Fix registry artifact dependency verification - #211
Merged
Merged
Conversation
Merged
xeonvs
added a commit
that referenced
this pull request
Sep 19, 2026
## Scope Prepare and authorize stable toolkit **v0.11.0** for the governed MCP federation, stage-aware DLP and OCR 1.12.0–1.12.7 qualification work tracked by: - #188–#193 - #201–#207 - #209 - #210 This release PR contains repository-side preparation only. Stable publication and external reconciliation remain pending until this exact PR is merged and the protected Release workflow completes. ## Reviewed implementation - Feature PR: #208 - Reviewed feature head: `1e3b7d668874b2e86b2700284675d997a1654c0b` - Protected feature squash merge: `cc784c157d1b9efb3e45158e0c1a75fbb4801bd5` - Corrective PR: #211 - Reviewed corrective head: `b41011b0d1744a5481eafe0d0eab4bf280a240c7` - Protected corrective squash merge and release base: `3f402948ce4606b935587af63920c467af43fa3b` - Release head: `9fdabc74e5dc26566105a086d924e609bbe426cb` ## Development publication - Workflow: https://github.com/xeonvs/open-code-review-toolkit/actions/runs/35444762966 - Version: `0.11.0.dev98` - Wheel SHA-256: `379684bce1983cb4058e1916bb4ae75c61d00cb8d7b0ccf45240b36b57122952` - Sdist SHA-256: `36236b7246c722f8df35495775ce6b80c38b8c76fe40e4e7aca22a68fee11d34` - Workflow verification passed provenance, exact TestPyPI bytes, hash-locked runtime dependency installation, and clean wheel/sdist CLI smokes. ## Release preparation - Stable marker: `0.11.0` - Next development marker: `0.12.0` - Deterministic source epoch: `1789823158` - Authorized issue set: `[188, 189, 190, 191, 192, 193, 201, 202, 203, 204, 205, 206, 207, 209, 210]` - Towncrier fragments are rendered into `CHANGELOG.md`. - Public GitLab example pins toolkit `0.11.0` with OCR `1.12.7`. - Both feature and corrective plans are archived at `docs/engineering/execution_history/releases.md#plan-toolkit-0-11-0` with stable external delivery pending. - `.release-reconciled-version` intentionally remains `0.10.1` until independent external readback. ## Release validation - `scripts/quality.sh check`: passed. - Focused release/documentation suite: **109 passed**. - Release-note extraction, marker contract and `git diff --check`: passed. - Local source-epoch-controlled builds are byte-identical and pass Twine plus clean wheel/sdist CLI smokes with the hash-locked runtime closure. Wheel SHA-256: `fa64701e627e1045cb9b597f79c05f834265f160f127564dcec9702375e2f072`; sdist SHA-256: `7a03f4bd1ff657f333111ef9155380fadcbd83f4beac0dce1f44d6818e0d103e`. - Feature qualification already completed local OCR v1.12.7 (`openai/gpt-5.6-terra`, 61/61 reviews, 22 evidence MCP calls, four findings fixed) and Codex Security scan `cc04b394-e16f-48b4-92ac-71cb2a27c963` with no reportable findings. No material security/runtime delta was introduced by this release-only commit. - Local Gitleaks did not run because the repository requires 8.30.1 while the local binary is 8.24.3; the exact-head hosted `secrets` gate is required before merge. ## Post-merge gates The protected Release workflow must independently prove stable TestPyPI/PyPI bytes, PEP 740 provenance, GitHub attestations, supported-Python installs, annotated tag target, immutable GitHub Release and exact five assets, the release receipt, and workflow-owned issue receipts. A later protected documentation-only reconciliation PR will record those facts, close the milestone from live state, and advance `.release-reconciled-version` without changing the published release.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The v0.11.0 feature merge published TestPyPI development artifacts successfully, but post-publication verification installed the immutable wheel and sdist with
--no-depsinto empty virtual environments. The first runtime import therefore failed onmcp_types, even though the build-stage artifact smoke had already passed with the hash-locked runtime closure.Fix
This changes publication verification only. Runtime federation, DLP, receipts, dependencies, and release authorization semantics are unchanged.
Validation
scripts/quality.sh check: passedgit diff --check: passedLocal Gitleaks was not rerun because the repository requires 8.30.1 while the local binary is 8.24.3; the exact-head hosted secrets gate remains authoritative.
Release lifecycle
This corrective PR is required before the separate
Release v0.11.0authorization PR. It intentionally uses no issue-closing keywords; stable workflow receipt reconciliation owns milestone closure.