Skip to content

Release generic Resolvent 1.0.0 with publication and ChatGPT update email - #2

Merged
mikkokotila merged 5 commits into
mainfrom
codex/generic-plugin-release
Oct 9, 2026
Merged

mikkokotila merged 5 commits into
mainfrom
codex/generic-plugin-release

Conversation

@mikkokotila

@mikkokotila mikkokotila commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Resolvent 1.0.0 is one generic Autonomio plugin for ChatGPT/Codex and Claude. Users supply OWNER/REPOSITORY in the invoking chat; installation has no company destination, Portal dependency or standing company merge delegation. The supplied research/capture, admission, correction, independent review, CI and authorized merge workflow is retained. Publisher branding is Autonomio, website https://autonom.io, and availability is all supported countries. No canonical world-model data changes.

Release CI publishes only in autonomio/resolvent after successful validation of an exact main commit. Bundled files, packaging scripts and both directory catalogs require a version bump. Publication creates the standalone plugin-release branch and versioned GitHub ZIPs with provenance/checksums. Both host ZIPs contain identical bytes. Retries preserve provenance, changed bytes cannot reuse a version, and data-only commits create no release. AGENTS.md requires a plugin compatibility assessment for future system changes.

After the downloadable ChatGPT ZIP is available, CI emails mailme@mikkokotila.com from Resolvent <resolvent@autonom.io> with its version, download link and ChatGPT publisher portal link. The Resend key and recipient are encrypted repository Actions secrets; the sender is an Actions variable. A release journal and provider idempotency key prevent repeat notices on data-only merges or retries. An uncertain pending attempt stops before Resend's 24-hour retention window expires; provider acceptance is distinct from inbox delivery. Notification code runs outside the installed package and does not change its protocol or ZIP bytes.

Claude's directory can track plugin-release after initial setup, subject to Anthropic's review/publication settings. ChatGPT bundled changes require ZIP upload, review and publisher action; this is why CI sends an actionable email. Directory approval and hosted installation are not established by this PR. Human maintainer review is required before merge; the first merged, validated main commit activates GitHub publication and its first notification.

Two inherited defects were corrected with explicit user approval: the originating-task observer recognizes a later benign current-head approval from the same independent requesting reviewer only with all threads resolved, and credential screening recursively decodes nested JSON, including fully Unicode-escaped credentials and duplicate members. Other feedback and legacy worker receipt requirements remain enforced. The packages were regenerated from this corrected source; all original tests are retained. Release recovery verifies existing assets before uploading only missing assets from a partial publication, preserving immutable bytes.

Validation: 68 repository tests and 82 retained/extended integration tests passed through the managed validation runner, including release isolation, catalog/packager version gates, partial-upload recovery, notification retry/failure handling and inherited defect regressions. A provider-call regression verifies that Unicode-escaped credentials block the network request. Compiler/closure, reproducible skill and both host packages, version check, workflow lint, strict Claude package/catalog validation and patch whitespace all passed. No live email was sent during local verification; the notification waits for a real published release.

@bit-mis bit-mis left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Change requested in inline comments.

Comment thread scripts/plugin_release.py

@bit-mis bit-mis left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Change requested in inline comments.

Comment thread .github/workflows/plugin-release.yml Outdated
Comment thread skills/resolvent/integrations/github/overlay/.github/resolvent/controller.py Outdated
@mikkokotila

Copy link
Copy Markdown
Contributor Author

Fixed the requested changes in 8ef55e5: the version gate now includes both packaging scripts and both marketplace catalogs. Regression tests cover each previously omitted input and confirm that a versioned catalog change is published. All 64 repository tests and 76 integration tests passed, along with packaging, closure, workflow lint and Claude validation. Please re-review the fix.

@mikkokotila mikkokotila changed the title Release generic Resolvent 1.0.0 with automated plugin distribution Release generic Resolvent 1.0.0 with publication and ChatGPT update email Oct 9, 2026

@bit-mis bit-mis left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Existing unresolved inline comments still block this head.

@mikkokotila

Copy link
Copy Markdown
Contributor Author

Fixed the remaining requested changes in 88832d3 and 5e6b817:

  • Originating-task observation concludes a superseded change request only after the same independent reviewer submits a later benign approval on the exact current head and all threads are resolved. Unresolved threads, issue comments, mixed approval feedback, stale approvals and legacy worker receipt requirements still block readiness.
  • Credential checks inspect decoded strings and JSON-escaped forms, blocking quoted, backslash, newline and Unicode credentials in diagnostics and nested contribution JSON before provider transmission.
  • Partial-release recovery verifies every existing expected asset before uploading only missing assets; mismatched published bytes are rejected.

All 68 repository tests and 80 integration tests passed, along with compiler/closure, reproducible packages, version checking, workflow lint and strict Claude package/catalog validation. Both host packages were rebuilt. Please re-review the fixes.

@bit-mis bit-mis left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Change requested in inline comments.

@mikkokotila

Copy link
Copy Markdown
Contributor Author

Fixed in 4c03037: credential screening recursively decodes serialized JSON inside contribution_json, preserving duplicate object members so an overwritten value cannot hide a secret. Regression tests cover fully Unicode-escaped credentials through multiple serialization layers, including quoted, backslash and newline characters. A provider-call test verifies that the network request is never made. All 68 repository tests and 82 integration tests passed, along with package reproducibility, compiler/closure, workflow lint, version checking and Claude validation; both host packages were rebuilt. Please re-review this fix.

@mikkokotila
mikkokotila requested a review from bit-mis October 9, 2026 09:50
@mikkokotila
mikkokotila merged commit 24a2c86 into main Oct 9, 2026
2 checks passed
@mikkokotila
mikkokotila deleted the codex/generic-plugin-release branch October 9, 2026 09:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants