Skip to content
This repository was archived by the owner on Sep 19, 2026. It is now read-only.

Latest commit

 

History

History
328 lines (208 loc) · 75.6 KB

File metadata and controls

328 lines (208 loc) · 75.6 KB

Public CLI release control

Status: v0.8.5 is an unreleased Devin provider and upgrade-repair candidate. v0.8.4 passed immutable GitHub and exact-byte npm release admission in release run 35136703343, attempt 2. Its exact release record binds source, immutable bytes, and cryptographic provenance. The v0.8.1 canonical GitHub predecessor and its unadmitted npm mirror retain their historical records. Artifact admission does not clear the blocked hosted command-writer rollout or authorize daemon upgrades. The published v0.6.0 artifacts remain an immutable partial publication, not an admitted release; preserve them without retrying, retagging, replacing, or deleting them.

The v0.8.5 candidate restores active Devin provider support, names the oompa command in the restored Devin login builders, and repairs the schema-61 upgrade for state roots that v0.8.4 migrated to schema 60; it requires its own exact artifact admission. The v0.8.4 patch repairs the upgrade migration from pre-authority state roots and names the refused invariant on a migration failure; it changes no schema, provider, or activation authority and passed its own exact artifact admission recorded below. The v0.8.3 patch adds optional support through the shared CLI protocol, native menu and public footer; it retains the existing interactive root-help introduction. The immutable v0.8.0 GitHub artifact passed canonical admission in release run 34560340100, attempt 1; its optional npm mirror remains unadmitted. Preserve its source and release bytes. Its admission does not authorize operational rollout; v0.8.3 has its own exact release evidence below.

The release retains provider-qualified cached account listing, revision- and idempotency-bound automatic usage policy controls, and provider recovery and attachment-custody repairs. It does not expose automatic account movement, managed-send forwarding, Claude native fallback, or the planned live usage meter. The browser adds a separately labelled daily Codex usage history; it cannot establish live capacity, reset credits, throughput or forecasts. Its tagged installer is available through the admitted v0.8.4 installation notes. The optional npm mirror passed separate exact-byte and provenance admission in the same release run. Preserve predecessor records; a local check or successful source merge never substitutes for the release workflow.

The v0.8.3 release retains the admitted v0.7.1 release's read-only exact Codex default-profile companion and browser-safe projection decoder that does not require CSP-blocked dynamic code generation. The display remains unavailable until a matching fresh companion is published by the intended daemon after the relevant rollout. That companion does not select routes or change command authority. Separately, this release retains Astra contract 2 for new and explicitly reselected Codex High/Ultra sessions and lets new browser starts choose Max effort for conservatively bounded prompts. Existing sessions retain their exact binding, and the capacity and target-marker gates remain required. The v0.8.3 exact-source checks and immutable artifact admission are recorded below; the v0.7.1 and v0.7.0 records below are predecessor evidence only.

The separate v0.6.2 authentication-hardening release completed immutable artifact admission on 2026-09-07. Its source appends authentication recovery schema 45 after the released automatic-approval schema 44. The admitted v0.7.0 release retains that exact predecessor authority and the default-off after-hours policy as schema 46, then appends peer and local-memory schema 47 and canonical-memory schema 48. Historical v0.6.1 installer recovery still uses its immutable release notes. The current admitted canonical artifact is v0.8.3, bound by its exact release record. Exact reviewed-main CI, matching installer pins, the protected tag path, and the immutable artifact workflow below remain required for every release. The hosted capacity block and unperformed real-provider qualification are unchanged.

The release also includes schema49's Work project-authority repair and schema50's exact historical profile persistence. The former preserves the released Work trigger definitions and digest preimages, adds a null-safe companion, and refuses contradictory live project authority before migration-owned quarantine. The latter backfills each session and Work row from its own frozen identity without admitting new models or changing public wire and evidence formats. The migration guidance describes refusal and whole-root downgrade boundaries. Artifact admission does not authorize daemon startup or migration outside the update runbook.

The separate v0.6.3 after-hours-policy release was prepared through PR 136 at b1f7743626bc93c135efdd441e235ac85ddd4c42 and completed immutable artifact admission through release run 34165802848, attempt 2, on 2026-09-07. Its exact release record binds that predecessor's source and bytes; it does not substitute for v0.7.0's separate admission, enable the default-off policy, or clear runtime rollout gates. Later work, including the canonical-profile catalog and attestation-visibility reliability repair, is not part of the immutable v0.6.3 artifact.

The former v0.1.0 beta process depended on the Oompa v0 Vercel deployment, its public fallback, and its paired provider readbacks. That dependency became invalid when Oompa v0's Vercel and Convex resources were permanently retired. At retirement, hraness/oompa had no v0.1.0 tag, no draft release for that tag, and no published v0.1.0 release.

The former public release:candidate and release:publish package entries remain removed. Their fallback-bound implementation and tests, scripts/release-candidate.ts and scripts/publish-beta-release.ts, were deleted on 2026-09-02: no package script or workflow referenced them, and their tests ran on every pull request. The failure records below and Git history are the design record. Nothing may recreate a candidate, tag, draft, workflow lease, publication, or provider mutation from that path.

The replacement release path is artifact-only and current-repository-only. After a release change reaches reviewed main and the required exact-source CI and artifact checks pass, an agent runs bun run release:tag under the standing task authority. The command fails closed unless the authenticated GitHub principal is immutable owner User ID 894119, the worktree is clean exact current remote main, package.json names a canonical monotonically newer stable version, the exact commit's Required CI job succeeded, and the live split tag rulesets have the expected narrow authority. It creates and pushes only that version's annotated tag, then reads back the exact tag object and peeled commit. It does not hold, print, or persist the GitHub credential, and it never asks for a second conversational approval.

Policy decision (2026-09-08): authenticated Claude and two-device hosted-memory qualification are optional operational evidence, not prerequisites for tagging or publishing v0.7.0. This supersedes the earlier pre-tag live-proof requirement, including the historical plan entries retained for provenance. Phase 10's delivery order now separates machine-gated artifact delivery from runtime qualification. Neither live proof is claimed complete. The tag helper and artifact workflow do not establish authenticated acceptance evidence.

Neither the local tag command nor the workflow reads or mutates Vercel, Convex, DNS, hosted aliases, or any retired Oompa v0 resource. They do not consume or prove the protected command-capacity evidence and activation receipt, target marker publication, or hosted effect readiness described in docs/hosted-sync.md. After its machine-enforced artifact gates pass, a release may publish independently of runtime rollout, but publication must never be presented as evidence that its hosted command path is available; the hosted runtime rejects fresh marker-2 enqueue and new provider-bound transitions until that runbook's capacity activation and intended-target gates pass.

The release workflow does not rerun the repository gate. Instead, scripts/check-commit-ci-run.ts independently reads the GitHub Actions API with actions: read and admits packaging only when the CI workflow has exactly one push run on the default branch whose head is that exact commit, that run completed with conclusion success, and its Required job for the same attempt and commit completed with conclusion success. A tag on a commit CI never checked, checked with any other result, or is still checking cannot package or publish. On Linux the verifier installs and verifies the same pinned Rust toolchain and musl targets as CI, rebuilds and verifies the native authority-supervisor artifacts, enables and proves an isolated user namespace, and runs the focused native custody test; an always-running cleanup restores the runner restriction. It then builds one tarball in the runner's temporary directory, outside the checked-out public tree, and verifies that same tarball on macOS and Linux. The canonical publish job creates and proves an immutable GitHub Release from that tarball plus SHA256SUMS, with no npm environment or OIDC capability. After canonical publication succeeds, a read-only npm_preflight job checks the exact tag-only npm environment and records registry state against the verified archive. Only its successful receipt admits npm_mirror to the npm environment and OIDC capability. The mirror retains the pinned-client check, non-publishing trusted-publisher exchange when the version is absent, exact publication, and combined public npm/GitHub byte and provenance admission. An npm failure leaves the verified immutable GitHub artifact available; the mirror remains failed until separately reconciled. The overall workflow reports that failure and does not claim npm admission.

The dependency prerequisite and recorded npm publisher binding are configured; the runtime OIDC exchange failed for v0.8.0 and its npm mirror is not admitted: Oompa pins the immutable public registry release @hraness/oh@0.10.8, the @hraness/oompa coordinate completed its non-executable bootstrap, and npm trusted publishing has exactly one binding, ID 28b1ff93-c1b0-42a7-bef6-41bffb992eb2, for repository hraness/oompa, workflow release.yml, and environment npm-release, with registry permissions publish, stage publish. The registry mandates stage permission for newly created bindings, but Oompa's workflow uses only direct publication. The environment has no human reviewers, disables administrator bypass, and admits only tag pattern v*. The npm mirror job names that environment. Its read-only preflight requires the exact tag-only environment before the OIDC job can start; canonical tagging and GitHub publication do not depend on npm environment readiness. This externally prevents a changed copy of release.yml running from main from obtaining the package's trusted-publisher identity. Stable @hraness/hra@0.7.1 remains an admitted npm predecessor; the current canonical GitHub artifact and admitted exact-byte npm mirror are @hraness/oompa@0.8.4. The immutable v0.5.0 record below preserves its reviewed source, tag, workflow attempts, npm package, and GitHub artifacts as historical evidence.

Every release job starts from a shallow checkout of only the requested tag or its verified commit, then explicitly unshallows only reviewed main and that exact annotated tag. It fails unless those are the only two refs in the runner. The unchanged package gate can therefore scan every local ref and every commit in the complete governed release ancestry without importing unrelated remote branches, deleted local-only tags, or automatic tag following.

Ordinary pull-request and main CI uses the same governed-history principle without release-tag authority. It checks out exact github.sha shallowly with no tags or persisted credentials, validates that lowercase commit identity, unshallows only that exact commit into refs/remotes/ci/verified, and fails unless HEAD and the runner's sole ref resolve to it. For a pull request, that commit is GitHub's exact synthetic merge; for a push, it is the exact pushed commit. The package gate still scans rev-list --all, including the complete tested ancestry and its merge resolution, while unrelated concurrent branch heads cannot enter or race the check.

Git truncates its generated hunk section labels, so a public package name in that label can appear to be an unreviewed package name. After verifying any exact historical patch evidence, the package-scope scan removes only the section label from a valid, column-zero ordinary hunk header. It preserves the header coordinates, physical line boundaries and every added, removed or context line. The complete sensitive-text scan still receives the unprojected patch; canonical rendering, immutable evidence digests, governed history, and time and output limits remain unchanged. This projection neither admits a partial package name nor creates a general public-text exception.

The canonical README and website use a two-phase local-release surface: candidate before exact admission, then live after the immutable canonical GitHub artifact passes its release gates. The v0.8.3 canonical GitHub artifact and exact-byte npm mirror are admitted. Current installation notes name the immutable release, archive, and tagged transactional installer. The release-bound README and package metadata retain their original pre-admission wording; this factual documentation update does not replace those immutable bytes. A later documentation or website update needs its own source and deployment checks; artifact admission does not prove that update is deployed. Never republish or retag a release to synchronize later documentation. The exact v0.8.3 record below, rather than a moving registry tag alone, establishes admission. Earlier v0.8.0 and v0.8.1 npm mirrors remain unadmitted. Hosted sync went live separately on 2026-09-03 and its deployment is independent of local CLI admission. The current additive candidate's guarded repair returned authority_reduction_hard_quota, so daemon upgrades and current command-writer rollout remain blocked. Publication under the machine-enforced artifact gates remains separate from runtime rollout; hosted enqueue and executor gates remain fail-closed. Before starting a current daemon, require protected two-pass zero-debt capacity evidence and its exact .activated receipt. Then obtain every intended target's marker proof before declaring command availability, following docs/hosted-sync.md. The v0.8.4 canonical GitHub artifact and exact-byte npm mirror are admitted; current installation notes name its immutable release, archive, and tagged transactional installer. Current source presents the v0.8.5 candidate command, explicitly unavailable until its own exact artifact admission.

The historical admitted predecessor's immutable v0.7.1 README also supplies its exact release-bound installation command. The immutable v0.7.0 README remains historical installer guidance. The v0.8.3 release has its own exact artifact admission; it inherits neither predecessor's evidence. The v0.8.4 release has its own exact artifact admission; it inherits no predecessor's evidence. This v0.8.5 source inherits no release's artifact admission.

Preserve old local state-protocol receipts, mutation intents, and evidence files as historical records; they do not authorize replay or any hosted-service mutation. The singleton $BUN_INSTALL/install/oompa/install-intent.json is different: it is live, release-bound local installer authority. Before installing another release, settle it only with the exact immutable installer from its originating release; never edit or delete it, and never treat that local recovery as authorization to retry or mutate the historical release workflow, tag, GitHub Release, or npm publication.

Immutable v0.1.0 failure record

The annotated v0.1.0 tag object ff3248801789d778829f18a55051443888fbc960 remains immutable and peels to commit 0e9287bc2ead3af2d432375efb86247455c2223d. Release workflow run 33363290345, attempt 1, failed in job 99398751969 at Run complete repository gate: the authority-supervisor runtime test could not map an isolated user namespace (unshare reported /proc/self/uid_map: Operation not permitted) and the supervisor returned namespace_mapping_failed.

That run stopped before registry-only package policy, tarball or checksum creation, npm registry preflight, and artifact upload. The unexpanded exact-artifact matrix and the publish job were skipped. It therefore created no npm 0.1.0, GitHub Release, draft Release, checksum, or retained workflow artifact. The publication variable was deleted after the failure. The tag and run remain historical evidence only: they must not be updated, deleted, recreated, or treated as authority for a later release.

Immutable v0.1.1 failure record

The annotated v0.1.1 tag object 6871f3e98ee22607ebea25531882c75da5ad8778 remains immutable and peels to reviewed main commit 2f773e588ec06a4d63811dc330012a32602b347e. Release workflow run 33368241909, attempt 1, completed the full verification job and preserved exact artifact 9749194160 with Actions digest 1a6ad2dd73065c01080df47a6c9f9c8de5733cd28ead4b4139c63e065e3e9cba. Both exact-artifact jobs downloaded those bytes and verified hraness-hra-0.1.1.tgz against its inner checksum.

The macOS and Ubuntu jobs then failed identically because the workflow had downloaded the sibling checksum to artifacts/SHA256SUMS inside the checked-out repository. The installed-package check correctly scanned the public tree and rejected that extensionless workflow file as UNREVIEWED_FILE_TYPE. Ubuntu's user-namespace enable and restoration both succeeded. The publish job was skipped, GitHub had no Release or draft, npm still exposed only 0.1.0-bootstrap.0, and the exact publication variable was deleted. The tag, run, and retained artifact remain historical evidence only; they must not be retried, updated, deleted, recreated, or treated as publication authority. The v0.1.2 repair moved generated and downloaded release bytes under RUNNER_TEMP, outside the checked-out public tree, without weakening the public-text policy.

Immutable v0.1.2 partial failure record

The annotated v0.1.2 tag object 334a5951037ecacb9895a153d76542bce63558b2 remains immutable and peels to reviewed main commit f0a1f4a31c1ebda745d2058c2f00a44e9fcbe5a4. Release workflow run 33373504473, attempts 1 and 2, completed the full verification job and both macOS and Ubuntu exact-tarball installation jobs. The run created immutable GitHub Release 379612601: asset 537702932 contains the 651,743-byte tarball with SHA-256 9b0fb77ffd6eb4f4535c91ac03c9b91afea7bd44c4c28a2069dabccbc95bfc93, and asset 537702965 contains the 88-byte checksum file with SHA-256 c0e3962a9c86b8dbf0d397593a919f5e12a5400c4d8f1a5964058e401c1950b6.

Both attempts then failed in the npm child after the GitHub Release became immutable. The wrapper had bounded but discarded all npm output, so the historical runs cannot distinguish OIDC exchange rejection from provenance or final registry-write failure. Registry readback proves @hraness/hra@0.1.2 is absent and both latest and bootstrap still name 0.1.0-bootstrap.0. The tag, release, assets, and runs remain unsupported historical evidence only: they must not be retried, updated, deleted, recreated, or treated as a complete publication. The v0.1.3 forward repair pins Node 24.20.0 with npm 11.19.0, removes setup-node's generated registry credential file, accepts the OIDC bearer endpoint only on GitHub's HTTPS Actions authority with the expected token-service path, isolates npm user and global configuration, proves the exact OIDC exchange before creating another GitHub Release, applies one aggregate output bound, emits only bounded allowlisted failure classes, forwards numeric repository-owner identity, and admits that owner identity inside the SLSA predicate.

Immutable v0.1.3 failure record

The annotated v0.1.3 tag object 61ebcaf33616bc29675053465725bc294f06f9d2 remains immutable and peels to reviewed main commit eef84596ec3891bcd29691d087449641dfda7e62. Release workflow run 33411496909, attempt 1, completed the full verification job and both macOS and Ubuntu exact-tarball installations. Retained Actions artifact 9765501271 has digest sha256:df1f40d36e19b92b92c8d6b256e49c7caa54ed5850bf353dec2c38995b3d449b; it carries the 651,739-byte tarball with SHA-256 cd7847d3e7c7369f05ad35bb80372e7a648875fc2201b1490591f9028db549ed and the 88-byte checksum file with SHA-256 371394f881aa1f0ed692ccf287c277571f2e0e78892f84a1652b5d3fea540f6c.

Publish job 99553962517 stopped at Prove npm trusted-publisher exchange without publication. The reviewed boundary rejected GitHub's newer hosted-runner OIDC path before starting npm, so the later GitHub Release, npm publication, and public-admission steps were skipped. Readback proves that no v0.1.3 GitHub Release or draft and no npm 0.1.3 exist; latest and bootstrap still name 0.1.0-bootstrap.0. The publication variable was deleted. The tag, run, and retained workflow artifact remain unsupported immutable evidence and must not be retried, updated, deleted, recreated, or treated as publication authority. The v0.1.4 repair preserves the GitHub HTTPS authority boundary while accepting both the legacy distributed-task path and the bounded current hosted-runner /idtoken/ path, and permits only one api-version=2.0 query parameter.

Immutable v0.1.4 failure record

The annotated v0.1.4 tag object 5c7e6add3062096c9545b10eaafddfd43f0b903e remains immutable and peels to reviewed main commit 586f954945f614c00efd12f13a0d43c6f5bb809c. Release workflow run 33417025171, attempts 1 and 2, completed the full verification job and both macOS and Ubuntu exact-tarball installations. Retained Actions artifact 9767593195, named hra-release-1, is 652,281 bytes with digest sha256:6816535110350f9bb3d43424caf05f04cc930481a64d9dd4917e0b8e4e7fa4b4 and expires at 2026-09-07T17:04:20Z; it carries the 651,736-byte tarball with SHA-256 d9c80317a85139347ec482d7b811aef57045af8175c72cc21e259d0e23249784 and the 88-byte SHA256SUMS file with SHA-256 2c67963d34862b06edb818c72644db08585d618d72c17baf3d531a9520dd1a1c.

Publish jobs 99572060480 and 99574351110 each stopped at Prove npm trusted-publisher exchange without publication with trusted_exchange_not_proven. GitHub's OIDC endpoint identity proof had passed, but npm 11.19.0 never reached OIDC: the boundary assigned both NPM_CONFIG_USERCONFIG and NPM_CONFIG_GLOBALCONFIG to /dev/null, and npm rejected double-loading /dev/null as both the user and global configuration source before initialization. The GitHub Release, npm publication, and public-admission steps were skipped. Readback proves no v0.1.4 GitHub Release and no npm 0.1.4 exist; latest and bootstrap still name 0.1.0-bootstrap.0. The publication variable was deleted. The tag, run, and retained workflow artifact remain unsupported immutable evidence and must not be retried, updated, deleted, recreated, or treated as publication authority. The v0.1.5 forward repair creates distinct private mode-0600 user and global npm configuration files in a fresh mode-0700 directory, adds bounded allowlisted publisher_configuration_failed and publisher_configuration_cleanup_failed classes, and still requires npm's exact Successfully retrieved and set token marker before GitHub publication.

Immutable v0.1.5 successful release record

Annotated v0.1.5 tag object 2503c4cccd52f4de9e8fb966f8050a08d26a3d06 peels to reviewed main commit 8e9b253bcebe07fc08289f033aaaeda6c574774d, merged through PR 49. Release workflow run 33427625936, attempts 1 and 2, completed the full verification job and both exact-platform installations. Attempt 1 publish job 99607830579 proved the npm trusted-publisher exchange, created immutable GitHub Release 379986294, and published npm @hraness/hra@0.1.5, but a bounded post-publication verification request ended with TimeoutError before final admission. The one-shot publication variable was immediately deleted. Registry and release readback then proved the exact version existed, latest named 0.1.5, provenance metadata was present, and no second publication authorization was required.

Attempt 2 publish job 99611394355 observed the registry state as exact, skipped the first-publication OIDC dry run, re-proved the existing GitHub Release and npm package, verified provenance from the same workflow run, and completed final public admission. Retained Actions artifact 9771995410, named hra-release-2, is 652,272 bytes with digest sha256:5e52442c02ee3fb8abee520df41a19e48ef9047f24eb6f160ece1686b2331efb and expires at 2026-09-07T19:14:29Z. GitHub asset 538406590 is the 651,736-byte hraness-hra-0.1.5.tgz with SHA-256 48f579f8bee54dbf87ccd5f54ff5d4bf89abd9ba9025280344ad0fe9bfdc57c6; asset 538406604 is the 88-byte SHA256SUMS file with SHA-256 a947561b784a41473d5728dfcc96cc6e9d50ba7b542d0010faf3997a041a7091. npm exposes those same tarball bytes with integrity sha512-Kv5JY5hbijho5MW79s7bygLb120pQ6RM8EV7aHycETK/hImL0/UQQuC9f72Vtgt4NSF39Glh1EVBFQXdddeGTw== and SHA-1 f598c36c331f87676382dfffd19907a8e9107b8f; independent download comparison is byte-identical. The tagged installer runtime has SHA-256 d684f9b7cbda8eabe6e1d217fca14acbe93bd888a8c8d03391ea91129696c1f1, an isolated public installation returned hra-install-safe, and the installed binary reported hra 0.1.5. The publication variable remains absent. v0.1.5 was the supported public CLI beta; hosted sync remains unavailable.

Immutable v0.1.6 successful release record

Annotated v0.1.6 tag object f125f3dc3d77d41d905327faa1cf825e8f3b0b92 peels to reviewed main commit b787e4d767d9bc95a70952e1002c150f5f33661c with tree f46d779d7c56cf011757471790b4c5cd72cf5747, merged through PR 65. Exact-main CI run 33562319207 passed. Release workflow run 33562952832, attempts 1 through 3, completed the full verification job and both exact-platform installations. Attempt 1 verifier job 100039504965, macOS job 100042411399, and Ubuntu job 100042411450 reached publish job 100042677957, which created the immutable GitHub Release and published npm @hraness/hra@0.1.6; final provenance admission received HTTP 404 from npm's Sigstore attestations endpoint and did not admit the run. The one-shot publication variable was removed.

Attempt 2 used verifier job 100043256132, macOS job 100043256791, Ubuntu job 100043256627, and publish job 100043256070; the publisher preflight stopped with version_conflict after the exact npm version already existed. Attempt 3 verifier job 100043668390, macOS job 100045311262, Ubuntu job 100045311412, and publish job 100045528708 observed the exact existing registry state, skipped the first-publication OIDC dry run, re-proved the GitHub Release, npm package, and provenance, and completed final public admission.

Retained Actions artifact 9822648569, named hra-release-3, is 658,170 bytes with digest sha256:4a4b8f796b3facba97b2ef1a92be916d21637060df48451044ac6b736cb464b3 and expires at 2026-09-08T22:08:27Z. Immutable GitHub Release 380848789, node RE_kwDOUAyvX84Ws0qV, contains asset 540202136, the 657,619-byte hraness-hra-0.1.6.tgz with SHA-256 c26a9352a8cefd032794a94c0c05c11319897890a78fa4c6e0eb6f2506635aca, and asset 540202181, the 88-byte SHA256SUMS file with SHA-256 de24d6c71005c7528562fff09200e529adfa119d4c1f469f46562931ceaf96c9. npm latest names @hraness/hra@0.1.6 and exposes those same tarball bytes with integrity sha512-Olb/QneV4Qy4oRabwINocuhakrJLOsm0omCHcFK5bkFqnzCNn5vYd0LplXTEtPxNe+yWqiSBHi+98v+6bLtbZQ== and SHA-1 a36bc66b0c727741c0306e695da8a13ce2104704; provenance is present and independent download comparison is byte-identical. The publication variable remains absent. v0.1.6 is the supported public CLI beta; hosted sync remains unavailable.

Immutable v0.2.0 successful release record

Annotated v0.2.0 tag object 46b4be7610b375fa788c373185c5aa6e6a0b4150 peels to reviewed main commit 6584ca1bf45041749e58bce60bff62bbe8cb844c with tree 516ad881ab1bffafa46f0a9f747117eb28a3c87c, merged through PR 73 after PR 71 (plan and wave 0) and PR 72 (the superseded v0.1.7 preparation). Exact-main CI run 33705600758 passed. The tag was created under a temporary repository-admin bypass on the Immutable version tags ruleset because GitHub reserves the v0.1.7 through v0.1.10 names for the retired v0 repository's immutable releases; the bypass was removed after creation. A throwaway lightweight v0.2.0 probe tag, pushed and deleted before the annotated tag to confirm the name was free, triggered run 33704483919, which failed at checkout with no side effects.

Release workflow run 33706170098 needed five attempts. Attempt 1 (verifier job 100495630588, macOS job 100495944582, Ubuntu job 100495944629) failed on macOS at the installed-package check: hra daemon stop after the restored PTY shell returned RECOVERY_REQUIRED with the immediate daemon-authority diagnostic. The same tree had passed that lifecycle on macOS runners in the PR and exact-main CI runs and on a developer machine, and every later attempt passed it, so it is recorded as a timing flake in the post-shell disconnect path. Attempt 2 (verifier 100497168789, macOS 100497142110, Ubuntu 100497143323, publish 100497352702) created immutable GitHub Release 381681569 and then stopped at the npm trusted-publishing step because the approval variable still named the superseded 0.1.7. Attempt 3 (verifier 100498205720, macOS 100498206375, Ubuntu 100498206491, publish 100498205834) ran with HRA_APPROVE_NPM_PUBLICATION=publish:@hraness/hra@0.2.0, published @hraness/hra@0.2.0, and failed after publication inside the same step. Attempt 4 (verifier 100498610260, macOS 100498610815, Ubuntu 100498610515, publish 100498610111) observed that the registry already contained the exact trusted-publisher bytes and stopped at the exchange-proof step. Attempt 5 (verifier 100501506346, macOS 100501786551, Ubuntu 100501786715, publish 100501970570) observed the exact existing registry state, re-proved the existing GitHub Release and npm package, verified provenance, and completed final public admission.

Retained Actions artifact 9875969848, named hra-release-5, is 675,149 bytes with digest sha256:278c88c2accc98876731d03ec4e81a6d37542971caa8bc6d8aa78c2bab88262e and expires at 2026-09-10T02:35:00Z. Immutable GitHub Release 381681569, node RE_kwDOUAyvX84Wv_-h, contains asset 542063653, the 674,632-byte hraness-hra-0.2.0.tgz with digest sha256:acc3fce6fbb4a20fea3f72a349db8eb23c47321917e291aa8668ce90c5a66ecc, and asset 542063671, the 88-byte SHA256SUMS with digest sha256:bc53dd0c632767104dc23b8881d7c0e343be373e18bcb311ce326112d39b8daa. npm latest names @hraness/hra@0.2.0; bootstrap still names 0.1.0-bootstrap.0. v0.2.0 is the supported public CLI beta.

Immutable v0.2.1 successful release record

Annotated v0.2.1 tag object f1c0b54a9c5c30ddb891032d19fddb58b1fa3219 peels to reviewed main commit 88b0567bd731b429db255e3cf454c320350d96c6 with tree 258524916c11a0078d040c927313a943d54d4a98, merged through PR 87 after PR 84 (the expired-access-token transport fix and its inventory re-pin); PR 85 and PR 86 were the same preparation superseded by GitHub rebase conflicts. Exact-main CI run 33802285588 passed. The throwaway lightweight v0.2.1 probe tag was created without any ruleset bypass, which showed that the Immutable version tags ruleset restricts only update and deletion; it triggered run 33803078820, which failed at the annotated-tag verification with no side effects. Replacing the probe with the annotated tag needed the temporary repository-admin bypass, which was removed immediately after the push.

Release workflow run 33803212691 needed five attempts. Attempt 1 (verifier job 100807395115, macOS job 100807802302, Ubuntu job 100807802313, publish job 100808120722) created immutable GitHub Release 382318983 and stopped at the npm trusted-publishing step because the run had started before HRA_APPROVE_NPM_PUBLICATION=publish:@hraness/hra@0.2.1 was set. Attempt 2 (verifier 100808663223, macOS 100808663701, Ubuntu 100808707624, publish 100808662986) published @hraness/hra@0.2.1 through the trusted-publisher exchange and then failed inside the same step because the registry did not expose the publication as latest within the bounded readback window; the version and latest tag appeared about ten minutes later and the tarball bytes became downloadable later still. Attempts 3 (verifier 100810189660, macOS 100810190894, Ubuntu 100810190563, publish 100810190404) and 4 (verifier 100810646915, macOS 100810646716, Ubuntu 100810646857, publish 100810646677) were failed-job reruns that reused attempt 1's absent preflight state and stopped at the exchange-proof dry run with version_conflict. Attempt 5 (verifier 100811712966, macOS 100812167959, Ubuntu 100812167768, publish 100812486546) was a full rerun after the registry served the exact bytes; it observed the exact existing registry state, re-proved the existing GitHub Release and npm package, verified provenance, and completed final public admission. The one-shot publication variable was removed afterwards.

Retained Actions artifact 9912412227, named hra-release-5, is 675,689 bytes with digest sha256:25091824b7b39876a95d89aadad7fc1ca09b5d2257361559d71601ab3c2898b9 and expires at 2026-09-10T20:51:13Z; attempt 1's hra-release-1 artifact is no longer listed on the run. Immutable GitHub Release 382318983, node RE_kwDOUAyvX84WybmH, contains asset 543311730, the 675,160-byte hraness-hra-0.2.1.tgz with digest sha256:daee36756d6c8fc8d14aa48f417b18f671951ada58f20c6d3f0217f16691c1be, and asset 543311784, the 88-byte SHA256SUMS with digest sha256:9533992bac958384444fdcf5bc39e9c7eee613c17bf3872058e64dac44d96a89. npm latest names @hraness/hra@0.2.1; bootstrap still names 0.1.0-bootstrap.0. v0.2.1 is the supported public CLI beta and the first release admitted while hosted sync is live.

Immutable v0.4.0 successful release record

Annotated v0.4.0 tag object 63b22c51b5ca848ce7793328cad81c3b68b11e08 peels to reviewed main commit 14a6a3cd035c2bb734c992e2c822750eb0a55651 with tree 4e3f95aba73f0a291b6ed7273b511c492ac02f78, merged through PR 98. Exact-main CI run 33880318651 passed. Release workflow run 33881060061 needed three attempts. Attempt 1 (verifier job 101049553622, macOS job 101049929138, Ubuntu job 101049929171, publish job 101050244642) proved the trusted-publisher exchange, created immutable GitHub Release 382773593, and then stopped at the npm trusted-publishing step because the run had started before HRA_APPROVE_NPM_PUBLICATION=publish:@hraness/hra@0.4.0 was set. Attempt 2 (verifier 101051274080, macOS 101051737083, Ubuntu 101051736881, publish 101052123726) published @hraness/hra@0.4.0 through the trusted-publisher exchange and then failed inside the same step because the registry had not yet made 0.4.0 readable as latest with provenance-bearing bytes within that attempt's bounded readback window. Attempt 3 (verifier 101053987552, macOS 101054436810, Ubuntu 101054436747, publish 101054723619) was a full rerun started after npm view @hraness/hra dist-tags.latest returned 0.4.0; it observed the exact existing registry state, re-proved the existing GitHub Release and npm package, verified provenance, and completed final public admission on 2026-09-04.

Retained Actions artifact 9940445919, named hra-release-3, is 759,460 bytes with digest sha256:60de6cd4ec36077aa6f10d797c88520791d6490379a2ace0179b0de8d2b4ddf9 and expires at 2026-09-11T14:14:04Z. Immutable GitHub Release 382773593, node RE_kwDOUAyvX84W0KlZ, was published at 2026-09-04T14:01:21Z and contains asset 544421144, the 758,879-byte hraness-hra-0.4.0.tgz with digest sha256:b8aafa202cdeae1c4adfdebbf0338822571f0202091a9493693fe253861a779f, and asset 544421177, the 88-byte SHA256SUMS with digest sha256:f81cf64e537e8846d90f57e826e5f16fa0c7bd2e4433b8b29ec785718801bf44. npm latest names @hraness/hra@0.4.0 and exposes those same tarball bytes with integrity sha512-ts2F4MfpFqNU4M1V4amBa4+AEri5JFEIQA8n4sAkzw4xAMl2l3B5rzVl9b+U/k+ebw+OPBAVsNHBuqS7Nbab+A== and SHA-1 b00dda6e8a7ce505618b41e3aca0c8555aac70d3; provenance is present and bootstrap still names 0.1.0-bootstrap.0. Under the now-retired gate, HRA_APPROVE_NPM_PUBLICATION remained set to the 0.4.0 publication grant after admission and would have needed manual removal before another release. The current workflow does not read that variable. v0.4.0 is the supported public CLI beta.

Immutable v0.4.1 successful release record

Annotated v0.4.1 tag object adb829c1051d5b52b2332a58ab1fa411ea22762e peels to reviewed main commit 260e8ca94896db8c5d3ae2a97bc31ab551889cb7 with tree 832da5c72529ed8f0f346b1a2dc018977df3bd88, merged through PR 100. Exact-main CI run 33888290468 passed. Release workflow run 33889054006 needed two attempts. Attempt 1 (verifier job 101075951254, macOS job 101076410640, Ubuntu job 101076410636, publish job 101076686630) proved the trusted-publisher exchange, created immutable GitHub Release 382829238, published @hraness/hra@0.4.1, and then failed inside the same npm trusted-publishing step because the registry had not yet made 0.4.1 readable as latest with provenance-bearing bytes within that attempt's bounded readback window. Attempt 2 (verifier 101077905699, macOS 101078306899, Ubuntu 101078306913, publish 101078744307) was a full rerun started after npm view @hraness/hra dist-tags.latest returned 0.4.1; it observed the exact existing registry state, skipped the first-publication OIDC dry run, re-proved the existing GitHub Release and npm package, verified provenance, and completed final public admission on 2026-09-04.

Retained Actions artifact 9943323040, named hra-release-2, is 760,750 bytes with digest sha256:dcc4ab99c6e888ada89037d01d76019efd163a7617c5a7384fe6fe2ea8af44a8 and expires at 2026-09-11T15:29:22Z; attempt 1's hra-release-1 artifact is no longer listed on the run. Immutable GitHub Release 382829238, node RE_kwDOUAyvX84W0YK2, was published at 2026-09-04T15:24:57Z and contains asset 544523403, the 760,170-byte hraness-hra-0.4.1.tgz with digest sha256:f440b0d26c02fdac553612fa18d3a61d4f3d1df3328d0e539844ed03ca3ba40a, and asset 544523424, the 88-byte SHA256SUMS with digest sha256:b944df6f9a5cb4f6152459550e8a8e83942a2ed575f5209157a6ad4d5d100076. npm latest names @hraness/hra@0.4.1 and exposes those same tarball bytes with integrity sha512-Xa6mym1D9PQOAnFEDNiKrZNaWWAH69ibOrlxffEH6uA8sDY7Hr7OXvdy7ilwsXyjcc0V1hgwsUojRMdDAw89Ig== and SHA-1 59638e2d6503a7d8fc8d7afd20755e44110c42ca; provenance is present and bootstrap still names 0.1.0-bootstrap.0. Under the now-retired gate, the workflow left HRA_APPROVE_NPM_PUBLICATION set to the 0.4.1 grant and would have required replacement before another release. The current workflow ignores that variable. v0.4.1 was the supported public CLI beta immediately before v0.5.0.

Immutable v0.5.0 successful release record

Annotated v0.5.0 tag object b91b0d30168cc684b762483ea2f652d2a576fe3a peels to reviewed main commit 846f5c99f573f97ce99f1f23ac1ea45d93e63042, merged through PR 103. Exact-main CI run 33902943920 passed. Release workflow run 33903621032 completed on attempt 3 and admitted immutable GitHub Release 382922988 at 2026-09-04T18:04:00Z.

Retained Actions artifact 9954989662, named hra-release-3, is 809,215 bytes with digest sha256:b91cf8a66dd65db33db563c81c2fc214379aefb52e55116c64dce28084bfe37d and expires at 2026-09-11T21:24:48Z. GitHub asset 544705971 is the 808,632-byte hraness-hra-0.5.0.tgz with SHA-256 d0d958a95b15989f639e60ba90a2abefa7d01a3c54af601c300657d365f39063; asset 544705988 is the 88-byte SHA256SUMS file with SHA-256 4ffe3a23d3ee7bd926c6a20df30e0f8b7378aaded6eb007a41e0d35d45c91a5b. At admission, npm latest names @hraness/hra@0.5.0 with integrity sha512-lpiJw1nEDc1CKVpnbtvw4+3+3DZAAKDJ2rvP0VZCwfzatP3gEMh6iTQNQjvZn1z4kyKCQcwo//cRg3/HLyz27Q== and SHA-1 f48f878256a768e5b58ebf990b63b4a3e59e5b69; bootstrap still names 0.1.0-bootstrap.0. v0.5.0 was the supported public CLI beta before v0.6.1 admission.

Immutable v0.6.0 partial publication record

Annotated v0.6.0 tag object c03c66a27398b2baf6f8dfc9bd04bcee5cc65459 peels to reviewed main commit 576ccd76a6742cd62759ab6176a6a41844846daa, merged through PR 122. Exact-main CI run 34056770875 passed. Release workflow run 34057589482 failed on attempts 1 and 2, and final public admission was skipped on both attempts.

Attempt 1 verifier job 101552204026, Ubuntu job 101552368631, and macOS job 101552368651 succeeded. Publish job 101552609010 proved the npm trusted-publisher exchange, created the immutable GitHub Release, and published npm @hraness/hra@0.6.0, then exhausted the bounded window for latest and provenance visibility before final admission. Attempt 2 verifier job 101555723682, Ubuntu job 101555918855, and macOS job 101555918878 succeeded. Publish job 101556083200 found the exact npm bytes, skipped republishing and the first-publication OIDC dry run, and re-proved the GitHub Release. It then failed cryptographic provenance admission because the frozen verifier expected Fulcio OID .24 to end in :ref:refs/tags/v0.6.0. The issued npm certificate instead carries DER UTF8String npm-release in OID .23 and repo:hraness@307125679/hra@1343008607:environment:npm-release in OID .24. Its certificate URI and independent ref OIDs still bind the exact v0.6.0 tag.

Retained Actions artifact 9996840156, named hra-release-2, is 1,101,922 bytes with digest sha256:874cde519d9297dbbb41d004cfc716d7ca5f7b589f18cd80297bc7e0d52aff4f, was created at 2026-09-06T20:45:15Z, and expires at 2026-09-13T20:45:13Z. Immutable GitHub Release 383705969, node RE_kwDOUAyvX84W3uNx, was published at 2026-09-06T20:22:19Z and contains asset 547641759, the 1,101,240-byte hraness-hra-0.6.0.tgz with SHA-256 f9f1bfecddd867e4ca781a2a045dc9573bd91eb9810fef75b2d28e8af0c37813, and asset 547641805, the 88-byte SHA256SUMS with SHA-256 659a510969f0e36f1f5f0e7fef739d4ee743ebb625c2052a2aba770ce30ef6fc. npm latest names @hraness/hra@0.6.0; bootstrap remains 0.1.0-bootstrap.0. npm exposes the tarball with integrity sha512-u49sO2O8i2KUFVxUFdeDoPwkQetOLBV31ULsuz5jxQN5nh/BgT55+CnRvAyneoBUsyZ+dZ/u0PsoJeKnRH0vhA== and SHA-1 16c4057d1a055d3f4bcecc4a070dc2b226060523.

The tag, release, assets, npm package, workflow run, and artifact remain immutable partial-publication evidence. They must not be updated, deleted, recreated, or treated as a fully admitted release. v0.5.0 remained the last fully admitted public CLI until the separate v0.6.1 forward repair completed exact admission.

Immutable v0.6.1 successful release record

Annotated v0.6.1 tag object 3d229acc034e4a2d3cb392a9e7fd6afe52be37a7 peels to reviewed main commit a75e7487594ce5b68345ccd3536974a10f7a93ee, tree b9025a56a9db70a194284ff81570e08e7994eb46, merged through PR 127. Exact-main CI run 34137918003 passed. Release workflow run 34140171965 completed successfully on attempt 2 at 2026-09-07T16:02:13Z.

Attempt 1 verifier 101800143905, Ubuntu install 101800587325, and macOS install 101800587380 passed. Publish job 101800925199 created immutable GitHub Release 384196103 and published the exact npm package, then exhausted the bounded public registry visibility window before final admission. Independent public readback subsequently proved identical GitHub and npm bytes, the exact checksum, current latest metadata, and cryptographic provenance bound to this source, tag, run, and first publication attempt. A complete same-run recovery re-proved the existing artifacts without replacing the tag or bytes. Attempt 2 verifier 101802496466, Ubuntu install 101802870410, macOS install 101802870373, and publish job 101803485479 passed, including final public admission.

Retained Actions artifact 10025888497, named hra-release-2, is 1,156,152 bytes with digest sha256:80b1441b27744608ad1fbdd7f3bb09fd885057d082dc3aacf16dbb0ff6a2854d; it expires at 2026-09-14T15:59:06Z. Immutable GitHub Release 384196103 was published at 2026-09-07T15:52:08Z. Asset 549023302 is the 1,155,452-byte hraness-hra-0.6.1.tgz with SHA-256 13669691caf3ae63bd6d88a7fab14a71e353ea1793f782d44e3cfcffe450b235. Asset 549023369 is the 88-byte SHA256SUMS with SHA-256 7bb1ce067a1bab01485bc963cd49ba8a7b3284e164c74ccdfa5e6c60b4f63e03. npm latest names @hraness/hra@0.6.1 with integrity sha512-REQdc/BAi3Bs//vCxXIs3+oaKqq5V43yeabvnTHn1F+SLJ/N0vXtbsJaXptvkiglQYHr71lgye4rIU8bT7HUsQ== and SHA-1 7f064e55a40964ec7f4cdbc8a3b9923c284a898a.

This is artifact admission only. The exact additive hosted candidate is live with notifications inactive, but its command-capacity repair remains hard-quota-blocked with no activation receipt. No daemon upgrade or current command-writer availability is claimed. Do not erase data, increase quotas, retry ambiguous effects, or bypass the hosted rollout runbook to make artifact and runtime status appear aligned.

Immutable v0.6.2 successful release record

Annotated tag object b3ecb87870d6a6c83b4e4a8b5117ad837d89d0bc binds v0.6.2 to reviewed commit 5c5c02ee5964167fb85e92da53cdb80c87991890. Release run 34156958618 completed source verification, exact tarball installs on macOS and Ubuntu, and final public npm/GitHub admission. Readback on 2026-09-07 proved immutable GitHub Release 384290677, published at 2026-09-07T19:51:37Z, and the exact registry version with provenance metadata.

GitHub asset 549302017 is the 1,160,242-byte hraness-hra-0.6.2.tgz, SHA-256 b5bc2a9125885c6ace33a70137202e99e1d6774f5d8945fac9bb96b6353c930c. Asset 549302046 is the 88-byte SHA256SUMS, SHA-256 abb2abdbea0a45a2e633c1955d2a31fbe4442c965bfbdd0f2c1ce95d048646de. npm records integrity sha512-AxZVX2IpSbE+Dblc1tTr+NN4MV1MpeQf7/2Ha80G2c3xsffb/v8kyiJQY5Zd48e+n8rwDTmUiT6fwtd+riuyeg== and SHA-1 bafd593a6f4607b936c6cc4f1c59970c14908241. Its exact-byte and cryptographic provenance admission is the successful workflow's evidence, not a new local archive comparison.

This admission does not release v0.7.0, qualify new Claude platform support, or satisfy hosted capacity activation and target-marker gates.

Immutable v0.6.3 successful release record

Annotated v0.6.3 tag object 633308ebe11adffecfaff1a4bea1c199f762df2d peels to reviewed main commit b1f7743626bc93c135efdd441e235ac85ddd4c42, tree 8f0399c41fd384fc987e4e5ea2e280e5e4aab569, merged through PR 136. Exact-main CI run 34164885896 passed. Release workflow run 34165802848 completed successfully on attempt 2 at 2026-09-07T22:22:49Z, including Admit exact public npm and GitHub state.

Attempt 1 verifier 101876480727, macOS install 101876702280, and Ubuntu install 101876702319 passed. Publish job 101876982835 created the immutable GitHub Release and published the npm package, then stopped when the npm Sigstore attestation endpoint returned HTTP 404 at 2026-09-07T22:17:35Z. Independent public readback at 2026-09-07T22:18:57Z proved identical GitHub and npm bytes, exact checksum and latest metadata, and cryptographic provenance bound to this source, tag, run, and first publication attempt. A complete same-run recovery preserved the tag and public bytes. Attempt 2 verifier 101877802299, Ubuntu install 101878024153, macOS install 101878024307, and publish job 101878267019 passed. Independent readback at 2026-09-07T22:24:28Z re-proved final workflow admission, identical public bytes, and cryptographic provenance.

Retained Actions artifact 10034263781, named hra-release-2, is 1,165,471 bytes with digest sha256:dbd74f694b9bcc4527290753b473f06697f3573d221f794b18226ecb412fac47; it expires at 2026-09-14T22:20:43Z. Immutable GitHub Release 384339082 was published at 2026-09-07T22:15:16Z. Asset 549449969 is the 1,164,765-byte hraness-hra-0.6.3.tgz with SHA-256 ae75cef126d32587fd9d3a1a755f8c126b2200107f55c5a412ccb15799363446. Asset 549450038 is the 88-byte SHA256SUMS with SHA-256 02f13245ceee5e8d0a85279fb08733de4d6ff4201baafec7e9ef58c8bb936766. At admission, npm latest names @hraness/hra@0.6.3 with integrity sha512-xrUt6rKfyWsExsojh+7+Bp9p/8udGF5gljZ6atyey4fBGKfFw8sBGCTHdQ/FCD8yfoLnkIIILUh4NBwSsxPTcw== and SHA-1 d5cd47d659cca022918c528f5715b99ddd8b799a.

This is artifact admission only. It does not release v0.7.0, qualify a new Claude platform or authenticated provider behavior, attest a new hosted candidate, publish command-capacity evidence or an activation receipt, upgrade a daemon, enable the default-off after-hours policy, or establish target-marker availability. Preserve the existing hosted rollout hold and originating-release installer recovery boundaries.

Immutable v0.7.0 successful release record

Annotated v0.7.0 tag object 4241ed401d82aa4c04e9c85e18f56cc084fc808f peels to reviewed main commit b856c66113c9a8752dbb431fc578287c23279cfe, tree 5ad0c78e2798d9b490429854ec098bfec33fa27c, merged through PR156. Release workflow run 34278486095 completed successfully on attempt 2 at 2026-09-08T21:26:37Z, including final public admission.

Attempt 1 created immutable GitHub Release 385063983 and published the npm package, then failed when the bounded metadata-visibility readback did not complete. That failure remains part of the release record. The complete same-run recovery preserved the tag, release and public bytes. Attempt 2 verifier 102242943990, macOS install 102243352864, Ubuntu install 102243352898, and publish job 102244020086 all passed. Independent final public readback at 2026-09-08T21:28:05.902Z re-proved the successful workflow, exact GitHub and npm bytes, checksum, latest metadata and cryptographic provenance bound to the release authority. No replacement publication or retagging was required.

Retained Actions artifact 10077341831, named hra-release-2, is 1,359,995 bytes with digest sha256:16b0be793d9be44da67dbdf7f86a8d2e90c12649004d2f69e5c60a9e4a556d8a; it expires at 2026-09-15T21:23:46Z. Immutable GitHub Release 385063983 was published at 2026-09-08T21:08:27Z. Asset 551312890 is the 1,359,243-byte hraness-hra-0.7.0.tgz with SHA-256 6a067b5efb48bb9253f132300b09e59ae45a6e90c8f97532b5deabdc802a1061. Asset 551312956 is the 88-byte SHA256SUMS with SHA-256 4316ed59ee09c7278a8cbea0be4dcaad282332a8d148cf3e29a77d5fa2abe83f. At admission, npm latest names @hraness/hra@0.7.0 with integrity sha512-T3eAkeEJrhVN/3/uYUi5IQ3eYqFbg+ln9VCEF008nJcJqRgiuzm6Oma+uTC1RIcUKWubr4WBFvDcF3iccNdLcw== and SHA-1 814a2911aa248a08145f0b7dfed3b256c9035e29.

This is artifact admission only. It does not qualify authenticated Claude behavior or a new platform, attest a new hosted deployment, publish command-capacity evidence or an activation receipt, upgrade a daemon, enable a default-off policy, admit a new model, or establish intended-target availability. Preserve the originating-release installer recovery boundary and the separate hosted capacity and target gates.

Immutable v0.7.1 successful release record

Annotated v0.7.1 tag object 61e22234cebd562a8cbcc1e62aa19e7640aeabaa peels to reviewed main commit 5ab43f11cc597c2f73f7f2c8f276b22f15bfb8b5, tree 72a26dec74c999db5a5c20d69997474933129e2a, merged through PR162. Exact-main CI 34365455021 and CodeQL passed. Release workflow run 34367591503 completed successfully on attempt 2 at 2026-09-09T15:31:26Z, including Admit exact public npm and GitHub state at 15:31:24.728Z.

Attempt 1 verifier 102520216739, macOS install 102520740240, and Ubuntu install 102520740373 passed. Publish job 102521422910 created immutable GitHub Release 385620163, then the npm publisher exited successfully with its trusted exchange proved. The job failed before provenance admission because exact-version metadata remained absent through its bounded visibility window. Independent public reconciliation at 2026-09-09T15:24:22.283Z subsequently proved exact GitHub/npm bytes, checksum, version/latest metadata and cryptographic provenance bound to this source, tag, run and original publication attempt 1. A complete same-run recovery preserved the tag, release and public bytes. Attempt 2 verifier 102529716172, macOS install 102530249997, Ubuntu install 102530250055, and publish job 102530908657 all passed. The completed log binds fresh preflight exact to the same run and attempt 2, skips the first-publication exchange, and confirms that npm already contains the exact trusted-publisher bytes. No republication occurred.

Fresh final public readback at 2026-09-09T15:38:01.271Z re-proved successful workflow admission, identical public bytes and cryptographic publication-attempt-1 provenance. Its first attempt had stopped before artifact checks because the private checker incorrectly required main to remain equal to the release commit after another protected merge. The corrected check reused the repository's existing ancestry policy, including exact comparison identity and immediate final-ref sampling. This did not change the immutable release source or relax any artifact predicate.

Retained Actions artifact 10111688372, named hra-release-2, is 1,332,298 bytes with digest sha256:6feca9bd9eb9b1ad4f915cd764f4235ccd78cca713ee4a9e89bc5395ebd27add; it expires at 2026-09-16T15:28:53Z. Immutable GitHub Release 385620163 was published at 2026-09-09T15:06:10Z, retaining creation and publication attempt 1. Asset 552998115 is the 1,331,554-byte hraness-hra-0.7.1.tgz with SHA-256 2c1a58d9f3a16c542f303668485731d2fd8f49721f5cb7ea7fd2a9d0ccdcf680. Asset 552998162 is the 88-byte SHA256SUMS with SHA-256 1b2669e8a1a54f7d590c237ee89c30592f5957a6b1780e9c309c45c46e918b70. At admission, npm latest names @hraness/hra@0.7.1 with integrity sha512-ccnQnh1NtumzY3KcjiVbWXxl/tANTLM4P7B7YuvXNO2Wz/24TnRznJMFSToIk7s19iH0pqUzgRevHsmBsKBOmg== and SHA-1 b4a1f2d7438b65fdc2a368766f5a746cc3453eb8.

This is artifact admission only. It does not qualify a provider or platform, attest a hosted deployment, repair capacity, upgrade a daemon, authorize migration, enable a default-off policy, admit a new model or prove intended-target availability. Preserve the separate hosted capacity and target gates. The tagged README and notes retain their pre-publication candidate wording; this later release record proves admission without editing those immutable source bytes.

Immutable v0.8.3 successful release record

Release run 35066335703, attempt 1, completed all six jobs successfully on 2026-09-16. Linux and macOS installed-package checks passed before publication. The final npm job admitted the exact public GitHub and npm bytes and verified cryptographic provenance.

  • Source: ca5b064dabd918c2038920038bf83383f99a2e28; Git tree: d54017292ed214bfd065e0ef0b38b5f44c86b595.
  • Annotated tag v0.8.3: 6cefaa0ee06cf853f30d34153db73e30c327d61b.
  • Immutable GitHub release: 389699417, published at 2026-09-16T07:04:26Z.
  • Archive hraness-oompa-0.8.3.tgz: asset 567398895, 1,721,327 bytes, SHA-256 b44a73461b49d970e13eb74a60c4c3bbaeaf06f42e25a26565e7e87c7f68d086.
  • SHA256SUMS: asset 567398966, 90 bytes, SHA-256 4cd7da919eba6653c84073c1b6e0e0ced28b5670ce3b98f7ccacd0bf6202ad29.
  • npm @hraness/oompa@0.8.3: integrity sha512-m51i4sc8aO7QAlMxG628q827KA1zodDNEgjc4RrhSNfqVYxnSrfKd6Xp+b+lz5aJeCvgYsRuKeNHdjXnAgbxqQ==, 214 files, 9,073,562 unpacked bytes. The registry's latest tag pointed to 0.8.3 after admission.

These records establish artifact availability only. No authenticated provider qualification, capacity activation, daemon upgrade, intended-target marker proof, or hosted command-writer readiness is claimed. The immutable artifact's earlier candidate wording remains historical; current installation guidance is in the reviewed release notes.

Immutable v0.8.4 successful release record

Release run 35136703343, attempt 2, completed all six jobs successfully on 2026-09-16. Attempt 1 verified the source, passed the Linux and macOS installed-package checks, and published the canonical GitHub artifacts, but its optional npm mirror readback did not observe the publication within its bounded poll and that job failed. Read-only reconciliation found no npm publication for the version, exact GitHub bytes matching SHA256SUMS, and the tagged commit as an ancestor of reviewed main, so the same run was rerun in full under the recovery procedure below. Attempt 2 repeated the source and platform gates, kept the existing GitHub artifacts, and its npm job admitted the exact public GitHub and npm bytes and verified cryptographic provenance.

  • Source: f79fd9b0bc0498b53af28878dba94b8db18900e5; Git tree: 91d94bfbb26693fce9a8ae8f15fc7e63f10629eb.
  • Annotated tag v0.8.4: 20d2ac7d159af950e825cca7f8ffe4559f261c28.
  • Immutable GitHub release: 390186501, published at 2026-09-16T18:52:52Z.
  • Archive hraness-oompa-0.8.4.tgz: asset 568579617, 1,722,209 bytes, SHA-256 988ed30b0f6932e6b5a53be60c9e97d0ed5f1a055f29c995476bbe0ae9703996.
  • SHA256SUMS: asset 568579708, 90 bytes, SHA-256 4b67951ff2cf7f0d62b8c03aa7132f6e0260232454bebdf12517c47cd74f4cf7.
  • npm @hraness/oompa@0.8.4: integrity sha512-wXVkOaL4B2y6H+ILXk64YEELuJy5uuvGV2MwQDc8uBYRvgvgJZxLVa4Qn6Hd0wDFg6AwH4MT8Ukqn/uYotXFxw==, 214 files, 9,076,723 unpacked bytes. The registry's latest tag pointed to 0.8.4 after admission.

These records establish artifact availability only. No authenticated provider qualification, capacity activation, daemon upgrade, intended-target marker proof, or hosted command-writer readiness is claimed. The immutable artifact's earlier candidate wording remains historical; current installation guidance is in the reviewed release notes.

Recover delayed public visibility

This procedure reconciles an uncertain npm publication, including the historical combined-admission workflows and the current optional mirror. An npm mirror failure does not revoke separately verified canonical GitHub admission, but the mirror and overall workflow remain failed until their own required evidence passes.

  1. Record the exact failed run, attempt, source, tag object and failing step. A successful publisher exit followed by missing metadata is an uncertain publication result, not permission to publish again. Preserve the failed attempt and all existing immutable identities.
  2. Reconcile public state read-only before a retry. Require exact-version and latest metadata, identical npm and GitHub tarball bytes, checksum and canonical release identity, and cryptographic provenance bound to the original source, tag, run and admissible publication attempt. Missing, mismatched or ambiguous evidence remains a hold. Do not substitute an unrelated release's evidence.
  3. Verify the tagged commit remains an ancestor of freshly observed reviewed main, using the existing strict branch/comparison helpers and final-ref readback. The release source, tag and artifact stay exact; unrelated protected forward commits do not have to leave main frozen at the tag.
  4. After complete reconciliation, use gh run rerun <run-id> --repo hraness/oompa for the same release run, not a new run or a failed-job-only rerun. The complete recovery rebinds preflight and artifact outputs to its new attempt and repeats the required source and platform gates. Its internal fresh preflight and transition checks remain authoritative. A rerun is not inherently read-only: do not claim the existing-artifact path until its resulting step evidence proves it. The public Jobs API does not expose the preflight job output as a separate manual pre-publication gate.
  5. Require all release jobs and final public admission to pass. Record the new attempt, its exact preflight and existing-artifact branch evidence, then perform fresh independent public byte, identity and original-publication provenance readback. Never update, delete, retag, replace or republish immutable artifacts to make a failed receipt appear successful. Release admission does not clear operational rollout gates.

Reserved version tag names

GitHub immutable releases reserve a tag name forever once an immutable release used it, and that reservation survives deleting the release and even deleting and recreating a repository with the same name. The retired Oompa v0 repository published immutable releases v0.1.7, v0.1.8, v0.1.9, and v0.1.10 under the hraness/oompa name, so those tags cannot be created in this repository even by an actor who bypasses repository rulesets. The first release after v0.1.6 was therefore v0.2.0. Never probe availability by creating and deleting a throwaway tag. Choose a monotonically newer package version and let bun run release:tag verify local and remote absence read-only before its one governed annotated-tag push. If GitHub retains an otherwise invisible reservation, the push fails before publication.

Repository rename to Oompa

On 2026-09-10 the repository path moved from hraness/hra to hraness/oompa, keeping numeric repository 1343008607. GitHub redirects Git, web, raw and release-asset URLs for the old path. The published v0.6.0 through v0.7.1 installers refuse redirects and require the original hraness/hra full name before reading local recovery authority, so their interrupted-install recovery commands no longer complete after the rename. No external installation existed at the time; the owner's complete hra 0.5.0 installation keeps running from ~/.bun/install/hra. Those immutable releases are not republished, retagged or replaced. v0.8.0 is the first @hraness/oompa artifact: it installs into ~/.bun/install/oompa, publishes the oompa command, and shares the existing control-plane state root.

Repository release governance

GitHub protects main through pull requests, strict successful Required checks, resolved review conversations, linear history, and restrictions on force-push and deletion. These main-branch rulesets have no administrator bypass. CODEOWNERS identifies release-authority owners, but GitHub does not currently require approving reviews, CODEOWNERS approval, or stale-approval dismissal. Record an independent agent review of the exact release commit and tree, including every release-authority change, and repeat it after any tree change; successful CI alone is not review evidence and the immutable owner identity is release-timing authority rather than a substitute for code review.

Keep tag protections split so creation authority never gains mutation authority. Immutable version tags ruleset 21213369 restricts update and deletion for refs/tags/v* with an empty bypass list. Release tag creation ruleset 22307191 restricts creation only and grants its sole always-bypass to immutable owner User ID 894119; provider readback of both rulesets is a release prerequisite enforced by bun run release:tag. Never put creation, update, and deletion in one bypassed ruleset, and never grant the generic GitHub Actions integration a creation bypass: repository branch workflows can select their own requested GITHUB_TOKEN permissions, so that integration is not an isolated release principal. No workflow, administrator, or retry path may update, recreate, or delete an admitted tag object.

Publication is admitted only after the workflow independently binds its active workflow identity, repository and owner identities, tag ref, annotated tag object, peeled commit, checked-out commit, successful exact-commit CI, and ancestry in reviewed main. Any positive rerun attempt may finish the same release only after re-proving that exact tag object, commit, artifact checksum, and main ancestry; it may never substitute bytes, a tag, a commit, or a different workflow run.

GitHub publication creates one deterministic draft before uploading. A later attempt may resume only one draft created by the same workflow run with the exact numeric release ID, tag, title, canonical identity body, tag object, commit, and artifact manifest. The body records repository path and numeric ID, workflow ref, run ID, creation and publication attempts, and both asset names, sizes, and SHA-256 digests. It inventories drafts exhaustively within ten bounded pages, rejects duplicates or extra assets, verifies existing asset names, sizes, digests, and downloaded bytes, uploads only a missing tarball or checksum, then publishes and re-reads the immutable Latest Release by the same numeric ID. Final success also requires that no residual draft for the tag remains. A mismatched, ambiguous, or coexisting draft is terminal and is never overwritten, deleted, or treated as retry authority.

GitHub can expose a newly created draft or a just-published Release through its direct and inventory endpoints at different times. The writer therefore polls only for bounded exact convergence: after creation, an empty inventory may become the one returned draft ID; after publication, the same ID may transiently remain in draft inventory only while a direct read is still the exact complete draft or exact publication with the reviewed asset bytes. Any foreign ID, duplicate, edited identity, different bytes, or state outside that narrow transition fails immediately.

A rerun may create a draft only when every earlier attempt's bounded GitHub Jobs API record proves that the exact publication step was skipped. The publisher checks that witness once while planning and again immediately before the POST, binds each job to this run, attempt, workflow, and verified commit, and grants the job only actions: read in addition to its existing writer permissions. If an earlier publication step may have run, a later attempt may only observe and recover its exact same-run draft or publication. This deliberately prefers safety over liveness when provider state never appears after an ambiguous attempt.

The verification job exports GitHub's positive numeric artifact ID and the upload action's lowercase digest. Consumers reject malformed values and download only that numeric ID; the outer digest is a transport assertion, not independent release authority. Authority over the consumed bytes comes from the downloaded inner SHA256SUMS, which is revalidated against the exact tarball before any publication step.

The privileged publication jobs' trusted computing base is broader than either writer script. It includes the reviewed workflow, its SHA-pinned actions/checkout, setup-bun, setup-node, upstream upload-artifact, and download-artifact revisions, the checked-out verification and publication code they execute, the installed locked toolchain, and the GitHub-hosted runner. Canonical publish has GitHub write authority but no npm environment or OIDC permission. Only npm_mirror receives npm OIDC permission, making every step in that job security-sensitive. The GitHub token is not job-wide: it is exposed only to the exact remote-authority revalidation, GitHub Release publication/readback, read-only npm environment check, npm publication's immediate live-public-repository identity check, and final public-admission steps in their respective jobs.

The coordinate bootstrap was a separate ceremony because npm cannot attach a trusted publisher to a package coordinate that does not yet exist. It published only a non-executable coordinate seed, @hraness/hra@0.1.0-bootstrap.0, while requesting the bootstrap dist-tag. npm also assigns latest to the first published version of a new package coordinate even when the publication requests another tag, so the seed initially resolves through both bootstrap and latest; that registry invariant is not a stable promotion. The seed did not consume stable 0.1.0, 0.1.1, 0.1.2, 0.1.3, 0.1.4, 0.1.5, 0.1.6, 0.2.0, 0.2.1, 0.3.0, 0.4.0, 0.4.1, 0.5.0, 0.6.0, or 0.6.1, expose the Oompa executable, or reuse any retained stable tarball. The coordinate bootstrap was the one-time interactive ceremony. For subsequent stable releases, the owner-authorized exact annotated tag is the publication authorization: the workflow still proves the exact main commit, artifact and canonical GitHub public readback. The optional npm mirror separately proves its trusted-publisher identity, Sigstore provenance and public bytes, without a second repository-variable or conversational approval.

After the coordinate existed, an operator using npm CLI 11.19.0 verified the sole trusted publisher as GitHub repository hraness/oompa, workflow release.yml, publish-only, with no npm environment for the releases through v0.5.0. On 2026-09-06, the operator revoked binding 41124856-baa6-46ad-b242-6e3278c73ce8 and created replacement binding 28b1ff93-c1b0-42a7-bef6-41bffb992eb2 in one npm-authenticated maintenance session with the same repository and workflow, environment npm-release, and direct --allow-publish. The request omitted --allow-stage-publish, but npm automatically grants stage publishing to trusted-publisher configurations created after 2026-09-03. Authenticated readback showed exactly that one replacement binding with repository hraness/oompa, workflow release.yml, environment npm-release, and permissions publish, stage publish. The registry-mandated stage permission is not an Oompa release path: .github/workflows/release.yml invokes direct npm publish and never invokes npm stage publish. Stable v0.1.5 is the first complete OIDC/provenance publication, stable v0.1.6 was the second, stable v0.2.0 the third, stable v0.2.1 the fourth, stable v0.3.0 the fifth, stable v0.4.0 the sixth, stable v0.4.1 the seventh, and stable v0.5.0 the eighth. v0.6.0 remains a partial publication, and v0.6.1, v0.6.2, v0.6.3, v0.7.0, and v0.7.1 are complete publications. v0.8.4 is the current admitted canonical GitHub artifact and exact-byte npm release; v0.7.1 remains an admitted npm predecessor. The stable workflow never performs the bootstrap or grants a second publisher. Exact 0.1.6 publication moved latest from stable 0.1.5 to stable 0.1.6, while the bootstrap seed remains available only as the explicitly named bootstrap version and dist-tag. Registry admission accepts either exact version metadata or a bounded full package document. Package documents must carry the exact package identity and own exact version entry; reads of /latest additionally require dist-tags.latest to name 0.6.1 during the historical v0.6.1 admission. This keeps transient registry response shapes from weakening the distinction between version existence and stable latest promotion.

The post-v0.6.3 source adds a narrow attestation-visibility read policy to the npm publisher and final public-admission checker. Only HTTP 404 from the fixed exact-version npm attestation endpoint is pending: at most 60 GET requests share a 180-second monotonic deadline, with three seconds between requests and a request/body timeout capped at 20 seconds or the remaining budget. A readable response must still pass the unchanged exact subject, source, tag, run/attempt, signer, and cryptographic verification. Other HTTP statuses, transport failures, malformed or oversized JSON, registry-key failures, and invalid provenance are terminal. The policy never retries publication or creates a new tag, release, artifact, or workflow run. This forward reliability repair is not part of the immutable v0.6.3 source; that release's successful same-run recovery remains recorded above.

Fulcio signer admission preserves raw ASCII matching for legacy GitHub workflow extension OIDs .2 through .6. Current V2 claims from .11 onward are matched as one canonical short-form DER UTF8String whose payload is bounded nonempty ASCII. Environment claim OID .23 must be exactly npm-release. Repository-subject OID .24 remains mandatory and exact: repository path hraness/oompa, numeric owner ID 307125679, numeric repository ID 1343008607, and environment npm-release. The exact tag ref refs/tags/v0.6.1 is independently required by the certificate URI and OIDs .6, .14, and .18 for the historical v0.6.1 admitted release. Every later candidate requires its own exact release version and tag; historical evidence never substitutes for current admission. The generated SLSA internal parameters must separately preserve exact event push, repository ID 1343008607, and owner ID 307125679. The already-published v0.5.0 historical provenance uses that same push event. The encoding repair does not drop or weaken any workflow, commit, ref, run, visibility, owner, or repository claim.

For v0.7.0, the successful admission independently proved dist-tags.latest naming 0.7.0 and the exact tag ref refs/tags/v0.7.0 in the certificate URI and OIDs .6, .14, and .18. Its exact release record above binds that proof; historical predecessor evidence never substitutes for a release's own admission.

Installer digest pins between releases

The transactional installer embeds the SHA-256 of src/cli.ts and of src/install-normalizer.ts, and the public one-line command carries the SHA-256 of src/install-preflight-runtime.ts at the released tag. That generated command must remove the complete runtime/native injection denylist before the download and Bun startup and must invoke Bun with --no-env-file --config=/dev/null; the tagged loader refuses if those stage-zero conditions are absent. Curl and the loader independently cap the streamed preflight at 512 KiB, and the loader refuses an overrun before transpilation or installation. Every detached installer Bun child repeats those flags and receives the same scrubbed environment while retaining reviewed registry, proxy, and certificate inputs. Between releases, any change to the CLI entry point or the normalizer must be followed by bun run install-pins:update, which rewrites only those inner digests so a locally packed archive still passes the local preflight; bun run check fails until that happens. The public command's digest and URLs deliberately keep naming the last immutable release during ordinary development. After the inner pins converge and the source URLs already name the exact v<package.version> tag, run bun ./scripts/check-install-pins.ts --prepare-release v<package.version> once, then bun ./scripts/check-install-pins.ts --release-tag v<package.version>. The preparation mode changes only the public runtime digest and refuses a mismatched tag, URL, inner pin, or ambiguous replacement site. bun run release:tag repeats that release-consistency proof before any local annotated tag is created, so a missed manual pin cannot consume an immutable release name; the tag workflow proves the same bytes again under the pushed tag ref.