Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
44 changes: 30 additions & 14 deletions .gitpin/change-evidence.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"schemaVersion": 1,
"summary": "Align the package, MCP Registry, Action, documentation, website, and generated demo release surfaces on the 0.6.3 candidate, and re-pin the repository self-gate to the published v0.6.3 release source.",
"summary": "Restore the 0.6.3 launch gates by patching a newly disclosed dependency advisory, hardening package truth checks, and documenting the current publication split.",
"claims": [
{
"id": "DOCS-1",
Expand All @@ -18,7 +18,7 @@
"path": "AGENTS.md",
"lineStart": 5,
"lineEnd": 10,
"contentSha256": "7c1b04097e8cb11831c83e49cd03a0ca6e3d7d40ff30b79fc84f0792891a1327"
"contentSha256": "da608bc5f1a6233fce6caa8e978dee617ca4d7b75671bee878e8b6eba216db69"
},
{
"ref": "head",
Expand Down Expand Up @@ -63,9 +63,9 @@
{
"ref": "head",
"path": "docs/current-state.md",
"lineStart": 17,
"lineEnd": 20,
"contentSha256": "9bfe919aa49b4aabcabab5b947bb52c9a98e90c964c4a648fa0e3243c8b7346f"
"lineStart": 27,
"lineEnd": 34,
"contentSha256": "71a2f01d3ad003f65df6b2f82c815e0f5c056ff2fa46d50213b1ff7b689c4051"
},
{
"ref": "head",
Expand Down Expand Up @@ -116,7 +116,7 @@
},
{
"id": "DEPS-1",
"statement": "The frozen pnpm graph forces nanoid to the patched 3.3.17 release while preserving the existing dependency major.",
"statement": "The frozen pnpm graph forces nanoid to the patched 3.3.18 release while preserving the existing dependency major.",
"covers": [
"pnpm-lock.yaml",
"pnpm-workspace.yaml"
Expand All @@ -127,14 +127,30 @@
"path": "pnpm-workspace.yaml",
"lineStart": 4,
"lineEnd": 8,
"contentSha256": "6874ae6d22591f7af07f17884df2950417d33ed54f065920851158b55342d1ac"
"contentSha256": "291c8788800b4c28f39a3041dee6396fa1ebc351fd70ad04678409eb85d9cea9"
},
{
"ref": "head",
"path": "pnpm-lock.yaml",
"lineStart": 7,
"lineEnd": 11,
"contentSha256": "6874ae6d22591f7af07f17884df2950417d33ed54f065920851158b55342d1ac"
"contentSha256": "291c8788800b4c28f39a3041dee6396fa1ebc351fd70ad04678409eb85d9cea9"
}
]
},
{
"id": "PACKAGE-TRUTH",
"statement": "The packed-package gate rejects multiple equivalent forms of stale pre-publication README guidance.",
"covers": [
"scripts/verify-package.mjs"
],
"evidence": [
{
"ref": "head",
"path": "scripts/verify-package.mjs",
"lineStart": 149,
"lineEnd": 160,
"contentSha256": "a8b5cdeb1c85a81988a139020324d3a3d29fe7c13c029a9058ad76fbd2032437"
}
]
},
Expand Down Expand Up @@ -229,7 +245,7 @@
},
{
"id": "V063-RELEASE-TRUTH",
"statement": "Release-surface documentation consistently names the 0.6.3 candidate in the mission, roadmap, changelog, install, CI, and troubleshooting guidance while historical 0.6.2 records remain immutable.",
"statement": "Release-surface documentation consistently names the published 0.6.3 package and GitHub Release while explicitly keeping MCP Registry and Pages verification pending.",
"covers": [
"AGENTS.md",
"README.md",
Expand All @@ -246,21 +262,21 @@
"path": "AGENTS.md",
"lineStart": 7,
"lineEnd": 9,
"contentSha256": "279f464d451eebdc284bae4d21d88be1434b79a42033e75204e95f413f1159e6"
"contentSha256": "44406fa5abfed446890a83b725107fa728e7ac0d7af72fb42450c300a95b217e"
},
{
"ref": "head",
"path": "README.md",
"lineStart": 39,
"lineEnd": 39,
"contentSha256": "7cddceec89b4dfbed67b2bafd39d81795f859f906a6b726ff926c3c1dbafb060"
"contentSha256": "b302ef8dc9ee5beccf8ed27dd7a9f6a40626b264a708f56d512d19e814ffd7ae"
},
{
"ref": "head",
"path": "ROADMAP.md",
"lineStart": 11,
"lineEnd": 11,
"contentSha256": "ad2f89df60650d8062bb99808dd14696b8f72c128073906febeebe52b0082d12"
"contentSha256": "1a1e491a39460a358b7697f44664fa672c9685cdb9c13d082586a62a7033f20b"
},
{
"ref": "head",
Expand Down Expand Up @@ -349,7 +365,7 @@
},
{
"id": "V063-SITE",
"statement": "The static site metadata, llms.txt quickstart, browser tests, and website documentation advertise the 0.6.3 candidate without asserting a live release.",
"statement": "The static site metadata, llms.txt quickstart, browser tests, and website documentation distinguish the 0.6.3 source from the still-live 0.6.2 Pages deployment.",
"covers": [
"site/index.html",
"site/llms.txt",
Expand Down Expand Up @@ -383,7 +399,7 @@
"path": "docs/website.md",
"lineStart": 5,
"lineEnd": 5,
"contentSha256": "bcecb1d2ffa80555f40d8791182e5844dbe8ebb6f464bdf5043402642bb1ca51"
"contentSha256": "820ae8ab0dd15828f445cf144a28b6a6f280d1d45d11d37bbcadd86e55efbcc5"
}
]
},
Expand Down
6 changes: 3 additions & 3 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,9 @@

**GitPin** is an index-free, read-only MCP server for multi-repo evidence pinned to
Git HEAD. Answers carry path, line, and full SHA. It has no databases, embeddings,
queues, or write tools. GitPin 0.6.3 is the release candidate for the required PR evidence gate,
commit-pinned locators, and the legible gate-report failure annotation. The previous
immutable release remains published until 0.6.3 completes publication and production verification.
queues, or write tools. GitPin 0.6.3 is published to npm and GitHub Releases for the
required PR evidence gate, commit-pinned locators, and the legible gate-report failure annotation. MCP
Registry and Pages publication remain pending until independently production-verified.
Package: `gitpin`. Tools: `pin.*`. CLI: `gitpin`.

## Knowledge authority
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ gitpin gate --base <full-base-sha> --head <full-head-sha>

The gate reads policy only from the trusted base commit, reads the submitted manifest only from the head commit, compares the merge-base diff, and verifies exact line-slice hashes. It never executes PR code and never labels a locator match as proof of semantic correctness. Use the [GitPin GitHub Action setup](docs/pr-evidence-gate.md) to make it a required check. That guide also documents an optional, separate CrewScore check for teams that want written-control coverage alongside GitPin evidence verification.

> **Release candidate:** GitPin 0.6.3 is prepared for npm, the MCP Registry, GitHub Releases, and Pages. After publication, install with `npx -y gitpin@0.6.3`. Node 20+.
> **Release status:** GitPin 0.6.3 is available from npm and GitHub Releases. MCP Registry and Pages publication are being completed against the same protected release tag. Install with `npx -y gitpin@0.6.3`. Node 20+.

GitPin is maintained by **Sarosh Hussain**, who leads the project's technical direction. **Pendoah** is his company and operating context; GitPin remains the product and repository.

Expand Down
2 changes: 1 addition & 1 deletion ROADMAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ GitPin's roadmap is evidence-led. Planned work may change when validation shows
- GitHub Action that emits a deterministic report suitable for a required merge check.
- Twelve bounded, read-only `pin.*` MCP tools for discovery, evidence, verification, and decision support.
- Git `HEAD` pinning with path, line, content hash, and full commit provenance.
- 0.6.3 is the release candidate for source, npm, MCP Registry metadata, GitHub Release, Pages, Action/install snippets, deterministic demos, launch materials, and the legible gate-report failure annotation; historical releases remain immutable.
- 0.6.3 is published to npm and GitHub Releases; MCP Registry and Pages publication remain pending. The release includes the Action/install snippets, deterministic demos, launch materials, and the legible gate-report failure annotation; historical releases remain immutable.
- Exposure policies that fail closed and sensitive-path blocking.
- Local stdio and bearer-authenticated, documentation-only HTTP transports.
- `init`, `doctor`, EvidenceBrief, deterministic tests, and clean packed install verification.
Expand Down
9 changes: 6 additions & 3 deletions docs/current-state.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,9 @@ Update this file whenever the project surface or its operational truth changes.
Git HEAD: `pin.*` tools, `gitpin` CLI, and a PR evidence gate. No databases,
embeddings, queues, or write tools.
- **Package:** `gitpin` (npm, MIT). **Homepage:** `https://shmindmaster.github.io/gitpin/`.
- **Published:** `0.6.2` is the current verified release (npm package, MCP Registry
entry, GitHub Release, GitHub Pages site). Historical releases remain immutable.
- **Published:** npm and GitHub Releases expose `0.6.3`; the MCP Registry and GitHub
Pages still expose `0.6.2` pending explicit publication and independent verification.
Historical releases remain immutable.

## Source layout

Expand All @@ -26,7 +27,9 @@ Update this file whenever the project surface or its operational truth changes.
- GitHub Actions: `ci.yml` (lint/format/typecheck/verifiers/tests), `evidence-gate.yml`
(PR evidence gate), `pages.yml` (site deploy), `publish-mcp.yml` (MCP registry),
`release.yml` (npm release).
- Publishing runs only from tagged releases on `main`.
- npm publishes from tags on `main`; MCP publication is manually dispatched against a
validated release tag. Pages is manually dispatched and requires independent deployed
SHA and content verification.

## Local generated artifacts

Expand Down
2 changes: 1 addition & 1 deletion docs/website.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

GitPin ships a static public site in `site/`. It leads with the required PR evidence gate, explains the trust boundary, demonstrates the local EvidenceBrief companion, and links directly to source setup and contributor documentation.

The GitPin 0.6.3 release candidate is prepared for the npm package, GitHub Release, and MCP Registry artifact. The 0.6.2 artifacts remain published and immutable until 0.6.3 completes publication and production verification. A Pages deployment has its own deployment SHA and must be verified independently; package parity does not imply website-source parity. Historical release artifacts remain immutable.
GitPin 0.6.3 is published to npm and GitHub Releases. The MCP Registry and Pages still expose 0.6.2 pending explicit publication and independent verification. A Pages deployment has its own deployment SHA and must be verified independently; package parity does not imply website-source parity. Historical release artifacts remain immutable.

The deployable surface includes a privacy page, canonical and social metadata, `robots.txt`, and a sitemap for the GitHub Pages URL. These are static release artifacts; they do not change the MCP server's read-only boundary.

Expand Down
10 changes: 5 additions & 5 deletions pnpm-lock.yaml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion pnpm-workspace.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,4 +5,4 @@ overrides:
hono: ^4.12.34
fast-uri: ^3.1.5
postcss: ^8.5.23
nanoid: ^3.3.17
nanoid: ^3.3.18
5 changes: 3 additions & 2 deletions scripts/verify-package.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ import { execFileSync } from 'node:child_process';
import { createHash } from 'node:crypto';
import { existsSync, mkdirSync, mkdtempSync, readFileSync, rmSync, writeFileSync } from 'node:fs';
import { tmpdir } from 'node:os';
import { basename, dirname, join, resolve } from 'node:path';
import { basename, join, resolve } from 'node:path';
import { pathToFileURL } from 'node:url';

const marker = 'REPOCONTEXT_PACKED_FIRST_ANSWER';
Expand Down Expand Up @@ -151,7 +151,8 @@ try {
throw new Error('Packed README must document the published GitPin package.');
}
if (
packageReadme.includes('After the package is published') ||
/(?:after|once) (?:the )?(?:package |release )?is published/iu.test(packageReadme) ||
/prepared for (?:npm|publication)/iu.test(packageReadme) ||
packageReadme.includes('GitHub Discussions or issues')
) {
throw new Error('Packed README must not contain stale pre-publication or disabled-community guidance.');
Expand Down