Dependency installs and CI jobs both executed code this repo never
reviewed. This closes those paths without changing what anything
resolves to.
pnpm 9 ran every dependency's install lifecycle script and had no
allow-list model, so CI executed install hooks from the whole tree on
every PR. pnpm 10.34.5 blocks them by default and carries the fix for
the fail-open integrity check in CVE-2026-50021. minimumReleaseAge holds
freshly published versions out of resolution for 48 hours, the window in
which a registry compromise is typically caught and yanked.
The two `*` peer ranges in reactor-cli were the only place the workspace
opted out of range discipline: any future major satisfied them, including
a hijacked one. Both now carry carets on the versions already resolved,
and the README install lines are pinned to match, since a 0.x caret does
not cross the minor line.
Third-party actions take the commit SHA their movable tags resolved to,
with a monthly grouped Dependabot entry so those pins do not go stale.
GitHub-maintained actions stay on tags as a stated trust decision rather
than a claim that pinning them would buy nothing.
The benchmark jobs needed the most work, since they run an external
repository's code with five LLM provider keys in scope. Dispatch inputs
now travel through the step environment as quoted variables instead of
being interpolated into shell. The pi version is hardcoded rather than
dispatchable: npm accepts package sources after the `@` — an alias, a
repository, a tarball URL — so an input in that position chose a package
rather than a version. The remaining ref override is documented as an
operator escape hatch whose clone target is fixed.
The publish job holds a credential that can publish under our name and
installed npm at latest before using it. It now pins an exact version
above the floor OIDC trusted publishing requires, and fails at that step
if the pin does not take.
CI also fails on a tampered or unsigned tarball now, checked per
publishable package rather than once at the root where npm would only
see dev tooling. The advisory audit runs alongside it as a signal, not a
gate.
Nothing re-resolves: no version or integrity line in the lockfile moves.
The smoke fixtures still exercised the retired pre-0.15 model: service
and system kinds, '### Ensures' contracts, and a harness that asked for
forme.manifest.json and checked every output under bindings/. The
execution docs now treat retired kinds as never-executable upgrade
input, which turned the kind-test case into a standing contradiction:
its subject resolved to a kind: service file the harness required to
execute. That contradiction fits kind-test's history as the suite's one
chronically flaky case.
Rewrite every fixture in current kinds while preserving what each case
smokes: functions for single render, caller input, execution block,
errors and strategies, and local pattern instantiation (standalone runs
publish '### Returns' under bindings/ via copy-on-return);
responsibility multi-node files for the wiring cases, with a deliberate
fan-in reconvergence replacing the retired '### Wiring' case; kind: test
now runs a function subject and asserts against its published bindings.
Align the harness with the current artifact layout: mounted runs
snapshot compiled-intent.json, publish node truth under world-model/,
and append receipts; a per-case outputRoot field selects world-model or
bindings for output checks. Give the test command a 40-turn budget,
since it reads the test file, resolves the subject, executes it, and
evaluates assertions in one session. Case ids and filenames are
unchanged, so required check names stay stable.
Ships @openprose/reactor 0.3.0, @openprose/reactor-cli 0.2.0, @openprose/reactor-devtools 0.2.0: the Reactor harness (compile-once-intelligent then dumb reconciler, content-addressed receipts, cost scales with surprise) with the distilled ideal public API — curated front door, full @openai/agents passthrough, one typed handle, one Substrate, unified observe, branded ids, and additive forward seams for the fixpoint.
Prepare the Reactor packages for the interim 0.1.0-rc.2 release.
Narrow the package publish workflow to reactor-v* tags, bump Reactor and Cradle package versions, refresh the Cradle package pin for the rc.2 tarball, and update release-candidate evidence helpers and package docs.
* feat(spec): declared ### Skills section with fail-closed compile resolution
Implements the spec from issue #60. Components declare required harness
skills via a `### Skills` section (colon form, e.g. `document-skills:pdf`).
`prose compile` resolves declared skills against ./skills/, ~/.claude/skills/,
~/.codex/skills/, and ~/.agents/skills/, and fails closed with
`skill_unresolved` before forwarding to the agent harness when any are
missing.
- Spec: skills/open-prose/contract-markdown.md gains a ### Skills row in
the Canonical Sections table and a ## Skills H2 covering colon naming,
search order, the BYO-harness invariant, and fail-closed semantics.
- Implementation: tools/cli/src/skills/declared.ts (parser + resolver +
directory walker + DeclaredSkillsUnresolvedError). Pure functions; no
I/O beyond readFile / readdir / stat.
- Wiring: tools/cli/src/commands/compile.ts pre-checks declared skills
before forwarding the compile prompt; fails closed with
CompileValidationError when any are unresolved. Gated behind the
existing skillPreflight option for test parity.
- Example: skills/open-prose/examples/declared-skills/ shows the
document-skills:pdf canonical pattern.
- Tests: 19 new (18 in declared.test.ts covering parser/resolver/walker/
error formatter; 1 in cli.test.ts asserting compile fails closed before
the harness is invoked when a declared skill is missing).
- BYO harness: OpenProse never installs harness skills; resolution failure
is the user's signal to install the named skill themselves.
Resolves#60.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* feat(spec): move skill resolution into compiler program; trim spec per review
Address review feedback on #62:
- contract-markdown.md: drop the "not duplicated in frontmatter" clause —
the rejected alternative shouldn't propagate into the spec.
- contract-markdown.md: fail-closed clause now mentions only `prose compile`;
`prose run` enforcement is deferred per the PR description.
- compiler/index.prose.md: add a `skills_resolver` agent that owns the
search-path order, scope aggregation, BYO invariant, and fail-closed
semantics. Skill resolution is now a compiler/program-level
responsibility, not a harness responsibility, so other harnesses running
the compiler get the same behavior.
- skills/declared.ts: add a header comment pointing at the program-level
spec; this module is the harness implementation of `skills_resolver`.
- examples/declared-skills/README.md: update wording to reference the
compiler agent.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* fix(ci): make smoke artifacts case-specific
* fix(ci): use deterministic audit policy
---------
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
OpenProse already installed as a Claude Code plugin via
`npx skills add openprose/prose`, but the packaging surface was
uneven: missing manifest fields, no native Codex envelope, no
plugin-track release process, and a couple of doc/audience
inconsistencies. This commit closes those gaps without changing
skill behavior.
OpenProse now ships from the repo root as a dual-host plugin
envelope — `.claude-plugin/` for Claude Code, `.codex-plugin/`
plus `.agents/plugins/` for Codex — with `skills/open-prose/`
as the shared core and `prose ...` as the only user-facing
command surface.
Codex envelope:
- .codex-plugin/plugin.json with first-class catalog metadata
(displayName, developer, descriptions, category, capabilities,
defaultPrompt, privacy/terms URLs).
- .agents/plugins/marketplace.json local-source catalog, installable
by anyone who clones this repo.
Claude Code manifest hygiene:
- Added license, homepage, and skills: ./skills so the plugin is
self-describing.
- Added marketplace.json metadata.description, clearing the sole
`claude plugin validate` warning.
- Deleted the stale .claude-plugin/README.md.
Skill metadata:
- Added license: MIT to skills/open-prose/SKILL.md frontmatter
(no top-level version — Claude Code strips unrecognized top-level
frontmatter keys; see anthropics/claude-code#13005).
- Fixed an inconsistent parse-table cell pair in
skills/open-prose/deps.md.
Audience boundaries:
- AGENTS.md is now contributor-only per agents.md.
- Recommended consumer [agents] Codex config moved to README.md
alongside the Quickstart.
Release process:
- scripts/bump-version.sh + .version-bump.json bump both manifests
atomically, with a --check mode for CI. The Claude Code
marketplace deduplicates by version, so a forgotten bump silently
strands users on cached copies; this gate prevents that.
- scripts/extract-changelog.sh pulls a single `## [X.Y.Z]` block
out of CHANGELOG.md.
- RELEASE.md documents the manual flow.
- .github/workflows/release.yml verifies declared versions match
on `v*` tag push and publishes a GitHub Release.
CI:
- New plugin-manifest.yml: every-PR gate validating both plugin.json
files, asserting declared skills paths resolve, and running
bump-version.sh --check.
- cli-skills-smoke.yml: added `npx skills list openprose/prose`
discoverability check alongside the existing install smoke.
- openprose-smoke/run.ts: removed a dead commands/prose-*.md regex.
Add a required smoke CI path for the `open-prose` skill.
- Add focused smoke fixtures for core OpenProse execution behavior.
- Add a TypeScript runner that installs the PR skill into isolated workspaces and validates `.prose/runs/` outputs.
- Add a GitHub Actions workflow with read-only permissions, fork safety, pinned tooling, artifact capture, and hardened Claude Code invocation.
- Validate the suite with both dry-run checks and a local live `9/9` smoke run.
workflow_dispatch action that runs the LongCoT benchmark using
pi-mono (@mariozechner/pi-coding-agent) as the inference harness.
Defaults (difficulty=longcot, thinking=high, no tools/scaffolding,
2 retries) mirror the paper for 1:1 result comparison; README
covers iteration with longcot-mini + slice inputs.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>