diff --git a/COMPATIBILITY.md b/COMPATIBILITY.md index 1f1834b..8caf91e 100644 --- a/COMPATIBILITY.md +++ b/COMPATIBILITY.md @@ -167,3 +167,19 @@ smoke, OIDC publication, public-registry ESM/CommonJS and declaration checks, single effective OpenAI installation, official error identity, integrity, signature, and provenance evidence is recorded in [RELEASING.md](./RELEASING.md#stable-012-release-evidence). + +For stable `0.1.3`, the README, runnable ESM/CommonJS examples, and bounded +release-tag validation moved to `gpt-5.6-sol` without expanding the supported +operation surface. The source change passed +[PR CI 30618613128](https://github.com/cometapi-dev/cometapi-node/actions/runs/30618613128), +and the action-authored release candidate passed +[CI run 30627706967 attempt 2](https://github.com/cometapi-dev/cometapi-node/actions/runs/30627706967/attempts/2). +Release Please created the immutable +[`v0.1.3` Release](https://github.com/cometapi-dev/cometapi-node/releases/tag/v0.1.3), +and +[Publish run 30628187558](https://github.com/cometapi-dev/cometapi-node/actions/runs/30628187558) +completed the tag-bound artifact and three-request live smoke, whose Chat +Completions and Responses calls used `gpt-5.6-sol`, followed by OIDC +publication, registry signature and provenance, and clean ESM/CommonJS public +installation checks. Exact evidence is recorded in +[RELEASING.md](./RELEASING.md#stable-013-release-evidence). diff --git a/RELEASING.md b/RELEASING.md index 978a916..eb0b911 100644 --- a/RELEASING.md +++ b/RELEASING.md @@ -672,6 +672,93 @@ Finally, commit-level `Release-As:` is rejected before the action because the GitHub documents that a `GITHUB_TOKEN`-created PR's opened or synchronize event [creates an approval-required workflow run](https://github.com/github/docs/blob/e1e4aa937308f21c411c248b4966873536bb0cba/data/reusables/actions/actions-do-not-trigger-workflows.md#L1-L6). +## Stable 0.1.3 release evidence + +Stable `0.1.3` completed on 2026-07-31 with these independently auditable +layers: + +- Source [PR #48](https://github.com/cometapi-dev/cometapi-node/pull/48) + updated the README, runnable ESM/CommonJS examples, mocked example fixtures, + and protected live-smoke defaults to `gpt-5.6-sol`. It also disabled reasoning + explicitly in the bounded chat and Responses requests so the 16-token cap + remained effective. Final head + `cae4c97a29221fd46aa798d93c0ed10b6e94cb7d` passed + [CI run 30618613128](https://github.com/cometapi-dev/cometapi-node/actions/runs/30618613128) + and merged as + [`3809692d35e2d9f98ba3a209947c716d8e4307b7`](https://github.com/cometapi-dev/cometapi-node/commit/3809692d35e2d9f98ba3a209947c716d8e4307b7). +- Manual Release Please preparation + [run 30627666360 attempt 1](https://github.com/cometapi-dev/cometapi-node/actions/runs/30627666360/attempts/1) + ran from that exact merge on `main` and created the action-authored release + PR below. +- The resulting four-file release + [PR #49](https://github.com/cometapi-dev/cometapi-node/pull/49) had final head + `39894513ae2534d778a0a4b8bc2a978533bec40b` and changed only the manifest, + changelog, package lock, and package manifest. After the human workflow gate, + its complete blocking matrix passed in + [CI run 30627706967 attempt 2](https://github.com/cometapi-dev/cometapi-node/actions/runs/30627706967/attempts/2). + Human repository administrator `tensornull`, distinct from bot author + `github-actions[bot]`, submitted formal + [review 4828166257](https://github.com/cometapi-dev/cometapi-node/pull/49#pullrequestreview-4828166257) + with `state=APPROVED` against that exact head before merge. The reviewed merge + produced + [`265375a088cce50d2e5980ca557404fd01028efc`](https://github.com/cometapi-dev/cometapi-node/commit/265375a088cce50d2e5980ca557404fd01028efc). +- [Release Please run 30628129319 attempt 1](https://github.com/cometapi-dev/cometapi-node/actions/runs/30628129319/attempts/1) + created the exact lightweight `v0.1.3` tag and immutable non-prerelease GitHub + Release ID `363031910`. The bot-authored + [`v0.1.3` Release](https://github.com/cometapi-dev/cometapi-node/releases/tag/v0.1.3) + targets the reviewed merge commit and was published at + `2026-07-31T11:45:32Z`. +- The unprivileged + [handoff run 30628167257 attempt 1](https://github.com/cometapi-dev/cometapi-node/actions/runs/30628167257/attempts/1) + validated the exact Release Please result and immutable Release before + dispatching the tag-bound + [Publish run 30628187558 attempt 1](https://github.com/cometapi-dev/cometapi-node/actions/runs/30628187558/attempts/1). + That run rebuilt the release commit, passed the full release checks and + public declarations/fixtures, and uploaded artifact ID `8792282959`, named + `npm-package-0.1.3-30628187558-1`, with ZIP digest + `sha256:f896a2a24ef8b6c30aac03327d022a277558c99db8c8ca2e32b3a4f7b25502f3`. + Its sole tarball has SHA-256 + `283b1dbc91f2eeb84d675da2623bc25eab4148da333f7a77b07be548b6589293` + and is byte-identical to the public registry tarball. +- The same run's + [live job 91148676643](https://github.com/cometapi-dev/cometapi-node/actions/runs/30628187558/job/91148676643) + checked out `refs/tags/v0.1.3` and passed exactly three sequential requests, + with Chat Completions and Responses using `gpt-5.6-sol`, a 16-token output + cap, 60-second per-request timeout, concurrency one, and + stop-on-first-failure behavior. +- Protected npm job + [91148760122](https://github.com/cometapi-dev/cometapi-node/actions/runs/30628187558/job/91148760122) + published through the tag-only npm Environment and GitHub Actions OIDC at + `2026-07-31T11:51:06.196Z`. Attempt 1 then completed exact artifact, + dist-tag, signature, attestation, provenance, and public-install verification + without a replay. +- At closeout, npm's stable channel resolved to `0.1.3`, while the prerelease + channel remained `0.1.0-alpha.3`. The package has SHA-1 + `e000b2066b6c19b6ff4a327ed9451dba896cc939` and integrity + `sha512-ByPYZsoLGDYZeyMZCnq99CzT3IhveylPMG8gB8bLlBSpRP8g/FdD8jrQvZMWx+4+qaVSTQp4HVHHYsU9POeFtw==`. + `npm audit signatures` verified registry signatures for all three installed + packages and attestations for two. npm exposes its publish attestation at + [Sigstore index 2300742325](https://search.sigstore.dev/?logIndex=2300742325) + and SLSA provenance at + [index 2300742191](https://search.sigstore.dev/?logIndex=2300742191). The + provenance binds `cometapi@0.1.3` to `publish.yml@refs/tags/v0.1.3`, commit + `265375a088cce50d2e5980ca557404fd01028efc`, and Publish run + `30628187558/1`. +- Independent public-registry verification downloaded the workflow artifact + and registry tarball, proved byte identity and the integrity above, installed + `cometapi@0.1.3` in clean ESM and CommonJS consumers, and resolved one + effective `openai@6.47.0` installation while preserving the public class and + official error-type boundary. +- Final readback kept `main` at the release commit, passed + [default-branch CI 30628129332](https://github.com/cometapi-dev/cometapi-node/actions/runs/30628129332), + restored `RELEASE_PLEASE_ENABLED=false`, kept `LIVE_SMOKE_ENABLED=true`, and + retained exactly one npm Environment deployment policy, `tag:v*` (policy ID + `55718965`). + +This release repeated the permanent immutable-tag path without recovery or +cross-run evidence reuse and moved the protected live validation to the same +model ID shown in the public examples. + ## Stable 0.1.2 release evidence Stable `0.1.2` completed on 2026-07-31 with these independently auditable diff --git a/ROADMAP.md b/ROADMAP.md index 4846107..bbd43eb 100644 --- a/ROADMAP.md +++ b/ROADMAP.md @@ -5,10 +5,9 @@ Last updated: 2026-07-31 Repository contract: This roadmap is self-contained and is the public source of truth for this repository's release sequence. -Stable `0.1.2` completed the public options type contract, release-neutral -consumer documentation, the first permanent immutable-tag publication, bounded -live smoke, OIDC provenance, public-install verification, and replay hardening -on 2026-07-31. +Stable `0.1.3` aligned the public examples and protected live validation on +`gpt-5.6-sol`, preserved the bounded smoke budget, and completed the immutable +tag, OIDC provenance, and public-install verification sequence on 2026-07-31. ## Product Target @@ -25,10 +24,11 @@ Release then failed before invoking npm because its publication guard rejected the fixed `actions/setup-node` authentication placeholder. `0.1.0-alpha.3` subsequently completed the OIDC, provenance, ownership, and public-install verification sequence. Stable `0.1.1` completed its separately -recorded recovery sequence on 2026-07-30, and stable `0.1.2` completed the -permanent tag-bound sequence on 2026-07-31. Stable 0.1.x packages use `latest`, -and Registry Alpha artifacts use `next`; query npm and GitHub rather than -treating this roadmap as current registry state. +recorded recovery sequence on 2026-07-30, stable `0.1.2` completed the first +permanent tag-bound sequence, and stable `0.1.3` repeated that sequence with the +updated example and live-smoke model on 2026-07-31. Stable 0.1.x packages use +`latest`, and Registry Alpha artifacts use `next`; query npm and GitHub rather +than treating this roadmap as current registry state. ## Milestones @@ -41,6 +41,7 @@ treating this roadmap as current registry state. | 0.1.0 Stable | Complete | Users can install a fully verified package from npm's default channel. | | 0.1.1 maintenance patch | Complete | Users receive the corrected options contract; the permanent tag-bound release architecture is installed and the one-time recovery is recorded. | | 0.1.2 maintenance patch | Complete | Users receive strict public option types and release-neutral package documentation through the verified permanent tag-bound publication path. | +| 0.1.3 maintenance patch | Complete | Users receive `gpt-5.6-sol` public examples backed by the same bounded model validation in the permanent tag-bound publication path. | | 0.2.0 provider-native text | Planned | Users can opt into Anthropic Messages and Gemini text adapters through isolated subpath exports. | | 0.3.0 CometAPI resources | Planned | Users receive typed access to the first stable CometAPI-specific account or platform resources. | | Media and task APIs | Later | Users receive typed image, video, audio, upload, polling, and task lifecycle helpers after their contracts are stable. | @@ -125,9 +126,11 @@ The permanent state is `RELEASE_PLEASE_ENABLED=false`, `tag:v*`. Current stable publication uses an unprivileged Release Please handoff followed by an immutable-tag dispatch, fresh verification and live smoke, and tag-bound npm OIDC. Stable `0.1.2` completed the first end-to-end -registry execution of that permanent path. Full immutable evidence is recorded -in [RELEASING.md](./RELEASING.md#stable-012-release-evidence); the earlier -one-time recovery remains separately recorded as historical evidence. +registry execution of that permanent path, and stable `0.1.3` repeated it +without a replay while aligning public and live-smoke model IDs. Full immutable +evidence for the later execution is recorded in +[RELEASING.md](./RELEASING.md#stable-013-release-evidence); the earlier one-time +recovery remains separately recorded as historical evidence. ## Private Remote Validation @@ -332,6 +335,26 @@ attempt 3 or later fails before entering the npm Environment. Release-specific PR, review, run, artifact, registry, provenance, and final-state evidence is recorded in [RELEASING.md](./RELEASING.md#stable-012-release-evidence). +## 0.1.3: Model Example and Live Validation Refresh (Complete) + +Stable `0.1.3` replaced the older model ID in the README, runnable ESM and +CommonJS examples, example documentation, and protected live-smoke defaults +with `gpt-5.6-sol`. Chat Completions now passes `reasoning_effort: "none"`, and +Responses passes `reasoning: { effort: "none" }`, so the existing 16-token +release budget remains effective. Example mocks assert the model; live-smoke +contracts assert the model and reasoning fields. This is an example and +validation update, not a new supported operation or an SDK-level default-model +contract. + +The source and action-authored release PRs passed their complete required +matrices. Release Please created the immutable tag and Release, the unprivileged +handoff dispatched one exact tag-bound Publish run, and that run rebuilt the +artifact, passed exactly three sequential requests with Chat Completions and +Responses using `gpt-5.6-sol`, published through npm OIDC, and completed +signature, provenance, and independent public-install verification without +replay. Release-specific evidence is recorded in +[RELEASING.md](./RELEASING.md#stable-013-release-evidence). + ## Stable 0.1.x Maintenance Maintenance patches close contract and release-process gaps without expanding