Prepare Patchwright 0.2.0 community release - #21
Merged
Conversation
Signed-off-by: Rafal Sikora <24563931+s1korrrr@users.noreply.github.com>
Signed-off-by: Rafal Sikora <24563931+s1korrrr@users.noreply.github.com>
s1korrrr
force-pushed
the
feat/andrzej_patchwright_org_release
branch
from
July 20, 2026 20:04
e0c06f7 to
ecbcba7
Compare
Signed-off-by: Rafal Sikora <24563931+s1korrrr@users.noreply.github.com>
s1korrrr
commented
Jul 20, 2026
s1korrrr
left a comment
Member
Author
There was a problem hiding this comment.
Reviewed exact PR head 17c0348e4b158b39b74f9cd04162bf3bd175c973 against rewritten main c77a3bdf5878bbe8e8c6f71f7980fed644046994.
Review outcome: code and packaging changes are ready; merge remains held only for the latest exact-head hosted verify job, which is currently queued without a runner.
Evidence reviewed:
- all three original PR #20 findings are closed: source-bound assembly, embedded privacy/third-party resources, and accurate changelog attribution
- Apache
LICENSEand projectNOTICEare now embedded in the signed app, published as standalone assets, and digest-bound in assembly/release manifests - expanded-archive tests compare both legal files byte-for-byte and verify the archive checksum plus deep code signature
- focused community and release contracts pass
- a real
build_release_components.sh --communityassembly passes with exact legal-file comparisons, assembly-wide SHA-256 verification, and deep signature verification - the previous exact revision passed full local verification, 65 Swift tests, smoke/runtime launch, and hosted CI; the new seven-file delta has focused and real-assembly proof
- v0.1.0 release evidence and its restored tag both resolve to
eaee7f7336e0642afdf89301ec426154129b7fed; the live Sparkle appcast remains available - rewritten v0.1.1 and all new commit/tag metadata use
24563931+s1korrrr@users.noreply.github.com
The v0.1.0 release is intentionally retained because it is the active signed Sparkle feed provider. Its evidence-bound legacy commit is the one explicit history-rewrite exception.
No Codex Security scan was run for this release review, per scope.
s1korrrr
added a commit
that referenced
this pull request
Jul 20, 2026
Consolidate the production-ready open-source release under RSI Tech, bind the community package to a clean tagged source checkout, embed required legal and privacy resources, and publish exact release-evidence contracts. Signed-off-by: Rafal Sikora <24563931+s1korrrr@users.noreply.github.com>
Member
Author
|
Final release reconciliation:
Release: https://github.com/rsitech-ai/patchwright/releases/tag/v0.2.0-community.1 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Outcome
Prepare Patchwright 0.2.0 for an RSI Tech community prerelease while preserving the stricter Developer ID/notarized distribution lane.
What changed
rsitech-ai/patchwrightrsitech.aiandinfo@rsitech.aias project contactsValidation
./script/verify.shbash Tests/PackagingTests/community_release_contract.shbash Tests/PackagingTests/compliance_contract.shgit diff --checkgit fsck --full --no-reflogs --unreachableNo Codex Security scan was run, per the requested scope.
Distribution boundary
The community artifact is ad-hoc signed and explicitly not Apple notarized. It is a prerelease for source-aligned evaluation and does not satisfy the Developer ID, notarization, clean-machine, or independent-promotion gates for an official direct-download release.