Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
62 changes: 27 additions & 35 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,22 +6,22 @@ Python SDK repository. Treat this directory as the repository root.
## Repository authority

Repository-local source, tests, documentation, metadata, fixtures, and workflow
definitions may be changed and verified locally. The current milestone may also
create the empty private canonical repository, initialize and push its sanitized
history, and observe credential-free GitHub Actions only when a maintainer has
explicitly authorized those remote actions. Changing repository visibility,
configuring secrets or environments, making live API requests, creating tags or
releases, publishing to PyPI, and changing registry settings remain outside the
current milestone.
definitions may be changed and verified locally. The current milestone may use
private pull requests and credential-free GitHub Actions to complete the
remaining pre-visibility work. Changing repository visibility, configuring
secrets or environments, making live API requests, creating tags or releases,
publishing to PyPI, and changing registry settings remain outside the current
authorized pre-visibility scope.

A local build, mocked test, statically valid workflow, or private remote CI run
proves only its own evidence layer. Never invent or mock missing evidence.

## Current milestone: Private Remote Validation
## Current milestone: Public Preview

Complete Private Remote Validation and stop before changing repository
visibility. A session starting in this repository must be able to finish this
milestone without instructions outside the repository.
Private Remote Validation is complete. Prepare the private canonical repository
for a future explicitly authorized visibility change, and stop before changing
visibility. A session starting in this repository must be able to finish the
remaining pre-visibility work without instructions outside the repository.

The accepted identity is:

Expand All @@ -37,30 +37,22 @@ The accepted identity is:
| Support and conduct | `support@cometapi.com` |
| Security | `https://github.com/cometapi-dev/cometapi-python/security/advisories/new` |

Before the first remote push:

1. Apply the accepted identity to package metadata and public documents.
2. Remove `.github/CODEOWNERS` and every check, fixture, test, or document that
requires it. Do not replace it with an individual owner.
3. Refactor the Public Preview document gate to collect and report all
violations in one run while returning non-zero if any violation exists.
Keep checks for canonical identity, contacts, repository metadata, public-
safe language, and standalone content.
4. Gate scheduled and manually dispatched live smoke with a
`LIVE_SMOKE_ENABLED` repository variable. An unset or non-true value must
prevent live execution. Keep
`RELEASE_PLEASE_ENABLED` disabled through the initial manual alpha.
5. Make the release live-model setting use `gpt-5.4` when
`COMETAPI_LIVE_MODEL` is unset or empty; never allow an empty model value.
6. Run every local offline, package, self-containment, public-content, secret,
and workflow-static-validation gate.

When authorized, create an empty private repository without generated files,
make the sanitized repository content its first commit, push the default
branch, and wait for credential-free CI. Do not configure branch or tag rules,
Private Vulnerability Reporting, secrets, protected environments, Trusted
Publishing, or live smoke during the private stage. Record the real CI result
and stop before any visibility change, even when all checks pass.
Before changing repository visibility:

1. Resolve or explicitly defer every open dependency pull request that is not
ready to merge. Dependabot PR #2 must not merge while its credential-free CI
is failing; record its disposition in `ROADMAP.md`.
2. Keep `.github/CODEOWNERS` absent until a real multi-maintainer model exists.
3. Keep scheduled and manually dispatched live smoke fail-closed behind
`LIVE_SMOKE_ENABLED=true`, and keep `RELEASE_PLEASE_ENABLED` disabled through
the initial manual alpha.
4. Run every local offline, package, self-containment, public-content, secret,
and workflow-static-validation gate, then deliver the pre-visibility changes
through a private pull request with successful credential-free CI.
5. Confirm the canonical repository is still private and stop. Visibility,
branch or tag rules, Private Vulnerability Reporting, secrets, protected
environments, Trusted Publishing, live API calls, tags, releases, and
publication require separate authorization after this stop point.

## Repository independence

Expand Down
31 changes: 25 additions & 6 deletions ROADMAP.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# CometAPI Python SDK Roadmap

Status: `0.1.0a1` in progress
Last updated: 2026-07-21
Last updated: 2026-07-22
Repository contract: this roadmap is self-contained.

## Product target
Expand All @@ -11,18 +11,18 @@ to CometAPI while preserving official request, response, error, retry, timeout,
sync, async, and streaming behavior.

Private Remote Validation is complete for the sanitized repository, which
remains private. Work stops before any visibility change. Public Preview and
the functional `0.1.0a1` prerelease remain separate evidence gates. Support
and release claims remain limited to the evidence defined in this roadmap and
`COMPATIBILITY.md`.
remains private. The current pre-visibility phase stops before any visibility
change. Public Preview and the functional `0.1.0a1` prerelease remain separate
evidence gates. Support and release claims remain limited to the evidence
defined in this roadmap and `COMPATIBILITY.md`.

## Milestones

| Milestone | Status | Exit outcome |
| --- | --- | --- |
| Repository foundation | Complete | Public files, offline gates, packaging checks, and self-containment are complete. |
| Private Remote Validation | Complete | The sanitized private repository passes real credential-free default-branch CI; public-only controls and live tests remain disabled. |
| Public Preview | Planned | The public repository has blocking CI, repository rules, security reporting, protected environments, and authorized live-smoke evidence before it claims preview readiness. |
| Public Preview | In progress | Pre-visibility work is delivered through private pull requests; after an authorized visibility change, the public repository must establish blocking CI, repository rules, security reporting, protected environments, and authorized live-smoke evidence before it claims preview readiness. |
| `0.1.0a1` Registry Alpha | Planned | Early adopters can install a functional prerelease from PyPI. |
| `0.1.0` stable | Planned | Complete runtime, release-PR, example, provenance, and registry gates pass. |
| `0.2.0` provider-native text | Planned | Optional official Anthropic and Gemini adapters. |
Expand Down Expand Up @@ -97,6 +97,25 @@ Recorded evidence on 2026-07-21:

## Public Preview

Public Preview is in progress at the pre-visibility stage. Before requesting a
visibility change:

- Deliver all remaining documentation and workflow changes through private pull
requests with credential-free CI.
- Review every open dependency pull request. Fix and merge only updates with
complete successful CI; otherwise record an explicit deferral and keep the PR
out of `main`.
- Rerun the complete local gate and private pull-request CI, confirm the
canonical repository remains private, and stop for explicit visibility-change
authorization. Do not configure public-only controls, secrets, environments,
live smoke, releases, or publication before that stop point.

Pre-visibility dependency disposition:

| Item | Disposition | Evidence and required action |
| --- | --- | --- |
| Dependabot [PR #2](https://github.com/cometapi-dev/cometapi-python/pull/2): `actions/checkout` 4.2.2 to 7.0.1 | Deferred; must not merge as-is | Credential-free [CI run 29796719306](https://github.com/cometapi-dev/cometapi-python/actions/runs/29796719306) failed in every test lane because the mutable-action-reference regression test hard-codes the previous v4 checkout SHA and no longer exercises its replacement; dependent artifact and copied-checkout jobs were skipped. Revisit only with version-independent regression coverage and a completely successful replacement CI run. The failed run is not upgrade evidence. |

Changing the repository to public begins a short configuration interval; it
does not establish Public Preview readiness by itself. The preview is ready
only when:
Expand Down
Loading