Skip to content

Commit f68fbc2

Browse files
committed
docs: record stable 0.1.3 release evidence
1 parent 265375a commit f68fbc2

3 files changed

Lines changed: 137 additions & 11 deletions

File tree

COMPATIBILITY.md

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -167,3 +167,19 @@ smoke, OIDC publication, public-registry ESM/CommonJS and declaration checks,
167167
single effective OpenAI installation, official error identity, integrity,
168168
signature, and provenance evidence is recorded in
169169
[RELEASING.md](./RELEASING.md#stable-012-release-evidence).
170+
171+
For stable `0.1.3`, the README, runnable ESM/CommonJS examples, and bounded
172+
release-tag validation moved to `gpt-5.6-sol` without expanding the supported
173+
operation surface. The source change passed
174+
[PR CI 30618613128](https://github.com/cometapi-dev/cometapi-node/actions/runs/30618613128),
175+
and the action-authored release candidate passed
176+
[CI run 30627706967 attempt 2](https://github.com/cometapi-dev/cometapi-node/actions/runs/30627706967/attempts/2).
177+
Release Please created the immutable
178+
[`v0.1.3` Release](https://github.com/cometapi-dev/cometapi-node/releases/tag/v0.1.3),
179+
and
180+
[Publish run 30628187558](https://github.com/cometapi-dev/cometapi-node/actions/runs/30628187558)
181+
completed the tag-bound artifact and three-request live smoke, whose Chat
182+
Completions and Responses calls used `gpt-5.6-sol`, followed by OIDC
183+
publication, registry signature and provenance, and clean ESM/CommonJS public
184+
installation checks. Exact evidence is recorded in
185+
[RELEASING.md](./RELEASING.md#stable-013-release-evidence).

RELEASING.md

Lines changed: 87 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -672,6 +672,93 @@ Finally, commit-level `Release-As:` is rejected before the action because the
672672
GitHub documents that a `GITHUB_TOKEN`-created PR's opened or synchronize event
673673
[creates an approval-required workflow run](https://github.com/github/docs/blob/e1e4aa937308f21c411c248b4966873536bb0cba/data/reusables/actions/actions-do-not-trigger-workflows.md#L1-L6).
674674

675+
## Stable 0.1.3 release evidence
676+
677+
Stable `0.1.3` completed on 2026-07-31 with these independently auditable
678+
layers:
679+
680+
- Source [PR #48](https://github.com/cometapi-dev/cometapi-node/pull/48)
681+
updated the README, runnable ESM/CommonJS examples, mocked example fixtures,
682+
and protected live-smoke defaults to `gpt-5.6-sol`. It also disabled reasoning
683+
explicitly in the bounded chat and Responses requests so the 16-token cap
684+
remained effective. Final head
685+
`cae4c97a29221fd46aa798d93c0ed10b6e94cb7d` passed
686+
[CI run 30618613128](https://github.com/cometapi-dev/cometapi-node/actions/runs/30618613128)
687+
and merged as
688+
[`3809692d35e2d9f98ba3a209947c716d8e4307b7`](https://github.com/cometapi-dev/cometapi-node/commit/3809692d35e2d9f98ba3a209947c716d8e4307b7).
689+
- Manual Release Please preparation
690+
[run 30627666360 attempt 1](https://github.com/cometapi-dev/cometapi-node/actions/runs/30627666360/attempts/1)
691+
ran from that exact merge on `main` and created the action-authored release
692+
PR below.
693+
- The resulting four-file release
694+
[PR #49](https://github.com/cometapi-dev/cometapi-node/pull/49) had final head
695+
`39894513ae2534d778a0a4b8bc2a978533bec40b` and changed only the manifest,
696+
changelog, package lock, and package manifest. After the human workflow gate,
697+
its complete blocking matrix passed in
698+
[CI run 30627706967 attempt 2](https://github.com/cometapi-dev/cometapi-node/actions/runs/30627706967/attempts/2).
699+
Human repository administrator `tensornull`, distinct from bot author
700+
`github-actions[bot]`, submitted formal
701+
[review 4828166257](https://github.com/cometapi-dev/cometapi-node/pull/49#pullrequestreview-4828166257)
702+
with `state=APPROVED` against that exact head before merge. The reviewed merge
703+
produced
704+
[`265375a088cce50d2e5980ca557404fd01028efc`](https://github.com/cometapi-dev/cometapi-node/commit/265375a088cce50d2e5980ca557404fd01028efc).
705+
- [Release Please run 30628129319 attempt 1](https://github.com/cometapi-dev/cometapi-node/actions/runs/30628129319/attempts/1)
706+
created the exact lightweight `v0.1.3` tag and immutable non-prerelease GitHub
707+
Release ID `363031910`. The bot-authored
708+
[`v0.1.3` Release](https://github.com/cometapi-dev/cometapi-node/releases/tag/v0.1.3)
709+
targets the reviewed merge commit and was published at
710+
`2026-07-31T11:45:32Z`.
711+
- The unprivileged
712+
[handoff run 30628167257 attempt 1](https://github.com/cometapi-dev/cometapi-node/actions/runs/30628167257/attempts/1)
713+
validated the exact Release Please result and immutable Release before
714+
dispatching the tag-bound
715+
[Publish run 30628187558 attempt 1](https://github.com/cometapi-dev/cometapi-node/actions/runs/30628187558/attempts/1).
716+
That run rebuilt the release commit, passed the full release checks and
717+
public declarations/fixtures, and uploaded artifact ID `8792282959`, named
718+
`npm-package-0.1.3-30628187558-1`, with ZIP digest
719+
`sha256:f896a2a24ef8b6c30aac03327d022a277558c99db8c8ca2e32b3a4f7b25502f3`.
720+
Its sole tarball has SHA-256
721+
`283b1dbc91f2eeb84d675da2623bc25eab4148da333f7a77b07be548b6589293`
722+
and is byte-identical to the public registry tarball.
723+
- The same run's
724+
[live job 91148676643](https://github.com/cometapi-dev/cometapi-node/actions/runs/30628187558/job/91148676643)
725+
checked out `refs/tags/v0.1.3` and passed exactly three sequential requests,
726+
with Chat Completions and Responses using `gpt-5.6-sol`, a 16-token output
727+
cap, 60-second per-request timeout, concurrency one, and
728+
stop-on-first-failure behavior.
729+
- Protected npm job
730+
[91148760122](https://github.com/cometapi-dev/cometapi-node/actions/runs/30628187558/job/91148760122)
731+
published through the tag-only npm Environment and GitHub Actions OIDC at
732+
`2026-07-31T11:51:06.196Z`. Attempt 1 then completed exact artifact,
733+
dist-tag, signature, attestation, provenance, and public-install verification
734+
without a replay.
735+
- At closeout, npm's stable channel resolved to `0.1.3`, while the prerelease
736+
channel remained `0.1.0-alpha.3`. The package has SHA-1
737+
`e000b2066b6c19b6ff4a327ed9451dba896cc939` and integrity
738+
`sha512-ByPYZsoLGDYZeyMZCnq99CzT3IhveylPMG8gB8bLlBSpRP8g/FdD8jrQvZMWx+4+qaVSTQp4HVHHYsU9POeFtw==`.
739+
`npm audit signatures` verified registry signatures for all three installed
740+
packages and attestations for two. npm exposes its publish attestation at
741+
[Sigstore index 2300742325](https://search.sigstore.dev/?logIndex=2300742325)
742+
and SLSA provenance at
743+
[index 2300742191](https://search.sigstore.dev/?logIndex=2300742191). The
744+
provenance binds `cometapi@0.1.3` to `publish.yml@refs/tags/v0.1.3`, commit
745+
`265375a088cce50d2e5980ca557404fd01028efc`, and Publish run
746+
`30628187558/1`.
747+
- Independent public-registry verification downloaded the workflow artifact
748+
and registry tarball, proved byte identity and the integrity above, installed
749+
`cometapi@0.1.3` in clean ESM and CommonJS consumers, and resolved one
750+
effective `openai@6.47.0` installation while preserving the public class and
751+
official error-type boundary.
752+
- Final readback kept `main` at the release commit, passed
753+
[default-branch CI 30628129332](https://github.com/cometapi-dev/cometapi-node/actions/runs/30628129332),
754+
restored `RELEASE_PLEASE_ENABLED=false`, kept `LIVE_SMOKE_ENABLED=true`, and
755+
retained exactly one npm Environment deployment policy, `tag:v*` (policy ID
756+
`55718965`).
757+
758+
This release repeated the permanent immutable-tag path without recovery or
759+
cross-run evidence reuse and moved the protected live validation to the same
760+
model ID shown in the public examples.
761+
675762
## Stable 0.1.2 release evidence
676763

677764
Stable `0.1.2` completed on 2026-07-31 with these independently auditable

ROADMAP.md

Lines changed: 34 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -5,10 +5,9 @@ Last updated: 2026-07-31
55
Repository contract: This roadmap is self-contained and is the public source
66
of truth for this repository's release sequence.
77

8-
Stable `0.1.2` completed the public options type contract, release-neutral
9-
consumer documentation, the first permanent immutable-tag publication, bounded
10-
live smoke, OIDC provenance, public-install verification, and replay hardening
11-
on 2026-07-31.
8+
Stable `0.1.3` aligned the public examples and protected live validation on
9+
`gpt-5.6-sol`, preserved the bounded smoke budget, and completed the immutable
10+
tag, OIDC provenance, and public-install verification sequence on 2026-07-31.
1211

1312
## Product Target
1413

@@ -25,10 +24,11 @@ Release then failed before invoking npm because its publication guard rejected
2524
the fixed `actions/setup-node` authentication placeholder.
2625
`0.1.0-alpha.3` subsequently completed the OIDC, provenance, ownership, and
2726
public-install verification sequence. Stable `0.1.1` completed its separately
28-
recorded recovery sequence on 2026-07-30, and stable `0.1.2` completed the
29-
permanent tag-bound sequence on 2026-07-31. Stable 0.1.x packages use `latest`,
30-
and Registry Alpha artifacts use `next`; query npm and GitHub rather than
31-
treating this roadmap as current registry state.
27+
recorded recovery sequence on 2026-07-30, stable `0.1.2` completed the first
28+
permanent tag-bound sequence, and stable `0.1.3` repeated that sequence with the
29+
updated example and live-smoke model on 2026-07-31. Stable 0.1.x packages use
30+
`latest`, and Registry Alpha artifacts use `next`; query npm and GitHub rather
31+
than treating this roadmap as current registry state.
3232

3333
## Milestones
3434

@@ -41,6 +41,7 @@ treating this roadmap as current registry state.
4141
| 0.1.0 Stable | Complete | Users can install a fully verified package from npm's default channel. |
4242
| 0.1.1 maintenance patch | Complete | Users receive the corrected options contract; the permanent tag-bound release architecture is installed and the one-time recovery is recorded. |
4343
| 0.1.2 maintenance patch | Complete | Users receive strict public option types and release-neutral package documentation through the verified permanent tag-bound publication path. |
44+
| 0.1.3 maintenance patch | Complete | Users receive `gpt-5.6-sol` public examples backed by the same bounded model validation in the permanent tag-bound publication path. |
4445
| 0.2.0 provider-native text | Planned | Users can opt into Anthropic Messages and Gemini text adapters through isolated subpath exports. |
4546
| 0.3.0 CometAPI resources | Planned | Users receive typed access to the first stable CometAPI-specific account or platform resources. |
4647
| Media and task APIs | Later | Users receive typed image, video, audio, upload, polling, and task lifecycle helpers after their contracts are stable. |
@@ -125,9 +126,11 @@ The permanent state is `RELEASE_PLEASE_ENABLED=false`,
125126
`tag:v*`. Current stable publication uses an unprivileged Release Please
126127
handoff followed by an immutable-tag dispatch, fresh verification and live
127128
smoke, and tag-bound npm OIDC. Stable `0.1.2` completed the first end-to-end
128-
registry execution of that permanent path. Full immutable evidence is recorded
129-
in [RELEASING.md](./RELEASING.md#stable-012-release-evidence); the earlier
130-
one-time recovery remains separately recorded as historical evidence.
129+
registry execution of that permanent path, and stable `0.1.3` repeated it
130+
without a replay while aligning public and live-smoke model IDs. Full immutable
131+
evidence for the later execution is recorded in
132+
[RELEASING.md](./RELEASING.md#stable-013-release-evidence); the earlier one-time
133+
recovery remains separately recorded as historical evidence.
131134

132135
## Private Remote Validation
133136

@@ -332,6 +335,26 @@ attempt 3 or later fails before entering the npm Environment. Release-specific
332335
PR, review, run, artifact, registry, provenance, and final-state evidence is
333336
recorded in [RELEASING.md](./RELEASING.md#stable-012-release-evidence).
334337

338+
## 0.1.3: Model Example and Live Validation Refresh (Complete)
339+
340+
Stable `0.1.3` replaced the older model ID in the README, runnable ESM and
341+
CommonJS examples, example documentation, and protected live-smoke defaults
342+
with `gpt-5.6-sol`. Chat Completions now passes `reasoning_effort: "none"`, and
343+
Responses passes `reasoning: { effort: "none" }`, so the existing 16-token
344+
release budget remains effective. Example mocks assert the model; live-smoke
345+
contracts assert the model and reasoning fields. This is an example and
346+
validation update, not a new supported operation or an SDK-level default-model
347+
contract.
348+
349+
The source and action-authored release PRs passed their complete required
350+
matrices. Release Please created the immutable tag and Release, the unprivileged
351+
handoff dispatched one exact tag-bound Publish run, and that run rebuilt the
352+
artifact, passed exactly three sequential requests with Chat Completions and
353+
Responses using `gpt-5.6-sol`, published through npm OIDC, and completed
354+
signature, provenance, and independent public-install verification without
355+
replay. Release-specific evidence is recorded in
356+
[RELEASING.md](./RELEASING.md#stable-013-release-evidence).
357+
335358
## Stable 0.1.x Maintenance
336359

337360
Maintenance patches close contract and release-process gaps without expanding

0 commit comments

Comments
 (0)