh suite count evidence (#2000) --- .../2.0.0-rc.1/preview-pack-manifest.md | 4 +-- .../publication-evidence-2026-05-19.md | 19 +++++++------ .../2.0.0-rc.1/publication-readiness.md | 10 +++---- ...cc-2-hypergrowth-release-command-center.md | 11 ++++---- scripts/platform-audit.js | 2 +- tests/docs/ecc2-release-surface.test.js | 2 +- .../operator-readiness-dashboard.test.js | 4 +-- tests/scripts/platform-audit.test.js | 28 ++++++++++++++++++- tests/scripts/release-video-suite.test.js | 2 +- 9 files changed, 56 insertions(+), 26 deletions(-) diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index 0763f3ed..033c0808 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -25,10 +25,10 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-16.md` | Current May 16/17 queue cleanup, recsys skill merge, GateGuard triage, PR #1947 supply-chain protection, AgentShield #87 plugin-cache confidence evidence, AgentShield #88 evidence-pack inspect/readback, AgentShield #89 evidence-pack fleet routing, AgentShield #90 fleet review items, AgentShield #91 policy export, AgentShield #92 policy promotion, ECC-Tools #76 fleet-summary consumption, ECC-Tools #77 hosted finding evidence paths, ECC-Tools #78 harness policy-route linking, dashboard refresh, and combined Node/Rust/release-surface gate evidence through the May 16 mirror | Must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` | May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack protection recheck, npm audit/signature checks, legacy and Linear progress routing, deterministic preview-pack smoke, operator dashboard refresh, Linear sync, and GitHub CI evidence for `27dc2918` | Superseded by the May 18 evidence snapshot; repeat from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, supply-chain recheck, AgentShield evidence mirror, Linear sync, current-head CI/security scan success for `4470e2e6`, and ITO-46 naming/plugin publication closure | Superseded by the May 19 ECC identity, video, and growth evidence snapshot | -| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, May 19 operator dashboard, preview-pack smoke digest `bc2bf157616e`, 2544-test local suite, and PR #1993 CI success | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | +| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, May 19 operator dashboard, preview-pack smoke digest `bc2bf157616e`, 2547-test local suite, PR #1998 visual QA CI success, and PR #1999 dashboard evidence CI success | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 19 generated dashboard | -| `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and adds the current `$1,728/mo` to `$10,000/mo` hypergrowth, release-video, and outbound-pack operating lanes | +| `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and adds the current `$1,728/mo` to `$10,000/mo` hypergrowth, video owner-approval, and outbound-pack operating lanes | | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md` | Live URL and approval-gated URL ledger for release copy | Must be regenerated from the final release commit before public announcements | | `docs/releases/2.0.0-rc.1/video-suite-production.md` | Release video production manifest | Gates local media inventory, rough primary render, captions, timeline, self-eval, and no-private-path publication rules | | `docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md` | Partner, sponsor, consulting, conference, podcast, and discussion copy | Must stay approval-gated and avoid live billing, release, package, or plugin claims without evidence | diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md index c2519037..8018c474 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -8,9 +8,9 @@ social announcement. | Field | Evidence | | --- | --- | -| Upstream main | `855e8c8336e1c18523cbb31cb29f4ce96d7518a7` | +| Upstream main | `3304848beb40f57043c2314c744b5ad6265aaa96` | | Git remote | `https://github.com/affaan-m/ECC.git` | -| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, and PR #1997 publish-candidate gate | +| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, and PR #1999 video dashboard evidence refresh | | Local status caveat | `git status --short --branch` was clean after pulling `origin/main`; generated evidence files are committed after the source snapshot they describe | The release operator must repeat all publish-facing checks from the exact final @@ -46,6 +46,8 @@ Tracked repositories in the platform audit were: | PR #1995 | Merged the May 19 operator dashboard refresh with the `$1,728/mo` MRR baseline, `$10,000/mo` target, and release/video/outbound top actions | | PR #1996 | Merged the primary launch render self-eval gate for duration, size, resolution, video stream, and audio stream checks | | PR #1997 | Merged the publish-candidate gate for the primary launch MP4/captions plus five short clips in wide and vertical formats | +| PR #1998 | Merged the release video visual QA gate for publish candidates and black-frame segment detection | +| PR #1999 | Merged the operator dashboard refresh that moved the release video suite to current once publish-candidate evidence was recorded | ## Release And Growth Evidence @@ -53,12 +55,13 @@ Tracked repositories in the platform audit were: | --- | --- | --- | | Release-surface tests | `node tests/docs/ecc2-release-surface.test.js` | 25 passed, 0 failed | | Preview-pack smoke | `npm run preview-pack:smoke -- --format json` | Ready true; digest `bc2bf157616e`; 30 required artifacts; 5 passed, 0 failed | -| Operator dashboard | `npm run operator:dashboard -- --markdown --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Generated May 19 dashboard with platform audit ready true, 0 tracked PRs, 0 tracked issues, 0 discussion gaps, `$1,728/mo` current MRR, `$10,000/mo` target MRR, and top actions for plugin publication, notifications, release video, outbound approval, AgentShield, and ECC Tools billing | +| Operator dashboard | `npm run operator:dashboard -- --markdown --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Generated May 19 dashboard with platform audit ready true, 0 tracked PRs, 0 tracked issues, 0 discussion gaps, `$1,728/mo` current MRR, `$10,000/mo` target MRR, the release video suite marked current, and top actions for plugin publication, notifications, outbound approval, AgentShield, and ECC Tools billing | | Release video suite | `npm run release:video-suite -- --format json --summary` with `ECC_VIDEO_SOURCE_ROOT` and `ECC_VIDEO_RELEASE_SUITE_ROOT` | Ready true; 15/15 source assets present; 13/13 render, timeline, caption, EDL, and segment artifacts present; 12/12 publish-candidate outputs present with zero detected black-frame segments; primary rough render self-eval passed at 144.759 seconds, 1920x1080, 1 audio stream, and 106.78 MB | -| Full local suite | `node tests/run-all.js` | 2545 passed, 0 failed | -| PR #1997 CI | GitHub Actions run `26097832795` | Completed successfully for `855e8c8336e1c18523cbb31cb29f4ce96d7518a7`; all reported checks passed, including lint, validation, security scan, coverage, GitGuardian, CodeRabbit, Cubic, and the macOS/Ubuntu/Windows test matrix | +| Full local suite | `node tests/run-all.js` | 2547 passed, 0 failed | +| PR #1998 CI | GitHub Actions run `26099020341` | Completed successfully for `d500de1e9f11c0446b6a1349bd98b522d31f9125`; all reported checks passed, including lint, validation, security scan, coverage, GitGuardian, CodeRabbit, Cubic, and the macOS/Ubuntu/Windows test matrix | +| PR #1999 CI | GitHub Actions run `26100148726` | Completed successfully for `90584b6d5e5814bc2ad9a4cd651bebd043de989d`; lint, validation, security scan, coverage, GitGuardian, CodeRabbit, and the macOS/Ubuntu/Windows test matrix passed; Cubic completed neutral and did not block merge | | Public-path sanitization | `node scripts/ci/validate-no-personal-paths.js` through local suite and CI | Passed | -| Markdown and whitespace | `markdownlint` focused release docs plus `git diff --check` before PR #1993 | Passed | +| Markdown and whitespace | `markdownlint` focused release docs plus `git diff --check` before PR #1999 | Passed | ## Product And Positioning Evidence @@ -95,8 +98,8 @@ Tracked repositories in the platform audit were: The tracked public PR queue, issue queue, discussion queue, canonical ECC identity, release video suite, preview pack, and growth outreach packet are current on May 19, 2026 for `main` through -`855e8c8336e1c18523cbb31cb29f4ce96d7518a7`, with the visual video QA gate -staged for the next merge. +`3304848beb40f57043c2314c744b5ad6265aaa96`. The remaining video work is +owner approval, upload, and public URL attachment, not render or QA production. This improves publication readiness but does not replace the approval-gated release, package, plugin, billing, Discord, and announcement steps in diff --git a/docs/releases/2.0.0-rc.1/publication-readiness.md b/docs/releases/2.0.0-rc.1/publication-readiness.md index 558fd2e0..f88fb764 100644 --- a/docs/releases/2.0.0-rc.1/publication-readiness.md +++ b/docs/releases/2.0.0-rc.1/publication-readiness.md @@ -98,22 +98,22 @@ Record the exact commit SHA and command output before any publication action: | Evidence | Command | Required result | Recorded output | | --- | --- | --- | --- | -| Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | `7a0645ed`: `## main...origin/main`; repeat from the exact final publication commit before release | +| Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | `3304848b`: `## main...origin/main`; repeat from the exact final publication commit before release | | Preview-pack smoke | `npm run preview-pack:smoke` | Preview pack artifacts, Hermes boundary, final verification command list, and publication blockers pass | `publication-evidence-2026-05-19.md`: ready yes, digest `bc2bf157616e`, 30 artifacts, 5 passed, 0 failed; repeat in the final strict clean-checkout release pass | | Harness audit | `npm run harness:audit -- --format json` | 70/70 passing | `99e01ded`: 70/70, 0 top actions | | Adapter scorecard | `npm run harness:adapters -- --check` | PASS | `99e01ded`: PASS, 11 adapters | | Observability readiness | `npm run observability:ready` | 21/21 passing | `publication-evidence-2026-05-18.md`: 21/21, ready yes | | Release safety gate | `npm run observability:ready -- --format json` | Release Safety category passing with publication readiness, supply-chain, workflow security, package surface, and release-surface evidence | May 18 evidence keeps release safety passing; repeat the JSON gate from the exact final release commit | | Supply-chain verification | `npm audit --json`; `npm audit signatures`; `cd ecc2 && cargo audit -q`; Dependabot alerts; GitGuardian Security Checks | 0 vulnerabilities/alerts, registry signatures verified, GitGuardian clean | `publication-evidence-2026-05-19.md` plus CI `26093792219`: GitGuardian and security scan passed; prior May 18 npm registry signatures and IOC scans remain the latest detailed supply-chain evidence | -| Root suite | `node tests/run-all.js` | 0 failures | `7a0645ed`: local `node tests/run-all.js` passed 2544/2544; PR #1993 CI `26093792219` passed the full OS/runtime/package-manager matrix for `d9ac22c6` | +| Root suite | `node tests/run-all.js` | 0 failures | `3304848b`: local `node tests/run-all.js` passed 2547/2547; PR #1999 CI `26100148726` passed the full OS/runtime/package-manager matrix for `90584b6d` | | Markdown lint | `npx markdownlint-cli '**/*.md' --ignore node_modules` | 0 failures | CI `26093792219`: markdownlint passed on the growth-pack PR; rerun after any release-copy edits | | Package surface | `node tests/scripts/npm-publish-surface.test.js` | 0 failures; no Python bytecode in npm tarball | `2/2` passed in May 12 evidence pass | | Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | May 19 evidence refresh: 25/25 passed after adding the video suite and partner/sponsor/talk gates | | Optional Rust surface | `cd ecc2 && cargo test` | 0 failures or explicit deferral | `publication-evidence-2026-05-16.md`: 462/462 passed, existing warnings only | -| Queue baseline | `node scripts/platform-audit.js --json` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | `7a0645ed`: platform audit ready, 0 open PRs, 0 open issues, 0 conflicting PRs, and 0 blocking dirty files | -| Discussion baseline | `node scripts/platform-audit.js --json` and `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | `7a0645ed`: platform audit sampled 58 trunk discussions, 0 needing maintainer touch, 0 answerable discussions missing accepted answer; `docs/architecture/discussion-response-playbook.md` records response templates and security escalation rules | +| Queue baseline | `node scripts/platform-audit.js --json` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | `3304848b`: platform audit ready, 0 open PRs, 0 open issues, 0 conflicting PRs, and 0 blocking dirty files | +| Discussion baseline | `node scripts/platform-audit.js --json` and `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | `3304848b`: platform audit sampled 58 trunk discussions, 0 needing maintainer touch, 0 answerable discussions missing accepted answer; `docs/architecture/discussion-response-playbook.md` records response templates and security escalation rules | | Linear roadmap | Linear project and issue readback | Detailed roadmap exists with release, security, AgentShield, ECC Tools, legacy, and observability lanes | May 18 Linear comments include ITO-57 `3fe5b2b7-c4fe-401c-a317-b40d72119cb3` and ITO-44 `fb4a4f33-6c2d-421a-bbdb-63cfad3e3ee4`; earlier evidence records the project and 16 issue lanes | -| Operator readiness dashboard | `npm run operator:dashboard -- --json` | Current queue state mapped to macro-goal deliverables and incomplete gaps | `4470e2e6`: regenerated May 18 dashboard from current main; platform audit ready true, 0 open PRs, 0 open issues, 0 discussion gaps, 0 dirty files, and publication gates still approval-gated | +| Operator readiness dashboard | `npm run operator:dashboard -- --json` | Current queue state mapped to macro-goal deliverables and incomplete gaps | `3304848b`: regenerated May 19 dashboard from current main; platform audit ready true, 0 open PRs, 0 open issues, 0 discussion gaps, 0 dirty files, release video suite current, and publication gates still approval-gated | | Release URL ledger | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md` plus placeholder-marker scan | Live links and approval-gated links are separated before announcement copy is posted | Ledger records public repo/docs/npm/OpenAI Codex documentation URLs and blocks GitHub release/npm/plugin/billing/social URLs until approval-gated checks pass | | Release name and plugin publication checklist | `docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md` | Name/package/plugin values are frozen, final-release commands are listed, and Claude/Codex publication paths cite current official docs | Checklist keeps `ECC`, `ecc-universal`, and plugin slug `ecc` for rc.1; no npm rename, npm publish, plugin tag, official listing, billing claim, or announcement before final evidence | diff --git a/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md b/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md index 09657477..508098e2 100644 --- a/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md +++ b/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md @@ -32,7 +32,7 @@ The release copy should show the 2.0 product shape directly. | MRR | `$1,728/mo` | `$10,000/mo` | `$8,272/mo` | | Sponsor motion | Active GitHub Sponsors plus open inbound | Repeatable sponsor close loop | Approval-gated outbound | | Consulting motion | Open, non-primary | Partner-ready packages | Public proof, talks, and intake | -| Content motion | Raw ECC 2 media exists | Weekly launch clips and founder proof | Final video suite | +| Content motion | Release video publish candidates ready | Weekly launch clips and founder proof | Owner approval, upload, and public URLs | | Community motion | Discord exists | Useful coding/operator community | Invite, channels, pins, moderation | MRR growth should come from four lanes at once: @@ -50,7 +50,7 @@ MRR growth should come from four lanes at once: | Package and plugin publication | `ecc-universal@2.0.0-rc.1` dry-runs clean, npm `next` is approved, Claude plugin tag dry-runs, Codex repo marketplace smoke passes, OpenCode build passes | Refresh publication evidence from final commit | | Product proof | Quickstart, cross-harness architecture, demo prompts, `ecc2/` alpha boundary, AgentShield safety proof, and hosted ECC Tools links are consistent | Keep proof surfaces concrete | | Revenue proof | Sponsor tiers, Pro pricing, consulting CTA, partner CTA, and billing-readback language are current | Do not announce billing claims before live readback | -| Content proof | Launch video, short-form clips, screenshots, release notes, GitHub Discussion, X, LinkedIn, and longform post are aligned | Validate `video-suite-production.md` and the local render suite | +| Content proof | Launch video, short-form clips, screenshots, release notes, GitHub Discussion, X, LinkedIn, and longform post are aligned | Pick final video cuts, upload after approval, and attach public URLs | | Community proof | Discord invite, rules, channels, onboarding, and sponsor/community routing are ready | Needs invite/token decision before public links | ## Video Suite @@ -128,11 +128,12 @@ Avoid: 1. Land the public repo identity fixes. 2. Refresh package, plugin, workflow, release, and launch-copy URLs. 3. Record final publication evidence from the exact release commit. -4. Produce the video suite manifest and transcripts from existing raw material; - gate it with `npm run release:video-suite -- --format json`. +4. Keep the video suite manifest, transcripts, publish candidates, and visual QA + current with `npm run release:video-suite -- --format json`. 5. Browser-capture the README, ECC Tools app, install flow, and relevant proof surfaces for b-roll. -6. Render the primary launch video plus five short clips. +6. Choose the owner-approved primary launch video and five short clips, then + upload and attach final public URLs. 7. Finalize GitHub release, X thread, LinkedIn post, Discussion announcement, sponsor email copy, consulting intro, partner DM, and podcast/talk pitch. 8. Publish only after npm, plugin, release URL, and billing-readback gates are diff --git a/scripts/platform-audit.js b/scripts/platform-audit.js index 0125a5d8..f39cc748 100644 --- a/scripts/platform-audit.js +++ b/scripts/platform-audit.js @@ -472,7 +472,7 @@ function buildLocalEvidenceChecks(rootDir) { ), buildCheck( 'release-evidence-current', - includesAll(evidence, ['Release video suite', 'growth outreach', 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', '2545 passed']) ? 'pass' : 'fail', + includesAll(evidence, ['Release video suite', 'growth outreach', 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', '2547 passed']) ? 'pass' : 'fail', 'rc.1 evidence includes current release, video, growth, and CI artifacts', { path: 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md' } ), diff --git a/tests/docs/ecc2-release-surface.test.js b/tests/docs/ecc2-release-surface.test.js index 1fb55df6..c36bb649 100644 --- a/tests/docs/ecc2-release-surface.test.js +++ b/tests/docs/ecc2-release-surface.test.js @@ -269,7 +269,7 @@ test('release video suite manifest gates the content launch lane', () => { } assert.ok(launchChecklist.includes('npm run release:video-suite -- --format json')); - assert.ok(hypergrowth.includes('Validate `video-suite-production.md`')); + assert.ok(hypergrowth.includes('Pick final video cuts, upload after approval, and attach public URLs')); assert.strictEqual(packageJson.scripts['release:video-suite'], 'node scripts/release-video-suite.js'); assert.ok(packageJson.files.includes('scripts/release-video-suite.js')); }); diff --git a/tests/scripts/operator-readiness-dashboard.test.js b/tests/scripts/operator-readiness-dashboard.test.js index 7c40091f..3c816cb0 100644 --- a/tests/scripts/operator-readiness-dashboard.test.js +++ b/tests/scripts/operator-readiness-dashboard.test.js @@ -178,7 +178,7 @@ function seedRepo(rootDir, overrides = {}) { 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', - '2545 passed', + '2547 passed', 'Business baseline', '$1,728/mo', '$8,272/mo' @@ -424,7 +424,7 @@ function runTests() { 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', - '2545 passed', + '2547 passed', 'Business baseline', '$1,728/mo', '$8,272/mo', diff --git a/tests/scripts/platform-audit.test.js b/tests/scripts/platform-audit.test.js index fc63ff10..16dcae40 100644 --- a/tests/scripts/platform-audit.test.js +++ b/tests/scripts/platform-audit.test.js @@ -68,7 +68,7 @@ function seedRepo(rootDir, overrides = {}) { 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', - '2545 passed' + '2547 passed' ].join('\n'), 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md': [ 'This dashboard is generated by `npm run operator:dashboard`', @@ -220,12 +220,38 @@ function runTests() { assert.ok(parsed.checks.some(check => check.id === 'supply-chain-runbook' && check.status === 'pass')); assert.ok(parsed.checks.some(check => check.id === 'operator-dashboard-command' && check.status === 'pass')); assert.ok(parsed.checks.some(check => check.id === 'operator-readiness-dashboard' && check.status === 'pass')); + assert.ok(parsed.checks.some(check => check.id === 'release-evidence-current' && check.status === 'pass')); assert.deepStrictEqual(parsed.top_actions, []); } finally { cleanup(projectRoot); } })) passed++; else failed++; + if (test('release evidence gate rejects stale root suite counts', () => { + const projectRoot = createTempDir('platform-audit-stale-release-evidence-'); + + try { + seedRepo(projectRoot, { + 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md': [ + 'Release video suite', + 'growth outreach', + 'Operator dashboard', + 'GitGuardian', + 'macOS/Ubuntu/Windows test matrix', + '2546 passed' + ].join('\n') + }); + + const parsed = JSON.parse(run(['--format=json', `--root=${projectRoot}`, '--skip-github'], { cwd: projectRoot })); + const releaseEvidence = parsed.checks.find(check => check.id === 'release-evidence-current'); + + assert.strictEqual(releaseEvidence.status, 'fail'); + assert.ok(parsed.top_actions.some(action => action.id === 'release-evidence-current')); + } finally { + cleanup(projectRoot); + } + })) passed++; else failed++; + if (test('markdown output can be written as an operator artifact', () => { const projectRoot = createTempDir('platform-audit-markdown-'); const outputPath = path.join(projectRoot, 'artifacts', 'platform-audit.md'); diff --git a/tests/scripts/release-video-suite.test.js b/tests/scripts/release-video-suite.test.js index 25a41cdc..cc114399 100644 --- a/tests/scripts/release-video-suite.test.js +++ b/tests/scripts/release-video-suite.test.js @@ -54,7 +54,7 @@ function seedRepo(rootDir, overrides = {}) { ].join('\n'), 'docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md': [ 'Keep raw absolute paths out of public docs', - 'Validate `video-suite-production.md`', + 'Pick final video cuts, upload after approval, and attach public URLs', ].join('\n'), 'docs/releases/2.0.0-rc.1/preview-pack-manifest.md': 'video-suite-production.md', 'docs/releases/2.0.0-rc.1/launch-checklist.md': 'release video suite', From 8148340ad14eb32c971346f0cb4cb9431ec0f5de Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 10:18:22 -0400 Subject: [PATCH 40/61] chore: add release owner approval packet (#2001) --- .../owner-approval-packet-2026-05-19.md | 95 +++++++++++++++++++ .../2.0.0-rc.1/preview-pack-manifest.md | 3 +- .../publication-evidence-2026-05-19.md | 15 +-- .../2.0.0-rc.1/publication-readiness.md | 9 +- ...cc-2-hypergrowth-release-command-center.md | 3 + scripts/platform-audit.js | 2 +- scripts/preview-pack-smoke.js | 1 + tests/docs/ecc2-release-surface.test.js | 47 +++++++++ .../operator-readiness-dashboard.test.js | 4 +- tests/scripts/platform-audit.test.js | 2 +- 10 files changed, 167 insertions(+), 14 deletions(-) create mode 100644 docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md diff --git a/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md b/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md new file mode 100644 index 00000000..2b949b5a --- /dev/null +++ b/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md @@ -0,0 +1,95 @@ +# ECC v2.0.0-rc.1 Owner Approval Packet + +Snapshot date: 2026-05-19. + +This packet is the final human decision sheet for the rc.1 public launch. It +does not publish anything by itself. Use it to approve, defer, or block each +release action after the final evidence commands are rerun from the intended +release commit. + +Source commit for the clean evidence baseline this packet extends: +`e7a7b2aaa33c0657cad9db3fa2ced0e636cd0f8c`. + +## Current Evidence + +| Evidence | Current recorded state | Repeat before approval | +| --- | --- | --- | +| Platform audit | ready true, 0 open PRs, 0 open issues, 0 discussion gaps, 0 dirty files | yes | +| Preview pack smoke | ready true, digest `790430aef4a8`, 5/5 checks | yes | +| Video suite | ready true, 15/15 source assets, 13/13 suite artifacts, 12/12 publish candidates | yes | +| Release surface tests | 26/26 passed after this packet was added | yes | +| Full local suite | 2548/2548 passed after this packet was added | yes | +| GitHub CI | PR #1998, PR #1999, and PR #2000 merged after green required checks | verify current head | + +## Decision Register + +| Decision | Approve / defer / block | Evidence required first | Notes | +| --- | --- | --- | --- | +| GitHub prerelease | defer | final clean branch, URL ledger, release notes, attached video or video link | Approve only after final release notes contain live package/plugin/video URLs or explicitly marked blocked URLs. | +| npm `next` publish | defer | `npm pack --dry-run`, `npm publish --tag next --dry-run`, registry dist-tag readback plan | Keep `ecc-universal@2.0.0-rc.1` on `next`; do not move `latest` during rc.1. | +| Claude plugin tag | defer | `claude plugin validate .claude-plugin/plugin.json`, `claude plugin tag .claude-plugin --dry-run` | Create and push the real tag only after release approval. | +| Codex repo marketplace | defer | temp-home marketplace add smoke and current official Plugin Directory status | Claim repo-marketplace distribution only; do not claim official Plugin Directory listing without listing evidence. | +| ECC Tools billing language | defer | live readiness readback for the target account and billing/product state | Do not announce native payments or Marketplace-managed Pro until the gate is live. | +| Video upload | defer | owner selects primary launch cut plus short clips, self-eval stays clean | Upload only approved cuts; keep editable timeline/project output preserved. | +| X, LinkedIn, GitHub Discussion, longform | defer | live release, npm, plugin, video, and billing URL ledger updates | Personal-account posts and outbound copy need explicit approval. | +| Sponsor, partner, consulting, conference, podcast outreach | defer | final public URLs plus owner-approved outbound copy | Do not send drafts until the owner approves the exact batch. | + +## Final URL Fill-In + +Update these surfaces after the approved publication actions finish: + +| Surface | Final value source | Update targets | +| --- | --- | --- | +| GitHub prerelease URL | `gh release view v2.0.0-rc.1 --repo affaan-m/ECC --json url` | release notes, URL ledger, social copy | +| npm rc package URL | `npm view ecc-universal@2.0.0-rc.1 version dist-tags --json` | URL ledger, quickstart, release notes | +| Claude plugin tag URL | pushed `ecc--v2.0.0-rc.1` tag or marketplace readback | URL ledger, plugin docs, release notes | +| Codex repo-marketplace evidence | temp-home `codex plugin marketplace add ` readback | URL ledger, publication readiness | +| Primary launch video URL | uploaded owner-approved primary launch video | GitHub release, X, LinkedIn, longform | +| Short clip URLs | uploaded approved clips | X thread, LinkedIn, partner/sponsor/talk pack | +| ECC Tools billing/readiness URL | live readiness readback or explicit blocked status | sponsor copy, Pro copy, release notes | + +## Final Evidence Commands + +Run these from the exact release commit before approving publication: + +```bash +git status --short --branch +node scripts/platform-audit.js --json +npm run preview-pack:smoke -- --format json +npm run release:video-suite -- --format json +npm run harness:adapters -- --check +npm run harness:audit -- --format json +npm run observability:ready +npm run security:ioc-scan +npm audit --audit-level=moderate +npm audit signatures +node tests/docs/ecc2-release-surface.test.js +node tests/run-all.js +cd ecc2 && cargo test +``` + +## Approval Text + +Use short, explicit approvals. Example: + +```text +Approved for rc.1 GitHub prerelease, npm next publish, Claude plugin tag, and +release announcement after the final evidence commands pass from commit . +Video uploads approved for and . +Outbound sponsor, partner, consulting, conference, and podcast messages remain +blocked until I approve the exact batch. +``` + +## Do Not Approve If + +- The final branch is dirty or no longer matches the intended release commit. +- Any required evidence command fails or is skipped without a written deferral. +- The release copy claims live billing, plugin marketplace propagation, npm + `next`, or official Codex Plugin Directory listing before readback exists. +- Announcement copy contains stale URLs, private paths, or unresolved live-link + decisions. +- The selected video cut has black frames, missing audio, stale URLs, weak + product proof, or unreviewed captions. +- The outbound batch has not been reviewed exactly as it will be sent. + +No outbound email, personal-account post, package publish, plugin tag, or billing announcement is authorized by this packet alone. diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index 033c0808..c0ea3c7a 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -25,10 +25,11 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-16.md` | Current May 16/17 queue cleanup, recsys skill merge, GateGuard triage, PR #1947 supply-chain protection, AgentShield #87 plugin-cache confidence evidence, AgentShield #88 evidence-pack inspect/readback, AgentShield #89 evidence-pack fleet routing, AgentShield #90 fleet review items, AgentShield #91 policy export, AgentShield #92 policy promotion, ECC-Tools #76 fleet-summary consumption, ECC-Tools #77 hosted finding evidence paths, ECC-Tools #78 harness policy-route linking, dashboard refresh, and combined Node/Rust/release-surface gate evidence through the May 16 mirror | Must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` | May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack protection recheck, npm audit/signature checks, legacy and Linear progress routing, deterministic preview-pack smoke, operator dashboard refresh, Linear sync, and GitHub CI evidence for `27dc2918` | Superseded by the May 18 evidence snapshot; repeat from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, supply-chain recheck, AgentShield evidence mirror, Linear sync, current-head CI/security scan success for `4470e2e6`, and ITO-46 naming/plugin publication closure | Superseded by the May 19 ECC identity, video, and growth evidence snapshot | -| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, May 19 operator dashboard, preview-pack smoke digest `bc2bf157616e`, 2547-test local suite, PR #1998 visual QA CI success, and PR #1999 dashboard evidence CI success | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | +| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, May 19 operator dashboard, preview-pack smoke digest `790430aef4a8`, 2548-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, and PR #2000 suite-count evidence success | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 19 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and adds the current `$1,728/mo` to `$10,000/mo` hypergrowth, video owner-approval, and outbound-pack operating lanes | +| `docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md` | Final human decision sheet for release, package, plugin, video, billing, social, and outbound approvals | Must be reviewed by the owner before any publication or outbound action | | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md` | Live URL and approval-gated URL ledger for release copy | Must be regenerated from the final release commit before public announcements | | `docs/releases/2.0.0-rc.1/video-suite-production.md` | Release video production manifest | Gates local media inventory, rough primary render, captions, timeline, self-eval, and no-private-path publication rules | | `docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md` | Partner, sponsor, consulting, conference, podcast, and discussion copy | Must stay approval-gated and avoid live billing, release, package, or plugin claims without evidence | diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md index 8018c474..cbecf7cf 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -8,9 +8,9 @@ social announcement. | Field | Evidence | | --- | --- | -| Upstream main | `3304848beb40f57043c2314c744b5ad6265aaa96` | +| Upstream main | `e7a7b2aaa33c0657cad9db3fa2ced0e636cd0f8c` | | Git remote | `https://github.com/affaan-m/ECC.git` | -| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, and PR #1999 video dashboard evidence refresh | +| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, and the owner approval packet addition | | Local status caveat | `git status --short --branch` was clean after pulling `origin/main`; generated evidence files are committed after the source snapshot they describe | The release operator must repeat all publish-facing checks from the exact final @@ -48,16 +48,18 @@ Tracked repositories in the platform audit were: | PR #1997 | Merged the publish-candidate gate for the primary launch MP4/captions plus five short clips in wide and vertical formats | | PR #1998 | Merged the release video visual QA gate for publish candidates and black-frame segment detection | | PR #1999 | Merged the operator dashboard refresh that moved the release video suite to current once publish-candidate evidence was recorded | +| PR #2000 | Merged the suite-count evidence refresh so the platform audit rejects stale local-suite totals | +| Owner approval packet | Added the final human decision sheet for release, package, plugin, video, billing, social, and outbound approvals | ## Release And Growth Evidence | Gate | Command | Result | | --- | --- | --- | -| Release-surface tests | `node tests/docs/ecc2-release-surface.test.js` | 25 passed, 0 failed | -| Preview-pack smoke | `npm run preview-pack:smoke -- --format json` | Ready true; digest `bc2bf157616e`; 30 required artifacts; 5 passed, 0 failed | +| Release-surface tests | `node tests/docs/ecc2-release-surface.test.js` | 26 passed, 0 failed | +| Preview-pack smoke | `npm run preview-pack:smoke -- --format json` | Ready true; digest `790430aef4a8`; 31 required artifacts; 5 passed, 0 failed | | Operator dashboard | `npm run operator:dashboard -- --markdown --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Generated May 19 dashboard with platform audit ready true, 0 tracked PRs, 0 tracked issues, 0 discussion gaps, `$1,728/mo` current MRR, `$10,000/mo` target MRR, the release video suite marked current, and top actions for plugin publication, notifications, outbound approval, AgentShield, and ECC Tools billing | | Release video suite | `npm run release:video-suite -- --format json --summary` with `ECC_VIDEO_SOURCE_ROOT` and `ECC_VIDEO_RELEASE_SUITE_ROOT` | Ready true; 15/15 source assets present; 13/13 render, timeline, caption, EDL, and segment artifacts present; 12/12 publish-candidate outputs present with zero detected black-frame segments; primary rough render self-eval passed at 144.759 seconds, 1920x1080, 1 audio stream, and 106.78 MB | -| Full local suite | `node tests/run-all.js` | 2547 passed, 0 failed | +| Full local suite | `node tests/run-all.js` | 2548 passed, 0 failed | | PR #1998 CI | GitHub Actions run `26099020341` | Completed successfully for `d500de1e9f11c0446b6a1349bd98b522d31f9125`; all reported checks passed, including lint, validation, security scan, coverage, GitGuardian, CodeRabbit, Cubic, and the macOS/Ubuntu/Windows test matrix | | PR #1999 CI | GitHub Actions run `26100148726` | Completed successfully for `90584b6d5e5814bc2ad9a4cd651bebd043de989d`; lint, validation, security scan, coverage, GitGuardian, CodeRabbit, and the macOS/Ubuntu/Windows test matrix passed; Cubic completed neutral and did not block merge | | Public-path sanitization | `node scripts/ci/validate-no-personal-paths.js` through local suite and CI | Passed | @@ -71,6 +73,7 @@ Tracked repositories in the platform audit were: | Release claim | Release notes and launch collateral frame ECC as the harness-native operator system for agentic work, not a Claude-only config pack | | Video proof | `video-suite-production.md` gates the local rough render, timeline, captions, source inventory, publish-candidate clip set, self-eval, black-frame QA, and no-private-path publication rules | | Growth proof | `partner-sponsor-talks-pack.md` provides approval-gated copy for sponsors, partners, consulting, talks, podcasts, GitHub Discussion, and video CTAs | +| Owner approval proof | `owner-approval-packet-2026-05-19.md` centralizes release, package, plugin, video, billing, social, and outbound decision gates | | Business baseline | Hypergrowth command center and partner pack use `$1,728/mo` current MRR, `$10,000/mo` target MRR, and `$8,272/mo` gap | | Operator dashboard | `operator-readiness-dashboard-2026-05-19.md` pulls the growth baseline into the same queue, publication, video, outbound, AgentShield, ECC Tools, Linear, and supply-chain control surface | @@ -98,7 +101,7 @@ Tracked repositories in the platform audit were: The tracked public PR queue, issue queue, discussion queue, canonical ECC identity, release video suite, preview pack, and growth outreach packet are current on May 19, 2026 for `main` through -`3304848beb40f57043c2314c744b5ad6265aaa96`. The remaining video work is +`e7a7b2aaa33c0657cad9db3fa2ced0e636cd0f8c`. The remaining video work is owner approval, upload, and public URL attachment, not render or QA production. This improves publication readiness but does not replace the approval-gated diff --git a/docs/releases/2.0.0-rc.1/publication-readiness.md b/docs/releases/2.0.0-rc.1/publication-readiness.md index f88fb764..d15455cc 100644 --- a/docs/releases/2.0.0-rc.1/publication-readiness.md +++ b/docs/releases/2.0.0-rc.1/publication-readiness.md @@ -58,6 +58,9 @@ For the May 18 operator dashboard refresh, see The current May 19 hypergrowth/operator dashboard is [`operator-readiness-dashboard-2026-05-19.md`](operator-readiness-dashboard-2026-05-19.md). +For the final owner decision sheet across release, npm, plugin, video, billing, +social, and outbound approvals, see +[`owner-approval-packet-2026-05-19.md`](owner-approval-packet-2026-05-19.md). For the May 19 live/pending release URL ledger after the public repo rename, see [`release-url-ledger-2026-05-19.md`](release-url-ledger-2026-05-19.md). @@ -99,16 +102,16 @@ Record the exact commit SHA and command output before any publication action: | Evidence | Command | Required result | Recorded output | | --- | --- | --- | --- | | Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | `3304848b`: `## main...origin/main`; repeat from the exact final publication commit before release | -| Preview-pack smoke | `npm run preview-pack:smoke` | Preview pack artifacts, Hermes boundary, final verification command list, and publication blockers pass | `publication-evidence-2026-05-19.md`: ready yes, digest `bc2bf157616e`, 30 artifacts, 5 passed, 0 failed; repeat in the final strict clean-checkout release pass | +| Preview-pack smoke | `npm run preview-pack:smoke` | Preview pack artifacts, Hermes boundary, final verification command list, and publication blockers pass | `publication-evidence-2026-05-19.md`: ready yes, digest `790430aef4a8`, 31 artifacts, 5 passed, 0 failed; repeat in the final strict clean-checkout release pass | | Harness audit | `npm run harness:audit -- --format json` | 70/70 passing | `99e01ded`: 70/70, 0 top actions | | Adapter scorecard | `npm run harness:adapters -- --check` | PASS | `99e01ded`: PASS, 11 adapters | | Observability readiness | `npm run observability:ready` | 21/21 passing | `publication-evidence-2026-05-18.md`: 21/21, ready yes | | Release safety gate | `npm run observability:ready -- --format json` | Release Safety category passing with publication readiness, supply-chain, workflow security, package surface, and release-surface evidence | May 18 evidence keeps release safety passing; repeat the JSON gate from the exact final release commit | | Supply-chain verification | `npm audit --json`; `npm audit signatures`; `cd ecc2 && cargo audit -q`; Dependabot alerts; GitGuardian Security Checks | 0 vulnerabilities/alerts, registry signatures verified, GitGuardian clean | `publication-evidence-2026-05-19.md` plus CI `26093792219`: GitGuardian and security scan passed; prior May 18 npm registry signatures and IOC scans remain the latest detailed supply-chain evidence | -| Root suite | `node tests/run-all.js` | 0 failures | `3304848b`: local `node tests/run-all.js` passed 2547/2547; PR #1999 CI `26100148726` passed the full OS/runtime/package-manager matrix for `90584b6d` | +| Root suite | `node tests/run-all.js` | 0 failures | Current packet branch based on `e7a7b2a`: local `node tests/run-all.js` passed 2548/2548; PR #2000 CI `26101512088` passed the full OS/runtime/package-manager matrix | | Markdown lint | `npx markdownlint-cli '**/*.md' --ignore node_modules` | 0 failures | CI `26093792219`: markdownlint passed on the growth-pack PR; rerun after any release-copy edits | | Package surface | `node tests/scripts/npm-publish-surface.test.js` | 0 failures; no Python bytecode in npm tarball | `2/2` passed in May 12 evidence pass | -| Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | May 19 evidence refresh: 25/25 passed after adding the video suite and partner/sponsor/talk gates | +| Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | May 19 evidence refresh: 26/26 passed after adding the video suite, partner/sponsor/talk gates, and owner approval packet | | Optional Rust surface | `cd ecc2 && cargo test` | 0 failures or explicit deferral | `publication-evidence-2026-05-16.md`: 462/462 passed, existing warnings only | | Queue baseline | `node scripts/platform-audit.js --json` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | `3304848b`: platform audit ready, 0 open PRs, 0 open issues, 0 conflicting PRs, and 0 blocking dirty files | | Discussion baseline | `node scripts/platform-audit.js --json` and `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | `3304848b`: platform audit sampled 58 trunk discussions, 0 needing maintainer touch, 0 answerable discussions missing accepted answer; `docs/architecture/discussion-response-playbook.md` records response templates and security escalation rules | diff --git a/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md b/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md index 508098e2..5a7dc203 100644 --- a/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md +++ b/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md @@ -103,6 +103,9 @@ Production steps: The source of truth for sponsor, partner, consulting, conference, podcast, and GitHub Discussion copy is `docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md`. +The source of truth for owner approval across release, package, plugin, video, +billing, social, and outbound actions is +`docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md`. ## Copy Rules diff --git a/scripts/platform-audit.js b/scripts/platform-audit.js index f39cc748..fe6b012d 100644 --- a/scripts/platform-audit.js +++ b/scripts/platform-audit.js @@ -472,7 +472,7 @@ function buildLocalEvidenceChecks(rootDir) { ), buildCheck( 'release-evidence-current', - includesAll(evidence, ['Release video suite', 'growth outreach', 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', '2547 passed']) ? 'pass' : 'fail', + includesAll(evidence, ['Release video suite', 'growth outreach', 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', '2548 passed']) ? 'pass' : 'fail', 'rc.1 evidence includes current release, video, growth, and CI artifacts', { path: 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md' } ), diff --git a/scripts/preview-pack-smoke.js b/scripts/preview-pack-smoke.js index 8dbee764..843eade8 100644 --- a/scripts/preview-pack-smoke.js +++ b/scripts/preview-pack-smoke.js @@ -30,6 +30,7 @@ const REQUIRED_ARTIFACTS = [ `${RELEASE_DIR}/operator-readiness-dashboard-2026-05-17.md`, `${RELEASE_DIR}/operator-readiness-dashboard-2026-05-18.md`, `${RELEASE_DIR}/operator-readiness-dashboard-2026-05-19.md`, + `${RELEASE_DIR}/owner-approval-packet-2026-05-19.md`, `${RELEASE_DIR}/release-url-ledger-2026-05-19.md`, `${RELEASE_DIR}/video-suite-production.md`, `${RELEASE_DIR}/partner-sponsor-talks-pack.md`, diff --git a/tests/docs/ecc2-release-surface.test.js b/tests/docs/ecc2-release-surface.test.js index c36bb649..8654080e 100644 --- a/tests/docs/ecc2-release-surface.test.js +++ b/tests/docs/ecc2-release-surface.test.js @@ -54,6 +54,7 @@ const expectedReleaseFiles = [ 'publication-readiness.md', 'video-suite-production.md', 'partner-sponsor-talks-pack.md', + 'owner-approval-packet-2026-05-19.md', 'release-name-plugin-publication-checklist-2026-05-18.md', ]; @@ -179,6 +180,7 @@ test('preview pack manifest assembles release, Hermes, and publication gates', ( 'docs/releases/2.0.0-rc.1/publication-readiness.md', 'docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md', 'docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md', + 'docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md', 'docs/releases/2.0.0-rc.1/video-suite-production.md', 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md', 'docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md', @@ -203,6 +205,51 @@ test('preview pack manifest assembles release, Hermes, and publication gates', ( assert.ok(manifest.includes('Reference-Inspired Adapter Direction')); }); +test('owner approval packet consolidates the final gated decisions', () => { + const packet = read('docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md'); + const manifest = read('docs/releases/2.0.0-rc.1/preview-pack-manifest.md'); + const publicationReadiness = read('docs/releases/2.0.0-rc.1/publication-readiness.md'); + const hypergrowth = read('docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md'); + + for (const marker of [ + 'Owner Approval Packet', + 'Source commit', + 'Decision Register', + 'GitHub prerelease', + 'npm `next` publish', + 'Claude plugin tag', + 'Video upload', + 'Final URL Fill-In', + 'Do Not Approve If', + 'No outbound email, personal-account post, package publish, plugin tag, or billing announcement is authorized by this packet alone.', + ]) { + assert.ok(packet.includes(marker), `owner approval packet missing ${marker}`); + } + + for (const command of [ + 'node scripts/platform-audit.js --json', + 'npm run preview-pack:smoke -- --format json', + 'npm run release:video-suite -- --format json', + 'node tests/run-all.js', + ]) { + assert.ok(packet.includes(command), `owner approval packet missing command ${command}`); + } + + for (const urlSurface of [ + 'GitHub prerelease URL', + 'npm rc package URL', + 'Claude plugin tag URL', + 'Primary launch video URL', + 'ECC Tools billing/readiness URL', + ]) { + assert.ok(packet.includes(urlSurface), `owner approval packet missing ${urlSurface}`); + } + + assert.ok(manifest.includes('owner-approval-packet-2026-05-19.md')); + assert.ok(publicationReadiness.includes('owner-approval-packet-2026-05-19.md')); + assert.ok(hypergrowth.includes('owner-approval-packet-2026-05-19.md')); +}); + test('rc.1 quickstart gives a clone-to-cross-harness path', () => { const quickstart = read('docs/releases/2.0.0-rc.1/quickstart.md'); for (const heading of ['Clone', 'Install', 'Verify', 'First Skill', 'Switch Harness']) { diff --git a/tests/scripts/operator-readiness-dashboard.test.js b/tests/scripts/operator-readiness-dashboard.test.js index 3c816cb0..7839e01a 100644 --- a/tests/scripts/operator-readiness-dashboard.test.js +++ b/tests/scripts/operator-readiness-dashboard.test.js @@ -178,7 +178,7 @@ function seedRepo(rootDir, overrides = {}) { 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', - '2547 passed', + '2548 passed', 'Business baseline', '$1,728/mo', '$8,272/mo' @@ -424,7 +424,7 @@ function runTests() { 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', - '2547 passed', + '2548 passed', 'Business baseline', '$1,728/mo', '$8,272/mo', diff --git a/tests/scripts/platform-audit.test.js b/tests/scripts/platform-audit.test.js index 16dcae40..d146c787 100644 --- a/tests/scripts/platform-audit.test.js +++ b/tests/scripts/platform-audit.test.js @@ -68,7 +68,7 @@ function seedRepo(rootDir, overrides = {}) { 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', - '2547 passed' + '2548 passed' ].join('\n'), 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md': [ 'This dashboard is generated by `npm run operator:dashboard`', From c7d662c3c68719e5ef0b5305ca3f6782b3214224 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 10:23:34 -0400 Subject: [PATCH 41/61] Track owner approval packet in dashboard --- docs/ECC-2.0-GA-ROADMAP.md | 20 ++++---- ...operator-readiness-dashboard-2026-05-19.md | 14 +++--- .../owner-approval-packet-2026-05-19.md | 6 +-- .../2.0.0-rc.1/preview-pack-manifest.md | 2 +- .../publication-evidence-2026-05-19.md | 11 +++-- .../2.0.0-rc.1/publication-readiness.md | 4 +- scripts/operator-readiness-dashboard.js | 25 ++++++++++ scripts/platform-audit.js | 2 +- tests/docs/ecc2-release-surface.test.js | 18 +++++++ .../operator-readiness-dashboard.test.js | 49 ++++++++++++++++++- tests/scripts/platform-audit.test.js | 2 +- 11 files changed, 123 insertions(+), 30 deletions(-) diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index 136e4848..d8304ba6 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -77,17 +77,19 @@ As of 2026-05-19: refreshed operator dashboard. - `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` records the current May 19 queue-zero state, canonical ECC identity merge, release video - suite gate, partner/sponsor/talk outreach pack, preview-pack smoke digest - `bc2bf157616e`, local 2544-test suite, and PR #1993 CI success. The May 18 - evidence remains the detailed supply-chain and publication-path snapshot. + suite gate, partner/sponsor/talk outreach pack, owner approval packet + (`owner-approval-packet-2026-05-19.md`), preview-pack smoke digest + `790430aef4a8`, local 2550-test suite, PR #2001 merge, and GitHub Actions run + `26102500291` success. The May 18 evidence remains the detailed supply-chain + and publication-path snapshot. - `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` regenerates the ITO-44 prompt-to-artifact dashboard from live platform audit evidence: PR queue, issue queue, discussion queue, local worktree gate, dashboard generation, and supply-chain loop are current; the dashboard now also tracks the `$1,728/mo` to `$10,000/mo` hypergrowth baseline, release - video-suite lane, and partner/sponsor/talk outbound pack; publication, - plugin, billing, AgentShield, ECC Tools, and final outbound approval remain - the next work. + video-suite lane, partner/sponsor/talk outbound pack, and owner approval + packet; publication, plugin, billing, AgentShield, ECC Tools, and final + outbound approval remain the next work. - `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` records the May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack @@ -732,12 +734,12 @@ is not complete unless the evidence column exists and has been freshly verified. | Prompt requirement | Required artifact or gate | Current evidence | Status | | --- | --- | --- | --- | -| Keep public PRs below 20 | Repo-family PR recheck | 0 open PRs across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-19 after merging PR #1993 and refreshing platform audit evidence | Complete | +| Keep public PRs below 20 | Repo-family PR recheck | 0 open PRs across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-19 after merging PR #2001 and refreshing platform audit evidence | Complete | | Keep public issues below 20 | Repo-family issue recheck | 0 open issues across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-19 after the live platform audit refresh | Complete | | Manage repository discussions | Repo-family discussion recheck plus response playbook | Platform audit reports 0 discussion maintainer-touch gaps and 0 answerable Q&A missing accepted answers; trunk still has 58 total discussions; `docs/architecture/discussion-response-playbook.md` distinguishes support, maintainer coordination, stale/concluded, release, informational, and security-sensitive response paths | Complete | -| Manage PR discussions | PR review/comment closure plus merge/close state | ECC #1990-#1993 merged through the harness audit, canonical identity, release video suite, and growth outreach batch; no open tracked PRs remain | Complete | +| Manage PR discussions | PR review/comment closure plus merge/close state | ECC #1990-#2001 merged through the harness audit, canonical identity, release video suite, growth outreach, evidence refresh, visual QA, suite-count, and owner-approval packet batch; no open tracked PRs remain | Complete | | Salvage useful stale work | `docs/stale-pr-salvage-ledger.md` plus `docs/legacy-artifact-inventory.md` | Ledger records salvaged, superseded, skipped, and manual-review tails; #1815-#1818 added cost tracking, skill scout, frontend design guidance, code-reviewer false-positive guardrails, and the May 12 gap pass; #1687, #1609, #1563, #1564, and #1565 localization tails are attached to Linear ITO-55 for language-owner review and no automatic import remains release-blocking | Complete; repeat legacy scan before release | -| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 19 evidence records queue-zero state, canonical ECC identity, release video suite, growth outreach pack, local 2544-test suite, PR #1993 CI success, May 19 operator dashboard, and preview-pack smoke digest `bc2bf157616e` | Needs final release approval | +| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 19 evidence records queue-zero state, canonical ECC identity, release video suite, growth outreach pack, owner approval packet, local 2550-test suite, PR #2001 merge, GitHub Actions run `26102500291` success, May 19 operator dashboard, `owner-approval-packet-2026-05-19.md`, and preview-pack smoke digest `790430aef4a8` | Needs final release approval | | Hermes specialized skills included safely | Hermes setup/import docs and sanitized skill surface | Hermes setup and import playbook are public; secrets stay local | Needs final release review | | Naming and rename readiness | Naming matrix across package/plugin/docs/social surfaces | `docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md` records current package, repo, Claude plugin, Codex plugin, OpenCode, and npm availability evidence | Complete for rc.1; post-rc rename remains future work | | Claude and Codex plugin publication | Contact/submission path with required artifacts and status | Publication readiness, naming matrix, and May 12 dry-run evidence document plugin validation, clean-checkout Claude tag/install smoke, and Codex marketplace CLI shape | Needs explicit approval for real tag/push and marketplace submission | diff --git a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md index a6dbea75..d63d7d93 100644 --- a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md @@ -2,8 +2,8 @@ This dashboard is generated by `npm run operator:dashboard`. It is an operator snapshot, not release approval. -Generated: 2026-05-19T13:22:19.744Z -Commit: 247750b7a6e918ac770402119c3191f512a69aa1 +Generated: 2026-05-19T14:27:11.558Z +Commit: a11bad8a7ad5bb028eb884913abf20285aec01d1 Status: work remaining ## Current Status @@ -37,6 +37,7 @@ Growth lanes: GitHub Sponsors and OSS partner sponsors; ECC Tools Pro subscripti | Include Hermes specialized skills safely | docs/HERMES-SETUP.md and skills/hermes-imports/SKILL.md | current | Hermes setup/import artifacts are covered by preview-pack smoke | repeat preview-pack smoke before release review | | Prepare name-change, Claude plugin, and Codex plugin paths | naming-and-publication-matrix plus release-name-plugin-publication checklist plus publication-readiness | in_progress | naming matrix, release publication checklist, and plugin readiness gates exist | real tag/push, marketplace submission, and final channel choice remain approval-gated | | Prepare release notes, articles, tweets, and push notifications | docs/releases/2.0.0-rc.1 social and release-copy files | in_progress | release notes, X thread, LinkedIn draft, and URL ledger are present | final live release/npm/plugin/billing URLs and publish approval still pending | +| Prepare final owner approval packet | docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md | current | owner approval packet covers release, package, plugin, video, billing, social, and outbound decisions | review owner approvals from the final release commit before any publication or outbound action | | Create a second-phase hypergrowth release command center | docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md plus May 19 evidence | current | current MRR, target MRR, gap, release claim, video lane, distribution plan, and approval boundaries are in-tree | refresh after every MRR, channel, or approval-state change before public launch | | Produce the ECC 2.0 release video suite | docs/releases/2.0.0-rc.1/video-suite-production.md and npm run release:video-suite | current | video-suite gate is ready with 15/15 source assets, 13/13 suite artifacts, 12/12 publish candidates, primary self-eval, and zero detected black-frame segments recorded in May 19 evidence | final owner approval, upload, and public video URLs remain approval-gated | | Prepare sponsor, partner, consulting, podcast, talk, and Discussion copy | docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md | in_progress | sponsor outbound, platform partner DM, consulting intro, talk/podcast pitch, GitHub Discussion announcement, CTA hooks, and do-not-send gate are drafted | replace final URLs after publication gates, then get explicit approval before outbound or personal-account posts | @@ -58,7 +59,8 @@ Growth lanes: GitHub Sponsors and OSS partner sponsors; ECC Tools Pro subscripti ## Next Work Order 1. Regenerate this dashboard from the final release commit before publication evidence is recorded. -2. Review the owner-approved primary launch video candidates, choose the final cuts, upload after approval, and attach public video URLs to the release pack. -3. Replace final release, npm, plugin, billing, and video URLs in the partner/sponsor/talk pack, then get explicit approval before outbound. -4. Repeat ITO-57 Linear/project status sync after the next significant merge batch or advisory-source refresh. -5. Create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure the target account and INTERNAL_API_SECRET, then rerun target readback and the live announcement gate before publishing native-payments copy. +2. Review the owner approval packet from the final release commit and approve, defer, or block each publication and outbound lane. +3. Review the owner-approved primary launch video candidates, choose the final cuts, upload after approval, and attach public video URLs to the release pack. +4. Replace final release, npm, plugin, billing, and video URLs in the partner/sponsor/talk pack, then get explicit approval before outbound. +5. Repeat ITO-57 Linear/project status sync after the next significant merge batch or advisory-source refresh. +6. Create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure the target account and INTERNAL_API_SECRET, then rerun target readback and the live announcement gate before publishing native-payments copy. diff --git a/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md b/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md index 2b949b5a..ff7b85a2 100644 --- a/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md @@ -17,9 +17,9 @@ Source commit for the clean evidence baseline this packet extends: | Platform audit | ready true, 0 open PRs, 0 open issues, 0 discussion gaps, 0 dirty files | yes | | Preview pack smoke | ready true, digest `790430aef4a8`, 5/5 checks | yes | | Video suite | ready true, 15/15 source assets, 13/13 suite artifacts, 12/12 publish candidates | yes | -| Release surface tests | 26/26 passed after this packet was added | yes | -| Full local suite | 2548/2548 passed after this packet was added | yes | -| GitHub CI | PR #1998, PR #1999, and PR #2000 merged after green required checks | verify current head | +| Release surface tests | 27/27 passed after this packet was added | yes | +| Full local suite | 2550/2550 passed after this packet was added | yes | +| GitHub CI | PR #1998, PR #1999, PR #2000, and PR #2001 merged after green required checks | verify current head | ## Decision Register diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index c0ea3c7a..13cc1d3c 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -25,7 +25,7 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-16.md` | Current May 16/17 queue cleanup, recsys skill merge, GateGuard triage, PR #1947 supply-chain protection, AgentShield #87 plugin-cache confidence evidence, AgentShield #88 evidence-pack inspect/readback, AgentShield #89 evidence-pack fleet routing, AgentShield #90 fleet review items, AgentShield #91 policy export, AgentShield #92 policy promotion, ECC-Tools #76 fleet-summary consumption, ECC-Tools #77 hosted finding evidence paths, ECC-Tools #78 harness policy-route linking, dashboard refresh, and combined Node/Rust/release-surface gate evidence through the May 16 mirror | Must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` | May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack protection recheck, npm audit/signature checks, legacy and Linear progress routing, deterministic preview-pack smoke, operator dashboard refresh, Linear sync, and GitHub CI evidence for `27dc2918` | Superseded by the May 18 evidence snapshot; repeat from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, supply-chain recheck, AgentShield evidence mirror, Linear sync, current-head CI/security scan success for `4470e2e6`, and ITO-46 naming/plugin publication closure | Superseded by the May 19 ECC identity, video, and growth evidence snapshot | -| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, May 19 operator dashboard, preview-pack smoke digest `790430aef4a8`, 2548-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, and PR #2000 suite-count evidence success | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | +| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, May 19 operator dashboard, preview-pack smoke digest `790430aef4a8`, 2550-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, and PR #2001 owner approval packet CI success | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 19 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and adds the current `$1,728/mo` to `$10,000/mo` hypergrowth, video owner-approval, and outbound-pack operating lanes | diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md index cbecf7cf..25e975b4 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -8,9 +8,9 @@ social announcement. | Field | Evidence | | --- | --- | -| Upstream main | `e7a7b2aaa33c0657cad9db3fa2ced0e636cd0f8c` | +| Upstream main | `8148340ad14eb32c971346f0cb4cb9431ec0f5de` | | Git remote | `https://github.com/affaan-m/ECC.git` | -| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, and the owner approval packet addition | +| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, and PR #2001 owner approval packet addition | | Local status caveat | `git status --short --branch` was clean after pulling `origin/main`; generated evidence files are committed after the source snapshot they describe | The release operator must repeat all publish-facing checks from the exact final @@ -49,19 +49,20 @@ Tracked repositories in the platform audit were: | PR #1998 | Merged the release video visual QA gate for publish candidates and black-frame segment detection | | PR #1999 | Merged the operator dashboard refresh that moved the release video suite to current once publish-candidate evidence was recorded | | PR #2000 | Merged the suite-count evidence refresh so the platform audit rejects stale local-suite totals | -| Owner approval packet | Added the final human decision sheet for release, package, plugin, video, billing, social, and outbound approvals | +| PR #2001 | Merged the final human decision sheet for release, package, plugin, video, billing, social, and outbound approvals; GitHub Actions run `26102500291` completed successfully | ## Release And Growth Evidence | Gate | Command | Result | | --- | --- | --- | -| Release-surface tests | `node tests/docs/ecc2-release-surface.test.js` | 26 passed, 0 failed | +| Release-surface tests | `node tests/docs/ecc2-release-surface.test.js` | 27 passed, 0 failed | | Preview-pack smoke | `npm run preview-pack:smoke -- --format json` | Ready true; digest `790430aef4a8`; 31 required artifacts; 5 passed, 0 failed | | Operator dashboard | `npm run operator:dashboard -- --markdown --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Generated May 19 dashboard with platform audit ready true, 0 tracked PRs, 0 tracked issues, 0 discussion gaps, `$1,728/mo` current MRR, `$10,000/mo` target MRR, the release video suite marked current, and top actions for plugin publication, notifications, outbound approval, AgentShield, and ECC Tools billing | | Release video suite | `npm run release:video-suite -- --format json --summary` with `ECC_VIDEO_SOURCE_ROOT` and `ECC_VIDEO_RELEASE_SUITE_ROOT` | Ready true; 15/15 source assets present; 13/13 render, timeline, caption, EDL, and segment artifacts present; 12/12 publish-candidate outputs present with zero detected black-frame segments; primary rough render self-eval passed at 144.759 seconds, 1920x1080, 1 audio stream, and 106.78 MB | -| Full local suite | `node tests/run-all.js` | 2548 passed, 0 failed | +| Full local suite | `node tests/run-all.js` | 2550 passed, 0 failed | | PR #1998 CI | GitHub Actions run `26099020341` | Completed successfully for `d500de1e9f11c0446b6a1349bd98b522d31f9125`; all reported checks passed, including lint, validation, security scan, coverage, GitGuardian, CodeRabbit, Cubic, and the macOS/Ubuntu/Windows test matrix | | PR #1999 CI | GitHub Actions run `26100148726` | Completed successfully for `90584b6d5e5814bc2ad9a4cd651bebd043de989d`; lint, validation, security scan, coverage, GitGuardian, CodeRabbit, and the macOS/Ubuntu/Windows test matrix passed; Cubic completed neutral and did not block merge | +| PR #2001 CI | GitHub Actions run `26102500291` | Completed successfully for `8148340ad14eb32c971346f0cb4cb9431ec0f5de`; required checks passed before merge | | Public-path sanitization | `node scripts/ci/validate-no-personal-paths.js` through local suite and CI | Passed | | Markdown and whitespace | `markdownlint` focused release docs plus `git diff --check` before PR #1999 | Passed | diff --git a/docs/releases/2.0.0-rc.1/publication-readiness.md b/docs/releases/2.0.0-rc.1/publication-readiness.md index d15455cc..84e7131b 100644 --- a/docs/releases/2.0.0-rc.1/publication-readiness.md +++ b/docs/releases/2.0.0-rc.1/publication-readiness.md @@ -108,10 +108,10 @@ Record the exact commit SHA and command output before any publication action: | Observability readiness | `npm run observability:ready` | 21/21 passing | `publication-evidence-2026-05-18.md`: 21/21, ready yes | | Release safety gate | `npm run observability:ready -- --format json` | Release Safety category passing with publication readiness, supply-chain, workflow security, package surface, and release-surface evidence | May 18 evidence keeps release safety passing; repeat the JSON gate from the exact final release commit | | Supply-chain verification | `npm audit --json`; `npm audit signatures`; `cd ecc2 && cargo audit -q`; Dependabot alerts; GitGuardian Security Checks | 0 vulnerabilities/alerts, registry signatures verified, GitGuardian clean | `publication-evidence-2026-05-19.md` plus CI `26093792219`: GitGuardian and security scan passed; prior May 18 npm registry signatures and IOC scans remain the latest detailed supply-chain evidence | -| Root suite | `node tests/run-all.js` | 0 failures | Current packet branch based on `e7a7b2a`: local `node tests/run-all.js` passed 2548/2548; PR #2000 CI `26101512088` passed the full OS/runtime/package-manager matrix | +| Root suite | `node tests/run-all.js` | 0 failures | Current dashboard branch: local `node tests/run-all.js` passed 2550/2550; PR #2001 CI `26102500291` passed the previous full OS/runtime/package-manager matrix | | Markdown lint | `npx markdownlint-cli '**/*.md' --ignore node_modules` | 0 failures | CI `26093792219`: markdownlint passed on the growth-pack PR; rerun after any release-copy edits | | Package surface | `node tests/scripts/npm-publish-surface.test.js` | 0 failures; no Python bytecode in npm tarball | `2/2` passed in May 12 evidence pass | -| Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | May 19 evidence refresh: 26/26 passed after adding the video suite, partner/sponsor/talk gates, and owner approval packet | +| Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | May 19 evidence refresh: 27/27 passed after adding the video suite, partner/sponsor/talk gates, owner approval packet, and roadmap evidence mirror | | Optional Rust surface | `cd ecc2 && cargo test` | 0 failures or explicit deferral | `publication-evidence-2026-05-16.md`: 462/462 passed, existing warnings only | | Queue baseline | `node scripts/platform-audit.js --json` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | `3304848b`: platform audit ready, 0 open PRs, 0 open issues, 0 conflicting PRs, and 0 blocking dirty files | | Discussion baseline | `node scripts/platform-audit.js --json` and `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | `3304848b`: platform audit sampled 58 trunk discussions, 0 needing maintainer touch, 0 answerable discussions missing accepted answer; `docs/architecture/discussion-response-playbook.md` records response templates and security escalation rules | diff --git a/scripts/operator-readiness-dashboard.js b/scripts/operator-readiness-dashboard.js index 1e5483d5..5e52fbbf 100644 --- a/scripts/operator-readiness-dashboard.js +++ b/scripts/operator-readiness-dashboard.js @@ -588,6 +588,7 @@ function buildRequirements(rootDir, platformReport) { const partnerSponsorTalksPack = readText(rootDir, 'docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md'); const releaseVideoProduction = readText(rootDir, 'docs/releases/2.0.0-rc.1/video-suite-production.md'); const ownerQueueCleanup = readText(rootDir, 'docs/releases/2.0.0-rc.1/owner-queue-cleanup-2026-05-18.md'); + const ownerApprovalPacket = readText(rootDir, 'docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md'); const previewManifest = readText(rootDir, 'docs/releases/2.0.0-rc.1/preview-pack-manifest.md'); const previewPackSmoke = readText(rootDir, 'scripts/preview-pack-smoke.js'); const releaseVideoSuite = readText(rootDir, 'scripts/release-video-suite.js'); @@ -658,6 +659,17 @@ function buildRequirements(rootDir, platformReport) { 'GitHub Discussion Announcement', 'Do Not Send Or Publish If', ]); + const ownerApprovalPacketReady = includesAll(ownerApprovalPacket, [ + 'Owner Approval Packet', + 'Decision Register', + 'GitHub prerelease', + 'npm `next` publish', + 'Claude plugin tag', + 'Video upload', + 'Final URL Fill-In', + 'Do Not Approve If', + 'No outbound email, personal-account post, package publish, plugin tag, or billing announcement is authorized by this packet alone.' + ]) && includesAll(previewManifest, ['owner-approval-packet-2026-05-19.md']); const githubLive = !platformReport.github.skipped && platformReport.github.totals.errors === 0; const ownerWideOpenPrs = extractLabeledCount(ownerQueueCleanup, 'Owner-wide open PRs after cleanup'); @@ -795,6 +807,18 @@ function buildRequirements(rootDir, platformReport) { ? 'final live release/npm/plugin/billing URLs and publish approval still pending' : 'URL-backed refresh and publish approval still pending' ), + buildRequirement( + 'owner-approval-packet', + 'Prepare final owner approval packet', + 'docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md', + ownerApprovalPacketReady ? 'current' : 'not_complete', + ownerApprovalPacketReady + ? 'owner approval packet covers release, package, plugin, video, billing, social, and outbound decisions' + : 'owner approval packet is missing or incomplete', + ownerApprovalPacketReady + ? 'review owner approvals from the final release commit before any publication or outbound action' + : 'add the owner decision sheet before publication review' + ), buildRequirement( 'hypergrowth-command-center', 'Create a second-phase hypergrowth release command center', @@ -954,6 +978,7 @@ function buildReport(options) { top_actions: topActions, next_work_order: [ 'Regenerate this dashboard from the final release commit before publication evidence is recorded.', + 'Review the owner approval packet from the final release commit and approve, defer, or block each publication and outbound lane.', releaseVideoWorkOrder, 'Replace final release, npm, plugin, billing, and video URLs in the partner/sponsor/talk pack, then get explicit approval before outbound.', 'Repeat ITO-57 Linear/project status sync after the next significant merge batch or advisory-source refresh.', diff --git a/scripts/platform-audit.js b/scripts/platform-audit.js index fe6b012d..a49c8a37 100644 --- a/scripts/platform-audit.js +++ b/scripts/platform-audit.js @@ -472,7 +472,7 @@ function buildLocalEvidenceChecks(rootDir) { ), buildCheck( 'release-evidence-current', - includesAll(evidence, ['Release video suite', 'growth outreach', 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', '2548 passed']) ? 'pass' : 'fail', + includesAll(evidence, ['Release video suite', 'growth outreach', 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', '2550 passed']) ? 'pass' : 'fail', 'rc.1 evidence includes current release, video, growth, and CI artifacts', { path: 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md' } ), diff --git a/tests/docs/ecc2-release-surface.test.js b/tests/docs/ecc2-release-surface.test.js index 8654080e..34eee09f 100644 --- a/tests/docs/ecc2-release-surface.test.js +++ b/tests/docs/ecc2-release-surface.test.js @@ -250,6 +250,24 @@ test('owner approval packet consolidates the final gated decisions', () => { assert.ok(hypergrowth.includes('owner-approval-packet-2026-05-19.md')); }); +test('GA roadmap mirrors the current May 19 release evidence', () => { + const roadmap = read('docs/ECC-2.0-GA-ROADMAP.md'); + + for (const marker of [ + 'owner-approval-packet-2026-05-19.md', + 'preview-pack smoke digest `790430aef4a8`', + 'local 2550-test suite', + 'PR #2001', + 'GitHub Actions run `26102500291`', + 'owner approval packet', + ]) { + assert.ok(roadmap.includes(marker), `GA roadmap missing current evidence marker ${marker}`); + } + + assert.ok(!roadmap.includes('preview-pack smoke digest `bc2bf157616e`')); + assert.ok(!roadmap.includes('local 2544-test suite')); +}); + test('rc.1 quickstart gives a clone-to-cross-harness path', () => { const quickstart = read('docs/releases/2.0.0-rc.1/quickstart.md'); for (const heading of ['Clone', 'Install', 'Verify', 'First Skill', 'Switch Harness']) { diff --git a/tests/scripts/operator-readiness-dashboard.test.js b/tests/scripts/operator-readiness-dashboard.test.js index 7839e01a..6a9a4958 100644 --- a/tests/scripts/operator-readiness-dashboard.test.js +++ b/tests/scripts/operator-readiness-dashboard.test.js @@ -100,9 +100,21 @@ function seedRepo(rootDir, overrides = {}) { 'docs/releases/2.0.0-rc.1/preview-pack-manifest.md': [ 'publication-readiness.md release-notes.md quickstart.md', 'release-name-plugin-publication-checklist-2026-05-18.md', + 'owner-approval-packet-2026-05-19.md', '`scripts/preview-pack-smoke.js`', 'npm run preview-pack:smoke' ].join('\n'), + 'docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md': [ + 'Owner Approval Packet', + 'Decision Register', + 'GitHub prerelease', + 'npm `next` publish', + 'Claude plugin tag', + 'Video upload', + 'Final URL Fill-In', + 'Do Not Approve If', + 'No outbound email, personal-account post, package publish, plugin tag, or billing announcement is authorized by this packet alone.' + ].join('\n'), 'docs/releases/2.0.0-rc.1/release-notes.md': 'release notes', 'docs/releases/2.0.0-rc.1/x-thread.md': 'x thread', 'docs/releases/2.0.0-rc.1/linkedin-post.md': 'linkedin post', @@ -178,7 +190,7 @@ function seedRepo(rootDir, overrides = {}) { 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', - '2548 passed', + '2550 passed', 'Business baseline', '$1,728/mo', '$8,272/mo' @@ -381,6 +393,12 @@ function runTests() { && item.evidence.includes('sponsor outbound') && item.gap === 'replace final URLs after publication gates, then get explicit approval before outbound or personal-account posts' ))); + assert.ok(report.requirements.some(item => ( + item.id === 'owner-approval-packet' + && item.status === 'current' + && item.evidence.includes('release, package, plugin, video, billing, social, and outbound decisions') + && item.gap === 'review owner approvals from the final release commit before any publication or outbound action' + ))); assert.ok(report.requirements.some(item => ( item.id === 'supply-chain-local-protection' && item.artifact.includes('AgentShield package-manager hardening') @@ -403,6 +421,7 @@ function runTests() { assert.ok(report.top_actions.some(item => item.id === 'naming-and-plugin-publication')); assert.ok(report.top_actions.some(item => item.id === 'release-video-suite')); assert.ok(report.top_actions.some(item => item.id === 'partner-sponsor-talks-pack')); + assert.ok(!report.top_actions.some(item => item.id === 'owner-approval-packet')); assert.ok(!report.top_actions.some(item => item.id === 'ecc-preview-pack')); assert.ok(!report.top_actions.some(item => item.id === 'hermes-specialized-skills')); assert.ok(!report.top_actions.some(item => item.id === 'hypergrowth-command-center')); @@ -424,7 +443,7 @@ function runTests() { 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', - '2548 passed', + '2550 passed', 'Business baseline', '$1,728/mo', '$8,272/mo', @@ -517,6 +536,32 @@ function runTests() { } })) passed++; else failed++; + if (test('owner approval packet fails closed when it is missing from the release pack', () => { + const rootDir = createTempDir('operator-dashboard-owner-packet-'); + + try { + seedRepo(rootDir, { + 'docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md': null, + 'docs/releases/2.0.0-rc.1/preview-pack-manifest.md': [ + 'publication-readiness.md release-notes.md quickstart.md', + 'release-name-plugin-publication-checklist-2026-05-18.md', + '`scripts/preview-pack-smoke.js`', + 'npm run preview-pack:smoke' + ].join('\n') + }); + + const report = buildSeededReport(rootDir); + const ownerPacket = report.requirements.find(item => item.id === 'owner-approval-packet'); + + assert.strictEqual(ownerPacket.status, 'not_complete'); + assert.strictEqual(ownerPacket.evidence, 'owner approval packet is missing or incomplete'); + assert.strictEqual(ownerPacket.gap, 'add the owner decision sheet before publication review'); + assert.ok(report.top_actions.some(item => item.id === 'owner-approval-packet')); + } finally { + cleanup(rootDir); + } + })) passed++; else failed++; + if (test('AgentShield enterprise evidence covers export and policy promotion markers', () => { const cases = [ { diff --git a/tests/scripts/platform-audit.test.js b/tests/scripts/platform-audit.test.js index d146c787..b7b1d9ba 100644 --- a/tests/scripts/platform-audit.test.js +++ b/tests/scripts/platform-audit.test.js @@ -68,7 +68,7 @@ function seedRepo(rootDir, overrides = {}) { 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', - '2548 passed' + '2550 passed' ].join('\n'), 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md': [ 'This dashboard is generated by `npm run operator:dashboard`', From ac7434ea8f39166b11e9d06ce64b38c4fb8d9202 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 10:48:42 -0400 Subject: [PATCH 42/61] docs: sync may 19 linear readiness evidence --- docs/ECC-2.0-GA-ROADMAP.md | 40 +++++++++++-------- ...operator-readiness-dashboard-2026-05-19.md | 6 +-- .../2.0.0-rc.1/preview-pack-manifest.md | 2 +- .../publication-evidence-2026-05-19.md | 14 ++++--- scripts/operator-readiness-dashboard.js | 9 ++++- tests/docs/ecc2-release-surface.test.js | 3 ++ 6 files changed, 48 insertions(+), 26 deletions(-) diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index d8304ba6..9d6b89ef 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -51,8 +51,9 @@ As of 2026-05-19: now at 0 open PRs and 0 open issues by live `gh search`. Archived repos touched during closure were restored to archived state. - GitHub discussions are current across those tracked repos: - `affaan-m/ECC` has 58 total discussions and 0 without - maintainer touch after May 15 maintainer updates on #73 and #1239; AgentShield, + `affaan-m/ECC` has 59 total discussions and 0 without + maintainer touch after the May 19 #2003 AURA integration proposal was routed + as an external-adapter proposal, not core wallet/escrow coupling; AgentShield, JARVIS, ECC Tools, and the ECC Tools website have discussions disabled or 0 total discussions. `docs/architecture/discussion-response-playbook.md` now supplies the ITO-59 response categories, public templates, security-escalation @@ -61,12 +62,17 @@ As of 2026-05-19: `ITO-59`) and five milestones: Security and Access Baseline, ECC 2.0 Preview and Publication, AgentShield Enterprise Iteration, ECC Tools Next-Level Platform, and Legacy Audit and Salvage. -- Linear live sync is current for the May 18 merge and supply-chain batch: - ITO-57 has a final emergency supply-chain refresh comment - (`3fe5b2b7-c4fe-401c-a317-b40d72119cb3`), and the ECC platform project has - the latest operator progress comment (`e32e5b7a-287b-4bf4-9ed7-314389a157e1`). - Linear project status updates are disabled in this workspace, so the project - comment is the supported external status surface. +- Linear live sync is current for the May 19 PR #2002 merge and discussion + batch: the ECC platform project has the post-PR #2002 sync document + `ecc-may-19-post-pr-2002-sync-64cef8f668e0`, project comment + `a6411e3a-8c8e-4a58-adba-687e77d4c543`, and issue comments on ITO-44, + ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56. ITO-47, ITO-48, + ITO-49, ITO-51, ITO-54, and ITO-56 were moved to In Progress because those + lanes now have current implementation/evidence and remaining gate/readback + work. ITO-57 still has the May 18 emergency supply-chain refresh comment + (`3fe5b2b7-c4fe-401c-a317-b40d72119cb3`). Linear project status updates are + disabled in this workspace, so project documents and comments are the + supported external status surface. - The latest May 18 merge batch on `main` includes PR #1970 workflow-security validator bypass fixes, PR #1971 metrics bridge cost-reporting and warning de-dup fixes, PR #1972 `uncloud` skill activation structure, PR #1976 @@ -79,9 +85,11 @@ As of 2026-05-19: current May 19 queue-zero state, canonical ECC identity merge, release video suite gate, partner/sponsor/talk outreach pack, owner approval packet (`owner-approval-packet-2026-05-19.md`), preview-pack smoke digest - `790430aef4a8`, local 2550-test suite, PR #2001 merge, and GitHub Actions run - `26102500291` success. The May 18 evidence remains the detailed supply-chain - and publication-path snapshot. + `790430aef4a8`, local 2550-test suite, PR #2001 merge and GitHub Actions run + `26102500291` success, plus PR #2002's owner-approval dashboard gate refresh, + GitHub Actions run `26103853507`, and the May 19 Linear sync document. The + May 18 evidence remains the detailed supply-chain and publication-path + snapshot. - `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` regenerates the ITO-44 prompt-to-artifact dashboard from live platform audit evidence: PR queue, issue queue, discussion queue, local worktree gate, @@ -734,12 +742,12 @@ is not complete unless the evidence column exists and has been freshly verified. | Prompt requirement | Required artifact or gate | Current evidence | Status | | --- | --- | --- | --- | -| Keep public PRs below 20 | Repo-family PR recheck | 0 open PRs across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-19 after merging PR #2001 and refreshing platform audit evidence | Complete | +| Keep public PRs below 20 | Repo-family PR recheck | 0 open PRs across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-19 after merging PR #2002 and refreshing platform audit evidence | Complete | | Keep public issues below 20 | Repo-family issue recheck | 0 open issues across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-19 after the live platform audit refresh | Complete | -| Manage repository discussions | Repo-family discussion recheck plus response playbook | Platform audit reports 0 discussion maintainer-touch gaps and 0 answerable Q&A missing accepted answers; trunk still has 58 total discussions; `docs/architecture/discussion-response-playbook.md` distinguishes support, maintainer coordination, stale/concluded, release, informational, and security-sensitive response paths | Complete | -| Manage PR discussions | PR review/comment closure plus merge/close state | ECC #1990-#2001 merged through the harness audit, canonical identity, release video suite, growth outreach, evidence refresh, visual QA, suite-count, and owner-approval packet batch; no open tracked PRs remain | Complete | +| Manage repository discussions | Repo-family discussion recheck plus response playbook | Platform audit reports 0 discussion maintainer-touch gaps and 0 answerable Q&A missing accepted answers; trunk has 59 total discussions after #2003 was routed with a maintainer response; `docs/architecture/discussion-response-playbook.md` distinguishes support, maintainer coordination, stale/concluded, release, informational, and security-sensitive response paths | Complete | +| Manage PR discussions | PR review/comment closure plus merge/close state | ECC #1990-#2002 merged through the harness audit, canonical identity, release video suite, growth outreach, evidence refresh, visual QA, suite-count, owner-approval packet, and owner-approval dashboard gate batch; no open tracked PRs remain | Complete | | Salvage useful stale work | `docs/stale-pr-salvage-ledger.md` plus `docs/legacy-artifact-inventory.md` | Ledger records salvaged, superseded, skipped, and manual-review tails; #1815-#1818 added cost tracking, skill scout, frontend design guidance, code-reviewer false-positive guardrails, and the May 12 gap pass; #1687, #1609, #1563, #1564, and #1565 localization tails are attached to Linear ITO-55 for language-owner review and no automatic import remains release-blocking | Complete; repeat legacy scan before release | -| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 19 evidence records queue-zero state, canonical ECC identity, release video suite, growth outreach pack, owner approval packet, local 2550-test suite, PR #2001 merge, GitHub Actions run `26102500291` success, May 19 operator dashboard, `owner-approval-packet-2026-05-19.md`, and preview-pack smoke digest `790430aef4a8` | Needs final release approval | +| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 19 evidence records queue-zero state, canonical ECC identity, release video suite, growth outreach pack, owner approval packet, local 2550-test suite, PR #2001 merge and GitHub Actions run `26102500291`, PR #2002 owner-approval dashboard gate refresh and GitHub Actions run `26103853507`, May 19 operator dashboard, `owner-approval-packet-2026-05-19.md`, and preview-pack smoke digest `790430aef4a8` | Needs final release approval | | Hermes specialized skills included safely | Hermes setup/import docs and sanitized skill surface | Hermes setup and import playbook are public; secrets stay local | Needs final release review | | Naming and rename readiness | Naming matrix across package/plugin/docs/social surfaces | `docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md` records current package, repo, Claude plugin, Codex plugin, OpenCode, and npm availability evidence | Complete for rc.1; post-rc rename remains future work | | Claude and Codex plugin publication | Contact/submission path with required artifacts and status | Publication readiness, naming matrix, and May 12 dry-run evidence document plugin validation, clean-checkout Claude tag/install smoke, and Codex marketplace CLI shape | Needs explicit approval for real tag/push and marketplace submission | @@ -748,7 +756,7 @@ is not complete unless the evidence column exists and has been freshly verified. | ECC Tools next-level app | Billing audit, PR checks, deep analyzer, sync backlog, evaluator/RAG corpus, analysis-depth readiness, hosted execution planning, hosted CI diagnostics, hosted security evidence review, hosted harness compatibility audit, hosted reference-set evaluation, hosted AI routing/cost review, hosted team backlog routing, hosted depth-plan check-run, PR-comment hosted job dispatch, hosted job result history/check-runs, hosted result status command, status-aware depth-plan recommendations, hosted promotion readiness, hosted promotion output scoring, hosted promotion retrieval planning, hosted promotion judge contract, gated hosted promotion judge execution, hosted promotion judge audit trace, payment-announcement readiness, billing announcement preflight, aggregate production billing KV readback, Marketplace webhook provenance, target-account billing readback, Marketplace-source provenance counts, AgentShield fleet-summary hosted routing, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output hosted telemetry, and operator-visible promotion output values | PRs #26-#43 plus #53-#78 landed with test evidence, including AgentShield evidence-pack gap routing, canonical bundle recognition, supply-chain signature gates, PR draft follow-up Linear tracking, evidence-backed/deep-ready repository classification, the `/api/analysis/depth-plan` hosted job plan, `/api/analysis/jobs/ci-diagnostics`, `/api/analysis/jobs/security-evidence-review`, `/api/analysis/jobs/harness-compatibility-audit`, `/api/analysis/jobs/reference-set-evaluation`, `/api/analysis/jobs/ai-routing-cost-review`, `/api/analysis/jobs/team-backlog-routing`, the `ECC Tools / Hosted Depth Plan` check-run, `/ecc-tools analyze --job ...` PR-comment dispatch, non-blocking per-hosted-job result check-runs backed by 30-day result cache records, `/ecc-tools analyze --job status` cache lookup, cache-aware next-job recommendations in the depth-plan check-run, the `ECC Tools / Hosted Promotion Readiness` corpus-backed PR check-run, deterministic hosted-output scoring against cached completed job artifacts/findings, ranked retrieval/model-prompt planning, the fail-closed `hosted-promotion-judge.v1` request contract, opt-in live model-judge execution behind hosted evidence, entitlement, budget, provider, executor, strict JSON, and citation gates, hosted promotion judge request fingerprints plus allowed-citation audit trails, a fail-closed `/api/billing/readiness` `announcementGate` for native GitHub payments claims, `npm run billing:announcement-gate` plus `--preflight` as the non-secret operator verifier, hosted security findings for AgentShield fleet summaries, an `Evidence` column in hosted finding comments/check-runs, hosted harness findings that route AgentShield fleet target paths to harness owners, ECC-Tools commit `8658951` routing AgentShield policy-promotion Action outputs into hosted security review and promotion-readiness scoring, ECC-Tools commit `16c537f` rendering policy-promotion status/pack/count/digest values directly in hosted security job comments/check-runs, ECC-Tools commit `05d4e82` rendering model-judge audit traces without exposing raw provider output, ECC-Tools commit `91a441b` adding the safe billing announcement preflight path, ECC-Tools commit `eb69412` recording the initial production readback state, ECC-Tools commit `95d0bec` adding `npm run billing:kv-readback` with aggregate account-billing and billing-state records but 0 Marketplace Pro billing-state records, ECC-Tools commit `2859678` requiring webhook-derived Marketplace provenance before announcement readiness, ECC-Tools commit `42653f9` adding Wrangler OAuth readback, ECC-Tools commit `632e059` adding sanitized target-account readback that requires both target key families before `--require-ready` can pass, and ECC-Tools commit `d5f60db` adding sanitized Marketplace plan/action provenance counts; the latest 2026-05-18 live Wrangler OAuth recheck found 256 account-billing records, 256 billing-state records, 197 Marketplace-source records, 4 Marketplace webhook-provenance records, all `Open Source`, and 0 Marketplace Pro records, then updated Linear ITO-61 with the data/provisioning blocker | Next work is create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure target account plus `INTERNAL_API_SECRET`, then run `billing:kv-readback -- --wrangler --wrangler-bin ./node_modules/.bin/wrangler --account --require-ready`, followed by the live announcement gate | | GitGuardian/Dependabot/CodeRabbit-style checks | Non-blocking taxonomy, deterministic follow-up checks, and local supply-chain gates | ECC-Tools risk taxonomy check plus follow-up signals landed, including Skill Quality, Deep Analyzer Evidence, Analyzer Corpus Evidence, RAG/Evaluator Evidence, PR Review/Salvage Evidence, and AgentShield evidence-pack evidence; #1846 added npm registry signature gates; #1848 added the supply-chain incident-response playbook and `pull_request_target` cache-poisoning validator guard; #1851 added the privileged checkout credential-persistence guard; AgentShield #78, JARVIS #13, and ECC-Tools #53 applied the same hardening outside trunk | Current supply-chain gate complete; deeper hosted review features remain future | | Harness-agnostic learning system | Audit, adapter matrix, observability, traces, promotion loop | Audit/adapters/observability gates plus `docs/architecture/evaluator-rag-prototype.md`, `examples/evaluator-rag-prototype/`, and ECC-Tools PR #40 define read-only stale-salvage, billing-readiness, CI-failure-diagnosis, harness-config-quality, AgentShield policy-exception, skill-quality evidence, deep-analyzer evidence, and RAG/evaluator comparison scenarios with trace, report, playbook, verifier, and predictive-check artifacts; ECC-Tools PRs #68-#72 now turn that corpus into a deterministic PR check-run gate with cached hosted-output scoring, ranked retrieval candidates, a model prompt seed, a fail-closed hosted model-judge request contract, and opt-in live model execution behind strict hosted-evidence gates | Deterministic hosted PR check, cached output scoring, retrieval planning, judge contract, and gated model execution integrated | -| Linear roadmap is detailed | Linear project status plus repo mirror | Repo mirror exists; issue creation was retried on 2026-05-12 and remains blocked by the workspace free issue limit; the May 18 sync adds queue-zero/work-items state, #1970/#1971/#1972/#1976 merge evidence, ITO-57 current-head supply-chain refresh comment `0b9931b9-1556-4ebc-a70c-f3635557625d`, ITO-57 defensive-deny scanner recheck reply `6fa15367-d994-4e53-ade3-9462477e1100`, ECC platform progress comment `e32e5b7a-287b-4bf4-9ed7-314389a157e1`, and generated `operator:dashboard` prompt-to-artifact audit for recurring status updates | Needs recurring status updates after each significant merge batch | +| Linear roadmap is detailed | Linear project status plus repo mirror | Repo mirror exists and issue creation works again; the May 19 sync adds post-PR #2002 document `ecc-may-19-post-pr-2002-sync-64cef8f668e0`, project comment `a6411e3a-8c8e-4a58-adba-687e77d4c543`, ITO-44/47/48/49/51/54/56 issue comments, and In Progress state for ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56 | Needs recurring status updates after each significant merge batch | | Flow separation and progress tracking | Flow lanes with owner artifacts and update cadence | This roadmap defines lanes below and `docs/architecture/progress-sync-contract.md` makes GitHub/Linear/handoff/roadmap sync part of the readiness gate | Active | | Realtime Linear sync | Project comments while issue/status capacity is blocked; issues later | ECC-Tools #39 implements opt-in Linear API sync for deferred follow-up backlog items, and ECC-Tools #54 adds copy-ready PR drafts to that backlog when draft PR shells are not opened; `docs/architecture/progress-sync-contract.md` defines the local file-backed realtime boundary while issue capacity is blocked; May 18 live connector comments were posted to ITO-57 and the ECC platform project after project status updates returned disabled | Needs workspace capacity/config rollout for productized issue sync | | Observability for self-use | Local readiness gate, traces, status snapshots, HUD/status contract, risk ledger, progress-sync contract | `npm run observability:ready` reports 21/21 | Complete for local gate | diff --git a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md index d63d7d93..c2de9d9f 100644 --- a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md @@ -2,8 +2,8 @@ This dashboard is generated by `npm run operator:dashboard`. It is an operator snapshot, not release approval. -Generated: 2026-05-19T14:27:11.558Z -Commit: a11bad8a7ad5bb028eb884913abf20285aec01d1 +Generated: 2026-05-19T14:47:22.463Z +Commit: c7d662c3c68719e5ef0b5305ca3f6782b3214224 Status: work remaining ## Current Status @@ -44,7 +44,7 @@ Growth lanes: GitHub Sponsors and OSS partner sponsors; ECC Tools Pro subscripti | Advance AgentShield enterprise iteration | AgentShield PR evidence plus enterprise roadmap | in_progress | AgentShield policy promotion `reviewItems` landed in `87aec47`; package-manager hardening drift detection landed in `28d08c7`; workflow action runtime pins were refreshed in `659f569`; npm age-gate guidance was corrected in `ee585cd`; package-manager hardening Action outputs landed in `1124535`; policy-promotion Action outputs and runtime-smoke job-summary evidence landed in `1593925`; fleet review ticket payloads and current Mini Shai-Hulud IOC breadcrumbs landed in `840952a`; ECC-Tools consumes those outputs in `8658951`, surfaces operator-readable status/pack/count/digest telemetry in `16c537f`, and renders hosted promotion judge audit traces in `05d4e82`; all are mirrored in the GA roadmap | deepen live operator approval/readback after Marketplace/payment gates | | Advance ECC Tools native payments and AI-native harness-agnostic app | ECC Tools PR evidence, billing gate, hosted analysis lanes | in_progress | billing announcement gate, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler OAuth readback, target-account billing readback, provenance-aware Marketplace billing-state gates, sanitized Marketplace plan/action provenance counts, hosted team-learning feedback controls, and ECC-Tools Dependabot alert remediation are mirrored in the GA roadmap | create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure the target account and INTERNAL_API_SECRET, then rerun target readback and the live announcement gate | | Audit, prune, or attach legacy work | docs/stale-pr-salvage-ledger.md and legacy inventory | current | legacy salvage ledger and inventory are current; all localization tails are attached to Linear ITO-55 for manual language-owner review | repeat legacy scan before release | -| Keep Linear roadmap detailed and progress tracking synchronized | Linear project mirror plus progress-sync contract | current | Linear live sync and project progress surface are current; progress-sync contract defines the file-backed work-items/status path | repeat Linear/project status update and local work-items sync after each significant merge batch | +| Keep Linear roadmap detailed and progress tracking synchronized | Linear project mirror plus progress-sync contract | current | Linear live sync is current with the May 19 post-PR #2002 sync document, project comment, and active issue-lane updates; progress-sync contract defines the file-backed work-items/status path | repeat Linear/project status update and local work-items sync after each significant merge batch | | Provide ECC 2.0 observability for self-use | observability readiness gate | complete | observability:ready command and readiness doc exist | runtime/dashboard implementation can continue after release gates | | Keep Mini Shai-Hulud/TanStack protection loop current | supply-chain watch plus runbook plus AgentShield package-manager hardening | current | scheduled supply-chain watch emits IOC/advisory-source refresh artifacts; ECC scanner covers gh-token-monitor token-store persistence; AgentShield now detects known AI-tool persistence IOCs, npm lifecycle/token drift, unsupported npm age-key drift, and pnpm/Yarn cooldown drift; current-head watch evidence and ITO-57 May 18 Linear evidence updates are current | repeat advisory/source refresh and Linear sync after each significant supply-chain batch | diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index 13cc1d3c..959a2adc 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -25,7 +25,7 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-16.md` | Current May 16/17 queue cleanup, recsys skill merge, GateGuard triage, PR #1947 supply-chain protection, AgentShield #87 plugin-cache confidence evidence, AgentShield #88 evidence-pack inspect/readback, AgentShield #89 evidence-pack fleet routing, AgentShield #90 fleet review items, AgentShield #91 policy export, AgentShield #92 policy promotion, ECC-Tools #76 fleet-summary consumption, ECC-Tools #77 hosted finding evidence paths, ECC-Tools #78 harness policy-route linking, dashboard refresh, and combined Node/Rust/release-surface gate evidence through the May 16 mirror | Must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` | May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack protection recheck, npm audit/signature checks, legacy and Linear progress routing, deterministic preview-pack smoke, operator dashboard refresh, Linear sync, and GitHub CI evidence for `27dc2918` | Superseded by the May 18 evidence snapshot; repeat from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, supply-chain recheck, AgentShield evidence mirror, Linear sync, current-head CI/security scan success for `4470e2e6`, and ITO-46 naming/plugin publication closure | Superseded by the May 19 ECC identity, video, and growth evidence snapshot | -| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, May 19 operator dashboard, preview-pack smoke digest `790430aef4a8`, 2550-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, and PR #2001 owner approval packet CI success | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | +| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, May 19 operator dashboard, preview-pack smoke digest `790430aef4a8`, 2550-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, and the May 19 Linear sync document | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 19 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and adds the current `$1,728/mo` to `$10,000/mo` hypergrowth, video owner-approval, and outbound-pack operating lanes | diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md index 25e975b4..3931f39e 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -8,9 +8,9 @@ social announcement. | Field | Evidence | | --- | --- | -| Upstream main | `8148340ad14eb32c971346f0cb4cb9431ec0f5de` | +| Upstream main | `c7d662c3c68719e5ef0b5305ca3f6782b3214224` | | Git remote | `https://github.com/affaan-m/ECC.git` | -| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, and PR #2001 owner approval packet addition | +| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, PR #2001 owner approval packet addition, and PR #2002 owner approval dashboard gate refresh | | Local status caveat | `git status --short --branch` was clean after pulling `origin/main`; generated evidence files are committed after the source snapshot they describe | The release operator must repeat all publish-facing checks from the exact final @@ -23,7 +23,7 @@ release commit with a strictly clean checkout before publishing. | Platform audit | `node scripts/platform-audit.js --json` | Ready true; tracked repos report 0 open PRs, 0 open issues, 0 discussion maintainer-touch gaps, 0 answerable Q&A gaps, 0 conflicting PRs, and 0 blocking dirty files | | Trunk PRs | `gh pr list --repo affaan-m/ECC --state open --json number,title,url,author --limit 100` | `[]` | | Trunk issues | `gh issue list --repo affaan-m/ECC --state open --json number,title,url,author --limit 100` | `[]` | -| Discussion audit through platform audit | `node scripts/platform-audit.js --json` | `affaan-m/ECC` discussions enabled; 58 sampled; 0 needing maintainer touch; 0 answerable without accepted answer | +| Discussion audit through platform audit | `node scripts/platform-audit.js --json` | `affaan-m/ECC` discussions enabled; 59 sampled after #2003 AURA integration proposal; 0 needing maintainer touch; 0 answerable without accepted answer | | Worktree | `git status --short --branch` | `## main...origin/main` | Tracked repositories in the platform audit were: @@ -50,6 +50,7 @@ Tracked repositories in the platform audit were: | PR #1999 | Merged the operator dashboard refresh that moved the release video suite to current once publish-candidate evidence was recorded | | PR #2000 | Merged the suite-count evidence refresh so the platform audit rejects stale local-suite totals | | PR #2001 | Merged the final human decision sheet for release, package, plugin, video, billing, social, and outbound approvals; GitHub Actions run `26102500291` completed successfully | +| PR #2002 | Merged the owner-approval dashboard refresh so the operator dashboard fails closed when the final decision sheet is missing or incomplete; CI passed before merge | ## Release And Growth Evidence @@ -57,12 +58,14 @@ Tracked repositories in the platform audit were: | --- | --- | --- | | Release-surface tests | `node tests/docs/ecc2-release-surface.test.js` | 27 passed, 0 failed | | Preview-pack smoke | `npm run preview-pack:smoke -- --format json` | Ready true; digest `790430aef4a8`; 31 required artifacts; 5 passed, 0 failed | -| Operator dashboard | `npm run operator:dashboard -- --markdown --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Generated May 19 dashboard with platform audit ready true, 0 tracked PRs, 0 tracked issues, 0 discussion gaps, `$1,728/mo` current MRR, `$10,000/mo` target MRR, the release video suite marked current, and top actions for plugin publication, notifications, outbound approval, AgentShield, and ECC Tools billing | +| Operator dashboard | `npm run operator:dashboard -- --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Regenerated from `c7d662c3c68719e5ef0b5305ca3f6782b3214224` with platform audit ready true, 0 tracked PRs, 0 tracked issues, 0 discussion gaps, `$1,728/mo` current MRR, `$10,000/mo` target MRR, the release video suite marked current, and top actions for plugin publication, notifications, outbound approval, AgentShield, and ECC Tools billing | | Release video suite | `npm run release:video-suite -- --format json --summary` with `ECC_VIDEO_SOURCE_ROOT` and `ECC_VIDEO_RELEASE_SUITE_ROOT` | Ready true; 15/15 source assets present; 13/13 render, timeline, caption, EDL, and segment artifacts present; 12/12 publish-candidate outputs present with zero detected black-frame segments; primary rough render self-eval passed at 144.759 seconds, 1920x1080, 1 audio stream, and 106.78 MB | | Full local suite | `node tests/run-all.js` | 2550 passed, 0 failed | | PR #1998 CI | GitHub Actions run `26099020341` | Completed successfully for `d500de1e9f11c0446b6a1349bd98b522d31f9125`; all reported checks passed, including lint, validation, security scan, coverage, GitGuardian, CodeRabbit, Cubic, and the macOS/Ubuntu/Windows test matrix | | PR #1999 CI | GitHub Actions run `26100148726` | Completed successfully for `90584b6d5e5814bc2ad9a4cd651bebd043de989d`; lint, validation, security scan, coverage, GitGuardian, CodeRabbit, and the macOS/Ubuntu/Windows test matrix passed; Cubic completed neutral and did not block merge | | PR #2001 CI | GitHub Actions run `26102500291` | Completed successfully for `8148340ad14eb32c971346f0cb4cb9431ec0f5de`; required checks passed before merge | +| PR #2002 CI | GitHub Actions run `26103853507` | Completed successfully before merge; required checks passed, Cubic remained non-blocking, and PR #2002 merged into `main` as `c7d662c3c68719e5ef0b5305ca3f6782b3214224` | +| Linear sync | Linear document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` plus project comment `a6411e3a-8c8e-4a58-adba-687e77d4c543` | Project and issue lanes now record PR #2002 evidence, discussion #2003 routing, owner-approval dashboard gate, and In Progress status for ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56 | | Public-path sanitization | `node scripts/ci/validate-no-personal-paths.js` through local suite and CI | Passed | | Markdown and whitespace | `markdownlint` focused release docs plus `git diff --check` before PR #1999 | Passed | @@ -77,6 +80,7 @@ Tracked repositories in the platform audit were: | Owner approval proof | `owner-approval-packet-2026-05-19.md` centralizes release, package, plugin, video, billing, social, and outbound decision gates | | Business baseline | Hypergrowth command center and partner pack use `$1,728/mo` current MRR, `$10,000/mo` target MRR, and `$8,272/mo` gap | | Operator dashboard | `operator-readiness-dashboard-2026-05-19.md` pulls the growth baseline into the same queue, publication, video, outbound, AgentShield, ECC Tools, Linear, and supply-chain control surface | +| Linear progress proof | Linear project document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` mirrors the post-PR #2002 state and records active lanes for launch materials, AgentShield, ECC Tools deep analysis, observability, and final release publication | ## Current Publication Blockers @@ -102,7 +106,7 @@ Tracked repositories in the platform audit were: The tracked public PR queue, issue queue, discussion queue, canonical ECC identity, release video suite, preview pack, and growth outreach packet are current on May 19, 2026 for `main` through -`e7a7b2aaa33c0657cad9db3fa2ced0e636cd0f8c`. The remaining video work is +`c7d662c3c68719e5ef0b5305ca3f6782b3214224`. The remaining video work is owner approval, upload, and public URL attachment, not render or QA production. This improves publication readiness but does not replace the approval-gated diff --git a/scripts/operator-readiness-dashboard.js b/scripts/operator-readiness-dashboard.js index 5e52fbbf..365f543f 100644 --- a/scripts/operator-readiness-dashboard.js +++ b/scripts/operator-readiness-dashboard.js @@ -458,9 +458,12 @@ function supplyChainLocalProtectionGap({ roadmap, scripts }) { function hasCurrentLinearProgressSync({ roadmap, progressSync }) { const hasOperatorProgressSurface = roadmap.includes('operator progress snapshot') || roadmap.includes('operator progress comment'); + const hasMay19ProgressSurface = roadmap.includes('ecc-may-19-post-pr-2002-sync-64cef8f668e0') + && roadmap.includes('a6411e3a-8c8e-4a58-adba-687e77d4c543') + && roadmap.includes('ITO-56'); return roadmap.includes('Linear live sync is current') - && hasOperatorProgressSurface + && (hasOperatorProgressSurface || hasMay19ProgressSurface) && includesAll(progressSync, [ 'node scripts/work-items.js sync-github --repo ', 'node scripts/status.js --json', @@ -483,6 +486,10 @@ function linearProgressStatus(context) { function linearProgressEvidence(context) { if (hasCurrentLinearProgressSync(context)) { + if (context.roadmap.includes('ecc-may-19-post-pr-2002-sync-64cef8f668e0')) { + return 'Linear live sync is current with the May 19 post-PR #2002 sync document, project comment, and active issue-lane updates; progress-sync contract defines the file-backed work-items/status path'; + } + return 'Linear live sync and project progress surface are current; progress-sync contract defines the file-backed work-items/status path'; } diff --git a/tests/docs/ecc2-release-surface.test.js b/tests/docs/ecc2-release-surface.test.js index 34eee09f..f635f374 100644 --- a/tests/docs/ecc2-release-surface.test.js +++ b/tests/docs/ecc2-release-surface.test.js @@ -259,6 +259,9 @@ test('GA roadmap mirrors the current May 19 release evidence', () => { 'local 2550-test suite', 'PR #2001', 'GitHub Actions run `26102500291`', + 'PR #2002', + 'GitHub Actions run `26103853507`', + 'ecc-may-19-post-pr-2002-sync-64cef8f668e0', 'owner approval packet', ]) { assert.ok(roadmap.includes(marker), `GA roadmap missing current evidence marker ${marker}`); From d6022d6b8dc5ef1393cf18ae40ee58f646f3754e Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 11:10:51 -0400 Subject: [PATCH 43/61] docs: refresh may 19 evidence after linear sync merge --- docs/ECC-2.0-GA-ROADMAP.md | 17 +++++++++-------- .../operator-readiness-dashboard-2026-05-19.md | 4 ++-- .../owner-approval-packet-2026-05-19.md | 4 ++-- .../2.0.0-rc.1/preview-pack-manifest.md | 2 +- .../publication-evidence-2026-05-19.md | 10 ++++++---- 5 files changed, 20 insertions(+), 17 deletions(-) diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index 9d6b89ef..ee133d6f 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -86,10 +86,11 @@ As of 2026-05-19: suite gate, partner/sponsor/talk outreach pack, owner approval packet (`owner-approval-packet-2026-05-19.md`), preview-pack smoke digest `790430aef4a8`, local 2550-test suite, PR #2001 merge and GitHub Actions run - `26102500291` success, plus PR #2002's owner-approval dashboard gate refresh, - GitHub Actions run `26103853507`, and the May 19 Linear sync document. The - May 18 evidence remains the detailed supply-chain and publication-path - snapshot. + `26102500291` success, PR #2002's owner-approval dashboard gate refresh and + GitHub Actions run `26103853507`, plus PR #2004's Linear readiness evidence + sync and GitHub Actions run `26105012698`. The May 19 Linear sync document + remains the current external project status surface, and the May 18 evidence + remains the detailed supply-chain and publication-path snapshot. - `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` regenerates the ITO-44 prompt-to-artifact dashboard from live platform audit evidence: PR queue, issue queue, discussion queue, local worktree gate, @@ -742,12 +743,12 @@ is not complete unless the evidence column exists and has been freshly verified. | Prompt requirement | Required artifact or gate | Current evidence | Status | | --- | --- | --- | --- | -| Keep public PRs below 20 | Repo-family PR recheck | 0 open PRs across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-19 after merging PR #2002 and refreshing platform audit evidence | Complete | +| Keep public PRs below 20 | Repo-family PR recheck | 0 open PRs across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-19 after merging PR #2004 and refreshing platform audit evidence | Complete | | Keep public issues below 20 | Repo-family issue recheck | 0 open issues across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-19 after the live platform audit refresh | Complete | | Manage repository discussions | Repo-family discussion recheck plus response playbook | Platform audit reports 0 discussion maintainer-touch gaps and 0 answerable Q&A missing accepted answers; trunk has 59 total discussions after #2003 was routed with a maintainer response; `docs/architecture/discussion-response-playbook.md` distinguishes support, maintainer coordination, stale/concluded, release, informational, and security-sensitive response paths | Complete | -| Manage PR discussions | PR review/comment closure plus merge/close state | ECC #1990-#2002 merged through the harness audit, canonical identity, release video suite, growth outreach, evidence refresh, visual QA, suite-count, owner-approval packet, and owner-approval dashboard gate batch; no open tracked PRs remain | Complete | +| Manage PR discussions | PR review/comment closure plus merge/close state | ECC #1990-#2004 merged through the harness audit, canonical identity, release video suite, growth outreach, evidence refresh, visual QA, suite-count, owner-approval packet, owner-approval dashboard gate, and Linear readiness evidence batch; no open tracked PRs remain | Complete | | Salvage useful stale work | `docs/stale-pr-salvage-ledger.md` plus `docs/legacy-artifact-inventory.md` | Ledger records salvaged, superseded, skipped, and manual-review tails; #1815-#1818 added cost tracking, skill scout, frontend design guidance, code-reviewer false-positive guardrails, and the May 12 gap pass; #1687, #1609, #1563, #1564, and #1565 localization tails are attached to Linear ITO-55 for language-owner review and no automatic import remains release-blocking | Complete; repeat legacy scan before release | -| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 19 evidence records queue-zero state, canonical ECC identity, release video suite, growth outreach pack, owner approval packet, local 2550-test suite, PR #2001 merge and GitHub Actions run `26102500291`, PR #2002 owner-approval dashboard gate refresh and GitHub Actions run `26103853507`, May 19 operator dashboard, `owner-approval-packet-2026-05-19.md`, and preview-pack smoke digest `790430aef4a8` | Needs final release approval | +| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 19 evidence records queue-zero state, canonical ECC identity, release video suite, growth outreach pack, owner approval packet, local 2550-test suite, PR #2001 merge and GitHub Actions run `26102500291`, PR #2002 owner-approval dashboard gate refresh and GitHub Actions run `26103853507`, PR #2004 Linear readiness evidence sync and GitHub Actions run `26105012698`, May 19 operator dashboard, `owner-approval-packet-2026-05-19.md`, and preview-pack smoke digest `790430aef4a8` | Needs final release approval | | Hermes specialized skills included safely | Hermes setup/import docs and sanitized skill surface | Hermes setup and import playbook are public; secrets stay local | Needs final release review | | Naming and rename readiness | Naming matrix across package/plugin/docs/social surfaces | `docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md` records current package, repo, Claude plugin, Codex plugin, OpenCode, and npm availability evidence | Complete for rc.1; post-rc rename remains future work | | Claude and Codex plugin publication | Contact/submission path with required artifacts and status | Publication readiness, naming matrix, and May 12 dry-run evidence document plugin validation, clean-checkout Claude tag/install smoke, and Codex marketplace CLI shape | Needs explicit approval for real tag/push and marketplace submission | @@ -756,7 +757,7 @@ is not complete unless the evidence column exists and has been freshly verified. | ECC Tools next-level app | Billing audit, PR checks, deep analyzer, sync backlog, evaluator/RAG corpus, analysis-depth readiness, hosted execution planning, hosted CI diagnostics, hosted security evidence review, hosted harness compatibility audit, hosted reference-set evaluation, hosted AI routing/cost review, hosted team backlog routing, hosted depth-plan check-run, PR-comment hosted job dispatch, hosted job result history/check-runs, hosted result status command, status-aware depth-plan recommendations, hosted promotion readiness, hosted promotion output scoring, hosted promotion retrieval planning, hosted promotion judge contract, gated hosted promotion judge execution, hosted promotion judge audit trace, payment-announcement readiness, billing announcement preflight, aggregate production billing KV readback, Marketplace webhook provenance, target-account billing readback, Marketplace-source provenance counts, AgentShield fleet-summary hosted routing, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output hosted telemetry, and operator-visible promotion output values | PRs #26-#43 plus #53-#78 landed with test evidence, including AgentShield evidence-pack gap routing, canonical bundle recognition, supply-chain signature gates, PR draft follow-up Linear tracking, evidence-backed/deep-ready repository classification, the `/api/analysis/depth-plan` hosted job plan, `/api/analysis/jobs/ci-diagnostics`, `/api/analysis/jobs/security-evidence-review`, `/api/analysis/jobs/harness-compatibility-audit`, `/api/analysis/jobs/reference-set-evaluation`, `/api/analysis/jobs/ai-routing-cost-review`, `/api/analysis/jobs/team-backlog-routing`, the `ECC Tools / Hosted Depth Plan` check-run, `/ecc-tools analyze --job ...` PR-comment dispatch, non-blocking per-hosted-job result check-runs backed by 30-day result cache records, `/ecc-tools analyze --job status` cache lookup, cache-aware next-job recommendations in the depth-plan check-run, the `ECC Tools / Hosted Promotion Readiness` corpus-backed PR check-run, deterministic hosted-output scoring against cached completed job artifacts/findings, ranked retrieval/model-prompt planning, the fail-closed `hosted-promotion-judge.v1` request contract, opt-in live model-judge execution behind hosted evidence, entitlement, budget, provider, executor, strict JSON, and citation gates, hosted promotion judge request fingerprints plus allowed-citation audit trails, a fail-closed `/api/billing/readiness` `announcementGate` for native GitHub payments claims, `npm run billing:announcement-gate` plus `--preflight` as the non-secret operator verifier, hosted security findings for AgentShield fleet summaries, an `Evidence` column in hosted finding comments/check-runs, hosted harness findings that route AgentShield fleet target paths to harness owners, ECC-Tools commit `8658951` routing AgentShield policy-promotion Action outputs into hosted security review and promotion-readiness scoring, ECC-Tools commit `16c537f` rendering policy-promotion status/pack/count/digest values directly in hosted security job comments/check-runs, ECC-Tools commit `05d4e82` rendering model-judge audit traces without exposing raw provider output, ECC-Tools commit `91a441b` adding the safe billing announcement preflight path, ECC-Tools commit `eb69412` recording the initial production readback state, ECC-Tools commit `95d0bec` adding `npm run billing:kv-readback` with aggregate account-billing and billing-state records but 0 Marketplace Pro billing-state records, ECC-Tools commit `2859678` requiring webhook-derived Marketplace provenance before announcement readiness, ECC-Tools commit `42653f9` adding Wrangler OAuth readback, ECC-Tools commit `632e059` adding sanitized target-account readback that requires both target key families before `--require-ready` can pass, and ECC-Tools commit `d5f60db` adding sanitized Marketplace plan/action provenance counts; the latest 2026-05-18 live Wrangler OAuth recheck found 256 account-billing records, 256 billing-state records, 197 Marketplace-source records, 4 Marketplace webhook-provenance records, all `Open Source`, and 0 Marketplace Pro records, then updated Linear ITO-61 with the data/provisioning blocker | Next work is create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure target account plus `INTERNAL_API_SECRET`, then run `billing:kv-readback -- --wrangler --wrangler-bin ./node_modules/.bin/wrangler --account --require-ready`, followed by the live announcement gate | | GitGuardian/Dependabot/CodeRabbit-style checks | Non-blocking taxonomy, deterministic follow-up checks, and local supply-chain gates | ECC-Tools risk taxonomy check plus follow-up signals landed, including Skill Quality, Deep Analyzer Evidence, Analyzer Corpus Evidence, RAG/Evaluator Evidence, PR Review/Salvage Evidence, and AgentShield evidence-pack evidence; #1846 added npm registry signature gates; #1848 added the supply-chain incident-response playbook and `pull_request_target` cache-poisoning validator guard; #1851 added the privileged checkout credential-persistence guard; AgentShield #78, JARVIS #13, and ECC-Tools #53 applied the same hardening outside trunk | Current supply-chain gate complete; deeper hosted review features remain future | | Harness-agnostic learning system | Audit, adapter matrix, observability, traces, promotion loop | Audit/adapters/observability gates plus `docs/architecture/evaluator-rag-prototype.md`, `examples/evaluator-rag-prototype/`, and ECC-Tools PR #40 define read-only stale-salvage, billing-readiness, CI-failure-diagnosis, harness-config-quality, AgentShield policy-exception, skill-quality evidence, deep-analyzer evidence, and RAG/evaluator comparison scenarios with trace, report, playbook, verifier, and predictive-check artifacts; ECC-Tools PRs #68-#72 now turn that corpus into a deterministic PR check-run gate with cached hosted-output scoring, ranked retrieval candidates, a model prompt seed, a fail-closed hosted model-judge request contract, and opt-in live model execution behind strict hosted-evidence gates | Deterministic hosted PR check, cached output scoring, retrieval planning, judge contract, and gated model execution integrated | -| Linear roadmap is detailed | Linear project status plus repo mirror | Repo mirror exists and issue creation works again; the May 19 sync adds post-PR #2002 document `ecc-may-19-post-pr-2002-sync-64cef8f668e0`, project comment `a6411e3a-8c8e-4a58-adba-687e77d4c543`, ITO-44/47/48/49/51/54/56 issue comments, and In Progress state for ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56 | Needs recurring status updates after each significant merge batch | +| Linear roadmap is detailed | Linear project status plus repo mirror | Repo mirror exists and issue creation works again; the May 19 sync adds post-PR #2002 document `ecc-may-19-post-pr-2002-sync-64cef8f668e0`, project comment `a6411e3a-8c8e-4a58-adba-687e77d4c543`, ITO-44/47/48/49/51/54/56 issue comments, and In Progress state for ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56; PR #2004 mirrors that sync into the repo evidence set | Needs recurring status updates after each significant merge batch | | Flow separation and progress tracking | Flow lanes with owner artifacts and update cadence | This roadmap defines lanes below and `docs/architecture/progress-sync-contract.md` makes GitHub/Linear/handoff/roadmap sync part of the readiness gate | Active | | Realtime Linear sync | Project comments while issue/status capacity is blocked; issues later | ECC-Tools #39 implements opt-in Linear API sync for deferred follow-up backlog items, and ECC-Tools #54 adds copy-ready PR drafts to that backlog when draft PR shells are not opened; `docs/architecture/progress-sync-contract.md` defines the local file-backed realtime boundary while issue capacity is blocked; May 18 live connector comments were posted to ITO-57 and the ECC platform project after project status updates returned disabled | Needs workspace capacity/config rollout for productized issue sync | | Observability for self-use | Local readiness gate, traces, status snapshots, HUD/status contract, risk ledger, progress-sync contract | `npm run observability:ready` reports 21/21 | Complete for local gate | diff --git a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md index c2de9d9f..83125f03 100644 --- a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md @@ -2,8 +2,8 @@ This dashboard is generated by `npm run operator:dashboard`. It is an operator snapshot, not release approval. -Generated: 2026-05-19T14:47:22.463Z -Commit: c7d662c3c68719e5ef0b5305ca3f6782b3214224 +Generated: 2026-05-19T15:08:49.870Z +Commit: ac7434ea8f39166b11e9d06ce64b38c4fb8d9202 Status: work remaining ## Current Status diff --git a/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md b/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md index ff7b85a2..d60d765a 100644 --- a/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md @@ -8,7 +8,7 @@ release action after the final evidence commands are rerun from the intended release commit. Source commit for the clean evidence baseline this packet extends: -`e7a7b2aaa33c0657cad9db3fa2ced0e636cd0f8c`. +`ac7434ea8f39166b11e9d06ce64b38c4fb8d9202`. ## Current Evidence @@ -19,7 +19,7 @@ Source commit for the clean evidence baseline this packet extends: | Video suite | ready true, 15/15 source assets, 13/13 suite artifacts, 12/12 publish candidates | yes | | Release surface tests | 27/27 passed after this packet was added | yes | | Full local suite | 2550/2550 passed after this packet was added | yes | -| GitHub CI | PR #1998, PR #1999, PR #2000, and PR #2001 merged after green required checks | verify current head | +| GitHub CI | PR #1998, PR #1999, PR #2000, PR #2001, PR #2002, and PR #2004 merged after green required checks | verify current head | ## Decision Register diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index 959a2adc..f15a7d62 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -25,7 +25,7 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-16.md` | Current May 16/17 queue cleanup, recsys skill merge, GateGuard triage, PR #1947 supply-chain protection, AgentShield #87 plugin-cache confidence evidence, AgentShield #88 evidence-pack inspect/readback, AgentShield #89 evidence-pack fleet routing, AgentShield #90 fleet review items, AgentShield #91 policy export, AgentShield #92 policy promotion, ECC-Tools #76 fleet-summary consumption, ECC-Tools #77 hosted finding evidence paths, ECC-Tools #78 harness policy-route linking, dashboard refresh, and combined Node/Rust/release-surface gate evidence through the May 16 mirror | Must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` | May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack protection recheck, npm audit/signature checks, legacy and Linear progress routing, deterministic preview-pack smoke, operator dashboard refresh, Linear sync, and GitHub CI evidence for `27dc2918` | Superseded by the May 18 evidence snapshot; repeat from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, supply-chain recheck, AgentShield evidence mirror, Linear sync, current-head CI/security scan success for `4470e2e6`, and ITO-46 naming/plugin publication closure | Superseded by the May 19 ECC identity, video, and growth evidence snapshot | -| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, May 19 operator dashboard, preview-pack smoke digest `790430aef4a8`, 2550-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, and the May 19 Linear sync document | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | +| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, May 19 operator dashboard, preview-pack smoke digest `790430aef4a8`, 2550-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, PR #2004 Linear readiness evidence sync CI success, and the May 19 Linear sync document | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 19 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and adds the current `$1,728/mo` to `$10,000/mo` hypergrowth, video owner-approval, and outbound-pack operating lanes | diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md index 3931f39e..d954c65d 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -8,9 +8,9 @@ social announcement. | Field | Evidence | | --- | --- | -| Upstream main | `c7d662c3c68719e5ef0b5305ca3f6782b3214224` | +| Upstream main | `ac7434ea8f39166b11e9d06ce64b38c4fb8d9202` | | Git remote | `https://github.com/affaan-m/ECC.git` | -| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, PR #2001 owner approval packet addition, and PR #2002 owner approval dashboard gate refresh | +| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, PR #2001 owner approval packet addition, PR #2002 owner approval dashboard gate refresh, and PR #2004 Linear readiness evidence sync | | Local status caveat | `git status --short --branch` was clean after pulling `origin/main`; generated evidence files are committed after the source snapshot they describe | The release operator must repeat all publish-facing checks from the exact final @@ -51,6 +51,7 @@ Tracked repositories in the platform audit were: | PR #2000 | Merged the suite-count evidence refresh so the platform audit rejects stale local-suite totals | | PR #2001 | Merged the final human decision sheet for release, package, plugin, video, billing, social, and outbound approvals; GitHub Actions run `26102500291` completed successfully | | PR #2002 | Merged the owner-approval dashboard refresh so the operator dashboard fails closed when the final decision sheet is missing or incomplete; CI passed before merge | +| PR #2004 | Merged the May 19 Linear readiness evidence sync after PR #2002, including roadmap, dashboard, preview-pack manifest, publication evidence, operator dashboard generator, and release-surface test updates | ## Release And Growth Evidence @@ -58,13 +59,14 @@ Tracked repositories in the platform audit were: | --- | --- | --- | | Release-surface tests | `node tests/docs/ecc2-release-surface.test.js` | 27 passed, 0 failed | | Preview-pack smoke | `npm run preview-pack:smoke -- --format json` | Ready true; digest `790430aef4a8`; 31 required artifacts; 5 passed, 0 failed | -| Operator dashboard | `npm run operator:dashboard -- --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Regenerated from `c7d662c3c68719e5ef0b5305ca3f6782b3214224` with platform audit ready true, 0 tracked PRs, 0 tracked issues, 0 discussion gaps, `$1,728/mo` current MRR, `$10,000/mo` target MRR, the release video suite marked current, and top actions for plugin publication, notifications, outbound approval, AgentShield, and ECC Tools billing | +| Operator dashboard | `npm run operator:dashboard -- --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Regenerated from `ac7434ea8f39166b11e9d06ce64b38c4fb8d9202` with platform audit ready true, 0 tracked PRs, 0 tracked issues, 0 discussion gaps, `$1,728/mo` current MRR, `$10,000/mo` target MRR, the release video suite marked current, and top actions for plugin publication, notifications, outbound approval, AgentShield, and ECC Tools billing | | Release video suite | `npm run release:video-suite -- --format json --summary` with `ECC_VIDEO_SOURCE_ROOT` and `ECC_VIDEO_RELEASE_SUITE_ROOT` | Ready true; 15/15 source assets present; 13/13 render, timeline, caption, EDL, and segment artifacts present; 12/12 publish-candidate outputs present with zero detected black-frame segments; primary rough render self-eval passed at 144.759 seconds, 1920x1080, 1 audio stream, and 106.78 MB | | Full local suite | `node tests/run-all.js` | 2550 passed, 0 failed | | PR #1998 CI | GitHub Actions run `26099020341` | Completed successfully for `d500de1e9f11c0446b6a1349bd98b522d31f9125`; all reported checks passed, including lint, validation, security scan, coverage, GitGuardian, CodeRabbit, Cubic, and the macOS/Ubuntu/Windows test matrix | | PR #1999 CI | GitHub Actions run `26100148726` | Completed successfully for `90584b6d5e5814bc2ad9a4cd651bebd043de989d`; lint, validation, security scan, coverage, GitGuardian, CodeRabbit, and the macOS/Ubuntu/Windows test matrix passed; Cubic completed neutral and did not block merge | | PR #2001 CI | GitHub Actions run `26102500291` | Completed successfully for `8148340ad14eb32c971346f0cb4cb9431ec0f5de`; required checks passed before merge | | PR #2002 CI | GitHub Actions run `26103853507` | Completed successfully before merge; required checks passed, Cubic remained non-blocking, and PR #2002 merged into `main` as `c7d662c3c68719e5ef0b5305ca3f6782b3214224` | +| PR #2004 CI | GitHub Actions run `26105012698` | Completed successfully after rerunning the single failed Windows Node 18 yarn job; required checks passed, Cubic remained non-blocking, and PR #2004 merged into `main` as `ac7434ea8f39166b11e9d06ce64b38c4fb8d9202` | | Linear sync | Linear document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` plus project comment `a6411e3a-8c8e-4a58-adba-687e77d4c543` | Project and issue lanes now record PR #2002 evidence, discussion #2003 routing, owner-approval dashboard gate, and In Progress status for ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56 | | Public-path sanitization | `node scripts/ci/validate-no-personal-paths.js` through local suite and CI | Passed | | Markdown and whitespace | `markdownlint` focused release docs plus `git diff --check` before PR #1999 | Passed | @@ -106,7 +108,7 @@ Tracked repositories in the platform audit were: The tracked public PR queue, issue queue, discussion queue, canonical ECC identity, release video suite, preview pack, and growth outreach packet are current on May 19, 2026 for `main` through -`c7d662c3c68719e5ef0b5305ca3f6782b3214224`. The remaining video work is +`ac7434ea8f39166b11e9d06ce64b38c4fb8d9202`. The remaining video work is owner approval, upload, and public URL attachment, not render or QA production. This improves publication readiness but does not replace the approval-gated From 27e4036075714bab8eafd8ee6b0645c97988c83b Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 11:47:40 -0400 Subject: [PATCH 44/61] Fix release supply-chain evidence gate --- docs/ECC-2.0-GA-ROADMAP.md | 13 +++--- .../publication-evidence-2026-05-19.md | 11 +++-- .../2.0.0-rc.1/publication-readiness.md | 26 ++++++------ package-lock.json | 40 +++++++++---------- package.json | 2 +- tests/docs/ecc2-release-surface.test.js | 2 +- yarn.lock | 32 +++++++-------- 7 files changed, 66 insertions(+), 60 deletions(-) diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index ee133d6f..58655881 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -87,10 +87,13 @@ As of 2026-05-19: (`owner-approval-packet-2026-05-19.md`), preview-pack smoke digest `790430aef4a8`, local 2550-test suite, PR #2001 merge and GitHub Actions run `26102500291` success, PR #2002's owner-approval dashboard gate refresh and - GitHub Actions run `26103853507`, plus PR #2004's Linear readiness evidence - sync and GitHub Actions run `26105012698`. The May 19 Linear sync document - remains the current external project status surface, and the May 18 evidence - remains the detailed supply-chain and publication-path snapshot. + GitHub Actions run `26103853507`, PR #2004's Linear readiness evidence sync + and GitHub Actions run `26105012698`, plus PR #2005's post-PR #2004 + evidence refresh and GitHub Actions run `26106321921`. The May 19 Linear + sync document remains the current external project status surface, and the + supply-chain gate now also records the `@types/node@25.7.0` pin and + `brace-expansion` lock refresh needed for current npm audit/signature + verification. - `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` regenerates the ITO-44 prompt-to-artifact dashboard from live platform audit evidence: PR queue, issue queue, discussion queue, local worktree gate, @@ -118,7 +121,7 @@ As of 2026-05-19: finding evidence paths, ECC-Tools #78 harness policy-route linking, PR #1947 supply-chain protection, and May 16 release-evidence refresh. -- `npm run harness:audit -- --format json` reports 70/70 on current `main`. +- `npm run harness:audit -- --format json` reports 80/80 on current `main`. - `npm run observability:ready` reports 21/21 readiness on current `main`, including the GitHub/Linear/handoff/roadmap progress-sync contract. - GitHub CI run `26017368895` completed successfully for diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md index d954c65d..d3ca65b8 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -8,9 +8,9 @@ social announcement. | Field | Evidence | | --- | --- | -| Upstream main | `ac7434ea8f39166b11e9d06ce64b38c4fb8d9202` | +| Upstream main | `d6022d6b8dc5ef1393cf18ae40ee58f646f3754e` | | Git remote | `https://github.com/affaan-m/ECC.git` | -| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, PR #2001 owner approval packet addition, PR #2002 owner approval dashboard gate refresh, and PR #2004 Linear readiness evidence sync | +| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, PR #2001 owner approval packet addition, PR #2002 owner approval dashboard gate refresh, PR #2004 Linear readiness evidence sync, and PR #2005 post-PR #2004 evidence refresh | | Local status caveat | `git status --short --branch` was clean after pulling `origin/main`; generated evidence files are committed after the source snapshot they describe | The release operator must repeat all publish-facing checks from the exact final @@ -52,6 +52,7 @@ Tracked repositories in the platform audit were: | PR #2001 | Merged the final human decision sheet for release, package, plugin, video, billing, social, and outbound approvals; GitHub Actions run `26102500291` completed successfully | | PR #2002 | Merged the owner-approval dashboard refresh so the operator dashboard fails closed when the final decision sheet is missing or incomplete; CI passed before merge | | PR #2004 | Merged the May 19 Linear readiness evidence sync after PR #2002, including roadmap, dashboard, preview-pack manifest, publication evidence, operator dashboard generator, and release-surface test updates | +| PR #2005 | Merged the post-PR #2004 evidence refresh, keeping the May 19 readiness ledger, dashboard, roadmap, and release-surface references current on `main` | ## Release And Growth Evidence @@ -59,7 +60,8 @@ Tracked repositories in the platform audit were: | --- | --- | --- | | Release-surface tests | `node tests/docs/ecc2-release-surface.test.js` | 27 passed, 0 failed | | Preview-pack smoke | `npm run preview-pack:smoke -- --format json` | Ready true; digest `790430aef4a8`; 31 required artifacts; 5 passed, 0 failed | -| Operator dashboard | `npm run operator:dashboard -- --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Regenerated from `ac7434ea8f39166b11e9d06ce64b38c4fb8d9202` with platform audit ready true, 0 tracked PRs, 0 tracked issues, 0 discussion gaps, `$1,728/mo` current MRR, `$10,000/mo` target MRR, the release video suite marked current, and top actions for plugin publication, notifications, outbound approval, AgentShield, and ECC Tools billing | +| Operator dashboard | `npm run operator:dashboard -- --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Regenerated from the May 19 `main` baseline with platform audit ready true, 0 tracked PRs, 0 tracked issues, 0 discussion gaps, `$1,728/mo` current MRR, `$10,000/mo` target MRR, the release video suite marked current, and top actions for plugin publication, notifications, outbound approval, AgentShield, and ECC Tools billing | +| Supply-chain verification | `npm audit --audit-level=moderate`; `npm audit signatures`; `yarn install --immutable --mode=skip-build` | Current supply-chain refresh found 0 npm vulnerabilities, verified 254 registry signatures and 30 attestations, and accepted the Yarn lock after pinning `@types/node@25.7.0` plus refreshing `brace-expansion` to `5.0.6` / `1.1.14` | | Release video suite | `npm run release:video-suite -- --format json --summary` with `ECC_VIDEO_SOURCE_ROOT` and `ECC_VIDEO_RELEASE_SUITE_ROOT` | Ready true; 15/15 source assets present; 13/13 render, timeline, caption, EDL, and segment artifacts present; 12/12 publish-candidate outputs present with zero detected black-frame segments; primary rough render self-eval passed at 144.759 seconds, 1920x1080, 1 audio stream, and 106.78 MB | | Full local suite | `node tests/run-all.js` | 2550 passed, 0 failed | | PR #1998 CI | GitHub Actions run `26099020341` | Completed successfully for `d500de1e9f11c0446b6a1349bd98b522d31f9125`; all reported checks passed, including lint, validation, security scan, coverage, GitGuardian, CodeRabbit, Cubic, and the macOS/Ubuntu/Windows test matrix | @@ -67,6 +69,7 @@ Tracked repositories in the platform audit were: | PR #2001 CI | GitHub Actions run `26102500291` | Completed successfully for `8148340ad14eb32c971346f0cb4cb9431ec0f5de`; required checks passed before merge | | PR #2002 CI | GitHub Actions run `26103853507` | Completed successfully before merge; required checks passed, Cubic remained non-blocking, and PR #2002 merged into `main` as `c7d662c3c68719e5ef0b5305ca3f6782b3214224` | | PR #2004 CI | GitHub Actions run `26105012698` | Completed successfully after rerunning the single failed Windows Node 18 yarn job; required checks passed, Cubic remained non-blocking, and PR #2004 merged into `main` as `ac7434ea8f39166b11e9d06ce64b38c4fb8d9202` | +| PR #2005 CI | GitHub Actions run `26106321921` | Completed successfully with 37 completed jobs, 0 failed jobs, and PR #2005 merged into `main` as `d6022d6b8dc5ef1393cf18ae40ee58f646f3754e` | | Linear sync | Linear document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` plus project comment `a6411e3a-8c8e-4a58-adba-687e77d4c543` | Project and issue lanes now record PR #2002 evidence, discussion #2003 routing, owner-approval dashboard gate, and In Progress status for ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56 | | Public-path sanitization | `node scripts/ci/validate-no-personal-paths.js` through local suite and CI | Passed | | Markdown and whitespace | `markdownlint` focused release docs plus `git diff --check` before PR #1999 | Passed | @@ -108,7 +111,7 @@ Tracked repositories in the platform audit were: The tracked public PR queue, issue queue, discussion queue, canonical ECC identity, release video suite, preview pack, and growth outreach packet are current on May 19, 2026 for `main` through -`ac7434ea8f39166b11e9d06ce64b38c4fb8d9202`. The remaining video work is +`d6022d6b8dc5ef1393cf18ae40ee58f646f3754e`. The remaining video work is owner approval, upload, and public URL attachment, not render or QA production. This improves publication readiness but does not replace the approval-gated diff --git a/docs/releases/2.0.0-rc.1/publication-readiness.md b/docs/releases/2.0.0-rc.1/publication-readiness.md index 84e7131b..32900601 100644 --- a/docs/releases/2.0.0-rc.1/publication-readiness.md +++ b/docs/releases/2.0.0-rc.1/publication-readiness.md @@ -101,22 +101,22 @@ Record the exact commit SHA and command output before any publication action: | Evidence | Command | Required result | Recorded output | | --- | --- | --- | --- | -| Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | `3304848b`: `## main...origin/main`; repeat from the exact final publication commit before release | +| Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | Post-PR #2005 baseline `d6022d6b8dc5ef1393cf18ae40ee58f646f3754e`: `## main...origin/main`; repeat from the exact final publication commit before release | | Preview-pack smoke | `npm run preview-pack:smoke` | Preview pack artifacts, Hermes boundary, final verification command list, and publication blockers pass | `publication-evidence-2026-05-19.md`: ready yes, digest `790430aef4a8`, 31 artifacts, 5 passed, 0 failed; repeat in the final strict clean-checkout release pass | -| Harness audit | `npm run harness:audit -- --format json` | 70/70 passing | `99e01ded`: 70/70, 0 top actions | -| Adapter scorecard | `npm run harness:adapters -- --check` | PASS | `99e01ded`: PASS, 11 adapters | -| Observability readiness | `npm run observability:ready` | 21/21 passing | `publication-evidence-2026-05-18.md`: 21/21, ready yes | -| Release safety gate | `npm run observability:ready -- --format json` | Release Safety category passing with publication readiness, supply-chain, workflow security, package surface, and release-surface evidence | May 18 evidence keeps release safety passing; repeat the JSON gate from the exact final release commit | -| Supply-chain verification | `npm audit --json`; `npm audit signatures`; `cd ecc2 && cargo audit -q`; Dependabot alerts; GitGuardian Security Checks | 0 vulnerabilities/alerts, registry signatures verified, GitGuardian clean | `publication-evidence-2026-05-19.md` plus CI `26093792219`: GitGuardian and security scan passed; prior May 18 npm registry signatures and IOC scans remain the latest detailed supply-chain evidence | -| Root suite | `node tests/run-all.js` | 0 failures | Current dashboard branch: local `node tests/run-all.js` passed 2550/2550; PR #2001 CI `26102500291` passed the previous full OS/runtime/package-manager matrix | -| Markdown lint | `npx markdownlint-cli '**/*.md' --ignore node_modules` | 0 failures | CI `26093792219`: markdownlint passed on the growth-pack PR; rerun after any release-copy edits | -| Package surface | `node tests/scripts/npm-publish-surface.test.js` | 0 failures; no Python bytecode in npm tarball | `2/2` passed in May 12 evidence pass | -| Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | May 19 evidence refresh: 27/27 passed after adding the video suite, partner/sponsor/talk gates, owner approval packet, and roadmap evidence mirror | +| Harness audit | `npm run harness:audit -- --format json` | 80/80 passing | Current release gate: 80/80 across 8 applicable categories, 0 top actions | +| Adapter scorecard | `npm run harness:adapters -- --check` | PASS | Current release gate: PASS, 11 adapters | +| Observability readiness | `npm run observability:ready` | 21/21 passing | Current release gate: 21/21, ready true | +| Release safety gate | `npm run observability:ready -- --format json` | Release Safety category passing with publication readiness, supply-chain, workflow security, package surface, and release-surface evidence | Current release gate keeps Release Safety passing at 3/3; repeat the JSON gate from the exact final release commit | +| Supply-chain verification | `npm audit --audit-level=moderate`; `npm audit signatures`; `yarn install --immutable --mode=skip-build`; `cd ecc2 && cargo audit -q`; Dependabot alerts; GitGuardian Security Checks | 0 vulnerabilities/alerts, registry signatures verified, package-manager locks accepted, GitGuardian clean | Current supply-chain branch: `npm audit` found 0 vulnerabilities; `npm audit signatures` verified 254 registry signatures and 30 attestations; Yarn immutable install accepted the lock after pinning `@types/node@25.7.0` and moving `brace-expansion` to `5.0.6` / `1.1.14`; PR #2005 CI `26106321921` completed 37/37 jobs with 0 failures | +| Root suite | `node tests/run-all.js` | 0 failures | PR #2005 CI `26106321921` completed successfully with 37/37 jobs and 0 failures; current branch reruns focused release/package/docs gates before merge | +| Markdown lint | `npx markdownlint-cli '**/*.md' --ignore node_modules` | 0 failures | Current release gate: focused lint passed for `publication-readiness.md`, `publication-evidence-2026-05-19.md`, and `docs/ECC-2.0-GA-ROADMAP.md` | +| Package surface | `node tests/scripts/npm-publish-surface.test.js` | 0 failures; no Python bytecode in npm tarball | Current release gate: 2/2 passed | +| Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | Current release gate: 27/27 passed after refreshing the discussion-count assertion to the post-PR #2005 baseline | | Optional Rust surface | `cd ecc2 && cargo test` | 0 failures or explicit deferral | `publication-evidence-2026-05-16.md`: 462/462 passed, existing warnings only | -| Queue baseline | `node scripts/platform-audit.js --json` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | `3304848b`: platform audit ready, 0 open PRs, 0 open issues, 0 conflicting PRs, and 0 blocking dirty files | -| Discussion baseline | `node scripts/platform-audit.js --json` and `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | `3304848b`: platform audit sampled 58 trunk discussions, 0 needing maintainer touch, 0 answerable discussions missing accepted answer; `docs/architecture/discussion-response-playbook.md` records response templates and security escalation rules | +| Queue baseline | `node scripts/platform-audit.js --json` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | Post-PR #2005 baseline: platform audit ready true, 0 open PRs, 0 open issues, 0 conflicting PRs, and 0 blocking dirty files across tracked repos | +| Discussion baseline | `node scripts/platform-audit.js --json` and `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | Post-PR #2005 baseline: platform audit sampled 59 trunk discussions, 0 needing maintainer touch, 0 answerable discussions missing accepted answer; `docs/architecture/discussion-response-playbook.md` records response templates and security escalation rules | | Linear roadmap | Linear project and issue readback | Detailed roadmap exists with release, security, AgentShield, ECC Tools, legacy, and observability lanes | May 18 Linear comments include ITO-57 `3fe5b2b7-c4fe-401c-a317-b40d72119cb3` and ITO-44 `fb4a4f33-6c2d-421a-bbdb-63cfad3e3ee4`; earlier evidence records the project and 16 issue lanes | -| Operator readiness dashboard | `npm run operator:dashboard -- --json` | Current queue state mapped to macro-goal deliverables and incomplete gaps | `3304848b`: regenerated May 19 dashboard from current main; platform audit ready true, 0 open PRs, 0 open issues, 0 discussion gaps, 0 dirty files, release video suite current, and publication gates still approval-gated | +| Operator readiness dashboard | `npm run operator:dashboard -- --json` | Current queue state mapped to macro-goal deliverables and incomplete gaps | Post-PR #2005 baseline: May 19 dashboard is current; platform audit ready true, 0 open PRs, 0 open issues, 0 discussion gaps, 0 dirty files, release video suite current, and publication gates still approval-gated | | Release URL ledger | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md` plus placeholder-marker scan | Live links and approval-gated links are separated before announcement copy is posted | Ledger records public repo/docs/npm/OpenAI Codex documentation URLs and blocks GitHub release/npm/plugin/billing/social URLs until approval-gated checks pass | | Release name and plugin publication checklist | `docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md` | Name/package/plugin values are frozen, final-release commands are listed, and Claude/Codex publication paths cite current official docs | Checklist keeps `ECC`, `ecc-universal`, and plugin slug `ecc` for rc.1; no npm rename, npm publish, plugin tag, official listing, billing claim, or announcement before final evidence | diff --git a/package-lock.json b/package-lock.json index 4f7fc3cd..b2306cd3 100644 --- a/package-lock.json +++ b/package-lock.json @@ -21,7 +21,7 @@ "devDependencies": { "@eslint/js": "^9.39.2", "@opencode-ai/plugin": "^1.0.0", - "@types/node": "^25.8.0", + "@types/node": "25.7.0", "c8": "^11.0.0", "eslint": "^9.39.2", "globals": "^17.4.0", @@ -398,13 +398,13 @@ "license": "MIT" }, "node_modules/@types/node": { - "version": "25.8.0", - "resolved": "https://registry.npmjs.org/@types/node/-/node-25.8.0.tgz", - "integrity": "sha512-TCFSk8IZh+iLX1xtksoBVtdmgL+1IX0fC9BeU4QqFSuNdN/K+HUlhqOzEmSYYpZUVsLYcPqc9KX+60iDuninSQ==", + "version": "25.7.0", + "resolved": "https://registry.npmjs.org/@types/node/-/node-25.7.0.tgz", + "integrity": "sha512-z+pdZyxE+RTQE9AcboAZCb4otwcrvgHD+GlBpPgn0emDVt0ohrTMhAwlr2Wd9nZ+nihhYFxO2pThz3C5qSu2Eg==", "dev": true, "license": "MIT", "dependencies": { - "undici-types": ">=7.24.0 <7.24.7" + "undici-types": "~7.21.0" } }, "node_modules/@types/unist": { @@ -497,9 +497,9 @@ "license": "MIT" }, "node_modules/brace-expansion": { - "version": "1.1.13", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.13.tgz", - "integrity": "sha512-9ZLprWS6EENmhEOpjCYW2c8VkmOvckIJZfkr7rBW6dObmfgJ/L1GpSYW5Hpo9lDz4D1+n0Ckz8rU7FwHDQiG/w==", + "version": "1.1.14", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.14.tgz", + "integrity": "sha512-MWPGfDxnyzKU7rNOW9SP/c50vi3xrmrua/+6hfPbCS2ABNWfx24vPidzvC7krjU/RTo235sV776ymlsMtGKj8g==", "dev": true, "license": "MIT", "dependencies": { @@ -1210,9 +1210,9 @@ } }, "node_modules/glob/node_modules/brace-expansion": { - "version": "5.0.5", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.5.tgz", - "integrity": "sha512-VZznLgtwhn+Mact9tfiwx64fA9erHH/MCXEUfB/0bX/6Fz6ny5EGTXYltMocqg4xFAQZtnO3DHWWXi8RiuN7cQ==", + "version": "5.0.6", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.6.tgz", + "integrity": "sha512-kLpxurY4Z4r9sgMsyG0Z9uzsBlgiU/EFKhj/h91/8yHu0edo7XuixOIH3VcJ8kkxs6/jPzoI6U9Vj3WqbMQ94g==", "dev": true, "license": "MIT", "dependencies": { @@ -1680,9 +1680,9 @@ } }, "node_modules/markdownlint-cli/node_modules/brace-expansion": { - "version": "5.0.5", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.5.tgz", - "integrity": "sha512-VZznLgtwhn+Mact9tfiwx64fA9erHH/MCXEUfB/0bX/6Fz6ny5EGTXYltMocqg4xFAQZtnO3DHWWXi8RiuN7cQ==", + "version": "5.0.6", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.6.tgz", + "integrity": "sha512-kLpxurY4Z4r9sgMsyG0Z9uzsBlgiU/EFKhj/h91/8yHu0edo7XuixOIH3VcJ8kkxs6/jPzoI6U9Vj3WqbMQ94g==", "dev": true, "license": "MIT", "dependencies": { @@ -2666,9 +2666,9 @@ } }, "node_modules/test-exclude/node_modules/brace-expansion": { - "version": "5.0.5", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.5.tgz", - "integrity": "sha512-VZznLgtwhn+Mact9tfiwx64fA9erHH/MCXEUfB/0bX/6Fz6ny5EGTXYltMocqg4xFAQZtnO3DHWWXi8RiuN7cQ==", + "version": "5.0.6", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.6.tgz", + "integrity": "sha512-kLpxurY4Z4r9sgMsyG0Z9uzsBlgiU/EFKhj/h91/8yHu0edo7XuixOIH3VcJ8kkxs6/jPzoI6U9Vj3WqbMQ94g==", "dev": true, "license": "MIT", "dependencies": { @@ -2745,9 +2745,9 @@ "dev": true }, "node_modules/undici-types": { - "version": "7.24.6", - "resolved": "https://registry.npmjs.org/undici-types/-/undici-types-7.24.6.tgz", - "integrity": "sha512-WRNW+sJgj5OBN4/0JpHFqtqzhpbnV0GuB+OozA9gCL7a993SmU+1JBZCzLNxYsbMfIeDL+lTsphD5jN5N+n0zg==", + "version": "7.21.0", + "resolved": "https://registry.npmjs.org/undici-types/-/undici-types-7.21.0.tgz", + "integrity": "sha512-w9IMgQrz4O0YN1LtB7K5P63vhlIOvC7opSmouCJ+ZywlPAlO9gIkJ+otk6LvGpAs2wg4econaCz3TvQ9xPoyuQ==", "dev": true, "license": "MIT" }, diff --git a/package.json b/package.json index 479374f2..07919d69 100644 --- a/package.json +++ b/package.json @@ -335,7 +335,7 @@ "devDependencies": { "@eslint/js": "^9.39.2", "@opencode-ai/plugin": "^1.0.0", - "@types/node": "^25.8.0", + "@types/node": "25.7.0", "c8": "^11.0.0", "eslint": "^9.39.2", "globals": "^17.4.0", diff --git a/tests/docs/ecc2-release-surface.test.js b/tests/docs/ecc2-release-surface.test.js index f635f374..bf7a5a2e 100644 --- a/tests/docs/ecc2-release-surface.test.js +++ b/tests/docs/ecc2-release-surface.test.js @@ -462,7 +462,7 @@ test('publication readiness checklist gates public release actions on evidence', assert.ok(source.includes('release-name-plugin-publication-checklist-2026-05-18.md')); assert.ok(source.includes('Release name and plugin publication checklist')); assert.ok(may15Evidence.includes('| Trunk discussions | GraphQL discussion count and maintainer-touch sweep | 58 total discussions;')); - assert.ok(source.includes('platform audit sampled 58 trunk discussions')); + assert.ok(source.includes('platform audit sampled 59 trunk discussions')); assert.ok(source.includes('0 needing maintainer touch')); assert.ok(source.includes('discussion-response-playbook.md')); for (const expected of [ diff --git a/yarn.lock b/yarn.lock index b1cd2a7c..eec98bd1 100644 --- a/yarn.lock +++ b/yarn.lock @@ -302,12 +302,12 @@ __metadata: languageName: node linkType: hard -"@types/node@npm:^25.8.0": - version: 25.8.0 - resolution: "@types/node@npm:25.8.0" +"@types/node@npm:25.7.0": + version: 25.7.0 + resolution: "@types/node@npm:25.7.0" dependencies: - undici-types: "npm:>=7.24.0 <7.24.7" - checksum: 10c0/ff53e5428309d2e6060190ec5e02afd0e4a7369456b16130a7f5898f12a6ad0efd62d752830f2f7355d714ae429bc0acbb2dc0cbf761cadb03e88c4996cdf1dc + undici-types: "npm:~7.21.0" + checksum: 10c0/47ec7eaca154c36ad6d1ac0270e6e254eedf20b9dc49afe3bc76e4f7eba29ceac705f8903b162aeaf40e3941101ffe76ffb374989359ea3ef8c8509d8b443f55 languageName: node linkType: hard @@ -412,21 +412,21 @@ __metadata: linkType: hard "brace-expansion@npm:^1.1.7": - version: 1.1.13 - resolution: "brace-expansion@npm:1.1.13" + version: 1.1.14 + resolution: "brace-expansion@npm:1.1.14" dependencies: balanced-match: "npm:^1.0.0" concat-map: "npm:0.0.1" - checksum: 10c0/384c61bb329b6adfdcc0cbbdd108dc19fb5f3e84ae15a02a74f94c6c791b5a9b035aae73b2a51929a8a478e2f0f212a771eb6a8b5b514cccfb8d0c9f2ce8cbd8 + checksum: 10c0/b6fdac832bc4e36a753658c9ed052c2e1a2be221763b002df25d1efbf7d21724334e726a6cd5eadc72a4b19ec3efb632d629cc003bc9c62f7af7a7915ffa4385 languageName: node linkType: hard "brace-expansion@npm:^5.0.5": - version: 5.0.5 - resolution: "brace-expansion@npm:5.0.5" + version: 5.0.6 + resolution: "brace-expansion@npm:5.0.6" dependencies: balanced-match: "npm:^4.0.2" - checksum: 10c0/4d238e14ed4f5cc9c07285550a41cef23121ca08ba99fa9eb5b55b580dcb6bf868b8210aa10526bdc9f8dc97f33ca2a7259039c4cc131a93042beddb424c48e3 + checksum: 10c0/8c919869b90f61d533b341d3340be5ee4413232ea89b8246cbc2f38eb014f1d8182785c98a006eaf6111d02dc9eeffefdc240d5ac158625b2ed084dccd4bbf9b languageName: node linkType: hard @@ -632,7 +632,7 @@ __metadata: "@eslint/js": "npm:^9.39.2" "@iarna/toml": "npm:^2.2.5" "@opencode-ai/plugin": "npm:^1.0.0" - "@types/node": "npm:^25.8.0" + "@types/node": "npm:25.7.0" ajv: "npm:^8.18.0" c8: "npm:^11.0.0" eslint: "npm:^9.39.2" @@ -2116,10 +2116,10 @@ __metadata: languageName: node linkType: hard -"undici-types@npm:>=7.24.0 <7.24.7": - version: 7.24.6 - resolution: "undici-types@npm:7.24.6" - checksum: 10c0/d9cd8befb643ac904615c280a095ba4240531f6bb4a5e75a22a7483630ca8d3f1016d2ab6ace6ceda1f63b3a2db2fe037fafe121d6917a0187573aa548ff78ca +"undici-types@npm:~7.21.0": + version: 7.21.0 + resolution: "undici-types@npm:7.21.0" + checksum: 10c0/c3b4ae5f066c398acb1962505b56214ecd72843f7d7827fcc2df7a48a63d1639d3608c580ac09f836253d21fa7ba8f1a04440569ed9d332474ad01b8a010db87 languageName: node linkType: hard From 7004a662430ca22d9c84f352e8008d5925393750 Mon Sep 17 00:00:00 2001 From: Mhd Ghaith Al Abtah <141250866+mhd-ghaith-abtah@users.noreply.github.com> Date: Tue, 19 May 2026 19:39:18 +0400 Subject: [PATCH 45/61] feat(install-targets): add claude-project (per-project Claude Code) adapter MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Completes the install-target matrix for Claude Code. Until now, ECC's Claude support was home-scope only (~/.claude/) via the `claude` target. This adds a project-scope counterpart (./.claude/) via a new `claude-project` target so teams can install ECC per-repo without contaminating ~/.claude/ — matching the existing project-scope adapters for Cursor, Antigravity, Gemini, CodeBuddy, Joycode, and Zed. Symmetric with `claude`: - Same namespace under rules/ecc and skills/ecc - Same docs/ handling for --locale - Same hooks placeholder substitution for hooks.json - Reuses claude-home's destination-mapping logic 1:1 Use cases: - Monorepos with multiple Flow-managed projects - Teams that want ECC scoped per-project without touching ~/.claude/ - Per-project skill/rule isolation when global install isn't desirable No breaking change: existing --target claude continues to route to claude-home (user-scope) unchanged. New target is opt-in. Tests ----- - 4 new tests in tests/lib/install-targets.test.js (root resolution, lookup-by-id, plan parity with claude, foreign-path filtering) - All install-target regression guards (schema enum / SUPPORTED_INSTALL_TARGETS) still pass - End-to-end smoke: `--target claude-project --profile minimal --dry-run` emits 359 ops with destinations rooted at /.claude/ (parity with --target claude which emits 359 ops rooted at ~/.claude/) --- manifests/install-modules.json | 45 +++++++-- schemas/ecc-install-config.schema.json | 1 + scripts/install-apply.js | 7 +- scripts/lib/install-manifests.js | 10 +- scripts/lib/install-targets/claude-project.js | 91 ++++++++++++++++++ scripts/lib/install-targets/registry.js | 2 + scripts/lib/install/apply.js | 2 +- scripts/lib/install/request.js | 4 +- tests/lib/install-targets.test.js | 94 +++++++++++++++++++ 9 files changed, 241 insertions(+), 15 deletions(-) create mode 100644 scripts/lib/install-targets/claude-project.js diff --git a/manifests/install-modules.json b/manifests/install-modules.json index 0edaf272..c8330f35 100644 --- a/manifests/install-modules.json +++ b/manifests/install-modules.json @@ -10,6 +10,7 @@ ], "targets": [ "claude", + "claude-project", "cursor", "antigravity", "codebuddy", @@ -33,6 +34,7 @@ ], "targets": [ "claude", + "claude-project", "cursor", "antigravity", "codex", @@ -55,6 +57,7 @@ ], "targets": [ "claude", + "claude-project", "cursor", "antigravity", "opencode", @@ -79,6 +82,7 @@ ], "targets": [ "claude", + "claude-project", "cursor", "opencode", "codebuddy" @@ -106,6 +110,7 @@ ], "targets": [ "claude", + "claude-project", "cursor", "antigravity", "codex", @@ -177,6 +182,7 @@ ], "targets": [ "claude", + "claude-project", "cursor", "antigravity", "codex", @@ -210,6 +216,7 @@ ], "targets": [ "claude", + "claude-project", "cursor", "antigravity", "codex", @@ -255,6 +262,7 @@ ], "targets": [ "claude", + "claude-project", "cursor", "antigravity", "codex", @@ -294,6 +302,7 @@ ], "targets": [ "claude", + "claude-project", "cursor", "antigravity", "codex", @@ -326,6 +335,7 @@ ], "targets": [ "claude", + "claude-project", "cursor", "antigravity", "codex", @@ -360,6 +370,7 @@ ], "targets": [ "claude", + "claude-project", "cursor", "antigravity", "codex", @@ -402,6 +413,7 @@ ], "targets": [ "claude", + "claude-project", "cursor", "antigravity", "codex", @@ -428,6 +440,7 @@ ], "targets": [ "claude", + "claude-project", "cursor", "antigravity", "codex", @@ -459,6 +472,7 @@ ], "targets": [ "claude", + "claude-project", "cursor", "codex", "opencode", @@ -490,6 +504,7 @@ ], "targets": [ "claude", + "claude-project", "codex", "opencode" ], @@ -515,6 +530,7 @@ ], "targets": [ "claude", + "claude-project", "cursor", "antigravity", "codex", @@ -559,6 +575,7 @@ ], "targets": [ "claude", + "claude-project", "cursor", "antigravity", "codex", @@ -592,6 +609,7 @@ ], "targets": [ "claude", + "claude-project", "cursor", "antigravity", "codex", @@ -617,6 +635,7 @@ ], "targets": [ "claude", + "claude-project", "cursor", "antigravity", "codex", @@ -653,6 +672,7 @@ ], "targets": [ "claude", + "claude-project", "cursor", "antigravity", "codex", @@ -679,6 +699,7 @@ ], "targets": [ "claude", + "claude-project", "cursor", "antigravity", "codex", @@ -703,7 +724,8 @@ "docs/ja-JP" ], "targets": [ - "claude" + "claude", + "claude-project" ], "dependencies": [], "defaultInstall": false, @@ -718,7 +740,8 @@ "docs/zh-CN" ], "targets": [ - "claude" + "claude", + "claude-project" ], "dependencies": [], "defaultInstall": false, @@ -733,7 +756,8 @@ "docs/ko-KR" ], "targets": [ - "claude" + "claude", + "claude-project" ], "dependencies": [], "defaultInstall": false, @@ -748,7 +772,8 @@ "docs/pt-BR" ], "targets": [ - "claude" + "claude", + "claude-project" ], "dependencies": [], "defaultInstall": false, @@ -763,7 +788,8 @@ "docs/ru" ], "targets": [ - "claude" + "claude", + "claude-project" ], "dependencies": [], "defaultInstall": false, @@ -778,7 +804,8 @@ "docs/tr" ], "targets": [ - "claude" + "claude", + "claude-project" ], "dependencies": [], "defaultInstall": false, @@ -793,7 +820,8 @@ "docs/vi-VN" ], "targets": [ - "claude" + "claude", + "claude-project" ], "dependencies": [], "defaultInstall": false, @@ -808,7 +836,8 @@ "docs/zh-TW" ], "targets": [ - "claude" + "claude", + "claude-project" ], "dependencies": [], "defaultInstall": false, diff --git a/schemas/ecc-install-config.schema.json b/schemas/ecc-install-config.schema.json index 65131fb8..dc5923d0 100644 --- a/schemas/ecc-install-config.schema.json +++ b/schemas/ecc-install-config.schema.json @@ -19,6 +19,7 @@ "type": "string", "enum": [ "claude", + "claude-project", "cursor", "antigravity", "codex", diff --git a/scripts/install-apply.js b/scripts/install-apply.js index eb48bb06..2e3009dd 100755 --- a/scripts/install-apply.js +++ b/scripts/install-apply.js @@ -27,11 +27,12 @@ Usage: install.sh [--target <${LEGACY_INSTALL_TARGETS.join('|')}>] [--dry-run] [ install.sh [--target <${SUPPORTED_INSTALL_TARGETS.join('|')}>] [--dry-run] [--json] --profile [--with ]... [--without ]... install.sh [--target <${SUPPORTED_INSTALL_TARGETS.join('|')}>] [--dry-run] [--json] --modules [--with ]... [--without ]... install.sh [--target <${SUPPORTED_INSTALL_TARGETS.join('|')}>] [--dry-run] [--json] --skills - install.sh [--target claude] [--dry-run] [--json] --locale + install.sh [--target claude|claude-project] [--dry-run] [--json] --locale install.sh [--dry-run] [--json] --config Targets: claude (default) - Install ECC into ~/.claude/ with managed rules/skills under rules/ecc and skills/ecc + claude-project - Install ECC into ./.claude/ (per-project) with managed rules/skills under rules/ecc and skills/ecc cursor - Install rules, hooks, and bundled Cursor configs to ./.cursor/ antigravity - Install rules, workflows, skills, and agents to ./.agent/ codex - Install shared agents/config into ~/.codex/ @@ -49,8 +50,8 @@ Options: --skills Install one or more skill directories by ID, e.g. continuous-learning-v2 --without Exclude a user-facing install component - --locale Install translated docs to ~/.claude/docs// - (claude target only; can be combined with --profile or --with) + --locale Install translated docs to ~/.claude/docs// (or ./.claude/docs// for claude-project) + (claude or claude-project target only; can be combined with --profile or --with) --config Load install intent from ecc-install.json --dry-run Show the install plan without copying files --json Emit machine-readable plan/result JSON diff --git a/scripts/lib/install-manifests.js b/scripts/lib/install-manifests.js index c27d5e23..0224b37d 100644 --- a/scripts/lib/install-manifests.js +++ b/scripts/lib/install-manifests.js @@ -4,7 +4,7 @@ const path = require('path'); const { getInstallTargetAdapter, planInstallTargetScaffold } = require('./install-targets/registry'); const DEFAULT_REPO_ROOT = path.join(__dirname, '../..'); -const SUPPORTED_INSTALL_TARGETS = ['claude', 'cursor', 'antigravity', 'codex', 'gemini', 'opencode', 'codebuddy', 'joycode', 'qwen', 'zed']; +const SUPPORTED_INSTALL_TARGETS = ['claude', 'claude-project', 'cursor', 'antigravity', 'codex', 'gemini', 'opencode', 'codebuddy', 'joycode', 'qwen', 'zed']; const COMPONENT_FAMILY_PREFIXES = { baseline: 'baseline:', language: 'lang:', @@ -43,6 +43,14 @@ const LEGACY_COMPAT_BASE_MODULE_IDS_BY_TARGET = Object.freeze({ 'platform-configs', 'workflow-quality', ], + 'claude-project': [ + 'rules-core', + 'agents-core', + 'commands-core', + 'hooks-runtime', + 'platform-configs', + 'workflow-quality', + ], cursor: [ 'rules-core', 'agents-core', diff --git a/scripts/lib/install-targets/claude-project.js b/scripts/lib/install-targets/claude-project.js new file mode 100644 index 00000000..150df276 --- /dev/null +++ b/scripts/lib/install-targets/claude-project.js @@ -0,0 +1,91 @@ +const path = require('path'); + +const { + createInstallTargetAdapter, + createRemappedOperation, + isForeignPlatformPath, + normalizeRelativePath, +} = require('./helpers'); + +const CLAUDE_ECC_NAMESPACE = 'ecc'; + +function getClaudeManagedDestinationPath(adapter, sourceRelativePath, input) { + const normalizedSourcePath = normalizeRelativePath(sourceRelativePath); + const targetRoot = adapter.resolveRoot(input); + + if (normalizedSourcePath === 'rules') { + return path.join(targetRoot, 'rules', CLAUDE_ECC_NAMESPACE); + } + + if (normalizedSourcePath.startsWith('rules/')) { + return path.join( + targetRoot, + 'rules', + CLAUDE_ECC_NAMESPACE, + normalizedSourcePath.slice('rules/'.length) + ); + } + + if (normalizedSourcePath === 'skills') { + return path.join(targetRoot, 'skills', CLAUDE_ECC_NAMESPACE); + } + + if (normalizedSourcePath.startsWith('skills/')) { + return path.join( + targetRoot, + 'skills', + CLAUDE_ECC_NAMESPACE, + normalizedSourcePath.slice('skills/'.length) + ); + } + + if (normalizedSourcePath === 'docs' || normalizedSourcePath.startsWith('docs/')) { + return path.join(targetRoot, normalizedSourcePath); + } + + return null; +} + +module.exports = createInstallTargetAdapter({ + id: 'claude-project', + target: 'claude-project', + kind: 'project', + rootSegments: ['.claude'], + installStatePathSegments: ['ecc', 'install-state.json'], + nativeRootRelativePath: '.claude-plugin', + planOperations(input, adapter) { + const modules = Array.isArray(input.modules) + ? input.modules + : (input.module ? [input.module] : []); + const planningInput = { + repoRoot: input.repoRoot, + projectRoot: input.projectRoot, + homeDir: input.homeDir, + }; + + return modules.flatMap(module => { + const paths = Array.isArray(module.paths) ? module.paths : []; + return paths + .filter(p => !isForeignPlatformPath(p, 'claude')) + .map(sourceRelativePath => { + const managedDestinationPath = getClaudeManagedDestinationPath( + adapter, + sourceRelativePath, + planningInput + ); + + if (managedDestinationPath) { + return createRemappedOperation( + adapter, + module.id, + sourceRelativePath, + managedDestinationPath, + { strategy: 'preserve-relative-path' } + ); + } + + return adapter.createScaffoldOperation(module.id, sourceRelativePath, planningInput); + }); + }); + }, +}); diff --git a/scripts/lib/install-targets/registry.js b/scripts/lib/install-targets/registry.js index 8e444a0e..e4e3e7c4 100644 --- a/scripts/lib/install-targets/registry.js +++ b/scripts/lib/install-targets/registry.js @@ -1,5 +1,6 @@ const antigravityProject = require('./antigravity-project'); const claudeHome = require('./claude-home'); +const claudeProject = require('./claude-project'); const codebuddyProject = require('./codebuddy-project'); const codexHome = require('./codex-home'); const cursorProject = require('./cursor-project'); @@ -11,6 +12,7 @@ const zedProject = require('./zed-project'); const ADAPTERS = Object.freeze([ claudeHome, + claudeProject, cursorProject, antigravityProject, codexHome, diff --git a/scripts/lib/install/apply.js b/scripts/lib/install/apply.js index 42497c42..6c473685 100644 --- a/scripts/lib/install/apply.js +++ b/scripts/lib/install/apply.js @@ -89,7 +89,7 @@ function isMcpConfigPath(filePath) { } function buildResolvedClaudeHooks(plan) { - if (!plan.adapter || plan.adapter.target !== 'claude') { + if (!plan.adapter || (plan.adapter.target !== 'claude' && plan.adapter.target !== 'claude-project')) { return null; } diff --git a/scripts/lib/install/request.js b/scripts/lib/install/request.js index 4cf5c043..5b69d67c 100644 --- a/scripts/lib/install/request.js +++ b/scripts/lib/install/request.js @@ -100,8 +100,8 @@ function normalizeInstallRequest(options = {}) { `Unsupported locale: "${locale}". Supported locales: ${listSupportedLocales().join(', ')}` ); } - if (locale && target !== 'claude') { - throw new Error('--locale can only be used with --target claude'); + if (locale && target !== 'claude' && target !== 'claude-project') { + throw new Error('--locale can only be used with --target claude or --target claude-project'); } const requestedIncludeComponentIds = dedupeStrings([ ...(config?.includeComponentIds || []), diff --git a/tests/lib/install-targets.test.js b/tests/lib/install-targets.test.js index daa2e722..6fa7b1bf 100644 --- a/tests/lib/install-targets.test.js +++ b/tests/lib/install-targets.test.js @@ -37,6 +37,7 @@ function runTests() { const adapters = listInstallTargetAdapters(); const targets = adapters.map(adapter => adapter.target); assert.ok(targets.includes('claude'), 'Should include claude target'); + assert.ok(targets.includes('claude-project'), 'Should include claude-project target'); assert.ok(targets.includes('cursor'), 'Should include cursor target'); assert.ok(targets.includes('antigravity'), 'Should include antigravity target'); assert.ok(targets.includes('codex'), 'Should include codex target'); @@ -865,6 +866,99 @@ function runTests() { } })) passed++; else failed++; + if (test('resolves claude-project adapter root and install-state path from project root', () => { + const adapter = getInstallTargetAdapter('claude-project'); + const projectRoot = '/workspace/app'; + const root = adapter.resolveRoot({ projectRoot }); + const statePath = adapter.getInstallStatePath({ projectRoot }); + + assert.strictEqual(adapter.id, 'claude-project'); + assert.strictEqual(adapter.target, 'claude-project'); + assert.strictEqual(adapter.kind, 'project'); + assert.strictEqual(root, path.join(projectRoot, '.claude')); + assert.strictEqual(statePath, path.join(projectRoot, '.claude', 'ecc', 'install-state.json')); + })) passed++; else failed++; + + if (test('claude-project adapter supports lookup by target and adapter id', () => { + const byTarget = getInstallTargetAdapter('claude-project'); + const byId = getInstallTargetAdapter('claude-project'); + + assert.strictEqual(byTarget.id, 'claude-project'); + assert.strictEqual(byId.id, 'claude-project'); + assert.ok(byTarget.supports('claude-project')); + })) passed++; else failed++; + + if (test('plans claude-project rules and skills under project-scope ECC-managed subdirectories', () => { + const repoRoot = path.join(__dirname, '..', '..'); + const projectRoot = '/workspace/app'; + + const plan = planInstallTargetScaffold({ + target: 'claude-project', + repoRoot, + projectRoot, + modules: [ + { + id: 'rules-core', + paths: ['rules'], + }, + { + id: 'workflow-quality', + paths: ['skills/tdd-workflow'], + }, + ], + }); + + assert.strictEqual(plan.adapter.id, 'claude-project'); + assert.strictEqual(plan.targetRoot, path.join(projectRoot, '.claude')); + assert.strictEqual(plan.installStatePath, path.join(projectRoot, '.claude', 'ecc', 'install-state.json')); + assert.ok( + plan.operations.some(operation => ( + normalizedRelativePath(operation.sourceRelativePath) === 'rules' + && operation.destinationPath === path.join(projectRoot, '.claude', 'rules', 'ecc') + )), + 'Should install bundled rules under project-scope rules/ecc' + ); + assert.ok( + plan.operations.some(operation => ( + normalizedRelativePath(operation.sourceRelativePath) === 'skills/tdd-workflow' + && operation.destinationPath === path.join(projectRoot, '.claude', 'skills', 'ecc', 'tdd-workflow') + )), + 'Should install bundled skills under project-scope skills/ecc' + ); + })) passed++; else failed++; + + if (test('claude-project skips foreign platform source paths', () => { + const repoRoot = path.join(__dirname, '..', '..'); + const projectRoot = '/workspace/app'; + + const plan = planInstallTargetScaffold({ + target: 'claude-project', + repoRoot, + projectRoot, + modules: [ + { + id: 'platform-configs', + paths: ['.cursor', '.zed', 'rules'], + }, + ], + }); + + assert.ok( + !plan.operations.some(operation => ( + normalizedRelativePath(operation.sourceRelativePath) === '.cursor' + || normalizedRelativePath(operation.sourceRelativePath).startsWith('.cursor/') + )), + 'Should skip foreign Cursor platform paths' + ); + assert.ok( + !plan.operations.some(operation => ( + normalizedRelativePath(operation.sourceRelativePath) === '.zed' + || normalizedRelativePath(operation.sourceRelativePath).startsWith('.zed/') + )), + 'Should skip foreign Zed platform paths' + ); + })) passed++; else failed++; + console.log(`\nResults: Passed: ${passed}, Failed: ${failed}`); process.exit(failed > 0 ? 1 : 0); } From b2c2616ab4322e6894d6d5b2376e7377609f3d9a Mon Sep 17 00:00:00 2001 From: Mhd Ghaith Al Abtah <141250866+mhd-ghaith-abtah@users.noreply.github.com> Date: Tue, 19 May 2026 19:50:48 +0400 Subject: [PATCH 46/61] test(install-targets): add positive rules assertion to claude-project foreign-path test Addresses CodeRabbit review: the negative-only assertions could have passed on an empty plan. Add a positive assertion that the non-foreign 'rules' path is still planned under .claude/rules/ecc so regression to zero ops would fail loudly. --- tests/lib/install-targets.test.js | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/tests/lib/install-targets.test.js b/tests/lib/install-targets.test.js index 6fa7b1bf..d74d95aa 100644 --- a/tests/lib/install-targets.test.js +++ b/tests/lib/install-targets.test.js @@ -943,6 +943,13 @@ function runTests() { ], }); + assert.ok( + plan.operations.some(operation => ( + normalizedRelativePath(operation.sourceRelativePath) === 'rules' + && operation.destinationPath === path.join(projectRoot, '.claude', 'rules', 'ecc') + )), + 'Should still include non-foreign rules path (guards against empty-plan regression)' + ); assert.ok( !plan.operations.some(operation => ( normalizedRelativePath(operation.sourceRelativePath) === '.cursor' From 98bd517451f38fa0150a53aab4234c2239a47b7e Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 12:12:10 -0400 Subject: [PATCH 47/61] fix(install): allow claude-project manifest target --- schemas/install-modules.schema.json | 1 + 1 file changed, 1 insertion(+) diff --git a/schemas/install-modules.schema.json b/schemas/install-modules.schema.json index 252f8e82..b8d9a095 100644 --- a/schemas/install-modules.schema.json +++ b/schemas/install-modules.schema.json @@ -49,6 +49,7 @@ "type": "string", "enum": [ "claude", + "claude-project", "cursor", "antigravity", "codex", From bc519e5b8ed42f26c0a5a611756e04351c323f21 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 12:26:08 -0400 Subject: [PATCH 48/61] fix(learning): add project registry maintenance --- .../continuous-learning-v2/hooks/observe.sh | 8 +- .../scripts/detect-project.sh | 42 ++- .../scripts/instinct-cli.py | 331 +++++++++++++++++- tests/hooks/detect-project-worktree.test.js | 84 +++-- tests/hooks/hooks.test.js | 11 +- .../observe-subdirectory-detection.test.js | 21 +- tests/scripts/instinct-cli-projects.test.js | 260 ++++++++++++++ 7 files changed, 706 insertions(+), 51 deletions(-) create mode 100644 tests/scripts/instinct-cli-projects.test.js diff --git a/skills/continuous-learning-v2/hooks/observe.sh b/skills/continuous-learning-v2/hooks/observe.sh index ce65b8e0..0410912c 100755 --- a/skills/continuous-learning-v2/hooks/observe.sh +++ b/skills/continuous-learning-v2/hooks/observe.sh @@ -116,7 +116,13 @@ except(KeyError, TypeError, ValueError): # If cwd was provided in stdin, use it for project detection if [ -n "$STDIN_CWD" ] && [ -d "$STDIN_CWD" ]; then _GIT_ROOT=$(git -C "$STDIN_CWD" rev-parse --show-toplevel 2>/dev/null || true) - export CLAUDE_PROJECT_DIR="${_GIT_ROOT:-$STDIN_CWD}" + if [ -n "$_GIT_ROOT" ]; then + export CLAUDE_PROJECT_DIR="$_GIT_ROOT" + unset CLV2_NO_PROJECT + else + unset CLAUDE_PROJECT_DIR + export CLV2_NO_PROJECT=1 + fi fi # ───────────────────────────────────────────── diff --git a/skills/continuous-learning-v2/scripts/detect-project.sh b/skills/continuous-learning-v2/scripts/detect-project.sh index 66e541c4..dbe9c5ed 100755 --- a/skills/continuous-learning-v2/scripts/detect-project.sh +++ b/skills/continuous-learning-v2/scripts/detect-project.sh @@ -75,16 +75,42 @@ _clv2_normalize_remote_url() { fi } +_clv2_main_worktree_root() { + local root="$1" + [ -z "$root" ] && return 0 + command -v git >/dev/null 2>&1 || return 0 + + git -C "$root" worktree list --porcelain 2>/dev/null | while IFS= read -r line; do + case "$line" in + worktree\ *) + printf '%s\n' "${line#worktree }" + break + ;; + esac + done +} + _clv2_detect_project() { local project_root="" local project_name="" local project_id="" local source_hint="" + if [ "${CLV2_NO_PROJECT:-0}" = "1" ]; then + _CLV2_PROJECT_ID="global" + _CLV2_PROJECT_NAME="global" + _CLV2_PROJECT_ROOT="" + _CLV2_PROJECT_DIR="${_CLV2_HOMUNCULUS_DIR}" + mkdir -p "$_CLV2_PROJECT_DIR" + return 0 + fi + # 1. Try CLAUDE_PROJECT_DIR env var - if [ -n "$CLAUDE_PROJECT_DIR" ] && [ -d "$CLAUDE_PROJECT_DIR" ]; then - project_root="$CLAUDE_PROJECT_DIR" - source_hint="env" + if [ -n "$CLAUDE_PROJECT_DIR" ] && [ -d "$CLAUDE_PROJECT_DIR" ] && command -v git &>/dev/null; then + project_root=$(git -C "$CLAUDE_PROJECT_DIR" rev-parse --show-toplevel 2>/dev/null || true) + if [ -n "$project_root" ]; then + source_hint="env" + fi fi # 2. Try git repo root from CWD (only if git is available) @@ -101,6 +127,7 @@ _clv2_detect_project() { _CLV2_PROJECT_NAME="global" _CLV2_PROJECT_ROOT="" _CLV2_PROJECT_DIR="${_CLV2_HOMUNCULUS_DIR}" + mkdir -p "$_CLV2_PROJECT_DIR" return 0 fi @@ -133,7 +160,14 @@ _clv2_detect_project() { normalized_remote=$(_clv2_normalize_remote_url "$remote_url") fi - local hash_input="${normalized_remote:-${remote_url:-$project_root}}" + local fallback_root="$project_root" + if [ -z "$remote_url" ]; then + local main_worktree_root + main_worktree_root=$(_clv2_main_worktree_root "$project_root") + [ -n "$main_worktree_root" ] && fallback_root="$main_worktree_root" + fi + + local hash_input="${normalized_remote:-${remote_url:-$fallback_root}}" # Prefer Python for consistent SHA256 behavior across shells/platforms. # Pass the value via env var and encode as UTF-8 inside Python so the hash # is locale-independent (shells vary between UTF-8 / CP932 / CP1252, which diff --git a/skills/continuous-learning-v2/scripts/instinct-cli.py b/skills/continuous-learning-v2/scripts/instinct-cli.py index 7b03bc0e..710f4c69 100755 --- a/skills/continuous-learning-v2/scripts/instinct-cli.py +++ b/skills/continuous-learning-v2/scripts/instinct-cli.py @@ -22,6 +22,7 @@ import os import subprocess import sys import re +import shutil import urllib.request from pathlib import Path from datetime import datetime, timedelta, timezone @@ -194,26 +195,64 @@ def _yaml_quote(value: str) -> str: # Project Detection (Python equivalent of detect-project.sh) # ───────────────────────────────────────────── +def _git_repo_root(cwd: Optional[str] = None) -> Optional[str]: + args = ["git"] + if cwd: + args.extend(["-C", cwd]) + args.extend(["rev-parse", "--show-toplevel"]) + try: + result = subprocess.run(args, capture_output=True, text=True, timeout=5) + if result.returncode == 0: + return result.stdout.strip() + except (subprocess.TimeoutExpired, FileNotFoundError): + pass + return None + + +def _main_worktree_root(project_root: str) -> str: + """Return the main worktree root when project_root is a linked worktree.""" + try: + result = subprocess.run( + ["git", "-C", project_root, "worktree", "list", "--porcelain"], + capture_output=True, text=True, timeout=5 + ) + except (subprocess.TimeoutExpired, FileNotFoundError): + return project_root + + if result.returncode != 0: + return project_root + + for line in result.stdout.splitlines(): + if line.startswith("worktree "): + main_root = line.split(" ", 1)[1].strip() + return main_root or project_root + return project_root + + def detect_project() -> dict: """Detect current project context. Returns dict with id, name, root, project_dir.""" project_root = None + if os.environ.get("CLV2_NO_PROJECT") == "1": + return { + "id": "global", + "name": "global", + "root": "", + "project_dir": HOMUNCULUS_DIR, + "instincts_personal": GLOBAL_PERSONAL_DIR, + "instincts_inherited": GLOBAL_INHERITED_DIR, + "evolved_dir": GLOBAL_EVOLVED_DIR, + "observations_file": GLOBAL_OBSERVATIONS_FILE, + } + # 1. CLAUDE_PROJECT_DIR env var env_dir = os.environ.get("CLAUDE_PROJECT_DIR") if env_dir and os.path.isdir(env_dir): - project_root = env_dir + project_root = _git_repo_root(env_dir) # 2. git repo root if not project_root: - try: - result = subprocess.run( - ["git", "rev-parse", "--show-toplevel"], - capture_output=True, text=True, timeout=5 - ) - if result.returncode == 0: - project_root = result.stdout.strip() - except (subprocess.TimeoutExpired, FileNotFoundError): - pass + project_root = _git_repo_root() # Normalize: strip trailing slashes to keep basename and hash stable if project_root: @@ -250,9 +289,10 @@ def detect_project() -> dict: if remote_url: remote_url = _strip_remote_credentials(remote_url) + fallback_root = _main_worktree_root(project_root) if not remote_url else project_root legacy_hash_source = remote_url if remote_url else project_root normalized_remote = _normalize_remote_url(remote_url) if remote_url else "" - hash_source = normalized_remote if normalized_remote else legacy_hash_source + hash_source = normalized_remote if normalized_remote else (remote_url if remote_url else fallback_root) project_id = _project_hash(hash_source) project_dir = PROJECTS_DIR / project_id @@ -352,6 +392,26 @@ def load_registry() -> dict: return {} +def _write_registry(registry: dict) -> None: + """Write the project registry atomically.""" + REGISTRY_FILE.parent.mkdir(parents=True, exist_ok=True) + tmp_file = REGISTRY_FILE.parent / f".{REGISTRY_FILE.name}.tmp.{os.getpid()}" + with open(tmp_file, "w", encoding="utf-8") as f: + json.dump(registry, f, indent=2) + f.write("\n") + f.flush() + os.fsync(f.fileno()) + os.replace(tmp_file, REGISTRY_FILE) + + +def _validate_project_id(project_id: str) -> bool: + if not project_id or len(project_id) > 128: + return False + if "/" in project_id or "\\" in project_id or ".." in project_id: + return False + return bool(re.match(r"^[A-Za-z0-9][A-Za-z0-9._-]*$", project_id)) + + # ───────────────────────────────────────────── # Instinct Parser # ───────────────────────────────────────────── @@ -436,6 +496,96 @@ def _load_instincts_from_dir(directory: Path, source_type: str, scope_label: str return instincts +def _project_counts(project_id: str) -> dict: + project_dir = PROJECTS_DIR / project_id + personal_dir = project_dir / "instincts" / "personal" + inherited_dir = project_dir / "instincts" / "inherited" + observations_file = project_dir / "observations.jsonl" + + personal_count = len(_load_instincts_from_dir(personal_dir, "personal", "project")) + inherited_count = len(_load_instincts_from_dir(inherited_dir, "inherited", "project")) + observations_count = 0 + if observations_file.exists(): + try: + with open(observations_file, encoding="utf-8") as f: + observations_count = sum(1 for _ in f) + except OSError: + observations_count = 0 + + return { + "personal": personal_count, + "inherited": inherited_count, + "observations": observations_count, + "total": personal_count + inherited_count + observations_count, + } + + +def _remove_project_storage(project_id: str) -> None: + project_dir = PROJECTS_DIR / project_id + if project_dir.exists(): + shutil.rmtree(project_dir) + + +def _project_instinct_ids(project_dir: Path, source_type: str) -> set[str]: + instinct_dir = project_dir / "instincts" / source_type + return { + inst.get("id") + for inst in _load_instincts_from_dir(instinct_dir, source_type, "project") + if inst.get("id") + } + + +def _merge_instinct_dir(from_dir: Path, into_dir: Path, existing_ids: set[str]) -> tuple[int, int]: + moved = 0 + skipped = 0 + if not from_dir.exists(): + return moved, skipped + + into_dir.mkdir(parents=True, exist_ok=True) + for file_path in sorted(from_dir.iterdir()): + if not file_path.is_file() or file_path.suffix.lower() not in ALLOWED_INSTINCT_EXTENSIONS: + continue + try: + instincts = parse_instinct_file(file_path.read_text(encoding="utf-8")) + except (OSError, UnicodeDecodeError): + instincts = [] + instinct_ids = [inst.get("id") for inst in instincts if inst.get("id")] + if any(instinct_id in existing_ids for instinct_id in instinct_ids): + skipped += 1 + continue + + target_path = into_dir / file_path.name + if target_path.exists(): + target_path = into_dir / f"{file_path.stem}-{_project_hash(str(file_path))}{file_path.suffix}" + shutil.copy2(file_path, target_path) + existing_ids.update(instinct_ids) + moved += 1 + + return moved, skipped + + +def _append_observations(from_project_dir: Path, into_project_dir: Path) -> int: + from_file = from_project_dir / "observations.jsonl" + if not from_file.exists(): + return 0 + + into_file = into_project_dir / "observations.jsonl" + into_file.parent.mkdir(parents=True, exist_ok=True) + try: + lines = from_file.read_text(encoding="utf-8").splitlines() + except (OSError, UnicodeDecodeError): + return 0 + + if not lines: + return 0 + + with open(into_file, "a", encoding="utf-8") as f: + for line in lines: + if line.strip(): + f.write(line.rstrip("\n") + "\n") + return len([line for line in lines if line.strip()]) + + def load_all_instincts(project: dict, include_global: bool = True) -> list[dict]: """Load all instincts: project-scoped + global. @@ -1180,7 +1330,14 @@ def _promote_auto(project: dict, force: bool, dry_run: bool) -> int: # ───────────────────────────────────────────── def cmd_projects(args) -> int: - """List all known projects and their instinct counts.""" + """List or maintain known projects and their instinct counts.""" + if getattr(args, "project_action", None) == "delete": + return _cmd_projects_delete(args) + if getattr(args, "project_action", None) == "merge": + return _cmd_projects_merge(args) + if getattr(args, "project_action", None) == "gc": + return _cmd_projects_gc(args) + registry = load_registry() if not registry: @@ -1225,6 +1382,143 @@ def cmd_projects(args) -> int: return 0 +def _cmd_projects_delete(args) -> int: + registry = load_registry() + project_id = args.project_id + + if not _validate_project_id(project_id): + print(f"Invalid project ID: {project_id}", file=sys.stderr) + return 1 + if project_id not in registry and not (PROJECTS_DIR / project_id).exists(): + print(f"Project '{project_id}' not found.", file=sys.stderr) + return 1 + + counts = _project_counts(project_id) + print(f"Project: {project_id}") + print(f" Instincts: {counts['personal']} personal, {counts['inherited']} inherited") + print(f" Observations: {counts['observations']} events") + + if args.dry_run: + print(f"\n[DRY RUN] Would delete project '{project_id}' from registry and storage.") + return 0 + + if not args.force: + if counts["total"] > 0: + print("\nWarning: this project has instincts or observations.") + response = input(f"Delete project '{project_id}'? [y/N] ") + if response.lower() != "y": + print("Cancelled.") + return 0 + + registry.pop(project_id, None) + _write_registry(registry) + _remove_project_storage(project_id) + print(f"\nDeleted project '{project_id}'.") + return 0 + + +def _cmd_projects_gc(args) -> int: + registry = load_registry() + candidates = [ + project_id + for project_id in sorted(registry) + if _validate_project_id(project_id) and _project_counts(project_id)["total"] == 0 + ] + + if not candidates: + print("No zero-value project entries found.") + return 0 + + print(f"Zero-value project entries: {len(candidates)}") + for project_id in candidates: + pinfo = registry.get(project_id, {}) + print(f" - {pinfo.get('name', project_id)} [{project_id}]") + + if args.dry_run: + print(f"\n[DRY RUN] Would delete {len(candidates)} project entr{'y' if len(candidates) == 1 else 'ies'}.") + return 0 + + if not args.force: + response = input(f"\nDelete {len(candidates)} zero-value project entr{'y' if len(candidates) == 1 else 'ies'}? [y/N] ") + if response.lower() != "y": + print("Cancelled.") + return 0 + + for project_id in candidates: + registry.pop(project_id, None) + _remove_project_storage(project_id) + _write_registry(registry) + print(f"\nDeleted {len(candidates)} zero-value project entr{'y' if len(candidates) == 1 else 'ies'}.") + return 0 + + +def _cmd_projects_merge(args) -> int: + from_id = args.from_id + into_id = args.into_id + + if not _validate_project_id(from_id) or not _validate_project_id(into_id): + print("Invalid project ID.", file=sys.stderr) + return 1 + if from_id == into_id: + print("Cannot merge a project into itself.", file=sys.stderr) + return 1 + + registry = load_registry() + if from_id not in registry: + print(f"Source project '{from_id}' not found.", file=sys.stderr) + return 1 + if into_id not in registry: + print(f"Destination project '{into_id}' not found.", file=sys.stderr) + return 1 + + from_counts = _project_counts(from_id) + into_counts = _project_counts(into_id) + print(f"Merge: {from_id} -> {into_id}") + print(f" Source: {from_counts['personal']} personal, {from_counts['inherited']} inherited, {from_counts['observations']} observations") + print(f" Destination before merge: {into_counts['personal']} personal, {into_counts['inherited']} inherited, {into_counts['observations']} observations") + + if args.dry_run: + print("\n[DRY RUN] Would merge source project into destination and remove source.") + return 0 + + if not args.force: + response = input(f"\nMerge '{from_id}' into '{into_id}' and remove source? [y/N] ") + if response.lower() != "y": + print("Cancelled.") + return 0 + + from_project_dir = PROJECTS_DIR / from_id + into_project_dir = PROJECTS_DIR / into_id + into_project_dir.mkdir(parents=True, exist_ok=True) + + personal_existing = _project_instinct_ids(into_project_dir, "personal") + inherited_existing = _project_instinct_ids(into_project_dir, "inherited") + personal_moved, personal_skipped = _merge_instinct_dir( + from_project_dir / "instincts" / "personal", + into_project_dir / "instincts" / "personal", + personal_existing, + ) + inherited_moved, inherited_skipped = _merge_instinct_dir( + from_project_dir / "instincts" / "inherited", + into_project_dir / "instincts" / "inherited", + inherited_existing, + ) + observations_moved = _append_observations(from_project_dir, into_project_dir) + + registry.pop(from_id, None) + destination = registry.get(into_id, {}) + destination["last_seen"] = datetime.now(timezone.utc).isoformat().replace("+00:00", "Z") + registry[into_id] = destination + _write_registry(registry) + _remove_project_storage(from_id) + + print("\nMerged project registry entry.") + print(f" Moved instincts: {personal_moved + inherited_moved}") + print(f" Skipped duplicate instincts: {personal_skipped + inherited_skipped}") + print(f" Appended observations: {observations_moved}") + return 0 + + # ───────────────────────────────────────────── # Generate Evolved Structures # ───────────────────────────────────────────── @@ -1486,6 +1780,19 @@ def main() -> int: # Projects (new in v2.1) projects_parser = subparsers.add_parser('projects', help='List known projects and instinct counts') + projects_subparsers = projects_parser.add_subparsers(dest='project_action') + projects_delete = projects_subparsers.add_parser('delete', help='Delete a project registry entry') + projects_delete.add_argument('project_id', help='Project ID to delete') + projects_delete.add_argument('--dry-run', action='store_true', help='Preview without deleting') + projects_delete.add_argument('--force', action='store_true', help='Skip confirmation') + projects_merge = projects_subparsers.add_parser('merge', help='Merge one project registry entry into another') + projects_merge.add_argument('from_id', help='Source project ID') + projects_merge.add_argument('into_id', help='Destination project ID') + projects_merge.add_argument('--dry-run', action='store_true', help='Preview without merging') + projects_merge.add_argument('--force', action='store_true', help='Skip confirmation') + projects_gc = projects_subparsers.add_parser('gc', help='Delete zero-value project registry entries') + projects_gc.add_argument('--dry-run', action='store_true', help='Preview without deleting') + projects_gc.add_argument('--force', action='store_true', help='Skip confirmation') # Prune (pending instinct TTL) prune_parser = subparsers.add_parser('prune', help='Delete pending instincts older than TTL') diff --git a/tests/hooks/detect-project-worktree.test.js b/tests/hooks/detect-project-worktree.test.js index 9c0a8fa2..a82a6f73 100644 --- a/tests/hooks/detect-project-worktree.test.js +++ b/tests/hooks/detect-project-worktree.test.js @@ -181,29 +181,14 @@ test('detect-project.sh sets PROJECT_NAME and non-global PROJECT_ID for worktree } }); - // Create a worktree-like directory with .git as a file const worktreeDir = path.join(testDir, 'my-worktree'); - fs.mkdirSync(worktreeDir, { recursive: true }); - - // Set up the worktree directory structure in the main repo - const worktreesDir = path.join(mainRepo, '.git', 'worktrees', 'my-worktree'); - fs.mkdirSync(worktreesDir, { recursive: true }); - - // Create the gitdir file and commondir in the worktree metadata - const mainGitDir = path.join(mainRepo, '.git'); - fs.writeFileSync( - path.join(worktreesDir, 'commondir'), - '../..\n' - ); - fs.writeFileSync( - path.join(worktreesDir, 'HEAD'), - fs.readFileSync(path.join(mainGitDir, 'HEAD'), 'utf8') - ); - - // Write .git file in the worktree directory (this is what git worktree creates) - fs.writeFileSync( - path.join(worktreeDir, '.git'), - `gitdir: ${worktreesDir}\n` + execSync(`git worktree add "${worktreeDir}" -b feature/project-id`, { + cwd: mainRepo, + stdio: 'pipe' + }); + assert.ok( + fs.statSync(path.join(worktreeDir, '.git')).isFile(), + 'linked worktree should expose .git as a file' ); // Source detect-project.sh from the worktree directory and capture results @@ -248,6 +233,61 @@ test('detect-project.sh sets PROJECT_NAME and non-global PROJECT_ID for worktree } }); +test('detect-project.sh uses the main worktree hash when no remote exists', () => { + const testDir = createTempDir(); + + try { + const mainRepo = path.join(testDir, 'main-repo'); + const worktreeDir = path.join(testDir, 'feature-worktree'); + const homeDir = path.join(testDir, 'home'); + fs.mkdirSync(mainRepo, { recursive: true }); + fs.mkdirSync(homeDir, { recursive: true }); + execSync('git init', { cwd: mainRepo, stdio: 'pipe' }); + execSync('git commit --allow-empty -m "init"', { + cwd: mainRepo, + stdio: 'pipe', + env: { + ...process.env, + GIT_AUTHOR_NAME: 'Test', + GIT_AUTHOR_EMAIL: 'test@test.com', + GIT_COMMITTER_NAME: 'Test', + GIT_COMMITTER_EMAIL: 'test@test.com' + } + }); + execSync(`git worktree add "${worktreeDir}" -b feature/no-remote`, { + cwd: mainRepo, + stdio: 'pipe' + }); + + function detectId(targetDir) { + const script = ` + export HOME="${toBashPath(homeDir)}" + export USERPROFILE="${toBashPath(homeDir)}" + export CLAUDE_PROJECT_DIR="${toBashPath(targetDir)}" + source "${toBashPath(detectProjectPath)}" >/dev/null + printf "%s" "$PROJECT_ID" + `; + return execFileSync('bash', ['-lc', script], { + cwd: targetDir, + timeout: 10000, + env: { + ...process.env, + HOME: toBashPath(homeDir), + USERPROFILE: toBashPath(homeDir), + CLAUDE_PROJECT_DIR: toBashPath(targetDir) + } + }).toString(); + } + + const mainId = detectId(mainRepo); + const worktreeId = detectId(worktreeDir); + assert.ok(mainId && mainId !== 'global', 'main repo should get a project id'); + assert.strictEqual(worktreeId, mainId, 'linked worktree should share the main worktree project id'); + } finally { + cleanupDir(testDir); + } +}); + // ────────────────────────────────────────────────────── // Summary // ────────────────────────────────────────────────────── diff --git a/tests/hooks/hooks.test.js b/tests/hooks/hooks.test.js index 6475fe54..7c69f988 100644 --- a/tests/hooks/hooks.test.js +++ b/tests/hooks/hooks.test.js @@ -3300,11 +3300,14 @@ async function runTests() { assert.strictEqual(result.code, 0, `observe.sh should exit successfully, stderr: ${result.stderr}`); - const projectsDir = path.join(homeDir, '.local', 'share', 'ecc-homunculus', 'projects'); - const projectIds = fs.readdirSync(projectsDir); - assert.strictEqual(projectIds.length, 1, 'observe.sh should create one project-scoped observation directory'); + const homunculusDir = path.join(homeDir, '.local', 'share', 'ecc-homunculus'); + const projectsDir = path.join(homunculusDir, 'projects'); + assert.ok( + !fs.existsSync(projectsDir) || fs.readdirSync(projectsDir).length === 0, + 'observe.sh should not create a project-scoped directory for a non-git cwd' + ); - const observationsPath = path.join(projectsDir, projectIds[0], 'observations.jsonl'); + const observationsPath = path.join(homunculusDir, 'observations.jsonl'); const observations = fs.readFileSync(observationsPath, 'utf8').trim().split('\n').filter(Boolean); assert.ok(observations.length > 0, 'observe.sh should append at least one observation'); diff --git a/tests/hooks/observe-subdirectory-detection.test.js b/tests/hooks/observe-subdirectory-detection.test.js index 5081efa8..559f0cff 100644 --- a/tests/hooks/observe-subdirectory-detection.test.js +++ b/tests/hooks/observe-subdirectory-detection.test.js @@ -135,8 +135,8 @@ test('observe.sh resolves cwd to git root before setting CLAUDE_PROJECT_DIR', () 'observe.sh should resolve STDIN_CWD to git repo root' ); assert.ok( - content.includes('${_GIT_ROOT:-$STDIN_CWD}'), - 'observe.sh should fall back to raw cwd when git root is unavailable' + content.includes('export CLV2_NO_PROJECT=1'), + 'observe.sh should mark non-git cwd payloads as global instead of registering raw cwd' ); }); @@ -250,7 +250,7 @@ test('observe.sh falls back to CLAUDE_HOOK_EVENT_NAME when no phase argument is } }); -test('observe.sh keeps the raw cwd when the directory is not inside a git repo', () => { +test('observe.sh records non-git cwd payloads globally without project registry side effects', () => { const testRoot = createTempDir(); try { @@ -262,12 +262,17 @@ test('observe.sh keeps the raw cwd when the directory is not inside a git repo', const result = runObserve({ homeDir, cwd: nonGitDir }); assert.strictEqual(result.status, 0, result.stderr); - const { metadata } = readSingleProjectMetadata(homeDir); - assert.strictEqual( - normalizeComparablePath(metadata.root), - normalizeComparablePath(nonGitDir), - 'project metadata root should stay on the non-git cwd' + const homunculusDir = path.join(homeDir, '.local', 'share', 'ecc-homunculus'); + const projectsDir = path.join(homunculusDir, 'projects'); + const registryPath = path.join(homunculusDir, 'projects.json'); + const observationsPath = path.join(homunculusDir, 'observations.jsonl'); + + assert.ok(!fs.existsSync(registryPath), 'non-git cwd should not create projects.json'); + assert.ok( + !fs.existsSync(projectsDir) || fs.readdirSync(projectsDir).length === 0, + 'non-git cwd should not create project directories' ); + assert.ok(fs.existsSync(observationsPath), 'non-git cwd should still record a global observation'); } finally { cleanupDir(testRoot); } diff --git a/tests/scripts/instinct-cli-projects.test.js b/tests/scripts/instinct-cli-projects.test.js new file mode 100644 index 00000000..3ebd8651 --- /dev/null +++ b/tests/scripts/instinct-cli-projects.test.js @@ -0,0 +1,260 @@ +const assert = require('assert'); +const fs = require('fs'); +const os = require('os'); +const path = require('path'); +const crypto = require('crypto'); +const { spawnSync } = require('child_process'); + +let passed = 0; +let failed = 0; + +const repoRoot = path.resolve(__dirname, '..', '..'); +const cliPath = path.join( + repoRoot, + 'skills', + 'continuous-learning-v2', + 'scripts', + 'instinct-cli.py' +); + +function test(name, fn) { + try { + fn(); + console.log(` ✓ ${name}`); + passed += 1; + } catch (error) { + console.log(` ✗ ${name}`); + console.log(` Error: ${error.message}`); + failed += 1; + } +} + +function createTempDir() { + return fs.mkdtempSync(path.join(os.tmpdir(), 'ecc-instinct-cli-projects-')); +} + +function cleanupDir(dir) { + fs.rmSync(dir, { recursive: true, force: true }); +} + +function writeJson(filePath, payload) { + fs.mkdirSync(path.dirname(filePath), { recursive: true }); + fs.writeFileSync(filePath, `${JSON.stringify(payload, null, 2)}\n`); +} + +function readJson(filePath) { + return JSON.parse(fs.readFileSync(filePath, 'utf8')); +} + +function writeInstinct(filePath, id, confidence = 0.9) { + fs.mkdirSync(path.dirname(filePath), { recursive: true }); + fs.writeFileSync( + filePath, + [ + '---', + `id: ${id}`, + 'trigger: "when repeated"', + `confidence: ${confidence}`, + 'domain: workflow', + '---', + '', + `Action for ${id}.`, + '', + ].join('\n') + ); +} + +function seedProject(root, id, options = {}) { + const projectDir = path.join(root, 'projects', id); + const personalDir = path.join(projectDir, 'instincts', 'personal'); + const inheritedDir = path.join(projectDir, 'instincts', 'inherited'); + fs.mkdirSync(personalDir, { recursive: true }); + fs.mkdirSync(inheritedDir, { recursive: true }); + + for (const instinct of options.personal || []) { + writeInstinct(path.join(personalDir, `${instinct}.yaml`), instinct); + } + for (const instinct of options.inherited || []) { + writeInstinct(path.join(inheritedDir, `${instinct}.yaml`), instinct); + } + if (options.observations) { + fs.writeFileSync( + path.join(projectDir, 'observations.jsonl'), + options.observations.map(row => JSON.stringify(row)).join('\n') + '\n' + ); + } + + return projectDir; +} + +function projectHash(value) { + return crypto.createHash('sha256').update(value).digest('hex').slice(0, 12); +} + +function runGit(cwd, args) { + const result = spawnSync('git', args, { + cwd, + encoding: 'utf8', + }); + assert.strictEqual(result.status, 0, result.stderr); + return result.stdout.trim(); +} + +function runCli(root, args, options = {}) { + return spawnSync('python3', [cliPath, ...args], { + cwd: options.cwd || repoRoot, + encoding: 'utf8', + env: { + ...process.env, + CLV2_HOMUNCULUS_DIR: root, + HOME: path.join(root, 'home'), + USERPROFILE: path.join(root, 'home'), + CLAUDE_PROJECT_DIR: '', + ...(options.env || {}), + }, + }); +} + +console.log('\n=== Testing instinct-cli.py projects maintenance ===\n'); + +test('projects delete --dry-run preserves registry and project files', () => { + const root = createTempDir(); + try { + const registryPath = path.join(root, 'projects.json'); + seedProject(root, 'alpha123', { + personal: ['keep-me'], + observations: [{ event: 'tool_complete' }], + }); + writeJson(registryPath, { + alpha123: { name: 'alpha', root: '/repo/alpha', remote: '', last_seen: '2026-01-01T00:00:00Z' }, + }); + + const result = runCli(root, ['projects', 'delete', 'alpha123', '--dry-run']); + assert.strictEqual(result.status, 0, result.stderr); + assert.match(result.stdout, /would delete/i); + assert.ok(fs.existsSync(path.join(root, 'projects', 'alpha123'))); + assert.ok(readJson(registryPath).alpha123); + } finally { + cleanupDir(root); + } +}); + +test('projects delete --force removes registry entry and project directory', () => { + const root = createTempDir(); + try { + const registryPath = path.join(root, 'projects.json'); + seedProject(root, 'alpha123', { personal: ['delete-me'] }); + writeJson(registryPath, { + alpha123: { name: 'alpha', root: '/repo/alpha', remote: '', last_seen: '2026-01-01T00:00:00Z' }, + }); + + const result = runCli(root, ['projects', 'delete', 'alpha123', '--force']); + assert.strictEqual(result.status, 0, result.stderr); + assert.ok(!fs.existsSync(path.join(root, 'projects', 'alpha123'))); + assert.ok(!readJson(registryPath).alpha123); + } finally { + cleanupDir(root); + } +}); + +test('projects gc --force removes only zero-value project entries', () => { + const root = createTempDir(); + try { + const registryPath = path.join(root, 'projects.json'); + seedProject(root, 'empty000'); + seedProject(root, 'active999', { personal: ['active'] }); + writeJson(registryPath, { + empty000: { name: 'empty', root: '/tmp/empty', remote: '', last_seen: '2026-01-01T00:00:00Z' }, + active999: { name: 'active', root: '/repo/active', remote: '', last_seen: '2026-01-02T00:00:00Z' }, + }); + + const result = runCli(root, ['projects', 'gc', '--force']); + assert.strictEqual(result.status, 0, result.stderr); + const registry = readJson(registryPath); + assert.ok(!registry.empty000); + assert.ok(registry.active999); + assert.ok(!fs.existsSync(path.join(root, 'projects', 'empty000'))); + assert.ok(fs.existsSync(path.join(root, 'projects', 'active999'))); + } finally { + cleanupDir(root); + } +}); + +test('projects merge deduplicates instincts, appends observations, and removes source', () => { + const root = createTempDir(); + try { + const registryPath = path.join(root, 'projects.json'); + seedProject(root, 'from111', { + personal: ['shared', 'from-only'], + observations: [{ event: 'from-event' }], + }); + seedProject(root, 'into222', { + personal: ['shared', 'into-only'], + observations: [{ event: 'into-event' }], + }); + writeJson(registryPath, { + from111: { name: 'from', root: '/repo/from', remote: '', last_seen: '2026-01-01T00:00:00Z' }, + into222: { name: 'into', root: '/repo/into', remote: '', last_seen: '2026-01-02T00:00:00Z' }, + }); + + const result = runCli(root, ['projects', 'merge', 'from111', 'into222', '--force']); + assert.strictEqual(result.status, 0, result.stderr); + assert.ok(!fs.existsSync(path.join(root, 'projects', 'from111'))); + assert.ok(!readJson(registryPath).from111); + assert.ok(readJson(registryPath).into222); + + const intoPersonal = path.join(root, 'projects', 'into222', 'instincts', 'personal'); + assert.ok(fs.existsSync(path.join(intoPersonal, 'shared.yaml'))); + assert.ok(fs.existsSync(path.join(intoPersonal, 'from-only.yaml'))); + assert.ok(fs.existsSync(path.join(intoPersonal, 'into-only.yaml'))); + + const observations = fs.readFileSync( + path.join(root, 'projects', 'into222', 'observations.jsonl'), + 'utf8' + ); + assert.match(observations, /from-event/); + assert.match(observations, /into-event/); + } finally { + cleanupDir(root); + } +}); + +test('status migrates legacy no-remote linked worktree project dirs to main worktree id', () => { + const root = createTempDir(); + const repoParent = createTempDir(); + try { + const mainWorktree = path.join(repoParent, 'main'); + const linkedWorktree = path.join(repoParent, 'linked'); + fs.mkdirSync(mainWorktree, { recursive: true }); + runGit(mainWorktree, ['init']); + runGit(mainWorktree, ['config', 'user.email', 'ecc@example.test']); + runGit(mainWorktree, ['config', 'user.name', 'ECC Test']); + fs.writeFileSync(path.join(mainWorktree, 'README.md'), 'test\n'); + runGit(mainWorktree, ['add', 'README.md']); + runGit(mainWorktree, ['commit', '-m', 'init']); + runGit(mainWorktree, ['worktree', 'add', linkedWorktree]); + + const mainRoot = runGit(mainWorktree, ['rev-parse', '--show-toplevel']); + const linkedRoot = runGit(linkedWorktree, ['rev-parse', '--show-toplevel']); + const oldLinkedId = projectHash(linkedRoot); + const mainId = projectHash(mainRoot); + seedProject(root, oldLinkedId, { personal: ['legacy-worktree'] }); + + const result = runCli(root, ['status'], { cwd: linkedRoot }); + assert.strictEqual(result.status, 0, result.stderr); + assert.ok(!fs.existsSync(path.join(root, 'projects', oldLinkedId))); + assert.ok(fs.existsSync(path.join(root, 'projects', mainId))); + assert.ok( + fs.existsSync(path.join(root, 'projects', mainId, 'instincts', 'personal', 'legacy-worktree.yaml')) + ); + assert.match(result.stdout, new RegExp(`\\(${mainId}\\)`)); + } finally { + cleanupDir(root); + cleanupDir(repoParent); + } +}); + +console.log(`\nPassed: ${passed}`); +console.log(`Failed: ${failed}`); + +process.exit(failed > 0 ? 1 : 0); From 8bf4de56b255323092114ac9e1198dc4d83083c1 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 13:03:58 -0400 Subject: [PATCH 49/61] docs(release): refresh hypergrowth evidence --- docs/ECC-2.0-GA-ROADMAP.md | 12 ++++++---- .../owner-approval-packet-2026-05-19.md | 6 ++--- .../2.0.0-rc.1/preview-pack-manifest.md | 2 +- .../publication-evidence-2026-05-19.md | 23 ++++++++++++------ .../2.0.0-rc.1/publication-readiness.md | 10 ++++---- .../2.0.0-rc.1/video-suite-production.md | 8 ++++--- ...cc-2-hypergrowth-release-command-center.md | 24 +++++++++++++++++++ scripts/platform-audit.js | 2 +- tests/docs/ecc2-release-surface.test.js | 4 +++- .../operator-readiness-dashboard.test.js | 4 ++-- tests/scripts/platform-audit.test.js | 2 +- 11 files changed, 69 insertions(+), 28 deletions(-) diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index 58655881..cedfda80 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -85,11 +85,15 @@ As of 2026-05-19: current May 19 queue-zero state, canonical ECC identity merge, release video suite gate, partner/sponsor/talk outreach pack, owner approval packet (`owner-approval-packet-2026-05-19.md`), preview-pack smoke digest - `790430aef4a8`, local 2550-test suite, PR #2001 merge and GitHub Actions run + `790430aef4a8`, local 2560-test suite, PR #2001 merge and GitHub Actions run `26102500291` success, PR #2002's owner-approval dashboard gate refresh and GitHub Actions run `26103853507`, PR #2004's Linear readiness evidence sync and GitHub Actions run `26105012698`, plus PR #2005's post-PR #2004 - evidence refresh and GitHub Actions run `26106321921`. The May 19 Linear + evidence refresh and GitHub Actions run `26106321921`, PR #2008's supply-chain + evidence gate fix and GitHub Actions run `26108473648`, post-PR #2006 main CI + run `26109953093`, and PR #2009's project-registry hygiene GitHub Actions run + `26111313938`, followed by post-PR #2009 main CI run `26111946778`. The May + 19 Linear sync document remains the current external project status surface, and the supply-chain gate now also records the `@types/node@25.7.0` pin and `brace-expansion` lock refresh needed for current npm audit/signature @@ -749,9 +753,9 @@ is not complete unless the evidence column exists and has been freshly verified. | Keep public PRs below 20 | Repo-family PR recheck | 0 open PRs across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-19 after merging PR #2004 and refreshing platform audit evidence | Complete | | Keep public issues below 20 | Repo-family issue recheck | 0 open issues across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-19 after the live platform audit refresh | Complete | | Manage repository discussions | Repo-family discussion recheck plus response playbook | Platform audit reports 0 discussion maintainer-touch gaps and 0 answerable Q&A missing accepted answers; trunk has 59 total discussions after #2003 was routed with a maintainer response; `docs/architecture/discussion-response-playbook.md` distinguishes support, maintainer coordination, stale/concluded, release, informational, and security-sensitive response paths | Complete | -| Manage PR discussions | PR review/comment closure plus merge/close state | ECC #1990-#2004 merged through the harness audit, canonical identity, release video suite, growth outreach, evidence refresh, visual QA, suite-count, owner-approval packet, owner-approval dashboard gate, and Linear readiness evidence batch; no open tracked PRs remain | Complete | +| Manage PR discussions | PR review/comment closure plus merge/close state | ECC #1990-#2009 merged through the harness audit, canonical identity, release video suite, growth outreach, evidence refresh, visual QA, suite-count, owner-approval packet, owner-approval dashboard gate, Linear readiness evidence, supply-chain evidence gate, per-project Claude Code adapter, and continuous-learning project-registry hygiene batch; no open tracked PRs remain | Complete | | Salvage useful stale work | `docs/stale-pr-salvage-ledger.md` plus `docs/legacy-artifact-inventory.md` | Ledger records salvaged, superseded, skipped, and manual-review tails; #1815-#1818 added cost tracking, skill scout, frontend design guidance, code-reviewer false-positive guardrails, and the May 12 gap pass; #1687, #1609, #1563, #1564, and #1565 localization tails are attached to Linear ITO-55 for language-owner review and no automatic import remains release-blocking | Complete; repeat legacy scan before release | -| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 19 evidence records queue-zero state, canonical ECC identity, release video suite, growth outreach pack, owner approval packet, local 2550-test suite, PR #2001 merge and GitHub Actions run `26102500291`, PR #2002 owner-approval dashboard gate refresh and GitHub Actions run `26103853507`, PR #2004 Linear readiness evidence sync and GitHub Actions run `26105012698`, May 19 operator dashboard, `owner-approval-packet-2026-05-19.md`, and preview-pack smoke digest `790430aef4a8` | Needs final release approval | +| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 19 evidence records queue-zero state, canonical ECC identity, release video suite, growth outreach pack, owner approval packet, local 2560-test suite, PR #2001 merge and GitHub Actions run `26102500291`, PR #2002 owner-approval dashboard gate refresh and GitHub Actions run `26103853507`, PR #2004 Linear readiness evidence sync and GitHub Actions run `26105012698`, PR #2008 supply-chain evidence gate CI run `26108473648`, post-PR #2006 main CI run `26109953093`, PR #2009 project-registry hygiene GitHub Actions run `26111313938`, post-PR #2009 main CI run `26111946778`, May 19 operator dashboard, `owner-approval-packet-2026-05-19.md`, and preview-pack smoke digest `790430aef4a8` | Needs final release approval | | Hermes specialized skills included safely | Hermes setup/import docs and sanitized skill surface | Hermes setup and import playbook are public; secrets stay local | Needs final release review | | Naming and rename readiness | Naming matrix across package/plugin/docs/social surfaces | `docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md` records current package, repo, Claude plugin, Codex plugin, OpenCode, and npm availability evidence | Complete for rc.1; post-rc rename remains future work | | Claude and Codex plugin publication | Contact/submission path with required artifacts and status | Publication readiness, naming matrix, and May 12 dry-run evidence document plugin validation, clean-checkout Claude tag/install smoke, and Codex marketplace CLI shape | Needs explicit approval for real tag/push and marketplace submission | diff --git a/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md b/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md index d60d765a..1f77e36d 100644 --- a/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md @@ -8,7 +8,7 @@ release action after the final evidence commands are rerun from the intended release commit. Source commit for the clean evidence baseline this packet extends: -`ac7434ea8f39166b11e9d06ce64b38c4fb8d9202`. +`bc519e5b8ed42f26c0a5a611756e04351c323f21`. ## Current Evidence @@ -18,8 +18,8 @@ Source commit for the clean evidence baseline this packet extends: | Preview pack smoke | ready true, digest `790430aef4a8`, 5/5 checks | yes | | Video suite | ready true, 15/15 source assets, 13/13 suite artifacts, 12/12 publish candidates | yes | | Release surface tests | 27/27 passed after this packet was added | yes | -| Full local suite | 2550/2550 passed after this packet was added | yes | -| GitHub CI | PR #1998, PR #1999, PR #2000, PR #2001, PR #2002, and PR #2004 merged after green required checks | verify current head | +| Full local suite | 2560/2560 passed after PR #2009 was prepared; focused post-merge regressions passed on `main` | yes | +| GitHub CI | PR #1998, PR #1999, PR #2000, PR #2001, PR #2002, PR #2004, PR #2008, post-PR #2006 `main`, PR #2009, and post-PR #2009 `main` all merged or advanced after green required checks | verify current head | ## Decision Register diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index f15a7d62..beb34a1e 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -25,7 +25,7 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-16.md` | Current May 16/17 queue cleanup, recsys skill merge, GateGuard triage, PR #1947 supply-chain protection, AgentShield #87 plugin-cache confidence evidence, AgentShield #88 evidence-pack inspect/readback, AgentShield #89 evidence-pack fleet routing, AgentShield #90 fleet review items, AgentShield #91 policy export, AgentShield #92 policy promotion, ECC-Tools #76 fleet-summary consumption, ECC-Tools #77 hosted finding evidence paths, ECC-Tools #78 harness policy-route linking, dashboard refresh, and combined Node/Rust/release-surface gate evidence through the May 16 mirror | Must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` | May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack protection recheck, npm audit/signature checks, legacy and Linear progress routing, deterministic preview-pack smoke, operator dashboard refresh, Linear sync, and GitHub CI evidence for `27dc2918` | Superseded by the May 18 evidence snapshot; repeat from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, supply-chain recheck, AgentShield evidence mirror, Linear sync, current-head CI/security scan success for `4470e2e6`, and ITO-46 naming/plugin publication closure | Superseded by the May 19 ECC identity, video, and growth evidence snapshot | -| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, May 19 operator dashboard, preview-pack smoke digest `790430aef4a8`, 2550-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, PR #2004 Linear readiness evidence sync CI success, and the May 19 Linear sync document | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | +| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, May 19 operator dashboard, preview-pack smoke digest `790430aef4a8`, 2560-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, PR #2004 Linear readiness evidence sync CI success, PR #2008 supply-chain evidence gate CI success, post-PR #2006 main CI success, PR #2009 project-registry hygiene CI success, post-PR #2009 main CI success, and the May 19 Linear sync document | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 19 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and adds the current `$1,728/mo` to `$10,000/mo` hypergrowth, video owner-approval, and outbound-pack operating lanes | diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md index d3ca65b8..e8fa6fd0 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -8,9 +8,9 @@ social announcement. | Field | Evidence | | --- | --- | -| Upstream main | `d6022d6b8dc5ef1393cf18ae40ee58f646f3754e` | +| Upstream main | `bc519e5b8ed42f26c0a5a611756e04351c323f21` | | Git remote | `https://github.com/affaan-m/ECC.git` | -| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, PR #2001 owner approval packet addition, PR #2002 owner approval dashboard gate refresh, PR #2004 Linear readiness evidence sync, and PR #2005 post-PR #2004 evidence refresh | +| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, PR #2001 owner approval packet addition, PR #2002 owner approval dashboard gate refresh, PR #2004 Linear readiness evidence sync, PR #2005 post-PR #2004 evidence refresh, PR #2008 release supply-chain evidence gate fix, PR #2006 per-project Claude Code adapter, and PR #2009 continuous-learning project registry hygiene fix | | Local status caveat | `git status --short --branch` was clean after pulling `origin/main`; generated evidence files are committed after the source snapshot they describe | The release operator must repeat all publish-facing checks from the exact final @@ -53,6 +53,9 @@ Tracked repositories in the platform audit were: | PR #2002 | Merged the owner-approval dashboard refresh so the operator dashboard fails closed when the final decision sheet is missing or incomplete; CI passed before merge | | PR #2004 | Merged the May 19 Linear readiness evidence sync after PR #2002, including roadmap, dashboard, preview-pack manifest, publication evidence, operator dashboard generator, and release-surface test updates | | PR #2005 | Merged the post-PR #2004 evidence refresh, keeping the May 19 readiness ledger, dashboard, roadmap, and release-surface references current on `main` | +| PR #2008 | Merged the release supply-chain evidence gate fix so platform-audit readiness keeps matching current publication evidence | +| PR #2006 | Merged the `claude-project` install target for per-project Claude Code adapter support, then fixed the manifest schema enum on top of the feature branch before merge | +| PR #2009 | Merged the continuous-learning project registry hygiene fix: non-git hook payloads stay global, no-remote linked worktrees migrate to the main worktree project ID, and `instinct-cli.py projects delete`, `merge`, and `gc` provide operator maintenance commands | ## Release And Growth Evidence @@ -63,13 +66,18 @@ Tracked repositories in the platform audit were: | Operator dashboard | `npm run operator:dashboard -- --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Regenerated from the May 19 `main` baseline with platform audit ready true, 0 tracked PRs, 0 tracked issues, 0 discussion gaps, `$1,728/mo` current MRR, `$10,000/mo` target MRR, the release video suite marked current, and top actions for plugin publication, notifications, outbound approval, AgentShield, and ECC Tools billing | | Supply-chain verification | `npm audit --audit-level=moderate`; `npm audit signatures`; `yarn install --immutable --mode=skip-build` | Current supply-chain refresh found 0 npm vulnerabilities, verified 254 registry signatures and 30 attestations, and accepted the Yarn lock after pinning `@types/node@25.7.0` plus refreshing `brace-expansion` to `5.0.6` / `1.1.14` | | Release video suite | `npm run release:video-suite -- --format json --summary` with `ECC_VIDEO_SOURCE_ROOT` and `ECC_VIDEO_RELEASE_SUITE_ROOT` | Ready true; 15/15 source assets present; 13/13 render, timeline, caption, EDL, and segment artifacts present; 12/12 publish-candidate outputs present with zero detected black-frame segments; primary rough render self-eval passed at 144.759 seconds, 1920x1080, 1 audio stream, and 106.78 MB | -| Full local suite | `node tests/run-all.js` | 2550 passed, 0 failed | +| Focused post-merge regression set | `node tests/hooks/detect-project-worktree.test.js`; `node tests/hooks/observe-subdirectory-detection.test.js`; `node tests/scripts/instinct-cli-projects.test.js`; `node tests/hooks/hooks.test.js` | 10/10, 6/6, 5/5, and 237/237 passed after PR #2009 merged | +| Full local suite | `node tests/run-all.js` | 2560 passed, 0 failed | | PR #1998 CI | GitHub Actions run `26099020341` | Completed successfully for `d500de1e9f11c0446b6a1349bd98b522d31f9125`; all reported checks passed, including lint, validation, security scan, coverage, GitGuardian, CodeRabbit, Cubic, and the macOS/Ubuntu/Windows test matrix | | PR #1999 CI | GitHub Actions run `26100148726` | Completed successfully for `90584b6d5e5814bc2ad9a4cd651bebd043de989d`; lint, validation, security scan, coverage, GitGuardian, CodeRabbit, and the macOS/Ubuntu/Windows test matrix passed; Cubic completed neutral and did not block merge | | PR #2001 CI | GitHub Actions run `26102500291` | Completed successfully for `8148340ad14eb32c971346f0cb4cb9431ec0f5de`; required checks passed before merge | | PR #2002 CI | GitHub Actions run `26103853507` | Completed successfully before merge; required checks passed, Cubic remained non-blocking, and PR #2002 merged into `main` as `c7d662c3c68719e5ef0b5305ca3f6782b3214224` | | PR #2004 CI | GitHub Actions run `26105012698` | Completed successfully after rerunning the single failed Windows Node 18 yarn job; required checks passed, Cubic remained non-blocking, and PR #2004 merged into `main` as `ac7434ea8f39166b11e9d06ce64b38c4fb8d9202` | | PR #2005 CI | GitHub Actions run `26106321921` | Completed successfully with 37 completed jobs, 0 failed jobs, and PR #2005 merged into `main` as `d6022d6b8dc5ef1393cf18ae40ee58f646f3754e` | +| PR #2008 CI | GitHub Actions run `26108473648` | Completed successfully across the required matrix before merge; non-blocking Cubic skipped after review | +| Post-PR #2006 main CI | GitHub Actions run `26109953093` | Completed successfully with 37 completed jobs, 0 failed jobs, and `main` advanced to `98bd517451f38fa0150a53aab4234c2239a47b7e` | +| PR #2009 CI | GitHub Actions run `26111313938` | Completed successfully with 37 completed jobs, 0 failed jobs after replacing the brittle fake-worktree regression fixture with a real `git worktree add` setup | +| Post-PR #2009 main CI | GitHub Actions run `26111946778` | Completed successfully with 37 completed jobs, 0 failed jobs, and `main` advanced to `bc519e5b8ed42f26c0a5a611756e04351c323f21` | | Linear sync | Linear document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` plus project comment `a6411e3a-8c8e-4a58-adba-687e77d4c543` | Project and issue lanes now record PR #2002 evidence, discussion #2003 routing, owner-approval dashboard gate, and In Progress status for ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56 | | Public-path sanitization | `node scripts/ci/validate-no-personal-paths.js` through local suite and CI | Passed | | Markdown and whitespace | `markdownlint` focused release docs plus `git diff --check` before PR #1999 | Passed | @@ -109,10 +117,11 @@ Tracked repositories in the platform audit were: ## Result The tracked public PR queue, issue queue, discussion queue, canonical ECC -identity, release video suite, preview pack, and growth outreach packet are -current on May 19, 2026 for `main` through -`d6022d6b8dc5ef1393cf18ae40ee58f646f3754e`. The remaining video work is -owner approval, upload, and public URL attachment, not render or QA production. +identity, release video suite, preview pack, growth outreach packet, per-project +Claude Code adapter surface, and continuous-learning project registry hygiene +are current on May 19, 2026 for `main` through +`bc519e5b8ed42f26c0a5a611756e04351c323f21`. The remaining video work is owner +approval, upload, and public URL attachment, not render or QA production. This improves publication readiness but does not replace the approval-gated release, package, plugin, billing, Discord, and announcement steps in diff --git a/docs/releases/2.0.0-rc.1/publication-readiness.md b/docs/releases/2.0.0-rc.1/publication-readiness.md index 32900601..aaf7fba8 100644 --- a/docs/releases/2.0.0-rc.1/publication-readiness.md +++ b/docs/releases/2.0.0-rc.1/publication-readiness.md @@ -101,22 +101,22 @@ Record the exact commit SHA and command output before any publication action: | Evidence | Command | Required result | Recorded output | | --- | --- | --- | --- | -| Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | Post-PR #2005 baseline `d6022d6b8dc5ef1393cf18ae40ee58f646f3754e`: `## main...origin/main`; repeat from the exact final publication commit before release | +| Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | Current May 19 baseline `bc519e5b8ed42f26c0a5a611756e04351c323f21`: `## main...origin/main`; repeat from the exact final publication commit before release | | Preview-pack smoke | `npm run preview-pack:smoke` | Preview pack artifacts, Hermes boundary, final verification command list, and publication blockers pass | `publication-evidence-2026-05-19.md`: ready yes, digest `790430aef4a8`, 31 artifacts, 5 passed, 0 failed; repeat in the final strict clean-checkout release pass | | Harness audit | `npm run harness:audit -- --format json` | 80/80 passing | Current release gate: 80/80 across 8 applicable categories, 0 top actions | | Adapter scorecard | `npm run harness:adapters -- --check` | PASS | Current release gate: PASS, 11 adapters | | Observability readiness | `npm run observability:ready` | 21/21 passing | Current release gate: 21/21, ready true | | Release safety gate | `npm run observability:ready -- --format json` | Release Safety category passing with publication readiness, supply-chain, workflow security, package surface, and release-surface evidence | Current release gate keeps Release Safety passing at 3/3; repeat the JSON gate from the exact final release commit | -| Supply-chain verification | `npm audit --audit-level=moderate`; `npm audit signatures`; `yarn install --immutable --mode=skip-build`; `cd ecc2 && cargo audit -q`; Dependabot alerts; GitGuardian Security Checks | 0 vulnerabilities/alerts, registry signatures verified, package-manager locks accepted, GitGuardian clean | Current supply-chain branch: `npm audit` found 0 vulnerabilities; `npm audit signatures` verified 254 registry signatures and 30 attestations; Yarn immutable install accepted the lock after pinning `@types/node@25.7.0` and moving `brace-expansion` to `5.0.6` / `1.1.14`; PR #2005 CI `26106321921` completed 37/37 jobs with 0 failures | -| Root suite | `node tests/run-all.js` | 0 failures | PR #2005 CI `26106321921` completed successfully with 37/37 jobs and 0 failures; current branch reruns focused release/package/docs gates before merge | +| Supply-chain verification | `npm audit --audit-level=moderate`; `npm audit signatures`; `yarn install --immutable --mode=skip-build`; `cd ecc2 && cargo audit -q`; Dependabot alerts; GitGuardian Security Checks | 0 vulnerabilities/alerts, registry signatures verified, package-manager locks accepted, GitGuardian clean | Current supply-chain branch: `npm audit` found 0 vulnerabilities; `npm audit signatures` verified 254 registry signatures and 30 attestations; Yarn immutable install accepted the lock after pinning `@types/node@25.7.0` and moving `brace-expansion` to `5.0.6` / `1.1.14`; PR #2008 CI `26108473648`, post-PR #2006 main CI `26109953093`, PR #2009 CI `26111313938`, and post-PR #2009 main CI `26111946778` completed with 0 failures | +| Root suite | `node tests/run-all.js` | 0 failures | Current May 19 local suite: 2560 passed, 0 failed; post-PR #2009 focused regressions also passed for worktree detection, observe subdirectory/global fallback, project maintenance CLI, and the hooks suite | | Markdown lint | `npx markdownlint-cli '**/*.md' --ignore node_modules` | 0 failures | Current release gate: focused lint passed for `publication-readiness.md`, `publication-evidence-2026-05-19.md`, and `docs/ECC-2.0-GA-ROADMAP.md` | | Package surface | `node tests/scripts/npm-publish-surface.test.js` | 0 failures; no Python bytecode in npm tarball | Current release gate: 2/2 passed | | Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | Current release gate: 27/27 passed after refreshing the discussion-count assertion to the post-PR #2005 baseline | | Optional Rust surface | `cd ecc2 && cargo test` | 0 failures or explicit deferral | `publication-evidence-2026-05-16.md`: 462/462 passed, existing warnings only | -| Queue baseline | `node scripts/platform-audit.js --json` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | Post-PR #2005 baseline: platform audit ready true, 0 open PRs, 0 open issues, 0 conflicting PRs, and 0 blocking dirty files across tracked repos | +| Queue baseline | `node scripts/platform-audit.js --json` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | Current May 19 baseline after PR #2009: platform audit ready true, 0 open PRs, 0 open issues, 0 conflicting PRs, and 0 blocking dirty files across tracked repos | | Discussion baseline | `node scripts/platform-audit.js --json` and `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | Post-PR #2005 baseline: platform audit sampled 59 trunk discussions, 0 needing maintainer touch, 0 answerable discussions missing accepted answer; `docs/architecture/discussion-response-playbook.md` records response templates and security escalation rules | | Linear roadmap | Linear project and issue readback | Detailed roadmap exists with release, security, AgentShield, ECC Tools, legacy, and observability lanes | May 18 Linear comments include ITO-57 `3fe5b2b7-c4fe-401c-a317-b40d72119cb3` and ITO-44 `fb4a4f33-6c2d-421a-bbdb-63cfad3e3ee4`; earlier evidence records the project and 16 issue lanes | -| Operator readiness dashboard | `npm run operator:dashboard -- --json` | Current queue state mapped to macro-goal deliverables and incomplete gaps | Post-PR #2005 baseline: May 19 dashboard is current; platform audit ready true, 0 open PRs, 0 open issues, 0 discussion gaps, 0 dirty files, release video suite current, and publication gates still approval-gated | +| Operator readiness dashboard | `npm run operator:dashboard -- --json` | Current queue state mapped to macro-goal deliverables and incomplete gaps | Current May 19 dashboard is refreshed from the post-PR #2009 baseline; platform audit ready true, 0 open PRs, 0 open issues, 0 discussion gaps, 0 dirty files, release video suite current, and publication gates still approval-gated | | Release URL ledger | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md` plus placeholder-marker scan | Live links and approval-gated links are separated before announcement copy is posted | Ledger records public repo/docs/npm/OpenAI Codex documentation URLs and blocks GitHub release/npm/plugin/billing/social URLs until approval-gated checks pass | | Release name and plugin publication checklist | `docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md` | Name/package/plugin values are frozen, final-release commands are listed, and Claude/Codex publication paths cite current official docs | Checklist keeps `ECC`, `ecc-universal`, and plugin slug `ecc` for rc.1; no npm rename, npm publish, plugin tag, official listing, billing claim, or announcement before final evidence | diff --git a/docs/releases/2.0.0-rc.1/video-suite-production.md b/docs/releases/2.0.0-rc.1/video-suite-production.md index 19ea68aa..292bd612 100644 --- a/docs/releases/2.0.0-rc.1/video-suite-production.md +++ b/docs/releases/2.0.0-rc.1/video-suite-production.md @@ -133,13 +133,15 @@ Use the same production shape as Video Use while keeping the ECC-specific media stack intact: 1. Treat transcript and timeline data as the editing surface. -2. Inspect filmstrip or frame samples only at ambiguous cut points. -3. Keep an edit decision list before rendering. +2. Keep visual inspection on demand: filmstrips, waveform/timeline composites, + or frame samples only at ambiguous cut points. +3. Propose the edit strategy and EDL before rendering. 4. Cut deterministically with FFmpeg. 5. Add proof overlays with Remotion or Manim where product claims need visual evidence. 6. Export the MP4 plus editable timeline and caption state. -7. Run self-eval before any upload or social post. +7. Run cut-boundary, audio, caption, black-frame, and product-claim self-eval + before any upload or social post. Do not dump frames into the repo. Frame samples used for self-eval belong in the local release suite workspace. diff --git a/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md b/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md index 5a7dc203..79feb9e6 100644 --- a/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md +++ b/docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md @@ -42,6 +42,30 @@ MRR growth should come from four lanes at once: - consulting and implementation contracts; - talks, podcasts, conference demos, and partner webinars that create inbound. +## Second Hypergrowth Phase + +The release should behave like a proof engine, not a name-change announcement. +Every public surface should make the product obvious in the first screen, +clip, paragraph, or demo: + +| Workstream | Public proof | Revenue path | +| --- | --- | --- | +| Product category | ECC as the harness-native operator system, not a Claude-only config pack | Converts confused OSS traffic into install, Pro, and sponsor intent | +| Harness coverage | Claude Code, Codex, OpenCode, Cursor, Gemini, Zed, GitHub Copilot, and terminal workflows shown as execution surfaces | Partner conversations with tools, IDEs, model providers, and platform teams | +| Control plane | `ecc2/` alpha dashboard/status/session surface and Hermes operator shell clearly framed as directionally live | Consulting and team implementation sprints | +| Enterprise trust | AgentShield, supply-chain, release, observability, and CI gates shown as repeatable evidence | Security vendors, code-review vendors, platform sponsors, and enterprise pilots | +| Media engine | Primary launch video, five proof clips, browser captures, transcripts, EDLs, captions, and editable timelines | Social reach, podcast/talk booking, sponsor proof, partner demos | +| Community funnel | GitHub Discussions, Discord once approved, sponsor tiers, Pro, and consulting CTAs routed without clutter | Repeatable inbound, not one-off launch spikes | + +The operating rhythm after launch should be weekly: + +1. one product proof clip; +2. one security or release-discipline proof clip; +3. one partner/sponsor/talk outreach batch after owner approval; +4. one public discussion or community prompt; +5. one measurable funnel readback covering repo traffic, sponsor clicks, Pro + conversions, MRR movement, and inbound replies. + ## Release Gates | Lane | Done when | Current action | diff --git a/scripts/platform-audit.js b/scripts/platform-audit.js index a49c8a37..e5a04d5c 100644 --- a/scripts/platform-audit.js +++ b/scripts/platform-audit.js @@ -472,7 +472,7 @@ function buildLocalEvidenceChecks(rootDir) { ), buildCheck( 'release-evidence-current', - includesAll(evidence, ['Release video suite', 'growth outreach', 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', '2550 passed']) ? 'pass' : 'fail', + includesAll(evidence, ['Release video suite', 'growth outreach', 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', '2560 passed']) ? 'pass' : 'fail', 'rc.1 evidence includes current release, video, growth, and CI artifacts', { path: 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md' } ), diff --git a/tests/docs/ecc2-release-surface.test.js b/tests/docs/ecc2-release-surface.test.js index bf7a5a2e..8456ce56 100644 --- a/tests/docs/ecc2-release-surface.test.js +++ b/tests/docs/ecc2-release-surface.test.js @@ -256,11 +256,13 @@ test('GA roadmap mirrors the current May 19 release evidence', () => { for (const marker of [ 'owner-approval-packet-2026-05-19.md', 'preview-pack smoke digest `790430aef4a8`', - 'local 2550-test suite', + 'local 2560-test suite', 'PR #2001', 'GitHub Actions run `26102500291`', 'PR #2002', 'GitHub Actions run `26103853507`', + 'PR #2009', + 'GitHub Actions run `26111313938`', 'ecc-may-19-post-pr-2002-sync-64cef8f668e0', 'owner approval packet', ]) { diff --git a/tests/scripts/operator-readiness-dashboard.test.js b/tests/scripts/operator-readiness-dashboard.test.js index 6a9a4958..77a0f5eb 100644 --- a/tests/scripts/operator-readiness-dashboard.test.js +++ b/tests/scripts/operator-readiness-dashboard.test.js @@ -190,7 +190,7 @@ function seedRepo(rootDir, overrides = {}) { 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', - '2550 passed', + '2560 passed', 'Business baseline', '$1,728/mo', '$8,272/mo' @@ -443,7 +443,7 @@ function runTests() { 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', - '2550 passed', + '2560 passed', 'Business baseline', '$1,728/mo', '$8,272/mo', diff --git a/tests/scripts/platform-audit.test.js b/tests/scripts/platform-audit.test.js index b7b1d9ba..3f9d514e 100644 --- a/tests/scripts/platform-audit.test.js +++ b/tests/scripts/platform-audit.test.js @@ -68,7 +68,7 @@ function seedRepo(rootDir, overrides = {}) { 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', - '2550 passed' + '2560 passed' ].join('\n'), 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md': [ 'This dashboard is generated by `npm run operator:dashboard`', From 3c388b7295b8d91ab01b0ae9529075de89b029d1 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 13:04:22 -0400 Subject: [PATCH 50/61] docs(release): refresh operator dashboard snapshot --- .../2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md index 83125f03..b4775910 100644 --- a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md @@ -2,8 +2,8 @@ This dashboard is generated by `npm run operator:dashboard`. It is an operator snapshot, not release approval. -Generated: 2026-05-19T15:08:49.870Z -Commit: ac7434ea8f39166b11e9d06ce64b38c4fb8d9202 +Generated: 2026-05-19T17:04:04.254Z +Commit: d2e91a49782c3158c552b7eaff3bbf70f8bba887 Status: work remaining ## Current Status From 14d88e517b0c56a80c1a6392b1cde2474948d29f Mon Sep 17 00:00:00 2001 From: luyua9 Date: Wed, 20 May 2026 01:15:27 +0800 Subject: [PATCH 51/61] fix(gateguard): preserve quoted git introspection args --- scripts/hooks/gateguard-fact-force.js | 73 +++++++++++++++++++++++- tests/hooks/gateguard-fact-force.test.js | 17 +++++- 2 files changed, 86 insertions(+), 4 deletions(-) diff --git a/scripts/hooks/gateguard-fact-force.js b/scripts/hooks/gateguard-fact-force.js index e49d6c14..c7c84c5a 100644 --- a/scripts/hooks/gateguard-fact-force.js +++ b/scripts/hooks/gateguard-fact-force.js @@ -119,6 +119,65 @@ function tokenize(segment) { return segment.split(/\s+/).filter(Boolean); } + +/** + * Tokenize a short allowlisted shell command while preserving quoted + * arguments. This is intentionally smaller than a full shell parser: the + * caller rejects shell control characters before invoking it, so this only + * needs to keep spaces inside quotes together for read-only git commands. + * + * @param {string} input + * @returns {string[] | null} + */ +function tokenizeAllowlistedShellWords(input) { + const tokens = []; + let current = ''; + let quote = null; + let escaped = false; + + for (const char of String(input || '')) { + if (escaped) { + current += char; + escaped = false; + continue; + } + + if (char === '\\') { + escaped = true; + continue; + } + + if (quote) { + if (char === quote) { + quote = null; + } else { + current += char; + } + continue; + } + + if (char === '"' || char === "'") { + quote = char; + continue; + } + + if (/\s/.test(char)) { + if (current) { + tokens.push(current); + current = ''; + } + continue; + } + + current += char; + } + + if (escaped) current += '\\'; + if (quote) return null; + if (current) tokens.push(current); + return tokens; +} + /** * Strip a leading path and trailing `.exe` from a command token so * `/usr/bin/git`, `git.exe`, and `GIT` all normalize to `git`. @@ -592,8 +651,16 @@ function isReadOnlyGitIntrospection(command) { return false; } - const tokens = trimmed.split(/\s+/); - if (tokens[0] !== 'git' || tokens.length < 2) { + const segments = splitCommandSegments(trimmed); + if (segments.length !== 1) { + return false; + } + + const tokens = tokenizeAllowlistedShellWords(trimmed); + if (!tokens) { + return false; + } + if (commandBasename(tokens[0]) !== 'git' || tokens.length < 2) { return false; } @@ -613,7 +680,7 @@ function isReadOnlyGitIntrospection(command) { } if (subcommand === 'show') { - return args.length === 1 && !args[0].startsWith('--') && /^[a-zA-Z0-9._:/-]+$/.test(args[0]); + return args.length === 1 && !args[0].startsWith('--') && /^[a-zA-Z0-9._:/ -]+$/.test(args[0]); } if (subcommand === 'branch') { diff --git a/tests/hooks/gateguard-fact-force.test.js b/tests/hooks/gateguard-fact-force.test.js index 74886d80..127b95ea 100644 --- a/tests/hooks/gateguard-fact-force.test.js +++ b/tests/hooks/gateguard-fact-force.test.js @@ -769,6 +769,8 @@ function runTests() { 'git diff --name-only', 'git log --oneline --max-count=1', 'git show HEAD:README.md', + 'git show HEAD:"docs/install guide.md"', + '/usr/bin/git status --short', 'git branch --show-current', 'git rev-parse --abbrev-ref HEAD', ]; @@ -802,7 +804,20 @@ function runTests() { assert.ok(output.hookSpecificOutput.permissionDecisionReason.includes('current user request')); })) passed++; else failed++; - // --- Test 23: module-load pruning removes old state files only --- + // --- Test 23: quoted shell separators are not read-only git bypasses + clearState(); + if (test('does not treat quoted shell separators as read-only git introspection', () => { + const result = runBashHook({ + tool_name: 'Bash', + tool_input: { command: 'git show HEAD:"docs/a;b.md"' } + }); + const output = parseOutput(result.stdout); + assert.ok(output, 'should produce valid JSON output'); + assert.strictEqual(output.hookSpecificOutput.permissionDecision, 'deny'); + assert.ok(output.hookSpecificOutput.permissionDecisionReason.includes('current user request')); + })) passed++; else failed++; + + // --- Test 24: module-load pruning removes old state files only --- clearState(); if (test('prunes stale state files while keeping fresh state files', () => { const staleFile = path.join(stateDir, 'state-stale-session.json'); From 2c0d226439ec14c60f509561386caba2a9ac7619 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 13:39:43 -0400 Subject: [PATCH 52/61] docs(release): record post-gateguard evidence --- docs/ECC-2.0-GA-ROADMAP.md | 10 +++++----- .../operator-readiness-dashboard-2026-05-19.md | 4 ++-- .../owner-approval-packet-2026-05-19.md | 7 ++++--- docs/releases/2.0.0-rc.1/preview-pack-manifest.md | 2 +- .../2.0.0-rc.1/publication-evidence-2026-05-19.md | 15 +++++++++------ 5 files changed, 21 insertions(+), 17 deletions(-) diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index cedfda80..dba2b0c4 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -92,9 +92,9 @@ As of 2026-05-19: evidence refresh and GitHub Actions run `26106321921`, PR #2008's supply-chain evidence gate fix and GitHub Actions run `26108473648`, post-PR #2006 main CI run `26109953093`, and PR #2009's project-registry hygiene GitHub Actions run - `26111313938`, followed by post-PR #2009 main CI run `26111946778`. The May - 19 Linear - sync document remains the current external project status surface, and the + `26111313938`, post-PR #2009 main CI run `26111946778`, and post-PR #2011 + GateGuard main CI run `26113695068`. The May 19 Linear sync document remains + the current external project status surface, and the supply-chain gate now also records the `@types/node@25.7.0` pin and `brace-expansion` lock refresh needed for current npm audit/signature verification. @@ -753,9 +753,9 @@ is not complete unless the evidence column exists and has been freshly verified. | Keep public PRs below 20 | Repo-family PR recheck | 0 open PRs across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-19 after merging PR #2004 and refreshing platform audit evidence | Complete | | Keep public issues below 20 | Repo-family issue recheck | 0 open issues across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-19 after the live platform audit refresh | Complete | | Manage repository discussions | Repo-family discussion recheck plus response playbook | Platform audit reports 0 discussion maintainer-touch gaps and 0 answerable Q&A missing accepted answers; trunk has 59 total discussions after #2003 was routed with a maintainer response; `docs/architecture/discussion-response-playbook.md` distinguishes support, maintainer coordination, stale/concluded, release, informational, and security-sensitive response paths | Complete | -| Manage PR discussions | PR review/comment closure plus merge/close state | ECC #1990-#2009 merged through the harness audit, canonical identity, release video suite, growth outreach, evidence refresh, visual QA, suite-count, owner-approval packet, owner-approval dashboard gate, Linear readiness evidence, supply-chain evidence gate, per-project Claude Code adapter, and continuous-learning project-registry hygiene batch; no open tracked PRs remain | Complete | +| Manage PR discussions | PR review/comment closure plus merge/close state | ECC #1990-#2011 merged through the harness audit, canonical identity, release video suite, growth outreach, evidence refresh, visual QA, suite-count, owner-approval packet, owner-approval dashboard gate, Linear readiness evidence, supply-chain evidence gate, per-project Claude Code adapter, continuous-learning project-registry hygiene, and GateGuard quoted git introspection batch; no open tracked PRs remain | Complete | | Salvage useful stale work | `docs/stale-pr-salvage-ledger.md` plus `docs/legacy-artifact-inventory.md` | Ledger records salvaged, superseded, skipped, and manual-review tails; #1815-#1818 added cost tracking, skill scout, frontend design guidance, code-reviewer false-positive guardrails, and the May 12 gap pass; #1687, #1609, #1563, #1564, and #1565 localization tails are attached to Linear ITO-55 for language-owner review and no automatic import remains release-blocking | Complete; repeat legacy scan before release | -| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 19 evidence records queue-zero state, canonical ECC identity, release video suite, growth outreach pack, owner approval packet, local 2560-test suite, PR #2001 merge and GitHub Actions run `26102500291`, PR #2002 owner-approval dashboard gate refresh and GitHub Actions run `26103853507`, PR #2004 Linear readiness evidence sync and GitHub Actions run `26105012698`, PR #2008 supply-chain evidence gate CI run `26108473648`, post-PR #2006 main CI run `26109953093`, PR #2009 project-registry hygiene GitHub Actions run `26111313938`, post-PR #2009 main CI run `26111946778`, May 19 operator dashboard, `owner-approval-packet-2026-05-19.md`, and preview-pack smoke digest `790430aef4a8` | Needs final release approval | +| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 19 evidence records queue-zero state, canonical ECC identity, release video suite, growth outreach pack, owner approval packet, local 2560-test suite, PR #2001 merge and GitHub Actions run `26102500291`, PR #2002 owner-approval dashboard gate refresh and GitHub Actions run `26103853507`, PR #2004 Linear readiness evidence sync and GitHub Actions run `26105012698`, PR #2008 supply-chain evidence gate CI run `26108473648`, post-PR #2006 main CI run `26109953093`, PR #2009 project-registry hygiene GitHub Actions run `26111313938`, post-PR #2009 main CI run `26111946778`, post-PR #2011 GateGuard main CI run `26113695068`, May 19 operator dashboard, `owner-approval-packet-2026-05-19.md`, and preview-pack smoke digest `790430aef4a8` | Needs final release approval | | Hermes specialized skills included safely | Hermes setup/import docs and sanitized skill surface | Hermes setup and import playbook are public; secrets stay local | Needs final release review | | Naming and rename readiness | Naming matrix across package/plugin/docs/social surfaces | `docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md` records current package, repo, Claude plugin, Codex plugin, OpenCode, and npm availability evidence | Complete for rc.1; post-rc rename remains future work | | Claude and Codex plugin publication | Contact/submission path with required artifacts and status | Publication readiness, naming matrix, and May 12 dry-run evidence document plugin validation, clean-checkout Claude tag/install smoke, and Codex marketplace CLI shape | Needs explicit approval for real tag/push and marketplace submission | diff --git a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md index b4775910..c8a1b172 100644 --- a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md @@ -2,8 +2,8 @@ This dashboard is generated by `npm run operator:dashboard`. It is an operator snapshot, not release approval. -Generated: 2026-05-19T17:04:04.254Z -Commit: d2e91a49782c3158c552b7eaff3bbf70f8bba887 +Generated: 2026-05-19T17:37:31.630Z +Commit: 14d88e517b0c56a80c1a6392b1cde2474948d29f Status: work remaining ## Current Status diff --git a/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md b/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md index 1f77e36d..4bd27ca0 100644 --- a/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md @@ -8,7 +8,7 @@ release action after the final evidence commands are rerun from the intended release commit. Source commit for the clean evidence baseline this packet extends: -`bc519e5b8ed42f26c0a5a611756e04351c323f21`. +`14d88e517b0c56a80c1a6392b1cde2474948d29f`. ## Current Evidence @@ -18,8 +18,8 @@ Source commit for the clean evidence baseline this packet extends: | Preview pack smoke | ready true, digest `790430aef4a8`, 5/5 checks | yes | | Video suite | ready true, 15/15 source assets, 13/13 suite artifacts, 12/12 publish candidates | yes | | Release surface tests | 27/27 passed after this packet was added | yes | -| Full local suite | 2560/2560 passed after PR #2009 was prepared; focused post-merge regressions passed on `main` | yes | -| GitHub CI | PR #1998, PR #1999, PR #2000, PR #2001, PR #2002, PR #2004, PR #2008, post-PR #2006 `main`, PR #2009, and post-PR #2009 `main` all merged or advanced after green required checks | verify current head | +| Full local suite | 2560/2560 passed after PR #2011 was prepared; focused GateGuard regression passed 91/91 again on current `main` | yes | +| GitHub CI | PR #1998, PR #1999, PR #2000, PR #2001, PR #2002, PR #2004, PR #2008, post-PR #2006 `main`, PR #2009, post-PR #2009 `main`, and post-PR #2011 `main` all merged or advanced after green required checks | verify current head | ## Decision Register @@ -64,6 +64,7 @@ npm run security:ioc-scan npm audit --audit-level=moderate npm audit signatures node tests/docs/ecc2-release-surface.test.js +node tests/hooks/gateguard-fact-force.test.js node tests/run-all.js cd ecc2 && cargo test ``` diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index beb34a1e..16e518c1 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -25,7 +25,7 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-16.md` | Current May 16/17 queue cleanup, recsys skill merge, GateGuard triage, PR #1947 supply-chain protection, AgentShield #87 plugin-cache confidence evidence, AgentShield #88 evidence-pack inspect/readback, AgentShield #89 evidence-pack fleet routing, AgentShield #90 fleet review items, AgentShield #91 policy export, AgentShield #92 policy promotion, ECC-Tools #76 fleet-summary consumption, ECC-Tools #77 hosted finding evidence paths, ECC-Tools #78 harness policy-route linking, dashboard refresh, and combined Node/Rust/release-surface gate evidence through the May 16 mirror | Must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` | May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack protection recheck, npm audit/signature checks, legacy and Linear progress routing, deterministic preview-pack smoke, operator dashboard refresh, Linear sync, and GitHub CI evidence for `27dc2918` | Superseded by the May 18 evidence snapshot; repeat from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, supply-chain recheck, AgentShield evidence mirror, Linear sync, current-head CI/security scan success for `4470e2e6`, and ITO-46 naming/plugin publication closure | Superseded by the May 19 ECC identity, video, and growth evidence snapshot | -| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, May 19 operator dashboard, preview-pack smoke digest `790430aef4a8`, 2560-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, PR #2004 Linear readiness evidence sync CI success, PR #2008 supply-chain evidence gate CI success, post-PR #2006 main CI success, PR #2009 project-registry hygiene CI success, post-PR #2009 main CI success, and the May 19 Linear sync document | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | +| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, May 19 operator dashboard, preview-pack smoke digest `790430aef4a8`, 2560-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, PR #2004 Linear readiness evidence sync CI success, PR #2008 supply-chain evidence gate CI success, post-PR #2006 main CI success, PR #2009 project-registry hygiene CI success, post-PR #2009 main CI success, post-PR #2011 GateGuard CI success, and the May 19 Linear sync document | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 19 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and adds the current `$1,728/mo` to `$10,000/mo` hypergrowth, video owner-approval, and outbound-pack operating lanes | diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md index e8fa6fd0..5d3dc12f 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -8,9 +8,9 @@ social announcement. | Field | Evidence | | --- | --- | -| Upstream main | `bc519e5b8ed42f26c0a5a611756e04351c323f21` | +| Upstream main | `14d88e517b0c56a80c1a6392b1cde2474948d29f` | | Git remote | `https://github.com/affaan-m/ECC.git` | -| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, PR #2001 owner approval packet addition, PR #2002 owner approval dashboard gate refresh, PR #2004 Linear readiness evidence sync, PR #2005 post-PR #2004 evidence refresh, PR #2008 release supply-chain evidence gate fix, PR #2006 per-project Claude Code adapter, and PR #2009 continuous-learning project registry hygiene fix | +| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, PR #2001 owner approval packet addition, PR #2002 owner approval dashboard gate refresh, PR #2004 Linear readiness evidence sync, PR #2005 post-PR #2004 evidence refresh, PR #2008 release supply-chain evidence gate fix, PR #2006 per-project Claude Code adapter, PR #2009 continuous-learning project registry hygiene fix, and PR #2011 GateGuard quoted git introspection fix | | Local status caveat | `git status --short --branch` was clean after pulling `origin/main`; generated evidence files are committed after the source snapshot they describe | The release operator must repeat all publish-facing checks from the exact final @@ -56,6 +56,7 @@ Tracked repositories in the platform audit were: | PR #2008 | Merged the release supply-chain evidence gate fix so platform-audit readiness keeps matching current publication evidence | | PR #2006 | Merged the `claude-project` install target for per-project Claude Code adapter support, then fixed the manifest schema enum on top of the feature branch before merge | | PR #2009 | Merged the continuous-learning project registry hygiene fix: non-git hook payloads stay global, no-remote linked worktrees migrate to the main worktree project ID, and `instinct-cli.py projects delete`, `merge`, and `gc` provide operator maintenance commands | +| PR #2011 | Merged the GateGuard read-only git introspection tokenizer fix so quoted `git show` pathspecs with spaces are preserved while quoted shell separators stay outside the bypass | ## Release And Growth Evidence @@ -67,6 +68,7 @@ Tracked repositories in the platform audit were: | Supply-chain verification | `npm audit --audit-level=moderate`; `npm audit signatures`; `yarn install --immutable --mode=skip-build` | Current supply-chain refresh found 0 npm vulnerabilities, verified 254 registry signatures and 30 attestations, and accepted the Yarn lock after pinning `@types/node@25.7.0` plus refreshing `brace-expansion` to `5.0.6` / `1.1.14` | | Release video suite | `npm run release:video-suite -- --format json --summary` with `ECC_VIDEO_SOURCE_ROOT` and `ECC_VIDEO_RELEASE_SUITE_ROOT` | Ready true; 15/15 source assets present; 13/13 render, timeline, caption, EDL, and segment artifacts present; 12/12 publish-candidate outputs present with zero detected black-frame segments; primary rough render self-eval passed at 144.759 seconds, 1920x1080, 1 audio stream, and 106.78 MB | | Focused post-merge regression set | `node tests/hooks/detect-project-worktree.test.js`; `node tests/hooks/observe-subdirectory-detection.test.js`; `node tests/scripts/instinct-cli-projects.test.js`; `node tests/hooks/hooks.test.js` | 10/10, 6/6, 5/5, and 237/237 passed after PR #2009 merged | +| GateGuard PR #2011 regression | `node tests/hooks/gateguard-fact-force.test.js`; `npm test`; `git diff --check main...HEAD` | 91/91 passed on the PR branch; full local suite passed 2560/2560 before merge; whitespace check passed; focused GateGuard suite passed again on current `main` | | Full local suite | `node tests/run-all.js` | 2560 passed, 0 failed | | PR #1998 CI | GitHub Actions run `26099020341` | Completed successfully for `d500de1e9f11c0446b6a1349bd98b522d31f9125`; all reported checks passed, including lint, validation, security scan, coverage, GitGuardian, CodeRabbit, Cubic, and the macOS/Ubuntu/Windows test matrix | | PR #1999 CI | GitHub Actions run `26100148726` | Completed successfully for `90584b6d5e5814bc2ad9a4cd651bebd043de989d`; lint, validation, security scan, coverage, GitGuardian, CodeRabbit, and the macOS/Ubuntu/Windows test matrix passed; Cubic completed neutral and did not block merge | @@ -78,6 +80,7 @@ Tracked repositories in the platform audit were: | Post-PR #2006 main CI | GitHub Actions run `26109953093` | Completed successfully with 37 completed jobs, 0 failed jobs, and `main` advanced to `98bd517451f38fa0150a53aab4234c2239a47b7e` | | PR #2009 CI | GitHub Actions run `26111313938` | Completed successfully with 37 completed jobs, 0 failed jobs after replacing the brittle fake-worktree regression fixture with a real `git worktree add` setup | | Post-PR #2009 main CI | GitHub Actions run `26111946778` | Completed successfully with 37 completed jobs, 0 failed jobs, and `main` advanced to `bc519e5b8ed42f26c0a5a611756e04351c323f21` | +| Post-PR #2011 main CI | GitHub Actions run `26113695068` | Completed successfully with 37 completed jobs, 0 failed jobs, and `main` advanced to `14d88e517b0c56a80c1a6392b1cde2474948d29f` | | Linear sync | Linear document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` plus project comment `a6411e3a-8c8e-4a58-adba-687e77d4c543` | Project and issue lanes now record PR #2002 evidence, discussion #2003 routing, owner-approval dashboard gate, and In Progress status for ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56 | | Public-path sanitization | `node scripts/ci/validate-no-personal-paths.js` through local suite and CI | Passed | | Markdown and whitespace | `markdownlint` focused release docs plus `git diff --check` before PR #1999 | Passed | @@ -118,10 +121,10 @@ Tracked repositories in the platform audit were: The tracked public PR queue, issue queue, discussion queue, canonical ECC identity, release video suite, preview pack, growth outreach packet, per-project -Claude Code adapter surface, and continuous-learning project registry hygiene -are current on May 19, 2026 for `main` through -`bc519e5b8ed42f26c0a5a611756e04351c323f21`. The remaining video work is owner -approval, upload, and public URL attachment, not render or QA production. +Claude Code adapter surface, continuous-learning project registry hygiene, and +GateGuard quoted git introspection fix are current on May 19, 2026 for `main` +through `14d88e517b0c56a80c1a6392b1cde2474948d29f`. The remaining video work is +owner approval, upload, and public URL attachment, not render or QA production. This improves publication readiness but does not replace the approval-gated release, package, plugin, billing, Discord, and announcement steps in From 9819626459a662773be7d0b1c18d82c1316b8c36 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 18:05:46 -0400 Subject: [PATCH 53/61] Add release approval gate --- docs/ECC-2.0-GA-ROADMAP.md | 4 +- docs/releases/2.0.0-rc.1/launch-checklist.md | 3 + .../owner-approval-packet-2026-05-19.md | 4 +- .../2.0.0-rc.1/preview-pack-manifest.md | 6 +- .../publication-evidence-2026-05-19.md | 3 +- .../2.0.0-rc.1/publication-readiness.md | 3 +- ...plugin-publication-checklist-2026-05-18.md | 1 + .../release-url-ledger-2026-05-19.md | 1 + package.json | 2 + scripts/preview-pack-smoke.js | 2 + scripts/release-approval-gate.js | 553 ++++++++++++++++++ tests/docs/ecc2-release-surface.test.js | 31 +- tests/scripts/npm-publish-surface.test.js | 2 + tests/scripts/release-approval-gate.test.js | 320 ++++++++++ 14 files changed, 928 insertions(+), 7 deletions(-) create mode 100644 scripts/release-approval-gate.js create mode 100644 tests/scripts/release-approval-gate.test.js diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index dba2b0c4..e350ad5b 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -85,7 +85,7 @@ As of 2026-05-19: current May 19 queue-zero state, canonical ECC identity merge, release video suite gate, partner/sponsor/talk outreach pack, owner approval packet (`owner-approval-packet-2026-05-19.md`), preview-pack smoke digest - `790430aef4a8`, local 2560-test suite, PR #2001 merge and GitHub Actions run + `531328aaaa53`, local 2560-test suite, PR #2001 merge and GitHub Actions run `26102500291` success, PR #2002's owner-approval dashboard gate refresh and GitHub Actions run `26103853507`, PR #2004's Linear readiness evidence sync and GitHub Actions run `26105012698`, plus PR #2005's post-PR #2004 @@ -755,7 +755,7 @@ is not complete unless the evidence column exists and has been freshly verified. | Manage repository discussions | Repo-family discussion recheck plus response playbook | Platform audit reports 0 discussion maintainer-touch gaps and 0 answerable Q&A missing accepted answers; trunk has 59 total discussions after #2003 was routed with a maintainer response; `docs/architecture/discussion-response-playbook.md` distinguishes support, maintainer coordination, stale/concluded, release, informational, and security-sensitive response paths | Complete | | Manage PR discussions | PR review/comment closure plus merge/close state | ECC #1990-#2011 merged through the harness audit, canonical identity, release video suite, growth outreach, evidence refresh, visual QA, suite-count, owner-approval packet, owner-approval dashboard gate, Linear readiness evidence, supply-chain evidence gate, per-project Claude Code adapter, continuous-learning project-registry hygiene, and GateGuard quoted git introspection batch; no open tracked PRs remain | Complete | | Salvage useful stale work | `docs/stale-pr-salvage-ledger.md` plus `docs/legacy-artifact-inventory.md` | Ledger records salvaged, superseded, skipped, and manual-review tails; #1815-#1818 added cost tracking, skill scout, frontend design guidance, code-reviewer false-positive guardrails, and the May 12 gap pass; #1687, #1609, #1563, #1564, and #1565 localization tails are attached to Linear ITO-55 for language-owner review and no automatic import remains release-blocking | Complete; repeat legacy scan before release | -| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 19 evidence records queue-zero state, canonical ECC identity, release video suite, growth outreach pack, owner approval packet, local 2560-test suite, PR #2001 merge and GitHub Actions run `26102500291`, PR #2002 owner-approval dashboard gate refresh and GitHub Actions run `26103853507`, PR #2004 Linear readiness evidence sync and GitHub Actions run `26105012698`, PR #2008 supply-chain evidence gate CI run `26108473648`, post-PR #2006 main CI run `26109953093`, PR #2009 project-registry hygiene GitHub Actions run `26111313938`, post-PR #2009 main CI run `26111946778`, post-PR #2011 GateGuard main CI run `26113695068`, May 19 operator dashboard, `owner-approval-packet-2026-05-19.md`, and preview-pack smoke digest `790430aef4a8` | Needs final release approval | +| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 19 evidence records queue-zero state, canonical ECC identity, release video suite, growth outreach pack, owner approval packet, local 2560-test suite, PR #2001 merge and GitHub Actions run `26102500291`, PR #2002 owner-approval dashboard gate refresh and GitHub Actions run `26103853507`, PR #2004 Linear readiness evidence sync and GitHub Actions run `26105012698`, PR #2008 supply-chain evidence gate CI run `26108473648`, post-PR #2006 main CI run `26109953093`, PR #2009 project-registry hygiene GitHub Actions run `26111313938`, post-PR #2009 main CI run `26111946778`, post-PR #2011 GateGuard main CI run `26113695068`, May 19 operator dashboard, `owner-approval-packet-2026-05-19.md`, `release-approval-gate.js`, and preview-pack smoke digest `531328aaaa53` | Needs final release approval | | Hermes specialized skills included safely | Hermes setup/import docs and sanitized skill surface | Hermes setup and import playbook are public; secrets stay local | Needs final release review | | Naming and rename readiness | Naming matrix across package/plugin/docs/social surfaces | `docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md` records current package, repo, Claude plugin, Codex plugin, OpenCode, and npm availability evidence | Complete for rc.1; post-rc rename remains future work | | Claude and Codex plugin publication | Contact/submission path with required artifacts and status | Publication readiness, naming matrix, and May 12 dry-run evidence document plugin validation, clean-checkout Claude tag/install smoke, and Codex marketplace CLI shape | Needs explicit approval for real tag/push and marketplace submission | diff --git a/docs/releases/2.0.0-rc.1/launch-checklist.md b/docs/releases/2.0.0-rc.1/launch-checklist.md index ac635ae9..de6d135c 100644 --- a/docs/releases/2.0.0-rc.1/launch-checklist.md +++ b/docs/releases/2.0.0-rc.1/launch-checklist.md @@ -21,6 +21,9 @@ - verify package, plugin, marketplace, OpenCode, and agent metadata stays at `2.0.0-rc.1` - verify `ecc2/Cargo.toml` stays at `0.1.0` for rc.1; `ecc2/` remains an alpha control-plane scaffold - complete `publication-readiness.md` with fresh evidence before any GitHub release, npm publish, plugin submission, or announcement post +- run `npm run release:approval-gate -- --format json` after owner approvals + and live URL readbacks are recorded; it must return ready true before any + publish, upload, social, or outbound action - rerun the release name/plugin publication checklist before creating a GitHub prerelease, publishing npm, pushing Claude plugin tags, recording the Codex marketplace path, or posting public copy diff --git a/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md b/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md index 4bd27ca0..96f0d98b 100644 --- a/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md @@ -15,7 +15,8 @@ Source commit for the clean evidence baseline this packet extends: | Evidence | Current recorded state | Repeat before approval | | --- | --- | --- | | Platform audit | ready true, 0 open PRs, 0 open issues, 0 discussion gaps, 0 dirty files | yes | -| Preview pack smoke | ready true, digest `790430aef4a8`, 5/5 checks | yes | +| Preview pack smoke | ready true, digest `531328aaaa53`, 5/5 checks | yes | +| Release approval gate | ready false, digest `ef8f49f727b7`, 4/6 checks pass; owner decisions and live URL readbacks pending | yes | | Video suite | ready true, 15/15 source assets, 13/13 suite artifacts, 12/12 publish candidates | yes | | Release surface tests | 27/27 passed after this packet was added | yes | | Full local suite | 2560/2560 passed after PR #2011 was prepared; focused GateGuard regression passed 91/91 again on current `main` | yes | @@ -56,6 +57,7 @@ Run these from the exact release commit before approving publication: git status --short --branch node scripts/platform-audit.js --json npm run preview-pack:smoke -- --format json +npm run release:approval-gate -- --format json npm run release:video-suite -- --format json npm run harness:adapters -- --check npm run harness:audit -- --format json diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index 16e518c1..595e0fc1 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -17,6 +17,7 @@ surfaces, or posting announcements. | `docs/architecture/observability-readiness.md` | Local operator-readiness gate | Verified by `npm run observability:ready` | | `docs/architecture/progress-sync-contract.md` | GitHub, Linear, handoff, roadmap, and work-item sync boundary | Checked by `node scripts/platform-audit.js --json` | | `scripts/preview-pack-smoke.js` | Deterministic preview-pack smoke gate | Verified by `npm run preview-pack:smoke` | +| `scripts/release-approval-gate.js` | Final owner-decision, live-URL, and launch-copy gate | Must return ready true before any release publish, package publish, plugin tag, video upload, announcement, or outbound batch | | `docs/releases/2.0.0-rc.1/release-notes.md` | GitHub release copy source | Must be refreshed with final live release/package/plugin URLs before publication | | `docs/releases/2.0.0-rc.1/quickstart.md` | Clone-to-first-workflow path | Covers clone, install, verify, first skill, and harness switch | | `docs/releases/2.0.0-rc.1/launch-checklist.md` | Operator launch checklist | Must remain approval-gated for release, package, plugin, and announcement actions | @@ -25,7 +26,7 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-16.md` | Current May 16/17 queue cleanup, recsys skill merge, GateGuard triage, PR #1947 supply-chain protection, AgentShield #87 plugin-cache confidence evidence, AgentShield #88 evidence-pack inspect/readback, AgentShield #89 evidence-pack fleet routing, AgentShield #90 fleet review items, AgentShield #91 policy export, AgentShield #92 policy promotion, ECC-Tools #76 fleet-summary consumption, ECC-Tools #77 hosted finding evidence paths, ECC-Tools #78 harness policy-route linking, dashboard refresh, and combined Node/Rust/release-surface gate evidence through the May 16 mirror | Must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` | May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack protection recheck, npm audit/signature checks, legacy and Linear progress routing, deterministic preview-pack smoke, operator dashboard refresh, Linear sync, and GitHub CI evidence for `27dc2918` | Superseded by the May 18 evidence snapshot; repeat from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, supply-chain recheck, AgentShield evidence mirror, Linear sync, current-head CI/security scan success for `4470e2e6`, and ITO-46 naming/plugin publication closure | Superseded by the May 19 ECC identity, video, and growth evidence snapshot | -| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, May 19 operator dashboard, preview-pack smoke digest `790430aef4a8`, 2560-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, PR #2004 Linear readiness evidence sync CI success, PR #2008 supply-chain evidence gate CI success, post-PR #2006 main CI success, PR #2009 project-registry hygiene CI success, post-PR #2009 main CI success, post-PR #2011 GateGuard CI success, and the May 19 Linear sync document | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | +| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, release approval gate, May 19 operator dashboard, preview-pack smoke digest `531328aaaa53`, 2560-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, PR #2004 Linear readiness evidence sync CI success, PR #2008 supply-chain evidence gate CI success, post-PR #2006 main CI success, PR #2009 project-registry hygiene CI success, post-PR #2009 main CI success, post-PR #2011 GateGuard CI success, and the May 19 Linear sync document | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 19 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and adds the current `$1,728/mo` to `$10,000/mo` hypergrowth, video owner-approval, and outbound-pack operating lanes | @@ -80,6 +81,7 @@ Run these from the exact release commit before publication: git status --short --branch node scripts/platform-audit.js --json npm run preview-pack:smoke +npm run release:approval-gate -- --format json npm run release:video-suite -- --format json npm run harness:adapters -- --check npm run harness:audit -- --format json @@ -98,6 +100,8 @@ The preview pack is assembled, but publication is still blocked until these live surfaces exist and are recorded in a final evidence file: - final release URL ledger regenerated from the intended release commit; +- `npm run release:approval-gate -- --format json` returning ready true after + owner approvals and live URL readbacks are recorded; - final release name/plugin publication checklist rerun from the intended release commit; - GitHub prerelease `v2.0.0-rc.1`; diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md index 5d3dc12f..25553703 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -63,7 +63,8 @@ Tracked repositories in the platform audit were: | Gate | Command | Result | | --- | --- | --- | | Release-surface tests | `node tests/docs/ecc2-release-surface.test.js` | 27 passed, 0 failed | -| Preview-pack smoke | `npm run preview-pack:smoke -- --format json` | Ready true; digest `790430aef4a8`; 31 required artifacts; 5 passed, 0 failed | +| Preview-pack smoke | `npm run preview-pack:smoke -- --format json` | Ready true; digest `531328aaaa53`; 32 required artifacts; 5 passed, 0 failed | +| Release approval gate | `npm run release:approval-gate -- --format json` | Expected blocked; digest `ef8f49f727b7`; 4 passed, 2 failed; owner decisions and live URL readbacks remain approval-gated | | Operator dashboard | `npm run operator:dashboard -- --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Regenerated from the May 19 `main` baseline with platform audit ready true, 0 tracked PRs, 0 tracked issues, 0 discussion gaps, `$1,728/mo` current MRR, `$10,000/mo` target MRR, the release video suite marked current, and top actions for plugin publication, notifications, outbound approval, AgentShield, and ECC Tools billing | | Supply-chain verification | `npm audit --audit-level=moderate`; `npm audit signatures`; `yarn install --immutable --mode=skip-build` | Current supply-chain refresh found 0 npm vulnerabilities, verified 254 registry signatures and 30 attestations, and accepted the Yarn lock after pinning `@types/node@25.7.0` plus refreshing `brace-expansion` to `5.0.6` / `1.1.14` | | Release video suite | `npm run release:video-suite -- --format json --summary` with `ECC_VIDEO_SOURCE_ROOT` and `ECC_VIDEO_RELEASE_SUITE_ROOT` | Ready true; 15/15 source assets present; 13/13 render, timeline, caption, EDL, and segment artifacts present; 12/12 publish-candidate outputs present with zero detected black-frame segments; primary rough render self-eval passed at 144.759 seconds, 1920x1080, 1 audio stream, and 106.78 MB | diff --git a/docs/releases/2.0.0-rc.1/publication-readiness.md b/docs/releases/2.0.0-rc.1/publication-readiness.md index aaf7fba8..88121da7 100644 --- a/docs/releases/2.0.0-rc.1/publication-readiness.md +++ b/docs/releases/2.0.0-rc.1/publication-readiness.md @@ -102,7 +102,8 @@ Record the exact commit SHA and command output before any publication action: | Evidence | Command | Required result | Recorded output | | --- | --- | --- | --- | | Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | Current May 19 baseline `bc519e5b8ed42f26c0a5a611756e04351c323f21`: `## main...origin/main`; repeat from the exact final publication commit before release | -| Preview-pack smoke | `npm run preview-pack:smoke` | Preview pack artifacts, Hermes boundary, final verification command list, and publication blockers pass | `publication-evidence-2026-05-19.md`: ready yes, digest `790430aef4a8`, 31 artifacts, 5 passed, 0 failed; repeat in the final strict clean-checkout release pass | +| Preview-pack smoke | `npm run preview-pack:smoke` | Preview pack artifacts, Hermes boundary, final verification command list, and publication blockers pass | `publication-evidence-2026-05-19.md`: ready yes, digest `531328aaaa53`, 32 artifacts, 5 passed, 0 failed; repeat in the final strict clean-checkout release pass | +| Release approval gate | `npm run release:approval-gate -- --format json` | Ready true only after owner decision rows are approved, live release/package/plugin/video/billing URLs are recorded, and launch/outbound copy has no placeholders or private paths | Current May 19 state is intentionally blocked because owner decisions and live URL readbacks remain approval-gated | | Harness audit | `npm run harness:audit -- --format json` | 80/80 passing | Current release gate: 80/80 across 8 applicable categories, 0 top actions | | Adapter scorecard | `npm run harness:adapters -- --check` | PASS | Current release gate: PASS, 11 adapters | | Observability readiness | `npm run observability:ready` | 21/21 passing | Current release gate: 21/21, ready true | diff --git a/docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md b/docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md index 6433c372..125dc5e4 100644 --- a/docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md +++ b/docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md @@ -66,6 +66,7 @@ npm pack --dry-run --json npm publish --tag next --dry-run npm run build:opencode npm run preview-pack:smoke +npm run release:approval-gate -- --format json ``` If a command is unavailable on the release machine, record the exact error and diff --git a/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md b/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md index 9bfbabad..437ea131 100644 --- a/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md @@ -47,6 +47,7 @@ npm view ecc-universal name version dist-tags --json codex plugin marketplace add --help rg -n "TODO|TBD|PLACEHOLDER" docs/releases/2.0.0-rc.1 npm run preview-pack:smoke +npm run release:approval-gate -- --format json ``` Do not post the social or notification copy until the approval-gated URLs above diff --git a/package.json b/package.json index 07919d69..203c2a27 100644 --- a/package.json +++ b/package.json @@ -89,6 +89,7 @@ "scripts/operator-readiness-dashboard.js", "scripts/platform-audit.js", "scripts/preview-pack-smoke.js", + "scripts/release-approval-gate.js", "scripts/release-video-suite.js", "scripts/hooks/", "scripts/install-apply.js", @@ -312,6 +313,7 @@ "observability:ready": "node scripts/observability-readiness.js", "operator:dashboard": "node scripts/operator-readiness-dashboard.js", "preview-pack:smoke": "node scripts/preview-pack-smoke.js", + "release:approval-gate": "node scripts/release-approval-gate.js", "release:video-suite": "node scripts/release-video-suite.js", "platform:audit": "node scripts/platform-audit.js", "discussion:audit": "node scripts/discussion-audit.js", diff --git a/scripts/preview-pack-smoke.js b/scripts/preview-pack-smoke.js index 843eade8..11df8c4c 100644 --- a/scripts/preview-pack-smoke.js +++ b/scripts/preview-pack-smoke.js @@ -18,6 +18,7 @@ const REQUIRED_ARTIFACTS = [ 'docs/architecture/observability-readiness.md', 'docs/architecture/progress-sync-contract.md', 'scripts/preview-pack-smoke.js', + 'scripts/release-approval-gate.js', `${RELEASE_DIR}/release-notes.md`, `${RELEASE_DIR}/quickstart.md`, `${RELEASE_DIR}/launch-checklist.md`, @@ -47,6 +48,7 @@ const REQUIRED_VERIFICATION_COMMANDS = [ 'git status --short --branch', 'node scripts/platform-audit.js --json', 'npm run preview-pack:smoke', + 'npm run release:approval-gate -- --format json', 'npm run release:video-suite -- --format json', 'npm run harness:adapters -- --check', 'npm run harness:audit -- --format json', diff --git a/scripts/release-approval-gate.js b/scripts/release-approval-gate.js new file mode 100644 index 00000000..a1c9e0de --- /dev/null +++ b/scripts/release-approval-gate.js @@ -0,0 +1,553 @@ +#!/usr/bin/env node +'use strict'; + +const crypto = require('crypto'); +const fs = require('fs'); +const path = require('path'); + +const RELEASE = '2.0.0-rc.1'; +const RELEASE_DIR = `docs/releases/${RELEASE}`; +const SCHEMA_VERSION = 'ecc.release-approval-gate.v1'; +const SCRIPT_PATH = 'scripts/release-approval-gate.js'; +const OWNER_PACKET_PATH = `${RELEASE_DIR}/owner-approval-packet-2026-05-19.md`; +const URL_LEDGER_PATH = `${RELEASE_DIR}/release-url-ledger-2026-05-19.md`; +const PREVIEW_MANIFEST_PATH = `${RELEASE_DIR}/preview-pack-manifest.md`; +const REQUIRED_COMMAND = 'npm run release:approval-gate -- --format json'; + +const REQUIRED_DECISIONS = [ + { + id: 'github-prerelease', + label: 'GitHub prerelease', + }, + { + id: 'npm-next-publish', + label: 'npm `next` publish', + }, + { + id: 'claude-plugin-tag', + label: 'Claude plugin tag', + }, + { + id: 'codex-repo-marketplace', + label: 'Codex repo marketplace', + }, + { + id: 'ecc-tools-billing-language', + label: 'ECC Tools billing language', + }, + { + id: 'video-upload', + label: 'Video upload', + }, + { + id: 'social-and-longform', + label: 'X, LinkedIn, GitHub Discussion, longform', + }, + { + id: 'outbound-growth', + label: 'Sponsor, partner, consulting, conference, podcast outreach', + }, +]; + +const REQUIRED_URL_SURFACES = [ + { + id: 'github-prerelease-url', + label: 'GitHub prerelease URL', + exampleUrl: 'https://github.com/affaan-m/ECC/releases/tag/v2.0.0-rc.1', + }, + { + id: 'npm-rc-package-url', + label: 'npm rc package URL', + exampleUrl: 'https://www.npmjs.com/package/ecc-universal/v/2.0.0-rc.1', + }, + { + id: 'claude-plugin-tag-url', + label: 'Claude plugin tag URL', + exampleUrl: 'https://github.com/affaan-m/ECC/releases/tag/ecc--v2.0.0-rc.1', + }, + { + id: 'codex-repo-marketplace-evidence', + label: 'Codex repo-marketplace evidence', + exampleUrl: 'https://github.com/affaan-m/ECC/tree/v2.0.0-rc.1/.codex-plugin', + }, + { + id: 'primary-launch-video-url', + label: 'Primary launch video URL', + exampleUrl: 'https://x.com/affaanmustafa/status/0000000000000000000', + }, + { + id: 'short-clip-urls', + label: 'Short clip URLs', + exampleUrl: 'https://x.com/affaanmustafa/status/0000000000000000001', + }, + { + id: 'ecc-tools-billing-readiness-url', + label: 'ECC Tools billing/readiness URL', + exampleUrl: 'https://github.com/ECC-Tools', + }, +]; + +const ANNOUNCEMENT_FILES = [ + `${RELEASE_DIR}/release-notes.md`, + `${RELEASE_DIR}/x-thread.md`, + `${RELEASE_DIR}/linkedin-post.md`, + `${RELEASE_DIR}/article-outline.md`, + `${RELEASE_DIR}/partner-sponsor-talks-pack.md`, + 'docs/business/social-launch-copy.md', +]; + +function usage() { + console.log([ + 'Usage: node scripts/release-approval-gate.js [--format ] [--root ]', + '', + 'Final approval gate for ECC 2.0 rc.1 publication and outbound actions.', + '', + 'Options:', + ' --format Output format (default: text)', + ' --json Alias for --format json', + ' --root Repository root to inspect (default: cwd)', + ' --help, -h Show this help', + ].join('\n')); +} + +function readArgValue(args, index, flagName) { + const value = args[index + 1]; + if (!value || value.startsWith('--')) { + throw new Error(`${flagName} requires a value`); + } + return value; +} + +function parseArgs(argv) { + const args = argv.slice(2); + const parsed = { + format: 'text', + help: false, + root: path.resolve(process.cwd()), + }; + + for (let index = 0; index < args.length; index += 1) { + const arg = args[index]; + + if (arg === '--help' || arg === '-h') { + parsed.help = true; + continue; + } + + if (arg === '--json') { + parsed.format = 'json'; + continue; + } + + if (arg === '--format') { + parsed.format = readArgValue(args, index, arg).toLowerCase(); + index += 1; + continue; + } + + if (arg.startsWith('--format=')) { + parsed.format = arg.slice('--format='.length).toLowerCase(); + continue; + } + + if (arg === '--root') { + parsed.root = path.resolve(readArgValue(args, index, arg)); + index += 1; + continue; + } + + if (arg.startsWith('--root=')) { + parsed.root = path.resolve(arg.slice('--root='.length)); + continue; + } + + throw new Error(`Unknown argument: ${arg}`); + } + + if (!['text', 'json'].includes(parsed.format)) { + throw new Error(`Invalid format: ${parsed.format}. Use text or json.`); + } + + return parsed; +} + +function readText(rootDir, relativePath) { + try { + return fs.readFileSync(path.join(rootDir, relativePath), 'utf8'); + } catch (_error) { + return ''; + } +} + +function fileExists(rootDir, relativePath) { + return fs.existsSync(path.join(rootDir, relativePath)); +} + +function safeParseJson(text) { + if (!text.trim()) { + return null; + } + + try { + return JSON.parse(text); + } catch (_error) { + return null; + } +} + +function normalizeLabel(value) { + return String(value) + .replace(/[`*_]/g, '') + .replace(/\s+/g, ' ') + .trim() + .toLowerCase(); +} + +function normalizeState(value) { + return String(value) + .replace(/[`*_]/g, '') + .replace(/\s+/g, ' ') + .trim() + .toLowerCase(); +} + +function splitMarkdownRow(row) { + const trimmed = row.trim(); + if (!trimmed.startsWith('|') || !trimmed.endsWith('|')) { + return []; + } + + return trimmed + .slice(1, -1) + .split('|') + .map(cell => cell.trim()); +} + +function parseDecisionRegister(packet) { + const decisions = new Map(); + + for (const line of packet.split('\n')) { + const cells = splitMarkdownRow(line); + if (cells.length < 4) { + continue; + } + + const [decision, state] = cells; + const normalizedDecision = normalizeLabel(decision); + if ( + !normalizedDecision + || normalizedDecision === 'decision' + || /^-+$/.test(normalizedDecision) + ) { + continue; + } + + decisions.set(normalizedDecision, normalizeState(state)); + } + + return decisions; +} + +function isApproved(state) { + return state === 'approve' || state === 'approved'; +} + +function lineNumberForIndex(text, index) { + return text.slice(0, index).split('\n').length; +} + +function findAnnouncementOffenders(rootDir, relativePaths) { + const offenders = []; + const privatePathPattern = /\/Users\/(?!\.\.\.)[A-Za-z0-9._-]+|\/home\/(?!user|runner)[A-Za-z0-9._-]+/g; + const anglePlaceholderPattern = /<(?!(?:https?:\/\/|mailto:|#))[^>\n]*(?:url|link|todo|tbd|placeholder)[^>\n]*>/gi; + const barePlaceholderPattern = /\bTODO\b|\bTBD\b|\bPLACEHOLDER\b/g; + + for (const relativePath of relativePaths) { + const text = readText(rootDir, relativePath); + if (!text) { + offenders.push({ + path: relativePath, + line: 1, + marker: 'missing file', + }); + continue; + } + + for (const match of text.matchAll(privatePathPattern)) { + offenders.push({ + path: relativePath, + line: lineNumberForIndex(text, match.index), + marker: match[0], + }); + } + + for (const match of text.matchAll(anglePlaceholderPattern)) { + offenders.push({ + path: relativePath, + line: lineNumberForIndex(text, match.index), + marker: match[0], + }); + } + + for (const match of text.matchAll(barePlaceholderPattern)) { + offenders.push({ + path: relativePath, + line: lineNumberForIndex(text, match.index), + marker: match[0], + }); + } + } + + return offenders; +} + +function ledgerBlockers(ledger) { + const blockers = []; + + if (/^##\s+Approval-Gated URLs\s*$/im.test(ledger)) { + blockers.push('approval-gated URL section still present'); + } + + for (const [pattern, label] of [ + [/not published yet/i, 'not-published marker still present'], + [/must return/i, 'must-return readback marker still present'], + [/Gate before use/i, 'gate-before-use column still present'], + [/\bpending\b/i, 'pending marker still present'], + [/\bblocked\b/i, 'blocked marker still present'], + ]) { + if (pattern.test(ledger)) { + blockers.push(label); + } + } + + return blockers; +} + +function makeCheck(id, status, evidence, fix) { + return { + id, + status, + evidence, + fix: status === 'pass' ? '' : fix, + }; +} + +function topActionsForChecks(checks) { + const actions = []; + const failedIds = new Set(checks.filter(check => check.status !== 'pass').map(check => check.id)); + + if (failedIds.has('release-approval-script-registered')) { + actions.push('Wire release:approval-gate into package.json, package files, and the preview-pack manifest.'); + } + + if (failedIds.has('owner-decisions-approved')) { + actions.push('Approve, defer, or block each owner decision row explicitly after final evidence is rerun from the release commit.'); + } + + if (failedIds.has('release-url-ledger-finalized')) { + actions.push('Replace approval-gated URL ledger rows with live readback URLs from the approved release, package, plugin, video, and billing surfaces.'); + } + + if (failedIds.has('final-evidence-command-listed')) { + actions.push('Add release:approval-gate to the final evidence command lists before asking for publication approval.'); + } + + if (failedIds.has('announcement-copy-finalized')) { + actions.push('Remove unresolved placeholders and private local paths from launch, social, and outbound copy.'); + } + + if (failedIds.has('public-action-guard-present')) { + actions.push('Restore the explicit no-outbound/no-publish authorization boundary in the owner packet.'); + } + + return actions; +} + +function buildReport(options = {}) { + const rootDir = path.resolve(options.root || process.cwd()); + const packageJson = safeParseJson(readText(rootDir, 'package.json')) || {}; + const packageScripts = packageJson.scripts || {}; + const packageFiles = Array.isArray(packageJson.files) ? packageJson.files : []; + const ownerPacket = readText(rootDir, OWNER_PACKET_PATH); + const ledger = readText(rootDir, URL_LEDGER_PATH); + const manifest = readText(rootDir, PREVIEW_MANIFEST_PATH); + const decisions = parseDecisionRegister(ownerPacket); + + const missingDecisions = []; + const unapprovedDecisions = []; + for (const decision of REQUIRED_DECISIONS) { + const state = decisions.get(normalizeLabel(decision.label)); + if (!state) { + missingDecisions.push(decision.label); + } else if (!isApproved(state)) { + unapprovedDecisions.push(`${decision.label}=${state}`); + } + } + + const missingUrlSurfaces = REQUIRED_URL_SURFACES + .filter(surface => !ledger.includes(surface.label)) + .map(surface => surface.label); + const urlBlockers = ledgerBlockers(ledger); + const announcementOffenders = findAnnouncementOffenders(rootDir, ANNOUNCEMENT_FILES); + const commandListedIn = [ + ownerPacket.includes(REQUIRED_COMMAND) ? OWNER_PACKET_PATH : '', + ledger.includes(REQUIRED_COMMAND) ? URL_LEDGER_PATH : '', + manifest.includes(REQUIRED_COMMAND) ? PREVIEW_MANIFEST_PATH : '', + ].filter(Boolean); + + const checks = [ + makeCheck( + 'release-approval-script-registered', + packageScripts['release:approval-gate'] === `node ${SCRIPT_PATH}` + && packageFiles.includes(SCRIPT_PATH) + && fileExists(rootDir, SCRIPT_PATH) + && manifest.includes(`\`${SCRIPT_PATH}\``) + && manifest.includes(REQUIRED_COMMAND) + ? 'pass' + : 'fail', + 'package script, npm package file entry, local script, and preview-pack manifest reference', + 'Add release:approval-gate to package scripts, package files, and preview-pack-manifest.md.' + ), + makeCheck( + 'owner-decisions-approved', + missingDecisions.length === 0 && unapprovedDecisions.length === 0 ? 'pass' : 'fail', + missingDecisions.length === 0 && unapprovedDecisions.length === 0 + ? `${REQUIRED_DECISIONS.length} owner decision rows are approved` + : `missing decisions: ${missingDecisions.join(', ') || 'none'}; pending decisions: ${unapprovedDecisions.join(', ') || 'none'}`, + 'Set every required owner decision row to approve only after the final release evidence has been rerun.' + ), + makeCheck( + 'release-url-ledger-finalized', + ledger + && missingUrlSurfaces.length === 0 + && urlBlockers.length === 0 + ? 'pass' + : 'fail', + ledger && missingUrlSurfaces.length === 0 && urlBlockers.length === 0 + ? `${REQUIRED_URL_SURFACES.length} final URL surfaces are recorded without approval-gated blockers` + : `missing URL surfaces: ${missingUrlSurfaces.join(', ') || 'none'}; blockers: ${urlBlockers.join(', ') || 'none'}`, + 'Regenerate the release URL ledger after the approved publication actions and record live readback URLs.' + ), + makeCheck( + 'final-evidence-command-listed', + commandListedIn.length === 3 ? 'pass' : 'fail', + commandListedIn.length === 3 + ? `${REQUIRED_COMMAND} is listed in owner packet, URL ledger, and preview manifest` + : `${REQUIRED_COMMAND} listed in: ${commandListedIn.join(', ') || 'none'}`, + 'List release:approval-gate in every final evidence command block.' + ), + makeCheck( + 'announcement-copy-finalized', + announcementOffenders.length === 0 ? 'pass' : 'fail', + announcementOffenders.length === 0 + ? `${ANNOUNCEMENT_FILES.length} launch/outbound copy files have no placeholders or private paths` + : `offenders: ${announcementOffenders.map(item => `${item.path}:${item.line}`).join(', ')}`, + 'Replace placeholders with live URLs and remove private local paths from launch/outbound copy.' + ), + makeCheck( + 'public-action-guard-present', + ownerPacket.includes( + 'No outbound email, personal-account post, package publish, plugin tag, or billing announcement is authorized by this packet alone.' + ) + ? 'pass' + : 'fail', + 'owner packet preserves the explicit no-public-action authorization boundary', + 'Restore the owner-packet sentence that blocks outbound, posts, package publish, plugin tags, and billing announcements.' + ), + ]; + + const failed = checks.filter(check => check.status !== 'pass'); + const digest = crypto + .createHash('sha256') + .update(JSON.stringify(checks.map(check => [check.id, check.status, check.evidence]))) + .digest('hex') + .slice(0, 12); + + return { + schema_version: SCHEMA_VERSION, + release: RELEASE, + ready: failed.length === 0, + digest, + summary: { + passed: checks.length - failed.length, + failed: failed.length, + total: checks.length, + }, + top_actions: topActionsForChecks(checks), + checks, + }; +} + +function renderText(report) { + const lines = [ + 'ECC release approval gate', + `Release: ${report.release}`, + `Ready: ${report.ready ? 'yes' : 'no'}`, + `Digest: ${report.digest}`, + '', + 'Checks:', + ]; + + for (const check of report.checks) { + lines.push(`- ${check.status} ${check.id}: ${check.evidence}`); + if (check.fix) { + lines.push(` fix: ${check.fix}`); + } + } + + if (report.top_actions.length > 0) { + lines.push(''); + lines.push('Top actions:'); + for (const action of report.top_actions) { + lines.push(`- ${action}`); + } + } + + lines.push(''); + lines.push(`Passed: ${report.summary.passed}`); + lines.push(`Failed: ${report.summary.failed}`); + + return `${lines.join('\n')}\n`; +} + +function main() { + let parsed; + + try { + parsed = parseArgs(process.argv); + } catch (error) { + console.error(`Error: ${error.message}`); + process.exit(1); + } + + if (parsed.help) { + usage(); + return; + } + + const report = buildReport({ root: parsed.root }); + + if (parsed.format === 'json') { + console.log(JSON.stringify(report, null, 2)); + } else { + process.stdout.write(renderText(report)); + } + + if (!report.ready) { + process.exit(2); + } +} + +if (require.main === module) { + main(); +} + +module.exports = { + ANNOUNCEMENT_FILES, + REQUIRED_COMMAND, + REQUIRED_DECISIONS, + REQUIRED_URL_SURFACES, + buildReport, + parseArgs, + renderText, +}; diff --git a/tests/docs/ecc2-release-surface.test.js b/tests/docs/ecc2-release-surface.test.js index 8456ce56..a0b59abd 100644 --- a/tests/docs/ecc2-release-surface.test.js +++ b/tests/docs/ecc2-release-surface.test.js @@ -177,6 +177,7 @@ test('preview pack manifest assembles release, Hermes, and publication gates', ( 'skills/hermes-imports/SKILL.md', 'docs/architecture/harness-adapter-compliance.md', 'scripts/preview-pack-smoke.js', + 'scripts/release-approval-gate.js', 'docs/releases/2.0.0-rc.1/publication-readiness.md', 'docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md', 'docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md', @@ -201,6 +202,7 @@ test('preview pack manifest assembles release, Hermes, and publication gates', ( assert.ok(manifest.includes('no raw workspace exports')); assert.ok(manifest.includes('Final Verification Commands')); assert.ok(manifest.includes('npm run preview-pack:smoke')); + assert.ok(manifest.includes('npm run release:approval-gate -- --format json')); assert.ok(manifest.includes('npm run release:video-suite -- --format json')); assert.ok(manifest.includes('Reference-Inspired Adapter Direction')); }); @@ -229,6 +231,7 @@ test('owner approval packet consolidates the final gated decisions', () => { for (const command of [ 'node scripts/platform-audit.js --json', 'npm run preview-pack:smoke -- --format json', + 'npm run release:approval-gate -- --format json', 'npm run release:video-suite -- --format json', 'node tests/run-all.js', ]) { @@ -255,7 +258,7 @@ test('GA roadmap mirrors the current May 19 release evidence', () => { for (const marker of [ 'owner-approval-packet-2026-05-19.md', - 'preview-pack smoke digest `790430aef4a8`', + 'preview-pack smoke digest `531328aaaa53`', 'local 2560-test suite', 'PR #2001', 'GitHub Actions run `26102500291`', @@ -344,6 +347,31 @@ test('release video suite manifest gates the content launch lane', () => { assert.ok(packageJson.files.includes('scripts/release-video-suite.js')); }); +test('release approval gate blocks publication until owner decisions and URLs are final', () => { + const manifest = read('docs/releases/2.0.0-rc.1/preview-pack-manifest.md'); + const packet = read('docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md'); + const ledger = read('docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md'); + const script = read('scripts/release-approval-gate.js'); + const packageJson = JSON.parse(read('package.json')); + + for (const marker of [ + 'ecc.release-approval-gate.v1', + 'owner-decisions-approved', + 'release-url-ledger-finalized', + 'announcement-copy-finalized', + 'No outbound email, personal-account post, package publish, plugin tag, or billing announcement', + ]) { + assert.ok(script.includes(marker), `release approval gate missing ${marker}`); + } + + assert.ok(manifest.includes('scripts/release-approval-gate.js')); + assert.ok(manifest.includes('npm run release:approval-gate -- --format json')); + assert.ok(packet.includes('npm run release:approval-gate -- --format json')); + assert.ok(ledger.includes('npm run release:approval-gate -- --format json')); + assert.strictEqual(packageJson.scripts['release:approval-gate'], 'node scripts/release-approval-gate.js'); + assert.ok(packageJson.files.includes('scripts/release-approval-gate.js')); +}); + test('partner sponsor talks pack gates the hypergrowth outbound lane', () => { const partnerPack = read('docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md'); const manifest = read('docs/releases/2.0.0-rc.1/preview-pack-manifest.md'); @@ -510,6 +538,7 @@ test('release name and plugin publication checklist freezes rc.1 surfaces', () = 'codex plugin marketplace add --help', 'npm publish --tag next --dry-run', 'npm run preview-pack:smoke', + 'npm run release:approval-gate -- --format json', ]) { assert.ok(checklist.includes(command), `release name/plugin checklist missing command ${command}`); } diff --git a/tests/scripts/npm-publish-surface.test.js b/tests/scripts/npm-publish-surface.test.js index 51df54c7..b93b8073 100644 --- a/tests/scripts/npm-publish-surface.test.js +++ b/tests/scripts/npm-publish-surface.test.js @@ -60,6 +60,7 @@ function buildExpectedPublishPaths(repoRoot) { "scripts/operator-readiness-dashboard.js", "scripts/platform-audit.js", "scripts/preview-pack-smoke.js", + "scripts/release-approval-gate.js", "scripts/release-video-suite.js", "scripts/skill-create-output.js", "scripts/repair.js", @@ -132,6 +133,7 @@ function main() { "scripts/discussion-audit.js", "scripts/operator-readiness-dashboard.js", "scripts/preview-pack-smoke.js", + "scripts/release-approval-gate.js", "scripts/release-video-suite.js", "scripts/work-items.js", "scripts/platform-audit.js", diff --git a/tests/scripts/release-approval-gate.test.js b/tests/scripts/release-approval-gate.test.js new file mode 100644 index 00000000..bc064ff3 --- /dev/null +++ b/tests/scripts/release-approval-gate.test.js @@ -0,0 +1,320 @@ +'use strict'; + +const assert = require('assert'); +const fs = require('fs'); +const os = require('os'); +const path = require('path'); +const { execFileSync, spawnSync } = require('child_process'); + +const SCRIPT = path.join(__dirname, '..', '..', 'scripts', 'release-approval-gate.js'); +const { + REQUIRED_DECISIONS, + REQUIRED_URL_SURFACES, + buildReport, + parseArgs, + renderText, +} = require(SCRIPT); + +const RELEASE_DIR = 'docs/releases/2.0.0-rc.1'; + +function createTempDir(prefix) { + return fs.mkdtempSync(path.join(os.tmpdir(), prefix)); +} + +function cleanup(dirPath) { + fs.rmSync(dirPath, { recursive: true, force: true }); +} + +function writeFile(rootDir, relativePath, content) { + const targetPath = path.join(rootDir, relativePath); + fs.mkdirSync(path.dirname(targetPath), { recursive: true }); + fs.writeFileSync(targetPath, content); +} + +function approvedPacketContent(overrides = {}) { + const decisions = new Map(REQUIRED_DECISIONS.map(decision => [decision.label, 'approve'])); + for (const [label, value] of Object.entries(overrides)) { + decisions.set(label, value); + } + + return [ + '# ECC v2.0.0-rc.1 Owner Approval Packet', + '', + '## Decision Register', + '', + '| Decision | Approve / defer / block | Evidence required first | Notes |', + '| --- | --- | --- | --- |', + ...REQUIRED_DECISIONS.map(decision => ( + `| ${decision.label} | ${decisions.get(decision.label)} | final evidence | approved fixture |` + )), + '', + '## Final Evidence Commands', + '', + '```bash', + 'npm run release:approval-gate -- --format json', + '```', + '', + 'No outbound email, personal-account post, package publish, plugin tag, or billing announcement is authorized by this packet alone.', + ].join('\n'); +} + +function finalLedgerContent(extra = '') { + return [ + '# ECC v2.0.0-rc.1 Release URL Ledger', + '', + '## Final Published URLs', + '', + '| Surface | URL | Verification |', + '| --- | --- | --- |', + ...REQUIRED_URL_SURFACES.map(surface => ( + `| ${surface.label} | ${surface.exampleUrl} | readback from final release commit |` + )), + '', + '## Final Verification Commands', + '', + '```bash', + 'npm run release:approval-gate -- --format json', + '```', + '', + extra, + ].join('\n'); +} + +function manifestContent() { + return [ + '# ECC v2.0.0-rc.1 Preview Pack Manifest', + '', + '| Artifact | Role | Gate |', + '| --- | --- | --- |', + '| `scripts/release-approval-gate.js` | Final owner approval and live URL gate | Verified by `npm run release:approval-gate -- --format json` |', + '', + '## Final Verification Commands', + '', + '```bash', + 'npm run release:approval-gate -- --format json', + '```', + ].join('\n'); +} + +function seedRepo(rootDir, overrides = {}) { + const files = { + 'package.json': JSON.stringify({ + files: ['scripts/release-approval-gate.js'], + scripts: { + 'release:approval-gate': 'node scripts/release-approval-gate.js', + }, + }, null, 2), + 'scripts/release-approval-gate.js': 'release approval gate script', + [`${RELEASE_DIR}/owner-approval-packet-2026-05-19.md`]: approvedPacketContent(), + [`${RELEASE_DIR}/release-url-ledger-2026-05-19.md`]: finalLedgerContent(), + [`${RELEASE_DIR}/preview-pack-manifest.md`]: manifestContent(), + [`${RELEASE_DIR}/release-notes.md`]: 'Release notes with final URLs.', + [`${RELEASE_DIR}/x-thread.md`]: 'X post with final URLs.', + [`${RELEASE_DIR}/linkedin-post.md`]: 'LinkedIn post with final URLs.', + [`${RELEASE_DIR}/article-outline.md`]: 'Article outline with final URLs.', + [`${RELEASE_DIR}/partner-sponsor-talks-pack.md`]: 'Outbound copy with final URLs.', + 'docs/business/social-launch-copy.md': 'Business launch copy with final URLs.', + }; + + for (const [relativePath, content] of Object.entries({ ...files, ...overrides })) { + if (content === null) { + continue; + } + writeFile(rootDir, relativePath, content); + } +} + +function run(args = [], options = {}) { + return execFileSync('node', [SCRIPT, ...args], { + cwd: options.cwd || path.join(__dirname, '..', '..'), + encoding: 'utf8', + stdio: ['pipe', 'pipe', 'pipe'], + timeout: 10000, + }); +} + +function runProcess(args = [], options = {}) { + return spawnSync('node', [SCRIPT, ...args], { + cwd: options.cwd || path.join(__dirname, '..', '..'), + encoding: 'utf8', + stdio: ['pipe', 'pipe', 'pipe'], + timeout: 10000, + }); +} + +function test(name, fn) { + try { + fn(); + console.log(` PASS ${name}`); + return true; + } catch (error) { + console.log(` FAIL ${name}`); + console.log(` Error: ${error.message}`); + return false; + } +} + +function runTests() { + console.log('\n=== Testing release-approval-gate.js ===\n'); + + let passed = 0; + let failed = 0; + + if (test('parseArgs accepts approval gate flags and rejects invalid values', () => { + const rootDir = createTempDir('release-approval-args-'); + + try { + const parsed = parseArgs([ + 'node', + 'script', + '--format=json', + `--root=${rootDir}`, + ]); + + assert.strictEqual(parsed.format, 'json'); + assert.strictEqual(parsed.root, path.resolve(rootDir)); + assert.throws(() => parseArgs(['node', 'script', '--format', 'xml']), /Invalid format/); + assert.throws(() => parseArgs(['node', 'script', '--root']), /--root requires a value/); + assert.throws(() => parseArgs(['node', 'script', '--unknown']), /Unknown argument/); + } finally { + cleanup(rootDir); + } + })) passed++; else failed++; + + if (test('seeded approved release passes every publication approval check', () => { + const rootDir = createTempDir('release-approval-pass-'); + + try { + seedRepo(rootDir); + const report = buildReport({ root: rootDir }); + + assert.strictEqual(report.schema_version, 'ecc.release-approval-gate.v1'); + assert.strictEqual(report.ready, true); + assert.strictEqual(report.summary.failed, 0); + assert.deepStrictEqual(report.top_actions, []); + assert.ok(report.checks.every(check => check.status === 'pass')); + + const text = renderText(report); + assert.ok(text.includes('Ready: yes')); + assert.ok(text.includes('Failed: 0')); + } finally { + cleanup(rootDir); + } + })) passed++; else failed++; + + if (test('deferred owner decisions keep the publication gate blocked', () => { + const rootDir = createTempDir('release-approval-deferred-'); + + try { + seedRepo(rootDir, { + [`${RELEASE_DIR}/owner-approval-packet-2026-05-19.md`]: approvedPacketContent({ + 'GitHub prerelease': 'defer', + 'Sponsor, partner, consulting, conference, podcast outreach': 'block', + }), + }); + + const report = buildReport({ root: rootDir }); + const decisions = report.checks.find(check => check.id === 'owner-decisions-approved'); + + assert.strictEqual(report.ready, false); + assert.strictEqual(decisions.status, 'fail'); + assert.ok(decisions.evidence.includes('GitHub prerelease=defer')); + assert.ok(decisions.evidence.includes('Sponsor, partner, consulting, conference, podcast outreach=block')); + assert.ok(report.top_actions.some(action => action.includes('Approve, defer, or block'))); + } finally { + cleanup(rootDir); + } + })) passed++; else failed++; + + if (test('approval-gated URL ledger rows keep the publication gate blocked', () => { + const rootDir = createTempDir('release-approval-ledger-'); + + try { + seedRepo(rootDir, { + [`${RELEASE_DIR}/release-url-ledger-2026-05-19.md`]: [ + '# ECC v2.0.0-rc.1 Release URL Ledger', + '', + '## Approval-Gated URLs', + '', + '| Surface | Intended URL or command | Gate before use |', + '| --- | --- | --- |', + '| GitHub prerelease | https://github.com/affaan-m/ECC/releases/tag/v2.0.0-rc.1 | must return the prerelease |', + ].join('\n'), + }); + + const report = buildReport({ root: rootDir }); + const ledger = report.checks.find(check => check.id === 'release-url-ledger-finalized'); + + assert.strictEqual(report.ready, false); + assert.strictEqual(ledger.status, 'fail'); + assert.ok(ledger.evidence.includes('approval-gated URL section still present')); + } finally { + cleanup(rootDir); + } + })) passed++; else failed++; + + if (test('announcement drafts fail on unresolved placeholders and private paths', () => { + const rootDir = createTempDir('release-approval-copy-'); + + try { + seedRepo(rootDir, { + [`${RELEASE_DIR}/x-thread.md`]: 'Ship copy with and /Users/affaan/raw-footage.', + }); + + const report = buildReport({ root: rootDir }); + const copy = report.checks.find(check => check.id === 'announcement-copy-finalized'); + + assert.strictEqual(report.ready, false); + assert.strictEqual(copy.status, 'fail'); + assert.ok(copy.evidence.includes(`${RELEASE_DIR}/x-thread.md:1`)); + } finally { + cleanup(rootDir); + } + })) passed++; else failed++; + + if (test('CLI emits json and uses status 2 for blocked approval reports', () => { + const rootDir = createTempDir('release-approval-cli-'); + + try { + seedRepo(rootDir); + const stdout = run(['--format=json', `--root=${rootDir}`], { cwd: rootDir }); + const parsed = JSON.parse(stdout); + assert.strictEqual(parsed.ready, true); + + writeFile( + rootDir, + `${RELEASE_DIR}/owner-approval-packet-2026-05-19.md`, + approvedPacketContent({ 'Video upload': 'defer' }) + ); + const failedRun = runProcess(['--format=json', `--root=${rootDir}`], { cwd: rootDir }); + assert.strictEqual(failedRun.status, 2); + assert.strictEqual(failedRun.stderr, ''); + assert.ok(failedRun.stdout.includes('"ready": false')); + } finally { + cleanup(rootDir); + } + })) passed++; else failed++; + + if (test('CLI help exits successfully and invalid flags fail before reporting', () => { + const help = runProcess(['--help']); + assert.strictEqual(help.status, 0); + assert.strictEqual(help.stderr, ''); + assert.ok(help.stdout.includes('Usage: node scripts/release-approval-gate.js')); + + const invalid = runProcess(['--format=xml']); + assert.strictEqual(invalid.status, 1); + assert.strictEqual(invalid.stdout, ''); + assert.match(invalid.stderr, /Error: Invalid format/); + })) passed++; else failed++; + + console.log(`\nPassed: ${passed}`); + console.log(`Failed: ${failed}`); + + if (failed > 0) { + process.exit(1); + } +} + +if (require.main === module) { + runTests(); +} From b3c015c7443c6617f897654613c21eddc3d25764 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 18:51:25 -0400 Subject: [PATCH 54/61] docs: sync late May 19 release roadmap state --- docs/ECC-2.0-GA-ROADMAP.md | 50 ++++++++++++------- docs/architecture/progress-sync-contract.md | 11 ++-- .../owner-approval-packet-2026-05-19.md | 6 +-- .../2.0.0-rc.1/preview-pack-manifest.md | 2 +- .../publication-evidence-2026-05-19.md | 34 +++++++++---- .../2.0.0-rc.1/publication-readiness.md | 2 +- scripts/platform-audit.js | 2 +- tests/docs/ecc2-release-surface.test.js | 2 +- .../operator-readiness-dashboard.test.js | 4 +- tests/scripts/platform-audit.test.js | 4 +- 10 files changed, 74 insertions(+), 43 deletions(-) diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index e350ad5b..589847c7 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -22,6 +22,12 @@ partner/sponsor funnel, consulting/talk funnel, and social launch plan. - The public repo identity is now `affaan-m/ECC`; release, package, plugin, workflow, and launch-copy surfaces should use that URL for current public links. +- The late May 19 queue drain added the deterministic `release:approval-gate` + on ECC `main`, merged ECC-Tools billing-announcement redaction hardening, and + cleared the JARVIS Dependabot/deploy repair tail. The tracked platform audit + is now green with 0 open PRs, 0 open issues, and 0 discussion gaps across all + five tracked repos, but release/publication actions remain owner and live-URL + gated. - The ECC 2.0 release story should lead with the product shape directly: harness-native operator system, reusable skills/rules/hooks/MCP conventions, `ecc2/` alpha control plane, Hermes as optional operator shell, and ECC Tools @@ -38,10 +44,9 @@ As of 2026-05-19: `affaan-m/agentshield`, `affaan-m/JARVIS`, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website`: the latest `platform-audit` sweep found 0 open PRs, 0 open issues, 0 discussion maintainer-touch gaps, 0 answerable Q&A missing - accepted answers, and 0 blocking dirty files when allowing the unrelated - local `docs/drafts/` directory. The May 18 sync also refreshed - `scripts/work-items.js sync-github` across all five tracked repos, leaving - no open or blocked local work items. + accepted answers, and 0 blocking dirty files. The current + `scripts/work-items.js list --json` output also reports `totalCount: 0`, so + there are no open or blocked local work items in the SQLite bridge. - Owner-wide queue cleanup is also inside the requested budget: `docs/releases/2.0.0-rc.1/owner-queue-cleanup-2026-05-18.md` records the live `gh search` sweep that closed 24 stale dependency-bot PRs and 72 stale @@ -85,19 +90,24 @@ As of 2026-05-19: current May 19 queue-zero state, canonical ECC identity merge, release video suite gate, partner/sponsor/talk outreach pack, owner approval packet (`owner-approval-packet-2026-05-19.md`), preview-pack smoke digest - `531328aaaa53`, local 2560-test suite, PR #2001 merge and GitHub Actions run + `531328aaaa53`, local 2568-test suite, PR #2001 merge and GitHub Actions run `26102500291` success, PR #2002's owner-approval dashboard gate refresh and GitHub Actions run `26103853507`, PR #2004's Linear readiness evidence sync and GitHub Actions run `26105012698`, plus PR #2005's post-PR #2004 evidence refresh and GitHub Actions run `26106321921`, PR #2008's supply-chain evidence gate fix and GitHub Actions run `26108473648`, post-PR #2006 main CI run `26109953093`, and PR #2009's project-registry hygiene GitHub Actions run - `26111313938`, post-PR #2009 main CI run `26111946778`, and post-PR #2011 - GateGuard main CI run `26113695068`. The May 19 Linear sync document remains - the current external project status surface, and the - supply-chain gate now also records the `@types/node@25.7.0` pin and - `brace-expansion` lock refresh needed for current npm audit/signature - verification. + `26111313938`, post-PR #2009 main CI run `26111946778`, post-PR #2011 + GateGuard main CI run `26113695068`, and post-PR #2013 release-approval-gate + main CI run `26128749863`. The late May 19 sync target also includes + ECC-Tools PR #79 billing-announcement redaction hardening and JARVIS PR #15 + / PR #16 queue/deploy repair, with JARVIS main CI, CodeQL, and Deploy green + after the workflow repair. The Linear external project status surface now has + both the post-PR #2002 sync document and the late-pass document + `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f`, plus project + comment `d42bf0e2-7a8e-4934-9f3f-e281498ee805`. The supply-chain gate now + also records the `@types/node@25.7.0` pin and `brace-expansion` lock refresh + needed for current npm audit/signature verification. - `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` regenerates the ITO-44 prompt-to-artifact dashboard from live platform audit evidence: PR queue, issue queue, discussion queue, local worktree gate, @@ -733,7 +743,7 @@ As of 2026-05-19: - Keep public PRs and issues below 20, with zero as the preferred release-lane target. -- Maintain 70/70 harness audit and 21/21 observability readiness after every +- Maintain 80/80 harness audit and 21/21 observability readiness after every GA-readiness batch. - Do not publish release or social announcements until the GitHub release, npm/package state, billing state, and plugin submission surfaces are verified @@ -741,7 +751,9 @@ As of 2026-05-19: - Do not treat closed stale PRs as discarded. Pair each cleanup batch with a salvage pass: inspect the closed diffs, port useful compatible work on maintainer-owned branches, and credit the source PR. -- Do not create new Linear issues until the active issue limit is cleared. +- Use Linear project documents/comments for project-level updates because + project status updates are disabled in this workspace; create or update + issues when a lane needs a durable execution owner. ## Prompt-To-Artifact Execution Checklist @@ -750,12 +762,12 @@ is not complete unless the evidence column exists and has been freshly verified. | Prompt requirement | Required artifact or gate | Current evidence | Status | | --- | --- | --- | --- | -| Keep public PRs below 20 | Repo-family PR recheck | 0 open PRs across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-19 after merging PR #2004 and refreshing platform audit evidence | Complete | +| Keep public PRs below 20 | Repo-family PR recheck | 0 open PRs across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on the late 2026-05-19 platform audit after merging ECC PR #2013, ECC-Tools PR #79, JARVIS PR #15, and JARVIS PR #16 | Complete | | Keep public issues below 20 | Repo-family issue recheck | 0 open issues across `ECC`, AgentShield, JARVIS, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` on 2026-05-19 after the live platform audit refresh | Complete | | Manage repository discussions | Repo-family discussion recheck plus response playbook | Platform audit reports 0 discussion maintainer-touch gaps and 0 answerable Q&A missing accepted answers; trunk has 59 total discussions after #2003 was routed with a maintainer response; `docs/architecture/discussion-response-playbook.md` distinguishes support, maintainer coordination, stale/concluded, release, informational, and security-sensitive response paths | Complete | -| Manage PR discussions | PR review/comment closure plus merge/close state | ECC #1990-#2011 merged through the harness audit, canonical identity, release video suite, growth outreach, evidence refresh, visual QA, suite-count, owner-approval packet, owner-approval dashboard gate, Linear readiness evidence, supply-chain evidence gate, per-project Claude Code adapter, continuous-learning project-registry hygiene, and GateGuard quoted git introspection batch; no open tracked PRs remain | Complete | +| Manage PR discussions | PR review/comment closure plus merge/close state | ECC #1990-#2013 merged through the harness audit, canonical identity, release video suite, growth outreach, evidence refresh, visual QA, suite-count, owner-approval packet, owner-approval dashboard gate, Linear readiness evidence, supply-chain evidence gate, per-project Claude Code adapter, continuous-learning project-registry hygiene, GateGuard quoted git introspection, and deterministic release-approval gate batch; ECC-Tools #79 and JARVIS #15/#16 also merged; no open tracked PRs remain | Complete | | Salvage useful stale work | `docs/stale-pr-salvage-ledger.md` plus `docs/legacy-artifact-inventory.md` | Ledger records salvaged, superseded, skipped, and manual-review tails; #1815-#1818 added cost tracking, skill scout, frontend design guidance, code-reviewer false-positive guardrails, and the May 12 gap pass; #1687, #1609, #1563, #1564, and #1565 localization tails are attached to Linear ITO-55 for language-owner review and no automatic import remains release-blocking | Complete; repeat legacy scan before release | -| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 19 evidence records queue-zero state, canonical ECC identity, release video suite, growth outreach pack, owner approval packet, local 2560-test suite, PR #2001 merge and GitHub Actions run `26102500291`, PR #2002 owner-approval dashboard gate refresh and GitHub Actions run `26103853507`, PR #2004 Linear readiness evidence sync and GitHub Actions run `26105012698`, PR #2008 supply-chain evidence gate CI run `26108473648`, post-PR #2006 main CI run `26109953093`, PR #2009 project-registry hygiene GitHub Actions run `26111313938`, post-PR #2009 main CI run `26111946778`, post-PR #2011 GateGuard main CI run `26113695068`, May 19 operator dashboard, `owner-approval-packet-2026-05-19.md`, `release-approval-gate.js`, and preview-pack smoke digest `531328aaaa53` | Needs final release approval | +| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 19 evidence records queue-zero state, canonical ECC identity, release video suite, growth outreach pack, owner approval packet, local 2568-test suite, PR #2001 merge and GitHub Actions run `26102500291`, PR #2002 owner-approval dashboard gate refresh and GitHub Actions run `26103853507`, PR #2004 Linear readiness evidence sync and GitHub Actions run `26105012698`, PR #2008 supply-chain evidence gate CI run `26108473648`, post-PR #2006 main CI run `26109953093`, PR #2009 project-registry hygiene GitHub Actions run `26111313938`, post-PR #2009 main CI run `26111946778`, post-PR #2011 GateGuard main CI run `26113695068`, post-PR #2013 release-approval main CI run `26128749863`, May 19 operator dashboard, `owner-approval-packet-2026-05-19.md`, `release-approval-gate.js`, and preview-pack smoke digest `531328aaaa53` | Needs final release approval | | Hermes specialized skills included safely | Hermes setup/import docs and sanitized skill surface | Hermes setup and import playbook are public; secrets stay local | Needs final release review | | Naming and rename readiness | Naming matrix across package/plugin/docs/social surfaces | `docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md` records current package, repo, Claude plugin, Codex plugin, OpenCode, and npm availability evidence | Complete for rc.1; post-rc rename remains future work | | Claude and Codex plugin publication | Contact/submission path with required artifacts and status | Publication readiness, naming matrix, and May 12 dry-run evidence document plugin validation, clean-checkout Claude tag/install smoke, and Codex marketplace CLI shape | Needs explicit approval for real tag/push and marketplace submission | @@ -764,9 +776,9 @@ is not complete unless the evidence column exists and has been freshly verified. | ECC Tools next-level app | Billing audit, PR checks, deep analyzer, sync backlog, evaluator/RAG corpus, analysis-depth readiness, hosted execution planning, hosted CI diagnostics, hosted security evidence review, hosted harness compatibility audit, hosted reference-set evaluation, hosted AI routing/cost review, hosted team backlog routing, hosted depth-plan check-run, PR-comment hosted job dispatch, hosted job result history/check-runs, hosted result status command, status-aware depth-plan recommendations, hosted promotion readiness, hosted promotion output scoring, hosted promotion retrieval planning, hosted promotion judge contract, gated hosted promotion judge execution, hosted promotion judge audit trace, payment-announcement readiness, billing announcement preflight, aggregate production billing KV readback, Marketplace webhook provenance, target-account billing readback, Marketplace-source provenance counts, AgentShield fleet-summary hosted routing, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output hosted telemetry, and operator-visible promotion output values | PRs #26-#43 plus #53-#78 landed with test evidence, including AgentShield evidence-pack gap routing, canonical bundle recognition, supply-chain signature gates, PR draft follow-up Linear tracking, evidence-backed/deep-ready repository classification, the `/api/analysis/depth-plan` hosted job plan, `/api/analysis/jobs/ci-diagnostics`, `/api/analysis/jobs/security-evidence-review`, `/api/analysis/jobs/harness-compatibility-audit`, `/api/analysis/jobs/reference-set-evaluation`, `/api/analysis/jobs/ai-routing-cost-review`, `/api/analysis/jobs/team-backlog-routing`, the `ECC Tools / Hosted Depth Plan` check-run, `/ecc-tools analyze --job ...` PR-comment dispatch, non-blocking per-hosted-job result check-runs backed by 30-day result cache records, `/ecc-tools analyze --job status` cache lookup, cache-aware next-job recommendations in the depth-plan check-run, the `ECC Tools / Hosted Promotion Readiness` corpus-backed PR check-run, deterministic hosted-output scoring against cached completed job artifacts/findings, ranked retrieval/model-prompt planning, the fail-closed `hosted-promotion-judge.v1` request contract, opt-in live model-judge execution behind hosted evidence, entitlement, budget, provider, executor, strict JSON, and citation gates, hosted promotion judge request fingerprints plus allowed-citation audit trails, a fail-closed `/api/billing/readiness` `announcementGate` for native GitHub payments claims, `npm run billing:announcement-gate` plus `--preflight` as the non-secret operator verifier, hosted security findings for AgentShield fleet summaries, an `Evidence` column in hosted finding comments/check-runs, hosted harness findings that route AgentShield fleet target paths to harness owners, ECC-Tools commit `8658951` routing AgentShield policy-promotion Action outputs into hosted security review and promotion-readiness scoring, ECC-Tools commit `16c537f` rendering policy-promotion status/pack/count/digest values directly in hosted security job comments/check-runs, ECC-Tools commit `05d4e82` rendering model-judge audit traces without exposing raw provider output, ECC-Tools commit `91a441b` adding the safe billing announcement preflight path, ECC-Tools commit `eb69412` recording the initial production readback state, ECC-Tools commit `95d0bec` adding `npm run billing:kv-readback` with aggregate account-billing and billing-state records but 0 Marketplace Pro billing-state records, ECC-Tools commit `2859678` requiring webhook-derived Marketplace provenance before announcement readiness, ECC-Tools commit `42653f9` adding Wrangler OAuth readback, ECC-Tools commit `632e059` adding sanitized target-account readback that requires both target key families before `--require-ready` can pass, and ECC-Tools commit `d5f60db` adding sanitized Marketplace plan/action provenance counts; the latest 2026-05-18 live Wrangler OAuth recheck found 256 account-billing records, 256 billing-state records, 197 Marketplace-source records, 4 Marketplace webhook-provenance records, all `Open Source`, and 0 Marketplace Pro records, then updated Linear ITO-61 with the data/provisioning blocker | Next work is create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure target account plus `INTERNAL_API_SECRET`, then run `billing:kv-readback -- --wrangler --wrangler-bin ./node_modules/.bin/wrangler --account --require-ready`, followed by the live announcement gate | | GitGuardian/Dependabot/CodeRabbit-style checks | Non-blocking taxonomy, deterministic follow-up checks, and local supply-chain gates | ECC-Tools risk taxonomy check plus follow-up signals landed, including Skill Quality, Deep Analyzer Evidence, Analyzer Corpus Evidence, RAG/Evaluator Evidence, PR Review/Salvage Evidence, and AgentShield evidence-pack evidence; #1846 added npm registry signature gates; #1848 added the supply-chain incident-response playbook and `pull_request_target` cache-poisoning validator guard; #1851 added the privileged checkout credential-persistence guard; AgentShield #78, JARVIS #13, and ECC-Tools #53 applied the same hardening outside trunk | Current supply-chain gate complete; deeper hosted review features remain future | | Harness-agnostic learning system | Audit, adapter matrix, observability, traces, promotion loop | Audit/adapters/observability gates plus `docs/architecture/evaluator-rag-prototype.md`, `examples/evaluator-rag-prototype/`, and ECC-Tools PR #40 define read-only stale-salvage, billing-readiness, CI-failure-diagnosis, harness-config-quality, AgentShield policy-exception, skill-quality evidence, deep-analyzer evidence, and RAG/evaluator comparison scenarios with trace, report, playbook, verifier, and predictive-check artifacts; ECC-Tools PRs #68-#72 now turn that corpus into a deterministic PR check-run gate with cached hosted-output scoring, ranked retrieval candidates, a model prompt seed, a fail-closed hosted model-judge request contract, and opt-in live model execution behind strict hosted-evidence gates | Deterministic hosted PR check, cached output scoring, retrieval planning, judge contract, and gated model execution integrated | -| Linear roadmap is detailed | Linear project status plus repo mirror | Repo mirror exists and issue creation works again; the May 19 sync adds post-PR #2002 document `ecc-may-19-post-pr-2002-sync-64cef8f668e0`, project comment `a6411e3a-8c8e-4a58-adba-687e77d4c543`, ITO-44/47/48/49/51/54/56 issue comments, and In Progress state for ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56; PR #2004 mirrors that sync into the repo evidence set | Needs recurring status updates after each significant merge batch | +| Linear roadmap is detailed | Linear project document/comments plus repo mirror | Repo mirror exists and issue creation works again; the May 19 sync adds post-PR #2002 document `ecc-may-19-post-pr-2002-sync-64cef8f668e0`, project comment `a6411e3a-8c8e-4a58-adba-687e77d4c543`, ITO-44/47/48/49/51/54/56 issue comments, and In Progress state for ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56; the late-pass batch adds document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f`, project comment `d42bf0e2-7a8e-4934-9f3f-e281498ee805`, and ITO-44/50/54/56/61 comments for PR #2013, ECC-Tools #79, and JARVIS #15/#16 because project status updates are disabled in the workspace | Needs recurring document/comment updates after each significant merge batch | | Flow separation and progress tracking | Flow lanes with owner artifacts and update cadence | This roadmap defines lanes below and `docs/architecture/progress-sync-contract.md` makes GitHub/Linear/handoff/roadmap sync part of the readiness gate | Active | -| Realtime Linear sync | Project comments while issue/status capacity is blocked; issues later | ECC-Tools #39 implements opt-in Linear API sync for deferred follow-up backlog items, and ECC-Tools #54 adds copy-ready PR drafts to that backlog when draft PR shells are not opened; `docs/architecture/progress-sync-contract.md` defines the local file-backed realtime boundary while issue capacity is blocked; May 18 live connector comments were posted to ITO-57 and the ECC platform project after project status updates returned disabled | Needs workspace capacity/config rollout for productized issue sync | +| Realtime Linear sync | Project documents/comments plus issue comments for lane updates | ECC-Tools #39 implements opt-in Linear API sync for deferred follow-up backlog items, and ECC-Tools #54 adds copy-ready PR drafts to that backlog when draft PR shells are not opened; `docs/architecture/progress-sync-contract.md` defines the local file-backed realtime boundary; May 18 and May 19 live connector comments were posted to the ECC platform project and lane issues after project status updates returned disabled | Needs workspace config/product rollout for hosted issue sync | | Observability for self-use | Local readiness gate, traces, status snapshots, HUD/status contract, risk ledger, progress-sync contract | `npm run observability:ready` reports 21/21 | Complete for local gate | | Proper release and notifications | Release tag, npm publish state, plugin state, social posts | Publication readiness gate exists with May 12 dry-run and May 13 readiness evidence | Not complete; approval/live URLs required | @@ -845,7 +857,7 @@ Acceptance: Zed-adjacent surfaces, dmux, Orca, Superset, Ghast, and terminal-only use. - Each adapter has supported assets, unsupported surfaces, install path, verification command, and risk notes. -- Harness audit remains 70/70 and gains a public onramp that explains how teams +- Harness audit remains 80/80 and gains a public onramp that explains how teams use the scorecard. - Reference findings are converted into concrete adapter, observability, or operator-surface deltas. diff --git a/docs/architecture/progress-sync-contract.md b/docs/architecture/progress-sync-contract.md index 8830e615..d852d705 100644 --- a/docs/architecture/progress-sync-contract.md +++ b/docs/architecture/progress-sync-contract.md @@ -9,7 +9,7 @@ status update can claim a lane is current. | Surface | Role | Current rule | | --- | --- | --- | | GitHub PRs/issues/discussions | Public queue and review state | Recheck live counts before every significant merge batch and before release approval. | -| Linear project | Executive roadmap and stakeholder status update | Post project status updates while issue capacity blocks issue creation. Create/reuse issues only when workspace capacity is available. | +| Linear project | Executive roadmap and stakeholder status update | Use project documents and project/issue comments because project status updates are disabled in this workspace; create/reuse issues for durable execution lanes. | | Local handoff | Durable operator continuity | Update the active handoff after every merge batch, queue drain, skipped release gate, or blocked external action. | | Repo roadmap | Auditable planning mirror | Keep `docs/ECC-2.0-GA-ROADMAP.md` aligned to merged PR evidence and unresolved gates. | | `scripts/work-items.js` | Local tracker bridge | Sync GitHub PRs/issues into the SQLite work-items store for status snapshots and blocked follow-up. | @@ -41,9 +41,12 @@ After a significant merge batch, update Linear and the handoff with: 4. Deferred or skipped work and the explicit reason. 5. The next one or two implementation slices. -When Linear issue capacity is unavailable, use a project status update instead -of creating placeholder issues. When issue capacity is available, create or -reuse exact-title issues and link them to the repo evidence. +When Linear project status updates are unavailable, use a project document plus +project/issue comments instead of creating placeholder issues. Issue capacity is +available for durable execution lanes, but do not use that issue capacity as a +substitute for evidence-backed project status. Create or reuse exact-title +issues only when the lane needs a durable execution owner, and link those issues +to repo evidence. ## Realtime Boundary diff --git a/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md b/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md index 96f0d98b..8f04df41 100644 --- a/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md @@ -8,7 +8,7 @@ release action after the final evidence commands are rerun from the intended release commit. Source commit for the clean evidence baseline this packet extends: -`14d88e517b0c56a80c1a6392b1cde2474948d29f`. +`9819626459a662773be7d0b1c18d82c1316b8c36`. ## Current Evidence @@ -19,8 +19,8 @@ Source commit for the clean evidence baseline this packet extends: | Release approval gate | ready false, digest `ef8f49f727b7`, 4/6 checks pass; owner decisions and live URL readbacks pending | yes | | Video suite | ready true, 15/15 source assets, 13/13 suite artifacts, 12/12 publish candidates | yes | | Release surface tests | 27/27 passed after this packet was added | yes | -| Full local suite | 2560/2560 passed after PR #2011 was prepared; focused GateGuard regression passed 91/91 again on current `main` | yes | -| GitHub CI | PR #1998, PR #1999, PR #2000, PR #2001, PR #2002, PR #2004, PR #2008, post-PR #2006 `main`, PR #2009, post-PR #2009 `main`, and post-PR #2011 `main` all merged or advanced after green required checks | verify current head | +| Full local suite | 2568/2568 passed before PR #2013 merged; focused GateGuard regression passed 91/91 again before PR #2011 merged | yes | +| GitHub CI | PR #1998, PR #1999, PR #2000, PR #2001, PR #2002, PR #2004, PR #2008, post-PR #2006 `main`, PR #2009, post-PR #2009 `main`, post-PR #2011 `main`, and post-PR #2013 `main` all merged or advanced after green required checks | verify current head | ## Decision Register diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index 595e0fc1..a3e397e9 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -26,7 +26,7 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-16.md` | Current May 16/17 queue cleanup, recsys skill merge, GateGuard triage, PR #1947 supply-chain protection, AgentShield #87 plugin-cache confidence evidence, AgentShield #88 evidence-pack inspect/readback, AgentShield #89 evidence-pack fleet routing, AgentShield #90 fleet review items, AgentShield #91 policy export, AgentShield #92 policy promotion, ECC-Tools #76 fleet-summary consumption, ECC-Tools #77 hosted finding evidence paths, ECC-Tools #78 harness policy-route linking, dashboard refresh, and combined Node/Rust/release-surface gate evidence through the May 16 mirror | Must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` | May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack protection recheck, npm audit/signature checks, legacy and Linear progress routing, deterministic preview-pack smoke, operator dashboard refresh, Linear sync, and GitHub CI evidence for `27dc2918` | Superseded by the May 18 evidence snapshot; repeat from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, supply-chain recheck, AgentShield evidence mirror, Linear sync, current-head CI/security scan success for `4470e2e6`, and ITO-46 naming/plugin publication closure | Superseded by the May 19 ECC identity, video, and growth evidence snapshot | -| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, release approval gate, May 19 operator dashboard, preview-pack smoke digest `531328aaaa53`, 2560-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, PR #2004 Linear readiness evidence sync CI success, PR #2008 supply-chain evidence gate CI success, post-PR #2006 main CI success, PR #2009 project-registry hygiene CI success, post-PR #2009 main CI success, post-PR #2011 GateGuard CI success, and the May 19 Linear sync document | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | +| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, release approval gate, May 19 operator dashboard, preview-pack smoke digest `531328aaaa53`, 2568-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, PR #2004 Linear readiness evidence sync CI success, PR #2008 supply-chain evidence gate CI success, post-PR #2006 main CI success, PR #2009 project-registry hygiene CI success, post-PR #2009 main CI success, post-PR #2011 GateGuard CI success, post-PR #2013 release-approval-gate CI success, ECC-Tools #79 billing-announcement redaction hardening, JARVIS #15/#16 queue/deploy repair, and the May 19 Linear sync document | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 19 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and adds the current `$1,728/mo` to `$10,000/mo` hypergrowth, video owner-approval, and outbound-pack operating lanes | diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md index 25553703..54b04b53 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -8,9 +8,9 @@ social announcement. | Field | Evidence | | --- | --- | -| Upstream main | `14d88e517b0c56a80c1a6392b1cde2474948d29f` | +| Upstream main | `9819626459a662773be7d0b1c18d82c1316b8c36` | | Git remote | `https://github.com/affaan-m/ECC.git` | -| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, PR #2001 owner approval packet addition, PR #2002 owner approval dashboard gate refresh, PR #2004 Linear readiness evidence sync, PR #2005 post-PR #2004 evidence refresh, PR #2008 release supply-chain evidence gate fix, PR #2006 per-project Claude Code adapter, PR #2009 continuous-learning project registry hygiene fix, and PR #2011 GateGuard quoted git introspection fix | +| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, PR #2001 owner approval packet addition, PR #2002 owner approval dashboard gate refresh, PR #2004 Linear readiness evidence sync, PR #2005 post-PR #2004 evidence refresh, PR #2008 release supply-chain evidence gate fix, PR #2006 per-project Claude Code adapter, PR #2009 continuous-learning project registry hygiene fix, PR #2011 GateGuard quoted git introspection fix, and PR #2013 deterministic release approval gate | | Local status caveat | `git status --short --branch` was clean after pulling `origin/main`; generated evidence files are committed after the source snapshot they describe | The release operator must repeat all publish-facing checks from the exact final @@ -57,6 +57,18 @@ Tracked repositories in the platform audit were: | PR #2006 | Merged the `claude-project` install target for per-project Claude Code adapter support, then fixed the manifest schema enum on top of the feature branch before merge | | PR #2009 | Merged the continuous-learning project registry hygiene fix: non-git hook payloads stay global, no-remote linked worktrees migrate to the main worktree project ID, and `instinct-cli.py projects delete`, `merge`, and `gc` provide operator maintenance commands | | PR #2011 | Merged the GateGuard read-only git introspection tokenizer fix so quoted `git show` pathspecs with spaces are preserved while quoted shell separators stay outside the bypass | +| PR #2013 | Merged the deterministic `release:approval-gate` so final publication, package, plugin, video, billing, social, and outbound actions remain blocked until owner decisions and live URL readbacks are complete | + +## Post-Queue-Zero Sync - 2026-05-19 Late Pass + +| Surface | Evidence | +| --- | --- | +| ECC approval gate | PR #2013 merged as `9819626459a662773be7d0b1c18d82c1316b8c36`; GitHub Actions run `26128749863` completed successfully; `npm run release:approval-gate -- --format json` remains intentionally blocked with digest `ef8f49f727b7`, 4/6 passing, and failures only on owner decisions plus live URL readbacks | +| ECC platform audit | `node scripts/platform-audit.js --json` at `2026-05-19T22:45:15Z` returned ready true, 0 open PRs, 0 open issues, 0 discussion maintainer-touch gaps, 0 answerable Q&A gaps, and 0 dirty blockers across `affaan-m/ECC`, `affaan-m/agentshield`, `affaan-m/JARVIS`, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website` | +| ECC-Tools billing hardening | ECC-Tools PR #79 merged as `67ee247ae1b7b50ecc1261ed5d62d65cc8390da8`; preflight and live billing-announcement output now redact account login values to a stable fingerprint while preserving readiness blockers/actions; local validation passed targeted tests, full test suite 678/678, lint, typecheck, manual preflight, and `git diff --check`; post-merge main CI run `26129253509` completed successfully | +| JARVIS queue drain | JARVIS PR #15 merged the Dependabot `idna` 3.11 to 3.15 security bump as `4b3685d6ee23b4da1f1a7d22281c6b5d6c0a42c7`; PR checks and post-merge CI/CodeQL passed | +| JARVIS deploy repair | JARVIS PR #16 merged as `4369c34babd21d539c420866da51c7a8365f1c9e`; the deploy workflow no longer uses an invalid job-level `secrets.*` condition, Vercel deploy skips cleanly when secrets are absent, backend image build/push succeeds, and main CI, CodeQL, and Deploy runs `26129539376`, `26129539427`, and `26129539425` completed successfully | +| Linear roadmap sync | Linear document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f`, project comment `d42bf0e2-7a8e-4934-9f3f-e281498ee805`, and issue comments on ITO-44, ITO-50, ITO-54, ITO-56, and ITO-61 record the late-pass queue-zero, release-gate, billing-safety, and progress-sync state. | ## Release And Growth Evidence @@ -70,7 +82,8 @@ Tracked repositories in the platform audit were: | Release video suite | `npm run release:video-suite -- --format json --summary` with `ECC_VIDEO_SOURCE_ROOT` and `ECC_VIDEO_RELEASE_SUITE_ROOT` | Ready true; 15/15 source assets present; 13/13 render, timeline, caption, EDL, and segment artifacts present; 12/12 publish-candidate outputs present with zero detected black-frame segments; primary rough render self-eval passed at 144.759 seconds, 1920x1080, 1 audio stream, and 106.78 MB | | Focused post-merge regression set | `node tests/hooks/detect-project-worktree.test.js`; `node tests/hooks/observe-subdirectory-detection.test.js`; `node tests/scripts/instinct-cli-projects.test.js`; `node tests/hooks/hooks.test.js` | 10/10, 6/6, 5/5, and 237/237 passed after PR #2009 merged | | GateGuard PR #2011 regression | `node tests/hooks/gateguard-fact-force.test.js`; `npm test`; `git diff --check main...HEAD` | 91/91 passed on the PR branch; full local suite passed 2560/2560 before merge; whitespace check passed; focused GateGuard suite passed again on current `main` | -| Full local suite | `node tests/run-all.js` | 2560 passed, 0 failed | +| Release approval gate PR #2013 validation | `npm test`; `npm run lint`; `git diff --check`; `npm run preview-pack:smoke -- --format json`; `npm run release:approval-gate -- --format json` | 2568/2568 tests passed before merge; lint and whitespace passed; preview pack stayed ready with digest `531328aaaa53`; release approval gate returned the expected blocked exit with digest `ef8f49f727b7` | +| Full local suite | `node tests/run-all.js` | 2568 passed, 0 failed before PR #2013 merge | | PR #1998 CI | GitHub Actions run `26099020341` | Completed successfully for `d500de1e9f11c0446b6a1349bd98b522d31f9125`; all reported checks passed, including lint, validation, security scan, coverage, GitGuardian, CodeRabbit, Cubic, and the macOS/Ubuntu/Windows test matrix | | PR #1999 CI | GitHub Actions run `26100148726` | Completed successfully for `90584b6d5e5814bc2ad9a4cd651bebd043de989d`; lint, validation, security scan, coverage, GitGuardian, CodeRabbit, and the macOS/Ubuntu/Windows test matrix passed; Cubic completed neutral and did not block merge | | PR #2001 CI | GitHub Actions run `26102500291` | Completed successfully for `8148340ad14eb32c971346f0cb4cb9431ec0f5de`; required checks passed before merge | @@ -82,7 +95,8 @@ Tracked repositories in the platform audit were: | PR #2009 CI | GitHub Actions run `26111313938` | Completed successfully with 37 completed jobs, 0 failed jobs after replacing the brittle fake-worktree regression fixture with a real `git worktree add` setup | | Post-PR #2009 main CI | GitHub Actions run `26111946778` | Completed successfully with 37 completed jobs, 0 failed jobs, and `main` advanced to `bc519e5b8ed42f26c0a5a611756e04351c323f21` | | Post-PR #2011 main CI | GitHub Actions run `26113695068` | Completed successfully with 37 completed jobs, 0 failed jobs, and `main` advanced to `14d88e517b0c56a80c1a6392b1cde2474948d29f` | -| Linear sync | Linear document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` plus project comment `a6411e3a-8c8e-4a58-adba-687e77d4c543` | Project and issue lanes now record PR #2002 evidence, discussion #2003 routing, owner-approval dashboard gate, and In Progress status for ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56 | +| Post-PR #2013 main CI | GitHub Actions run `26128749863` | Completed successfully with `main` advanced to `9819626459a662773be7d0b1c18d82c1316b8c36` | +| Linear sync | Linear document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` plus project comment `a6411e3a-8c8e-4a58-adba-687e77d4c543`; late-pass document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f` plus project comment `d42bf0e2-7a8e-4934-9f3f-e281498ee805` | Project and issue lanes record PR #2002 evidence, discussion #2003 routing, owner-approval dashboard gate, and In Progress status for ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56; the late-pass sync attaches PR #2013, ECC-Tools #79, and JARVIS #15/#16 evidence to ITO-44, ITO-50, ITO-54, ITO-56, and ITO-61 | | Public-path sanitization | `node scripts/ci/validate-no-personal-paths.js` through local suite and CI | Passed | | Markdown and whitespace | `markdownlint` focused release docs plus `git diff --check` before PR #1999 | Passed | @@ -97,7 +111,7 @@ Tracked repositories in the platform audit were: | Owner approval proof | `owner-approval-packet-2026-05-19.md` centralizes release, package, plugin, video, billing, social, and outbound decision gates | | Business baseline | Hypergrowth command center and partner pack use `$1,728/mo` current MRR, `$10,000/mo` target MRR, and `$8,272/mo` gap | | Operator dashboard | `operator-readiness-dashboard-2026-05-19.md` pulls the growth baseline into the same queue, publication, video, outbound, AgentShield, ECC Tools, Linear, and supply-chain control surface | -| Linear progress proof | Linear project document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` mirrors the post-PR #2002 state and records active lanes for launch materials, AgentShield, ECC Tools deep analysis, observability, and final release publication | +| Linear progress proof | Linear project document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` mirrors the post-PR #2002 state and records active lanes for launch materials, AgentShield, ECC Tools deep analysis, observability, and final release publication; Linear document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f` adds the PR #2013 approval gate, ECC-Tools #79 redaction hardening, and JARVIS #15/#16 queue/deploy repair evidence | ## Current Publication Blockers @@ -122,10 +136,12 @@ Tracked repositories in the platform audit were: The tracked public PR queue, issue queue, discussion queue, canonical ECC identity, release video suite, preview pack, growth outreach packet, per-project -Claude Code adapter surface, continuous-learning project registry hygiene, and -GateGuard quoted git introspection fix are current on May 19, 2026 for `main` -through `14d88e517b0c56a80c1a6392b1cde2474948d29f`. The remaining video work is -owner approval, upload, and public URL attachment, not render or QA production. +Claude Code adapter surface, continuous-learning project registry hygiene, +GateGuard quoted git introspection fix, deterministic release approval gate, +ECC-Tools billing-announcement redaction hardening, and JARVIS security/deploy +queue repairs are current on May 19, 2026 for `main` through +`9819626459a662773be7d0b1c18d82c1316b8c36`. The remaining video work is owner +approval, upload, and public URL attachment, not render or QA production. This improves publication readiness but does not replace the approval-gated release, package, plugin, billing, Discord, and announcement steps in diff --git a/docs/releases/2.0.0-rc.1/publication-readiness.md b/docs/releases/2.0.0-rc.1/publication-readiness.md index 88121da7..1a57e3be 100644 --- a/docs/releases/2.0.0-rc.1/publication-readiness.md +++ b/docs/releases/2.0.0-rc.1/publication-readiness.md @@ -109,7 +109,7 @@ Record the exact commit SHA and command output before any publication action: | Observability readiness | `npm run observability:ready` | 21/21 passing | Current release gate: 21/21, ready true | | Release safety gate | `npm run observability:ready -- --format json` | Release Safety category passing with publication readiness, supply-chain, workflow security, package surface, and release-surface evidence | Current release gate keeps Release Safety passing at 3/3; repeat the JSON gate from the exact final release commit | | Supply-chain verification | `npm audit --audit-level=moderate`; `npm audit signatures`; `yarn install --immutable --mode=skip-build`; `cd ecc2 && cargo audit -q`; Dependabot alerts; GitGuardian Security Checks | 0 vulnerabilities/alerts, registry signatures verified, package-manager locks accepted, GitGuardian clean | Current supply-chain branch: `npm audit` found 0 vulnerabilities; `npm audit signatures` verified 254 registry signatures and 30 attestations; Yarn immutable install accepted the lock after pinning `@types/node@25.7.0` and moving `brace-expansion` to `5.0.6` / `1.1.14`; PR #2008 CI `26108473648`, post-PR #2006 main CI `26109953093`, PR #2009 CI `26111313938`, and post-PR #2009 main CI `26111946778` completed with 0 failures | -| Root suite | `node tests/run-all.js` | 0 failures | Current May 19 local suite: 2560 passed, 0 failed; post-PR #2009 focused regressions also passed for worktree detection, observe subdirectory/global fallback, project maintenance CLI, and the hooks suite | +| Root suite | `node tests/run-all.js` | 0 failures | Current May 19 local suite: 2568 passed, 0 failed before PR #2013 merged; post-PR #2009 focused regressions also passed for worktree detection, observe subdirectory/global fallback, project maintenance CLI, and the hooks suite | | Markdown lint | `npx markdownlint-cli '**/*.md' --ignore node_modules` | 0 failures | Current release gate: focused lint passed for `publication-readiness.md`, `publication-evidence-2026-05-19.md`, and `docs/ECC-2.0-GA-ROADMAP.md` | | Package surface | `node tests/scripts/npm-publish-surface.test.js` | 0 failures; no Python bytecode in npm tarball | Current release gate: 2/2 passed | | Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | Current release gate: 27/27 passed after refreshing the discussion-count assertion to the post-PR #2005 baseline | diff --git a/scripts/platform-audit.js b/scripts/platform-audit.js index e5a04d5c..6dc3731a 100644 --- a/scripts/platform-audit.js +++ b/scripts/platform-audit.js @@ -472,7 +472,7 @@ function buildLocalEvidenceChecks(rootDir) { ), buildCheck( 'release-evidence-current', - includesAll(evidence, ['Release video suite', 'growth outreach', 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', '2560 passed']) ? 'pass' : 'fail', + includesAll(evidence, ['Release video suite', 'growth outreach', 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', '2568 passed']) ? 'pass' : 'fail', 'rc.1 evidence includes current release, video, growth, and CI artifacts', { path: 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md' } ), diff --git a/tests/docs/ecc2-release-surface.test.js b/tests/docs/ecc2-release-surface.test.js index a0b59abd..efd72830 100644 --- a/tests/docs/ecc2-release-surface.test.js +++ b/tests/docs/ecc2-release-surface.test.js @@ -259,7 +259,7 @@ test('GA roadmap mirrors the current May 19 release evidence', () => { for (const marker of [ 'owner-approval-packet-2026-05-19.md', 'preview-pack smoke digest `531328aaaa53`', - 'local 2560-test suite', + 'local 2568-test suite', 'PR #2001', 'GitHub Actions run `26102500291`', 'PR #2002', diff --git a/tests/scripts/operator-readiness-dashboard.test.js b/tests/scripts/operator-readiness-dashboard.test.js index 77a0f5eb..d70f03ea 100644 --- a/tests/scripts/operator-readiness-dashboard.test.js +++ b/tests/scripts/operator-readiness-dashboard.test.js @@ -190,7 +190,7 @@ function seedRepo(rootDir, overrides = {}) { 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', - '2560 passed', + '2568 passed', 'Business baseline', '$1,728/mo', '$8,272/mo' @@ -443,7 +443,7 @@ function runTests() { 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', - '2560 passed', + '2568 passed', 'Business baseline', '$1,728/mo', '$8,272/mo', diff --git a/tests/scripts/platform-audit.test.js b/tests/scripts/platform-audit.test.js index 3f9d514e..9451bb9f 100644 --- a/tests/scripts/platform-audit.test.js +++ b/tests/scripts/platform-audit.test.js @@ -68,7 +68,7 @@ function seedRepo(rootDir, overrides = {}) { 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', - '2560 passed' + '2568 passed' ].join('\n'), 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md': [ 'This dashboard is generated by `npm run operator:dashboard`', @@ -238,7 +238,7 @@ function runTests() { 'Operator dashboard', 'GitGuardian', 'macOS/Ubuntu/Windows test matrix', - '2546 passed' + '2560 passed' ].join('\n') }); From 3cb8c48e74d7ee9883fd2e6d94d8e5aea7421d8c Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 20:23:53 -0400 Subject: [PATCH 55/61] docs: sync May 20 ECC Tools evidence --- docs/ECC-2.0-GA-ROADMAP.md | 92 ++++++++++++++++++- .../2.0.0-rc.1/preview-pack-manifest.md | 2 +- .../publication-evidence-2026-05-19.md | 22 ++++- 3 files changed, 108 insertions(+), 8 deletions(-) diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index 589847c7..4790ae89 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -17,6 +17,35 @@ The May 19 release/growth execution map lives at It is the operator surface for the final ECC 2.0 repo identity, video suite, partner/sponsor funnel, consulting/talk funnel, and social launch plan. +## 2026-05-20 Delta + +- The tracked platform audit is still green on May 20 with 0 open PRs, + 0 open issues, 0 discussion maintainer-touch gaps, 0 answerable Q&A gaps, + 0 conflicting PRs, and 0 blocking dirty files across `affaan-m/ECC`, + `affaan-m/agentshield`, `affaan-m/JARVIS`, `ECC-Tools/ECC-Tools`, and + `ECC-Tools/ECC-website`. +- The new #2015 setup-location Q&A was answered and marked accepted. The + answer keeps install guidance conservative: do not install into `C:\`; use a + normal workspace, install the `ecc@ecc` Claude plugin once, copy only needed + rule folders when using manual rules, and avoid stacking plugin plus full + manual install. +- ECC-Tools PRs #80-#88 landed the next hosted-platform batch: runtime + receipts now require failure reasons; AgentShield fleet approval IDs survive + hosted security review and render into comments/check-runs; Linear follow-up + sync reuses deterministic external IDs; hosted AgentShield remediation items + sync to Linear; hosted job observability events are emitted for queued, + completed, blocked, failed, and budget-blocked states; and both hosted job + status comments and hosted depth-plan check-runs read back recent + observability/budget events. PR #88 adds the authenticated observability API + readback for operator dashboards and production smoke tests. +- Linear ITO-54 and the ECC Platform Roadmap now have the May 20 ECC-Tools + hosted observability update comments + `74dcc101-3be5-4173-be13-62b80d54f569` and + `348ea8f5-2a2d-46d9-a0fe-ed99653e7fe5`, after earlier PR #84/#85 comments + recorded remediation sync and hosted observability events. PR #88 is recorded + in Linear comments `291e2a4b-06e3-4672-a057-cdb141478161` and + `b2d35de0-ca49-44cb-982a-ddec229e7691`. + ## 2026-05-19 Delta - The public repo identity is now `affaan-m/ECC`; release, package, plugin, @@ -38,7 +67,7 @@ partner/sponsor funnel, consulting/talk funnel, and social launch plan. ## Current Evidence -As of 2026-05-19: +As of 2026-05-20: - GitHub queues are clean across `affaan-m/ECC`, `affaan-m/agentshield`, `affaan-m/JARVIS`, `ECC-Tools/ECC-Tools`, and @@ -56,9 +85,10 @@ As of 2026-05-19: now at 0 open PRs and 0 open issues by live `gh search`. Archived repos touched during closure were restored to archived state. - GitHub discussions are current across those tracked repos: - `affaan-m/ECC` has 59 total discussions and 0 without + `affaan-m/ECC` has 60 total discussions and 0 without maintainer touch after the May 19 #2003 AURA integration proposal was routed - as an external-adapter proposal, not core wallet/escrow coupling; AgentShield, + as an external-adapter proposal, not core wallet/escrow coupling, and the + May 20 #2015 setup-location Q&A was answered and accepted; AgentShield, JARVIS, ECC Tools, and the ECC Tools website have discussions disabled or 0 total discussions. `docs/architecture/discussion-response-playbook.md` now supplies the ITO-59 response categories, public templates, security-escalation @@ -108,6 +138,16 @@ As of 2026-05-19: comment `d42bf0e2-7a8e-4934-9f3f-e281498ee805`. The supply-chain gate now also records the `@types/node@25.7.0` pin and `brace-expansion` lock refresh needed for current npm audit/signature verification. +- The May 20 ECC-Tools hosted-platform pass extends that evidence with PR #80 + through PR #88, all merged after green GitHub Verify/Security Audit/Workers + Builds checks. Local validation for the final depth-plan observability slice + passed the focused hosted depth-plan route test, the full route suite + (89/89), typecheck, lint, full ECC-Tools Vitest suite (683/683), and + `git diff --check`. PR #88 additionally exposes authenticated hosted + observability readback at `/api/analysis/observability` for operator + dashboards and production smoke tests; its local verification passed + typecheck, lint, the full ECC-Tools Vitest suite (686/686), and + `git diff --check`. - `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` regenerates the ITO-44 prompt-to-artifact dashboard from live platform audit evidence: PR queue, issue queue, discussion queue, local worktree gate, @@ -662,6 +702,44 @@ As of 2026-05-19: fleet summaries are collected as harness evidence, target paths are mapped to Claude, Codex, OpenCode, MCP, plugin, and cross-harness owners, and routed findings carry source evidence paths for operator review. +- ECC-Tools PR #79 merged as `67ee247ae1b7b50ecc1261ed5d62d65cc8390da8` + and redacts billing announcement gate account output: the billing preflight + and live readback now print stable account fingerprints and sanitized + readiness booleans instead of raw account logins or KV key names. +- ECC-Tools PR #80 merged as `4efc8cc858022f84c844690f3298633b081c4398` + and requires runtime receipt failure reasons before harness runtime receipts + can count as hosted observability evidence. +- ECC-Tools PR #81 merged as `1fbf635f492284f75ba7166c029c39eb8cc15794` + and preserves AgentShield fleet approval IDs through hosted security review + so policy-promotion follow-ups keep owner-review identity stable. +- ECC-Tools PR #82 merged as `7a7b4d096a176ae80b3a2076c09d45601e36013a` + and renders AgentShield fleet approval IDs in hosted comments and check-runs, + giving operators a direct bridge from hosted security review back to + AgentShield policy-promotion review items. +- ECC-Tools PR #83 merged as `b6b107f33961bef18a85fb619f3a976eb5d752dd` + and makes Linear follow-up sync reuse deterministic external IDs before title + fallback, preventing duplicate deferred backlog issues during repeated + `/ecc-tools followups sync-linear` runs. +- ECC-Tools PR #84 merged as `73bac7058071c55cb30c6b8ac6db779b3660c02c` + and syncs hosted AgentShield remediation items to Linear when the workspace + token/team are configured; hosted result comments now include created/reused + Linear remediation links. +- ECC-Tools PR #85 merged as `1637e0f2bfa0a889387f2c20675680ccc5528123` + and emits hosted job observability events for queued, completed, blocked, + failed, and budget-blocked states into `ANALYSIS_CACHE`, including budget + snapshots and result counts. +- ECC-Tools PR #86 merged as `5a9e94d3ff860307c3e7fd9fd065f0de2bd633dd` + and reads recent hosted observability events in + `/ecc-tools analyze --job status`, so status comments show budget snapshots, + blocked results, and budget-blocked outcomes alongside latest job runs. +- ECC-Tools PR #87 merged as `508fbc02b63cf1fcb5af2f3624608fa66e53b5d4` + and adds the same hosted observability readback to hosted depth-plan + check-runs, keeping the PR check surface aligned with status comments. +- ECC-Tools PR #88 merged as `c836ac3fb24ed7e2ae38cd61e41c9651ac9c00f8` + and exposes authenticated hosted observability API readback at + `/api/analysis/observability`, summarizing recent hosted events by event type + and job while skipping malformed stale KV records. The deployment runbook now + includes the production smoke command for operator/dashboard readback. - AgentShield PR #90 merged as `6d1c57c92000541d65a3b6bc366f0322d7d0dacc` and adds durable fleet `reviewItems`: `agentshield evidence-pack fleet --json` now returns owner-ready review items with route, severity, repository/target @@ -1062,6 +1140,14 @@ Acceptance: ECC-Tools commit `632e059` adds sanitized target-account readback, so the final operator gate should verify the exact Marketplace test account without printing its login or raw KV key names. + ECC-Tools PR #79 redacts the billing announcement gate account output; + PR #80 requires failure reasons in runtime receipts; PRs #81/#82 preserve + and render AgentShield fleet approval IDs; PR #83 makes Linear follow-up + sync idempotent by external ID; PR #84 syncs hosted AgentShield + remediation items into Linear; PR #85 emits hosted job observability events + including budget-blocked outcomes; PRs #86/#87 read those events back into + hosted status comments and hosted depth-plan check-runs; and PR #88 exposes + authenticated hosted observability API readback for operator dashboards. 2. Run `npm run billing:announcement-gate -- --preflight --account `, then run the same command without `--preflight` against a Marketplace-managed test account and require `announcementGate.ready === diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index a3e397e9..e423d3c4 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -26,7 +26,7 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-16.md` | Current May 16/17 queue cleanup, recsys skill merge, GateGuard triage, PR #1947 supply-chain protection, AgentShield #87 plugin-cache confidence evidence, AgentShield #88 evidence-pack inspect/readback, AgentShield #89 evidence-pack fleet routing, AgentShield #90 fleet review items, AgentShield #91 policy export, AgentShield #92 policy promotion, ECC-Tools #76 fleet-summary consumption, ECC-Tools #77 hosted finding evidence paths, ECC-Tools #78 harness policy-route linking, dashboard refresh, and combined Node/Rust/release-surface gate evidence through the May 16 mirror | Must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` | May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack protection recheck, npm audit/signature checks, legacy and Linear progress routing, deterministic preview-pack smoke, operator dashboard refresh, Linear sync, and GitHub CI evidence for `27dc2918` | Superseded by the May 18 evidence snapshot; repeat from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, supply-chain recheck, AgentShield evidence mirror, Linear sync, current-head CI/security scan success for `4470e2e6`, and ITO-46 naming/plugin publication closure | Superseded by the May 19 ECC identity, video, and growth evidence snapshot | -| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, release approval gate, May 19 operator dashboard, preview-pack smoke digest `531328aaaa53`, 2568-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, PR #2004 Linear readiness evidence sync CI success, PR #2008 supply-chain evidence gate CI success, post-PR #2006 main CI success, PR #2009 project-registry hygiene CI success, post-PR #2009 main CI success, post-PR #2011 GateGuard CI success, post-PR #2013 release-approval-gate CI success, ECC-Tools #79 billing-announcement redaction hardening, JARVIS #15/#16 queue/deploy repair, and the May 19 Linear sync document | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | +| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19/20 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, release approval gate, May 19 operator dashboard, preview-pack smoke digest `531328aaaa53`, 2568-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, PR #2004 Linear readiness evidence sync CI success, PR #2008 supply-chain evidence gate CI success, post-PR #2006 main CI success, PR #2009 project-registry hygiene CI success, post-PR #2009 main CI success, post-PR #2011 GateGuard CI success, post-PR #2013 release-approval-gate CI success, ECC-Tools #79 billing-announcement redaction hardening, ECC-Tools #80-#88 runtime-receipt, AgentShield approval-ID, Linear sync, remediation sync, hosted observability event/status/depth-plan/API readback, JARVIS #15/#16 queue/deploy repair, and the May 19/20 Linear sync comments | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 19 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and adds the current `$1,728/mo` to `$10,000/mo` hypergrowth, video owner-approval, and outbound-pack operating lanes | diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md index 54b04b53..05aa2bc9 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -70,6 +70,18 @@ Tracked repositories in the platform audit were: | JARVIS deploy repair | JARVIS PR #16 merged as `4369c34babd21d539c420866da51c7a8365f1c9e`; the deploy workflow no longer uses an invalid job-level `secrets.*` condition, Vercel deploy skips cleanly when secrets are absent, backend image build/push succeeds, and main CI, CodeQL, and Deploy runs `26129539376`, `26129539427`, and `26129539425` completed successfully | | Linear roadmap sync | Linear document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f`, project comment `d42bf0e2-7a8e-4934-9f3f-e281498ee805`, and issue comments on ITO-44, ITO-50, ITO-54, ITO-56, and ITO-61 record the late-pass queue-zero, release-gate, billing-safety, and progress-sync state. | +## May 20 Hosted Observability Sync + +| Surface | Evidence | +| --- | --- | +| ECC discussion queue | Discussion #2015 was answered and marked accepted with conservative setup guidance: do not install in `C:\`; use a normal workspace; install `ecc@ecc` once through the Claude plugin marketplace; copy only needed rule folders when using manual rules; do not stack plugin plus full manual install. | +| ECC platform audit | `node scripts/platform-audit.js --json` at `2026-05-20T00:25:38Z` returned ready true with 0 open PRs, 0 open issues, 0 discussion maintainer-touch gaps, 0 answerable Q&A gaps, 0 conflicting PRs, and 0 dirty blockers across `affaan-m/ECC`, `affaan-m/agentshield`, `affaan-m/JARVIS`, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website`. | +| ECC-Tools #80/#81/#82 | PR #80 merged runtime-receipt failure-reason enforcement as `4efc8cc858022f84c844690f3298633b081c4398`; PR #81 preserved AgentShield fleet approval IDs as `1fbf635f492284f75ba7166c029c39eb8cc15794`; PR #82 rendered those approval IDs in hosted security review comments/check-runs as `7a7b4d096a176ae80b3a2076c09d45601e36013a`. | +| ECC-Tools #83/#84 | PR #83 merged deterministic Linear external-ID reuse for deferred follow-ups as `b6b107f33961bef18a85fb619f3a976eb5d752dd`; PR #84 merged hosted AgentShield remediation sync to Linear as `73bac7058071c55cb30c6b8ac6db779b3660c02c`. Local validation covered focused route/client tests, typecheck, lint, full ECC-Tools test suite, and whitespace checks before merge; GitHub Verify, Security Audit, and Workers Builds passed. | +| ECC-Tools #85/#86/#87 | PR #85 merged hosted job observability events as `1637e0f2bfa0a889387f2c20675680ccc5528123`; PR #86 merged hosted status observability readback as `5a9e94d3ff860307c3e7fd9fd065f0de2bd633dd`; PR #87 merged hosted depth-plan observability readback as `508fbc02b63cf1fcb5af2f3624608fa66e53b5d4`. Local validation for the final depth-plan readback slice passed the focused hosted depth-plan route test, full route suite (89/89), typecheck, lint, full ECC-Tools Vitest suite (683/683), and `git diff --check`; GitHub Verify, Security Audit, and Workers Builds passed before merge. | +| ECC-Tools #88 | PR #88 merged authenticated hosted observability API readback as `c836ac3fb24ed7e2ae38cd61e41c9651ac9c00f8`. `GET /api/analysis/observability` now summarizes hosted events by event type and job for operator/dashboard readback, skips malformed stale KV records, and the deployment runbook includes the production smoke command. Local verification passed typecheck, lint, full ECC-Tools Vitest suite (686/686), and `git diff --check`; GitHub Verify, Security Audit, and Workers Builds passed before merge. | +| Linear roadmap sync | Linear ITO-54 comment `74dcc101-3be5-4173-be13-62b80d54f569` and ECC Platform Roadmap project comment `348ea8f5-2a2d-46d9-a0fe-ed99653e7fe5` record the May 20 hosted observability status/depth-plan readback batch; Linear comments `291e2a4b-06e3-4672-a057-cdb141478161` and `b2d35de0-ca49-44cb-982a-ddec229e7691` add the #88 observability API readback; earlier comments on ITO-54, ITO-48, and the project record the #84 hosted remediation sync and #85 hosted observability event emission batches. | + ## Release And Growth Evidence | Gate | Command | Result | @@ -111,7 +123,7 @@ Tracked repositories in the platform audit were: | Owner approval proof | `owner-approval-packet-2026-05-19.md` centralizes release, package, plugin, video, billing, social, and outbound decision gates | | Business baseline | Hypergrowth command center and partner pack use `$1,728/mo` current MRR, `$10,000/mo` target MRR, and `$8,272/mo` gap | | Operator dashboard | `operator-readiness-dashboard-2026-05-19.md` pulls the growth baseline into the same queue, publication, video, outbound, AgentShield, ECC Tools, Linear, and supply-chain control surface | -| Linear progress proof | Linear project document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` mirrors the post-PR #2002 state and records active lanes for launch materials, AgentShield, ECC Tools deep analysis, observability, and final release publication; Linear document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f` adds the PR #2013 approval gate, ECC-Tools #79 redaction hardening, and JARVIS #15/#16 queue/deploy repair evidence | +| Linear progress proof | Linear project document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` mirrors the post-PR #2002 state and records active lanes for launch materials, AgentShield, ECC Tools deep analysis, observability, and final release publication; Linear document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f` adds the PR #2013 approval gate, ECC-Tools #79 redaction hardening, and JARVIS #15/#16 queue/deploy repair evidence; May 20 Linear comments `74dcc101-3be5-4173-be13-62b80d54f569`, `348ea8f5-2a2d-46d9-a0fe-ed99653e7fe5`, `291e2a4b-06e3-4672-a057-cdb141478161`, and `b2d35de0-ca49-44cb-982a-ddec229e7691` add ECC-Tools #86/#87/#88 hosted observability readback evidence to ITO-54 and the project | ## Current Publication Blockers @@ -138,9 +150,11 @@ The tracked public PR queue, issue queue, discussion queue, canonical ECC identity, release video suite, preview pack, growth outreach packet, per-project Claude Code adapter surface, continuous-learning project registry hygiene, GateGuard quoted git introspection fix, deterministic release approval gate, -ECC-Tools billing-announcement redaction hardening, and JARVIS security/deploy -queue repairs are current on May 19, 2026 for `main` through -`9819626459a662773be7d0b1c18d82c1316b8c36`. The remaining video work is owner +ECC-Tools billing-announcement redaction hardening, ECC-Tools hosted +observability readback, and JARVIS security/deploy queue repairs are current on +May 20, 2026 for ECC `main` through +`b3c015c7443c6617f897654613c21eddc3d25764` plus ECC-Tools `main` through +`c836ac3fb24ed7e2ae38cd61e41c9651ac9c00f8`. The remaining video work is owner approval, upload, and public URL attachment, not render or QA production. This improves publication readiness but does not replace the approval-gated From 906e06406e95742944ccb05065f95a7e4dd4a036 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 20:44:51 -0400 Subject: [PATCH 56/61] docs: sync AgentShield adapter evidence --- docs/ECC-2.0-GA-ROADMAP.md | 24 ++++++++++++++++--- .../2.0.0-rc.1/preview-pack-manifest.md | 2 +- .../publication-evidence-2026-05-19.md | 21 +++++++++------- .../supply-chain-incident-response.md | 7 +++--- 4 files changed, 38 insertions(+), 16 deletions(-) diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index 4790ae89..07647242 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -38,13 +38,19 @@ partner/sponsor funnel, consulting/talk funnel, and social launch plan. status comments and hosted depth-plan check-runs read back recent observability/budget events. PR #88 adds the authenticated observability API readback for operator dashboards and production smoke tests. +- AgentShield PR #94 landed the next cross-harness adapter slice: Zed and + VS Code are first-class adapter detections, `.zed/settings.json` and + `.zed/tasks.json` are discoverable scan inputs, and `.zed/setup.mjs` now + trips the same AI-tool persistence IOC rule as `.vscode/setup.mjs`. - Linear ITO-54 and the ECC Platform Roadmap now have the May 20 ECC-Tools hosted observability update comments `74dcc101-3be5-4173-be13-62b80d54f569` and `348ea8f5-2a2d-46d9-a0fe-ed99653e7fe5`, after earlier PR #84/#85 comments recorded remediation sync and hosted observability events. PR #88 is recorded in Linear comments `291e2a4b-06e3-4672-a057-cdb141478161` and - `b2d35de0-ca49-44cb-982a-ddec229e7691`. + `b2d35de0-ca49-44cb-982a-ddec229e7691`; AgentShield #94 is recorded in + ITO-49 comment `faed69dd-35f5-469d-acb5-ddde6a70d6a1` and project comment + `70187c1e-d481-4181-b418-09bd65d54b5e`. ## 2026-05-19 Delta @@ -148,6 +154,12 @@ As of 2026-05-20: dashboards and production smoke tests; its local verification passed typecheck, lint, the full ECC-Tools Vitest suite (686/686), and `git diff --check`. +- AgentShield PR #94 adds Zed and VS Code to the first-class adapter registry + after local verification with typecheck, lint, the focused core scanner/rule + tests, full `npm test` (1822 tests), `npm run build`, and `git diff --check`. + GitHub checks passed across GitGuardian, scan suite, self-scan, + self-scan examples, Node 18/20/22 CI, CodeRabbit, and Cubic after rerunning a + transient GitHub artifact-upload failure. - `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` regenerates the ITO-44 prompt-to-artifact dashboard from live platform audit evidence: PR queue, issue queue, discussion queue, local worktree gate, @@ -756,6 +768,12 @@ As of 2026-05-20: policy SHA-256 digest, rejects tampered policy JSON, requires explicit pack selection for multi-pack manifests, and supports dry-run JSON review before writing the active `.agentshield/policy.json`. +- AgentShield PR #94 merged as `4caee27acfadb50a4cd024e738b5c3cbd4b0bb03` + and adds editor-native adapter coverage for Zed and VS Code. Zed + `.zed/settings.json`, `.zed/tasks.json`, and `.zed` hook-code files are now + scan inputs, adapter reports expose Zed MCP/tool-permission/task metadata and + VS Code workspace/task/extension metadata, and `.zed/setup.mjs` is covered by + the AI-tool persistence IOC rule. - AgentShield main commit `87aec47fb55d04ea28d494852d4f664c268c5601` extends policy promotion with durable `reviewItems` for manifest digest evidence, policy-owner approval, protected rollout PR handoff, and runtime @@ -850,7 +868,7 @@ is not complete unless the evidence column exists and has been freshly verified. | Naming and rename readiness | Naming matrix across package/plugin/docs/social surfaces | `docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md` records current package, repo, Claude plugin, Codex plugin, OpenCode, and npm availability evidence | Complete for rc.1; post-rc rename remains future work | | Claude and Codex plugin publication | Contact/submission path with required artifacts and status | Publication readiness, naming matrix, and May 12 dry-run evidence document plugin validation, clean-checkout Claude tag/install smoke, and Codex marketplace CLI shape | Needs explicit approval for real tag/push and marketplace submission | | Articles, tweets, and announcements | X thread, LinkedIn copy, GitHub release copy, push checklist, partner/sponsor/talk pack | Draft launch collateral and approval-gated outreach copy exist under rc.1 release docs | Needs URL-backed refresh and human approval before posting or sending | -| AgentShield enterprise iteration | Policy gates, SARIF, packs, provenance, corpus, HTML reports, exception lifecycle audit, baseline drift Action/CLI surfaces, evidence-pack redaction, harness adapter registry, enterprise research roadmap, supply-chain hardened release path, CI-safe baseline fingerprints, corpus accuracy recommendations, remediation workflow phases, env proxy hijack corpus coverage, Mini Shai-Hulud full-campaign package IOCs, CI-provenance evidence packs, plugin-cache runtime-confidence triage, evidence-pack consumer readback, fleet-level evidence-pack routing, fleet review items, fleet review ticket payloads, checksum-backed policy export, checksum-verified policy promotion, policy promotion review items, package-manager hardening drift detection, npm age-gate guidance correction, workflow action-runtime pin refresh, package-manager hardening Action outputs, policy-promotion Action outputs, ECC-Tools hosted consumption of promotion Action outputs, ECC-Tools operator-visible promotion output values, and ECC-Tools hosted promotion judge audit traces | PRs #53, #55-#64, #67-#69, and #78-#92 landed with test evidence, ECC-Tools #76 consumes the fleet-summary output in hosted security review, #77 surfaces source evidence paths in hosted finding output, and #78 links fleet routes to harness owner review; AgentShield #91 adds `agentshield policy export` bundles for branch-protection review and downstream promotion; AgentShield #92 adds `agentshield policy promote` with digest verification, tamper rejection, explicit pack selection, dry-run review, and JSON output before writing active policy; AgentShield commit `87aec47` adds `reviewItems` for digest evidence, owner review, protected rollout PR handoff, and runtime smoke testing with green local and remote CI; AgentShield commit `28d08c7` adds package-manager hardening drift detection for plaintext registry credentials, lifecycle-script enablement, and weak pnpm/Yarn release-age cooldowns with green local and remote CI; AgentShield commit `659f569` refreshes all workflow action runtime pins to SHA-pinned checkout v6.0.2 and setup-node v6.4.0 with green remote CI and no remaining action-runtime deprecation annotation; AgentShield commit `ee585cd` corrects npm release-age guidance by flagging unsupported npm age keys and keeping enforceable cooldown findings on pnpm/Yarn with green local and remote CI; AgentShield commit `1124535` exposes package-manager hardening status/count outputs and a redacted job-summary section for registry credentials, lifecycle scripts, and release-age gates with green local and remote CI; AgentShield commit `1593925` exposes policy-promotion status/count/digest outputs plus job-summary review items for owner approval, protected rollout, and runtime smoke, and marks runtime smoke verified when the same Action job scans with the promoted policy; AgentShield commit `840952a` adds Linear/operator-ready fleet review ticket payloads and expands current Mini Shai-Hulud IOC breadcrumbs with green local and remote CI; ECC-Tools commit `8658951` routes those policy-promotion Action outputs into hosted security review findings and Hosted Promotion Readiness scoring; ECC-Tools commit `16c537f` renders policy-promotion status, pack, review item count, action-required count, and digest in hosted security job comments/check-runs; ECC-Tools commit `05d4e82` renders hosted promotion judge request fingerprints and allowed-citation counts without raw provider output; native PDF export deferred in favor of self-contained HTML plus print-to-PDF until explicit enterprise demand appears; `docs/architecture/agentshield-enterprise-research-roadmap.md` now has baseline drift, evidence-pack bundle, redaction, adapter-registry, supply-chain hardening, hashed baseline fingerprints, corpus accuracy recommendation, remediation workflow, env proxy hijack corpus, Mini Shai-Hulud full-campaign package-table, `ci-context.json` provenance, `plugin-cache` confidence, `evidence-pack inspect` readback, `evidence-pack fleet` routing, fleet `reviewItems`, fleet review ticket payloads, policy export, policy promotion, policy promotion `reviewItems`, package-manager hardening Action outputs, policy-promotion Action outputs, hosted consumption of promotion Action outputs, operator-visible promotion output values, and hosted promotion judge audit traces landed | Next workflow automation should deepen live operator approval/readback after Marketplace/payment gates | +| AgentShield enterprise iteration | Policy gates, SARIF, packs, provenance, corpus, HTML reports, exception lifecycle audit, baseline drift Action/CLI surfaces, evidence-pack redaction, harness adapter registry, editor-native Zed/VS Code adapter coverage, enterprise research roadmap, supply-chain hardened release path, CI-safe baseline fingerprints, corpus accuracy recommendations, remediation workflow phases, env proxy hijack corpus coverage, Mini Shai-Hulud full-campaign package IOCs, CI-provenance evidence packs, plugin-cache runtime-confidence triage, evidence-pack consumer readback, fleet-level evidence-pack routing, fleet review items, fleet review ticket payloads, checksum-backed policy export, checksum-verified policy promotion, policy promotion review items, package-manager hardening drift detection, npm age-gate guidance correction, workflow action-runtime pin refresh, package-manager hardening Action outputs, policy-promotion Action outputs, ECC-Tools hosted consumption of promotion Action outputs, ECC-Tools operator-visible promotion output values, and ECC-Tools hosted promotion judge audit traces | PRs #53, #55-#64, #67-#69, #78-#92, and #94 landed with test evidence, ECC-Tools #76 consumes the fleet-summary output in hosted security review, #77 surfaces source evidence paths in hosted finding output, and #78 links fleet routes to harness owner review; AgentShield #91 adds `agentshield policy export` bundles for branch-protection review and downstream promotion; AgentShield #92 adds `agentshield policy promote` with digest verification, tamper rejection, explicit pack selection, dry-run review, and JSON output before writing active policy; AgentShield #94 adds Zed/VS Code adapter detection, `.zed/settings.json` and `.zed/tasks.json` scan discovery, and `.zed/setup.mjs` AI-tool persistence IOC coverage; AgentShield commit `87aec47` adds `reviewItems` for digest evidence, owner review, protected rollout PR handoff, and runtime smoke testing with green local and remote CI; AgentShield commit `28d08c7` adds package-manager hardening drift detection for plaintext registry credentials, lifecycle-script enablement, and weak pnpm/Yarn release-age cooldowns with green local and remote CI; AgentShield commit `659f569` refreshes all workflow action runtime pins to SHA-pinned checkout v6.0.2 and setup-node v6.4.0 with green remote CI and no remaining action-runtime deprecation annotation; AgentShield commit `ee585cd` corrects npm release-age guidance by flagging unsupported npm age keys and keeping enforceable cooldown findings on pnpm/Yarn with green local and remote CI; AgentShield commit `1124535` exposes package-manager hardening status/count outputs and a redacted job-summary section for registry credentials, lifecycle scripts, and release-age gates with green local and remote CI; AgentShield commit `1593925` exposes policy-promotion status/count/digest outputs plus job-summary review items for owner approval, protected rollout, and runtime smoke, and marks runtime smoke verified when the same Action job scans with the promoted policy; AgentShield commit `840952a` adds Linear/operator-ready fleet review ticket payloads and expands current Mini Shai-Hulud IOC breadcrumbs with green local and remote CI; ECC-Tools commit `8658951` routes those policy-promotion Action outputs into hosted security review findings and Hosted Promotion Readiness scoring; ECC-Tools commit `16c537f` renders policy-promotion status, pack, review item count, action-required count, and digest in hosted security job comments/check-runs; ECC-Tools commit `05d4e82` renders hosted promotion judge request fingerprints and allowed-citation counts without raw provider output; native PDF export deferred in favor of self-contained HTML plus print-to-PDF until explicit enterprise demand appears; `docs/architecture/agentshield-enterprise-research-roadmap.md` now has baseline drift, evidence-pack bundle, redaction, adapter-registry, supply-chain hardening, hashed baseline fingerprints, corpus accuracy recommendation, remediation workflow, env proxy hijack corpus, Mini Shai-Hulud full-campaign package-table, `ci-context.json` provenance, `plugin-cache` confidence, `evidence-pack inspect` readback, `evidence-pack fleet` routing, fleet `reviewItems`, fleet review ticket payloads, policy export, policy promotion, policy promotion `reviewItems`, package-manager hardening Action outputs, policy-promotion Action outputs, hosted consumption of promotion Action outputs, operator-visible promotion output values, hosted promotion judge audit traces, and editor-native adapter coverage landed | Next workflow automation should deepen live operator approval/readback after Marketplace/payment gates | | ECC Tools next-level app | Billing audit, PR checks, deep analyzer, sync backlog, evaluator/RAG corpus, analysis-depth readiness, hosted execution planning, hosted CI diagnostics, hosted security evidence review, hosted harness compatibility audit, hosted reference-set evaluation, hosted AI routing/cost review, hosted team backlog routing, hosted depth-plan check-run, PR-comment hosted job dispatch, hosted job result history/check-runs, hosted result status command, status-aware depth-plan recommendations, hosted promotion readiness, hosted promotion output scoring, hosted promotion retrieval planning, hosted promotion judge contract, gated hosted promotion judge execution, hosted promotion judge audit trace, payment-announcement readiness, billing announcement preflight, aggregate production billing KV readback, Marketplace webhook provenance, target-account billing readback, Marketplace-source provenance counts, AgentShield fleet-summary hosted routing, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output hosted telemetry, and operator-visible promotion output values | PRs #26-#43 plus #53-#78 landed with test evidence, including AgentShield evidence-pack gap routing, canonical bundle recognition, supply-chain signature gates, PR draft follow-up Linear tracking, evidence-backed/deep-ready repository classification, the `/api/analysis/depth-plan` hosted job plan, `/api/analysis/jobs/ci-diagnostics`, `/api/analysis/jobs/security-evidence-review`, `/api/analysis/jobs/harness-compatibility-audit`, `/api/analysis/jobs/reference-set-evaluation`, `/api/analysis/jobs/ai-routing-cost-review`, `/api/analysis/jobs/team-backlog-routing`, the `ECC Tools / Hosted Depth Plan` check-run, `/ecc-tools analyze --job ...` PR-comment dispatch, non-blocking per-hosted-job result check-runs backed by 30-day result cache records, `/ecc-tools analyze --job status` cache lookup, cache-aware next-job recommendations in the depth-plan check-run, the `ECC Tools / Hosted Promotion Readiness` corpus-backed PR check-run, deterministic hosted-output scoring against cached completed job artifacts/findings, ranked retrieval/model-prompt planning, the fail-closed `hosted-promotion-judge.v1` request contract, opt-in live model-judge execution behind hosted evidence, entitlement, budget, provider, executor, strict JSON, and citation gates, hosted promotion judge request fingerprints plus allowed-citation audit trails, a fail-closed `/api/billing/readiness` `announcementGate` for native GitHub payments claims, `npm run billing:announcement-gate` plus `--preflight` as the non-secret operator verifier, hosted security findings for AgentShield fleet summaries, an `Evidence` column in hosted finding comments/check-runs, hosted harness findings that route AgentShield fleet target paths to harness owners, ECC-Tools commit `8658951` routing AgentShield policy-promotion Action outputs into hosted security review and promotion-readiness scoring, ECC-Tools commit `16c537f` rendering policy-promotion status/pack/count/digest values directly in hosted security job comments/check-runs, ECC-Tools commit `05d4e82` rendering model-judge audit traces without exposing raw provider output, ECC-Tools commit `91a441b` adding the safe billing announcement preflight path, ECC-Tools commit `eb69412` recording the initial production readback state, ECC-Tools commit `95d0bec` adding `npm run billing:kv-readback` with aggregate account-billing and billing-state records but 0 Marketplace Pro billing-state records, ECC-Tools commit `2859678` requiring webhook-derived Marketplace provenance before announcement readiness, ECC-Tools commit `42653f9` adding Wrangler OAuth readback, ECC-Tools commit `632e059` adding sanitized target-account readback that requires both target key families before `--require-ready` can pass, and ECC-Tools commit `d5f60db` adding sanitized Marketplace plan/action provenance counts; the latest 2026-05-18 live Wrangler OAuth recheck found 256 account-billing records, 256 billing-state records, 197 Marketplace-source records, 4 Marketplace webhook-provenance records, all `Open Source`, and 0 Marketplace Pro records, then updated Linear ITO-61 with the data/provisioning blocker | Next work is create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure target account plus `INTERNAL_API_SECRET`, then run `billing:kv-readback -- --wrangler --wrangler-bin ./node_modules/.bin/wrangler --account --require-ready`, followed by the live announcement gate | | GitGuardian/Dependabot/CodeRabbit-style checks | Non-blocking taxonomy, deterministic follow-up checks, and local supply-chain gates | ECC-Tools risk taxonomy check plus follow-up signals landed, including Skill Quality, Deep Analyzer Evidence, Analyzer Corpus Evidence, RAG/Evaluator Evidence, PR Review/Salvage Evidence, and AgentShield evidence-pack evidence; #1846 added npm registry signature gates; #1848 added the supply-chain incident-response playbook and `pull_request_target` cache-poisoning validator guard; #1851 added the privileged checkout credential-persistence guard; AgentShield #78, JARVIS #13, and ECC-Tools #53 applied the same hardening outside trunk | Current supply-chain gate complete; deeper hosted review features remain future | | Harness-agnostic learning system | Audit, adapter matrix, observability, traces, promotion loop | Audit/adapters/observability gates plus `docs/architecture/evaluator-rag-prototype.md`, `examples/evaluator-rag-prototype/`, and ECC-Tools PR #40 define read-only stale-salvage, billing-readiness, CI-failure-diagnosis, harness-config-quality, AgentShield policy-exception, skill-quality evidence, deep-analyzer evidence, and RAG/evaluator comparison scenarios with trace, report, playbook, verifier, and predictive-check artifacts; ECC-Tools PRs #68-#72 now turn that corpus into a deterministic PR check-run gate with cached hosted-output scoring, ranked retrieval candidates, a model prompt seed, a fail-closed hosted model-judge request contract, and opt-in live model execution behind strict hosted-evidence gates | Deterministic hosted PR check, cached output scoring, retrieval planning, judge contract, and gated model execution integrated | @@ -874,7 +892,7 @@ repo evidence and merge commits. | Release and publication | rc.1 release docs, publication readiness doc | Naming matrix and plugin submission/contact checklist | Before any tag | | Harness OS core | Audit, adapter matrix, observability docs, `ecc2/` | HUD/session-control acceptance spec | Weekly until GA | | Evaluation and RAG | Reference-set validation, harness audit, traces, ECC-Tools corpus | Read-only evaluator/RAG prototype plus stale-salvage, billing-readiness, CI-failure-diagnosis, harness-config-quality, AgentShield policy-exception, skill-quality evidence, deep-analyzer evidence, and RAG/evaluator comparison fixtures; ECC-Tools #68 publishes the corpus as a hosted promotion readiness check-run, #69 scores cached hosted job outputs against the same corpus, #70 emits ranked retrieval candidates plus a model prompt seed, #71 adds a fail-closed hosted model-judge request contract, and #72 executes that judge only when explicitly enabled and backed by hosted retrieval citations; ECC-Tools `16c537f` surfaces policy-promotion Action output values in hosted security comments/checks; ECC-Tools `05d4e82` adds hosted model-judge audit traces with request fingerprints and allowed-citation counts | Marketplace Pro billing-state verification with webhook provenance | -| AgentShield enterprise | AgentShield PR evidence and roadmap notes | Fleet routing landed in #89 after evidence-pack inspect/readback shipped in #88; #90 emits fleet `reviewItems`; #91 exports checksum-backed policy bundles; #92 promotes checksum-verified policies from those bundles into active policy files; AgentShield `87aec47` adds policy promotion `reviewItems`; `28d08c7` adds package-manager hardening drift detection; `659f569` refreshes workflow action runtime pins; `ee585cd` corrects unsupported npm release-age guidance and keeps enforceable cooldown findings on pnpm/Yarn; `1124535` exposes package-manager hardening Action outputs for CI/hosted routing; `1593925` exposes policy-promotion Action outputs and runtime-smoke job-summary evidence; `840952a` adds fleet review ticket payloads and current Mini Shai-Hulud IOC breadcrumbs; ECC-Tools #76 consumes fleet summaries, #77 surfaces source evidence paths in hosted findings, #78 links fleet routes to harness owners, ECC-Tools `8658951` consumes policy-promotion Action outputs, and ECC-Tools `16c537f` renders operator-visible output values | Deepen live operator approval/readback after Marketplace/payment gates | +| AgentShield enterprise | AgentShield PR evidence and roadmap notes | Fleet routing landed in #89 after evidence-pack inspect/readback shipped in #88; #90 emits fleet `reviewItems`; #91 exports checksum-backed policy bundles; #92 promotes checksum-verified policies from those bundles into active policy files; #94 adds Zed and VS Code adapter detection, Zed project scan discovery, and `.zed/setup.mjs` persistence IOC coverage; AgentShield `87aec47` adds policy promotion `reviewItems`; `28d08c7` adds package-manager hardening drift detection; `659f569` refreshes workflow action runtime pins; `ee585cd` corrects unsupported npm release-age guidance and keeps enforceable cooldown findings on pnpm/Yarn; `1124535` exposes package-manager hardening Action outputs for CI/hosted routing; `1593925` exposes policy-promotion Action outputs and runtime-smoke job-summary evidence; `840952a` adds fleet review ticket payloads and current Mini Shai-Hulud IOC breadcrumbs; ECC-Tools #76 consumes fleet summaries, #77 surfaces source evidence paths in hosted findings, #78 links fleet routes to harness owners, ECC-Tools `8658951` consumes policy-promotion Action outputs, and ECC-Tools `16c537f` renders operator-visible output values | Deepen live operator approval/readback after Marketplace/payment gates | | ECC Tools app | ECC-Tools PR evidence, billing audit, risk taxonomy, evaluator/RAG corpus | ECC-Tools #53 published the supply-chain workflow hardening branch, #54 tracks copy-ready PR drafts in the Linear/project backlog, #55 classifies analysis-depth readiness, #56 exposes the hosted execution plan, #57 executes the first hosted CI diagnostics job, #58 executes the hosted security evidence review job, #59 executes the hosted harness compatibility audit, #60 executes the hosted reference-set evaluation, #61 executes the hosted AI routing/cost review, #62 executes hosted team backlog routing, #63 publishes the hosted depth-plan check-run, #64 dispatches hosted jobs from PR comments, #65 persists hosted result history/check-runs, #66 exposes hosted job status from PR comments, #67 makes depth-plan recommendations cache-aware, #68 publishes hosted promotion readiness from the evaluator/RAG corpus, #69 scores cached hosted job outputs against that corpus, #70 emits ranked retrieval candidates plus a model prompt seed, #71 emits the gated `hosted-promotion-judge.v1` contract without live model calls, #72 adds opt-in live model-judge execution behind hosted-evidence and strict JSON/citation gates, #73 adds a fail-closed native-payments `announcementGate` to billing readiness, #74 adds `npm run billing:announcement-gate` for operator verification, #75 tightens the billing announcement gate for live Marketplace readback, #76 routes AgentShield fleet-summary evidence into hosted security findings, #77 adds source evidence paths to hosted finding output, #78 links AgentShield fleet target paths to hosted harness owner findings, `8658951` routes AgentShield policy-promotion Action outputs into hosted security review and promotion readiness, `16c537f` renders policy-promotion status/pack/count/digest values in hosted security comments/checks, `05d4e82` renders hosted promotion judge request fingerprints plus allowed-citation audit traces, `91a441b` adds billing announcement preflight output for required readback inputs, `eb69412` records the initial production readback state, `95d0bec` adds aggregate `billing:kv-readback` evidence, `2859678` requires Marketplace webhook provenance in billing readiness, `42653f9` adds Wrangler OAuth readback with live aggregate production counts, and `632e059` adds sanitized target-account billing readback for the exact Marketplace test account | Create or verify Marketplace-managed Pro target billing-state with webhook provenance, then live target readback and announcement gate | | Linear progress | Linear project status updates, `docs/architecture/progress-sync-contract.md`, generated `operator:dashboard` output, and this mirror | Status update with queue/evidence/missing gates | Every significant merge batch | diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index e423d3c4..bc245c53 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -26,7 +26,7 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-16.md` | Current May 16/17 queue cleanup, recsys skill merge, GateGuard triage, PR #1947 supply-chain protection, AgentShield #87 plugin-cache confidence evidence, AgentShield #88 evidence-pack inspect/readback, AgentShield #89 evidence-pack fleet routing, AgentShield #90 fleet review items, AgentShield #91 policy export, AgentShield #92 policy promotion, ECC-Tools #76 fleet-summary consumption, ECC-Tools #77 hosted finding evidence paths, ECC-Tools #78 harness policy-route linking, dashboard refresh, and combined Node/Rust/release-surface gate evidence through the May 16 mirror | Must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` | May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack protection recheck, npm audit/signature checks, legacy and Linear progress routing, deterministic preview-pack smoke, operator dashboard refresh, Linear sync, and GitHub CI evidence for `27dc2918` | Superseded by the May 18 evidence snapshot; repeat from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, supply-chain recheck, AgentShield evidence mirror, Linear sync, current-head CI/security scan success for `4470e2e6`, and ITO-46 naming/plugin publication closure | Superseded by the May 19 ECC identity, video, and growth evidence snapshot | -| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19/20 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, release approval gate, May 19 operator dashboard, preview-pack smoke digest `531328aaaa53`, 2568-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, PR #2004 Linear readiness evidence sync CI success, PR #2008 supply-chain evidence gate CI success, post-PR #2006 main CI success, PR #2009 project-registry hygiene CI success, post-PR #2009 main CI success, post-PR #2011 GateGuard CI success, post-PR #2013 release-approval-gate CI success, ECC-Tools #79 billing-announcement redaction hardening, ECC-Tools #80-#88 runtime-receipt, AgentShield approval-ID, Linear sync, remediation sync, hosted observability event/status/depth-plan/API readback, JARVIS #15/#16 queue/deploy repair, and the May 19/20 Linear sync comments | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | +| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19/20 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, release approval gate, May 19 operator dashboard, preview-pack smoke digest `531328aaaa53`, 2568-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, PR #2004 Linear readiness evidence sync CI success, PR #2008 supply-chain evidence gate CI success, post-PR #2006 main CI success, PR #2009 project-registry hygiene CI success, post-PR #2009 main CI success, post-PR #2011 GateGuard CI success, post-PR #2013 release-approval-gate CI success, ECC-Tools #79 billing-announcement redaction hardening, ECC-Tools #80-#88 runtime-receipt, AgentShield approval-ID, Linear sync, remediation sync, hosted observability event/status/depth-plan/API readback, AgentShield #94 Zed/VS Code adapter coverage, JARVIS #15/#16 queue/deploy repair, and the May 19/20 Linear sync comments | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 19 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and adds the current `$1,728/mo` to `$10,000/mo` hypergrowth, video owner-approval, and outbound-pack operating lanes | diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md index 05aa2bc9..35db4322 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -8,9 +8,9 @@ social announcement. | Field | Evidence | | --- | --- | -| Upstream main | `9819626459a662773be7d0b1c18d82c1316b8c36` | +| Upstream main | `3cb8c48e74d7ee9883fd2e6d94d8e5aea7421d8c` | | Git remote | `https://github.com/affaan-m/ECC.git` | -| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, PR #2001 owner approval packet addition, PR #2002 owner approval dashboard gate refresh, PR #2004 Linear readiness evidence sync, PR #2005 post-PR #2004 evidence refresh, PR #2008 release supply-chain evidence gate fix, PR #2006 per-project Claude Code adapter, PR #2009 continuous-learning project registry hygiene fix, PR #2011 GateGuard quoted git introspection fix, and PR #2013 deterministic release approval gate | +| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, PR #2001 owner approval packet addition, PR #2002 owner approval dashboard gate refresh, PR #2004 Linear readiness evidence sync, PR #2005 post-PR #2004 evidence refresh, PR #2008 release supply-chain evidence gate fix, PR #2006 per-project Claude Code adapter, PR #2009 continuous-learning project registry hygiene fix, PR #2011 GateGuard quoted git introspection fix, PR #2013 deterministic release approval gate, ECC-Tools #80-#88 hosted observability/readback batch, and AgentShield #94 Zed/VS Code adapter coverage | | Local status caveat | `git status --short --branch` was clean after pulling `origin/main`; generated evidence files are committed after the source snapshot they describe | The release operator must repeat all publish-facing checks from the exact final @@ -70,17 +70,19 @@ Tracked repositories in the platform audit were: | JARVIS deploy repair | JARVIS PR #16 merged as `4369c34babd21d539c420866da51c7a8365f1c9e`; the deploy workflow no longer uses an invalid job-level `secrets.*` condition, Vercel deploy skips cleanly when secrets are absent, backend image build/push succeeds, and main CI, CodeQL, and Deploy runs `26129539376`, `26129539427`, and `26129539425` completed successfully | | Linear roadmap sync | Linear document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f`, project comment `d42bf0e2-7a8e-4934-9f3f-e281498ee805`, and issue comments on ITO-44, ITO-50, ITO-54, ITO-56, and ITO-61 record the late-pass queue-zero, release-gate, billing-safety, and progress-sync state. | -## May 20 Hosted Observability Sync +## May 20 Hosted Observability And AgentShield Adapter Sync | Surface | Evidence | | --- | --- | | ECC discussion queue | Discussion #2015 was answered and marked accepted with conservative setup guidance: do not install in `C:\`; use a normal workspace; install `ecc@ecc` once through the Claude plugin marketplace; copy only needed rule folders when using manual rules; do not stack plugin plus full manual install. | | ECC platform audit | `node scripts/platform-audit.js --json` at `2026-05-20T00:25:38Z` returned ready true with 0 open PRs, 0 open issues, 0 discussion maintainer-touch gaps, 0 answerable Q&A gaps, 0 conflicting PRs, and 0 dirty blockers across `affaan-m/ECC`, `affaan-m/agentshield`, `affaan-m/JARVIS`, `ECC-Tools/ECC-Tools`, and `ECC-Tools/ECC-website`. | +| ECC platform audit recheck | `npm run platform:audit -- --json` at `2026-05-20T00:42:11Z` returned ready true with 0 open PRs, 0 open issues, 0 discussion maintainer-touch gaps, 0 answerable Q&A gaps, 0 conflicting PRs, 0 GitHub errors, and 0 dirty blockers across the same tracked repo set after AgentShield #94 merged. | | ECC-Tools #80/#81/#82 | PR #80 merged runtime-receipt failure-reason enforcement as `4efc8cc858022f84c844690f3298633b081c4398`; PR #81 preserved AgentShield fleet approval IDs as `1fbf635f492284f75ba7166c029c39eb8cc15794`; PR #82 rendered those approval IDs in hosted security review comments/check-runs as `7a7b4d096a176ae80b3a2076c09d45601e36013a`. | | ECC-Tools #83/#84 | PR #83 merged deterministic Linear external-ID reuse for deferred follow-ups as `b6b107f33961bef18a85fb619f3a976eb5d752dd`; PR #84 merged hosted AgentShield remediation sync to Linear as `73bac7058071c55cb30c6b8ac6db779b3660c02c`. Local validation covered focused route/client tests, typecheck, lint, full ECC-Tools test suite, and whitespace checks before merge; GitHub Verify, Security Audit, and Workers Builds passed. | | ECC-Tools #85/#86/#87 | PR #85 merged hosted job observability events as `1637e0f2bfa0a889387f2c20675680ccc5528123`; PR #86 merged hosted status observability readback as `5a9e94d3ff860307c3e7fd9fd065f0de2bd633dd`; PR #87 merged hosted depth-plan observability readback as `508fbc02b63cf1fcb5af2f3624608fa66e53b5d4`. Local validation for the final depth-plan readback slice passed the focused hosted depth-plan route test, full route suite (89/89), typecheck, lint, full ECC-Tools Vitest suite (683/683), and `git diff --check`; GitHub Verify, Security Audit, and Workers Builds passed before merge. | | ECC-Tools #88 | PR #88 merged authenticated hosted observability API readback as `c836ac3fb24ed7e2ae38cd61e41c9651ac9c00f8`. `GET /api/analysis/observability` now summarizes hosted events by event type and job for operator/dashboard readback, skips malformed stale KV records, and the deployment runbook includes the production smoke command. Local verification passed typecheck, lint, full ECC-Tools Vitest suite (686/686), and `git diff --check`; GitHub Verify, Security Audit, and Workers Builds passed before merge. | -| Linear roadmap sync | Linear ITO-54 comment `74dcc101-3be5-4173-be13-62b80d54f569` and ECC Platform Roadmap project comment `348ea8f5-2a2d-46d9-a0fe-ed99653e7fe5` record the May 20 hosted observability status/depth-plan readback batch; Linear comments `291e2a4b-06e3-4672-a057-cdb141478161` and `b2d35de0-ca49-44cb-982a-ddec229e7691` add the #88 observability API readback; earlier comments on ITO-54, ITO-48, and the project record the #84 hosted remediation sync and #85 hosted observability event emission batches. | +| AgentShield #94 | PR #94 merged Zed/VS Code adapter coverage as `4caee27acfadb50a4cd024e738b5c3cbd4b0bb03`. AgentShield now reports Zed and VS Code as first-class harness adapters, discovers `.zed/settings.json`, `.zed/tasks.json`, and `.zed` hook-code files, and flags `.zed/setup.mjs` in the AI-tool persistence IOC rule alongside `.vscode/setup.mjs`. Local verification passed typecheck, lint, focused scanner/rule tests, full `npm test` (1822 tests), `npm run build`, and `git diff --check`; GitHub checks passed across GitGuardian, scan suite, self-scan, self-scan examples, Node 18/20/22 CI, CodeRabbit, and Cubic after rerunning a transient artifact-upload failure. | +| Linear roadmap sync | Linear ITO-54 comment `74dcc101-3be5-4173-be13-62b80d54f569` and ECC Platform Roadmap project comment `348ea8f5-2a2d-46d9-a0fe-ed99653e7fe5` record the May 20 hosted observability status/depth-plan readback batch; Linear comments `291e2a4b-06e3-4672-a057-cdb141478161` and `b2d35de0-ca49-44cb-982a-ddec229e7691` add the #88 observability API readback; Linear ITO-49 comment `faed69dd-35f5-469d-acb5-ddde6a70d6a1` and project comment `70187c1e-d481-4181-b418-09bd65d54b5e` add the #94 AgentShield Zed/VS Code adapter evidence; earlier comments on ITO-54, ITO-48, and the project record the #84 hosted remediation sync and #85 hosted observability event emission batches. | ## Release And Growth Evidence @@ -123,7 +125,7 @@ Tracked repositories in the platform audit were: | Owner approval proof | `owner-approval-packet-2026-05-19.md` centralizes release, package, plugin, video, billing, social, and outbound decision gates | | Business baseline | Hypergrowth command center and partner pack use `$1,728/mo` current MRR, `$10,000/mo` target MRR, and `$8,272/mo` gap | | Operator dashboard | `operator-readiness-dashboard-2026-05-19.md` pulls the growth baseline into the same queue, publication, video, outbound, AgentShield, ECC Tools, Linear, and supply-chain control surface | -| Linear progress proof | Linear project document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` mirrors the post-PR #2002 state and records active lanes for launch materials, AgentShield, ECC Tools deep analysis, observability, and final release publication; Linear document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f` adds the PR #2013 approval gate, ECC-Tools #79 redaction hardening, and JARVIS #15/#16 queue/deploy repair evidence; May 20 Linear comments `74dcc101-3be5-4173-be13-62b80d54f569`, `348ea8f5-2a2d-46d9-a0fe-ed99653e7fe5`, `291e2a4b-06e3-4672-a057-cdb141478161`, and `b2d35de0-ca49-44cb-982a-ddec229e7691` add ECC-Tools #86/#87/#88 hosted observability readback evidence to ITO-54 and the project | +| Linear progress proof | Linear project document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` mirrors the post-PR #2002 state and records active lanes for launch materials, AgentShield, ECC Tools deep analysis, observability, and final release publication; Linear document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f` adds the PR #2013 approval gate, ECC-Tools #79 redaction hardening, and JARVIS #15/#16 queue/deploy repair evidence; May 20 Linear comments `74dcc101-3be5-4173-be13-62b80d54f569`, `348ea8f5-2a2d-46d9-a0fe-ed99653e7fe5`, `291e2a4b-06e3-4672-a057-cdb141478161`, `b2d35de0-ca49-44cb-982a-ddec229e7691`, `faed69dd-35f5-469d-acb5-ddde6a70d6a1`, and `70187c1e-d481-4181-b418-09bd65d54b5e` add ECC-Tools #86/#87/#88 hosted observability readback evidence and AgentShield #94 adapter evidence to ITO-54, ITO-49, and the project | ## Current Publication Blockers @@ -151,10 +153,11 @@ identity, release video suite, preview pack, growth outreach packet, per-project Claude Code adapter surface, continuous-learning project registry hygiene, GateGuard quoted git introspection fix, deterministic release approval gate, ECC-Tools billing-announcement redaction hardening, ECC-Tools hosted -observability readback, and JARVIS security/deploy queue repairs are current on -May 20, 2026 for ECC `main` through -`b3c015c7443c6617f897654613c21eddc3d25764` plus ECC-Tools `main` through -`c836ac3fb24ed7e2ae38cd61e41c9651ac9c00f8`. The remaining video work is owner +observability readback, AgentShield Zed/VS Code adapter coverage, and JARVIS +security/deploy queue repairs are current on May 20, 2026 for ECC `main` +through `3cb8c48e74d7ee9883fd2e6d94d8e5aea7421d8c`, ECC-Tools `main` +through `c836ac3fb24ed7e2ae38cd61e41c9651ac9c00f8`, and AgentShield `main` +through `4caee27acfadb50a4cd024e738b5c3cbd4b0bb03`. The remaining video work is owner approval, upload, and public URL attachment, not render or QA production. This improves publication readiness but does not replace the approval-gated diff --git a/docs/security/supply-chain-incident-response.md b/docs/security/supply-chain-incident-response.md index 99d603af..2adb9f95 100644 --- a/docs/security/supply-chain-incident-response.md +++ b/docs/security/supply-chain-incident-response.md @@ -26,8 +26,9 @@ credentials: with historical malicious `node-ipc` versions also blocked by ECC because they carried destructive or unauthorized file-writing behavior. - The live IOC set includes persistence through Claude Code - `.claude/settings.json`, VS Code `.vscode/tasks.json`, and OS-level - `gh-token-monitor` LaunchAgent/systemd services. Some variants add + `.claude/settings.json`, VS Code `.vscode/tasks.json`, Zed + `.zed/tasks.json`, and OS-level `gh-token-monitor` LaunchAgent/systemd + services. Some variants add `~/.config/gh-token-monitor/token` plus a dead-man-switch token description `IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner`, malicious workflow files such as `.github/workflows/codeql_analysis.yml`, and Python runtime @@ -179,7 +180,7 @@ Escalate to a maintainer security review before any release or merge if: - a dependency lockfile references a package named in an active advisory; - `node scripts/ci/scan-supply-chain-iocs.js --home` finds Claude Code, - VS Code, or OS-level persistence indicators; + VS Code, Zed, or OS-level persistence indicators; - a workflow combines `pull_request_target` with dependency installation, cache restore/save, PR-head checkout, or write permissions; - a release workflow combines `id-token: write` with shared cache usage; From 68b4e45145968acd52e68d900f8422061ed7f4a2 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 21:13:36 -0400 Subject: [PATCH 57/61] docs: sync AgentShield dependabot evidence (#2018) --- docs/ECC-2.0-GA-ROADMAP.md | 24 ++++++++++++++++--- .../2.0.0-rc.1/preview-pack-manifest.md | 2 +- .../publication-evidence-2026-05-19.md | 21 +++++++++------- 3 files changed, 34 insertions(+), 13 deletions(-) diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index 07647242..59b54e75 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -42,6 +42,10 @@ partner/sponsor funnel, consulting/talk funnel, and social launch plan. VS Code are first-class adapter detections, `.zed/settings.json` and `.zed/tasks.json` are discoverable scan inputs, and `.zed/setup.mjs` now trips the same AI-tool persistence IOC rule as `.vscode/setup.mjs`. +- AgentShield PR #95 cleared the remaining default-branch Dependabot alert by + moving transitive `brace-expansion` 5.x lockfile entries to `5.0.6`; the + post-merge Dependabot open-alert API now returns `[]`, and local + `npm audit --audit-level=moderate` returns 0 vulnerabilities. - Linear ITO-54 and the ECC Platform Roadmap now have the May 20 ECC-Tools hosted observability update comments `74dcc101-3be5-4173-be13-62b80d54f569` and @@ -50,7 +54,10 @@ partner/sponsor funnel, consulting/talk funnel, and social launch plan. in Linear comments `291e2a4b-06e3-4672-a057-cdb141478161` and `b2d35de0-ca49-44cb-982a-ddec229e7691`; AgentShield #94 is recorded in ITO-49 comment `faed69dd-35f5-469d-acb5-ddde6a70d6a1` and project comment - `70187c1e-d481-4181-b418-09bd65d54b5e`. + `70187c1e-d481-4181-b418-09bd65d54b5e`; AgentShield #95 is recorded in + ITO-49 comment `371fc3e4-611f-4d20-a23f-67db1260b418`, ITO-57 comment + `bd06e252-15c1-4256-b667-caa3f64f5968`, and project comment + `22c2c388-2fd1-4dea-a939-6141f40c9a21`. ## 2026-05-19 Delta @@ -160,6 +167,13 @@ As of 2026-05-20: GitHub checks passed across GitGuardian, scan suite, self-scan, self-scan examples, Node 18/20/22 CI, CodeRabbit, and Cubic after rerunning a transient GitHub artifact-upload failure. +- AgentShield PR #95 resolves Dependabot #20 / `GHSA-jxxr-4gwj-5jf2` / + `CVE-2026-45149` by updating the vulnerable `brace-expansion` 5.x + transitive lockfile entries to `5.0.6`. Local validation passed + `npm audit --audit-level=moderate`, typecheck, lint, full `npm test` + (1822 tests), build, and whitespace checks; GitHub checks passed across + Verify Node 18/20/22, self-scan, self-scan examples, Test GitHub Action, + GitGuardian, CodeRabbit, and Cubic. - `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` regenerates the ITO-44 prompt-to-artifact dashboard from live platform audit evidence: PR queue, issue queue, discussion queue, local worktree gate, @@ -774,6 +788,10 @@ As of 2026-05-20: scan inputs, adapter reports expose Zed MCP/tool-permission/task metadata and VS Code workspace/task/extension metadata, and `.zed/setup.mjs` is covered by the AI-tool persistence IOC rule. +- AgentShield PR #95 merged as `25d91f0002214c408da4ceaac7def20bad40ca10` + and clears the `brace-expansion` Dependabot alert. The lockfile now resolves + the vulnerable transitive 5.x copies to `5.0.6`; the remaining 1.x copy is + outside the advisory range. - AgentShield main commit `87aec47fb55d04ea28d494852d4f664c268c5601` extends policy promotion with durable `reviewItems` for manifest digest evidence, policy-owner approval, protected rollout PR handoff, and runtime @@ -868,7 +886,7 @@ is not complete unless the evidence column exists and has been freshly verified. | Naming and rename readiness | Naming matrix across package/plugin/docs/social surfaces | `docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md` records current package, repo, Claude plugin, Codex plugin, OpenCode, and npm availability evidence | Complete for rc.1; post-rc rename remains future work | | Claude and Codex plugin publication | Contact/submission path with required artifacts and status | Publication readiness, naming matrix, and May 12 dry-run evidence document plugin validation, clean-checkout Claude tag/install smoke, and Codex marketplace CLI shape | Needs explicit approval for real tag/push and marketplace submission | | Articles, tweets, and announcements | X thread, LinkedIn copy, GitHub release copy, push checklist, partner/sponsor/talk pack | Draft launch collateral and approval-gated outreach copy exist under rc.1 release docs | Needs URL-backed refresh and human approval before posting or sending | -| AgentShield enterprise iteration | Policy gates, SARIF, packs, provenance, corpus, HTML reports, exception lifecycle audit, baseline drift Action/CLI surfaces, evidence-pack redaction, harness adapter registry, editor-native Zed/VS Code adapter coverage, enterprise research roadmap, supply-chain hardened release path, CI-safe baseline fingerprints, corpus accuracy recommendations, remediation workflow phases, env proxy hijack corpus coverage, Mini Shai-Hulud full-campaign package IOCs, CI-provenance evidence packs, plugin-cache runtime-confidence triage, evidence-pack consumer readback, fleet-level evidence-pack routing, fleet review items, fleet review ticket payloads, checksum-backed policy export, checksum-verified policy promotion, policy promotion review items, package-manager hardening drift detection, npm age-gate guidance correction, workflow action-runtime pin refresh, package-manager hardening Action outputs, policy-promotion Action outputs, ECC-Tools hosted consumption of promotion Action outputs, ECC-Tools operator-visible promotion output values, and ECC-Tools hosted promotion judge audit traces | PRs #53, #55-#64, #67-#69, #78-#92, and #94 landed with test evidence, ECC-Tools #76 consumes the fleet-summary output in hosted security review, #77 surfaces source evidence paths in hosted finding output, and #78 links fleet routes to harness owner review; AgentShield #91 adds `agentshield policy export` bundles for branch-protection review and downstream promotion; AgentShield #92 adds `agentshield policy promote` with digest verification, tamper rejection, explicit pack selection, dry-run review, and JSON output before writing active policy; AgentShield #94 adds Zed/VS Code adapter detection, `.zed/settings.json` and `.zed/tasks.json` scan discovery, and `.zed/setup.mjs` AI-tool persistence IOC coverage; AgentShield commit `87aec47` adds `reviewItems` for digest evidence, owner review, protected rollout PR handoff, and runtime smoke testing with green local and remote CI; AgentShield commit `28d08c7` adds package-manager hardening drift detection for plaintext registry credentials, lifecycle-script enablement, and weak pnpm/Yarn release-age cooldowns with green local and remote CI; AgentShield commit `659f569` refreshes all workflow action runtime pins to SHA-pinned checkout v6.0.2 and setup-node v6.4.0 with green remote CI and no remaining action-runtime deprecation annotation; AgentShield commit `ee585cd` corrects npm release-age guidance by flagging unsupported npm age keys and keeping enforceable cooldown findings on pnpm/Yarn with green local and remote CI; AgentShield commit `1124535` exposes package-manager hardening status/count outputs and a redacted job-summary section for registry credentials, lifecycle scripts, and release-age gates with green local and remote CI; AgentShield commit `1593925` exposes policy-promotion status/count/digest outputs plus job-summary review items for owner approval, protected rollout, and runtime smoke, and marks runtime smoke verified when the same Action job scans with the promoted policy; AgentShield commit `840952a` adds Linear/operator-ready fleet review ticket payloads and expands current Mini Shai-Hulud IOC breadcrumbs with green local and remote CI; ECC-Tools commit `8658951` routes those policy-promotion Action outputs into hosted security review findings and Hosted Promotion Readiness scoring; ECC-Tools commit `16c537f` renders policy-promotion status, pack, review item count, action-required count, and digest in hosted security job comments/check-runs; ECC-Tools commit `05d4e82` renders hosted promotion judge request fingerprints and allowed-citation counts without raw provider output; native PDF export deferred in favor of self-contained HTML plus print-to-PDF until explicit enterprise demand appears; `docs/architecture/agentshield-enterprise-research-roadmap.md` now has baseline drift, evidence-pack bundle, redaction, adapter-registry, supply-chain hardening, hashed baseline fingerprints, corpus accuracy recommendation, remediation workflow, env proxy hijack corpus, Mini Shai-Hulud full-campaign package-table, `ci-context.json` provenance, `plugin-cache` confidence, `evidence-pack inspect` readback, `evidence-pack fleet` routing, fleet `reviewItems`, fleet review ticket payloads, policy export, policy promotion, policy promotion `reviewItems`, package-manager hardening Action outputs, policy-promotion Action outputs, hosted consumption of promotion Action outputs, operator-visible promotion output values, hosted promotion judge audit traces, and editor-native adapter coverage landed | Next workflow automation should deepen live operator approval/readback after Marketplace/payment gates | +| AgentShield enterprise iteration | Policy gates, SARIF, packs, provenance, corpus, HTML reports, exception lifecycle audit, baseline drift Action/CLI surfaces, evidence-pack redaction, harness adapter registry, editor-native Zed/VS Code adapter coverage, Dependabot alert closure, enterprise research roadmap, supply-chain hardened release path, CI-safe baseline fingerprints, corpus accuracy recommendations, remediation workflow phases, env proxy hijack corpus coverage, Mini Shai-Hulud full-campaign package IOCs, CI-provenance evidence packs, plugin-cache runtime-confidence triage, evidence-pack consumer readback, fleet-level evidence-pack routing, fleet review items, fleet review ticket payloads, checksum-backed policy export, checksum-verified policy promotion, policy promotion review items, package-manager hardening drift detection, npm age-gate guidance correction, workflow action-runtime pin refresh, package-manager hardening Action outputs, policy-promotion Action outputs, ECC-Tools hosted consumption of promotion Action outputs, ECC-Tools operator-visible promotion output values, and ECC-Tools hosted promotion judge audit traces | PRs #53, #55-#64, #67-#69, #78-#92, #94, and #95 landed with test evidence, ECC-Tools #76 consumes the fleet-summary output in hosted security review, #77 surfaces source evidence paths in hosted finding output, and #78 links fleet routes to harness owner review; AgentShield #91 adds `agentshield policy export` bundles for branch-protection review and downstream promotion; AgentShield #92 adds `agentshield policy promote` with digest verification, tamper rejection, explicit pack selection, dry-run review, and JSON output before writing active policy; AgentShield #94 adds Zed/VS Code adapter detection, `.zed/settings.json` and `.zed/tasks.json` scan discovery, and `.zed/setup.mjs` AI-tool persistence IOC coverage; AgentShield #95 clears the `brace-expansion` Dependabot alert with a patched lockfile and 0 open Dependabot alerts after merge; AgentShield commit `87aec47` adds `reviewItems` for digest evidence, owner review, protected rollout PR handoff, and runtime smoke testing with green local and remote CI; AgentShield commit `28d08c7` adds package-manager hardening drift detection for plaintext registry credentials, lifecycle-script enablement, and weak pnpm/Yarn release-age cooldowns with green local and remote CI; AgentShield commit `659f569` refreshes all workflow action runtime pins to SHA-pinned checkout v6.0.2 and setup-node v6.4.0 with green remote CI and no remaining action-runtime deprecation annotation; AgentShield commit `ee585cd` corrects npm release-age guidance by flagging unsupported npm age keys and keeping enforceable cooldown findings on pnpm/Yarn with green local and remote CI; AgentShield commit `1124535` exposes package-manager hardening status/count outputs and a redacted job-summary section for registry credentials, lifecycle scripts, and release-age gates with green local and remote CI; AgentShield commit `1593925` exposes policy-promotion status/count/digest outputs plus job-summary review items for owner approval, protected rollout, and runtime smoke, and marks runtime smoke verified when the same Action job scans with the promoted policy; AgentShield commit `840952a` adds Linear/operator-ready fleet review ticket payloads and expands current Mini Shai-Hulud IOC breadcrumbs with green local and remote CI; ECC-Tools commit `8658951` routes those policy-promotion Action outputs into hosted security review findings and Hosted Promotion Readiness scoring; ECC-Tools commit `16c537f` renders policy-promotion status, pack, review item count, action-required count, and digest in hosted security job comments/check-runs; ECC-Tools commit `05d4e82` renders hosted promotion judge request fingerprints and allowed-citation counts without raw provider output; native PDF export deferred in favor of self-contained HTML plus print-to-PDF until explicit enterprise demand appears; `docs/architecture/agentshield-enterprise-research-roadmap.md` now has baseline drift, evidence-pack bundle, redaction, adapter-registry, supply-chain hardening, hashed baseline fingerprints, corpus accuracy recommendation, remediation workflow, env proxy hijack corpus, Mini Shai-Hulud full-campaign package-table, `ci-context.json` provenance, `plugin-cache` confidence, `evidence-pack inspect` readback, `evidence-pack fleet` routing, fleet `reviewItems`, fleet review ticket payloads, policy export, policy promotion, policy promotion `reviewItems`, package-manager hardening Action outputs, policy-promotion Action outputs, hosted consumption of promotion Action outputs, operator-visible promotion output values, hosted promotion judge audit traces, editor-native adapter coverage, and Dependabot closure landed | Next workflow automation should deepen live operator approval/readback after Marketplace/payment gates | | ECC Tools next-level app | Billing audit, PR checks, deep analyzer, sync backlog, evaluator/RAG corpus, analysis-depth readiness, hosted execution planning, hosted CI diagnostics, hosted security evidence review, hosted harness compatibility audit, hosted reference-set evaluation, hosted AI routing/cost review, hosted team backlog routing, hosted depth-plan check-run, PR-comment hosted job dispatch, hosted job result history/check-runs, hosted result status command, status-aware depth-plan recommendations, hosted promotion readiness, hosted promotion output scoring, hosted promotion retrieval planning, hosted promotion judge contract, gated hosted promotion judge execution, hosted promotion judge audit trace, payment-announcement readiness, billing announcement preflight, aggregate production billing KV readback, Marketplace webhook provenance, target-account billing readback, Marketplace-source provenance counts, AgentShield fleet-summary hosted routing, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output hosted telemetry, and operator-visible promotion output values | PRs #26-#43 plus #53-#78 landed with test evidence, including AgentShield evidence-pack gap routing, canonical bundle recognition, supply-chain signature gates, PR draft follow-up Linear tracking, evidence-backed/deep-ready repository classification, the `/api/analysis/depth-plan` hosted job plan, `/api/analysis/jobs/ci-diagnostics`, `/api/analysis/jobs/security-evidence-review`, `/api/analysis/jobs/harness-compatibility-audit`, `/api/analysis/jobs/reference-set-evaluation`, `/api/analysis/jobs/ai-routing-cost-review`, `/api/analysis/jobs/team-backlog-routing`, the `ECC Tools / Hosted Depth Plan` check-run, `/ecc-tools analyze --job ...` PR-comment dispatch, non-blocking per-hosted-job result check-runs backed by 30-day result cache records, `/ecc-tools analyze --job status` cache lookup, cache-aware next-job recommendations in the depth-plan check-run, the `ECC Tools / Hosted Promotion Readiness` corpus-backed PR check-run, deterministic hosted-output scoring against cached completed job artifacts/findings, ranked retrieval/model-prompt planning, the fail-closed `hosted-promotion-judge.v1` request contract, opt-in live model-judge execution behind hosted evidence, entitlement, budget, provider, executor, strict JSON, and citation gates, hosted promotion judge request fingerprints plus allowed-citation audit trails, a fail-closed `/api/billing/readiness` `announcementGate` for native GitHub payments claims, `npm run billing:announcement-gate` plus `--preflight` as the non-secret operator verifier, hosted security findings for AgentShield fleet summaries, an `Evidence` column in hosted finding comments/check-runs, hosted harness findings that route AgentShield fleet target paths to harness owners, ECC-Tools commit `8658951` routing AgentShield policy-promotion Action outputs into hosted security review and promotion-readiness scoring, ECC-Tools commit `16c537f` rendering policy-promotion status/pack/count/digest values directly in hosted security job comments/check-runs, ECC-Tools commit `05d4e82` rendering model-judge audit traces without exposing raw provider output, ECC-Tools commit `91a441b` adding the safe billing announcement preflight path, ECC-Tools commit `eb69412` recording the initial production readback state, ECC-Tools commit `95d0bec` adding `npm run billing:kv-readback` with aggregate account-billing and billing-state records but 0 Marketplace Pro billing-state records, ECC-Tools commit `2859678` requiring webhook-derived Marketplace provenance before announcement readiness, ECC-Tools commit `42653f9` adding Wrangler OAuth readback, ECC-Tools commit `632e059` adding sanitized target-account readback that requires both target key families before `--require-ready` can pass, and ECC-Tools commit `d5f60db` adding sanitized Marketplace plan/action provenance counts; the latest 2026-05-18 live Wrangler OAuth recheck found 256 account-billing records, 256 billing-state records, 197 Marketplace-source records, 4 Marketplace webhook-provenance records, all `Open Source`, and 0 Marketplace Pro records, then updated Linear ITO-61 with the data/provisioning blocker | Next work is create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure target account plus `INTERNAL_API_SECRET`, then run `billing:kv-readback -- --wrangler --wrangler-bin ./node_modules/.bin/wrangler --account --require-ready`, followed by the live announcement gate | | GitGuardian/Dependabot/CodeRabbit-style checks | Non-blocking taxonomy, deterministic follow-up checks, and local supply-chain gates | ECC-Tools risk taxonomy check plus follow-up signals landed, including Skill Quality, Deep Analyzer Evidence, Analyzer Corpus Evidence, RAG/Evaluator Evidence, PR Review/Salvage Evidence, and AgentShield evidence-pack evidence; #1846 added npm registry signature gates; #1848 added the supply-chain incident-response playbook and `pull_request_target` cache-poisoning validator guard; #1851 added the privileged checkout credential-persistence guard; AgentShield #78, JARVIS #13, and ECC-Tools #53 applied the same hardening outside trunk | Current supply-chain gate complete; deeper hosted review features remain future | | Harness-agnostic learning system | Audit, adapter matrix, observability, traces, promotion loop | Audit/adapters/observability gates plus `docs/architecture/evaluator-rag-prototype.md`, `examples/evaluator-rag-prototype/`, and ECC-Tools PR #40 define read-only stale-salvage, billing-readiness, CI-failure-diagnosis, harness-config-quality, AgentShield policy-exception, skill-quality evidence, deep-analyzer evidence, and RAG/evaluator comparison scenarios with trace, report, playbook, verifier, and predictive-check artifacts; ECC-Tools PRs #68-#72 now turn that corpus into a deterministic PR check-run gate with cached hosted-output scoring, ranked retrieval candidates, a model prompt seed, a fail-closed hosted model-judge request contract, and opt-in live model execution behind strict hosted-evidence gates | Deterministic hosted PR check, cached output scoring, retrieval planning, judge contract, and gated model execution integrated | @@ -892,7 +910,7 @@ repo evidence and merge commits. | Release and publication | rc.1 release docs, publication readiness doc | Naming matrix and plugin submission/contact checklist | Before any tag | | Harness OS core | Audit, adapter matrix, observability docs, `ecc2/` | HUD/session-control acceptance spec | Weekly until GA | | Evaluation and RAG | Reference-set validation, harness audit, traces, ECC-Tools corpus | Read-only evaluator/RAG prototype plus stale-salvage, billing-readiness, CI-failure-diagnosis, harness-config-quality, AgentShield policy-exception, skill-quality evidence, deep-analyzer evidence, and RAG/evaluator comparison fixtures; ECC-Tools #68 publishes the corpus as a hosted promotion readiness check-run, #69 scores cached hosted job outputs against the same corpus, #70 emits ranked retrieval candidates plus a model prompt seed, #71 adds a fail-closed hosted model-judge request contract, and #72 executes that judge only when explicitly enabled and backed by hosted retrieval citations; ECC-Tools `16c537f` surfaces policy-promotion Action output values in hosted security comments/checks; ECC-Tools `05d4e82` adds hosted model-judge audit traces with request fingerprints and allowed-citation counts | Marketplace Pro billing-state verification with webhook provenance | -| AgentShield enterprise | AgentShield PR evidence and roadmap notes | Fleet routing landed in #89 after evidence-pack inspect/readback shipped in #88; #90 emits fleet `reviewItems`; #91 exports checksum-backed policy bundles; #92 promotes checksum-verified policies from those bundles into active policy files; #94 adds Zed and VS Code adapter detection, Zed project scan discovery, and `.zed/setup.mjs` persistence IOC coverage; AgentShield `87aec47` adds policy promotion `reviewItems`; `28d08c7` adds package-manager hardening drift detection; `659f569` refreshes workflow action runtime pins; `ee585cd` corrects unsupported npm release-age guidance and keeps enforceable cooldown findings on pnpm/Yarn; `1124535` exposes package-manager hardening Action outputs for CI/hosted routing; `1593925` exposes policy-promotion Action outputs and runtime-smoke job-summary evidence; `840952a` adds fleet review ticket payloads and current Mini Shai-Hulud IOC breadcrumbs; ECC-Tools #76 consumes fleet summaries, #77 surfaces source evidence paths in hosted findings, #78 links fleet routes to harness owners, ECC-Tools `8658951` consumes policy-promotion Action outputs, and ECC-Tools `16c537f` renders operator-visible output values | Deepen live operator approval/readback after Marketplace/payment gates | +| AgentShield enterprise | AgentShield PR evidence and roadmap notes | Fleet routing landed in #89 after evidence-pack inspect/readback shipped in #88; #90 emits fleet `reviewItems`; #91 exports checksum-backed policy bundles; #92 promotes checksum-verified policies from those bundles into active policy files; #94 adds Zed and VS Code adapter detection, Zed project scan discovery, and `.zed/setup.mjs` persistence IOC coverage; #95 closes the `brace-expansion` Dependabot alert with 0 open alerts after merge; AgentShield `87aec47` adds policy promotion `reviewItems`; `28d08c7` adds package-manager hardening drift detection; `659f569` refreshes workflow action runtime pins; `ee585cd` corrects unsupported npm release-age guidance and keeps enforceable cooldown findings on pnpm/Yarn; `1124535` exposes package-manager hardening Action outputs for CI/hosted routing; `1593925` exposes policy-promotion Action outputs and runtime-smoke job-summary evidence; `840952a` adds fleet review ticket payloads and current Mini Shai-Hulud IOC breadcrumbs; ECC-Tools #76 consumes fleet summaries, #77 surfaces source evidence paths in hosted findings, #78 links fleet routes to harness owners, ECC-Tools `8658951` consumes policy-promotion Action outputs, and ECC-Tools `16c537f` renders operator-visible output values | Deepen live operator approval/readback after Marketplace/payment gates | | ECC Tools app | ECC-Tools PR evidence, billing audit, risk taxonomy, evaluator/RAG corpus | ECC-Tools #53 published the supply-chain workflow hardening branch, #54 tracks copy-ready PR drafts in the Linear/project backlog, #55 classifies analysis-depth readiness, #56 exposes the hosted execution plan, #57 executes the first hosted CI diagnostics job, #58 executes the hosted security evidence review job, #59 executes the hosted harness compatibility audit, #60 executes the hosted reference-set evaluation, #61 executes the hosted AI routing/cost review, #62 executes hosted team backlog routing, #63 publishes the hosted depth-plan check-run, #64 dispatches hosted jobs from PR comments, #65 persists hosted result history/check-runs, #66 exposes hosted job status from PR comments, #67 makes depth-plan recommendations cache-aware, #68 publishes hosted promotion readiness from the evaluator/RAG corpus, #69 scores cached hosted job outputs against that corpus, #70 emits ranked retrieval candidates plus a model prompt seed, #71 emits the gated `hosted-promotion-judge.v1` contract without live model calls, #72 adds opt-in live model-judge execution behind hosted-evidence and strict JSON/citation gates, #73 adds a fail-closed native-payments `announcementGate` to billing readiness, #74 adds `npm run billing:announcement-gate` for operator verification, #75 tightens the billing announcement gate for live Marketplace readback, #76 routes AgentShield fleet-summary evidence into hosted security findings, #77 adds source evidence paths to hosted finding output, #78 links AgentShield fleet target paths to hosted harness owner findings, `8658951` routes AgentShield policy-promotion Action outputs into hosted security review and promotion readiness, `16c537f` renders policy-promotion status/pack/count/digest values in hosted security comments/checks, `05d4e82` renders hosted promotion judge request fingerprints plus allowed-citation audit traces, `91a441b` adds billing announcement preflight output for required readback inputs, `eb69412` records the initial production readback state, `95d0bec` adds aggregate `billing:kv-readback` evidence, `2859678` requires Marketplace webhook provenance in billing readiness, `42653f9` adds Wrangler OAuth readback with live aggregate production counts, and `632e059` adds sanitized target-account billing readback for the exact Marketplace test account | Create or verify Marketplace-managed Pro target billing-state with webhook provenance, then live target readback and announcement gate | | Linear progress | Linear project status updates, `docs/architecture/progress-sync-contract.md`, generated `operator:dashboard` output, and this mirror | Status update with queue/evidence/missing gates | Every significant merge batch | diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index bc245c53..2fc85300 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -26,7 +26,7 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-16.md` | Current May 16/17 queue cleanup, recsys skill merge, GateGuard triage, PR #1947 supply-chain protection, AgentShield #87 plugin-cache confidence evidence, AgentShield #88 evidence-pack inspect/readback, AgentShield #89 evidence-pack fleet routing, AgentShield #90 fleet review items, AgentShield #91 policy export, AgentShield #92 policy promotion, ECC-Tools #76 fleet-summary consumption, ECC-Tools #77 hosted finding evidence paths, ECC-Tools #78 harness policy-route linking, dashboard refresh, and combined Node/Rust/release-surface gate evidence through the May 16 mirror | Must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` | May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack protection recheck, npm audit/signature checks, legacy and Linear progress routing, deterministic preview-pack smoke, operator dashboard refresh, Linear sync, and GitHub CI evidence for `27dc2918` | Superseded by the May 18 evidence snapshot; repeat from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, supply-chain recheck, AgentShield evidence mirror, Linear sync, current-head CI/security scan success for `4470e2e6`, and ITO-46 naming/plugin publication closure | Superseded by the May 19 ECC identity, video, and growth evidence snapshot | -| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19/20 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, release approval gate, May 19 operator dashboard, preview-pack smoke digest `531328aaaa53`, 2568-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, PR #2004 Linear readiness evidence sync CI success, PR #2008 supply-chain evidence gate CI success, post-PR #2006 main CI success, PR #2009 project-registry hygiene CI success, post-PR #2009 main CI success, post-PR #2011 GateGuard CI success, post-PR #2013 release-approval-gate CI success, ECC-Tools #79 billing-announcement redaction hardening, ECC-Tools #80-#88 runtime-receipt, AgentShield approval-ID, Linear sync, remediation sync, hosted observability event/status/depth-plan/API readback, AgentShield #94 Zed/VS Code adapter coverage, JARVIS #15/#16 queue/deploy repair, and the May 19/20 Linear sync comments | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | +| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19/20 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, release approval gate, May 19 operator dashboard, preview-pack smoke digest `531328aaaa53`, 2568-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, PR #2004 Linear readiness evidence sync CI success, PR #2008 supply-chain evidence gate CI success, post-PR #2006 main CI success, PR #2009 project-registry hygiene CI success, post-PR #2009 main CI success, post-PR #2011 GateGuard CI success, post-PR #2013 release-approval-gate CI success, PR #2017 AgentShield adapter evidence sync, ECC-Tools #79 billing-announcement redaction hardening, ECC-Tools #80-#88 runtime-receipt, AgentShield approval-ID, Linear sync, remediation sync, hosted observability event/status/depth-plan/API readback, AgentShield #94 Zed/VS Code adapter coverage, AgentShield #95 Dependabot alert closure, JARVIS #15/#16 queue/deploy repair, and the May 19/20 Linear sync comments | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 19 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and adds the current `$1,728/mo` to `$10,000/mo` hypergrowth, video owner-approval, and outbound-pack operating lanes | diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md index 35db4322..0bb0e795 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -8,9 +8,9 @@ social announcement. | Field | Evidence | | --- | --- | -| Upstream main | `3cb8c48e74d7ee9883fd2e6d94d8e5aea7421d8c` | +| Upstream main | `906e06406e95742944ccb05065f95a7e4dd4a036` | | Git remote | `https://github.com/affaan-m/ECC.git` | -| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, PR #2001 owner approval packet addition, PR #2002 owner approval dashboard gate refresh, PR #2004 Linear readiness evidence sync, PR #2005 post-PR #2004 evidence refresh, PR #2008 release supply-chain evidence gate fix, PR #2006 per-project Claude Code adapter, PR #2009 continuous-learning project registry hygiene fix, PR #2011 GateGuard quoted git introspection fix, PR #2013 deterministic release approval gate, ECC-Tools #80-#88 hosted observability/readback batch, and AgentShield #94 Zed/VS Code adapter coverage | +| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, PR #2001 owner approval packet addition, PR #2002 owner approval dashboard gate refresh, PR #2004 Linear readiness evidence sync, PR #2005 post-PR #2004 evidence refresh, PR #2008 release supply-chain evidence gate fix, PR #2006 per-project Claude Code adapter, PR #2009 continuous-learning project registry hygiene fix, PR #2011 GateGuard quoted git introspection fix, PR #2013 deterministic release approval gate, PR #2017 AgentShield adapter evidence sync, ECC-Tools #80-#88 hosted observability/readback batch, AgentShield #94 Zed/VS Code adapter coverage, and AgentShield #95 Dependabot alert closure | | Local status caveat | `git status --short --branch` was clean after pulling `origin/main`; generated evidence files are committed after the source snapshot they describe | The release operator must repeat all publish-facing checks from the exact final @@ -23,7 +23,7 @@ release commit with a strictly clean checkout before publishing. | Platform audit | `node scripts/platform-audit.js --json` | Ready true; tracked repos report 0 open PRs, 0 open issues, 0 discussion maintainer-touch gaps, 0 answerable Q&A gaps, 0 conflicting PRs, and 0 blocking dirty files | | Trunk PRs | `gh pr list --repo affaan-m/ECC --state open --json number,title,url,author --limit 100` | `[]` | | Trunk issues | `gh issue list --repo affaan-m/ECC --state open --json number,title,url,author --limit 100` | `[]` | -| Discussion audit through platform audit | `node scripts/platform-audit.js --json` | `affaan-m/ECC` discussions enabled; 59 sampled after #2003 AURA integration proposal; 0 needing maintainer touch; 0 answerable without accepted answer | +| Discussion audit through platform audit | `node scripts/platform-audit.js --json` | `affaan-m/ECC` discussions enabled; 60 sampled after #2015 setup-location Q&A was answered and accepted; 0 needing maintainer touch; 0 answerable without accepted answer | | Worktree | `git status --short --branch` | `## main...origin/main` | Tracked repositories in the platform audit were: @@ -58,6 +58,7 @@ Tracked repositories in the platform audit were: | PR #2009 | Merged the continuous-learning project registry hygiene fix: non-git hook payloads stay global, no-remote linked worktrees migrate to the main worktree project ID, and `instinct-cli.py projects delete`, `merge`, and `gc` provide operator maintenance commands | | PR #2011 | Merged the GateGuard read-only git introspection tokenizer fix so quoted `git show` pathspecs with spaces are preserved while quoted shell separators stay outside the bypass | | PR #2013 | Merged the deterministic `release:approval-gate` so final publication, package, plugin, video, billing, social, and outbound actions remain blocked until owner decisions and live URL readbacks are complete | +| PR #2017 | Merged the AgentShield #94 evidence mirror as `906e06406e95742944ccb05065f95a7e4dd4a036`, syncing roadmap, publication evidence, preview-pack manifest, and supply-chain incident-response surfaces after full GitHub CI passed | ## Post-Queue-Zero Sync - 2026-05-19 Late Pass @@ -82,13 +83,14 @@ Tracked repositories in the platform audit were: | ECC-Tools #85/#86/#87 | PR #85 merged hosted job observability events as `1637e0f2bfa0a889387f2c20675680ccc5528123`; PR #86 merged hosted status observability readback as `5a9e94d3ff860307c3e7fd9fd065f0de2bd633dd`; PR #87 merged hosted depth-plan observability readback as `508fbc02b63cf1fcb5af2f3624608fa66e53b5d4`. Local validation for the final depth-plan readback slice passed the focused hosted depth-plan route test, full route suite (89/89), typecheck, lint, full ECC-Tools Vitest suite (683/683), and `git diff --check`; GitHub Verify, Security Audit, and Workers Builds passed before merge. | | ECC-Tools #88 | PR #88 merged authenticated hosted observability API readback as `c836ac3fb24ed7e2ae38cd61e41c9651ac9c00f8`. `GET /api/analysis/observability` now summarizes hosted events by event type and job for operator/dashboard readback, skips malformed stale KV records, and the deployment runbook includes the production smoke command. Local verification passed typecheck, lint, full ECC-Tools Vitest suite (686/686), and `git diff --check`; GitHub Verify, Security Audit, and Workers Builds passed before merge. | | AgentShield #94 | PR #94 merged Zed/VS Code adapter coverage as `4caee27acfadb50a4cd024e738b5c3cbd4b0bb03`. AgentShield now reports Zed and VS Code as first-class harness adapters, discovers `.zed/settings.json`, `.zed/tasks.json`, and `.zed` hook-code files, and flags `.zed/setup.mjs` in the AI-tool persistence IOC rule alongside `.vscode/setup.mjs`. Local verification passed typecheck, lint, focused scanner/rule tests, full `npm test` (1822 tests), `npm run build`, and `git diff --check`; GitHub checks passed across GitGuardian, scan suite, self-scan, self-scan examples, Node 18/20/22 CI, CodeRabbit, and Cubic after rerunning a transient artifact-upload failure. | -| Linear roadmap sync | Linear ITO-54 comment `74dcc101-3be5-4173-be13-62b80d54f569` and ECC Platform Roadmap project comment `348ea8f5-2a2d-46d9-a0fe-ed99653e7fe5` record the May 20 hosted observability status/depth-plan readback batch; Linear comments `291e2a4b-06e3-4672-a057-cdb141478161` and `b2d35de0-ca49-44cb-982a-ddec229e7691` add the #88 observability API readback; Linear ITO-49 comment `faed69dd-35f5-469d-acb5-ddde6a70d6a1` and project comment `70187c1e-d481-4181-b418-09bd65d54b5e` add the #94 AgentShield Zed/VS Code adapter evidence; earlier comments on ITO-54, ITO-48, and the project record the #84 hosted remediation sync and #85 hosted observability event emission batches. | +| AgentShield #95 | PR #95 merged the `brace-expansion` Dependabot fix as `25d91f0002214c408da4ceaac7def20bad40ca10`. The lockfile now resolves vulnerable transitive `brace-expansion` 5.x entries to `5.0.6`, local `npm audit --audit-level=moderate` returns 0 vulnerabilities, and `gh api repos/affaan-m/agentshield/dependabot/alerts?state=open` returns `[]`. Local validation passed typecheck, lint, full `npm test` (1822 tests), build, audit, and whitespace checks; GitHub checks passed across Verify Node 18/20/22, self-scan, self-scan examples, Test GitHub Action, GitGuardian, CodeRabbit, and Cubic. | +| Linear roadmap sync | Linear ITO-54 comment `74dcc101-3be5-4173-be13-62b80d54f569` and ECC Platform Roadmap project comment `348ea8f5-2a2d-46d9-a0fe-ed99653e7fe5` record the May 20 hosted observability status/depth-plan readback batch; Linear comments `291e2a4b-06e3-4672-a057-cdb141478161` and `b2d35de0-ca49-44cb-982a-ddec229e7691` add the #88 observability API readback; Linear ITO-49 comment `faed69dd-35f5-469d-acb5-ddde6a70d6a1` and project comment `70187c1e-d481-4181-b418-09bd65d54b5e` add the #94 AgentShield Zed/VS Code adapter evidence; Linear ITO-49 comment `371fc3e4-611f-4d20-a23f-67db1260b418`, ITO-57 comment `bd06e252-15c1-4256-b667-caa3f64f5968`, and project comment `22c2c388-2fd1-4dea-a939-6141f40c9a21` add the #95 AgentShield Dependabot alert closure; earlier comments on ITO-54, ITO-48, and the project record the #84 hosted remediation sync and #85 hosted observability event emission batches. | ## Release And Growth Evidence | Gate | Command | Result | | --- | --- | --- | -| Release-surface tests | `node tests/docs/ecc2-release-surface.test.js` | 27 passed, 0 failed | +| Release-surface tests | `node tests/docs/ecc2-release-surface.test.js` | 28 passed, 0 failed | | Preview-pack smoke | `npm run preview-pack:smoke -- --format json` | Ready true; digest `531328aaaa53`; 32 required artifacts; 5 passed, 0 failed | | Release approval gate | `npm run release:approval-gate -- --format json` | Expected blocked; digest `ef8f49f727b7`; 4 passed, 2 failed; owner decisions and live URL readbacks remain approval-gated | | Operator dashboard | `npm run operator:dashboard -- --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Regenerated from the May 19 `main` baseline with platform audit ready true, 0 tracked PRs, 0 tracked issues, 0 discussion gaps, `$1,728/mo` current MRR, `$10,000/mo` target MRR, the release video suite marked current, and top actions for plugin publication, notifications, outbound approval, AgentShield, and ECC Tools billing | @@ -125,7 +127,7 @@ Tracked repositories in the platform audit were: | Owner approval proof | `owner-approval-packet-2026-05-19.md` centralizes release, package, plugin, video, billing, social, and outbound decision gates | | Business baseline | Hypergrowth command center and partner pack use `$1,728/mo` current MRR, `$10,000/mo` target MRR, and `$8,272/mo` gap | | Operator dashboard | `operator-readiness-dashboard-2026-05-19.md` pulls the growth baseline into the same queue, publication, video, outbound, AgentShield, ECC Tools, Linear, and supply-chain control surface | -| Linear progress proof | Linear project document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` mirrors the post-PR #2002 state and records active lanes for launch materials, AgentShield, ECC Tools deep analysis, observability, and final release publication; Linear document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f` adds the PR #2013 approval gate, ECC-Tools #79 redaction hardening, and JARVIS #15/#16 queue/deploy repair evidence; May 20 Linear comments `74dcc101-3be5-4173-be13-62b80d54f569`, `348ea8f5-2a2d-46d9-a0fe-ed99653e7fe5`, `291e2a4b-06e3-4672-a057-cdb141478161`, `b2d35de0-ca49-44cb-982a-ddec229e7691`, `faed69dd-35f5-469d-acb5-ddde6a70d6a1`, and `70187c1e-d481-4181-b418-09bd65d54b5e` add ECC-Tools #86/#87/#88 hosted observability readback evidence and AgentShield #94 adapter evidence to ITO-54, ITO-49, and the project | +| Linear progress proof | Linear project document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` mirrors the post-PR #2002 state and records active lanes for launch materials, AgentShield, ECC Tools deep analysis, observability, and final release publication; Linear document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f` adds the PR #2013 approval gate, ECC-Tools #79 redaction hardening, and JARVIS #15/#16 queue/deploy repair evidence; May 20 Linear comments `74dcc101-3be5-4173-be13-62b80d54f569`, `348ea8f5-2a2d-46d9-a0fe-ed99653e7fe5`, `291e2a4b-06e3-4672-a057-cdb141478161`, `b2d35de0-ca49-44cb-982a-ddec229e7691`, `faed69dd-35f5-469d-acb5-ddde6a70d6a1`, `70187c1e-d481-4181-b418-09bd65d54b5e`, `371fc3e4-611f-4d20-a23f-67db1260b418`, `bd06e252-15c1-4256-b667-caa3f64f5968`, and `22c2c388-2fd1-4dea-a939-6141f40c9a21` add ECC-Tools #86/#87/#88 hosted observability readback evidence, AgentShield #94 adapter evidence, and AgentShield #95 Dependabot alert closure to ITO-54, ITO-49, ITO-57, and the project | ## Current Publication Blockers @@ -153,11 +155,12 @@ identity, release video suite, preview pack, growth outreach packet, per-project Claude Code adapter surface, continuous-learning project registry hygiene, GateGuard quoted git introspection fix, deterministic release approval gate, ECC-Tools billing-announcement redaction hardening, ECC-Tools hosted -observability readback, AgentShield Zed/VS Code adapter coverage, and JARVIS +observability readback, AgentShield Zed/VS Code adapter coverage, AgentShield +Dependabot alert closure, and JARVIS security/deploy queue repairs are current on May 20, 2026 for ECC `main` -through `3cb8c48e74d7ee9883fd2e6d94d8e5aea7421d8c`, ECC-Tools `main` +through `906e06406e95742944ccb05065f95a7e4dd4a036`, ECC-Tools `main` through `c836ac3fb24ed7e2ae38cd61e41c9651ac9c00f8`, and AgentShield `main` -through `4caee27acfadb50a4cd024e738b5c3cbd4b0bb03`. The remaining video work is owner +through `25d91f0002214c408da4ceaac7def20bad40ca10`. The remaining video work is owner approval, upload, and public URL attachment, not render or QA production. This improves publication readiness but does not replace the approval-gated From 30f60710d4e0424fc70d9bbdc105009db141d9d8 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 21:39:03 -0400 Subject: [PATCH 58/61] Sync Marketplace Pro readback release gate (#2019) * docs: sync marketplace pro readback gate * docs: refresh operator dashboard after readback sync * docs: sanitize marketplace readback summary * docs: refresh operator dashboard after marketplace readback --- docs/ECC-2.0-GA-ROADMAP.md | 23 ++++++++++++------- .../naming-and-publication-matrix.md | 2 +- ...operator-readiness-dashboard-2026-05-19.md | 10 ++++---- .../2.0.0-rc.1/preview-pack-manifest.md | 5 ++-- .../publication-evidence-2026-05-19.md | 9 +++++--- scripts/operator-readiness-dashboard.js | 13 ++++++++++- .../operator-readiness-dashboard.test.js | 6 ++++- 7 files changed, 47 insertions(+), 21 deletions(-) diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index 59b54e75..567853f4 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -463,13 +463,20 @@ As of 2026-05-20: `brace-expansion@5.0.6` and fixed Dependabot alert 44 for CVE-2026-45149; GitHub API reported `state: fixed` at `2026-05-18T19:10:15Z` and current-head CI `26054671308` passed. -- The latest ITO-61 readback retry narrowed the blocker: Wrangler OAuth now - works, the safe aggregate readback has 0 parse failures and still reports 0 - Marketplace Pro records, and `billing:announcement-gate -- --preflight` is - missing the target Marketplace account plus `INTERNAL_API_SECRET`. - Native-payments copy remains blocked until the target Pro readback and live - announcement gate pass. Linear comment - `6904e4fb-bec7-4787-90e2-759f077a628c` records the redacted readback counts. +- ECC-Tools PR #89 merged as `512bca6b99cdaa67058a6aa9a4e7e7f0b1d9873a` + and adds + `npm run billing:kv-readback -- --select-ready-target --require-ready` so + operators can prove a ready Marketplace Pro account without passing or + printing the login. The 2026-05-20 production Wrangler OAuth readback found + ready-like Marketplace Pro records with webhook provenance and 0 parse + failures. The selected target report printed only a stable fingerprint, + confirmed both key families, `marketplace` source, `pro` tier, seat ready, + webhook evidence ready, automatic overage disabled, and 0 blockers. The old + "no Marketplace-managed Pro target billing-state" blocker is cleared. + Native-payments copy remains blocked until the local/internal + `INTERNAL_API_SECRET` bearer-token path is available and the live + `billing:announcement-gate -- --account ` call passes. Linear comment + `f14ed2fe-a219-470c-8119-63429e197027` records the redacted readback counts. - Handoff `ecc-supply-chain-audit-20260513-0645.md` under `~/.cluster-swarm/handoffs/` records the May 13 supply-chain sweep: no active lockfile/manifest hit for @@ -887,7 +894,7 @@ is not complete unless the evidence column exists and has been freshly verified. | Claude and Codex plugin publication | Contact/submission path with required artifacts and status | Publication readiness, naming matrix, and May 12 dry-run evidence document plugin validation, clean-checkout Claude tag/install smoke, and Codex marketplace CLI shape | Needs explicit approval for real tag/push and marketplace submission | | Articles, tweets, and announcements | X thread, LinkedIn copy, GitHub release copy, push checklist, partner/sponsor/talk pack | Draft launch collateral and approval-gated outreach copy exist under rc.1 release docs | Needs URL-backed refresh and human approval before posting or sending | | AgentShield enterprise iteration | Policy gates, SARIF, packs, provenance, corpus, HTML reports, exception lifecycle audit, baseline drift Action/CLI surfaces, evidence-pack redaction, harness adapter registry, editor-native Zed/VS Code adapter coverage, Dependabot alert closure, enterprise research roadmap, supply-chain hardened release path, CI-safe baseline fingerprints, corpus accuracy recommendations, remediation workflow phases, env proxy hijack corpus coverage, Mini Shai-Hulud full-campaign package IOCs, CI-provenance evidence packs, plugin-cache runtime-confidence triage, evidence-pack consumer readback, fleet-level evidence-pack routing, fleet review items, fleet review ticket payloads, checksum-backed policy export, checksum-verified policy promotion, policy promotion review items, package-manager hardening drift detection, npm age-gate guidance correction, workflow action-runtime pin refresh, package-manager hardening Action outputs, policy-promotion Action outputs, ECC-Tools hosted consumption of promotion Action outputs, ECC-Tools operator-visible promotion output values, and ECC-Tools hosted promotion judge audit traces | PRs #53, #55-#64, #67-#69, #78-#92, #94, and #95 landed with test evidence, ECC-Tools #76 consumes the fleet-summary output in hosted security review, #77 surfaces source evidence paths in hosted finding output, and #78 links fleet routes to harness owner review; AgentShield #91 adds `agentshield policy export` bundles for branch-protection review and downstream promotion; AgentShield #92 adds `agentshield policy promote` with digest verification, tamper rejection, explicit pack selection, dry-run review, and JSON output before writing active policy; AgentShield #94 adds Zed/VS Code adapter detection, `.zed/settings.json` and `.zed/tasks.json` scan discovery, and `.zed/setup.mjs` AI-tool persistence IOC coverage; AgentShield #95 clears the `brace-expansion` Dependabot alert with a patched lockfile and 0 open Dependabot alerts after merge; AgentShield commit `87aec47` adds `reviewItems` for digest evidence, owner review, protected rollout PR handoff, and runtime smoke testing with green local and remote CI; AgentShield commit `28d08c7` adds package-manager hardening drift detection for plaintext registry credentials, lifecycle-script enablement, and weak pnpm/Yarn release-age cooldowns with green local and remote CI; AgentShield commit `659f569` refreshes all workflow action runtime pins to SHA-pinned checkout v6.0.2 and setup-node v6.4.0 with green remote CI and no remaining action-runtime deprecation annotation; AgentShield commit `ee585cd` corrects npm release-age guidance by flagging unsupported npm age keys and keeping enforceable cooldown findings on pnpm/Yarn with green local and remote CI; AgentShield commit `1124535` exposes package-manager hardening status/count outputs and a redacted job-summary section for registry credentials, lifecycle scripts, and release-age gates with green local and remote CI; AgentShield commit `1593925` exposes policy-promotion status/count/digest outputs plus job-summary review items for owner approval, protected rollout, and runtime smoke, and marks runtime smoke verified when the same Action job scans with the promoted policy; AgentShield commit `840952a` adds Linear/operator-ready fleet review ticket payloads and expands current Mini Shai-Hulud IOC breadcrumbs with green local and remote CI; ECC-Tools commit `8658951` routes those policy-promotion Action outputs into hosted security review findings and Hosted Promotion Readiness scoring; ECC-Tools commit `16c537f` renders policy-promotion status, pack, review item count, action-required count, and digest in hosted security job comments/check-runs; ECC-Tools commit `05d4e82` renders hosted promotion judge request fingerprints and allowed-citation counts without raw provider output; native PDF export deferred in favor of self-contained HTML plus print-to-PDF until explicit enterprise demand appears; `docs/architecture/agentshield-enterprise-research-roadmap.md` now has baseline drift, evidence-pack bundle, redaction, adapter-registry, supply-chain hardening, hashed baseline fingerprints, corpus accuracy recommendation, remediation workflow, env proxy hijack corpus, Mini Shai-Hulud full-campaign package-table, `ci-context.json` provenance, `plugin-cache` confidence, `evidence-pack inspect` readback, `evidence-pack fleet` routing, fleet `reviewItems`, fleet review ticket payloads, policy export, policy promotion, policy promotion `reviewItems`, package-manager hardening Action outputs, policy-promotion Action outputs, hosted consumption of promotion Action outputs, operator-visible promotion output values, hosted promotion judge audit traces, editor-native adapter coverage, and Dependabot closure landed | Next workflow automation should deepen live operator approval/readback after Marketplace/payment gates | -| ECC Tools next-level app | Billing audit, PR checks, deep analyzer, sync backlog, evaluator/RAG corpus, analysis-depth readiness, hosted execution planning, hosted CI diagnostics, hosted security evidence review, hosted harness compatibility audit, hosted reference-set evaluation, hosted AI routing/cost review, hosted team backlog routing, hosted depth-plan check-run, PR-comment hosted job dispatch, hosted job result history/check-runs, hosted result status command, status-aware depth-plan recommendations, hosted promotion readiness, hosted promotion output scoring, hosted promotion retrieval planning, hosted promotion judge contract, gated hosted promotion judge execution, hosted promotion judge audit trace, payment-announcement readiness, billing announcement preflight, aggregate production billing KV readback, Marketplace webhook provenance, target-account billing readback, Marketplace-source provenance counts, AgentShield fleet-summary hosted routing, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output hosted telemetry, and operator-visible promotion output values | PRs #26-#43 plus #53-#78 landed with test evidence, including AgentShield evidence-pack gap routing, canonical bundle recognition, supply-chain signature gates, PR draft follow-up Linear tracking, evidence-backed/deep-ready repository classification, the `/api/analysis/depth-plan` hosted job plan, `/api/analysis/jobs/ci-diagnostics`, `/api/analysis/jobs/security-evidence-review`, `/api/analysis/jobs/harness-compatibility-audit`, `/api/analysis/jobs/reference-set-evaluation`, `/api/analysis/jobs/ai-routing-cost-review`, `/api/analysis/jobs/team-backlog-routing`, the `ECC Tools / Hosted Depth Plan` check-run, `/ecc-tools analyze --job ...` PR-comment dispatch, non-blocking per-hosted-job result check-runs backed by 30-day result cache records, `/ecc-tools analyze --job status` cache lookup, cache-aware next-job recommendations in the depth-plan check-run, the `ECC Tools / Hosted Promotion Readiness` corpus-backed PR check-run, deterministic hosted-output scoring against cached completed job artifacts/findings, ranked retrieval/model-prompt planning, the fail-closed `hosted-promotion-judge.v1` request contract, opt-in live model-judge execution behind hosted evidence, entitlement, budget, provider, executor, strict JSON, and citation gates, hosted promotion judge request fingerprints plus allowed-citation audit trails, a fail-closed `/api/billing/readiness` `announcementGate` for native GitHub payments claims, `npm run billing:announcement-gate` plus `--preflight` as the non-secret operator verifier, hosted security findings for AgentShield fleet summaries, an `Evidence` column in hosted finding comments/check-runs, hosted harness findings that route AgentShield fleet target paths to harness owners, ECC-Tools commit `8658951` routing AgentShield policy-promotion Action outputs into hosted security review and promotion-readiness scoring, ECC-Tools commit `16c537f` rendering policy-promotion status/pack/count/digest values directly in hosted security job comments/check-runs, ECC-Tools commit `05d4e82` rendering model-judge audit traces without exposing raw provider output, ECC-Tools commit `91a441b` adding the safe billing announcement preflight path, ECC-Tools commit `eb69412` recording the initial production readback state, ECC-Tools commit `95d0bec` adding `npm run billing:kv-readback` with aggregate account-billing and billing-state records but 0 Marketplace Pro billing-state records, ECC-Tools commit `2859678` requiring webhook-derived Marketplace provenance before announcement readiness, ECC-Tools commit `42653f9` adding Wrangler OAuth readback, ECC-Tools commit `632e059` adding sanitized target-account readback that requires both target key families before `--require-ready` can pass, and ECC-Tools commit `d5f60db` adding sanitized Marketplace plan/action provenance counts; the latest 2026-05-18 live Wrangler OAuth recheck found 256 account-billing records, 256 billing-state records, 197 Marketplace-source records, 4 Marketplace webhook-provenance records, all `Open Source`, and 0 Marketplace Pro records, then updated Linear ITO-61 with the data/provisioning blocker | Next work is create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure target account plus `INTERNAL_API_SECRET`, then run `billing:kv-readback -- --wrangler --wrangler-bin ./node_modules/.bin/wrangler --account --require-ready`, followed by the live announcement gate | +| ECC Tools next-level app | Billing audit, PR checks, deep analyzer, sync backlog, evaluator/RAG corpus, hosted promotion judge audit trace, native-payments readback, ready Marketplace Pro target selection, hosted observability, AgentShield fleet-summary hosted routing, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output hosted telemetry, and operator-visible promotion output values | PRs #26-#43 plus #53-#89 landed with test evidence across hosted analysis, hosted promotion readiness, model-judge execution, native-payments announcement gating, AgentShield evidence consumption, hosted remediation/Linear sync, hosted observability readback, and ready Marketplace Pro target selection; ECC-Tools #89 merged as `512bca6` after Verify, Security Audit, and Workers Builds passed, and the 2026-05-20 production Wrangler OAuth readback found ready-like Marketplace Pro records with webhook provenance, selected a target with both key families, and reported 0 blockers without printing the login | Next work is obtain or rotate the local/internal `INTERNAL_API_SECRET` bearer-token path, then run the live billing announcement gate for the selected Marketplace Pro target before publishing native-payments copy | | GitGuardian/Dependabot/CodeRabbit-style checks | Non-blocking taxonomy, deterministic follow-up checks, and local supply-chain gates | ECC-Tools risk taxonomy check plus follow-up signals landed, including Skill Quality, Deep Analyzer Evidence, Analyzer Corpus Evidence, RAG/Evaluator Evidence, PR Review/Salvage Evidence, and AgentShield evidence-pack evidence; #1846 added npm registry signature gates; #1848 added the supply-chain incident-response playbook and `pull_request_target` cache-poisoning validator guard; #1851 added the privileged checkout credential-persistence guard; AgentShield #78, JARVIS #13, and ECC-Tools #53 applied the same hardening outside trunk | Current supply-chain gate complete; deeper hosted review features remain future | | Harness-agnostic learning system | Audit, adapter matrix, observability, traces, promotion loop | Audit/adapters/observability gates plus `docs/architecture/evaluator-rag-prototype.md`, `examples/evaluator-rag-prototype/`, and ECC-Tools PR #40 define read-only stale-salvage, billing-readiness, CI-failure-diagnosis, harness-config-quality, AgentShield policy-exception, skill-quality evidence, deep-analyzer evidence, and RAG/evaluator comparison scenarios with trace, report, playbook, verifier, and predictive-check artifacts; ECC-Tools PRs #68-#72 now turn that corpus into a deterministic PR check-run gate with cached hosted-output scoring, ranked retrieval candidates, a model prompt seed, a fail-closed hosted model-judge request contract, and opt-in live model execution behind strict hosted-evidence gates | Deterministic hosted PR check, cached output scoring, retrieval planning, judge contract, and gated model execution integrated | | Linear roadmap is detailed | Linear project document/comments plus repo mirror | Repo mirror exists and issue creation works again; the May 19 sync adds post-PR #2002 document `ecc-may-19-post-pr-2002-sync-64cef8f668e0`, project comment `a6411e3a-8c8e-4a58-adba-687e77d4c543`, ITO-44/47/48/49/51/54/56 issue comments, and In Progress state for ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56; the late-pass batch adds document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f`, project comment `d42bf0e2-7a8e-4934-9f3f-e281498ee805`, and ITO-44/50/54/56/61 comments for PR #2013, ECC-Tools #79, and JARVIS #15/#16 because project status updates are disabled in the workspace | Needs recurring document/comment updates after each significant merge batch | diff --git a/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md b/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md index f04e8c5d..97009af8 100644 --- a/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md +++ b/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md @@ -71,7 +71,7 @@ Reason: | Codex repo marketplace | Local and GitHub-ref temp-home marketplace add smokes passed on Codex CLI `0.131.0` | `.codex-plugin/plugin.json`, `.agents/plugins/marketplace.json`, repo/personal marketplace evidence | Plugin owner | Official Plugin Directory listing requires OpenAI submission/listing evidence | | Codex official Plugin Directory | OpenAI docs describe the curated official directory; ECC has not submitted or received listing evidence | Directory submission link or OpenAI approval path once available | Plugin owner | Track as an ITO-56/ITO-46 follow-up; do not claim an official listing | | OpenCode package | `npm run build:opencode` passed | Built `.opencode` package metadata inside npm tarball | Package owner | No separate public plugin channel identified; follows npm | -| Billing/native payments | Announcement remains blocked by ITO-61 | Marketplace Pro target readback, webhook provenance, `INTERNAL_API_SECRET`, announcement gate | ECC Tools owner | Do not include native-payments claim in rc.1 announcement | +| Billing/native payments | Marketplace Pro target readback passed; announcement remains blocked by ITO-61 | 2026-05-20 selected-target readback, webhook provenance, `INTERNAL_API_SECRET`, live announcement gate | ECC Tools owner | Do not include native-payments claim in rc.1 announcement until the live gate passes | | Social/longform copy | Drafts exist | Final live GitHub, npm, Claude, Codex, billing URLs | Release owner | Publish only after release/package/plugin URLs exist | ## Package Rename After rc.1 diff --git a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md index c8a1b172..517749bb 100644 --- a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md @@ -2,8 +2,8 @@ This dashboard is generated by `npm run operator:dashboard`. It is an operator snapshot, not release approval. -Generated: 2026-05-19T17:37:31.630Z -Commit: 14d88e517b0c56a80c1a6392b1cde2474948d29f +Generated: 2026-05-20T01:28:52.541Z +Commit: a2bbc45504ff55f09e9e06be0e253d72f3c54f90 Status: work remaining ## Current Status @@ -42,7 +42,7 @@ Growth lanes: GitHub Sponsors and OSS partner sponsors; ECC Tools Pro subscripti | Produce the ECC 2.0 release video suite | docs/releases/2.0.0-rc.1/video-suite-production.md and npm run release:video-suite | current | video-suite gate is ready with 15/15 source assets, 13/13 suite artifacts, 12/12 publish candidates, primary self-eval, and zero detected black-frame segments recorded in May 19 evidence | final owner approval, upload, and public video URLs remain approval-gated | | Prepare sponsor, partner, consulting, podcast, talk, and Discussion copy | docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md | in_progress | sponsor outbound, platform partner DM, consulting intro, talk/podcast pitch, GitHub Discussion announcement, CTA hooks, and do-not-send gate are drafted | replace final URLs after publication gates, then get explicit approval before outbound or personal-account posts | | Advance AgentShield enterprise iteration | AgentShield PR evidence plus enterprise roadmap | in_progress | AgentShield policy promotion `reviewItems` landed in `87aec47`; package-manager hardening drift detection landed in `28d08c7`; workflow action runtime pins were refreshed in `659f569`; npm age-gate guidance was corrected in `ee585cd`; package-manager hardening Action outputs landed in `1124535`; policy-promotion Action outputs and runtime-smoke job-summary evidence landed in `1593925`; fleet review ticket payloads and current Mini Shai-Hulud IOC breadcrumbs landed in `840952a`; ECC-Tools consumes those outputs in `8658951`, surfaces operator-readable status/pack/count/digest telemetry in `16c537f`, and renders hosted promotion judge audit traces in `05d4e82`; all are mirrored in the GA roadmap | deepen live operator approval/readback after Marketplace/payment gates | -| Advance ECC Tools native payments and AI-native harness-agnostic app | ECC Tools PR evidence, billing gate, hosted analysis lanes | in_progress | billing announcement gate, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler OAuth readback, target-account billing readback, provenance-aware Marketplace billing-state gates, sanitized Marketplace plan/action provenance counts, hosted team-learning feedback controls, and ECC-Tools Dependabot alert remediation are mirrored in the GA roadmap | create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure the target account and INTERNAL_API_SECRET, then rerun target readback and the live announcement gate | +| Advance ECC Tools native payments and AI-native harness-agnostic app | ECC Tools PR evidence, billing gate, hosted analysis lanes | in_progress | billing announcement gate, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler OAuth readback, target-account billing readback, provenance-aware Marketplace billing-state gates, sanitized Marketplace plan/action provenance counts, ready Marketplace Pro target selection, hosted team-learning feedback controls, and ECC-Tools Dependabot alert remediation are mirrored in the GA roadmap | obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, then run the live billing announcement gate for the selected Marketplace Pro target before publishing native-payments copy | | Audit, prune, or attach legacy work | docs/stale-pr-salvage-ledger.md and legacy inventory | current | legacy salvage ledger and inventory are current; all localization tails are attached to Linear ITO-55 for manual language-owner review | repeat legacy scan before release | | Keep Linear roadmap detailed and progress tracking synchronized | Linear project mirror plus progress-sync contract | current | Linear live sync is current with the May 19 post-PR #2002 sync document, project comment, and active issue-lane updates; progress-sync contract defines the file-backed work-items/status path | repeat Linear/project status update and local work-items sync after each significant merge batch | | Provide ECC 2.0 observability for self-use | observability readiness gate | complete | observability:ready command and readiness doc exist | runtime/dashboard implementation can continue after release gates | @@ -54,7 +54,7 @@ Growth lanes: GitHub Sponsors and OSS partner sponsors; ECC Tools Pro subscripti - `release-notes-and-notifications`: final live release/npm/plugin/billing URLs and publish approval still pending - `partner-sponsor-talks-pack`: replace final URLs after publication gates, then get explicit approval before outbound or personal-account posts - `agentshield-enterprise-iteration`: deepen live operator approval/readback after Marketplace/payment gates -- `ecc-tools-next-level`: create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure the target account and INTERNAL_API_SECRET, then rerun target readback and the live announcement gate +- `ecc-tools-next-level`: obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, then run the live billing announcement gate for the selected Marketplace Pro target before publishing native-payments copy ## Next Work Order @@ -63,4 +63,4 @@ Growth lanes: GitHub Sponsors and OSS partner sponsors; ECC Tools Pro subscripti 3. Review the owner-approved primary launch video candidates, choose the final cuts, upload after approval, and attach public video URLs to the release pack. 4. Replace final release, npm, plugin, billing, and video URLs in the partner/sponsor/talk pack, then get explicit approval before outbound. 5. Repeat ITO-57 Linear/project status sync after the next significant merge batch or advisory-source refresh. -6. Create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure the target account and INTERNAL_API_SECRET, then rerun target readback and the live announcement gate before publishing native-payments copy. +6. Obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, then run the live billing announcement gate for the selected Marketplace Pro target before publishing native-payments copy. diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index 2fc85300..341de114 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -110,8 +110,9 @@ surfaces exist and are recorded in a final evidence file: - Codex repo-marketplace distribution evidence plus official Plugin Directory availability status; - final announcement URLs in X, LinkedIn, GitHub release, and longform copy; -- ECC Tools billing/product readiness evidence before any native-payments - announcement copy is published. +- ECC Tools billing/product readiness evidence, the local/internal announcement + bearer-token path, and a live announcement gate pass before any + native-payments announcement copy is published. ## Result diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md index 0bb0e795..2d0998d1 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -138,9 +138,12 @@ Tracked repositories in the platform audit were: - Codex repo-marketplace distribution is verified by prior evidence, but official Plugin Directory publishing remains blocked on OpenAI submission or listing evidence. -- ECC Tools billing/native-payments copy remains blocked until a Marketplace - Pro purchase/webhook path writes ready production billing state for a target - Marketplace test account and the billing announcement gate passes. +- ECC Tools billing/native-payments copy remains blocked until the + local/internal `INTERNAL_API_SECRET` bearer-token path is available and the + billing announcement gate passes for the ready Marketplace Pro target. + ECC-Tools PR #89 (`512bca6`) added `billing:kv-readback -- + --select-ready-target --require-ready`; its 2026-05-20 production run cleared + the old missing-target-state blocker without printing the account login. - Release notes, X, LinkedIn, GitHub release, GitHub Discussion, longform copy, sponsor outreach, partner outreach, consulting copy, conference pitches, and podcast pitches still need final live URLs plus human approval before posting diff --git a/scripts/operator-readiness-dashboard.js b/scripts/operator-readiness-dashboard.js index 365f543f..fa42a662 100644 --- a/scripts/operator-readiness-dashboard.js +++ b/scripts/operator-readiness-dashboard.js @@ -342,6 +342,11 @@ function agentShieldEnterpriseEvidence(roadmap) { } function eccToolsNextLevelEvidence(roadmap) { + if (roadmap.includes('select-ready-target') + || roadmap.includes('f14ed2fe-a219-470c-8119-63429e197027')) { + return 'billing announcement gate, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler OAuth readback, target-account billing readback, provenance-aware Marketplace billing-state gates, sanitized Marketplace plan/action provenance counts, ready Marketplace Pro target selection, hosted team-learning feedback controls, and ECC-Tools Dependabot alert remediation are mirrored in the GA roadmap'; + } + if (roadmap.includes('69ca535') || roadmap.includes('team feedback controls') || roadmap.includes('e56fc1a')) { @@ -387,6 +392,12 @@ function eccToolsNextLevelEvidence(roadmap) { } function eccToolsNextLevelGap(roadmap) { + if (roadmap.includes('select-ready-target') + || roadmap.includes('f14ed2fe-a219-470c-8119-63429e197027') + || roadmap.includes('old "no Marketplace-managed Pro target billing-state" blocker is cleared')) { + return 'obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, then run the live billing announcement gate for the selected Marketplace Pro target before publishing native-payments copy'; + } + if (roadmap.includes('1Password CLI authorization timed out') || roadmap.includes('Cloudflare API auth returned `Authentication error [code: 10000]`')) { return 'authorize Cloudflare API or 1Password CLI access, configure the target Marketplace Pro account and INTERNAL_API_SECRET, create or replay Marketplace Pro webhook state, then rerun target readback and the live announcement gate'; @@ -989,7 +1000,7 @@ function buildReport(options) { releaseVideoWorkOrder, 'Replace final release, npm, plugin, billing, and video URLs in the partner/sponsor/talk pack, then get explicit approval before outbound.', 'Repeat ITO-57 Linear/project status sync after the next significant merge batch or advisory-source refresh.', - 'Create or verify Marketplace-managed Pro target billing-state with webhook provenance, configure the target account and INTERNAL_API_SECRET, then rerun target readback and the live announcement gate before publishing native-payments copy.', + 'Obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, then run the live billing announcement gate for the selected Marketplace Pro target before publishing native-payments copy.', ], }; } diff --git a/tests/scripts/operator-readiness-dashboard.test.js b/tests/scripts/operator-readiness-dashboard.test.js index d70f03ea..5e943d0b 100644 --- a/tests/scripts/operator-readiness-dashboard.test.js +++ b/tests/scripts/operator-readiness-dashboard.test.js @@ -77,6 +77,9 @@ function seedRepo(rootDir, overrides = {}) { '42653f9', 'target account billing readback', '632e059', + 'select-ready-target', + 'f14ed2fe-a219-470c-8119-63429e197027', + 'old "no Marketplace-managed Pro target billing-state" blocker is cleared', '69ca535', 'team feedback controls', 'e56fc1a', @@ -347,7 +350,7 @@ function runTests() { ))); assert.ok(report.requirements.some(item => ( item.id === 'ecc-tools-next-level' - && item.gap === 'authorize Cloudflare API or 1Password CLI access, configure the target Marketplace Pro account and INTERNAL_API_SECRET, create or replay Marketplace Pro webhook state, then rerun target readback and the live announcement gate' + && item.gap === 'obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, then run the live billing announcement gate for the selected Marketplace Pro target before publishing native-payments copy' && item.evidence.includes('operator-visible promotion output details') && item.evidence.includes('hosted promotion judge audit traces') && item.evidence.includes('billing announcement preflight') @@ -355,6 +358,7 @@ function runTests() { && item.evidence.includes('Wrangler OAuth readback') && item.evidence.includes('target-account billing readback') && item.evidence.includes('provenance-aware Marketplace billing-state gates') + && item.evidence.includes('ready Marketplace Pro target selection') && item.evidence.includes('hosted team-learning feedback controls') && item.evidence.includes('ECC-Tools Dependabot alert remediation') ))); From c2471fe5c535310f8a8008c9ed7ea9f6757b33f2 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 22:09:45 -0400 Subject: [PATCH 59/61] docs: sync selected-target announcement gate (#2020) --- docs/ECC-2.0-GA-ROADMAP.md | 55 +++++++++++----- .../naming-and-publication-matrix.md | 2 +- ...operator-readiness-dashboard-2026-05-20.md | 66 +++++++++++++++++++ .../2.0.0-rc.1/preview-pack-manifest.md | 7 +- .../publication-evidence-2026-05-19.md | 30 +++++++-- .../2.0.0-rc.1/publication-readiness.md | 6 +- .../release-url-ledger-2026-05-19.md | 3 +- scripts/operator-readiness-dashboard.js | 25 +++++-- scripts/platform-audit.js | 4 +- scripts/preview-pack-smoke.js | 1 + tests/docs/ecc2-release-surface.test.js | 8 ++- .../operator-readiness-dashboard.test.js | 23 ++++++- tests/scripts/platform-audit.test.js | 2 +- 13 files changed, 190 insertions(+), 42 deletions(-) create mode 100644 docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index 567853f4..04034de3 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -46,6 +46,14 @@ partner/sponsor funnel, consulting/talk funnel, and social launch plan. moving transitive `brace-expansion` 5.x lockfile entries to `5.0.6`; the post-merge Dependabot open-alert API now returns `[]`, and local `npm audit --audit-level=moderate` returns 0 vulnerabilities. +- ECC PR #2019 merged the Marketplace Pro selected-target release-gate sync + into this repo as `30f60710d4e0424fc70d9bbdc105009db141d9d8`. The post-merge + main CI run `26135974576` completed green across lint, coverage, security, + validation, and the full OS/package-manager matrix. +- ECC-Tools PR #90 added the selected-target official announcement gate for + `billing:announcement-gate -- --select-ready-target`; safe production + preflight no longer requires a raw GitHub login and now blocks only on the + local/internal `INTERNAL_API_SECRET` input before live execution. - Linear ITO-54 and the ECC Platform Roadmap now have the May 20 ECC-Tools hosted observability update comments `74dcc101-3be5-4173-be13-62b80d54f569` and @@ -58,6 +66,10 @@ partner/sponsor funnel, consulting/talk funnel, and social launch plan. ITO-49 comment `371fc3e4-611f-4d20-a23f-67db1260b418`, ITO-57 comment `bd06e252-15c1-4256-b667-caa3f64f5968`, and project comment `22c2c388-2fd1-4dea-a939-6141f40c9a21`. +- Linear ITO-61 and the ECC Platform Roadmap now have the May 20 Marketplace + Pro release-gate comments `467d148a-712a-4777-aad9-95593e9f1739` and + `7642ee9c-3107-400c-a229-53e2895a8914`, recording ECC-Tools #89, ECC #2019, + the green post-merge CI run, and the remaining internal bearer-token gate. ## 2026-05-19 Delta @@ -132,8 +144,8 @@ As of 2026-05-20: - `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` records the current May 19 queue-zero state, canonical ECC identity merge, release video suite gate, partner/sponsor/talk outreach pack, owner approval packet - (`owner-approval-packet-2026-05-19.md`), preview-pack smoke digest - `531328aaaa53`, local 2568-test suite, PR #2001 merge and GitHub Actions run + (`owner-approval-packet-2026-05-19.md`), current preview-pack smoke digest + `eebb8a66c33e`, local 2568-test suite, PR #2001 merge and GitHub Actions run `26102500291` success, PR #2002's owner-approval dashboard gate refresh and GitHub Actions run `26103853507`, PR #2004's Linear readiness evidence sync and GitHub Actions run `26105012698`, plus PR #2005's post-PR #2004 @@ -174,14 +186,14 @@ As of 2026-05-20: (1822 tests), build, and whitespace checks; GitHub checks passed across Verify Node 18/20/22, self-scan, self-scan examples, Test GitHub Action, GitGuardian, CodeRabbit, and Cubic. -- `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` +- `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md` regenerates the ITO-44 prompt-to-artifact dashboard from live platform audit evidence: PR queue, issue queue, discussion queue, local worktree gate, dashboard generation, and supply-chain loop are current; the dashboard now also tracks the `$1,728/mo` to `$10,000/mo` hypergrowth baseline, release video-suite lane, partner/sponsor/talk outbound pack, and owner approval - packet; publication, plugin, billing, AgentShield, ECC Tools, and final - outbound approval remain the next work. + packet; publication, plugin, billing, AgentShield, ECC Tools, Linear release + gate sync, and final outbound approval remain the next work. - `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` records the May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack @@ -472,11 +484,20 @@ As of 2026-05-20: failures. The selected target report printed only a stable fingerprint, confirmed both key families, `marketplace` source, `pro` tier, seat ready, webhook evidence ready, automatic overage disabled, and 0 blockers. The old - "no Marketplace-managed Pro target billing-state" blocker is cleared. - Native-payments copy remains blocked until the local/internal - `INTERNAL_API_SECRET` bearer-token path is available and the live - `billing:announcement-gate -- --account ` call passes. Linear comment - `f14ed2fe-a219-470c-8119-63429e197027` records the redacted readback counts. + "no Marketplace-managed Pro target billing-state" blocker is cleared. Linear + comment `f14ed2fe-a219-470c-8119-63429e197027` records the redacted readback + counts. +- ECC-Tools PR #90 merged as + `16a5bb33ee5ce7c31d2ad8d041e5afac03308f05` after Verify, Security Audit, + and Workers Builds passed. It adds the selected-target official announcement + gate through `/api/billing/readiness?selectReadyTarget=1` and + `npm run billing:announcement-gate -- --select-ready-target`, so operators no + longer need to pass or print a raw GitHub login for the official + native-payments gate. The 2026-05-20 safe production preflight requested a + selected ready target and narrowed the remaining blocker to the missing + local/internal `INTERNAL_API_SECRET` bearer token. Native-payments copy remains + blocked until that token path is available and the live + `billing:announcement-gate -- --select-ready-target` call passes. - Handoff `ecc-supply-chain-audit-20260513-0645.md` under `~/.cluster-swarm/handoffs/` records the May 13 supply-chain sweep: no active lockfile/manifest hit for @@ -888,13 +909,13 @@ is not complete unless the evidence column exists and has been freshly verified. | Manage repository discussions | Repo-family discussion recheck plus response playbook | Platform audit reports 0 discussion maintainer-touch gaps and 0 answerable Q&A missing accepted answers; trunk has 59 total discussions after #2003 was routed with a maintainer response; `docs/architecture/discussion-response-playbook.md` distinguishes support, maintainer coordination, stale/concluded, release, informational, and security-sensitive response paths | Complete | | Manage PR discussions | PR review/comment closure plus merge/close state | ECC #1990-#2013 merged through the harness audit, canonical identity, release video suite, growth outreach, evidence refresh, visual QA, suite-count, owner-approval packet, owner-approval dashboard gate, Linear readiness evidence, supply-chain evidence gate, per-project Claude Code adapter, continuous-learning project-registry hygiene, GateGuard quoted git introspection, and deterministic release-approval gate batch; ECC-Tools #79 and JARVIS #15/#16 also merged; no open tracked PRs remain | Complete | | Salvage useful stale work | `docs/stale-pr-salvage-ledger.md` plus `docs/legacy-artifact-inventory.md` | Ledger records salvaged, superseded, skipped, and manual-review tails; #1815-#1818 added cost tracking, skill scout, frontend design guidance, code-reviewer false-positive guardrails, and the May 12 gap pass; #1687, #1609, #1563, #1564, and #1565 localization tails are attached to Linear ITO-55 for language-owner review and no automatic import remains release-blocking | Complete; repeat legacy scan before release | -| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 19 evidence records queue-zero state, canonical ECC identity, release video suite, growth outreach pack, owner approval packet, local 2568-test suite, PR #2001 merge and GitHub Actions run `26102500291`, PR #2002 owner-approval dashboard gate refresh and GitHub Actions run `26103853507`, PR #2004 Linear readiness evidence sync and GitHub Actions run `26105012698`, PR #2008 supply-chain evidence gate CI run `26108473648`, post-PR #2006 main CI run `26109953093`, PR #2009 project-registry hygiene GitHub Actions run `26111313938`, post-PR #2009 main CI run `26111946778`, post-PR #2011 GateGuard main CI run `26113695068`, post-PR #2013 release-approval main CI run `26128749863`, May 19 operator dashboard, `owner-approval-packet-2026-05-19.md`, `release-approval-gate.js`, and preview-pack smoke digest `531328aaaa53` | Needs final release approval | +| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 19/20 evidence records queue-zero state, canonical ECC identity, release video suite, growth outreach pack, owner approval packet, local 2568-test suite, PR #2001 merge and GitHub Actions run `26102500291`, PR #2002 owner-approval dashboard gate refresh and GitHub Actions run `26103853507`, PR #2004 Linear readiness evidence sync and GitHub Actions run `26105012698`, PR #2008 supply-chain evidence gate CI run `26108473648`, post-PR #2006 main CI run `26109953093`, PR #2009 project-registry hygiene GitHub Actions run `26111313938`, post-PR #2009 main CI run `26111946778`, post-PR #2011 GateGuard main CI run `26113695068`, post-PR #2013 release-approval main CI run `26128749863`, post-PR #2019 main CI run `26135974576`, May 20 operator dashboard, `owner-approval-packet-2026-05-19.md`, `release-approval-gate.js`, and preview-pack smoke digest `eebb8a66c33e` | Needs final release approval | | Hermes specialized skills included safely | Hermes setup/import docs and sanitized skill surface | Hermes setup and import playbook are public; secrets stay local | Needs final release review | | Naming and rename readiness | Naming matrix across package/plugin/docs/social surfaces | `docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md` records current package, repo, Claude plugin, Codex plugin, OpenCode, and npm availability evidence | Complete for rc.1; post-rc rename remains future work | | Claude and Codex plugin publication | Contact/submission path with required artifacts and status | Publication readiness, naming matrix, and May 12 dry-run evidence document plugin validation, clean-checkout Claude tag/install smoke, and Codex marketplace CLI shape | Needs explicit approval for real tag/push and marketplace submission | | Articles, tweets, and announcements | X thread, LinkedIn copy, GitHub release copy, push checklist, partner/sponsor/talk pack | Draft launch collateral and approval-gated outreach copy exist under rc.1 release docs | Needs URL-backed refresh and human approval before posting or sending | | AgentShield enterprise iteration | Policy gates, SARIF, packs, provenance, corpus, HTML reports, exception lifecycle audit, baseline drift Action/CLI surfaces, evidence-pack redaction, harness adapter registry, editor-native Zed/VS Code adapter coverage, Dependabot alert closure, enterprise research roadmap, supply-chain hardened release path, CI-safe baseline fingerprints, corpus accuracy recommendations, remediation workflow phases, env proxy hijack corpus coverage, Mini Shai-Hulud full-campaign package IOCs, CI-provenance evidence packs, plugin-cache runtime-confidence triage, evidence-pack consumer readback, fleet-level evidence-pack routing, fleet review items, fleet review ticket payloads, checksum-backed policy export, checksum-verified policy promotion, policy promotion review items, package-manager hardening drift detection, npm age-gate guidance correction, workflow action-runtime pin refresh, package-manager hardening Action outputs, policy-promotion Action outputs, ECC-Tools hosted consumption of promotion Action outputs, ECC-Tools operator-visible promotion output values, and ECC-Tools hosted promotion judge audit traces | PRs #53, #55-#64, #67-#69, #78-#92, #94, and #95 landed with test evidence, ECC-Tools #76 consumes the fleet-summary output in hosted security review, #77 surfaces source evidence paths in hosted finding output, and #78 links fleet routes to harness owner review; AgentShield #91 adds `agentshield policy export` bundles for branch-protection review and downstream promotion; AgentShield #92 adds `agentshield policy promote` with digest verification, tamper rejection, explicit pack selection, dry-run review, and JSON output before writing active policy; AgentShield #94 adds Zed/VS Code adapter detection, `.zed/settings.json` and `.zed/tasks.json` scan discovery, and `.zed/setup.mjs` AI-tool persistence IOC coverage; AgentShield #95 clears the `brace-expansion` Dependabot alert with a patched lockfile and 0 open Dependabot alerts after merge; AgentShield commit `87aec47` adds `reviewItems` for digest evidence, owner review, protected rollout PR handoff, and runtime smoke testing with green local and remote CI; AgentShield commit `28d08c7` adds package-manager hardening drift detection for plaintext registry credentials, lifecycle-script enablement, and weak pnpm/Yarn release-age cooldowns with green local and remote CI; AgentShield commit `659f569` refreshes all workflow action runtime pins to SHA-pinned checkout v6.0.2 and setup-node v6.4.0 with green remote CI and no remaining action-runtime deprecation annotation; AgentShield commit `ee585cd` corrects npm release-age guidance by flagging unsupported npm age keys and keeping enforceable cooldown findings on pnpm/Yarn with green local and remote CI; AgentShield commit `1124535` exposes package-manager hardening status/count outputs and a redacted job-summary section for registry credentials, lifecycle scripts, and release-age gates with green local and remote CI; AgentShield commit `1593925` exposes policy-promotion status/count/digest outputs plus job-summary review items for owner approval, protected rollout, and runtime smoke, and marks runtime smoke verified when the same Action job scans with the promoted policy; AgentShield commit `840952a` adds Linear/operator-ready fleet review ticket payloads and expands current Mini Shai-Hulud IOC breadcrumbs with green local and remote CI; ECC-Tools commit `8658951` routes those policy-promotion Action outputs into hosted security review findings and Hosted Promotion Readiness scoring; ECC-Tools commit `16c537f` renders policy-promotion status, pack, review item count, action-required count, and digest in hosted security job comments/check-runs; ECC-Tools commit `05d4e82` renders hosted promotion judge request fingerprints and allowed-citation counts without raw provider output; native PDF export deferred in favor of self-contained HTML plus print-to-PDF until explicit enterprise demand appears; `docs/architecture/agentshield-enterprise-research-roadmap.md` now has baseline drift, evidence-pack bundle, redaction, adapter-registry, supply-chain hardening, hashed baseline fingerprints, corpus accuracy recommendation, remediation workflow, env proxy hijack corpus, Mini Shai-Hulud full-campaign package-table, `ci-context.json` provenance, `plugin-cache` confidence, `evidence-pack inspect` readback, `evidence-pack fleet` routing, fleet `reviewItems`, fleet review ticket payloads, policy export, policy promotion, policy promotion `reviewItems`, package-manager hardening Action outputs, policy-promotion Action outputs, hosted consumption of promotion Action outputs, operator-visible promotion output values, hosted promotion judge audit traces, editor-native adapter coverage, and Dependabot closure landed | Next workflow automation should deepen live operator approval/readback after Marketplace/payment gates | -| ECC Tools next-level app | Billing audit, PR checks, deep analyzer, sync backlog, evaluator/RAG corpus, hosted promotion judge audit trace, native-payments readback, ready Marketplace Pro target selection, hosted observability, AgentShield fleet-summary hosted routing, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output hosted telemetry, and operator-visible promotion output values | PRs #26-#43 plus #53-#89 landed with test evidence across hosted analysis, hosted promotion readiness, model-judge execution, native-payments announcement gating, AgentShield evidence consumption, hosted remediation/Linear sync, hosted observability readback, and ready Marketplace Pro target selection; ECC-Tools #89 merged as `512bca6` after Verify, Security Audit, and Workers Builds passed, and the 2026-05-20 production Wrangler OAuth readback found ready-like Marketplace Pro records with webhook provenance, selected a target with both key families, and reported 0 blockers without printing the login | Next work is obtain or rotate the local/internal `INTERNAL_API_SECRET` bearer-token path, then run the live billing announcement gate for the selected Marketplace Pro target before publishing native-payments copy | +| ECC Tools next-level app | Billing audit, PR checks, deep analyzer, sync backlog, evaluator/RAG corpus, hosted promotion judge audit trace, native-payments readback, ready Marketplace Pro target selection, selected-target announcement gate, hosted observability, AgentShield fleet-summary hosted routing, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output hosted telemetry, and operator-visible promotion output values | PRs #26-#43 plus #53-#90 landed with test evidence across hosted analysis, hosted promotion readiness, model-judge execution, native-payments announcement gating, AgentShield evidence consumption, hosted remediation/Linear sync, hosted observability readback, ready Marketplace Pro target selection, and selected-target official announcement gating; ECC-Tools #89 merged as `512bca6` after Verify, Security Audit, and Workers Builds passed, and the 2026-05-20 production Wrangler OAuth readback found ready-like Marketplace Pro records with webhook provenance, selected a target with both key families, and reported 0 blockers without printing the login; ECC-Tools #90 merged as `16a5bb3` after Verify, Security Audit, and Workers Builds passed, and production preflight now requests `/api/billing/readiness?selectReadyTarget=1` without a raw login | Next work is obtain or rotate the local/internal `INTERNAL_API_SECRET` bearer-token path, then run the live selected-target billing announcement gate before publishing native-payments copy | | GitGuardian/Dependabot/CodeRabbit-style checks | Non-blocking taxonomy, deterministic follow-up checks, and local supply-chain gates | ECC-Tools risk taxonomy check plus follow-up signals landed, including Skill Quality, Deep Analyzer Evidence, Analyzer Corpus Evidence, RAG/Evaluator Evidence, PR Review/Salvage Evidence, and AgentShield evidence-pack evidence; #1846 added npm registry signature gates; #1848 added the supply-chain incident-response playbook and `pull_request_target` cache-poisoning validator guard; #1851 added the privileged checkout credential-persistence guard; AgentShield #78, JARVIS #13, and ECC-Tools #53 applied the same hardening outside trunk | Current supply-chain gate complete; deeper hosted review features remain future | | Harness-agnostic learning system | Audit, adapter matrix, observability, traces, promotion loop | Audit/adapters/observability gates plus `docs/architecture/evaluator-rag-prototype.md`, `examples/evaluator-rag-prototype/`, and ECC-Tools PR #40 define read-only stale-salvage, billing-readiness, CI-failure-diagnosis, harness-config-quality, AgentShield policy-exception, skill-quality evidence, deep-analyzer evidence, and RAG/evaluator comparison scenarios with trace, report, playbook, verifier, and predictive-check artifacts; ECC-Tools PRs #68-#72 now turn that corpus into a deterministic PR check-run gate with cached hosted-output scoring, ranked retrieval candidates, a model prompt seed, a fail-closed hosted model-judge request contract, and opt-in live model execution behind strict hosted-evidence gates | Deterministic hosted PR check, cached output scoring, retrieval planning, judge contract, and gated model execution integrated | | Linear roadmap is detailed | Linear project document/comments plus repo mirror | Repo mirror exists and issue creation works again; the May 19 sync adds post-PR #2002 document `ecc-may-19-post-pr-2002-sync-64cef8f668e0`, project comment `a6411e3a-8c8e-4a58-adba-687e77d4c543`, ITO-44/47/48/49/51/54/56 issue comments, and In Progress state for ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56; the late-pass batch adds document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f`, project comment `d42bf0e2-7a8e-4934-9f3f-e281498ee805`, and ITO-44/50/54/56/61 comments for PR #2013, ECC-Tools #79, and JARVIS #15/#16 because project status updates are disabled in the workspace | Needs recurring document/comment updates after each significant merge batch | @@ -918,7 +939,7 @@ repo evidence and merge commits. | Harness OS core | Audit, adapter matrix, observability docs, `ecc2/` | HUD/session-control acceptance spec | Weekly until GA | | Evaluation and RAG | Reference-set validation, harness audit, traces, ECC-Tools corpus | Read-only evaluator/RAG prototype plus stale-salvage, billing-readiness, CI-failure-diagnosis, harness-config-quality, AgentShield policy-exception, skill-quality evidence, deep-analyzer evidence, and RAG/evaluator comparison fixtures; ECC-Tools #68 publishes the corpus as a hosted promotion readiness check-run, #69 scores cached hosted job outputs against the same corpus, #70 emits ranked retrieval candidates plus a model prompt seed, #71 adds a fail-closed hosted model-judge request contract, and #72 executes that judge only when explicitly enabled and backed by hosted retrieval citations; ECC-Tools `16c537f` surfaces policy-promotion Action output values in hosted security comments/checks; ECC-Tools `05d4e82` adds hosted model-judge audit traces with request fingerprints and allowed-citation counts | Marketplace Pro billing-state verification with webhook provenance | | AgentShield enterprise | AgentShield PR evidence and roadmap notes | Fleet routing landed in #89 after evidence-pack inspect/readback shipped in #88; #90 emits fleet `reviewItems`; #91 exports checksum-backed policy bundles; #92 promotes checksum-verified policies from those bundles into active policy files; #94 adds Zed and VS Code adapter detection, Zed project scan discovery, and `.zed/setup.mjs` persistence IOC coverage; #95 closes the `brace-expansion` Dependabot alert with 0 open alerts after merge; AgentShield `87aec47` adds policy promotion `reviewItems`; `28d08c7` adds package-manager hardening drift detection; `659f569` refreshes workflow action runtime pins; `ee585cd` corrects unsupported npm release-age guidance and keeps enforceable cooldown findings on pnpm/Yarn; `1124535` exposes package-manager hardening Action outputs for CI/hosted routing; `1593925` exposes policy-promotion Action outputs and runtime-smoke job-summary evidence; `840952a` adds fleet review ticket payloads and current Mini Shai-Hulud IOC breadcrumbs; ECC-Tools #76 consumes fleet summaries, #77 surfaces source evidence paths in hosted findings, #78 links fleet routes to harness owners, ECC-Tools `8658951` consumes policy-promotion Action outputs, and ECC-Tools `16c537f` renders operator-visible output values | Deepen live operator approval/readback after Marketplace/payment gates | -| ECC Tools app | ECC-Tools PR evidence, billing audit, risk taxonomy, evaluator/RAG corpus | ECC-Tools #53 published the supply-chain workflow hardening branch, #54 tracks copy-ready PR drafts in the Linear/project backlog, #55 classifies analysis-depth readiness, #56 exposes the hosted execution plan, #57 executes the first hosted CI diagnostics job, #58 executes the hosted security evidence review job, #59 executes the hosted harness compatibility audit, #60 executes the hosted reference-set evaluation, #61 executes the hosted AI routing/cost review, #62 executes hosted team backlog routing, #63 publishes the hosted depth-plan check-run, #64 dispatches hosted jobs from PR comments, #65 persists hosted result history/check-runs, #66 exposes hosted job status from PR comments, #67 makes depth-plan recommendations cache-aware, #68 publishes hosted promotion readiness from the evaluator/RAG corpus, #69 scores cached hosted job outputs against that corpus, #70 emits ranked retrieval candidates plus a model prompt seed, #71 emits the gated `hosted-promotion-judge.v1` contract without live model calls, #72 adds opt-in live model-judge execution behind hosted-evidence and strict JSON/citation gates, #73 adds a fail-closed native-payments `announcementGate` to billing readiness, #74 adds `npm run billing:announcement-gate` for operator verification, #75 tightens the billing announcement gate for live Marketplace readback, #76 routes AgentShield fleet-summary evidence into hosted security findings, #77 adds source evidence paths to hosted finding output, #78 links AgentShield fleet target paths to hosted harness owner findings, `8658951` routes AgentShield policy-promotion Action outputs into hosted security review and promotion readiness, `16c537f` renders policy-promotion status/pack/count/digest values in hosted security comments/checks, `05d4e82` renders hosted promotion judge request fingerprints plus allowed-citation audit traces, `91a441b` adds billing announcement preflight output for required readback inputs, `eb69412` records the initial production readback state, `95d0bec` adds aggregate `billing:kv-readback` evidence, `2859678` requires Marketplace webhook provenance in billing readiness, `42653f9` adds Wrangler OAuth readback with live aggregate production counts, and `632e059` adds sanitized target-account billing readback for the exact Marketplace test account | Create or verify Marketplace-managed Pro target billing-state with webhook provenance, then live target readback and announcement gate | +| ECC Tools app | ECC-Tools PR evidence, billing audit, risk taxonomy, evaluator/RAG corpus | ECC-Tools #53 published the supply-chain workflow hardening branch, #54 tracks copy-ready PR drafts in the Linear/project backlog, #55 classifies analysis-depth readiness, #56 exposes the hosted execution plan, #57 executes the first hosted CI diagnostics job, #58 executes the hosted security evidence review job, #59 executes the hosted harness compatibility audit, #60 executes the hosted reference-set evaluation, #61 executes the hosted AI routing/cost review, #62 executes hosted team backlog routing, #63 publishes the hosted depth-plan check-run, #64 dispatches hosted jobs from PR comments, #65 persists hosted result history/check-runs, #66 exposes hosted job status from PR comments, #67 makes depth-plan recommendations cache-aware, #68 publishes hosted promotion readiness from the evaluator/RAG corpus, #69 scores cached hosted job outputs against that corpus, #70 emits ranked retrieval candidates plus a model prompt seed, #71 emits the gated `hosted-promotion-judge.v1` contract without live model calls, #72 adds opt-in live model-judge execution behind hosted-evidence and strict JSON/citation gates, #73 adds a fail-closed native-payments `announcementGate` to billing readiness, #74 adds `npm run billing:announcement-gate` for operator verification, #75 tightens the billing announcement gate for live Marketplace readback, #76 routes AgentShield fleet-summary evidence into hosted security findings, #77 adds source evidence paths to hosted finding output, #78 links AgentShield fleet target paths to hosted harness owner findings, `8658951` routes AgentShield policy-promotion Action outputs into hosted security review and promotion readiness, `16c537f` renders policy-promotion status/pack/count/digest values in hosted security comments/checks, `05d4e82` renders hosted promotion judge request fingerprints plus allowed-citation audit traces, `91a441b` adds billing announcement preflight output for required readback inputs, `eb69412` records the initial production readback state, `95d0bec` adds aggregate `billing:kv-readback` evidence, `2859678` requires Marketplace webhook provenance in billing readiness, `42653f9` adds Wrangler OAuth readback with live aggregate production counts, `632e059` adds sanitized target-account billing readback for the exact Marketplace test account, ECC-Tools #89 adds selected-ready-target KV readback, and ECC-Tools #90 adds selected-target official announcement gating without raw login input | Obtain or rotate the local/internal `INTERNAL_API_SECRET` bearer-token path, then run the live selected-target billing announcement gate | | Linear progress | Linear project status updates, `docs/architecture/progress-sync-contract.md`, generated `operator:dashboard` output, and this mirror | Status update with queue/evidence/missing gates | Every significant merge batch | The project status update should always include: @@ -1191,10 +1212,10 @@ Acceptance: including budget-blocked outcomes; PRs #86/#87 read those events back into hosted status comments and hosted depth-plan check-runs; and PR #88 exposes authenticated hosted observability API readback for operator dashboards. -2. Run `npm run billing:announcement-gate -- --preflight --account - `, then run the same command without `--preflight` against a - Marketplace-managed test account and require `announcementGate.ready === - true` before any native GitHub payments announcement. +2. Run `npm run billing:announcement-gate -- --preflight + --select-ready-target`, then run the same command without `--preflight` and + require `announcementGate.ready === true` before any native GitHub payments + announcement. 3. Enable/configure the merged Linear backlog sync path after workspace issue capacity clears or the Linear workspace is upgraded, then verify PR-draft salvage items land in the expected project. diff --git a/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md b/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md index 97009af8..30237485 100644 --- a/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md +++ b/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md @@ -71,7 +71,7 @@ Reason: | Codex repo marketplace | Local and GitHub-ref temp-home marketplace add smokes passed on Codex CLI `0.131.0` | `.codex-plugin/plugin.json`, `.agents/plugins/marketplace.json`, repo/personal marketplace evidence | Plugin owner | Official Plugin Directory listing requires OpenAI submission/listing evidence | | Codex official Plugin Directory | OpenAI docs describe the curated official directory; ECC has not submitted or received listing evidence | Directory submission link or OpenAI approval path once available | Plugin owner | Track as an ITO-56/ITO-46 follow-up; do not claim an official listing | | OpenCode package | `npm run build:opencode` passed | Built `.opencode` package metadata inside npm tarball | Package owner | No separate public plugin channel identified; follows npm | -| Billing/native payments | Marketplace Pro target readback passed; announcement remains blocked by ITO-61 | 2026-05-20 selected-target readback, webhook provenance, `INTERNAL_API_SECRET`, live announcement gate | ECC Tools owner | Do not include native-payments claim in rc.1 announcement until the live gate passes | +| Billing/native payments | Marketplace Pro target readback and selected-target announcement preflight passed; live announcement remains blocked by ITO-61 | 2026-05-20 selected-target readback, webhook provenance, selected-target announcement gate, `INTERNAL_API_SECRET`, live announcement gate | ECC Tools owner | Do not include native-payments claim in rc.1 announcement until the live selected-target gate passes | | Social/longform copy | Drafts exist | Final live GitHub, npm, Claude, Codex, billing URLs | Release owner | Publish only after release/package/plugin URLs exist | ## Package Rename After rc.1 diff --git a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md new file mode 100644 index 00000000..0871cd11 --- /dev/null +++ b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md @@ -0,0 +1,66 @@ +# ECC Operator Readiness Dashboard + +This dashboard is generated by `npm run operator:dashboard`. It is an operator snapshot, not release approval. + +Generated: 2026-05-20T01:57:18.637Z +Commit: 59ac4b4a6a3d750326b81ca4e2c22c54ddb5ad5a +Status: work remaining + +## Current Status + +| Area | Status | Evidence | +| --- | --- | --- | +| PR queue | Current | 0 open PRs across tracked repos | +| Issue queue | Current | 0 open issues across tracked repos | +| Discussions | Current | 0 need maintainer touch; 0 missing accepted answer | +| Local worktree | Current | 0 blocking dirty files; 0 ignored dirty entries | +| Dashboard generation | Current | platform audit ready: true; GitHub skipped: false | +| Publication | Not complete | release, npm, plugin, billing, and announcement gates are tracked below | + +## Growth Baseline + +| Metric | Current | Target | Gap | +| --- | ---: | ---: | ---: | +| MRR | $1,728/mo | $10,000/mo | $8,272/mo | + +Growth lanes: GitHub Sponsors and OSS partner sponsors; ECC Tools Pro subscriptions; consulting and implementation contracts; talks, podcasts, conference demos, and partner webinars. + +## Prompt-To-Artifact Checklist + +| Objective requirement | Artifact or gate | Status | Evidence | Gap | +| --- | --- | --- | --- | --- | +| Keep public PRs below 20 | scripts/platform-audit.js live GitHub sweep plus owner-wide queue cleanup ledger | current | 0 open PRs across 5 tracked repos; 0 owner-wide open PRs after cleanup | repeat platform:audit and owner-wide gh search before release | +| Keep public issues below 20 | scripts/platform-audit.js live GitHub sweep plus owner-wide queue cleanup ledger | current | 0 open issues across 5 tracked repos; 0 owner-wide open issues after cleanup | repeat platform:audit and owner-wide gh search before release | +| Respond and manage repository discussions | scripts/platform-audit.js discussion summary | current | 0 need maintainer touch; 0 answerable discussions missing accepted answer | repeat before release | +| Build ITO-44 completion dashboard into a repeatable command | npm run operator:dashboard | complete | operator:dashboard package script exists | keep generated dashboard attached to publication evidence | +| ECC 2.0 preview pack ready | docs/releases/2.0.0-rc.1/preview-pack-manifest.md | current | preview pack manifest and deterministic smoke gate are in-tree | repeat clean-checkout preview-pack smoke before publication | +| Include Hermes specialized skills safely | docs/HERMES-SETUP.md and skills/hermes-imports/SKILL.md | current | Hermes setup/import artifacts are covered by preview-pack smoke | repeat preview-pack smoke before release review | +| Prepare name-change, Claude plugin, and Codex plugin paths | naming-and-publication-matrix plus release-name-plugin-publication checklist plus publication-readiness | in_progress | naming matrix, release publication checklist, and plugin readiness gates exist | real tag/push, marketplace submission, and final channel choice remain approval-gated | +| Prepare release notes, articles, tweets, and push notifications | docs/releases/2.0.0-rc.1 social and release-copy files | in_progress | release notes, X thread, LinkedIn draft, and URL ledger are present | final live release/npm/plugin/billing URLs and publish approval still pending | +| Prepare final owner approval packet | docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md | current | owner approval packet covers release, package, plugin, video, billing, social, and outbound decisions | review owner approvals from the final release commit before any publication or outbound action | +| Create a second-phase hypergrowth release command center | docs/releases/2.0.0/ecc-2-hypergrowth-release-command-center.md plus May 19 evidence | current | current MRR, target MRR, gap, release claim, video lane, distribution plan, and approval boundaries are in-tree | refresh after every MRR, channel, or approval-state change before public launch | +| Produce the ECC 2.0 release video suite | docs/releases/2.0.0-rc.1/video-suite-production.md and npm run release:video-suite | current | video-suite gate is ready with 15/15 source assets, 13/13 suite artifacts, 12/12 publish candidates, primary self-eval, and zero detected black-frame segments recorded in May 19 evidence | final owner approval, upload, and public video URLs remain approval-gated | +| Prepare sponsor, partner, consulting, podcast, talk, and Discussion copy | docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md | in_progress | sponsor outbound, platform partner DM, consulting intro, talk/podcast pitch, GitHub Discussion announcement, CTA hooks, and do-not-send gate are drafted | replace final URLs after publication gates, then get explicit approval before outbound or personal-account posts | +| Advance AgentShield enterprise iteration | AgentShield PR evidence plus enterprise roadmap | in_progress | AgentShield policy promotion `reviewItems` landed in `87aec47`; package-manager hardening drift detection landed in `28d08c7`; workflow action runtime pins were refreshed in `659f569`; npm age-gate guidance was corrected in `ee585cd`; package-manager hardening Action outputs landed in `1124535`; policy-promotion Action outputs and runtime-smoke job-summary evidence landed in `1593925`; fleet review ticket payloads and current Mini Shai-Hulud IOC breadcrumbs landed in `840952a`; ECC-Tools consumes those outputs in `8658951`, surfaces operator-readable status/pack/count/digest telemetry in `16c537f`, and renders hosted promotion judge audit traces in `05d4e82`; all are mirrored in the GA roadmap | deepen live operator approval/readback after Marketplace/payment gates | +| Advance ECC Tools native payments and AI-native harness-agnostic app | ECC Tools PR evidence, billing gate, hosted analysis lanes | in_progress | billing announcement gate, selected-target announcement gate, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler OAuth readback, target-account billing readback, provenance-aware Marketplace billing-state gates, sanitized Marketplace plan/action provenance counts, ready Marketplace Pro target selection, hosted team-learning feedback controls, and ECC-Tools Dependabot alert remediation are mirrored in the GA roadmap | obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, then run the live selected-target billing announcement gate before publishing native-payments copy | +| Audit, prune, or attach legacy work | docs/stale-pr-salvage-ledger.md and legacy inventory | current | legacy salvage ledger and inventory are current; all localization tails are attached to Linear ITO-55 for manual language-owner review | repeat legacy scan before release | +| Keep Linear roadmap detailed and progress tracking synchronized | Linear project mirror plus progress-sync contract | current | Linear live sync is current with the May 20 Marketplace Pro release-gate comments on ITO-61 and the ECC platform roadmap; progress-sync contract defines the file-backed work-items/status path | repeat Linear/project status update and local work-items sync after each significant merge batch | +| Provide ECC 2.0 observability for self-use | observability readiness gate | complete | observability:ready command and readiness doc exist | runtime/dashboard implementation can continue after release gates | +| Keep Mini Shai-Hulud/TanStack protection loop current | supply-chain watch plus runbook plus AgentShield package-manager hardening | current | scheduled supply-chain watch emits IOC/advisory-source refresh artifacts; ECC scanner covers gh-token-monitor token-store persistence; AgentShield now detects known AI-tool persistence IOCs, npm lifecycle/token drift, unsupported npm age-key drift, and pnpm/Yarn cooldown drift; current-head watch evidence and ITO-57 May 18 Linear evidence updates are current | repeat advisory/source refresh and Linear sync after each significant supply-chain batch | + +## Top Actions + +- `naming-and-plugin-publication`: real tag/push, marketplace submission, and final channel choice remain approval-gated +- `release-notes-and-notifications`: final live release/npm/plugin/billing URLs and publish approval still pending +- `partner-sponsor-talks-pack`: replace final URLs after publication gates, then get explicit approval before outbound or personal-account posts +- `agentshield-enterprise-iteration`: deepen live operator approval/readback after Marketplace/payment gates +- `ecc-tools-next-level`: obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, then run the live selected-target billing announcement gate before publishing native-payments copy + +## Next Work Order + +1. Regenerate this dashboard from the final release commit before publication evidence is recorded. +2. Review the owner approval packet from the final release commit and approve, defer, or block each publication and outbound lane. +3. Review the owner-approved primary launch video candidates, choose the final cuts, upload after approval, and attach public video URLs to the release pack. +4. Replace final release, npm, plugin, billing, and video URLs in the partner/sponsor/talk pack, then get explicit approval before outbound. +5. Repeat ITO-57 Linear/project status sync after the next significant merge batch or advisory-source refresh. +6. Obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, then run the live selected-target billing announcement gate before publishing native-payments copy. diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index 341de114..f6e9bf9f 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -26,10 +26,11 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-16.md` | Current May 16/17 queue cleanup, recsys skill merge, GateGuard triage, PR #1947 supply-chain protection, AgentShield #87 plugin-cache confidence evidence, AgentShield #88 evidence-pack inspect/readback, AgentShield #89 evidence-pack fleet routing, AgentShield #90 fleet review items, AgentShield #91 policy export, AgentShield #92 policy promotion, ECC-Tools #76 fleet-summary consumption, ECC-Tools #77 hosted finding evidence paths, ECC-Tools #78 harness policy-route linking, dashboard refresh, and combined Node/Rust/release-surface gate evidence through the May 16 mirror | Must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` | May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack protection recheck, npm audit/signature checks, legacy and Linear progress routing, deterministic preview-pack smoke, operator dashboard refresh, Linear sync, and GitHub CI evidence for `27dc2918` | Superseded by the May 18 evidence snapshot; repeat from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, supply-chain recheck, AgentShield evidence mirror, Linear sync, current-head CI/security scan success for `4470e2e6`, and ITO-46 naming/plugin publication closure | Superseded by the May 19 ECC identity, video, and growth evidence snapshot | -| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19/20 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, release approval gate, May 19 operator dashboard, preview-pack smoke digest `531328aaaa53`, 2568-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, PR #2004 Linear readiness evidence sync CI success, PR #2008 supply-chain evidence gate CI success, post-PR #2006 main CI success, PR #2009 project-registry hygiene CI success, post-PR #2009 main CI success, post-PR #2011 GateGuard CI success, post-PR #2013 release-approval-gate CI success, PR #2017 AgentShield adapter evidence sync, ECC-Tools #79 billing-announcement redaction hardening, ECC-Tools #80-#88 runtime-receipt, AgentShield approval-ID, Linear sync, remediation sync, hosted observability event/status/depth-plan/API readback, AgentShield #94 Zed/VS Code adapter coverage, AgentShield #95 Dependabot alert closure, JARVIS #15/#16 queue/deploy repair, and the May 19/20 Linear sync comments | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | +| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19/20 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, release approval gate, May 20 operator dashboard, preview-pack smoke digest `eebb8a66c33e`, 2568-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, PR #2004 Linear readiness evidence sync CI success, PR #2008 supply-chain evidence gate CI success, post-PR #2006 main CI success, PR #2009 project-registry hygiene CI success, post-PR #2009 main CI success, post-PR #2011 GateGuard CI success, post-PR #2013 release-approval-gate CI success, PR #2017/#2018 AgentShield evidence sync, ECC-Tools #79 billing-announcement redaction hardening, ECC-Tools #80-#89 runtime-receipt, AgentShield approval-ID, Linear sync, remediation sync, hosted observability event/status/depth-plan/API readback, Marketplace Pro selected-target readback, AgentShield #94 Zed/VS Code adapter coverage, AgentShield #95 Dependabot alert closure, JARVIS #15/#16 queue/deploy repair, ECC #2019 Marketplace Pro release-gate sync, and the May 19/20 Linear sync comments | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 19 generated dashboard | -| `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and adds the current `$1,728/mo` to `$10,000/mo` hypergrowth, video owner-approval, and outbound-pack operating lanes | +| `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 20 generated dashboard | +| `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and adds the current `$1,728/mo` to `$10,000/mo` hypergrowth, video owner-approval, Linear release-gate sync, and outbound-pack operating lanes | | `docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md` | Final human decision sheet for release, package, plugin, video, billing, social, and outbound approvals | Must be reviewed by the owner before any publication or outbound action | | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md` | Live URL and approval-gated URL ledger for release copy | Must be regenerated from the final release commit before public announcements | | `docs/releases/2.0.0-rc.1/video-suite-production.md` | Release video production manifest | Gates local media inventory, rough primary render, captions, timeline, self-eval, and no-private-path publication rules | @@ -111,7 +112,7 @@ surfaces exist and are recorded in a final evidence file: availability status; - final announcement URLs in X, LinkedIn, GitHub release, and longform copy; - ECC Tools billing/product readiness evidence, the local/internal announcement - bearer-token path, and a live announcement gate pass before any + bearer-token path, and a live selected-target announcement gate pass before any native-payments announcement copy is published. ## Result diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md index 2d0998d1..5d4f40d8 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -8,9 +8,9 @@ social announcement. | Field | Evidence | | --- | --- | -| Upstream main | `906e06406e95742944ccb05065f95a7e4dd4a036` | +| Upstream main | `30f60710d4e0424fc70d9bbdc105009db141d9d8` | | Git remote | `https://github.com/affaan-m/ECC.git` | -| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, PR #2001 owner approval packet addition, PR #2002 owner approval dashboard gate refresh, PR #2004 Linear readiness evidence sync, PR #2005 post-PR #2004 evidence refresh, PR #2008 release supply-chain evidence gate fix, PR #2006 per-project Claude Code adapter, PR #2009 continuous-learning project registry hygiene fix, PR #2011 GateGuard quoted git introspection fix, PR #2013 deterministic release approval gate, PR #2017 AgentShield adapter evidence sync, ECC-Tools #80-#88 hosted observability/readback batch, AgentShield #94 Zed/VS Code adapter coverage, and AgentShield #95 Dependabot alert closure | +| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, PR #2001 owner approval packet addition, PR #2002 owner approval dashboard gate refresh, PR #2004 Linear readiness evidence sync, PR #2005 post-PR #2004 evidence refresh, PR #2008 release supply-chain evidence gate fix, PR #2006 per-project Claude Code adapter, PR #2009 continuous-learning project registry hygiene fix, PR #2011 GateGuard quoted git introspection fix, PR #2013 deterministic release approval gate, PR #2017 AgentShield adapter evidence sync, PR #2018 AgentShield Dependabot evidence sync, ECC-Tools #80-#89 hosted observability/readback and Marketplace Pro selected-target batch, AgentShield #94 Zed/VS Code adapter coverage, AgentShield #95 Dependabot alert closure, and PR #2019 Marketplace Pro release-gate sync | | Local status caveat | `git status --short --branch` was clean after pulling `origin/main`; generated evidence files are committed after the source snapshot they describe | The release operator must repeat all publish-facing checks from the exact final @@ -59,6 +59,8 @@ Tracked repositories in the platform audit were: | PR #2011 | Merged the GateGuard read-only git introspection tokenizer fix so quoted `git show` pathspecs with spaces are preserved while quoted shell separators stay outside the bypass | | PR #2013 | Merged the deterministic `release:approval-gate` so final publication, package, plugin, video, billing, social, and outbound actions remain blocked until owner decisions and live URL readbacks are complete | | PR #2017 | Merged the AgentShield #94 evidence mirror as `906e06406e95742944ccb05065f95a7e4dd4a036`, syncing roadmap, publication evidence, preview-pack manifest, and supply-chain incident-response surfaces after full GitHub CI passed | +| PR #2018 | Merged the AgentShield #95 Dependabot evidence mirror as `68b4e45145968acd52e68d900f8422061ed7f4a2`, syncing the roadmap, publication evidence, and preview-pack manifest after full PR CI passed | +| PR #2019 | Merged the Marketplace Pro selected-target release-gate sync as `30f60710d4e0424fc70d9bbdc105009db141d9d8`, updating the roadmap, publication evidence, naming matrix, preview manifest, and operator dashboard after full PR CI passed | ## Post-Queue-Zero Sync - 2026-05-19 Late Pass @@ -86,14 +88,26 @@ Tracked repositories in the platform audit were: | AgentShield #95 | PR #95 merged the `brace-expansion` Dependabot fix as `25d91f0002214c408da4ceaac7def20bad40ca10`. The lockfile now resolves vulnerable transitive `brace-expansion` 5.x entries to `5.0.6`, local `npm audit --audit-level=moderate` returns 0 vulnerabilities, and `gh api repos/affaan-m/agentshield/dependabot/alerts?state=open` returns `[]`. Local validation passed typecheck, lint, full `npm test` (1822 tests), build, audit, and whitespace checks; GitHub checks passed across Verify Node 18/20/22, self-scan, self-scan examples, Test GitHub Action, GitGuardian, CodeRabbit, and Cubic. | | Linear roadmap sync | Linear ITO-54 comment `74dcc101-3be5-4173-be13-62b80d54f569` and ECC Platform Roadmap project comment `348ea8f5-2a2d-46d9-a0fe-ed99653e7fe5` record the May 20 hosted observability status/depth-plan readback batch; Linear comments `291e2a4b-06e3-4672-a057-cdb141478161` and `b2d35de0-ca49-44cb-982a-ddec229e7691` add the #88 observability API readback; Linear ITO-49 comment `faed69dd-35f5-469d-acb5-ddde6a70d6a1` and project comment `70187c1e-d481-4181-b418-09bd65d54b5e` add the #94 AgentShield Zed/VS Code adapter evidence; Linear ITO-49 comment `371fc3e4-611f-4d20-a23f-67db1260b418`, ITO-57 comment `bd06e252-15c1-4256-b667-caa3f64f5968`, and project comment `22c2c388-2fd1-4dea-a939-6141f40c9a21` add the #95 AgentShield Dependabot alert closure; earlier comments on ITO-54, ITO-48, and the project record the #84 hosted remediation sync and #85 hosted observability event emission batches. | +## May 20 Marketplace Pro Release-Gate Sync + +| Surface | Evidence | +| --- | --- | +| ECC-Tools #89 | PR #89 merged as `512bca6b99cdaa67058a6aa9a4e7e7f0b1d9873a` after Verify, Security Audit, and Workers Builds passed. It added `billing:kv-readback -- --select-ready-target --require-ready`, allowing operators to select a ready Marketplace Pro target internally without passing or printing the login. | +| Live production readback | The 2026-05-20 Wrangler OAuth readback found ready-like Marketplace Pro records with webhook provenance, selected a target with both key families, seat and webhook readiness, no overage, and 0 blockers, with account details redacted. The old missing Marketplace Pro target-state blocker is cleared. | +| ECC #2019 | PR #2019 merged as `30f60710d4e0424fc70d9bbdc105009db141d9d8`, syncing the selected-target readback evidence into the GA roadmap, rc.1 publication evidence, naming matrix, preview manifest, and operator dashboard. | +| Post-merge main CI | GitHub Actions run `26135974576` completed successfully on `main` for `30f60710d4e0424fc70d9bbdc105009db141d9d8` across lint, coverage, security, validation, and the full OS/package-manager matrix. | +| Post-merge local gates | `npm run platform:audit -- --json` returned ready true with 0 PRs, 0 issues, 0 discussion gaps, and 0 dirty blockers; `npm run preview-pack:smoke -- --format json` returned ready true with digest `531328aaaa53` before the May 20 dashboard rollover and `eebb8a66c33e` after adding the May 20 dashboard artifact; `git diff --check HEAD~1..HEAD` was clean. | +| Linear roadmap sync | Linear ITO-61 comment `467d148a-712a-4777-aad9-95593e9f1739` and ECC Platform Roadmap project comment `7642ee9c-3107-400c-a229-53e2895a8914` record ECC-Tools #89, ECC #2019, the green post-merge CI run, and the remaining internal bearer-token gate. | +| Remaining blocker | Native-payments announcement copy remains blocked until the local/internal `INTERNAL_API_SECRET` bearer-token path is available and `npm run billing:announcement-gate -- --select-ready-target` returns ready for the selected Marketplace Pro target. | + ## Release And Growth Evidence | Gate | Command | Result | | --- | --- | --- | | Release-surface tests | `node tests/docs/ecc2-release-surface.test.js` | 28 passed, 0 failed | -| Preview-pack smoke | `npm run preview-pack:smoke -- --format json` | Ready true; digest `531328aaaa53`; 32 required artifacts; 5 passed, 0 failed | +| Preview-pack smoke | `npm run preview-pack:smoke -- --format json` | Ready true; digest `eebb8a66c33e`; 33 required artifacts; 5 passed, 0 failed | | Release approval gate | `npm run release:approval-gate -- --format json` | Expected blocked; digest `ef8f49f727b7`; 4 passed, 2 failed; owner decisions and live URL readbacks remain approval-gated | -| Operator dashboard | `npm run operator:dashboard -- --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Regenerated from the May 19 `main` baseline with platform audit ready true, 0 tracked PRs, 0 tracked issues, 0 discussion gaps, `$1,728/mo` current MRR, `$10,000/mo` target MRR, the release video suite marked current, and top actions for plugin publication, notifications, outbound approval, AgentShield, and ECC Tools billing | +| Operator dashboard | `npm run operator:dashboard -- --write docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md` | Regenerated from the May 20 `main` baseline with platform audit ready true, 0 tracked PRs, 0 tracked issues, 0 discussion gaps, `$1,728/mo` current MRR, `$10,000/mo` target MRR, the release video suite marked current, Linear release-gate sync current, and top actions for plugin publication, notifications, outbound approval, AgentShield, and ECC Tools billing | | Supply-chain verification | `npm audit --audit-level=moderate`; `npm audit signatures`; `yarn install --immutable --mode=skip-build` | Current supply-chain refresh found 0 npm vulnerabilities, verified 254 registry signatures and 30 attestations, and accepted the Yarn lock after pinning `@types/node@25.7.0` plus refreshing `brace-expansion` to `5.0.6` / `1.1.14` | | Release video suite | `npm run release:video-suite -- --format json --summary` with `ECC_VIDEO_SOURCE_ROOT` and `ECC_VIDEO_RELEASE_SUITE_ROOT` | Ready true; 15/15 source assets present; 13/13 render, timeline, caption, EDL, and segment artifacts present; 12/12 publish-candidate outputs present with zero detected black-frame segments; primary rough render self-eval passed at 144.759 seconds, 1920x1080, 1 audio stream, and 106.78 MB | | Focused post-merge regression set | `node tests/hooks/detect-project-worktree.test.js`; `node tests/hooks/observe-subdirectory-detection.test.js`; `node tests/scripts/instinct-cli-projects.test.js`; `node tests/hooks/hooks.test.js` | 10/10, 6/6, 5/5, and 237/237 passed after PR #2009 merged | @@ -112,7 +126,8 @@ Tracked repositories in the platform audit were: | Post-PR #2009 main CI | GitHub Actions run `26111946778` | Completed successfully with 37 completed jobs, 0 failed jobs, and `main` advanced to `bc519e5b8ed42f26c0a5a611756e04351c323f21` | | Post-PR #2011 main CI | GitHub Actions run `26113695068` | Completed successfully with 37 completed jobs, 0 failed jobs, and `main` advanced to `14d88e517b0c56a80c1a6392b1cde2474948d29f` | | Post-PR #2013 main CI | GitHub Actions run `26128749863` | Completed successfully with `main` advanced to `9819626459a662773be7d0b1c18d82c1316b8c36` | -| Linear sync | Linear document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` plus project comment `a6411e3a-8c8e-4a58-adba-687e77d4c543`; late-pass document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f` plus project comment `d42bf0e2-7a8e-4934-9f3f-e281498ee805` | Project and issue lanes record PR #2002 evidence, discussion #2003 routing, owner-approval dashboard gate, and In Progress status for ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56; the late-pass sync attaches PR #2013, ECC-Tools #79, and JARVIS #15/#16 evidence to ITO-44, ITO-50, ITO-54, ITO-56, and ITO-61 | +| Post-PR #2019 main CI | GitHub Actions run `26135974576` | Completed successfully with `main` advanced to `30f60710d4e0424fc70d9bbdc105009db141d9d8` | +| Linear sync | Linear document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` plus project comment `a6411e3a-8c8e-4a58-adba-687e77d4c543`; late-pass document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f` plus project comment `d42bf0e2-7a8e-4934-9f3f-e281498ee805`; May 20 ITO-61 comment `467d148a-712a-4777-aad9-95593e9f1739` plus project comment `7642ee9c-3107-400c-a229-53e2895a8914` | Project and issue lanes record PR #2002 evidence, discussion #2003 routing, owner-approval dashboard gate, and In Progress status for ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56; the late-pass sync attaches PR #2013, ECC-Tools #79, and JARVIS #15/#16 evidence to ITO-44, ITO-50, ITO-54, ITO-56, and ITO-61; the May 20 sync attaches ECC-Tools #89 and ECC #2019 Marketplace Pro selected-target evidence to ITO-61 and the project | | Public-path sanitization | `node scripts/ci/validate-no-personal-paths.js` through local suite and CI | Passed | | Markdown and whitespace | `markdownlint` focused release docs plus `git diff --check` before PR #1999 | Passed | @@ -140,10 +155,13 @@ Tracked repositories in the platform audit were: listing evidence. - ECC Tools billing/native-payments copy remains blocked until the local/internal `INTERNAL_API_SECRET` bearer-token path is available and the - billing announcement gate passes for the ready Marketplace Pro target. + live `billing:announcement-gate -- --select-ready-target` check passes. ECC-Tools PR #89 (`512bca6`) added `billing:kv-readback -- --select-ready-target --require-ready`; its 2026-05-20 production run cleared the old missing-target-state blocker without printing the account login. + ECC-Tools PR #90 (`16a5bb3`) added the selected-target official announcement + gate, so production preflight no longer needs a raw GitHub login and now + blocks only on the missing `INTERNAL_API_SECRET` input before live execution. - Release notes, X, LinkedIn, GitHub release, GitHub Discussion, longform copy, sponsor outreach, partner outreach, consulting copy, conference pitches, and podcast pitches still need final live URLs plus human approval before posting diff --git a/docs/releases/2.0.0-rc.1/publication-readiness.md b/docs/releases/2.0.0-rc.1/publication-readiness.md index 1a57e3be..c921baea 100644 --- a/docs/releases/2.0.0-rc.1/publication-readiness.md +++ b/docs/releases/2.0.0-rc.1/publication-readiness.md @@ -56,8 +56,10 @@ For the May 17 operator dashboard refresh, see For the May 18 operator dashboard refresh, see [`operator-readiness-dashboard-2026-05-18.md`](operator-readiness-dashboard-2026-05-18.md). -The current May 19 hypergrowth/operator dashboard is +For the May 19 hypergrowth/operator dashboard, see [`operator-readiness-dashboard-2026-05-19.md`](operator-readiness-dashboard-2026-05-19.md). +The current May 20 Marketplace Pro release-gate operator dashboard is +[`operator-readiness-dashboard-2026-05-20.md`](operator-readiness-dashboard-2026-05-20.md). For the final owner decision sheet across release, npm, plugin, video, billing, social, and outbound approvals, see [`owner-approval-packet-2026-05-19.md`](owner-approval-packet-2026-05-19.md). @@ -102,7 +104,7 @@ Record the exact commit SHA and command output before any publication action: | Evidence | Command | Required result | Recorded output | | --- | --- | --- | --- | | Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | Current May 19 baseline `bc519e5b8ed42f26c0a5a611756e04351c323f21`: `## main...origin/main`; repeat from the exact final publication commit before release | -| Preview-pack smoke | `npm run preview-pack:smoke` | Preview pack artifacts, Hermes boundary, final verification command list, and publication blockers pass | `publication-evidence-2026-05-19.md`: ready yes, digest `531328aaaa53`, 32 artifacts, 5 passed, 0 failed; repeat in the final strict clean-checkout release pass | +| Preview-pack smoke | `npm run preview-pack:smoke` | Preview pack artifacts, Hermes boundary, final verification command list, and publication blockers pass | `publication-evidence-2026-05-19.md`: ready yes, digest `eebb8a66c33e`, 33 artifacts, 5 passed, 0 failed; repeat in the final strict clean-checkout release pass | | Release approval gate | `npm run release:approval-gate -- --format json` | Ready true only after owner decision rows are approved, live release/package/plugin/video/billing URLs are recorded, and launch/outbound copy has no placeholders or private paths | Current May 19 state is intentionally blocked because owner decisions and live URL readbacks remain approval-gated | | Harness audit | `npm run harness:audit -- --format json` | 80/80 passing | Current release gate: 80/80 across 8 applicable categories, 0 top actions | | Adapter scorecard | `npm run harness:adapters -- --check` | PASS | Current release gate: PASS, 11 adapters | diff --git a/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md b/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md index 437ea131..9245e54e 100644 --- a/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md @@ -20,7 +20,8 @@ with output from the exact release commit. | May 19 evidence snapshot | | Current strongest identity, video, growth, and CI readiness evidence | | May 18 evidence snapshot | | Previous supply-chain and publication-path readiness evidence | | May 18 operator dashboard | | Previous prompt-to-artifact dashboard | -| May 19 operator dashboard | | Current prompt-to-artifact dashboard with hypergrowth, video, and outbound lanes | +| May 19 operator dashboard | | Previous prompt-to-artifact dashboard with hypergrowth, video, and outbound lanes | +| May 20 operator dashboard | | Current prompt-to-artifact dashboard with Marketplace Pro release-gate sync | | npm package page | | `npm view ecc-universal name version dist-tags --json` returned `latest: 1.10.0`; rc.1 is not published yet | | Codex marketplace CLI docs | | Official docs list `codex plugin marketplace add` for GitHub shorthand, Git URLs, SSH URLs, and local marketplace roots | | Codex official Plugin Directory status | | Official docs say public Plugin Directory publishing and self-serve management are coming soon | diff --git a/scripts/operator-readiness-dashboard.js b/scripts/operator-readiness-dashboard.js index fa42a662..8507d9e0 100644 --- a/scripts/operator-readiness-dashboard.js +++ b/scripts/operator-readiness-dashboard.js @@ -342,9 +342,11 @@ function agentShieldEnterpriseEvidence(roadmap) { } function eccToolsNextLevelEvidence(roadmap) { - if (roadmap.includes('select-ready-target') + if (roadmap.includes('selected-target official announcement gate') + || roadmap.includes('16a5bb3') + || roadmap.includes('select-ready-target') || roadmap.includes('f14ed2fe-a219-470c-8119-63429e197027')) { - return 'billing announcement gate, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler OAuth readback, target-account billing readback, provenance-aware Marketplace billing-state gates, sanitized Marketplace plan/action provenance counts, ready Marketplace Pro target selection, hosted team-learning feedback controls, and ECC-Tools Dependabot alert remediation are mirrored in the GA roadmap'; + return 'billing announcement gate, selected-target announcement gate, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler OAuth readback, target-account billing readback, provenance-aware Marketplace billing-state gates, sanitized Marketplace plan/action provenance counts, ready Marketplace Pro target selection, hosted team-learning feedback controls, and ECC-Tools Dependabot alert remediation are mirrored in the GA roadmap'; } if (roadmap.includes('69ca535') @@ -392,10 +394,12 @@ function eccToolsNextLevelEvidence(roadmap) { } function eccToolsNextLevelGap(roadmap) { - if (roadmap.includes('select-ready-target') + if (roadmap.includes('selected-target official announcement gate') + || roadmap.includes('16a5bb3') + || roadmap.includes('select-ready-target') || roadmap.includes('f14ed2fe-a219-470c-8119-63429e197027') || roadmap.includes('old "no Marketplace-managed Pro target billing-state" blocker is cleared')) { - return 'obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, then run the live billing announcement gate for the selected Marketplace Pro target before publishing native-payments copy'; + return 'obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, then run the live selected-target billing announcement gate before publishing native-payments copy'; } if (roadmap.includes('1Password CLI authorization timed out') @@ -472,9 +476,13 @@ function hasCurrentLinearProgressSync({ roadmap, progressSync }) { const hasMay19ProgressSurface = roadmap.includes('ecc-may-19-post-pr-2002-sync-64cef8f668e0') && roadmap.includes('a6411e3a-8c8e-4a58-adba-687e77d4c543') && roadmap.includes('ITO-56'); + const hasMay20ReleaseGateSurface = roadmap.includes('467d148a-712a-4777-aad9-95593e9f1739') + && roadmap.includes('7642ee9c-3107-400c-a229-53e2895a8914') + && roadmap.includes('30f60710') + && roadmap.includes('26135974576'); return roadmap.includes('Linear live sync is current') - && (hasOperatorProgressSurface || hasMay19ProgressSurface) + && (hasOperatorProgressSurface || hasMay19ProgressSurface || hasMay20ReleaseGateSurface) && includesAll(progressSync, [ 'node scripts/work-items.js sync-github --repo ', 'node scripts/status.js --json', @@ -497,6 +505,11 @@ function linearProgressStatus(context) { function linearProgressEvidence(context) { if (hasCurrentLinearProgressSync(context)) { + if (context.roadmap.includes('467d148a-712a-4777-aad9-95593e9f1739') + && context.roadmap.includes('7642ee9c-3107-400c-a229-53e2895a8914')) { + return 'Linear live sync is current with the May 20 Marketplace Pro release-gate comments on ITO-61 and the ECC platform roadmap; progress-sync contract defines the file-backed work-items/status path'; + } + if (context.roadmap.includes('ecc-may-19-post-pr-2002-sync-64cef8f668e0')) { return 'Linear live sync is current with the May 19 post-PR #2002 sync document, project comment, and active issue-lane updates; progress-sync contract defines the file-backed work-items/status path'; } @@ -1000,7 +1013,7 @@ function buildReport(options) { releaseVideoWorkOrder, 'Replace final release, npm, plugin, billing, and video URLs in the partner/sponsor/talk pack, then get explicit approval before outbound.', 'Repeat ITO-57 Linear/project status sync after the next significant merge batch or advisory-source refresh.', - 'Obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, then run the live billing announcement gate for the selected Marketplace Pro target before publishing native-payments copy.', + 'Obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, then run the live selected-target billing announcement gate before publishing native-payments copy.', ], }; } diff --git a/scripts/platform-audit.js b/scripts/platform-audit.js index 6dc3731a..06f9e420 100644 --- a/scripts/platform-audit.js +++ b/scripts/platform-audit.js @@ -427,7 +427,7 @@ function buildLocalEvidenceChecks(rootDir) { const progressSync = readText(rootDir, 'docs/architecture/progress-sync-contract.md'); const supplyChain = readText(rootDir, 'docs/security/supply-chain-incident-response.md'); const evidence = readText(rootDir, 'docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md'); - const operatorDashboard = readText(rootDir, 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md'); + const operatorDashboard = readText(rootDir, 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md'); return [ buildCheck( @@ -488,7 +488,7 @@ function buildLocalEvidenceChecks(rootDir) { 'Next Work Order', ]) ? 'pass' : 'fail', 'operator dashboard maps macro-goal requirements to current evidence and open gaps', - { path: 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md' } + { path: 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md' } ), ]; } diff --git a/scripts/preview-pack-smoke.js b/scripts/preview-pack-smoke.js index 11df8c4c..b997f60f 100644 --- a/scripts/preview-pack-smoke.js +++ b/scripts/preview-pack-smoke.js @@ -31,6 +31,7 @@ const REQUIRED_ARTIFACTS = [ `${RELEASE_DIR}/operator-readiness-dashboard-2026-05-17.md`, `${RELEASE_DIR}/operator-readiness-dashboard-2026-05-18.md`, `${RELEASE_DIR}/operator-readiness-dashboard-2026-05-19.md`, + `${RELEASE_DIR}/operator-readiness-dashboard-2026-05-20.md`, `${RELEASE_DIR}/owner-approval-packet-2026-05-19.md`, `${RELEASE_DIR}/release-url-ledger-2026-05-19.md`, `${RELEASE_DIR}/video-suite-production.md`, diff --git a/tests/docs/ecc2-release-surface.test.js b/tests/docs/ecc2-release-surface.test.js index efd72830..ae6125d8 100644 --- a/tests/docs/ecc2-release-surface.test.js +++ b/tests/docs/ecc2-release-surface.test.js @@ -258,7 +258,7 @@ test('GA roadmap mirrors the current May 19 release evidence', () => { for (const marker of [ 'owner-approval-packet-2026-05-19.md', - 'preview-pack smoke digest `531328aaaa53`', + 'preview-pack smoke digest `eebb8a66c33e`', 'local 2568-test suite', 'PR #2001', 'GitHub Actions run `26102500291`', @@ -266,6 +266,11 @@ test('GA roadmap mirrors the current May 19 release evidence', () => { 'GitHub Actions run `26103853507`', 'PR #2009', 'GitHub Actions run `26111313938`', + 'PR #2019', + '30f60710', + '26135974576', + '467d148a-712a-4777-aad9-95593e9f1739', + '7642ee9c-3107-400c-a229-53e2895a8914', 'ecc-may-19-post-pr-2002-sync-64cef8f668e0', 'owner approval packet', ]) { @@ -273,6 +278,7 @@ test('GA roadmap mirrors the current May 19 release evidence', () => { } assert.ok(!roadmap.includes('preview-pack smoke digest `bc2bf157616e`')); + assert.ok(!roadmap.includes('preview-pack smoke digest `531328aaaa53`')); assert.ok(!roadmap.includes('local 2544-test suite')); }); diff --git a/tests/scripts/operator-readiness-dashboard.test.js b/tests/scripts/operator-readiness-dashboard.test.js index 5e943d0b..47df13ed 100644 --- a/tests/scripts/operator-readiness-dashboard.test.js +++ b/tests/scripts/operator-readiness-dashboard.test.js @@ -78,8 +78,14 @@ function seedRepo(rootDir, overrides = {}) { 'target account billing readback', '632e059', 'select-ready-target', + 'selected-target official announcement gate', + '16a5bb3', 'f14ed2fe-a219-470c-8119-63429e197027', 'old "no Marketplace-managed Pro target billing-state" blocker is cleared', + '30f60710', + '26135974576', + '467d148a-712a-4777-aad9-95593e9f1739', + '7642ee9c-3107-400c-a229-53e2895a8914', '69ca535', 'team feedback controls', 'e56fc1a', @@ -143,6 +149,18 @@ function seedRepo(rootDir, overrides = {}) { 'PR queue', 'Not complete' ].join('\n'), + 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md': [ + 'This dashboard is generated by `npm run operator:dashboard`', + 'operator:dashboard', + 'Growth Baseline', + 'hypergrowth release command center', + 'Prompt-To-Artifact Checklist', + 'Next Work Order', + 'ITO-44', + 'ITO-59', + 'PR queue', + 'Not complete' + ].join('\n'), 'docs/releases/2.0.0-rc.1/owner-queue-cleanup-2026-05-18.md': [ 'Owner-wide open PRs after cleanup: 0.', 'Owner-wide open issues after cleanup: 0.', @@ -350,9 +368,10 @@ function runTests() { ))); assert.ok(report.requirements.some(item => ( item.id === 'ecc-tools-next-level' - && item.gap === 'obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, then run the live billing announcement gate for the selected Marketplace Pro target before publishing native-payments copy' + && item.gap === 'obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, then run the live selected-target billing announcement gate before publishing native-payments copy' && item.evidence.includes('operator-visible promotion output details') && item.evidence.includes('hosted promotion judge audit traces') + && item.evidence.includes('selected-target announcement gate') && item.evidence.includes('billing announcement preflight') && item.evidence.includes('aggregate production billing KV readback') && item.evidence.includes('Wrangler OAuth readback') @@ -419,7 +438,7 @@ function runTests() { assert.ok(report.requirements.some(item => ( item.id === 'linear-roadmap-and-progress' && item.status === 'current' - && item.evidence.includes('Linear live sync') + && item.evidence.includes('May 20 Marketplace Pro release-gate comments') && item.gap === 'repeat Linear/project status update and local work-items sync after each significant merge batch' ))); assert.ok(report.top_actions.some(item => item.id === 'naming-and-plugin-publication')); diff --git a/tests/scripts/platform-audit.test.js b/tests/scripts/platform-audit.test.js index 9451bb9f..a3f1e063 100644 --- a/tests/scripts/platform-audit.test.js +++ b/tests/scripts/platform-audit.test.js @@ -70,7 +70,7 @@ function seedRepo(rootDir, overrides = {}) { 'macOS/Ubuntu/Windows test matrix', '2568 passed' ].join('\n'), - 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md': [ + 'docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md': [ 'This dashboard is generated by `npm run operator:dashboard`', 'Growth Baseline', 'hypergrowth release command center', From 6e25458dbc15cd07cfb7a4e1f0b06f3eda41a043 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 22:43:19 -0400 Subject: [PATCH 60/61] Sync billing gate env-file evidence (#2021) --- docs/ECC-2.0-GA-ROADMAP.md | 39 ++++++++++++---- .../naming-and-publication-matrix.md | 4 +- ...operator-readiness-dashboard-2026-05-20.md | 10 ++-- .../2.0.0-rc.1/preview-pack-manifest.md | 10 ++-- .../publication-evidence-2026-05-19.md | 46 ++++++++++++------- .../2.0.0-rc.1/publication-readiness.md | 8 ++-- .../release-url-ledger-2026-05-19.md | 2 +- scripts/operator-readiness-dashboard.js | 10 ++-- tests/docs/ecc2-release-surface.test.js | 2 +- .../operator-readiness-dashboard.test.js | 5 +- 10 files changed, 89 insertions(+), 47 deletions(-) diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index 04034de3..6c2f3537 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -50,10 +50,20 @@ partner/sponsor funnel, consulting/talk funnel, and social launch plan. into this repo as `30f60710d4e0424fc70d9bbdc105009db141d9d8`. The post-merge main CI run `26135974576` completed green across lint, coverage, security, validation, and the full OS/package-manager matrix. +- ECC PR #2020 merged the selected-target announcement-gate mirror as + `c2471fe5c535310f8a8008c9ed7ea9f6757b33f2`. The post-merge main CI run + `26136949698` completed green across lint, coverage, security, validation, + and the full OS/package-manager matrix. - ECC-Tools PR #90 added the selected-target official announcement gate for `billing:announcement-gate -- --select-ready-target`; safe production preflight no longer requires a raw GitHub login and now blocks only on the local/internal `INTERNAL_API_SECRET` input before live execution. +- ECC-Tools PR #91 added `--env-file` support to both billing gate scripts so + ignored local operator credential files can supply `INTERNAL_API_SECRET`, + Cloudflare auth, Wrangler auth mode, or target fallbacks without printing + secret contents. Verify, Security Audit, and Workers Builds passed before + merge as `72119a1`, and main CI run `26137280847` completed successfully after + merge. - Linear ITO-54 and the ECC Platform Roadmap now have the May 20 ECC-Tools hosted observability update comments `74dcc101-3be5-4173-be13-62b80d54f569` and @@ -70,6 +80,8 @@ partner/sponsor funnel, consulting/talk funnel, and social launch plan. Pro release-gate comments `467d148a-712a-4777-aad9-95593e9f1739` and `7642ee9c-3107-400c-a229-53e2895a8914`, recording ECC-Tools #89, ECC #2019, the green post-merge CI run, and the remaining internal bearer-token gate. + The repo mirror now also records ECC-Tools #90 and #91 as the selected-target + announcement gate and billing gate env-file operator-path follow-up. ## 2026-05-19 Delta @@ -498,6 +510,13 @@ As of 2026-05-20: local/internal `INTERNAL_API_SECRET` bearer token. Native-payments copy remains blocked until that token path is available and the live `billing:announcement-gate -- --select-ready-target` call passes. +- ECC-Tools PR #91 merged as `72119a1acc6f5a0cd3bb5d90afd6e87fd1fefd05` + after Verify, Security Audit, and Workers Builds passed. It adds the billing + gate env-file operator path with `--env-file` support for the announcement + gate and KV readback scripts, plus sentinel tests proving loaded secrets and + account logins are not printed. The local May 20 live recheck still found no + usable `INTERNAL_API_SECRET`, and Wrangler readback still failed with + Cloudflare auth code `10000`; no native-payments announcement is unblocked. - Handoff `ecc-supply-chain-audit-20260513-0645.md` under `~/.cluster-swarm/handoffs/` records the May 13 supply-chain sweep: no active lockfile/manifest hit for @@ -909,13 +928,13 @@ is not complete unless the evidence column exists and has been freshly verified. | Manage repository discussions | Repo-family discussion recheck plus response playbook | Platform audit reports 0 discussion maintainer-touch gaps and 0 answerable Q&A missing accepted answers; trunk has 59 total discussions after #2003 was routed with a maintainer response; `docs/architecture/discussion-response-playbook.md` distinguishes support, maintainer coordination, stale/concluded, release, informational, and security-sensitive response paths | Complete | | Manage PR discussions | PR review/comment closure plus merge/close state | ECC #1990-#2013 merged through the harness audit, canonical identity, release video suite, growth outreach, evidence refresh, visual QA, suite-count, owner-approval packet, owner-approval dashboard gate, Linear readiness evidence, supply-chain evidence gate, per-project Claude Code adapter, continuous-learning project-registry hygiene, GateGuard quoted git introspection, and deterministic release-approval gate batch; ECC-Tools #79 and JARVIS #15/#16 also merged; no open tracked PRs remain | Complete | | Salvage useful stale work | `docs/stale-pr-salvage-ledger.md` plus `docs/legacy-artifact-inventory.md` | Ledger records salvaged, superseded, skipped, and manual-review tails; #1815-#1818 added cost tracking, skill scout, frontend design guidance, code-reviewer false-positive guardrails, and the May 12 gap pass; #1687, #1609, #1563, #1564, and #1565 localization tails are attached to Linear ITO-55 for language-owner review and no automatic import remains release-blocking | Complete; repeat legacy scan before release | -| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 19/20 evidence records queue-zero state, canonical ECC identity, release video suite, growth outreach pack, owner approval packet, local 2568-test suite, PR #2001 merge and GitHub Actions run `26102500291`, PR #2002 owner-approval dashboard gate refresh and GitHub Actions run `26103853507`, PR #2004 Linear readiness evidence sync and GitHub Actions run `26105012698`, PR #2008 supply-chain evidence gate CI run `26108473648`, post-PR #2006 main CI run `26109953093`, PR #2009 project-registry hygiene GitHub Actions run `26111313938`, post-PR #2009 main CI run `26111946778`, post-PR #2011 GateGuard main CI run `26113695068`, post-PR #2013 release-approval main CI run `26128749863`, post-PR #2019 main CI run `26135974576`, May 20 operator dashboard, `owner-approval-packet-2026-05-19.md`, `release-approval-gate.js`, and preview-pack smoke digest `eebb8a66c33e` | Needs final release approval | +| ECC 2.0 preview pack ready | Release docs, quickstart, publication readiness, release notes | `docs/releases/2.0.0-rc.1/` and readiness docs are in-tree; May 19/20 evidence records queue-zero state, canonical ECC identity, release video suite, growth outreach pack, owner approval packet, local 2568-test suite, PR #2001 merge and GitHub Actions run `26102500291`, PR #2002 owner-approval dashboard gate refresh and GitHub Actions run `26103853507`, PR #2004 Linear readiness evidence sync and GitHub Actions run `26105012698`, PR #2008 supply-chain evidence gate CI run `26108473648`, post-PR #2006 main CI run `26109953093`, PR #2009 project-registry hygiene GitHub Actions run `26111313938`, post-PR #2009 main CI run `26111946778`, post-PR #2011 GateGuard main CI run `26113695068`, post-PR #2013 release-approval main CI run `26128749863`, post-PR #2019 main CI run `26135974576`, post-PR #2020 main CI run `26136949698`, ECC-Tools #91 main CI run `26137280847`, May 20 operator dashboard, `owner-approval-packet-2026-05-19.md`, `release-approval-gate.js`, and preview-pack smoke digest `eebb8a66c33e` | Needs final release approval | | Hermes specialized skills included safely | Hermes setup/import docs and sanitized skill surface | Hermes setup and import playbook are public; secrets stay local | Needs final release review | | Naming and rename readiness | Naming matrix across package/plugin/docs/social surfaces | `docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md` records current package, repo, Claude plugin, Codex plugin, OpenCode, and npm availability evidence | Complete for rc.1; post-rc rename remains future work | | Claude and Codex plugin publication | Contact/submission path with required artifacts and status | Publication readiness, naming matrix, and May 12 dry-run evidence document plugin validation, clean-checkout Claude tag/install smoke, and Codex marketplace CLI shape | Needs explicit approval for real tag/push and marketplace submission | | Articles, tweets, and announcements | X thread, LinkedIn copy, GitHub release copy, push checklist, partner/sponsor/talk pack | Draft launch collateral and approval-gated outreach copy exist under rc.1 release docs | Needs URL-backed refresh and human approval before posting or sending | | AgentShield enterprise iteration | Policy gates, SARIF, packs, provenance, corpus, HTML reports, exception lifecycle audit, baseline drift Action/CLI surfaces, evidence-pack redaction, harness adapter registry, editor-native Zed/VS Code adapter coverage, Dependabot alert closure, enterprise research roadmap, supply-chain hardened release path, CI-safe baseline fingerprints, corpus accuracy recommendations, remediation workflow phases, env proxy hijack corpus coverage, Mini Shai-Hulud full-campaign package IOCs, CI-provenance evidence packs, plugin-cache runtime-confidence triage, evidence-pack consumer readback, fleet-level evidence-pack routing, fleet review items, fleet review ticket payloads, checksum-backed policy export, checksum-verified policy promotion, policy promotion review items, package-manager hardening drift detection, npm age-gate guidance correction, workflow action-runtime pin refresh, package-manager hardening Action outputs, policy-promotion Action outputs, ECC-Tools hosted consumption of promotion Action outputs, ECC-Tools operator-visible promotion output values, and ECC-Tools hosted promotion judge audit traces | PRs #53, #55-#64, #67-#69, #78-#92, #94, and #95 landed with test evidence, ECC-Tools #76 consumes the fleet-summary output in hosted security review, #77 surfaces source evidence paths in hosted finding output, and #78 links fleet routes to harness owner review; AgentShield #91 adds `agentshield policy export` bundles for branch-protection review and downstream promotion; AgentShield #92 adds `agentshield policy promote` with digest verification, tamper rejection, explicit pack selection, dry-run review, and JSON output before writing active policy; AgentShield #94 adds Zed/VS Code adapter detection, `.zed/settings.json` and `.zed/tasks.json` scan discovery, and `.zed/setup.mjs` AI-tool persistence IOC coverage; AgentShield #95 clears the `brace-expansion` Dependabot alert with a patched lockfile and 0 open Dependabot alerts after merge; AgentShield commit `87aec47` adds `reviewItems` for digest evidence, owner review, protected rollout PR handoff, and runtime smoke testing with green local and remote CI; AgentShield commit `28d08c7` adds package-manager hardening drift detection for plaintext registry credentials, lifecycle-script enablement, and weak pnpm/Yarn release-age cooldowns with green local and remote CI; AgentShield commit `659f569` refreshes all workflow action runtime pins to SHA-pinned checkout v6.0.2 and setup-node v6.4.0 with green remote CI and no remaining action-runtime deprecation annotation; AgentShield commit `ee585cd` corrects npm release-age guidance by flagging unsupported npm age keys and keeping enforceable cooldown findings on pnpm/Yarn with green local and remote CI; AgentShield commit `1124535` exposes package-manager hardening status/count outputs and a redacted job-summary section for registry credentials, lifecycle scripts, and release-age gates with green local and remote CI; AgentShield commit `1593925` exposes policy-promotion status/count/digest outputs plus job-summary review items for owner approval, protected rollout, and runtime smoke, and marks runtime smoke verified when the same Action job scans with the promoted policy; AgentShield commit `840952a` adds Linear/operator-ready fleet review ticket payloads and expands current Mini Shai-Hulud IOC breadcrumbs with green local and remote CI; ECC-Tools commit `8658951` routes those policy-promotion Action outputs into hosted security review findings and Hosted Promotion Readiness scoring; ECC-Tools commit `16c537f` renders policy-promotion status, pack, review item count, action-required count, and digest in hosted security job comments/check-runs; ECC-Tools commit `05d4e82` renders hosted promotion judge request fingerprints and allowed-citation counts without raw provider output; native PDF export deferred in favor of self-contained HTML plus print-to-PDF until explicit enterprise demand appears; `docs/architecture/agentshield-enterprise-research-roadmap.md` now has baseline drift, evidence-pack bundle, redaction, adapter-registry, supply-chain hardening, hashed baseline fingerprints, corpus accuracy recommendation, remediation workflow, env proxy hijack corpus, Mini Shai-Hulud full-campaign package-table, `ci-context.json` provenance, `plugin-cache` confidence, `evidence-pack inspect` readback, `evidence-pack fleet` routing, fleet `reviewItems`, fleet review ticket payloads, policy export, policy promotion, policy promotion `reviewItems`, package-manager hardening Action outputs, policy-promotion Action outputs, hosted consumption of promotion Action outputs, operator-visible promotion output values, hosted promotion judge audit traces, editor-native adapter coverage, and Dependabot closure landed | Next workflow automation should deepen live operator approval/readback after Marketplace/payment gates | -| ECC Tools next-level app | Billing audit, PR checks, deep analyzer, sync backlog, evaluator/RAG corpus, hosted promotion judge audit trace, native-payments readback, ready Marketplace Pro target selection, selected-target announcement gate, hosted observability, AgentShield fleet-summary hosted routing, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output hosted telemetry, and operator-visible promotion output values | PRs #26-#43 plus #53-#90 landed with test evidence across hosted analysis, hosted promotion readiness, model-judge execution, native-payments announcement gating, AgentShield evidence consumption, hosted remediation/Linear sync, hosted observability readback, ready Marketplace Pro target selection, and selected-target official announcement gating; ECC-Tools #89 merged as `512bca6` after Verify, Security Audit, and Workers Builds passed, and the 2026-05-20 production Wrangler OAuth readback found ready-like Marketplace Pro records with webhook provenance, selected a target with both key families, and reported 0 blockers without printing the login; ECC-Tools #90 merged as `16a5bb3` after Verify, Security Audit, and Workers Builds passed, and production preflight now requests `/api/billing/readiness?selectReadyTarget=1` without a raw login | Next work is obtain or rotate the local/internal `INTERNAL_API_SECRET` bearer-token path, then run the live selected-target billing announcement gate before publishing native-payments copy | +| ECC Tools next-level app | Billing audit, PR checks, deep analyzer, sync backlog, evaluator/RAG corpus, hosted promotion judge audit trace, native-payments readback, ready Marketplace Pro target selection, selected-target announcement gate, billing gate env-file operator path, hosted observability, AgentShield fleet-summary hosted routing, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output hosted telemetry, and operator-visible promotion output values | PRs #26-#43 plus #53-#91 landed with test evidence across hosted analysis, hosted promotion readiness, model-judge execution, native-payments announcement gating, AgentShield evidence consumption, hosted remediation/Linear sync, hosted observability readback, ready Marketplace Pro target selection, selected-target official announcement gating, and env-file operator loading; ECC-Tools #89 merged as `512bca6` after Verify, Security Audit, and Workers Builds passed, and the 2026-05-20 production Wrangler OAuth readback found ready-like Marketplace Pro records with webhook provenance, selected a target with both key families, and reported 0 blockers without printing the login; ECC-Tools #90 merged as `16a5bb3` after Verify, Security Audit, and Workers Builds passed, and production preflight now requests `/api/billing/readiness?selectReadyTarget=1` without a raw login; ECC-Tools #91 merged as `72119a1` with `--env-file` support for ignored local billing credentials and sentinel no-secret/no-login output tests | Next work is obtain or rotate the local/internal `INTERNAL_API_SECRET` bearer-token path, via exported env or ignored `--env-file`, then run the live selected-target billing announcement gate before publishing native-payments copy | | GitGuardian/Dependabot/CodeRabbit-style checks | Non-blocking taxonomy, deterministic follow-up checks, and local supply-chain gates | ECC-Tools risk taxonomy check plus follow-up signals landed, including Skill Quality, Deep Analyzer Evidence, Analyzer Corpus Evidence, RAG/Evaluator Evidence, PR Review/Salvage Evidence, and AgentShield evidence-pack evidence; #1846 added npm registry signature gates; #1848 added the supply-chain incident-response playbook and `pull_request_target` cache-poisoning validator guard; #1851 added the privileged checkout credential-persistence guard; AgentShield #78, JARVIS #13, and ECC-Tools #53 applied the same hardening outside trunk | Current supply-chain gate complete; deeper hosted review features remain future | | Harness-agnostic learning system | Audit, adapter matrix, observability, traces, promotion loop | Audit/adapters/observability gates plus `docs/architecture/evaluator-rag-prototype.md`, `examples/evaluator-rag-prototype/`, and ECC-Tools PR #40 define read-only stale-salvage, billing-readiness, CI-failure-diagnosis, harness-config-quality, AgentShield policy-exception, skill-quality evidence, deep-analyzer evidence, and RAG/evaluator comparison scenarios with trace, report, playbook, verifier, and predictive-check artifacts; ECC-Tools PRs #68-#72 now turn that corpus into a deterministic PR check-run gate with cached hosted-output scoring, ranked retrieval candidates, a model prompt seed, a fail-closed hosted model-judge request contract, and opt-in live model execution behind strict hosted-evidence gates | Deterministic hosted PR check, cached output scoring, retrieval planning, judge contract, and gated model execution integrated | | Linear roadmap is detailed | Linear project document/comments plus repo mirror | Repo mirror exists and issue creation works again; the May 19 sync adds post-PR #2002 document `ecc-may-19-post-pr-2002-sync-64cef8f668e0`, project comment `a6411e3a-8c8e-4a58-adba-687e77d4c543`, ITO-44/47/48/49/51/54/56 issue comments, and In Progress state for ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56; the late-pass batch adds document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f`, project comment `d42bf0e2-7a8e-4934-9f3f-e281498ee805`, and ITO-44/50/54/56/61 comments for PR #2013, ECC-Tools #79, and JARVIS #15/#16 because project status updates are disabled in the workspace | Needs recurring document/comment updates after each significant merge batch | @@ -939,7 +958,7 @@ repo evidence and merge commits. | Harness OS core | Audit, adapter matrix, observability docs, `ecc2/` | HUD/session-control acceptance spec | Weekly until GA | | Evaluation and RAG | Reference-set validation, harness audit, traces, ECC-Tools corpus | Read-only evaluator/RAG prototype plus stale-salvage, billing-readiness, CI-failure-diagnosis, harness-config-quality, AgentShield policy-exception, skill-quality evidence, deep-analyzer evidence, and RAG/evaluator comparison fixtures; ECC-Tools #68 publishes the corpus as a hosted promotion readiness check-run, #69 scores cached hosted job outputs against the same corpus, #70 emits ranked retrieval candidates plus a model prompt seed, #71 adds a fail-closed hosted model-judge request contract, and #72 executes that judge only when explicitly enabled and backed by hosted retrieval citations; ECC-Tools `16c537f` surfaces policy-promotion Action output values in hosted security comments/checks; ECC-Tools `05d4e82` adds hosted model-judge audit traces with request fingerprints and allowed-citation counts | Marketplace Pro billing-state verification with webhook provenance | | AgentShield enterprise | AgentShield PR evidence and roadmap notes | Fleet routing landed in #89 after evidence-pack inspect/readback shipped in #88; #90 emits fleet `reviewItems`; #91 exports checksum-backed policy bundles; #92 promotes checksum-verified policies from those bundles into active policy files; #94 adds Zed and VS Code adapter detection, Zed project scan discovery, and `.zed/setup.mjs` persistence IOC coverage; #95 closes the `brace-expansion` Dependabot alert with 0 open alerts after merge; AgentShield `87aec47` adds policy promotion `reviewItems`; `28d08c7` adds package-manager hardening drift detection; `659f569` refreshes workflow action runtime pins; `ee585cd` corrects unsupported npm release-age guidance and keeps enforceable cooldown findings on pnpm/Yarn; `1124535` exposes package-manager hardening Action outputs for CI/hosted routing; `1593925` exposes policy-promotion Action outputs and runtime-smoke job-summary evidence; `840952a` adds fleet review ticket payloads and current Mini Shai-Hulud IOC breadcrumbs; ECC-Tools #76 consumes fleet summaries, #77 surfaces source evidence paths in hosted findings, #78 links fleet routes to harness owners, ECC-Tools `8658951` consumes policy-promotion Action outputs, and ECC-Tools `16c537f` renders operator-visible output values | Deepen live operator approval/readback after Marketplace/payment gates | -| ECC Tools app | ECC-Tools PR evidence, billing audit, risk taxonomy, evaluator/RAG corpus | ECC-Tools #53 published the supply-chain workflow hardening branch, #54 tracks copy-ready PR drafts in the Linear/project backlog, #55 classifies analysis-depth readiness, #56 exposes the hosted execution plan, #57 executes the first hosted CI diagnostics job, #58 executes the hosted security evidence review job, #59 executes the hosted harness compatibility audit, #60 executes the hosted reference-set evaluation, #61 executes the hosted AI routing/cost review, #62 executes hosted team backlog routing, #63 publishes the hosted depth-plan check-run, #64 dispatches hosted jobs from PR comments, #65 persists hosted result history/check-runs, #66 exposes hosted job status from PR comments, #67 makes depth-plan recommendations cache-aware, #68 publishes hosted promotion readiness from the evaluator/RAG corpus, #69 scores cached hosted job outputs against that corpus, #70 emits ranked retrieval candidates plus a model prompt seed, #71 emits the gated `hosted-promotion-judge.v1` contract without live model calls, #72 adds opt-in live model-judge execution behind hosted-evidence and strict JSON/citation gates, #73 adds a fail-closed native-payments `announcementGate` to billing readiness, #74 adds `npm run billing:announcement-gate` for operator verification, #75 tightens the billing announcement gate for live Marketplace readback, #76 routes AgentShield fleet-summary evidence into hosted security findings, #77 adds source evidence paths to hosted finding output, #78 links AgentShield fleet target paths to hosted harness owner findings, `8658951` routes AgentShield policy-promotion Action outputs into hosted security review and promotion readiness, `16c537f` renders policy-promotion status/pack/count/digest values in hosted security comments/checks, `05d4e82` renders hosted promotion judge request fingerprints plus allowed-citation audit traces, `91a441b` adds billing announcement preflight output for required readback inputs, `eb69412` records the initial production readback state, `95d0bec` adds aggregate `billing:kv-readback` evidence, `2859678` requires Marketplace webhook provenance in billing readiness, `42653f9` adds Wrangler OAuth readback with live aggregate production counts, `632e059` adds sanitized target-account billing readback for the exact Marketplace test account, ECC-Tools #89 adds selected-ready-target KV readback, and ECC-Tools #90 adds selected-target official announcement gating without raw login input | Obtain or rotate the local/internal `INTERNAL_API_SECRET` bearer-token path, then run the live selected-target billing announcement gate | +| ECC Tools app | ECC-Tools PR evidence, billing audit, risk taxonomy, evaluator/RAG corpus | ECC-Tools #53 published the supply-chain workflow hardening branch, #54 tracks copy-ready PR drafts in the Linear/project backlog, #55 classifies analysis-depth readiness, #56 exposes the hosted execution plan, #57 executes the first hosted CI diagnostics job, #58 executes the hosted security evidence review job, #59 executes the hosted harness compatibility audit, #60 executes the hosted reference-set evaluation, #61 executes the hosted AI routing/cost review, #62 executes hosted team backlog routing, #63 publishes the hosted depth-plan check-run, #64 dispatches hosted jobs from PR comments, #65 persists hosted result history/check-runs, #66 exposes hosted job status from PR comments, #67 makes depth-plan recommendations cache-aware, #68 publishes hosted promotion readiness from the evaluator/RAG corpus, #69 scores cached hosted job outputs against that corpus, #70 emits ranked retrieval candidates plus a model prompt seed, #71 emits the gated `hosted-promotion-judge.v1` contract without live model calls, #72 adds opt-in live model-judge execution behind hosted-evidence and strict JSON/citation gates, #73 adds a fail-closed native-payments `announcementGate` to billing readiness, #74 adds `npm run billing:announcement-gate` for operator verification, #75 tightens the billing announcement gate for live Marketplace readback, #76 routes AgentShield fleet-summary evidence into hosted security findings, #77 adds source evidence paths to hosted finding output, #78 links AgentShield fleet target paths to hosted harness owner findings, `8658951` routes AgentShield policy-promotion Action outputs into hosted security review and promotion readiness, `16c537f` renders policy-promotion status/pack/count/digest values in hosted security comments/checks, `05d4e82` renders hosted promotion judge request fingerprints plus allowed-citation audit traces, `91a441b` adds billing announcement preflight output for required readback inputs, `eb69412` records the initial production readback state, `95d0bec` adds aggregate `billing:kv-readback` evidence, `2859678` requires Marketplace webhook provenance in billing readiness, `42653f9` adds Wrangler OAuth readback with live aggregate production counts, `632e059` adds sanitized target-account billing readback for the exact Marketplace test account, ECC-Tools #89 adds selected-ready-target KV readback, ECC-Tools #90 adds selected-target official announcement gating without raw login input, and ECC-Tools #91 adds `--env-file` support for ignored local billing credentials without printing secrets or logins | Obtain or rotate the local/internal `INTERNAL_API_SECRET` bearer-token path, via exported env or ignored `--env-file`, then run the live selected-target billing announcement gate | | Linear progress | Linear project status updates, `docs/architecture/progress-sync-contract.md`, generated `operator:dashboard` output, and this mirror | Status update with queue/evidence/missing gates | Every significant merge batch | The project status update should always include: @@ -1201,9 +1220,10 @@ Acceptance: ECC-Tools commit `42653f9` adds Wrangler OAuth KV readback and confirms the current blocker is not Cloudflare read access; it is the absence of a ready-like Marketplace Pro billing-state record with webhook provenance. - ECC-Tools commit `632e059` adds sanitized target-account readback, so the - final operator gate should verify the exact Marketplace test account without - printing its login or raw KV key names. + ECC-Tools commit `632e059` adds sanitized target-account readback, and PRs + #89/#90/#91 move the final operator path to selected-target readback, + selected-target announcement gating, and ignored env-file credential loading + without printing account logins or raw KV key names. ECC-Tools PR #79 redacts the billing announcement gate account output; PR #80 requires failure reasons in runtime receipts; PRs #81/#82 preserve and render AgentShield fleet approval IDs; PR #83 makes Linear follow-up @@ -1213,9 +1233,10 @@ Acceptance: hosted status comments and hosted depth-plan check-runs; and PR #88 exposes authenticated hosted observability API readback for operator dashboards. 2. Run `npm run billing:announcement-gate -- --preflight - --select-ready-target`, then run the same command without `--preflight` and - require `announcementGate.ready === true` before any native GitHub payments - announcement. + --select-ready-target`, adding `--env-file /path/to/ecc-tools.env` when the + local bearer token is stored in an ignored operator file, then run the same + command without `--preflight` and require `announcementGate.ready === true` + before any native GitHub payments announcement. 3. Enable/configure the merged Linear backlog sync path after workspace issue capacity clears or the Linear workspace is upgraded, then verify PR-draft salvage items land in the expected project. diff --git a/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md b/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md index 30237485..f6eb62d4 100644 --- a/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md +++ b/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md @@ -56,7 +56,7 @@ Reason: | Claude marketplace | `.claude-plugin/marketplace.json` points at `ecc` and the public repo | Verify marketplace update/install path after tag exists | External marketplace propagation not verified | | Codex plugin | `codex plugin marketplace` supports local and Git marketplace sources; `.codex-plugin/plugin.json` is present; `.agents/plugins/marketplace.json` exposes `ecc` from the repo root; temp-home local and GitHub-ref marketplace adds passed | Publish rc.1 docs with the repo-marketplace command, then monitor OpenAI's official Plugin Directory path | Do not claim official Plugin Directory listing before OpenAI submission evidence | | OpenCode package | `.opencode/package.json` builds from source and ships inside npm package | Re-run `npm run build:opencode` and package dry-run from release commit | OpenCode CLI 1.2.21 does not expose a separate plugin publication command in this pass | -| ECC Tools billing claim | README and launch copy mention ECC Tools / marketplace context | ECC-Tools #73 adds `/api/billing/readiness` `announcementGate`; run it against a Marketplace-managed test account before any payment announcement | Billing announcement code gate exists; live Marketplace account readback still pending | +| ECC Tools billing claim | README and launch copy mention ECC Tools / marketplace context | ECC-Tools #89/#90/#91 add selected-target billing readback, selected-target announcement gating, and ignored `--env-file` support for the bearer-token path; run the live selected-target gate before any payment announcement | Billing announcement code gate exists; live selected-target announcement readback still pending | | Social and longform copy | X thread, LinkedIn copy, article outline, GitHub release copy exist | Replace any stale URLs, then publish only after release/npm/plugin URLs work | Public URLs not final until release actions complete | ## ITO-46 Blocker Register @@ -71,7 +71,7 @@ Reason: | Codex repo marketplace | Local and GitHub-ref temp-home marketplace add smokes passed on Codex CLI `0.131.0` | `.codex-plugin/plugin.json`, `.agents/plugins/marketplace.json`, repo/personal marketplace evidence | Plugin owner | Official Plugin Directory listing requires OpenAI submission/listing evidence | | Codex official Plugin Directory | OpenAI docs describe the curated official directory; ECC has not submitted or received listing evidence | Directory submission link or OpenAI approval path once available | Plugin owner | Track as an ITO-56/ITO-46 follow-up; do not claim an official listing | | OpenCode package | `npm run build:opencode` passed | Built `.opencode` package metadata inside npm tarball | Package owner | No separate public plugin channel identified; follows npm | -| Billing/native payments | Marketplace Pro target readback and selected-target announcement preflight passed; live announcement remains blocked by ITO-61 | 2026-05-20 selected-target readback, webhook provenance, selected-target announcement gate, `INTERNAL_API_SECRET`, live announcement gate | ECC Tools owner | Do not include native-payments claim in rc.1 announcement until the live selected-target gate passes | +| Billing/native payments | Marketplace Pro target readback, selected-target announcement preflight, and env-file operator path are implemented; live announcement remains blocked by ITO-61 | 2026-05-20 selected-target readback, webhook provenance, selected-target announcement gate, ECC-Tools #91 `--env-file` support, `INTERNAL_API_SECRET`, live announcement gate | ECC Tools owner | Do not include native-payments claim in rc.1 announcement until the live selected-target gate passes | | Social/longform copy | Drafts exist | Final live GitHub, npm, Claude, Codex, billing URLs | Release owner | Publish only after release/package/plugin URLs exist | ## Package Rename After rc.1 diff --git a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md index 0871cd11..8d705458 100644 --- a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md +++ b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md @@ -2,8 +2,8 @@ This dashboard is generated by `npm run operator:dashboard`. It is an operator snapshot, not release approval. -Generated: 2026-05-20T01:57:18.637Z -Commit: 59ac4b4a6a3d750326b81ca4e2c22c54ddb5ad5a +Generated: 2026-05-20T02:29:26.959Z +Commit: 4d3113dd1d40dbc87a5baa351867e50891538220 Status: work remaining ## Current Status @@ -42,7 +42,7 @@ Growth lanes: GitHub Sponsors and OSS partner sponsors; ECC Tools Pro subscripti | Produce the ECC 2.0 release video suite | docs/releases/2.0.0-rc.1/video-suite-production.md and npm run release:video-suite | current | video-suite gate is ready with 15/15 source assets, 13/13 suite artifacts, 12/12 publish candidates, primary self-eval, and zero detected black-frame segments recorded in May 19 evidence | final owner approval, upload, and public video URLs remain approval-gated | | Prepare sponsor, partner, consulting, podcast, talk, and Discussion copy | docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md | in_progress | sponsor outbound, platform partner DM, consulting intro, talk/podcast pitch, GitHub Discussion announcement, CTA hooks, and do-not-send gate are drafted | replace final URLs after publication gates, then get explicit approval before outbound or personal-account posts | | Advance AgentShield enterprise iteration | AgentShield PR evidence plus enterprise roadmap | in_progress | AgentShield policy promotion `reviewItems` landed in `87aec47`; package-manager hardening drift detection landed in `28d08c7`; workflow action runtime pins were refreshed in `659f569`; npm age-gate guidance was corrected in `ee585cd`; package-manager hardening Action outputs landed in `1124535`; policy-promotion Action outputs and runtime-smoke job-summary evidence landed in `1593925`; fleet review ticket payloads and current Mini Shai-Hulud IOC breadcrumbs landed in `840952a`; ECC-Tools consumes those outputs in `8658951`, surfaces operator-readable status/pack/count/digest telemetry in `16c537f`, and renders hosted promotion judge audit traces in `05d4e82`; all are mirrored in the GA roadmap | deepen live operator approval/readback after Marketplace/payment gates | -| Advance ECC Tools native payments and AI-native harness-agnostic app | ECC Tools PR evidence, billing gate, hosted analysis lanes | in_progress | billing announcement gate, selected-target announcement gate, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler OAuth readback, target-account billing readback, provenance-aware Marketplace billing-state gates, sanitized Marketplace plan/action provenance counts, ready Marketplace Pro target selection, hosted team-learning feedback controls, and ECC-Tools Dependabot alert remediation are mirrored in the GA roadmap | obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, then run the live selected-target billing announcement gate before publishing native-payments copy | +| Advance ECC Tools native payments and AI-native harness-agnostic app | ECC Tools PR evidence, billing gate, hosted analysis lanes | in_progress | billing announcement gate, selected-target announcement gate, billing gate env-file operator path, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler OAuth readback, target-account billing readback, provenance-aware Marketplace billing-state gates, sanitized Marketplace plan/action provenance counts, ready Marketplace Pro target selection, hosted team-learning feedback controls, and ECC-Tools Dependabot alert remediation are mirrored in the GA roadmap | obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, via exported env or ignored --env-file, then run the live selected-target billing announcement gate before publishing native-payments copy | | Audit, prune, or attach legacy work | docs/stale-pr-salvage-ledger.md and legacy inventory | current | legacy salvage ledger and inventory are current; all localization tails are attached to Linear ITO-55 for manual language-owner review | repeat legacy scan before release | | Keep Linear roadmap detailed and progress tracking synchronized | Linear project mirror plus progress-sync contract | current | Linear live sync is current with the May 20 Marketplace Pro release-gate comments on ITO-61 and the ECC platform roadmap; progress-sync contract defines the file-backed work-items/status path | repeat Linear/project status update and local work-items sync after each significant merge batch | | Provide ECC 2.0 observability for self-use | observability readiness gate | complete | observability:ready command and readiness doc exist | runtime/dashboard implementation can continue after release gates | @@ -54,7 +54,7 @@ Growth lanes: GitHub Sponsors and OSS partner sponsors; ECC Tools Pro subscripti - `release-notes-and-notifications`: final live release/npm/plugin/billing URLs and publish approval still pending - `partner-sponsor-talks-pack`: replace final URLs after publication gates, then get explicit approval before outbound or personal-account posts - `agentshield-enterprise-iteration`: deepen live operator approval/readback after Marketplace/payment gates -- `ecc-tools-next-level`: obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, then run the live selected-target billing announcement gate before publishing native-payments copy +- `ecc-tools-next-level`: obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, via exported env or ignored --env-file, then run the live selected-target billing announcement gate before publishing native-payments copy ## Next Work Order @@ -63,4 +63,4 @@ Growth lanes: GitHub Sponsors and OSS partner sponsors; ECC Tools Pro subscripti 3. Review the owner-approved primary launch video candidates, choose the final cuts, upload after approval, and attach public video URLs to the release pack. 4. Replace final release, npm, plugin, billing, and video URLs in the partner/sponsor/talk pack, then get explicit approval before outbound. 5. Repeat ITO-57 Linear/project status sync after the next significant merge batch or advisory-source refresh. -6. Obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, then run the live selected-target billing announcement gate before publishing native-payments copy. +6. Obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, via exported env or ignored --env-file, then run the live selected-target billing announcement gate before publishing native-payments copy. diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index f6e9bf9f..f33b3fda 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -26,11 +26,11 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-16.md` | Current May 16/17 queue cleanup, recsys skill merge, GateGuard triage, PR #1947 supply-chain protection, AgentShield #87 plugin-cache confidence evidence, AgentShield #88 evidence-pack inspect/readback, AgentShield #89 evidence-pack fleet routing, AgentShield #90 fleet review items, AgentShield #91 policy export, AgentShield #92 policy promotion, ECC-Tools #76 fleet-summary consumption, ECC-Tools #77 hosted finding evidence paths, ECC-Tools #78 harness policy-route linking, dashboard refresh, and combined Node/Rust/release-surface gate evidence through the May 16 mirror | Must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` | May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack protection recheck, npm audit/signature checks, legacy and Linear progress routing, deterministic preview-pack smoke, operator dashboard refresh, Linear sync, and GitHub CI evidence for `27dc2918` | Superseded by the May 18 evidence snapshot; repeat from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, supply-chain recheck, AgentShield evidence mirror, Linear sync, current-head CI/security scan success for `4470e2e6`, and ITO-46 naming/plugin publication closure | Superseded by the May 19 ECC identity, video, and growth evidence snapshot | -| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19/20 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, release approval gate, May 20 operator dashboard, preview-pack smoke digest `eebb8a66c33e`, 2568-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, PR #2004 Linear readiness evidence sync CI success, PR #2008 supply-chain evidence gate CI success, post-PR #2006 main CI success, PR #2009 project-registry hygiene CI success, post-PR #2009 main CI success, post-PR #2011 GateGuard CI success, post-PR #2013 release-approval-gate CI success, PR #2017/#2018 AgentShield evidence sync, ECC-Tools #79 billing-announcement redaction hardening, ECC-Tools #80-#89 runtime-receipt, AgentShield approval-ID, Linear sync, remediation sync, hosted observability event/status/depth-plan/API readback, Marketplace Pro selected-target readback, AgentShield #94 Zed/VS Code adapter coverage, AgentShield #95 Dependabot alert closure, JARVIS #15/#16 queue/deploy repair, ECC #2019 Marketplace Pro release-gate sync, and the May 19/20 Linear sync comments | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | +| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19/20 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, release approval gate, May 20 operator dashboard, preview-pack smoke digest `eebb8a66c33e`, 2568-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, PR #2004 Linear readiness evidence sync CI success, PR #2008 supply-chain evidence gate CI success, post-PR #2006 main CI success, PR #2009 project-registry hygiene CI success, post-PR #2009 main CI success, post-PR #2011 GateGuard CI success, post-PR #2013 release-approval-gate CI success, PR #2017/#2018 AgentShield evidence sync, ECC-Tools #79 billing-announcement redaction hardening, ECC-Tools #80-#91 runtime-receipt, AgentShield approval-ID, Linear sync, remediation sync, hosted observability event/status/depth-plan/API readback, Marketplace Pro selected-target readback, selected-target announcement gate, env-file billing operator path, AgentShield #94 Zed/VS Code adapter coverage, AgentShield #95 Dependabot alert closure, JARVIS #15/#16 queue/deploy repair, ECC #2019/#2020 Marketplace Pro gate sync, and the May 19/20 Linear sync comments | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 19 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 20 generated dashboard | -| `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and adds the current `$1,728/mo` to `$10,000/mo` hypergrowth, video owner-approval, Linear release-gate sync, and outbound-pack operating lanes | +| `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and adds the current `$1,728/mo` to `$10,000/mo` hypergrowth, video owner-approval, Linear release-gate sync, selected-target billing gate, env-file bearer-token path, and outbound-pack operating lanes | | `docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md` | Final human decision sheet for release, package, plugin, video, billing, social, and outbound approvals | Must be reviewed by the owner before any publication or outbound action | | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md` | Live URL and approval-gated URL ledger for release copy | Must be regenerated from the final release commit before public announcements | | `docs/releases/2.0.0-rc.1/video-suite-production.md` | Release video production manifest | Gates local media inventory, rough primary render, captions, timeline, self-eval, and no-private-path publication rules | @@ -112,8 +112,10 @@ surfaces exist and are recorded in a final evidence file: availability status; - final announcement URLs in X, LinkedIn, GitHub release, and longform copy; - ECC Tools billing/product readiness evidence, the local/internal announcement - bearer-token path, and a live selected-target announcement gate pass before any - native-payments announcement copy is published. + bearer-token path through exported env or ignored `--env-file`, usable + Cloudflare/Wrangler auth for repeat KV evidence, and a live selected-target + announcement gate pass before any native-payments announcement copy is + published. ## Result diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md index 5d4f40d8..bae74588 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -8,9 +8,9 @@ social announcement. | Field | Evidence | | --- | --- | -| Upstream main | `30f60710d4e0424fc70d9bbdc105009db141d9d8` | +| Upstream main | `c2471fe5c535310f8a8008c9ed7ea9f6757b33f2` | | Git remote | `https://github.com/affaan-m/ECC.git` | -| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, PR #2001 owner approval packet addition, PR #2002 owner approval dashboard gate refresh, PR #2004 Linear readiness evidence sync, PR #2005 post-PR #2004 evidence refresh, PR #2008 release supply-chain evidence gate fix, PR #2006 per-project Claude Code adapter, PR #2009 continuous-learning project registry hygiene fix, PR #2011 GateGuard quoted git introspection fix, PR #2013 deterministic release approval gate, PR #2017 AgentShield adapter evidence sync, PR #2018 AgentShield Dependabot evidence sync, ECC-Tools #80-#89 hosted observability/readback and Marketplace Pro selected-target batch, AgentShield #94 Zed/VS Code adapter coverage, AgentShield #95 Dependabot alert closure, and PR #2019 Marketplace Pro release-gate sync | +| Evidence scope | Current `main` after PR #1990 harness-audit GitHub integration scoring, PR #1991 canonical ECC identity gate, PR #1992 release video-suite gate, PR #1993 growth outreach pack, PR #1994 May 19 publication evidence refresh, PR #1995 operator dashboard refresh, PR #1996 primary render self-eval gate, PR #1997 publish-candidate gate, PR #1998 visual QA gate, PR #1999 video dashboard evidence refresh, PR #2000 suite-count evidence refresh, PR #2001 owner approval packet addition, PR #2002 owner approval dashboard gate refresh, PR #2004 Linear readiness evidence sync, PR #2005 post-PR #2004 evidence refresh, PR #2008 release supply-chain evidence gate fix, PR #2006 per-project Claude Code adapter, PR #2009 continuous-learning project registry hygiene fix, PR #2011 GateGuard quoted git introspection fix, PR #2013 deterministic release approval gate, PR #2017 AgentShield adapter evidence sync, PR #2018 AgentShield Dependabot evidence sync, ECC-Tools #80-#91 hosted observability/readback, Marketplace Pro selected-target, selected-target announcement gate, and env-file operator-path batch, AgentShield #94 Zed/VS Code adapter coverage, AgentShield #95 Dependabot alert closure, PR #2019 Marketplace Pro release-gate sync, and PR #2020 selected-target announcement gate sync | | Local status caveat | `git status --short --branch` was clean after pulling `origin/main`; generated evidence files are committed after the source snapshot they describe | The release operator must repeat all publish-facing checks from the exact final @@ -61,6 +61,7 @@ Tracked repositories in the platform audit were: | PR #2017 | Merged the AgentShield #94 evidence mirror as `906e06406e95742944ccb05065f95a7e4dd4a036`, syncing roadmap, publication evidence, preview-pack manifest, and supply-chain incident-response surfaces after full GitHub CI passed | | PR #2018 | Merged the AgentShield #95 Dependabot evidence mirror as `68b4e45145968acd52e68d900f8422061ed7f4a2`, syncing the roadmap, publication evidence, and preview-pack manifest after full PR CI passed | | PR #2019 | Merged the Marketplace Pro selected-target release-gate sync as `30f60710d4e0424fc70d9bbdc105009db141d9d8`, updating the roadmap, publication evidence, naming matrix, preview manifest, and operator dashboard after full PR CI passed | +| PR #2020 | Merged the selected-target announcement gate sync as `c2471fe5c535310f8a8008c9ed7ea9f6757b33f2`, updating the roadmap, publication evidence, naming matrix, preview manifest, release URL ledger, platform audit surfaces, and operator dashboard after full PR CI passed | ## Post-Queue-Zero Sync - 2026-05-19 Late Pass @@ -95,10 +96,14 @@ Tracked repositories in the platform audit were: | ECC-Tools #89 | PR #89 merged as `512bca6b99cdaa67058a6aa9a4e7e7f0b1d9873a` after Verify, Security Audit, and Workers Builds passed. It added `billing:kv-readback -- --select-ready-target --require-ready`, allowing operators to select a ready Marketplace Pro target internally without passing or printing the login. | | Live production readback | The 2026-05-20 Wrangler OAuth readback found ready-like Marketplace Pro records with webhook provenance, selected a target with both key families, seat and webhook readiness, no overage, and 0 blockers, with account details redacted. The old missing Marketplace Pro target-state blocker is cleared. | | ECC #2019 | PR #2019 merged as `30f60710d4e0424fc70d9bbdc105009db141d9d8`, syncing the selected-target readback evidence into the GA roadmap, rc.1 publication evidence, naming matrix, preview manifest, and operator dashboard. | -| Post-merge main CI | GitHub Actions run `26135974576` completed successfully on `main` for `30f60710d4e0424fc70d9bbdc105009db141d9d8` across lint, coverage, security, validation, and the full OS/package-manager matrix. | +| ECC-Tools #90 | PR #90 merged as `16a5bb33ee5ce7c31d2ad8d041e5afac03308f05` after Verify, Security Audit, and Workers Builds passed. It added the selected-target official announcement gate through `/api/billing/readiness?selectReadyTarget=1` and `npm run billing:announcement-gate -- --select-ready-target`, keeping the raw account login out of command logs. | +| ECC #2020 | PR #2020 merged as `c2471fe5c535310f8a8008c9ed7ea9f6757b33f2`, syncing ECC-Tools #90 into the roadmap, publication evidence, naming matrix, preview manifest, publication readiness, release URL ledger, platform audit surfaces, and operator dashboard. | +| ECC-Tools #91 | PR #91 merged as `72119a1acc6f5a0cd3bb5d90afd6e87fd1fefd05` after Verify, Security Audit, and Workers Builds passed. It added `--env-file` to the billing announcement and KV readback scripts for ignored local operator credential files, with tests proving sentinel secrets and account logins are not printed. | +| May 20 live gate recheck | `npm run billing:announcement-gate -- --preflight --select-ready-target` exited 2 with only `INTERNAL_API_SECRET` missing. `npm run billing:kv-readback -- --wrangler --select-ready-target --require-ready` exited 1 with Cloudflare auth code `10000` on this machine. No live announcement gate passed. | +| Post-merge main CI | ECC GitHub Actions runs `26135974576` and `26136949698` completed successfully on `main` for `30f60710d4e0424fc70d9bbdc105009db141d9d8` and `c2471fe5c535310f8a8008c9ed7ea9f6757b33f2` across lint, coverage, security, validation, and the full OS/package-manager matrix. ECC-Tools main CI run `26137280847` completed successfully for `72119a1acc6f5a0cd3bb5d90afd6e87fd1fefd05` across Verify, Security Audit, and Workers Builds. | | Post-merge local gates | `npm run platform:audit -- --json` returned ready true with 0 PRs, 0 issues, 0 discussion gaps, and 0 dirty blockers; `npm run preview-pack:smoke -- --format json` returned ready true with digest `531328aaaa53` before the May 20 dashboard rollover and `eebb8a66c33e` after adding the May 20 dashboard artifact; `git diff --check HEAD~1..HEAD` was clean. | -| Linear roadmap sync | Linear ITO-61 comment `467d148a-712a-4777-aad9-95593e9f1739` and ECC Platform Roadmap project comment `7642ee9c-3107-400c-a229-53e2895a8914` record ECC-Tools #89, ECC #2019, the green post-merge CI run, and the remaining internal bearer-token gate. | -| Remaining blocker | Native-payments announcement copy remains blocked until the local/internal `INTERNAL_API_SECRET` bearer-token path is available and `npm run billing:announcement-gate -- --select-ready-target` returns ready for the selected Marketplace Pro target. | +| Linear roadmap sync | Linear ITO-61 comment `467d148a-712a-4777-aad9-95593e9f1739` and ECC Platform Roadmap project comment `7642ee9c-3107-400c-a229-53e2895a8914` record ECC-Tools #89, ECC #2019, the green post-merge CI run, and the remaining internal bearer-token gate; Linear ITO-44 comment `a9297467-208a-41e4-8dbb-35f0dad5fe2b`, ITO-56 comment `5008b70b-cf98-43cd-a8d4-f098ba9b9780`, ITO-61 comment `5ebf0aaf-e2d3-4537-878f-484f49dcf87a`, and project reply `1c74a3d0-f8ca-4306-997e-a37c53d49f97` record the ECC #2020 selected-target announcement-gate sync and remaining bearer-token/live-gate blocker. | +| Remaining blocker | Native-payments announcement copy remains blocked until the local/internal `INTERNAL_API_SECRET` bearer-token path is available via exported env or ignored `--env-file`, Cloudflare/Wrangler auth is usable for repeat KV evidence, and `npm run billing:announcement-gate -- --select-ready-target` returns ready for the selected Marketplace Pro target. | ## Release And Growth Evidence @@ -127,7 +132,9 @@ Tracked repositories in the platform audit were: | Post-PR #2011 main CI | GitHub Actions run `26113695068` | Completed successfully with 37 completed jobs, 0 failed jobs, and `main` advanced to `14d88e517b0c56a80c1a6392b1cde2474948d29f` | | Post-PR #2013 main CI | GitHub Actions run `26128749863` | Completed successfully with `main` advanced to `9819626459a662773be7d0b1c18d82c1316b8c36` | | Post-PR #2019 main CI | GitHub Actions run `26135974576` | Completed successfully with `main` advanced to `30f60710d4e0424fc70d9bbdc105009db141d9d8` | -| Linear sync | Linear document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` plus project comment `a6411e3a-8c8e-4a58-adba-687e77d4c543`; late-pass document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f` plus project comment `d42bf0e2-7a8e-4934-9f3f-e281498ee805`; May 20 ITO-61 comment `467d148a-712a-4777-aad9-95593e9f1739` plus project comment `7642ee9c-3107-400c-a229-53e2895a8914` | Project and issue lanes record PR #2002 evidence, discussion #2003 routing, owner-approval dashboard gate, and In Progress status for ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56; the late-pass sync attaches PR #2013, ECC-Tools #79, and JARVIS #15/#16 evidence to ITO-44, ITO-50, ITO-54, ITO-56, and ITO-61; the May 20 sync attaches ECC-Tools #89 and ECC #2019 Marketplace Pro selected-target evidence to ITO-61 and the project | +| Post-PR #2020 main CI | GitHub Actions run `26136949698` | Completed successfully with `main` advanced to `c2471fe5c535310f8a8008c9ed7ea9f6757b33f2` | +| ECC-Tools #91 main CI | GitHub Actions run `26137280847` | Completed successfully on ECC-Tools `main` with `72119a1acc6f5a0cd3bb5d90afd6e87fd1fefd05` after the env-file billing gate support merged | +| Linear sync | Linear document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` plus project comment `a6411e3a-8c8e-4a58-adba-687e77d4c543`; late-pass document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f` plus project comment `d42bf0e2-7a8e-4934-9f3f-e281498ee805`; May 20 ITO-61 comment `467d148a-712a-4777-aad9-95593e9f1739` plus project comment `7642ee9c-3107-400c-a229-53e2895a8914`; May 20 ITO-44 comment `a9297467-208a-41e4-8dbb-35f0dad5fe2b`, ITO-56 comment `5008b70b-cf98-43cd-a8d4-f098ba9b9780`, ITO-61 comment `5ebf0aaf-e2d3-4537-878f-484f49dcf87a`, and project reply `1c74a3d0-f8ca-4306-997e-a37c53d49f97` | Project and issue lanes record PR #2002 evidence, discussion #2003 routing, owner-approval dashboard gate, and In Progress status for ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56; the late-pass sync attaches PR #2013, ECC-Tools #79, and JARVIS #15/#16 evidence to ITO-44, ITO-50, ITO-54, ITO-56, and ITO-61; the May 20 sync attaches ECC-Tools #89/#90, ECC #2019/#2020 Marketplace Pro selected-target and selected-target announcement-gate evidence, and the remaining env-file/bearer-token gate to ITO-44, ITO-56, ITO-61, and the project | | Public-path sanitization | `node scripts/ci/validate-no-personal-paths.js` through local suite and CI | Passed | | Markdown and whitespace | `markdownlint` focused release docs plus `git diff --check` before PR #1999 | Passed | @@ -141,8 +148,8 @@ Tracked repositories in the platform audit were: | Growth proof | `partner-sponsor-talks-pack.md` provides approval-gated copy for sponsors, partners, consulting, talks, podcasts, GitHub Discussion, and video CTAs | | Owner approval proof | `owner-approval-packet-2026-05-19.md` centralizes release, package, plugin, video, billing, social, and outbound decision gates | | Business baseline | Hypergrowth command center and partner pack use `$1,728/mo` current MRR, `$10,000/mo` target MRR, and `$8,272/mo` gap | -| Operator dashboard | `operator-readiness-dashboard-2026-05-19.md` pulls the growth baseline into the same queue, publication, video, outbound, AgentShield, ECC Tools, Linear, and supply-chain control surface | -| Linear progress proof | Linear project document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` mirrors the post-PR #2002 state and records active lanes for launch materials, AgentShield, ECC Tools deep analysis, observability, and final release publication; Linear document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f` adds the PR #2013 approval gate, ECC-Tools #79 redaction hardening, and JARVIS #15/#16 queue/deploy repair evidence; May 20 Linear comments `74dcc101-3be5-4173-be13-62b80d54f569`, `348ea8f5-2a2d-46d9-a0fe-ed99653e7fe5`, `291e2a4b-06e3-4672-a057-cdb141478161`, `b2d35de0-ca49-44cb-982a-ddec229e7691`, `faed69dd-35f5-469d-acb5-ddde6a70d6a1`, `70187c1e-d481-4181-b418-09bd65d54b5e`, `371fc3e4-611f-4d20-a23f-67db1260b418`, `bd06e252-15c1-4256-b667-caa3f64f5968`, and `22c2c388-2fd1-4dea-a939-6141f40c9a21` add ECC-Tools #86/#87/#88 hosted observability readback evidence, AgentShield #94 adapter evidence, and AgentShield #95 Dependabot alert closure to ITO-54, ITO-49, ITO-57, and the project | +| Operator dashboard | `operator-readiness-dashboard-2026-05-20.md` pulls the growth baseline into the same queue, publication, video, outbound, AgentShield, ECC Tools billing/env-file gate, Linear, and supply-chain control surface | +| Linear progress proof | Linear project document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` mirrors the post-PR #2002 state and records active lanes for launch materials, AgentShield, ECC Tools deep analysis, observability, and final release publication; Linear document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f` adds the PR #2013 approval gate, ECC-Tools #79 redaction hardening, and JARVIS #15/#16 queue/deploy repair evidence; May 20 Linear comments `74dcc101-3be5-4173-be13-62b80d54f569`, `348ea8f5-2a2d-46d9-a0fe-ed99653e7fe5`, `291e2a4b-06e3-4672-a057-cdb141478161`, `b2d35de0-ca49-44cb-982a-ddec229e7691`, `faed69dd-35f5-469d-acb5-ddde6a70d6a1`, `70187c1e-d481-4181-b418-09bd65d54b5e`, `371fc3e4-611f-4d20-a23f-67db1260b418`, `bd06e252-15c1-4256-b667-caa3f64f5968`, `22c2c388-2fd1-4dea-a939-6141f40c9a21`, `a9297467-208a-41e4-8dbb-35f0dad5fe2b`, `5008b70b-cf98-43cd-a8d4-f098ba9b9780`, `5ebf0aaf-e2d3-4537-878f-484f49dcf87a`, and `1c74a3d0-f8ca-4306-997e-a37c53d49f97` add ECC-Tools hosted observability readback evidence, AgentShield adapter evidence, AgentShield Dependabot alert closure, and Marketplace selected-target announcement-gate evidence to ITO-44, ITO-49, ITO-54, ITO-56, ITO-57, ITO-61, and the project | ## Current Publication Blockers @@ -154,14 +161,18 @@ Tracked repositories in the platform audit were: official Plugin Directory publishing remains blocked on OpenAI submission or listing evidence. - ECC Tools billing/native-payments copy remains blocked until the - local/internal `INTERNAL_API_SECRET` bearer-token path is available and the - live `billing:announcement-gate -- --select-ready-target` check passes. + local/internal `INTERNAL_API_SECRET` bearer-token path is available via + exported env or ignored `--env-file`, Cloudflare/Wrangler auth is usable for + repeat KV evidence, and the live `billing:announcement-gate -- + --select-ready-target` check passes. ECC-Tools PR #89 (`512bca6`) added `billing:kv-readback -- --select-ready-target --require-ready`; its 2026-05-20 production run cleared the old missing-target-state blocker without printing the account login. ECC-Tools PR #90 (`16a5bb3`) added the selected-target official announcement gate, so production preflight no longer needs a raw GitHub login and now blocks only on the missing `INTERNAL_API_SECRET` input before live execution. + ECC-Tools PR #91 (`72119a1`) added `--env-file` support for ignored local + billing credentials without printing loaded secrets or account logins. - Release notes, X, LinkedIn, GitHub release, GitHub Discussion, longform copy, sponsor outreach, partner outreach, consulting copy, conference pitches, and podcast pitches still need final live URLs plus human approval before posting @@ -175,13 +186,14 @@ The tracked public PR queue, issue queue, discussion queue, canonical ECC identity, release video suite, preview pack, growth outreach packet, per-project Claude Code adapter surface, continuous-learning project registry hygiene, GateGuard quoted git introspection fix, deterministic release approval gate, -ECC-Tools billing-announcement redaction hardening, ECC-Tools hosted -observability readback, AgentShield Zed/VS Code adapter coverage, AgentShield -Dependabot alert closure, and JARVIS -security/deploy queue repairs are current on May 20, 2026 for ECC `main` -through `906e06406e95742944ccb05065f95a7e4dd4a036`, ECC-Tools `main` -through `c836ac3fb24ed7e2ae38cd61e41c9651ac9c00f8`, and AgentShield `main` -through `25d91f0002214c408da4ceaac7def20bad40ca10`. The remaining video work is owner +ECC-Tools billing-announcement redaction hardening, selected-target billing +readback, selected-target announcement gate, billing gate env-file operator path, +ECC-Tools hosted observability readback, AgentShield Zed/VS Code adapter coverage, +AgentShield Dependabot alert closure, and JARVIS security/deploy queue repairs +are current on May 20, 2026 for ECC `main` through +`c2471fe5c535310f8a8008c9ed7ea9f6757b33f2`, ECC-Tools `main` through +`72119a1acc6f5a0cd3bb5d90afd6e87fd1fefd05`, and AgentShield `main` through +`25d91f0002214c408da4ceaac7def20bad40ca10`. The remaining video work is owner approval, upload, and public URL attachment, not render or QA production. This improves publication readiness but does not replace the approval-gated diff --git a/docs/releases/2.0.0-rc.1/publication-readiness.md b/docs/releases/2.0.0-rc.1/publication-readiness.md index c921baea..61417fb8 100644 --- a/docs/releases/2.0.0-rc.1/publication-readiness.md +++ b/docs/releases/2.0.0-rc.1/publication-readiness.md @@ -93,7 +93,7 @@ For the May 19 live/pending release URL ledger after the public repo rename, see | Claude plugin | Manifest validates, marketplace JSON points to public repo, install docs match slug | `claude plugin validate .claude-plugin/plugin.json`; `claude plugin tag .claude-plugin --dry-run`; isolated temp-home install smoke | `Blocker: real tag creation/push requires approval` | Plugin owner | Clean-checkout dry-run and install smoke recorded | | Codex plugin | Manifest version matches package and docs, repo marketplace points at the plugin root, and OpenAI's current official Plugin Directory status is recorded | `node tests/docs/ecc2-release-surface.test.js`; `node tests/plugin-manifest.test.js`; `codex plugin marketplace add --help`; temp-home `codex plugin marketplace add ` | `Blocker: official Plugin Directory listing requires OpenAI submission/listing evidence` | Plugin owner | Repo-marketplace distribution verified; official directory pending | | OpenCode package | Build output is regenerated from source and package metadata is current | `npm run build:opencode` | `Blocker: none for local build; public distribution still follows npm/plugin release` | Package owner | Evidence recorded | -| ECC Tools billing reference | Any billing claim links to verified Marketplace/App state | `env -u GITHUB_TOKEN gh repo view ECC-Tools/ECC-Tools --json nameWithOwner,isPrivate,viewerPermission` plus internal `/api/billing/readiness?accountLogin=` readback | `Blocker: ECC-Tools #73 added announcementGate; live Marketplace test-account readback must return announcementGate.ready === true before payment announcement` | ECC Tools owner | Code gate recorded; live billing readback pending | +| ECC Tools billing reference | Any billing claim links to verified Marketplace/App state | `env -u GITHUB_TOKEN gh repo view ECC-Tools/ECC-Tools --json nameWithOwner,isPrivate,viewerPermission` plus internal `/api/billing/readiness?selectReadyTarget=1` readback using exported env or ignored `--env-file` for the bearer token | `Blocker: ECC-Tools #91 added the env-file operator path, but live selected-target announcement readback must return announcementGate.ready === true before payment announcement` | ECC Tools owner | Code gate recorded; live billing readback pending | | Announcement copy | X, LinkedIn, GitHub release, and longform copy point to live URLs | placeholder-marker scan and `release-url-ledger-2026-05-19.md` | `Blocker: final live release/npm/plugin/billing URLs do not exist yet; live and pending URLs are separated in the May 19 ledger` | Release owner | URL ledger recorded; final URLs pending | | Privileged workflow hardening | Release and maintenance workflows avoid persisted checkout tokens | `node scripts/ci/validate-workflow-security.js` | `Blocker:` | Release owner | Evidence recorded in post-hardening refresh | @@ -103,7 +103,7 @@ Record the exact commit SHA and command output before any publication action: | Evidence | Command | Required result | Recorded output | | --- | --- | --- | --- | -| Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | Current May 19 baseline `bc519e5b8ed42f26c0a5a611756e04351c323f21`: `## main...origin/main`; repeat from the exact final publication commit before release | +| Clean release branch | `git status --short --branch` | On intended release commit; no unrelated files | Current May 20 baseline `c2471fe5c535310f8a8008c9ed7ea9f6757b33f2`: `## main...origin/main`; repeat from the exact final publication commit before release | | Preview-pack smoke | `npm run preview-pack:smoke` | Preview pack artifacts, Hermes boundary, final verification command list, and publication blockers pass | `publication-evidence-2026-05-19.md`: ready yes, digest `eebb8a66c33e`, 33 artifacts, 5 passed, 0 failed; repeat in the final strict clean-checkout release pass | | Release approval gate | `npm run release:approval-gate -- --format json` | Ready true only after owner decision rows are approved, live release/package/plugin/video/billing URLs are recorded, and launch/outbound copy has no placeholders or private paths | Current May 19 state is intentionally blocked because owner decisions and live URL readbacks remain approval-gated | | Harness audit | `npm run harness:audit -- --format json` | 80/80 passing | Current release gate: 80/80 across 8 applicable categories, 0 top actions | @@ -116,10 +116,10 @@ Record the exact commit SHA and command output before any publication action: | Package surface | `node tests/scripts/npm-publish-surface.test.js` | 0 failures; no Python bytecode in npm tarball | Current release gate: 2/2 passed | | Release surface | `node tests/docs/ecc2-release-surface.test.js` | 0 failures | Current release gate: 27/27 passed after refreshing the discussion-count assertion to the post-PR #2005 baseline | | Optional Rust surface | `cd ecc2 && cargo test` | 0 failures or explicit deferral | `publication-evidence-2026-05-16.md`: 462/462 passed, existing warnings only | -| Queue baseline | `node scripts/platform-audit.js --json` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | Current May 19 baseline after PR #2009: platform audit ready true, 0 open PRs, 0 open issues, 0 conflicting PRs, and 0 blocking dirty files across tracked repos | +| Queue baseline | `node scripts/platform-audit.js --json` across trunk, AgentShield, JARVIS, ECC Tools, and ECC website | Under 20 open PRs and under 20 open issues | Current May 20 baseline after PR #2020: platform audit ready true, 0 open PRs, 0 open issues, 0 discussion gaps, 0 conflicting PRs, and 0 blocking dirty files across tracked repos | | Discussion baseline | `node scripts/platform-audit.js --json` and `node scripts/discussion-audit.js --json` | No unmanaged active discussion queue and no answerable Q&A missing an accepted answer | Post-PR #2005 baseline: platform audit sampled 59 trunk discussions, 0 needing maintainer touch, 0 answerable discussions missing accepted answer; `docs/architecture/discussion-response-playbook.md` records response templates and security escalation rules | | Linear roadmap | Linear project and issue readback | Detailed roadmap exists with release, security, AgentShield, ECC Tools, legacy, and observability lanes | May 18 Linear comments include ITO-57 `3fe5b2b7-c4fe-401c-a317-b40d72119cb3` and ITO-44 `fb4a4f33-6c2d-421a-bbdb-63cfad3e3ee4`; earlier evidence records the project and 16 issue lanes | -| Operator readiness dashboard | `npm run operator:dashboard -- --json` | Current queue state mapped to macro-goal deliverables and incomplete gaps | Current May 19 dashboard is refreshed from the post-PR #2009 baseline; platform audit ready true, 0 open PRs, 0 open issues, 0 discussion gaps, 0 dirty files, release video suite current, and publication gates still approval-gated | +| Operator readiness dashboard | `npm run operator:dashboard -- --json` | Current queue state mapped to macro-goal deliverables and incomplete gaps | Current May 20 dashboard is refreshed from the post-PR #2020 baseline; platform audit ready true, 0 open PRs, 0 open issues, 0 discussion gaps, 0 dirty files, release video suite current, selected-target billing/env-file path mirrored, and publication gates still approval-gated | | Release URL ledger | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md` plus placeholder-marker scan | Live links and approval-gated links are separated before announcement copy is posted | Ledger records public repo/docs/npm/OpenAI Codex documentation URLs and blocks GitHub release/npm/plugin/billing/social URLs until approval-gated checks pass | | Release name and plugin publication checklist | `docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md` | Name/package/plugin values are frozen, final-release commands are listed, and Claude/Codex publication paths cite current official docs | Checklist keeps `ECC`, `ecc-universal`, and plugin slug `ecc` for rc.1; no npm rename, npm publish, plugin tag, official listing, billing claim, or announcement before final evidence | diff --git a/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md b/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md index 9245e54e..0d14c070 100644 --- a/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md @@ -34,7 +34,7 @@ with output from the exact release commit. | npm rc package | | `npm publish --tag next` approval and post-publish `npm view ecc-universal dist-tags --json` | | Claude plugin tag | `claude plugin tag .claude-plugin --dry-run`, then real tag only after approval | Clean release commit and plugin tag/push approval | | Codex repo marketplace install | `codex plugin marketplace add affaan-m/ECC --ref v2.0.0-rc.1` | GitHub tag must exist; official Plugin Directory submission remains separate | -| ECC Tools native-payments announcement | ECC Tools Marketplace/App URL plus billing readiness readback | Marketplace-managed test account must return `announcementGate.ready === true` | +| ECC Tools native-payments announcement | ECC Tools Marketplace/App URL plus selected-target billing readiness readback, with bearer token supplied through exported env or ignored `--env-file` | Marketplace-managed selected target must return `announcementGate.ready === true` | | Public announcements | X, LinkedIn, GitHub release, and longform URLs | GitHub release, npm, plugin, and billing URLs must resolve first | ## Pre-Post Check diff --git a/scripts/operator-readiness-dashboard.js b/scripts/operator-readiness-dashboard.js index 8507d9e0..3a30087d 100644 --- a/scripts/operator-readiness-dashboard.js +++ b/scripts/operator-readiness-dashboard.js @@ -343,10 +343,12 @@ function agentShieldEnterpriseEvidence(roadmap) { function eccToolsNextLevelEvidence(roadmap) { if (roadmap.includes('selected-target official announcement gate') + || roadmap.includes('billing gate env-file operator path') + || roadmap.includes('72119a1') || roadmap.includes('16a5bb3') || roadmap.includes('select-ready-target') || roadmap.includes('f14ed2fe-a219-470c-8119-63429e197027')) { - return 'billing announcement gate, selected-target announcement gate, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler OAuth readback, target-account billing readback, provenance-aware Marketplace billing-state gates, sanitized Marketplace plan/action provenance counts, ready Marketplace Pro target selection, hosted team-learning feedback controls, and ECC-Tools Dependabot alert remediation are mirrored in the GA roadmap'; + return 'billing announcement gate, selected-target announcement gate, billing gate env-file operator path, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler OAuth readback, target-account billing readback, provenance-aware Marketplace billing-state gates, sanitized Marketplace plan/action provenance counts, ready Marketplace Pro target selection, hosted team-learning feedback controls, and ECC-Tools Dependabot alert remediation are mirrored in the GA roadmap'; } if (roadmap.includes('69ca535') @@ -395,11 +397,13 @@ function eccToolsNextLevelEvidence(roadmap) { function eccToolsNextLevelGap(roadmap) { if (roadmap.includes('selected-target official announcement gate') + || roadmap.includes('billing gate env-file operator path') + || roadmap.includes('72119a1') || roadmap.includes('16a5bb3') || roadmap.includes('select-ready-target') || roadmap.includes('f14ed2fe-a219-470c-8119-63429e197027') || roadmap.includes('old "no Marketplace-managed Pro target billing-state" blocker is cleared')) { - return 'obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, then run the live selected-target billing announcement gate before publishing native-payments copy'; + return 'obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, via exported env or ignored --env-file, then run the live selected-target billing announcement gate before publishing native-payments copy'; } if (roadmap.includes('1Password CLI authorization timed out') @@ -1013,7 +1017,7 @@ function buildReport(options) { releaseVideoWorkOrder, 'Replace final release, npm, plugin, billing, and video URLs in the partner/sponsor/talk pack, then get explicit approval before outbound.', 'Repeat ITO-57 Linear/project status sync after the next significant merge batch or advisory-source refresh.', - 'Obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, then run the live selected-target billing announcement gate before publishing native-payments copy.', + 'Obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, via exported env or ignored --env-file, then run the live selected-target billing announcement gate before publishing native-payments copy.', ], }; } diff --git a/tests/docs/ecc2-release-surface.test.js b/tests/docs/ecc2-release-surface.test.js index ae6125d8..01d9954d 100644 --- a/tests/docs/ecc2-release-surface.test.js +++ b/tests/docs/ecc2-release-surface.test.js @@ -493,7 +493,7 @@ test('publication readiness checklist gates public release actions on evidence', assert.ok(may15Evidence.includes('codex plugin marketplace add ')); assert.ok(may15Evidence.includes('Plugin Directory publishing is still blocked')); assert.ok(may15Evidence.includes('announcementGate.ready === true')); - assert.ok(source.includes('ECC-Tools #73 added announcementGate')); + assert.ok(source.includes('ECC-Tools #91 added the env-file operator path')); assert.ok(source.includes('do not claim official Plugin Directory listing before OpenAI submission evidence')); assert.ok(source.includes('release-name-plugin-publication-checklist-2026-05-18.md')); assert.ok(source.includes('Release name and plugin publication checklist')); diff --git a/tests/scripts/operator-readiness-dashboard.test.js b/tests/scripts/operator-readiness-dashboard.test.js index 47df13ed..2c7e9b93 100644 --- a/tests/scripts/operator-readiness-dashboard.test.js +++ b/tests/scripts/operator-readiness-dashboard.test.js @@ -79,6 +79,8 @@ function seedRepo(rootDir, overrides = {}) { '632e059', 'select-ready-target', 'selected-target official announcement gate', + 'billing gate env-file operator path', + '72119a1', '16a5bb3', 'f14ed2fe-a219-470c-8119-63429e197027', 'old "no Marketplace-managed Pro target billing-state" blocker is cleared', @@ -368,10 +370,11 @@ function runTests() { ))); assert.ok(report.requirements.some(item => ( item.id === 'ecc-tools-next-level' - && item.gap === 'obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, then run the live selected-target billing announcement gate before publishing native-payments copy' + && item.gap === 'obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, via exported env or ignored --env-file, then run the live selected-target billing announcement gate before publishing native-payments copy' && item.evidence.includes('operator-visible promotion output details') && item.evidence.includes('hosted promotion judge audit traces') && item.evidence.includes('selected-target announcement gate') + && item.evidence.includes('billing gate env-file operator path') && item.evidence.includes('billing announcement preflight') && item.evidence.includes('aggregate production billing KV readback') && item.evidence.includes('Wrangler OAuth readback') From 1e8c7e7994223e0ff337d1626cd08e04a1ae67ed Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Tue, 19 May 2026 23:09:39 -0400 Subject: [PATCH 61/61] docs: sync live native payments gate evidence --- docs/ECC-2.0-GA-ROADMAP.md | 36 ++++++++++++++++--- .../naming-and-publication-matrix.md | 4 +-- ...operator-readiness-dashboard-2026-05-20.md | 10 +++--- .../2.0.0-rc.1/preview-pack-manifest.md | 13 ++++--- .../publication-evidence-2026-05-19.md | 28 +++++++++------ .../2.0.0-rc.1/publication-readiness.md | 2 +- ...plugin-publication-checklist-2026-05-18.md | 2 +- .../release-url-ledger-2026-05-19.md | 2 +- scripts/operator-readiness-dashboard.js | 14 +++++++- tests/docs/ecc2-release-surface.test.js | 3 +- .../operator-readiness-dashboard.test.js | 8 +++-- 11 files changed, 86 insertions(+), 36 deletions(-) diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index 6c2f3537..f3bb8e06 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -64,6 +64,23 @@ partner/sponsor funnel, consulting/talk funnel, and social launch plan. secret contents. Verify, Security Audit, and Workers Builds passed before merge as `72119a1`, and main CI run `26137280847` completed successfully after merge. +- ECC-Tools PR #92 added a non-breaking `INTERNAL_OPERATOR_API_SECRET` bearer + accepted by privileged internal API routes without rotating the existing + `INTERNAL_API_SECRET`; Verify, Security Audit, and Workers Builds passed + before merge as `18d80197be779619283e0b37e2952bac53819a07`, and the merged + Worker was deployed to `api.ecc.tools`. +- The May 20 live native-payments gate now passes: the vault-backed Wrangler + readback selected a ready Marketplace Pro target with fingerprint + `e953a74209fe`, both key families present, webhook evidence ready, 0 KV + blockers, and the official + `npm run billing:announcement-gate -- --select-ready-target` returned + `announcementGateReady: true`, 0 required actions, 0 blockers, and audit + summary 6 pass / 1 warn / 0 fail through the new operator bearer path. +- ECC-Tools PR #93 recorded that live billing evidence in the app launch + checklist and distribution roadmap as + `d3d62df83fa075660fa4530c3e0edc311a4355fe`; public native-payments copy is no + longer blocked by billing evidence, but publication timing remains behind the + final release, plugin, live URL, and owner-approval gates. - Linear ITO-54 and the ECC Platform Roadmap now have the May 20 ECC-Tools hosted observability update comments `74dcc101-3be5-4173-be13-62b80d54f569` and @@ -514,9 +531,20 @@ As of 2026-05-20: after Verify, Security Audit, and Workers Builds passed. It adds the billing gate env-file operator path with `--env-file` support for the announcement gate and KV readback scripts, plus sentinel tests proving loaded secrets and - account logins are not printed. The local May 20 live recheck still found no - usable `INTERNAL_API_SECRET`, and Wrangler readback still failed with - Cloudflare auth code `10000`; no native-payments announcement is unblocked. + account logins are not printed. +- ECC-Tools PR #92 merged as `18d80197be779619283e0b37e2952bac53819a07` after + Verify, Security Audit, and Workers Builds passed. It adds the optional + `INTERNAL_OPERATOR_API_SECRET` recovery bearer so operators can run privileged + internal readiness gates without replacing the primary `INTERNAL_API_SECRET`; + the merged Worker was deployed to `api.ecc.tools` before the live gate run. +- ECC-Tools PR #93 merged as `d3d62df83fa075660fa4530c3e0edc311a4355fe` after + Verify, Security Audit, and Workers Builds passed. It records the live + 2026-05-20 billing evidence in the app launch checklist and roadmap: + selected ready Marketplace Pro target, fingerprint `e953a74209fe`, 0 KV + blockers, preflight ready, `announcementGateReady: true`, 0 required actions, + 0 blockers, and audit summary 6 pass / 1 warn / 0 fail. Native-payments copy + is no longer blocked by billing evidence, but final announcement timing still + requires the release, plugin, live URL, and owner-approval gates. - Handoff `ecc-supply-chain-audit-20260513-0645.md` under `~/.cluster-swarm/handoffs/` records the May 13 supply-chain sweep: no active lockfile/manifest hit for @@ -934,7 +962,7 @@ is not complete unless the evidence column exists and has been freshly verified. | Claude and Codex plugin publication | Contact/submission path with required artifacts and status | Publication readiness, naming matrix, and May 12 dry-run evidence document plugin validation, clean-checkout Claude tag/install smoke, and Codex marketplace CLI shape | Needs explicit approval for real tag/push and marketplace submission | | Articles, tweets, and announcements | X thread, LinkedIn copy, GitHub release copy, push checklist, partner/sponsor/talk pack | Draft launch collateral and approval-gated outreach copy exist under rc.1 release docs | Needs URL-backed refresh and human approval before posting or sending | | AgentShield enterprise iteration | Policy gates, SARIF, packs, provenance, corpus, HTML reports, exception lifecycle audit, baseline drift Action/CLI surfaces, evidence-pack redaction, harness adapter registry, editor-native Zed/VS Code adapter coverage, Dependabot alert closure, enterprise research roadmap, supply-chain hardened release path, CI-safe baseline fingerprints, corpus accuracy recommendations, remediation workflow phases, env proxy hijack corpus coverage, Mini Shai-Hulud full-campaign package IOCs, CI-provenance evidence packs, plugin-cache runtime-confidence triage, evidence-pack consumer readback, fleet-level evidence-pack routing, fleet review items, fleet review ticket payloads, checksum-backed policy export, checksum-verified policy promotion, policy promotion review items, package-manager hardening drift detection, npm age-gate guidance correction, workflow action-runtime pin refresh, package-manager hardening Action outputs, policy-promotion Action outputs, ECC-Tools hosted consumption of promotion Action outputs, ECC-Tools operator-visible promotion output values, and ECC-Tools hosted promotion judge audit traces | PRs #53, #55-#64, #67-#69, #78-#92, #94, and #95 landed with test evidence, ECC-Tools #76 consumes the fleet-summary output in hosted security review, #77 surfaces source evidence paths in hosted finding output, and #78 links fleet routes to harness owner review; AgentShield #91 adds `agentshield policy export` bundles for branch-protection review and downstream promotion; AgentShield #92 adds `agentshield policy promote` with digest verification, tamper rejection, explicit pack selection, dry-run review, and JSON output before writing active policy; AgentShield #94 adds Zed/VS Code adapter detection, `.zed/settings.json` and `.zed/tasks.json` scan discovery, and `.zed/setup.mjs` AI-tool persistence IOC coverage; AgentShield #95 clears the `brace-expansion` Dependabot alert with a patched lockfile and 0 open Dependabot alerts after merge; AgentShield commit `87aec47` adds `reviewItems` for digest evidence, owner review, protected rollout PR handoff, and runtime smoke testing with green local and remote CI; AgentShield commit `28d08c7` adds package-manager hardening drift detection for plaintext registry credentials, lifecycle-script enablement, and weak pnpm/Yarn release-age cooldowns with green local and remote CI; AgentShield commit `659f569` refreshes all workflow action runtime pins to SHA-pinned checkout v6.0.2 and setup-node v6.4.0 with green remote CI and no remaining action-runtime deprecation annotation; AgentShield commit `ee585cd` corrects npm release-age guidance by flagging unsupported npm age keys and keeping enforceable cooldown findings on pnpm/Yarn with green local and remote CI; AgentShield commit `1124535` exposes package-manager hardening status/count outputs and a redacted job-summary section for registry credentials, lifecycle scripts, and release-age gates with green local and remote CI; AgentShield commit `1593925` exposes policy-promotion status/count/digest outputs plus job-summary review items for owner approval, protected rollout, and runtime smoke, and marks runtime smoke verified when the same Action job scans with the promoted policy; AgentShield commit `840952a` adds Linear/operator-ready fleet review ticket payloads and expands current Mini Shai-Hulud IOC breadcrumbs with green local and remote CI; ECC-Tools commit `8658951` routes those policy-promotion Action outputs into hosted security review findings and Hosted Promotion Readiness scoring; ECC-Tools commit `16c537f` renders policy-promotion status, pack, review item count, action-required count, and digest in hosted security job comments/check-runs; ECC-Tools commit `05d4e82` renders hosted promotion judge request fingerprints and allowed-citation counts without raw provider output; native PDF export deferred in favor of self-contained HTML plus print-to-PDF until explicit enterprise demand appears; `docs/architecture/agentshield-enterprise-research-roadmap.md` now has baseline drift, evidence-pack bundle, redaction, adapter-registry, supply-chain hardening, hashed baseline fingerprints, corpus accuracy recommendation, remediation workflow, env proxy hijack corpus, Mini Shai-Hulud full-campaign package-table, `ci-context.json` provenance, `plugin-cache` confidence, `evidence-pack inspect` readback, `evidence-pack fleet` routing, fleet `reviewItems`, fleet review ticket payloads, policy export, policy promotion, policy promotion `reviewItems`, package-manager hardening Action outputs, policy-promotion Action outputs, hosted consumption of promotion Action outputs, operator-visible promotion output values, hosted promotion judge audit traces, editor-native adapter coverage, and Dependabot closure landed | Next workflow automation should deepen live operator approval/readback after Marketplace/payment gates | -| ECC Tools next-level app | Billing audit, PR checks, deep analyzer, sync backlog, evaluator/RAG corpus, hosted promotion judge audit trace, native-payments readback, ready Marketplace Pro target selection, selected-target announcement gate, billing gate env-file operator path, hosted observability, AgentShield fleet-summary hosted routing, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output hosted telemetry, and operator-visible promotion output values | PRs #26-#43 plus #53-#91 landed with test evidence across hosted analysis, hosted promotion readiness, model-judge execution, native-payments announcement gating, AgentShield evidence consumption, hosted remediation/Linear sync, hosted observability readback, ready Marketplace Pro target selection, selected-target official announcement gating, and env-file operator loading; ECC-Tools #89 merged as `512bca6` after Verify, Security Audit, and Workers Builds passed, and the 2026-05-20 production Wrangler OAuth readback found ready-like Marketplace Pro records with webhook provenance, selected a target with both key families, and reported 0 blockers without printing the login; ECC-Tools #90 merged as `16a5bb3` after Verify, Security Audit, and Workers Builds passed, and production preflight now requests `/api/billing/readiness?selectReadyTarget=1` without a raw login; ECC-Tools #91 merged as `72119a1` with `--env-file` support for ignored local billing credentials and sentinel no-secret/no-login output tests | Next work is obtain or rotate the local/internal `INTERNAL_API_SECRET` bearer-token path, via exported env or ignored `--env-file`, then run the live selected-target billing announcement gate before publishing native-payments copy | +| ECC Tools next-level app | Billing audit, PR checks, deep analyzer, sync backlog, evaluator/RAG corpus, hosted promotion judge audit trace, native-payments readback, ready Marketplace Pro target selection, selected-target announcement gate, billing gate env-file operator path, hosted observability, AgentShield fleet-summary hosted routing, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output hosted telemetry, and operator-visible promotion output values | PRs #26-#43 plus #53-#93 landed with test evidence across hosted analysis, hosted promotion readiness, model-judge execution, native-payments announcement gating, AgentShield evidence consumption, hosted remediation/Linear sync, hosted observability readback, ready Marketplace Pro target selection, selected-target official announcement gating, and env-file operator loading; ECC-Tools #89 merged as `512bca6` after Verify, Security Audit, and Workers Builds passed, and the 2026-05-20 production Wrangler OAuth readback found ready-like Marketplace Pro records with webhook provenance, selected a target with both key families, and reported 0 blockers without printing the login; ECC-Tools #90 merged as `16a5bb3` after Verify, Security Audit, and Workers Builds passed, and production preflight now requests `/api/billing/readiness?selectReadyTarget=1` without a raw login; ECC-Tools #91 merged as `72119a1` with `--env-file` support for ignored local billing credentials and sentinel no-secret/no-login output tests; ECC-Tools #92 merged as `18d8019`, deployed the non-breaking `INTERNAL_OPERATOR_API_SECRET` path to `api.ecc.tools`, and the 2026-05-20 live selected-target gate returned `announcementGateReady: true` with 0 required actions and 0 blockers; ECC-Tools #93 merged as `d3d62df` to record the live billing evidence in the app launch checklist and roadmap | Repeat KV readback and selected-target announcement gate immediately before launch; keep native-payments copy behind final release, plugin, live URL, and owner-approval gates | | GitGuardian/Dependabot/CodeRabbit-style checks | Non-blocking taxonomy, deterministic follow-up checks, and local supply-chain gates | ECC-Tools risk taxonomy check plus follow-up signals landed, including Skill Quality, Deep Analyzer Evidence, Analyzer Corpus Evidence, RAG/Evaluator Evidence, PR Review/Salvage Evidence, and AgentShield evidence-pack evidence; #1846 added npm registry signature gates; #1848 added the supply-chain incident-response playbook and `pull_request_target` cache-poisoning validator guard; #1851 added the privileged checkout credential-persistence guard; AgentShield #78, JARVIS #13, and ECC-Tools #53 applied the same hardening outside trunk | Current supply-chain gate complete; deeper hosted review features remain future | | Harness-agnostic learning system | Audit, adapter matrix, observability, traces, promotion loop | Audit/adapters/observability gates plus `docs/architecture/evaluator-rag-prototype.md`, `examples/evaluator-rag-prototype/`, and ECC-Tools PR #40 define read-only stale-salvage, billing-readiness, CI-failure-diagnosis, harness-config-quality, AgentShield policy-exception, skill-quality evidence, deep-analyzer evidence, and RAG/evaluator comparison scenarios with trace, report, playbook, verifier, and predictive-check artifacts; ECC-Tools PRs #68-#72 now turn that corpus into a deterministic PR check-run gate with cached hosted-output scoring, ranked retrieval candidates, a model prompt seed, a fail-closed hosted model-judge request contract, and opt-in live model execution behind strict hosted-evidence gates | Deterministic hosted PR check, cached output scoring, retrieval planning, judge contract, and gated model execution integrated | | Linear roadmap is detailed | Linear project document/comments plus repo mirror | Repo mirror exists and issue creation works again; the May 19 sync adds post-PR #2002 document `ecc-may-19-post-pr-2002-sync-64cef8f668e0`, project comment `a6411e3a-8c8e-4a58-adba-687e77d4c543`, ITO-44/47/48/49/51/54/56 issue comments, and In Progress state for ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56; the late-pass batch adds document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f`, project comment `d42bf0e2-7a8e-4934-9f3f-e281498ee805`, and ITO-44/50/54/56/61 comments for PR #2013, ECC-Tools #79, and JARVIS #15/#16 because project status updates are disabled in the workspace | Needs recurring document/comment updates after each significant merge batch | diff --git a/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md b/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md index f6eb62d4..587a2220 100644 --- a/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md +++ b/docs/releases/2.0.0-rc.1/naming-and-publication-matrix.md @@ -56,7 +56,7 @@ Reason: | Claude marketplace | `.claude-plugin/marketplace.json` points at `ecc` and the public repo | Verify marketplace update/install path after tag exists | External marketplace propagation not verified | | Codex plugin | `codex plugin marketplace` supports local and Git marketplace sources; `.codex-plugin/plugin.json` is present; `.agents/plugins/marketplace.json` exposes `ecc` from the repo root; temp-home local and GitHub-ref marketplace adds passed | Publish rc.1 docs with the repo-marketplace command, then monitor OpenAI's official Plugin Directory path | Do not claim official Plugin Directory listing before OpenAI submission evidence | | OpenCode package | `.opencode/package.json` builds from source and ships inside npm package | Re-run `npm run build:opencode` and package dry-run from release commit | OpenCode CLI 1.2.21 does not expose a separate plugin publication command in this pass | -| ECC Tools billing claim | README and launch copy mention ECC Tools / marketplace context | ECC-Tools #89/#90/#91 add selected-target billing readback, selected-target announcement gating, and ignored `--env-file` support for the bearer-token path; run the live selected-target gate before any payment announcement | Billing announcement code gate exists; live selected-target announcement readback still pending | +| ECC Tools billing claim | README and launch copy mention ECC Tools / marketplace context | ECC-Tools #89/#90/#91 add selected-target billing readback, selected-target announcement gating, and ignored `--env-file` support; #92 adds the non-breaking operator bearer path; #93 records the live selected-target gate pass | Billing evidence ready; repeat the live selected-target gate before any payment announcement | | Social and longform copy | X thread, LinkedIn copy, article outline, GitHub release copy exist | Replace any stale URLs, then publish only after release/npm/plugin URLs work | Public URLs not final until release actions complete | ## ITO-46 Blocker Register @@ -71,7 +71,7 @@ Reason: | Codex repo marketplace | Local and GitHub-ref temp-home marketplace add smokes passed on Codex CLI `0.131.0` | `.codex-plugin/plugin.json`, `.agents/plugins/marketplace.json`, repo/personal marketplace evidence | Plugin owner | Official Plugin Directory listing requires OpenAI submission/listing evidence | | Codex official Plugin Directory | OpenAI docs describe the curated official directory; ECC has not submitted or received listing evidence | Directory submission link or OpenAI approval path once available | Plugin owner | Track as an ITO-56/ITO-46 follow-up; do not claim an official listing | | OpenCode package | `npm run build:opencode` passed | Built `.opencode` package metadata inside npm tarball | Package owner | No separate public plugin channel identified; follows npm | -| Billing/native payments | Marketplace Pro target readback, selected-target announcement preflight, and env-file operator path are implemented; live announcement remains blocked by ITO-61 | 2026-05-20 selected-target readback, webhook provenance, selected-target announcement gate, ECC-Tools #91 `--env-file` support, `INTERNAL_API_SECRET`, live announcement gate | ECC Tools owner | Do not include native-payments claim in rc.1 announcement until the live selected-target gate passes | +| Billing/native payments | Marketplace Pro target readback, selected-target announcement preflight, env-file operator path, non-breaking operator bearer, and live selected-target gate have passed | 2026-05-20 selected-target readback, webhook provenance, selected-target announcement gate, ECC-Tools #91 `--env-file` support, ECC-Tools #92 operator bearer, ECC-Tools #93 live gate evidence | ECC Tools owner | Repeat the live gate immediately before rc.1 announcement; final copy still waits on release/plugin/live URL approvals | | Social/longform copy | Drafts exist | Final live GitHub, npm, Claude, Codex, billing URLs | Release owner | Publish only after release/package/plugin URLs exist | ## Package Rename After rc.1 diff --git a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md index 8d705458..fe9642d8 100644 --- a/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md +++ b/docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md @@ -2,8 +2,8 @@ This dashboard is generated by `npm run operator:dashboard`. It is an operator snapshot, not release approval. -Generated: 2026-05-20T02:29:26.959Z -Commit: 4d3113dd1d40dbc87a5baa351867e50891538220 +Generated: 2026-05-20T03:14:39.338Z +Commit: 66733b511b70cf1cb501e8a3298b1cbd9968a9a0 Status: work remaining ## Current Status @@ -42,7 +42,7 @@ Growth lanes: GitHub Sponsors and OSS partner sponsors; ECC Tools Pro subscripti | Produce the ECC 2.0 release video suite | docs/releases/2.0.0-rc.1/video-suite-production.md and npm run release:video-suite | current | video-suite gate is ready with 15/15 source assets, 13/13 suite artifacts, 12/12 publish candidates, primary self-eval, and zero detected black-frame segments recorded in May 19 evidence | final owner approval, upload, and public video URLs remain approval-gated | | Prepare sponsor, partner, consulting, podcast, talk, and Discussion copy | docs/releases/2.0.0-rc.1/partner-sponsor-talks-pack.md | in_progress | sponsor outbound, platform partner DM, consulting intro, talk/podcast pitch, GitHub Discussion announcement, CTA hooks, and do-not-send gate are drafted | replace final URLs after publication gates, then get explicit approval before outbound or personal-account posts | | Advance AgentShield enterprise iteration | AgentShield PR evidence plus enterprise roadmap | in_progress | AgentShield policy promotion `reviewItems` landed in `87aec47`; package-manager hardening drift detection landed in `28d08c7`; workflow action runtime pins were refreshed in `659f569`; npm age-gate guidance was corrected in `ee585cd`; package-manager hardening Action outputs landed in `1124535`; policy-promotion Action outputs and runtime-smoke job-summary evidence landed in `1593925`; fleet review ticket payloads and current Mini Shai-Hulud IOC breadcrumbs landed in `840952a`; ECC-Tools consumes those outputs in `8658951`, surfaces operator-readable status/pack/count/digest telemetry in `16c537f`, and renders hosted promotion judge audit traces in `05d4e82`; all are mirrored in the GA roadmap | deepen live operator approval/readback after Marketplace/payment gates | -| Advance ECC Tools native payments and AI-native harness-agnostic app | ECC Tools PR evidence, billing gate, hosted analysis lanes | in_progress | billing announcement gate, selected-target announcement gate, billing gate env-file operator path, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler OAuth readback, target-account billing readback, provenance-aware Marketplace billing-state gates, sanitized Marketplace plan/action provenance counts, ready Marketplace Pro target selection, hosted team-learning feedback controls, and ECC-Tools Dependabot alert remediation are mirrored in the GA roadmap | obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, via exported env or ignored --env-file, then run the live selected-target billing announcement gate before publishing native-payments copy | +| Advance ECC Tools native payments and AI-native harness-agnostic app | ECC Tools PR evidence, billing gate, hosted analysis lanes | in_progress | billing announcement gate, selected-target announcement gate, billing gate env-file operator path, non-breaking operator bearer path, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler selected-target readback, target-account billing readback, provenance-aware Marketplace billing-state gates, sanitized Marketplace plan/action provenance counts, ready Marketplace Pro target selection, hosted team-learning feedback controls, and ECC-Tools Dependabot alert remediation are mirrored in the GA roadmap | repeat KV readback and selected-target announcement gate immediately before launch; keep native-payments copy behind the final release, plugin, URL, and owner-approval gates | | Audit, prune, or attach legacy work | docs/stale-pr-salvage-ledger.md and legacy inventory | current | legacy salvage ledger and inventory are current; all localization tails are attached to Linear ITO-55 for manual language-owner review | repeat legacy scan before release | | Keep Linear roadmap detailed and progress tracking synchronized | Linear project mirror plus progress-sync contract | current | Linear live sync is current with the May 20 Marketplace Pro release-gate comments on ITO-61 and the ECC platform roadmap; progress-sync contract defines the file-backed work-items/status path | repeat Linear/project status update and local work-items sync after each significant merge batch | | Provide ECC 2.0 observability for self-use | observability readiness gate | complete | observability:ready command and readiness doc exist | runtime/dashboard implementation can continue after release gates | @@ -54,7 +54,7 @@ Growth lanes: GitHub Sponsors and OSS partner sponsors; ECC Tools Pro subscripti - `release-notes-and-notifications`: final live release/npm/plugin/billing URLs and publish approval still pending - `partner-sponsor-talks-pack`: replace final URLs after publication gates, then get explicit approval before outbound or personal-account posts - `agentshield-enterprise-iteration`: deepen live operator approval/readback after Marketplace/payment gates -- `ecc-tools-next-level`: obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, via exported env or ignored --env-file, then run the live selected-target billing announcement gate before publishing native-payments copy +- `ecc-tools-next-level`: repeat KV readback and selected-target announcement gate immediately before launch; keep native-payments copy behind the final release, plugin, URL, and owner-approval gates ## Next Work Order @@ -63,4 +63,4 @@ Growth lanes: GitHub Sponsors and OSS partner sponsors; ECC Tools Pro subscripti 3. Review the owner-approved primary launch video candidates, choose the final cuts, upload after approval, and attach public video URLs to the release pack. 4. Replace final release, npm, plugin, billing, and video URLs in the partner/sponsor/talk pack, then get explicit approval before outbound. 5. Repeat ITO-57 Linear/project status sync after the next significant merge batch or advisory-source refresh. -6. Obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, via exported env or ignored --env-file, then run the live selected-target billing announcement gate before publishing native-payments copy. +6. Repeat KV readback and the selected-target billing announcement gate immediately before launch; keep native-payments copy behind the final release, plugin, URL, and owner-approval gates. diff --git a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md index f33b3fda..2bee8231 100644 --- a/docs/releases/2.0.0-rc.1/preview-pack-manifest.md +++ b/docs/releases/2.0.0-rc.1/preview-pack-manifest.md @@ -26,11 +26,11 @@ surfaces, or posting announcements. | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-16.md` | Current May 16/17 queue cleanup, recsys skill merge, GateGuard triage, PR #1947 supply-chain protection, AgentShield #87 plugin-cache confidence evidence, AgentShield #88 evidence-pack inspect/readback, AgentShield #89 evidence-pack fleet routing, AgentShield #90 fleet review items, AgentShield #91 policy export, AgentShield #92 policy promotion, ECC-Tools #76 fleet-summary consumption, ECC-Tools #77 hosted finding evidence paths, ECC-Tools #78 harness policy-route linking, dashboard refresh, and combined Node/Rust/release-surface gate evidence through the May 16 mirror | Must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-17.md` | May 17 queue-zero state, Japanese localization merge, Dependabot TypeScript and Node type merges, post-merge ja-JP lint repair, Mini Shai-Hulud/TanStack protection recheck, npm audit/signature checks, legacy and Linear progress routing, deterministic preview-pack smoke, operator dashboard refresh, Linear sync, and GitHub CI evidence for `27dc2918` | Superseded by the May 18 evidence snapshot; repeat from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-18.md` | May 18 queue-zero state, #1970/#1971/#1972 merge batch, #1978 review/closure, supply-chain recheck, AgentShield evidence mirror, Linear sync, current-head CI/security scan success for `4470e2e6`, and ITO-46 naming/plugin publication closure | Superseded by the May 19 ECC identity, video, and growth evidence snapshot | -| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19/20 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, release approval gate, May 20 operator dashboard, preview-pack smoke digest `eebb8a66c33e`, 2568-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, PR #2004 Linear readiness evidence sync CI success, PR #2008 supply-chain evidence gate CI success, post-PR #2006 main CI success, PR #2009 project-registry hygiene CI success, post-PR #2009 main CI success, post-PR #2011 GateGuard CI success, post-PR #2013 release-approval-gate CI success, PR #2017/#2018 AgentShield evidence sync, ECC-Tools #79 billing-announcement redaction hardening, ECC-Tools #80-#91 runtime-receipt, AgentShield approval-ID, Linear sync, remediation sync, hosted observability event/status/depth-plan/API readback, Marketplace Pro selected-target readback, selected-target announcement gate, env-file billing operator path, AgentShield #94 Zed/VS Code adapter coverage, AgentShield #95 Dependabot alert closure, JARVIS #15/#16 queue/deploy repair, ECC #2019/#2020 Marketplace Pro gate sync, and the May 19/20 Linear sync comments | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | +| `docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md` | Current May 19/20 evidence for canonical ECC identity, release video suite, partner/sponsor/talk outreach pack, owner approval packet, release approval gate, May 20 operator dashboard, preview-pack smoke digest `eebb8a66c33e`, 2568-test local suite, PR #1998 visual QA CI success, PR #1999 dashboard evidence CI success, PR #2000 suite-count evidence success, PR #2001 owner approval packet CI success, PR #2002 owner-approval dashboard gate CI success, PR #2004 Linear readiness evidence sync CI success, PR #2008 supply-chain evidence gate CI success, post-PR #2006 main CI success, PR #2009 project-registry hygiene CI success, post-PR #2009 main CI success, post-PR #2011 GateGuard CI success, post-PR #2013 release-approval-gate CI success, PR #2017/#2018 AgentShield evidence sync, ECC-Tools #79 billing-announcement redaction hardening, ECC-Tools #80-#93 runtime-receipt, AgentShield approval-ID, Linear sync, remediation sync, hosted observability event/status/depth-plan/API readback, Marketplace Pro selected-target readback, selected-target announcement gate, env-file billing operator path, non-breaking operator bearer path, live `announcementGateReady: true`, AgentShield #94 Zed/VS Code adapter coverage, AgentShield #95 Dependabot alert closure, JARVIS #15/#16 queue/deploy repair, ECC #2019/#2020 Marketplace Pro gate sync, and the May 19/20 Linear sync comments | Current strongest readiness snapshot; must still be repeated from a strict clean checkout before real publication | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-17.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 18 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-18.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 19 generated dashboard | | `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-19.md` | Previous prompt-to-artifact operator dashboard | Superseded by the May 20 generated dashboard | -| `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and adds the current `$1,728/mo` to `$10,000/mo` hypergrowth, video owner-approval, Linear release-gate sync, selected-target billing gate, env-file bearer-token path, and outbound-pack operating lanes | +| `docs/releases/2.0.0-rc.1/operator-readiness-dashboard-2026-05-20.md` | Current prompt-to-artifact operator dashboard | Shows PR/issue/discussion/platform/supply-chain gates current and adds the current `$1,728/mo` to `$10,000/mo` hypergrowth, video owner-approval, Linear release-gate sync, selected-target billing gate, operator bearer path, live billing gate pass, and outbound-pack operating lanes | | `docs/releases/2.0.0-rc.1/owner-approval-packet-2026-05-19.md` | Final human decision sheet for release, package, plugin, video, billing, social, and outbound approvals | Must be reviewed by the owner before any publication or outbound action | | `docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md` | Live URL and approval-gated URL ledger for release copy | Must be regenerated from the final release commit before public announcements | | `docs/releases/2.0.0-rc.1/video-suite-production.md` | Release video production manifest | Gates local media inventory, rough primary render, captions, timeline, self-eval, and no-private-path publication rules | @@ -111,11 +111,10 @@ surfaces exist and are recorded in a final evidence file: - Codex repo-marketplace distribution evidence plus official Plugin Directory availability status; - final announcement URLs in X, LinkedIn, GitHub release, and longform copy; -- ECC Tools billing/product readiness evidence, the local/internal announcement - bearer-token path through exported env or ignored `--env-file`, usable - Cloudflare/Wrangler auth for repeat KV evidence, and a live selected-target - announcement gate pass before any native-payments announcement copy is - published. +- ECC Tools billing/product readiness evidence remains fresh: the May 20 + selected-target KV readback and live announcement gate passed through the + operator bearer path. Repeat the billing readback and gate immediately before + any native-payments announcement copy is published. ## Result diff --git a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md index bae74588..fab16743 100644 --- a/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/publication-evidence-2026-05-19.md @@ -99,11 +99,13 @@ Tracked repositories in the platform audit were: | ECC-Tools #90 | PR #90 merged as `16a5bb33ee5ce7c31d2ad8d041e5afac03308f05` after Verify, Security Audit, and Workers Builds passed. It added the selected-target official announcement gate through `/api/billing/readiness?selectReadyTarget=1` and `npm run billing:announcement-gate -- --select-ready-target`, keeping the raw account login out of command logs. | | ECC #2020 | PR #2020 merged as `c2471fe5c535310f8a8008c9ed7ea9f6757b33f2`, syncing ECC-Tools #90 into the roadmap, publication evidence, naming matrix, preview manifest, publication readiness, release URL ledger, platform audit surfaces, and operator dashboard. | | ECC-Tools #91 | PR #91 merged as `72119a1acc6f5a0cd3bb5d90afd6e87fd1fefd05` after Verify, Security Audit, and Workers Builds passed. It added `--env-file` to the billing announcement and KV readback scripts for ignored local operator credential files, with tests proving sentinel secrets and account logins are not printed. | -| May 20 live gate recheck | `npm run billing:announcement-gate -- --preflight --select-ready-target` exited 2 with only `INTERNAL_API_SECRET` missing. `npm run billing:kv-readback -- --wrangler --select-ready-target --require-ready` exited 1 with Cloudflare auth code `10000` on this machine. No live announcement gate passed. | -| Post-merge main CI | ECC GitHub Actions runs `26135974576` and `26136949698` completed successfully on `main` for `30f60710d4e0424fc70d9bbdc105009db141d9d8` and `c2471fe5c535310f8a8008c9ed7ea9f6757b33f2` across lint, coverage, security, validation, and the full OS/package-manager matrix. ECC-Tools main CI run `26137280847` completed successfully for `72119a1acc6f5a0cd3bb5d90afd6e87fd1fefd05` across Verify, Security Audit, and Workers Builds. | +| ECC-Tools #92 | PR #92 merged as `18d80197be779619283e0b37e2952bac53819a07` after Verify, Security Audit, and Workers Builds passed. It added the non-breaking `INTERNAL_OPERATOR_API_SECRET` bearer accepted by privileged internal API routes without rotating the primary `INTERNAL_API_SECRET`, and the merged Worker was deployed to `api.ecc.tools`. | +| May 20 live selected-target gate | Vault-backed Wrangler readback passed with Marketplace Pro state, target fingerprint `e953a74209fe`, both key families, webhook evidence, seat readiness, no overage, and 0 blockers. After rotating the operator bearer, `npm run billing:announcement-gate -- --preflight --select-ready-target` returned ready and `npm run billing:announcement-gate -- --select-ready-target` returned `announcementGateReady: true`, 0 required actions, 0 blockers, and audit summary 6 pass / 1 warn / 0 fail. | +| ECC-Tools #93 | PR #93 merged as `d3d62df83fa075660fa4530c3e0edc311a4355fe`, recording the live billing announcement gate pass in the launch checklist and distribution roadmap while preserving final release/plugin/URL approval gates. | +| Post-merge main CI | ECC GitHub Actions runs `26135974576`, `26136949698`, and `26138015245` completed successfully on `main` for `30f60710d4e0424fc70d9bbdc105009db141d9d8`, `c2471fe5c535310f8a8008c9ed7ea9f6757b33f2`, and `6e25458dbc15cd07cfb7a4e1f0b06f3eda41a043` across lint, coverage, security, validation, and the full OS/package-manager matrix. ECC-Tools main CI runs `26137280847`, `26138403065`, and `26138669148` completed successfully for `72119a1acc6f5a0cd3bb5d90afd6e87fd1fefd05`, `18d80197be779619283e0b37e2952bac53819a07`, and `d3d62df83fa075660fa4530c3e0edc311a4355fe`. | | Post-merge local gates | `npm run platform:audit -- --json` returned ready true with 0 PRs, 0 issues, 0 discussion gaps, and 0 dirty blockers; `npm run preview-pack:smoke -- --format json` returned ready true with digest `531328aaaa53` before the May 20 dashboard rollover and `eebb8a66c33e` after adding the May 20 dashboard artifact; `git diff --check HEAD~1..HEAD` was clean. | -| Linear roadmap sync | Linear ITO-61 comment `467d148a-712a-4777-aad9-95593e9f1739` and ECC Platform Roadmap project comment `7642ee9c-3107-400c-a229-53e2895a8914` record ECC-Tools #89, ECC #2019, the green post-merge CI run, and the remaining internal bearer-token gate; Linear ITO-44 comment `a9297467-208a-41e4-8dbb-35f0dad5fe2b`, ITO-56 comment `5008b70b-cf98-43cd-a8d4-f098ba9b9780`, ITO-61 comment `5ebf0aaf-e2d3-4537-878f-484f49dcf87a`, and project reply `1c74a3d0-f8ca-4306-997e-a37c53d49f97` record the ECC #2020 selected-target announcement-gate sync and remaining bearer-token/live-gate blocker. | -| Remaining blocker | Native-payments announcement copy remains blocked until the local/internal `INTERNAL_API_SECRET` bearer-token path is available via exported env or ignored `--env-file`, Cloudflare/Wrangler auth is usable for repeat KV evidence, and `npm run billing:announcement-gate -- --select-ready-target` returns ready for the selected Marketplace Pro target. | +| Linear roadmap sync | Linear ITO-61 comment `467d148a-712a-4777-aad9-95593e9f1739` and ECC Platform Roadmap project comment `7642ee9c-3107-400c-a229-53e2895a8914` record ECC-Tools #89, ECC #2019, the green post-merge CI run, and the earlier internal bearer-token gate; Linear ITO-44 comment `a9297467-208a-41e4-8dbb-35f0dad5fe2b`, ITO-56 comment `5008b70b-cf98-43cd-a8d4-f098ba9b9780`, ITO-61 comment `5ebf0aaf-e2d3-4537-878f-484f49dcf87a`, and project reply `1c74a3d0-f8ca-4306-997e-a37c53d49f97` record the ECC #2020 selected-target announcement-gate sync; a new Linear sync should record ECC-Tools #92/#93 and the live gate pass. | +| Remaining blocker | Native-payments billing evidence is ready as of the May 20 selected-target gate pass. Repeat KV readback and `billing:announcement-gate -- --select-ready-target` immediately before launch, and keep native-payments copy behind the final release, plugin, live URL, and owner-approval gates. | ## Release And Growth Evidence @@ -134,6 +136,8 @@ Tracked repositories in the platform audit were: | Post-PR #2019 main CI | GitHub Actions run `26135974576` | Completed successfully with `main` advanced to `30f60710d4e0424fc70d9bbdc105009db141d9d8` | | Post-PR #2020 main CI | GitHub Actions run `26136949698` | Completed successfully with `main` advanced to `c2471fe5c535310f8a8008c9ed7ea9f6757b33f2` | | ECC-Tools #91 main CI | GitHub Actions run `26137280847` | Completed successfully on ECC-Tools `main` with `72119a1acc6f5a0cd3bb5d90afd6e87fd1fefd05` after the env-file billing gate support merged | +| ECC-Tools #92 main CI | GitHub Actions run `26138403065` | Completed successfully on ECC-Tools `main` with `18d80197be779619283e0b37e2952bac53819a07` after the operator bearer path merged | +| ECC-Tools #93 main CI | GitHub Actions run `26138669148` | Completed successfully on ECC-Tools `main` with `d3d62df83fa075660fa4530c3e0edc311a4355fe` after the live billing announcement evidence merged | | Linear sync | Linear document `ecc-may-19-post-pr-2002-sync-64cef8f668e0` plus project comment `a6411e3a-8c8e-4a58-adba-687e77d4c543`; late-pass document `ecc-may-19-late-queue-zero-and-release-gate-sync-1c26f65e6b3f` plus project comment `d42bf0e2-7a8e-4934-9f3f-e281498ee805`; May 20 ITO-61 comment `467d148a-712a-4777-aad9-95593e9f1739` plus project comment `7642ee9c-3107-400c-a229-53e2895a8914`; May 20 ITO-44 comment `a9297467-208a-41e4-8dbb-35f0dad5fe2b`, ITO-56 comment `5008b70b-cf98-43cd-a8d4-f098ba9b9780`, ITO-61 comment `5ebf0aaf-e2d3-4537-878f-484f49dcf87a`, and project reply `1c74a3d0-f8ca-4306-997e-a37c53d49f97` | Project and issue lanes record PR #2002 evidence, discussion #2003 routing, owner-approval dashboard gate, and In Progress status for ITO-47, ITO-48, ITO-49, ITO-51, ITO-54, and ITO-56; the late-pass sync attaches PR #2013, ECC-Tools #79, and JARVIS #15/#16 evidence to ITO-44, ITO-50, ITO-54, ITO-56, and ITO-61; the May 20 sync attaches ECC-Tools #89/#90, ECC #2019/#2020 Marketplace Pro selected-target and selected-target announcement-gate evidence, and the remaining env-file/bearer-token gate to ITO-44, ITO-56, ITO-61, and the project | | Public-path sanitization | `node scripts/ci/validate-no-personal-paths.js` through local suite and CI | Passed | | Markdown and whitespace | `markdownlint` focused release docs plus `git diff --check` before PR #1999 | Passed | @@ -160,19 +164,21 @@ Tracked repositories in the platform audit were: - Codex repo-marketplace distribution is verified by prior evidence, but official Plugin Directory publishing remains blocked on OpenAI submission or listing evidence. -- ECC Tools billing/native-payments copy remains blocked until the - local/internal `INTERNAL_API_SECRET` bearer-token path is available via - exported env or ignored `--env-file`, Cloudflare/Wrangler auth is usable for - repeat KV evidence, and the live `billing:announcement-gate -- - --select-ready-target` check passes. +- ECC Tools billing/native-payments evidence is no longer blocked by the + internal bearer-token path or selected-target announcement gate. Repeat + `billing:kv-readback -- --select-ready-target --require-ready` and + `billing:announcement-gate -- --select-ready-target` immediately before + launch, and keep the copy behind the final release, plugin, live URL, and + owner-approval gates. ECC-Tools PR #89 (`512bca6`) added `billing:kv-readback -- --select-ready-target --require-ready`; its 2026-05-20 production run cleared the old missing-target-state blocker without printing the account login. ECC-Tools PR #90 (`16a5bb3`) added the selected-target official announcement - gate, so production preflight no longer needs a raw GitHub login and now - blocks only on the missing `INTERNAL_API_SECRET` input before live execution. + gate, so production preflight no longer needs a raw GitHub login. ECC-Tools PR #91 (`72119a1`) added `--env-file` support for ignored local billing credentials without printing loaded secrets or account logins. + ECC-Tools PR #92 (`18d8019`) added the non-breaking operator bearer path, and + ECC-Tools PR #93 (`d3d62df`) recorded the live gate pass. - Release notes, X, LinkedIn, GitHub release, GitHub Discussion, longform copy, sponsor outreach, partner outreach, consulting copy, conference pitches, and podcast pitches still need final live URLs plus human approval before posting diff --git a/docs/releases/2.0.0-rc.1/publication-readiness.md b/docs/releases/2.0.0-rc.1/publication-readiness.md index 61417fb8..20674cd1 100644 --- a/docs/releases/2.0.0-rc.1/publication-readiness.md +++ b/docs/releases/2.0.0-rc.1/publication-readiness.md @@ -93,7 +93,7 @@ For the May 19 live/pending release URL ledger after the public repo rename, see | Claude plugin | Manifest validates, marketplace JSON points to public repo, install docs match slug | `claude plugin validate .claude-plugin/plugin.json`; `claude plugin tag .claude-plugin --dry-run`; isolated temp-home install smoke | `Blocker: real tag creation/push requires approval` | Plugin owner | Clean-checkout dry-run and install smoke recorded | | Codex plugin | Manifest version matches package and docs, repo marketplace points at the plugin root, and OpenAI's current official Plugin Directory status is recorded | `node tests/docs/ecc2-release-surface.test.js`; `node tests/plugin-manifest.test.js`; `codex plugin marketplace add --help`; temp-home `codex plugin marketplace add ` | `Blocker: official Plugin Directory listing requires OpenAI submission/listing evidence` | Plugin owner | Repo-marketplace distribution verified; official directory pending | | OpenCode package | Build output is regenerated from source and package metadata is current | `npm run build:opencode` | `Blocker: none for local build; public distribution still follows npm/plugin release` | Package owner | Evidence recorded | -| ECC Tools billing reference | Any billing claim links to verified Marketplace/App state | `env -u GITHUB_TOKEN gh repo view ECC-Tools/ECC-Tools --json nameWithOwner,isPrivate,viewerPermission` plus internal `/api/billing/readiness?selectReadyTarget=1` readback using exported env or ignored `--env-file` for the bearer token | `Blocker: ECC-Tools #91 added the env-file operator path, but live selected-target announcement readback must return announcementGate.ready === true before payment announcement` | ECC Tools owner | Code gate recorded; live billing readback pending | +| ECC Tools billing reference | Any billing claim links to verified Marketplace/App state | `env -u GITHUB_TOKEN gh repo view ECC-Tools/ECC-Tools --json nameWithOwner,isPrivate,viewerPermission` plus internal `/api/billing/readiness?selectReadyTarget=1` readback using the operator bearer path | `Ready: ECC-Tools #92 main CI and ECC-Tools #93 main CI passed; live selected-target readback returned announcementGate.ready === true on 2026-05-20; repeat before payment announcement` | ECC Tools owner | Billing evidence ready; final copy still waits on release/plugin/live URL approvals | | Announcement copy | X, LinkedIn, GitHub release, and longform copy point to live URLs | placeholder-marker scan and `release-url-ledger-2026-05-19.md` | `Blocker: final live release/npm/plugin/billing URLs do not exist yet; live and pending URLs are separated in the May 19 ledger` | Release owner | URL ledger recorded; final URLs pending | | Privileged workflow hardening | Release and maintenance workflows avoid persisted checkout tokens | `node scripts/ci/validate-workflow-security.js` | `Blocker:` | Release owner | Evidence recorded in post-hardening refresh | diff --git a/docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md b/docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md index 125dc5e4..24170fad 100644 --- a/docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md +++ b/docs/releases/2.0.0-rc.1/release-name-plugin-publication-checklist-2026-05-18.md @@ -41,7 +41,7 @@ Reasons: | Claude marketplace | `.claude-plugin/marketplace.json` | `claude plugin marketplace add --help`; Anthropic plugin marketplace docs | GitHub repo, git URL, remote marketplace JSON, and local path marketplace sources are supported | Verify post-tag marketplace install/update path after final evidence | | Codex plugin | `ecc@2.0.0-rc.1` | `node tests/plugin-manifest.test.js`; `codex plugin marketplace add --help`; OpenAI Codex plugin docs | Plugin manifest passed 54/54; local and GitHub-ref repo marketplace smokes passed on Codex CLI `0.131.0` | Use repo marketplace for rc.1; do not claim official directory listing until OpenAI publishing path is available | | OpenCode package | `ecc-universal@2.0.0-rc.1` | `node -p "require('./.opencode/package.json').name + '@' + require('./.opencode/package.json').version"` | Matches rc.1 package identity | Follow npm package publication | -| Billing claim | Pending ECC Tools readiness | ECC Tools billing gate and Marketplace account readback | Code-side gate exists; live Marketplace account readback still pending | Do not announce native payments | +| Billing claim | ECC Tools selected-target billing evidence ready | ECC Tools billing gate and Marketplace account readback | May 20 selected-target readback and live selected-target announcement gate passed with `announcementGateReady: true`; repeat immediately before announcement | Do not announce native payments until final release/plugin/live URL approvals are green | ## Required Gate diff --git a/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md b/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md index 0d14c070..c5ea4afa 100644 --- a/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md +++ b/docs/releases/2.0.0-rc.1/release-url-ledger-2026-05-19.md @@ -34,7 +34,7 @@ with output from the exact release commit. | npm rc package | | `npm publish --tag next` approval and post-publish `npm view ecc-universal dist-tags --json` | | Claude plugin tag | `claude plugin tag .claude-plugin --dry-run`, then real tag only after approval | Clean release commit and plugin tag/push approval | | Codex repo marketplace install | `codex plugin marketplace add affaan-m/ECC --ref v2.0.0-rc.1` | GitHub tag must exist; official Plugin Directory submission remains separate | -| ECC Tools native-payments announcement | ECC Tools Marketplace/App URL plus selected-target billing readiness readback, with bearer token supplied through exported env or ignored `--env-file` | Marketplace-managed selected target must return `announcementGate.ready === true` | +| ECC Tools native-payments announcement | ECC Tools Marketplace/App URL plus selected-target billing readiness readback through the operator bearer path | Marketplace-managed selected target returned `announcementGate.ready === true` on 2026-05-20; repeat immediately before publication | | Public announcements | X, LinkedIn, GitHub release, and longform URLs | GitHub release, npm, plugin, and billing URLs must resolve first | ## Pre-Post Check diff --git a/scripts/operator-readiness-dashboard.js b/scripts/operator-readiness-dashboard.js index 3a30087d..4de99084 100644 --- a/scripts/operator-readiness-dashboard.js +++ b/scripts/operator-readiness-dashboard.js @@ -342,6 +342,12 @@ function agentShieldEnterpriseEvidence(roadmap) { } function eccToolsNextLevelEvidence(roadmap) { + if (roadmap.includes('announcementGateReady` is `true') + || roadmap.includes('Native GitHub payments announcement gate is ready') + || roadmap.includes('d3d62df83fa075660fa4530c3e0edc311a4355fe')) { + return 'billing announcement gate, selected-target announcement gate, billing gate env-file operator path, non-breaking operator bearer path, hosted analysis lanes, AgentShield fleet-summary consumption, hosted finding evidence paths, harness-route policy linking, policy-promotion Action-output telemetry, operator-visible promotion output details, hosted promotion judge audit traces, billing announcement preflight, aggregate production billing KV readback, Wrangler selected-target readback, target-account billing readback, provenance-aware Marketplace billing-state gates, sanitized Marketplace plan/action provenance counts, ready Marketplace Pro target selection, hosted team-learning feedback controls, and ECC-Tools Dependabot alert remediation are mirrored in the GA roadmap'; + } + if (roadmap.includes('selected-target official announcement gate') || roadmap.includes('billing gate env-file operator path') || roadmap.includes('72119a1') @@ -396,6 +402,12 @@ function eccToolsNextLevelEvidence(roadmap) { } function eccToolsNextLevelGap(roadmap) { + if (roadmap.includes('announcementGateReady` is `true') + || roadmap.includes('Native GitHub payments announcement gate is ready') + || roadmap.includes('d3d62df83fa075660fa4530c3e0edc311a4355fe')) { + return 'repeat KV readback and selected-target announcement gate immediately before launch; keep native-payments copy behind the final release, plugin, URL, and owner-approval gates'; + } + if (roadmap.includes('selected-target official announcement gate') || roadmap.includes('billing gate env-file operator path') || roadmap.includes('72119a1') @@ -1017,7 +1029,7 @@ function buildReport(options) { releaseVideoWorkOrder, 'Replace final release, npm, plugin, billing, and video URLs in the partner/sponsor/talk pack, then get explicit approval before outbound.', 'Repeat ITO-57 Linear/project status sync after the next significant merge batch or advisory-source refresh.', - 'Obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, via exported env or ignored --env-file, then run the live selected-target billing announcement gate before publishing native-payments copy.', + 'Repeat KV readback and the selected-target billing announcement gate immediately before launch; keep native-payments copy behind the final release, plugin, URL, and owner-approval gates.', ], }; } diff --git a/tests/docs/ecc2-release-surface.test.js b/tests/docs/ecc2-release-surface.test.js index 01d9954d..554eb363 100644 --- a/tests/docs/ecc2-release-surface.test.js +++ b/tests/docs/ecc2-release-surface.test.js @@ -493,7 +493,8 @@ test('publication readiness checklist gates public release actions on evidence', assert.ok(may15Evidence.includes('codex plugin marketplace add ')); assert.ok(may15Evidence.includes('Plugin Directory publishing is still blocked')); assert.ok(may15Evidence.includes('announcementGate.ready === true')); - assert.ok(source.includes('ECC-Tools #91 added the env-file operator path')); + assert.ok(source.includes('ECC-Tools #92 main CI')); + assert.ok(source.includes('ECC-Tools #93 main CI')); assert.ok(source.includes('do not claim official Plugin Directory listing before OpenAI submission evidence')); assert.ok(source.includes('release-name-plugin-publication-checklist-2026-05-18.md')); assert.ok(source.includes('Release name and plugin publication checklist')); diff --git a/tests/scripts/operator-readiness-dashboard.test.js b/tests/scripts/operator-readiness-dashboard.test.js index 2c7e9b93..690866c9 100644 --- a/tests/scripts/operator-readiness-dashboard.test.js +++ b/tests/scripts/operator-readiness-dashboard.test.js @@ -80,6 +80,9 @@ function seedRepo(rootDir, overrides = {}) { 'select-ready-target', 'selected-target official announcement gate', 'billing gate env-file operator path', + 'non-breaking operator bearer path', + 'announcementGateReady` is `true', + 'd3d62df83fa075660fa4530c3e0edc311a4355fe', '72119a1', '16a5bb3', 'f14ed2fe-a219-470c-8119-63429e197027', @@ -370,14 +373,15 @@ function runTests() { ))); assert.ok(report.requirements.some(item => ( item.id === 'ecc-tools-next-level' - && item.gap === 'obtain or rotate the local/internal INTERNAL_API_SECRET bearer-token path, via exported env or ignored --env-file, then run the live selected-target billing announcement gate before publishing native-payments copy' + && item.gap === 'repeat KV readback and selected-target announcement gate immediately before launch; keep native-payments copy behind the final release, plugin, URL, and owner-approval gates' && item.evidence.includes('operator-visible promotion output details') && item.evidence.includes('hosted promotion judge audit traces') && item.evidence.includes('selected-target announcement gate') && item.evidence.includes('billing gate env-file operator path') + && item.evidence.includes('non-breaking operator bearer path') && item.evidence.includes('billing announcement preflight') && item.evidence.includes('aggregate production billing KV readback') - && item.evidence.includes('Wrangler OAuth readback') + && item.evidence.includes('Wrangler selected-target readback') && item.evidence.includes('target-account billing readback') && item.evidence.includes('provenance-aware Marketplace billing-state gates') && item.evidence.includes('ready Marketplace Pro target selection')