From defb193a7ed89d8b9bb821994f224b6ace1d2dfe Mon Sep 17 00:00:00 2001 From: Sarosh Hussain Date: Tue, 18 Aug 2026 09:24:23 -0500 Subject: [PATCH 1/2] fix(release): restore GitPin launch gates --- AGENTS.md | 6 +++--- README.md | 2 +- ROADMAP.md | 2 +- docs/current-state.md | 9 ++++++--- docs/website.md | 2 +- pnpm-lock.yaml | 10 +++++----- pnpm-workspace.yaml | 2 +- scripts/verify-package.mjs | 5 +++-- 8 files changed, 21 insertions(+), 17 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index 56d5e0f..54e84e2 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -4,9 +4,9 @@ **GitPin** is an index-free, read-only MCP server for multi-repo evidence pinned to Git HEAD. Answers carry path, line, and full SHA. It has no databases, embeddings, -queues, or write tools. GitPin 0.6.3 is the release candidate for the required PR evidence gate, -commit-pinned locators, and the legible gate-report failure annotation. The previous -immutable release remains published until 0.6.3 completes publication and production verification. +queues, or write tools. GitPin 0.6.3 is published to npm and GitHub Releases for the +required PR evidence gate, commit-pinned locators, and the legible gate-report failure annotation. MCP +Registry and Pages publication remain pending until independently production-verified. Package: `gitpin`. Tools: `pin.*`. CLI: `gitpin`. ## Knowledge authority diff --git a/README.md b/README.md index df6a387..4e1889a 100644 --- a/README.md +++ b/README.md @@ -36,7 +36,7 @@ gitpin gate --base --head The gate reads policy only from the trusted base commit, reads the submitted manifest only from the head commit, compares the merge-base diff, and verifies exact line-slice hashes. It never executes PR code and never labels a locator match as proof of semantic correctness. Use the [GitPin GitHub Action setup](docs/pr-evidence-gate.md) to make it a required check. That guide also documents an optional, separate CrewScore check for teams that want written-control coverage alongside GitPin evidence verification. -> **Release candidate:** GitPin 0.6.3 is prepared for npm, the MCP Registry, GitHub Releases, and Pages. After publication, install with `npx -y gitpin@0.6.3`. Node 20+. +> **Release status:** GitPin 0.6.3 is available from npm and GitHub Releases. MCP Registry and Pages publication are being completed against the same protected release tag. Install with `npx -y gitpin@0.6.3`. Node 20+. GitPin is maintained by **Sarosh Hussain**, who leads the project's technical direction. **Pendoah** is his company and operating context; GitPin remains the product and repository. diff --git a/ROADMAP.md b/ROADMAP.md index f2d6127..9a4e868 100644 --- a/ROADMAP.md +++ b/ROADMAP.md @@ -8,7 +8,7 @@ GitPin's roadmap is evidence-led. Planned work may change when validation shows - GitHub Action that emits a deterministic report suitable for a required merge check. - Twelve bounded, read-only `pin.*` MCP tools for discovery, evidence, verification, and decision support. - Git `HEAD` pinning with path, line, content hash, and full commit provenance. -- 0.6.3 is the release candidate for source, npm, MCP Registry metadata, GitHub Release, Pages, Action/install snippets, deterministic demos, launch materials, and the legible gate-report failure annotation; historical releases remain immutable. +- 0.6.3 is published to npm and GitHub Releases; MCP Registry and Pages publication remain pending. The release includes the Action/install snippets, deterministic demos, launch materials, and the legible gate-report failure annotation; historical releases remain immutable. - Exposure policies that fail closed and sensitive-path blocking. - Local stdio and bearer-authenticated, documentation-only HTTP transports. - `init`, `doctor`, EvidenceBrief, deterministic tests, and clean packed install verification. diff --git a/docs/current-state.md b/docs/current-state.md index f61ff00..5b121fa 100644 --- a/docs/current-state.md +++ b/docs/current-state.md @@ -9,8 +9,9 @@ Update this file whenever the project surface or its operational truth changes. Git HEAD: `pin.*` tools, `gitpin` CLI, and a PR evidence gate. No databases, embeddings, queues, or write tools. - **Package:** `gitpin` (npm, MIT). **Homepage:** `https://shmindmaster.github.io/gitpin/`. -- **Published:** `0.6.2` is the current verified release (npm package, MCP Registry - entry, GitHub Release, GitHub Pages site). Historical releases remain immutable. +- **Published:** npm and GitHub Releases expose `0.6.3`; the MCP Registry and GitHub + Pages still expose `0.6.2` pending explicit publication and independent verification. + Historical releases remain immutable. ## Source layout @@ -26,7 +27,9 @@ Update this file whenever the project surface or its operational truth changes. - GitHub Actions: `ci.yml` (lint/format/typecheck/verifiers/tests), `evidence-gate.yml` (PR evidence gate), `pages.yml` (site deploy), `publish-mcp.yml` (MCP registry), `release.yml` (npm release). -- Publishing runs only from tagged releases on `main`. +- npm publishes from tags on `main`; MCP publication is manually dispatched against a + validated release tag. Pages is manually dispatched and requires independent deployed + SHA and content verification. ## Local generated artifacts diff --git a/docs/website.md b/docs/website.md index 6a4310f..30e8caf 100644 --- a/docs/website.md +++ b/docs/website.md @@ -2,7 +2,7 @@ GitPin ships a static public site in `site/`. It leads with the required PR evidence gate, explains the trust boundary, demonstrates the local EvidenceBrief companion, and links directly to source setup and contributor documentation. -The GitPin 0.6.3 release candidate is prepared for the npm package, GitHub Release, and MCP Registry artifact. The 0.6.2 artifacts remain published and immutable until 0.6.3 completes publication and production verification. A Pages deployment has its own deployment SHA and must be verified independently; package parity does not imply website-source parity. Historical release artifacts remain immutable. +GitPin 0.6.3 is published to npm and GitHub Releases. The MCP Registry and Pages still expose 0.6.2 pending explicit publication and independent verification. A Pages deployment has its own deployment SHA and must be verified independently; package parity does not imply website-source parity. Historical release artifacts remain immutable. The deployable surface includes a privacy page, canonical and social metadata, `robots.txt`, and a sitemap for the GitHub Pages URL. These are static release artifacts; they do not change the MCP server's read-only boundary. diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 497aedd..a2bda18 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -8,7 +8,7 @@ overrides: hono: ^4.12.34 fast-uri: ^3.1.5 postcss: ^8.5.23 - nanoid: ^3.3.17 + nanoid: ^3.3.18 importers: @@ -869,8 +869,8 @@ packages: ms@2.1.3: resolution: {integrity: sha512-6FlzubTLZG3J2a/NVCAleEhjzq5oxgHyaCU9yYXvcLsvoVaHJq/s5xXI6/XXP6tz7R9xAOtHnSO/tXtF3WRTlA==} - nanoid@3.3.17: - resolution: {integrity: sha512-xQLf0A3HOMlgHq0n247/LRuAOYmB7dXJ/DvAxGvsSBij45XtBSmQycu+F8ODbHwns/XyFZagyL1+J0Offw1E0g==} + nanoid@3.3.18: + resolution: {integrity: sha512-DTg4MJbGMWkfi6VZFdNt2/caMbQy4Ou+Op/hJQvGEWcnVfoA1QA+xzRKAzw9jD6+GVOOeYr/mIcuDSdug6F6+w==} engines: {node: ^10 || ^12 || ^13.7 || ^14 || >=15.0.1} hasBin: true @@ -1812,7 +1812,7 @@ snapshots: ms@2.1.3: {} - nanoid@3.3.17: {} + nanoid@3.3.18: {} negotiator@1.0.0: {} @@ -1854,7 +1854,7 @@ snapshots: postcss@8.5.25: dependencies: - nanoid: 3.3.17 + nanoid: 3.3.18 picocolors: 1.1.1 source-map-js: 1.2.1 diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml index d1745c1..8463d44 100644 --- a/pnpm-workspace.yaml +++ b/pnpm-workspace.yaml @@ -5,4 +5,4 @@ overrides: hono: ^4.12.34 fast-uri: ^3.1.5 postcss: ^8.5.23 - nanoid: ^3.3.17 + nanoid: ^3.3.18 diff --git a/scripts/verify-package.mjs b/scripts/verify-package.mjs index a12b04b..30b2d64 100644 --- a/scripts/verify-package.mjs +++ b/scripts/verify-package.mjs @@ -2,7 +2,7 @@ import { execFileSync } from 'node:child_process'; import { createHash } from 'node:crypto'; import { existsSync, mkdirSync, mkdtempSync, readFileSync, rmSync, writeFileSync } from 'node:fs'; import { tmpdir } from 'node:os'; -import { basename, dirname, join, resolve } from 'node:path'; +import { basename, join, resolve } from 'node:path'; import { pathToFileURL } from 'node:url'; const marker = 'REPOCONTEXT_PACKED_FIRST_ANSWER'; @@ -151,7 +151,8 @@ try { throw new Error('Packed README must document the published GitPin package.'); } if ( - packageReadme.includes('After the package is published') || + /(?:after|once) (?:the )?(?:package |release )?is published/iu.test(packageReadme) || + /prepared for (?:npm|publication)/iu.test(packageReadme) || packageReadme.includes('GitHub Discussions or issues') ) { throw new Error('Packed README must not contain stale pre-publication or disabled-community guidance.'); From 48e18aa35437a96bac45ad876ef55c43481a3fbd Mon Sep 17 00:00:00 2001 From: Sarosh Hussain Date: Tue, 18 Aug 2026 09:27:18 -0500 Subject: [PATCH 2/2] docs(gate): refresh launch evidence --- .gitpin/change-evidence.json | 44 ++++++++++++++++++++++++------------ 1 file changed, 30 insertions(+), 14 deletions(-) diff --git a/.gitpin/change-evidence.json b/.gitpin/change-evidence.json index bfae716..c36f310 100644 --- a/.gitpin/change-evidence.json +++ b/.gitpin/change-evidence.json @@ -1,6 +1,6 @@ { "schemaVersion": 1, - "summary": "Align the package, MCP Registry, Action, documentation, website, and generated demo release surfaces on the 0.6.3 candidate, and re-pin the repository self-gate to the published v0.6.3 release source.", + "summary": "Restore the 0.6.3 launch gates by patching a newly disclosed dependency advisory, hardening package truth checks, and documenting the current publication split.", "claims": [ { "id": "DOCS-1", @@ -18,7 +18,7 @@ "path": "AGENTS.md", "lineStart": 5, "lineEnd": 10, - "contentSha256": "7c1b04097e8cb11831c83e49cd03a0ca6e3d7d40ff30b79fc84f0792891a1327" + "contentSha256": "da608bc5f1a6233fce6caa8e978dee617ca4d7b75671bee878e8b6eba216db69" }, { "ref": "head", @@ -63,9 +63,9 @@ { "ref": "head", "path": "docs/current-state.md", - "lineStart": 17, - "lineEnd": 20, - "contentSha256": "9bfe919aa49b4aabcabab5b947bb52c9a98e90c964c4a648fa0e3243c8b7346f" + "lineStart": 27, + "lineEnd": 34, + "contentSha256": "71a2f01d3ad003f65df6b2f82c815e0f5c056ff2fa46d50213b1ff7b689c4051" }, { "ref": "head", @@ -116,7 +116,7 @@ }, { "id": "DEPS-1", - "statement": "The frozen pnpm graph forces nanoid to the patched 3.3.17 release while preserving the existing dependency major.", + "statement": "The frozen pnpm graph forces nanoid to the patched 3.3.18 release while preserving the existing dependency major.", "covers": [ "pnpm-lock.yaml", "pnpm-workspace.yaml" @@ -127,14 +127,30 @@ "path": "pnpm-workspace.yaml", "lineStart": 4, "lineEnd": 8, - "contentSha256": "6874ae6d22591f7af07f17884df2950417d33ed54f065920851158b55342d1ac" + "contentSha256": "291c8788800b4c28f39a3041dee6396fa1ebc351fd70ad04678409eb85d9cea9" }, { "ref": "head", "path": "pnpm-lock.yaml", "lineStart": 7, "lineEnd": 11, - "contentSha256": "6874ae6d22591f7af07f17884df2950417d33ed54f065920851158b55342d1ac" + "contentSha256": "291c8788800b4c28f39a3041dee6396fa1ebc351fd70ad04678409eb85d9cea9" + } + ] + }, + { + "id": "PACKAGE-TRUTH", + "statement": "The packed-package gate rejects multiple equivalent forms of stale pre-publication README guidance.", + "covers": [ + "scripts/verify-package.mjs" + ], + "evidence": [ + { + "ref": "head", + "path": "scripts/verify-package.mjs", + "lineStart": 149, + "lineEnd": 160, + "contentSha256": "a8b5cdeb1c85a81988a139020324d3a3d29fe7c13c029a9058ad76fbd2032437" } ] }, @@ -229,7 +245,7 @@ }, { "id": "V063-RELEASE-TRUTH", - "statement": "Release-surface documentation consistently names the 0.6.3 candidate in the mission, roadmap, changelog, install, CI, and troubleshooting guidance while historical 0.6.2 records remain immutable.", + "statement": "Release-surface documentation consistently names the published 0.6.3 package and GitHub Release while explicitly keeping MCP Registry and Pages verification pending.", "covers": [ "AGENTS.md", "README.md", @@ -246,21 +262,21 @@ "path": "AGENTS.md", "lineStart": 7, "lineEnd": 9, - "contentSha256": "279f464d451eebdc284bae4d21d88be1434b79a42033e75204e95f413f1159e6" + "contentSha256": "44406fa5abfed446890a83b725107fa728e7ac0d7af72fb42450c300a95b217e" }, { "ref": "head", "path": "README.md", "lineStart": 39, "lineEnd": 39, - "contentSha256": "7cddceec89b4dfbed67b2bafd39d81795f859f906a6b726ff926c3c1dbafb060" + "contentSha256": "b302ef8dc9ee5beccf8ed27dd7a9f6a40626b264a708f56d512d19e814ffd7ae" }, { "ref": "head", "path": "ROADMAP.md", "lineStart": 11, "lineEnd": 11, - "contentSha256": "ad2f89df60650d8062bb99808dd14696b8f72c128073906febeebe52b0082d12" + "contentSha256": "1a1e491a39460a358b7697f44664fa672c9685cdb9c13d082586a62a7033f20b" }, { "ref": "head", @@ -349,7 +365,7 @@ }, { "id": "V063-SITE", - "statement": "The static site metadata, llms.txt quickstart, browser tests, and website documentation advertise the 0.6.3 candidate without asserting a live release.", + "statement": "The static site metadata, llms.txt quickstart, browser tests, and website documentation distinguish the 0.6.3 source from the still-live 0.6.2 Pages deployment.", "covers": [ "site/index.html", "site/llms.txt", @@ -383,7 +399,7 @@ "path": "docs/website.md", "lineStart": 5, "lineEnd": 5, - "contentSha256": "bcecb1d2ffa80555f40d8791182e5844dbe8ebb6f464bdf5043402642bb1ca51" + "contentSha256": "820ae8ab0dd15828f445cf144a28b6a6f280d1d45d11d37bbcadd86e55efbcc5" } ] },