Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ jobs:
fetch-depth: 0
path: tmp/firstdraft-cli
persist-credentials: false
- run: git -C tmp/firstdraft-cli merge-base --is-ancestor d37d8b6775a0b97ce10bd651485bd308fed1dda2 HEAD
- run: git -C tmp/firstdraft-cli checkout --detach d37d8b6775a0b97ce10bd651485bd308fed1dda2
- run: git -C tmp/firstdraft-cli merge-base --is-ancestor 5ac300f1a2e7262c56473de270a0bd140f169c25 HEAD
- run: git -C tmp/firstdraft-cli checkout --detach 5ac300f1a2e7262c56473de270a0bd140f169c25
- run: node script/check-cli-contract.mjs tmp/firstdraft-cli
- run: node script/check-claude-plugin-package.mjs --cli-root tmp/firstdraft-cli
8 changes: 4 additions & 4 deletions .github/workflows/publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -60,8 +60,8 @@ jobs:
fetch-depth: 0
path: tmp/firstdraft-cli
persist-credentials: false
- run: git -C tmp/firstdraft-cli merge-base --is-ancestor d37d8b6775a0b97ce10bd651485bd308fed1dda2 HEAD
- run: git -C tmp/firstdraft-cli checkout --detach d37d8b6775a0b97ce10bd651485bd308fed1dda2
- run: git -C tmp/firstdraft-cli merge-base --is-ancestor 5ac300f1a2e7262c56473de270a0bd140f169c25 HEAD
- run: git -C tmp/firstdraft-cli checkout --detach 5ac300f1a2e7262c56473de270a0bd140f169c25
- run: node script/check-cli-registry-package.mjs --cli-root tmp/firstdraft-cli
- run: node script/check-claude-plugin-package.mjs --cli-root tmp/firstdraft-cli

Expand Down Expand Up @@ -118,8 +118,8 @@ jobs:
fetch-depth: 0
path: tmp/firstdraft-cli
persist-credentials: false
- run: git -C tmp/firstdraft-cli merge-base --is-ancestor d37d8b6775a0b97ce10bd651485bd308fed1dda2 HEAD
- run: git -C tmp/firstdraft-cli checkout --detach d37d8b6775a0b97ce10bd651485bd308fed1dda2
- run: git -C tmp/firstdraft-cli merge-base --is-ancestor 5ac300f1a2e7262c56473de270a0bd140f169c25 HEAD
- run: git -C tmp/firstdraft-cli checkout --detach 5ac300f1a2e7262c56473de270a0bd140f169c25
- run: node script/check-cli-registry-package.mjs --cli-root tmp/firstdraft-cli
- run: node script/claude-plugin-package.mjs pack "$RUNNER_TEMP/plugin" --cli-root tmp/firstdraft-cli
- name: Verify publication bytes
Expand Down
13 changes: 7 additions & 6 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,18 +4,19 @@ Portable Agent Skills for [First Draft](https://github.com/firstdraft/firstdraft
the current bounded Rails-and-iPhone Compilation workflow.

This repository is experimental. It does not offer arbitrary application generation, deployment, Android, iPad,
Accounts, notifications, or broader web and native clients. Unsupported product meaning must remain explicit and
fails the complete candidate closed.
Accounts, notifications, or broader web and native clients. Unsupported product meaning must remain explicit. A
valid review can carry a complete GapSet describing meaning skipped by the service or not realized by the selected
target.

## Current state

| Surface | Selected identity |
|---|---|
| Source candidate | Plugin `0.1.2`; packed SHA-256 `24be4d4ea73d0d21aeed6248b72a775b4aba89c30180ccc6a69af13907b8b9ec` |
| Source candidate | Plugin `0.2.0`; packed SHA-256 `c3e87bb450630f04da9c6f724045784a4396f0e41222bab9f6ac5297273b0313` |
| Public marketplace | Plugin `0.1.1` |
| npm `next` and `latest` | Plugin `0.1.1` |
| Bundled CLI | `@firstdraft.com/cli@0.1.0` |
| Compatible service API | `>= 0.2.0`, `< 0.3.0` |
| Bundled CLI | `@firstdraft.com/cli@0.2.0` |
| Compatible service API | `>= 0.3.0`, `< 0.4.0` |
| Foundation Plan | `firstdraft.foundation-plan.sketch/0.19` |

The source candidate is unpublished and unpromoted. Public installation still selects immutable plugin `0.1.1`.
Expand Down Expand Up @@ -76,7 +77,7 @@ remain outside those installable directories.

Packing copies the canonical `skills/create-full-stack-app` directory into a temporary plugin tree; no second
editable Skill copy is committed under `packages/`. The assembled plugin also includes a small `firstdraft` adapter
and the exact packed files from CLI `0.1.0`. Executables in a plugin-root `bin/` directory are added to the Bash
and the exact packed files from CLI `0.2.0`. Executables in a plugin-root `bin/` directory are added to the Bash
tool's `PATH` by Claude Code.

Sensitive user configuration is not delivered to an executable merely because the plugin's `bin/` directory is on
Expand Down
40 changes: 24 additions & 16 deletions RELEASING.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,14 +8,14 @@ This is the current policy and operator sequence for coordinated work across `fi

| Surface | Current identity |
|---|---|
| Source candidate | `@firstdraft.com/claude-code@0.1.2` |
| Candidate packed SHA-256 | `24be4d4ea73d0d21aeed6248b72a775b4aba89c30180ccc6a69af13907b8b9ec` |
| Source candidate | `@firstdraft.com/claude-code@0.2.0` |
| Candidate packed SHA-256 | `c3e87bb450630f04da9c6f724045784a4396f0e41222bab9f6ac5297273b0313` |
| Public plugin package | `@firstdraft.com/claude-code@0.1.1` |
| Public catalog | Plugin `0.1.1` at promotion commit `ff2f0863f85e1f95194c8e3fbe9986b56efb0ad1` |
| Plugin npm `next` / `latest` | `0.1.1` / `0.1.1` |
| Compatible CLI | `@firstdraft.com/cli@0.1.0` |
| Compatible CLI | `@firstdraft.com/cli@0.2.0` |
| CLI npm `next` / `latest` | `0.1.0` / `0.1.0` |
| Service API contract | `>= 0.2.0`, `< 0.3.0` |
| Service API contract | `>= 0.3.0`, `< 0.4.0` |
| Foundation Plan format | `firstdraft.foundation-plan.sketch/0.19` |

The source candidate is unpublished and unpromoted. Its exact integration commit must be resolved from the final
Expand Down Expand Up @@ -70,20 +70,22 @@ syntax; do not add compatibility aliases.
and service identities. Candidate compatibility and local validation never prove authentication, service
compatibility, a fresh public install, a successful Compile, or GitHub Publication.

The current 0.1.2 candidate still requires one human-observed, two-turn approval smoke before publication. Use the
The current 0.2.0 candidate still requires one human-observed, two-turn approval smoke before publication. Use the
paired `precompile-semantic-read-back` and `compile-prepared-movie-catalog` cases in the same fresh continuing agent
session:

1. Record the exact Skills commit, package version and tarball SHA-256, compatible CLI and service identities, and
staged Plan SHA-256. Use a controlled local service and strict fake GitHub path unless the approved scope names a
live gate.
2. In the first turn, the agent presents the complete semantic read-back of that exact Plan, including that Compile
does not deploy and successful Publication creates one private GitHub repository, then stops for approval. The
observer confirms that the Compile wrapper count is zero before approval.
3. Give explicit approval of the presented semantic model and Plan SHA-256. In the same continuing session, the
agent rereads the unchanged Plan, invokes exactly one zero-flag Compile without another confirmation, and reports
the validated terminal Compilation and Publication outcome. The observer confirms that the Compile wrapper count
is exactly one after the turn.
2. In the first turn, the agent presents the complete semantic read-back of that exact Plan and the matching valid
AnalysisRun's one Appearance target-gap record with its digest. It explains that the admitted Appearance meaning
is not fully realized, Compile does not deploy, and successful Publication creates one private GitHub repository.
It then stops for approval. The observer confirms that the Compile wrapper count is zero before approval.
3. Give explicit approval of the presented semantic model, reviewed support result, and Plan SHA-256 without
requiring the user to echo the GapSet digest or records. In the same continuing session, the agent rereads the
unchanged Plan, invokes exactly one zero-flag Compile without another confirmation or gap-specific field, and
reports the validated terminal Compilation and Publication outcome. The observer confirms that the Compile
wrapper count is exactly one after the turn.

Retain the two-turn transcript, explicit approval, identities and digests above, pre-approval Compile count zero,
post-approval Compile count exactly one, and the final Compilation and Publication outcome. This smoke does not
Expand All @@ -104,6 +106,11 @@ This step requires explicit authorization for protected tag creation and npm pub
part of a named release sequence. The operator resolves and reports the exact candidate commit, package version,
and tarball digest before mutation; the user does not need to recite them.

Plugin 0.2.0 vendors and requires exact public `@firstdraft.com/cli@0.2.0`. Publish and reconcile that CLI under npm
`next` before tagging this plugin; the plugin registry-package gate must resolve those exact public bytes. Then
publish and reconcile plugin 0.2.0 under `next`. Both package steps precede any API 0.3 service activation, while
plugin and CLI `latest` and the public catalog remain unchanged until their separately approved promotions.

Immediately before tagging:

1. Verify the `claude-v*` ruleset protects tags from deletion and unauthorized updates.
Expand Down Expand Up @@ -181,10 +188,11 @@ maintenance window. The maintenance-window approval may include named rollback a
reports the exact package and service candidates and the approval names affected users, notice, start, rollback,
and completion criteria.

Publish and reconcile compatible package bytes under `next` before changing shared service roles. Leave `latest` and
the public catalog unchanged until the exact web and worker revisions are active and the selected qualification
passes. During the approved window, stop other operator-controlled Compile and Publication invocations in that lane
and serialize the one qualification invocation through its retained outcome.
For the current API 0.3 transition, publish and reconcile CLI 0.2.0 under `next`, then plugin 0.2.0 under `next`,
before changing shared service roles. Leave both `latest` tags and the public catalog unchanged until the exact web
and worker revisions are active and the selected qualification passes. During the approved window, stop other
operator-controlled Compile and Publication invocations in that lane and serialize the one qualification invocation
through its retained outcome.

Reconcile web, worker, queue, package, catalog, and supported-client state at every boundary. A web-only or
worker-only activation is not completion. Public traffic may continue as unattributed capacity activity under the
Expand Down
11 changes: 7 additions & 4 deletions evals/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -78,13 +78,16 @@ fresh private state with the exact reviewed CLI in an isolated scratch project.
- `report-successful-product-compile`
- `compile-terminal-publication-failure`

For the human-observed 0.1.2 release smoke, run `precompile-semantic-read-back` and
For the human-observed 0.2.0 release smoke, run `precompile-semantic-read-back` and
`compile-prepared-movie-catalog` as two user turns in the same fresh continuing agent session. Before the first turn,
record the exact candidate and package identity, compatible CLI and service identities, staged Plan SHA-256, and a
zero Compile-wrapper count. The first response must present the complete semantic model, identify the execution
consequences, and stop for explicit approval.
zero Compile-wrapper count. The first response must present the complete semantic model, the matching GapSet digest,
and the one Appearance target-gap record; explain that admitted target meaning is not fully realized, identify the
execution consequence, preserve Appearance, and stop for explicit approval. This deliberately exercises a valid
candidate with a nonempty GapSet.

The second prompt approves that semantic model and Plan SHA-256. The same session must reread unchanged Plan bytes,
The second prompt approves that semantic model, reviewed support result, and Plan SHA-256 without echoing the GapSet
digest or records. The same session must reread unchanged Plan bytes,
invoke exactly one zero-flag Compile without another confirmation, and report the validated terminal Compilation and
Publication outcome. A live run requires approval that includes that journey and freshly initialized private state;
otherwise use a controlled local service and strict fake GitHub transport.
Expand Down
Loading