diff --git a/AGENTS.md b/AGENTS.md index e0615ff..85af3c5 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -234,6 +234,9 @@ committed. - Manual or arbitrary-branch publication is forbidden. - A successful build or upload is not a release. Registry installation, import, mocked-call smoke, and provenance must be verified separately. +- Every distribution `Project-URL` must use HTTPS. The canonical Support URL + is `https://github.com/cometapi-dev/cometapi-python/blob/main/SUPPORT.md`; + `support@cometapi.com` remains the support and conduct contact. - Keep third-party Actions pinned to full commit SHAs and grant `id-token: write` only to the publishing job. - Keep README, roadmap, compatibility matrix, examples, and changelog aligned diff --git a/ARCHITECTURE.md b/ARCHITECTURE.md index c7886ac..d39df4d 100644 --- a/ARCHITECTURE.md +++ b/ARCHITECTURE.md @@ -76,6 +76,11 @@ separate `resources/` and `types/` packages. Provider-native adapters belong to a later milestone and use the official provider SDKs as optional dependencies. Empty placeholders are not part of 0.1. +Distribution `Project-URL` metadata uses HTTPS for every entry so registries +can validate and render it consistently. The Support entry links to the public +`SUPPORT.md` document; `support@cometapi.com` remains the support and conduct +contact published inside that document. + ## Dependency policy The installable OpenAI range is `openai>=2.45.0,<3.0.0`. End users resolve diff --git a/CHANGELOG.md b/CHANGELOG.md index 1bcc246..0b1d37f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -37,6 +37,8 @@ No user-visible changes are currently recorded beyond the initial alpha scope. language, and standalone content. - Scheduled live smoke requires the explicit repository opt-in, and release live smoke defaults an unset or empty model setting to `gpt-5.4`. +- Distribution metadata now exposes Support as an HTTPS link to `SUPPORT.md`; + release checks reject non-HTTPS canonical project URLs. ### Removed diff --git a/RELEASING.md b/RELEASING.md index bc18d0b..8fa75e6 100644 --- a/RELEASING.md +++ b/RELEASING.md @@ -94,6 +94,11 @@ exact artifact must be installed independently outside the source tree; the check must assert installed metadata, public exports, absence of legacy aliases, and an offline mocked call. +Every canonical `[project.urls]` value must use HTTPS. In particular, Support +must resolve to +`https://github.com/cometapi-dev/cometapi-python/blob/main/SUPPORT.md`; the +email address in that document remains the canonical support contact. + Record every command, outcome, skipped check, and unavailable tool in the verification record. diff --git a/ROADMAP.md b/ROADMAP.md index ba47964..2dd392b 100644 --- a/ROADMAP.md +++ b/ROADMAP.md @@ -41,8 +41,9 @@ Deliverables: - Standalone documentation, MIT licensing, contribution and conduct guidance, security and support policies, architecture, release guide, changelog, compatibility matrix, and issue and pull-request templates. -- Normalized package metadata, a reproducible development lock, Ruff, Pyright, - pytest, metadata, artifact, clean-install, secret, and version checks. +- Normalized package metadata with HTTPS-only project URLs and a public support + document link, a reproducible development lock, Ruff, Pyright, pytest, + metadata, artifact, clean-install, secret, and version checks. - Offline CI, trusted live-smoke definition, release-PR automation, OIDC publishing definition, and dependency update automation. - A repository-independence gate that copies the candidate into an empty diff --git a/pyproject.toml b/pyproject.toml index 61969af..47eb762 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -27,7 +27,7 @@ Homepage = "https://www.cometapi.com" Documentation = "https://apidoc.cometapi.com/" Repository = "https://github.com/cometapi-dev/cometapi-python" Issues = "https://github.com/cometapi-dev/cometapi-python/issues" -Support = "mailto:support@cometapi.com" +Support = "https://github.com/cometapi-dev/cometapi-python/blob/main/SUPPORT.md" Security = "https://github.com/cometapi-dev/cometapi-python/security/advisories/new" [dependency-groups] diff --git a/scripts/_checks.py b/scripts/_checks.py index 74b9758..f3ac86a 100644 --- a/scripts/_checks.py +++ b/scripts/_checks.py @@ -28,7 +28,7 @@ "Documentation": "https://apidoc.cometapi.com/", "Repository": CANONICAL_REPOSITORY, "Issues": f"{CANONICAL_REPOSITORY}/issues", - "Support": f"mailto:{CANONICAL_SUPPORT}", + "Support": f"{CANONICAL_REPOSITORY}/blob/main/SUPPORT.md", "Security": CANONICAL_SECURITY, } diff --git a/scripts/check_version.py b/scripts/check_version.py index b406376..5c7a986 100644 --- a/scripts/check_version.py +++ b/scripts/check_version.py @@ -132,6 +132,9 @@ def _check_project_identity(violations: list[str]) -> None: urls = project.get("urls") url_values = cast(dict[str, object], urls) if isinstance(urls, dict) else {} for label, expected in CANONICAL_PROJECT_URLS.items(): + parsed = urlsplit(expected) + if parsed.scheme != "https" or not parsed.netloc: + violations.append(f"canonical Project-URL {label} must use HTTPS: {expected!r}") actual = url_values.get(label) if actual != expected: violations.append(f"pyproject.toml: [project.urls].{label} must equal {expected!r}") diff --git a/tests/test_release_documents.py b/tests/test_release_documents.py index 08b7213..5a1d2b0 100644 --- a/tests/test_release_documents.py +++ b/tests/test_release_documents.py @@ -121,6 +121,16 @@ def test_public_preview_documents_accept_durable_public_content( require_public_preview_docs() +def test_public_preview_documents_reject_non_https_canonical_project_url( + releasable_documents: Path, + monkeypatch: pytest.MonkeyPatch, +) -> None: + monkeypatch.setitem(CANONICAL_PROJECT_URLS, "Support", f"mailto:{CANONICAL_SUPPORT}") + + with pytest.raises(CheckError, match="canonical Project-URL Support must use HTTPS"): + require_public_preview_docs() + + def test_public_preview_documents_reject_codeowners(releasable_documents: Path) -> None: codeowners = releasable_documents / ".github/CODEOWNERS" codeowners.parent.mkdir(parents=True, exist_ok=True)