feat: TMCRA 1.0.0-rc.1 local workspace (scanner adjudication pending) - #4
Draft
reshuibuduo wants to merge 5 commits into
Draft
feat: TMCRA 1.0.0-rc.1 local workspace (scanner adjudication pending)#4reshuibuduo wants to merge 5 commits into
reshuibuduo wants to merge 5 commits into
Conversation
This was referenced Sep 5, 2026
Draft
reshuibuduo
marked this pull request as draft
September 5, 2026 20:14
Owner
Author
|
Upstream detector fix submitted: hashgraph-online/hol-guard#2805 The patch removes the eight Python inference-method false positives on the unchanged bundled runtime. Local validation: 186 related tests passed on Python 3.12; 93 code-quality tests passed on Python 3.10. Genuine dynamic-evaluation and JavaScript/TypeScript cases retain high-severity findings. Upstream GitHub Actions currently require maintainer approval. This release stays a draft: the official pinned Action is unchanged, the score-80/high-severity gate and Cisco scanning remain in place, and synthetic test-credential findings still need separate resolution. This local regression result is not a passing official marketplace scan. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Unified TMCRA 1.0.0-rc.1 candidate: memory workspace, local Writer/organizer settings, knowledge/graph views, session modes, task continuity, bounded evidence budgets, and interactive chat confirmation for exact-source corrections.
Account-free Windows x64 installation bundles the actual backend and verified inventory.
Install-Local.cmd/tmcra_open_local_installprepare private Python, pinned models and a local identity. Setup has no API credential and exposes no memory actions; after installation the host must restart. First-time downloads need internet, while memory runtime does not need TMCRA servers/accounts.Verification
The Codex and Claude Code contract suites pass, including 15 lifecycle scenarios, 7 authorization flows, confirmation/no-write-before-consent, local/cloud isolation and account-free setup. The 235-entry release archive and binary/runtime integrity checks pass. Latest code tests: https://github.com/reshuibuduo/tmcra-plugin-codex/actions/runs/33988900575
Publication blocked by scanner
The official HOL/Cisco job still fails: https://github.com/reshuibuduo/tmcra-plugin-codex/actions/runs/33988900546
The native detector misclassifies PyTorch
Module.eval()in eight bundled Python files. The current Action additionally flags synthetic test-fixture credentials because repository test exclusions are not trusted by default. Local CLI and raw CI reports therefore differ; neither is a passing severity gate. No new exclusions, baseline suppressions, or threshold reductions were introduced.Reviewed source paths and limitations: https://github.com/reshuibuduo/tmcra-plugin-codex/blob/codex/memory-controls-continuity/docs/security-scanner-review.md
This PR and three dependent Codex/Claude catalog refreshes remain draft pending an upstream detector fix or maintainer adjudication. No standalone Codex 1.0.0-rc.1 tag/release has been published. Main TMCRA runtime, DSH and generic MCP are separate 1.0.0-rc.1 releases.
Local-model acceptance is partial
Synthetic CPU ingest/raw recall passed; complex compilation timed out at 600 seconds. Organizer/full-service restart, latest memory-limit settings and balanced/high-tier hardware acceptance remain pending. Current laptop lacks approximately 6.3 GiB of free RAM for the next full run. A cloud-hosted Agent main model may still receive recalled evidence. Production services, real user memory and currently installed plugins were not changed.