Skip to content

Prepare Patchwright 0.2.0 community release - #21

Merged
s1korrrr merged 3 commits into
mainfrom
feat/andrzej_patchwright_org_release
Jul 20, 2026
Merged

Prepare Patchwright 0.2.0 community release#21
s1korrrr merged 3 commits into
mainfrom
feat/andrzej_patchwright_org_release

Conversation

@s1korrrr

Copy link
Copy Markdown
Member

Outcome

Prepare Patchwright 0.2.0 for an RSI Tech community prerelease while preserving the stricter Developer ID/notarized distribution lane.

What changed

  • move canonical repository and release metadata to rsitech-ai/patchwright
  • adopt Apache-2.0 as the sole project license with Rafal Sikora as copyright owner and RSI Tech as maintainer
  • publish rsitech.ai and info@rsitech.ai as project contacts
  • consolidate maintained architecture and release documentation while removing obsolete internal release dossiers and plans
  • bind the community app to an exact clean tagged checkout instead of accepting an external app bundle
  • embed the privacy manifest, third-party notices, and complete license tree
  • publish archive checksum, manifest, SPDX SBOM, and third-party notices as release assets
  • reject source drift, tag drift, post-assembly byte changes, and missing provenance evidence

Validation

  • ./script/verify.sh
  • bash Tests/PackagingTests/community_release_contract.sh
  • bash Tests/PackagingTests/compliance_contract.sh
  • git diff --check
  • author and committer identity audit across all rewritten branch/tag history
  • git fsck --full --no-reflogs --unreachable

No Codex Security scan was run, per the requested scope.

Distribution boundary

The community artifact is ad-hoc signed and explicitly not Apple notarized. It is a prerelease for source-aligned evaluation and does not satisfy the Developer ID, notarization, clean-machine, or independent-promotion gates for an official direct-download release.

s1korrrr added 2 commits July 20, 2026 21:39
Signed-off-by: Rafal Sikora <24563931+s1korrrr@users.noreply.github.com>
Signed-off-by: Rafal Sikora <24563931+s1korrrr@users.noreply.github.com>
@s1korrrr
s1korrrr force-pushed the feat/andrzej_patchwright_org_release branch from e0c06f7 to ecbcba7 Compare July 20, 2026 20:04
Signed-off-by: Rafal Sikora <24563931+s1korrrr@users.noreply.github.com>

@s1korrrr s1korrrr left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed exact PR head 17c0348e4b158b39b74f9cd04162bf3bd175c973 against rewritten main c77a3bdf5878bbe8e8c6f71f7980fed644046994.

Review outcome: code and packaging changes are ready; merge remains held only for the latest exact-head hosted verify job, which is currently queued without a runner.

Evidence reviewed:

  • all three original PR #20 findings are closed: source-bound assembly, embedded privacy/third-party resources, and accurate changelog attribution
  • Apache LICENSE and project NOTICE are now embedded in the signed app, published as standalone assets, and digest-bound in assembly/release manifests
  • expanded-archive tests compare both legal files byte-for-byte and verify the archive checksum plus deep code signature
  • focused community and release contracts pass
  • a real build_release_components.sh --community assembly passes with exact legal-file comparisons, assembly-wide SHA-256 verification, and deep signature verification
  • the previous exact revision passed full local verification, 65 Swift tests, smoke/runtime launch, and hosted CI; the new seven-file delta has focused and real-assembly proof
  • v0.1.0 release evidence and its restored tag both resolve to eaee7f7336e0642afdf89301ec426154129b7fed; the live Sparkle appcast remains available
  • rewritten v0.1.1 and all new commit/tag metadata use 24563931+s1korrrr@users.noreply.github.com

The v0.1.0 release is intentionally retained because it is the active signed Sparkle feed provider. Its evidence-bound legacy commit is the one explicit history-rewrite exception.

No Codex Security scan was run for this release review, per scope.

@s1korrrr
s1korrrr merged commit eea52b5 into main Jul 20, 2026
1 check passed
@s1korrrr
s1korrrr deleted the feat/andrzej_patchwright_org_release branch July 20, 2026 21:04
s1korrrr added a commit that referenced this pull request Jul 20, 2026
Consolidate the production-ready open-source release under RSI Tech, bind the community package to a clean tagged source checkout, embed required legal and privacy resources, and publish exact release-evidence contracts.

Signed-off-by: Rafal Sikora <24563931+s1korrrr@users.noreply.github.com>
@s1korrrr

Copy link
Copy Markdown
Member Author

Final release reconciliation:

  • exact PR head 17c0348e4b158b39b74f9cd04162bf3bd175c973 passed hosted CI and PR Prepare Patchwright 0.2.0 community release #21 merged
  • GitHub squash metadata initially selected the account old primary email; the single merge commit was lease-protected rewritten per the authorized identity rewrite
  • authoritative main is 2d087e8a30d41f7158cd732b883d7d05c8e65e7a, with author and committer Rafal Sikora <24563931+s1korrrr@users.noreply.github.com>
  • exact-main CI run 29778787581 passed every step
  • tag v0.2.0-community.1 resolves to that exact main commit
  • the seven-asset community prerelease was downloaded separately and passed checksum, deep signature, version/build, privacy, legal-resource, third-party-license-tree, and manifest-digest verification
  • v0.1.0 is retained because it remains the active stable Sparkle feed provider
  • no Codex Security scan was run, per scope

Release: https://github.com/rsitech-ai/patchwright/releases/tag/v0.2.0-community.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant