Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 16 additions & 0 deletions COMPATIBILITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -167,3 +167,19 @@ smoke, OIDC publication, public-registry ESM/CommonJS and declaration checks,
single effective OpenAI installation, official error identity, integrity,
signature, and provenance evidence is recorded in
[RELEASING.md](./RELEASING.md#stable-012-release-evidence).

For stable `0.1.3`, the README, runnable ESM/CommonJS examples, and bounded
release-tag validation moved to `gpt-5.6-sol` without expanding the supported
operation surface. The source change passed
[PR CI 30618613128](https://github.com/cometapi-dev/cometapi-node/actions/runs/30618613128),
and the action-authored release candidate passed
[CI run 30627706967 attempt 2](https://github.com/cometapi-dev/cometapi-node/actions/runs/30627706967/attempts/2).
Release Please created the immutable
[`v0.1.3` Release](https://github.com/cometapi-dev/cometapi-node/releases/tag/v0.1.3),
and
[Publish run 30628187558](https://github.com/cometapi-dev/cometapi-node/actions/runs/30628187558)
completed the tag-bound artifact and three-request live smoke, whose Chat
Completions and Responses calls used `gpt-5.6-sol`, followed by OIDC
publication, registry signature and provenance, and clean ESM/CommonJS public
installation checks. Exact evidence is recorded in
[RELEASING.md](./RELEASING.md#stable-013-release-evidence).
87 changes: 87 additions & 0 deletions RELEASING.md
Original file line number Diff line number Diff line change
Expand Up @@ -672,6 +672,93 @@ Finally, commit-level `Release-As:` is rejected before the action because the
GitHub documents that a `GITHUB_TOKEN`-created PR's opened or synchronize event
[creates an approval-required workflow run](https://github.com/github/docs/blob/e1e4aa937308f21c411c248b4966873536bb0cba/data/reusables/actions/actions-do-not-trigger-workflows.md#L1-L6).

## Stable 0.1.3 release evidence

Stable `0.1.3` completed on 2026-07-31 with these independently auditable
layers:

- Source [PR #48](https://github.com/cometapi-dev/cometapi-node/pull/48)
updated the README, runnable ESM/CommonJS examples, mocked example fixtures,
and protected live-smoke defaults to `gpt-5.6-sol`. It also disabled reasoning
explicitly in the bounded chat and Responses requests so the 16-token cap
remained effective. Final head
`cae4c97a29221fd46aa798d93c0ed10b6e94cb7d` passed
[CI run 30618613128](https://github.com/cometapi-dev/cometapi-node/actions/runs/30618613128)
and merged as
[`3809692d35e2d9f98ba3a209947c716d8e4307b7`](https://github.com/cometapi-dev/cometapi-node/commit/3809692d35e2d9f98ba3a209947c716d8e4307b7).
- Manual Release Please preparation
[run 30627666360 attempt 1](https://github.com/cometapi-dev/cometapi-node/actions/runs/30627666360/attempts/1)
ran from that exact merge on `main` and created the action-authored release
PR below.
- The resulting four-file release
[PR #49](https://github.com/cometapi-dev/cometapi-node/pull/49) had final head
`39894513ae2534d778a0a4b8bc2a978533bec40b` and changed only the manifest,
changelog, package lock, and package manifest. After the human workflow gate,
its complete blocking matrix passed in
[CI run 30627706967 attempt 2](https://github.com/cometapi-dev/cometapi-node/actions/runs/30627706967/attempts/2).
Human repository administrator `tensornull`, distinct from bot author
`github-actions[bot]`, submitted formal
[review 4828166257](https://github.com/cometapi-dev/cometapi-node/pull/49#pullrequestreview-4828166257)
with `state=APPROVED` against that exact head before merge. The reviewed merge
produced
[`265375a088cce50d2e5980ca557404fd01028efc`](https://github.com/cometapi-dev/cometapi-node/commit/265375a088cce50d2e5980ca557404fd01028efc).
- [Release Please run 30628129319 attempt 1](https://github.com/cometapi-dev/cometapi-node/actions/runs/30628129319/attempts/1)
created the exact lightweight `v0.1.3` tag and immutable non-prerelease GitHub
Release ID `363031910`. The bot-authored
[`v0.1.3` Release](https://github.com/cometapi-dev/cometapi-node/releases/tag/v0.1.3)
targets the reviewed merge commit and was published at
`2026-07-31T11:45:32Z`.
- The unprivileged
[handoff run 30628167257 attempt 1](https://github.com/cometapi-dev/cometapi-node/actions/runs/30628167257/attempts/1)
validated the exact Release Please result and immutable Release before
dispatching the tag-bound
[Publish run 30628187558 attempt 1](https://github.com/cometapi-dev/cometapi-node/actions/runs/30628187558/attempts/1).
That run rebuilt the release commit, passed the full release checks and
public declarations/fixtures, and uploaded artifact ID `8792282959`, named
`npm-package-0.1.3-30628187558-1`, with ZIP digest
`sha256:f896a2a24ef8b6c30aac03327d022a277558c99db8c8ca2e32b3a4f7b25502f3`.
Its sole tarball has SHA-256
`283b1dbc91f2eeb84d675da2623bc25eab4148da333f7a77b07be548b6589293`
and is byte-identical to the public registry tarball.
- The same run's
[live job 91148676643](https://github.com/cometapi-dev/cometapi-node/actions/runs/30628187558/job/91148676643)
checked out `refs/tags/v0.1.3` and passed exactly three sequential requests,
with Chat Completions and Responses using `gpt-5.6-sol`, a 16-token output
cap, 60-second per-request timeout, concurrency one, and
stop-on-first-failure behavior.
- Protected npm job
[91148760122](https://github.com/cometapi-dev/cometapi-node/actions/runs/30628187558/job/91148760122)
published through the tag-only npm Environment and GitHub Actions OIDC at
`2026-07-31T11:51:06.196Z`. Attempt 1 then completed exact artifact,
dist-tag, signature, attestation, provenance, and public-install verification
without a replay.
- At closeout, npm's stable channel resolved to `0.1.3`, while the prerelease
channel remained `0.1.0-alpha.3`. The package has SHA-1
`e000b2066b6c19b6ff4a327ed9451dba896cc939` and integrity
`sha512-ByPYZsoLGDYZeyMZCnq99CzT3IhveylPMG8gB8bLlBSpRP8g/FdD8jrQvZMWx+4+qaVSTQp4HVHHYsU9POeFtw==`.
`npm audit signatures` verified registry signatures for all three installed
packages and attestations for two. npm exposes its publish attestation at
[Sigstore index 2300742325](https://search.sigstore.dev/?logIndex=2300742325)
and SLSA provenance at
[index 2300742191](https://search.sigstore.dev/?logIndex=2300742191). The
provenance binds `cometapi@0.1.3` to `publish.yml@refs/tags/v0.1.3`, commit
`265375a088cce50d2e5980ca557404fd01028efc`, and Publish run
`30628187558/1`.
- Independent public-registry verification downloaded the workflow artifact
and registry tarball, proved byte identity and the integrity above, installed
`cometapi@0.1.3` in clean ESM and CommonJS consumers, and resolved one
effective `openai@6.47.0` installation while preserving the public class and
official error-type boundary.
- Final readback kept `main` at the release commit, passed
[default-branch CI 30628129332](https://github.com/cometapi-dev/cometapi-node/actions/runs/30628129332),
restored `RELEASE_PLEASE_ENABLED=false`, kept `LIVE_SMOKE_ENABLED=true`, and
retained exactly one npm Environment deployment policy, `tag:v*` (policy ID
`55718965`).

This release repeated the permanent immutable-tag path without recovery or
cross-run evidence reuse and moved the protected live validation to the same
model ID shown in the public examples.

## Stable 0.1.2 release evidence

Stable `0.1.2` completed on 2026-07-31 with these independently auditable
Expand Down
45 changes: 34 additions & 11 deletions ROADMAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,10 +5,9 @@ Last updated: 2026-07-31
Repository contract: This roadmap is self-contained and is the public source
of truth for this repository's release sequence.

Stable `0.1.2` completed the public options type contract, release-neutral
consumer documentation, the first permanent immutable-tag publication, bounded
live smoke, OIDC provenance, public-install verification, and replay hardening
on 2026-07-31.
Stable `0.1.3` aligned the public examples and protected live validation on
`gpt-5.6-sol`, preserved the bounded smoke budget, and completed the immutable
tag, OIDC provenance, and public-install verification sequence on 2026-07-31.

## Product Target

Expand All @@ -25,10 +24,11 @@ Release then failed before invoking npm because its publication guard rejected
the fixed `actions/setup-node` authentication placeholder.
`0.1.0-alpha.3` subsequently completed the OIDC, provenance, ownership, and
public-install verification sequence. Stable `0.1.1` completed its separately
recorded recovery sequence on 2026-07-30, and stable `0.1.2` completed the
permanent tag-bound sequence on 2026-07-31. Stable 0.1.x packages use `latest`,
and Registry Alpha artifacts use `next`; query npm and GitHub rather than
treating this roadmap as current registry state.
recorded recovery sequence on 2026-07-30, stable `0.1.2` completed the first
permanent tag-bound sequence, and stable `0.1.3` repeated that sequence with the
updated example and live-smoke model on 2026-07-31. Stable 0.1.x packages use
`latest`, and Registry Alpha artifacts use `next`; query npm and GitHub rather
than treating this roadmap as current registry state.

## Milestones

Expand All @@ -41,6 +41,7 @@ treating this roadmap as current registry state.
| 0.1.0 Stable | Complete | Users can install a fully verified package from npm's default channel. |
| 0.1.1 maintenance patch | Complete | Users receive the corrected options contract; the permanent tag-bound release architecture is installed and the one-time recovery is recorded. |
| 0.1.2 maintenance patch | Complete | Users receive strict public option types and release-neutral package documentation through the verified permanent tag-bound publication path. |
| 0.1.3 maintenance patch | Complete | Users receive `gpt-5.6-sol` public examples backed by the same bounded model validation in the permanent tag-bound publication path. |
| 0.2.0 provider-native text | Planned | Users can opt into Anthropic Messages and Gemini text adapters through isolated subpath exports. |
| 0.3.0 CometAPI resources | Planned | Users receive typed access to the first stable CometAPI-specific account or platform resources. |
| Media and task APIs | Later | Users receive typed image, video, audio, upload, polling, and task lifecycle helpers after their contracts are stable. |
Expand Down Expand Up @@ -125,9 +126,11 @@ The permanent state is `RELEASE_PLEASE_ENABLED=false`,
`tag:v*`. Current stable publication uses an unprivileged Release Please
handoff followed by an immutable-tag dispatch, fresh verification and live
smoke, and tag-bound npm OIDC. Stable `0.1.2` completed the first end-to-end
registry execution of that permanent path. Full immutable evidence is recorded
in [RELEASING.md](./RELEASING.md#stable-012-release-evidence); the earlier
one-time recovery remains separately recorded as historical evidence.
registry execution of that permanent path, and stable `0.1.3` repeated it
without a replay while aligning public and live-smoke model IDs. Full immutable
evidence for the later execution is recorded in
[RELEASING.md](./RELEASING.md#stable-013-release-evidence); the earlier one-time
recovery remains separately recorded as historical evidence.

## Private Remote Validation

Expand Down Expand Up @@ -332,6 +335,26 @@ attempt 3 or later fails before entering the npm Environment. Release-specific
PR, review, run, artifact, registry, provenance, and final-state evidence is
recorded in [RELEASING.md](./RELEASING.md#stable-012-release-evidence).

## 0.1.3: Model Example and Live Validation Refresh (Complete)

Stable `0.1.3` replaced the older model ID in the README, runnable ESM and
CommonJS examples, example documentation, and protected live-smoke defaults
with `gpt-5.6-sol`. Chat Completions now passes `reasoning_effort: "none"`, and
Responses passes `reasoning: { effort: "none" }`, so the existing 16-token
release budget remains effective. Example mocks assert the model; live-smoke
contracts assert the model and reasoning fields. This is an example and
validation update, not a new supported operation or an SDK-level default-model
contract.

The source and action-authored release PRs passed their complete required
matrices. Release Please created the immutable tag and Release, the unprivileged
handoff dispatched one exact tag-bound Publish run, and that run rebuilt the
artifact, passed exactly three sequential requests with Chat Completions and
Responses using `gpt-5.6-sol`, published through npm OIDC, and completed
signature, provenance, and independent public-install verification without
replay. Release-specific evidence is recorded in
[RELEASING.md](./RELEASING.md#stable-013-release-evidence).

## Stable 0.1.x Maintenance

Maintenance patches close contract and release-process gaps without expanding
Expand Down