diff --git a/README.md b/README.md
index 75e6bd8a..db30f4d9 100644
--- a/README.md
+++ b/README.md
@@ -14,7 +14,7 @@
-**Version:** 4.44.2
+**Version:** 4.44.3
**LocalSetup gives coding agents a repo-local operating layer.**
@@ -25,14 +25,15 @@ LocalSetup provides capability skills, executable workflow packages, explicit ad
Start with the [quickstart](ls/docs/QUICKSTART.md) or browse the [documentation](ls/docs/README.md). The [latest published release](https://github.com/CruxExperts/localsetup/releases/latest) provides release notes and downloads.
-## What's new in 4.44.2
+## What's new in 4.44.3
-LocalSetup 4.44.2 improves release-documentation completion capacity for maintainers and aligns the release arithmetic with the verified published 4.44.1 anchor. The 4.x major-line lock and historical release evidence remain in force.
+LocalSetup 4.44.3 includes the approved release-documentation QC budget updates and corrects the framework version recorded and checked in CycloneDX SBOMs. Release SBOMs use the completed archive's VERSION; source and installed SBOMs use the repository VERSION when present and fall back to the installed framework distribution version when it is absent. It follows the published v4.44.1 baseline after two sequential patch slices; the pushed v4.44.2 tag and its draft assets remain unchanged and unpublished.
- **Longer release-docs QC sessions:** Preparation defaults to 800 completion calls and a 9,000-second (150-minute) whole-session budget. The hosted publish job allows 165 minutes total, with a 15-minute grace period; individual provider requests use a separate 180-second fallback timeout.
-- **Corrected 4.x release arithmetic:** Published v4.44.1 was the first release under corrected arithmetic and is the baseline for this patch. The v5.6.2 and v4.22.9 tags and assets remain unchanged, and major-version increments remain locked.
+- **Framework-versioned SBOMs:** Release SBOMs use the framework VERSION stored in the completed archive. Source and installed SBOMs use the repository VERSION when present and fall back to the installed distribution version when it is absent. `verify-release` rejects missing, malformed, or stale release SBOM application versions. The separate pack-format value in artifact metadata remains `3`.
+- **Corrected 4.x release arithmetic:** v4.44.1 is the published baseline. Sequential patch arithmetic maps the QC and SBOM fixes to 4.44.2 and 4.44.3. The pushed v4.44.2 tag and its draft assets remain unchanged and unpublished; the 4.x major-line lock and historical release evidence remain in force.
-See the [4.44.2 release guide](ls/docs/releases/4.44.2.md) for compatibility, updating, and verification.
+See the [4.44.3 release guide](ls/docs/releases/4.44.3.md) for compatibility, updating, and verification.
The [4.4.0 guide](ls/docs/releases/4.4.0.md) remains available as release history.
@@ -83,7 +84,7 @@ Start with the [workflow packages guide](ls/docs/WORKFLOW_PACKAGES.md) for usage
| Fact | Value |
|---|---|
-| Current version | `4.44.2` |
+| Current version | `4.44.3` |
| Supported platforms | `codex, claude-code, cursor, kilo, opencode, openclaw, github-copilot-cli, github-copilot-vscode, cline-cli, cline-vscode, amp-cli, goose-cli, pi-cli, hermes-agent, qwen-code-cli, kimi-cli, factory-droid, antigravity-app, gemini-cli, omp-cli` |
| Shipped skills | `105` |
| Workflow packages | `18` |
diff --git a/VERSION b/VERSION
index 1a6b68cc..f360ff72 100644
--- a/VERSION
+++ b/VERSION
@@ -1 +1 @@
-4.44.2
+4.44.3
diff --git a/ls/README.md b/ls/README.md
index bd6db3e6..31f3772e 100644
--- a/ls/README.md
+++ b/ls/README.md
@@ -1,6 +1,6 @@
# LocalSetup Framework Engine
-**Version:** 4.44.2
+**Version:** 4.44.3
`ls/` is the engine that makes the public LocalSetup promise real. It stores the framework code, shipped skills, workflow packages, platform templates, docs, tests, and install manifests that turn a repository into a portable agent workspace.
@@ -26,7 +26,7 @@ For the public product overview, start with the [root README](../README.md). Thi
LocalSetup-managed entries in consuming repositories are install output. Adapter directories may also contain project-owned skills, files, and symlinks; preserve that content in place. See [adapter ownership](docs/ADAPTER_OWNERSHIP.md).
-Read the [current release guide](docs/releases/4.44.2.md) for LocalSetup 4.44.2, including compatibility, updating, and verification. Find downloads in the [latest published release](https://github.com/CruxExperts/localsetup/releases/latest).
+Read the [current release guide](docs/releases/4.44.3.md) for LocalSetup 4.44.3, including compatibility, updating, and verification. Find downloads in the [latest published release](https://github.com/CruxExperts/localsetup/releases/latest).
## Install flow
diff --git a/ls/config/branding.json b/ls/config/branding.json
index 78d5232d..e9c7be24 100644
--- a/ls/config/branding.json
+++ b/ls/config/branding.json
@@ -1307,11 +1307,11 @@
},
{
"path": "ls/core/package.py",
- "line_sha256": "dba45bec4f8271be61ed1e7e8bee453380675b3ac3d0462b74b44f2c7b753d6b",
+ "line_sha256": "6b656a31bda137a48a392f5ed8377de3fb0c13faef997c7b95065502b8f04410",
"token": "localsetup",
"count": 1,
"kind": "compatibility_identifier",
- "reason": "Established package/plugin ID, migration alias pattern, temporary-path prefix or protocol identifier at this source location; not a product display label."
+ "reason": "Stable internal installed SBOM component identifier; technical metadata rather than user-facing product text."
},
{
"path": "ls/core/package_surface.py",
@@ -4832,6 +4832,22 @@
"count": 3,
"kind": "compatibility_identifier",
"reason": "Launcher fixture checks the established framework command path."
+ },
+ {
+ "count": 1,
+ "kind": "compatibility_identifier",
+ "line_sha256": "3413ba2788cb308eb131957ea2433f1aa0b5e326c296a45527b2f7413ff308e2",
+ "path": "ls/tests/test_install_flow_docs_package_a.py",
+ "reason": "CycloneDX verification fixture uses the established pack ID to check metadata parsing; technical compatibility data rather than display text.",
+ "token": "localsetup"
+ },
+ {
+ "count": 1,
+ "kind": "compatibility_identifier",
+ "line_sha256": "5b562a0ad13ff0f7b9f6c9b2ebd04280f3742a7f27e55f5ff33ff36d4418b10c",
+ "path": "ls/tests/test_install_flow_package_version_provenance.py",
+ "reason": "Test supplies the canonical Python distribution key to exercise installed-version metadata lookup; technical compatibility data rather than display text.",
+ "token": "localsetup"
}
],
"visual_reviews": [
diff --git a/ls/core/package.py b/ls/core/package.py
index fc58a0cd..8880c96a 100644
--- a/ls/core/package.py
+++ b/ls/core/package.py
@@ -10,15 +10,25 @@
from typing import Any
from .boundary import scan_tar_for_leaks
+from .framework_version import framework_version
from .manifests import load_pack_config
from .paths import repo_path
from .source import source_commit, source_tag
+from .versioning import read_version
+from .versioning_models import SemVer
from .sdk_payload.integrity import verify as verify_sdk
from .sdk_payload.artifacts import inspect_artifact as inspect_sdk_artifact
from .sdk_payload.sbom import components as sdk_components
ARTIFACT_METADATA_PATH = "ls/artifact-metadata.json"
+MAX_FRAMEWORK_VERSION_BYTES = 128
+
+
+def _framework_version_for_repo(repo_root: Path) -> str:
+ if (repo_root / "VERSION").is_file():
+ return str(read_version(repo_root))
+ return framework_version()
def _load_toml(path: Path) -> dict[str, Any]:
@@ -111,6 +121,32 @@ def _components_for_sbom(repo_root: Path) -> list[dict[str, Any]]:
return result
+def _framework_version_from_artifact(artifact_path: Path) -> str:
+ with tarfile.open(artifact_path, "r:*") as tar:
+ members = [member for member in tar.getmembers() if member.name == "VERSION"]
+ if not members:
+ raise ValueError("framework VERSION not found in artifact")
+ if len(members) != 1:
+ raise ValueError("artifact must contain exactly one framework VERSION entry")
+ member = members[0]
+ if not member.isfile():
+ raise ValueError("framework VERSION entry in artifact must be a regular file")
+ if member.size < 0 or member.size > MAX_FRAMEWORK_VERSION_BYTES:
+ raise ValueError(
+ f"framework VERSION entry exceeds the {MAX_FRAMEWORK_VERSION_BYTES}-byte limit"
+ )
+ handle = tar.extractfile(member)
+ if handle is None:
+ raise ValueError("framework VERSION could not be read from artifact")
+ data = handle.read(MAX_FRAMEWORK_VERSION_BYTES + 1)
+ if len(data) != member.size:
+ raise ValueError("framework VERSION entry is truncated in artifact")
+ try:
+ return str(SemVer.parse(data.decode("utf-8").strip()))
+ except (UnicodeDecodeError, ValueError) as exc:
+ raise ValueError(f"invalid framework VERSION in artifact: {exc}") from exc
+
+
def _expected_components_from_artifact(artifact_path: Path) -> list[dict[str, str]]:
with tarfile.open(artifact_path, "r:*") as tar:
try:
@@ -155,7 +191,7 @@ def write_cyclonedx_sbom(repo_root: Path, artifact_path: Path, metadata: dict[st
"component": {
"type": "application",
"name": metadata["pack_id"],
- "version": str(metadata["version"]),
+ "version": _framework_version_from_artifact(artifact_path),
"bom-ref": metadata["pack_id"],
},
"properties": [
@@ -175,7 +211,7 @@ def write_source_sbom(repo_root: Path, output_path: Path) -> dict[str, Any]:
"bomFormat": "CycloneDX",
"specVersion": "1.6",
"version": 1,
- "metadata": {"component": {"type": "application", "name": pack.pack_id, "version": str(pack.version)}},
+ "metadata": {"component": {"type": "application", "name": pack.pack_id, "version": _framework_version_for_repo(repo_root)}},
"components": _components_for_sbom(repo_root),
}
output_path.parent.mkdir(parents=True, exist_ok=True)
@@ -198,7 +234,7 @@ def write_installed_sbom(repo_root: Path, target_root: Path, output_path: Path)
"bomFormat": "CycloneDX",
"specVersion": "1.6",
"version": 1,
- "metadata": {"component": {"type": "application", "name": "localsetup-installed", "version": str(pack.version)}},
+ "metadata": {"component": {"type": "application", "name": "localsetup-installed", "version": _framework_version_for_repo(repo_root)}},
"components": components,
}
output_path.parent.mkdir(parents=True, exist_ok=True)
@@ -331,8 +367,10 @@ def verify_cyclonedx_sbom(sbom_path: Path, artifact_path: Path, metadata: dict[s
if isinstance(item, dict)
}
component = payload.get("metadata", {}).get("component", {})
+ component = component if isinstance(component, dict) else {}
components = payload.get("components", [])
try:
+ expected_framework_version = _framework_version_from_artifact(artifact_path)
expected_components = _expected_components_from_artifact(artifact_path)
sdk = inspect_sdk_artifact(artifact_path, required=False, expected_digest=metadata.get("sdk_manifest_sha256"))
vendored = sdk_components(sdk["manifest"]) if sdk else []
@@ -348,6 +386,7 @@ def verify_cyclonedx_sbom(sbom_path: Path, artifact_path: Path, metadata: dict[s
payload.get("specVersion") == "1.6",
isinstance(components, list),
component.get("name") == metadata.get("pack_id"),
+ component.get("version") == expected_framework_version,
properties.get("localsetup:artifact") == artifact_path.name,
properties.get("localsetup:source_commit") == metadata.get("source_commit"),
not missing,
@@ -361,6 +400,8 @@ def verify_cyclonedx_sbom(sbom_path: Path, artifact_path: Path, metadata: dict[s
"path": str(sbom_path),
"bomFormat": payload.get("bomFormat"),
"component": component.get("name"),
+ "component_version": component.get("version"),
+ "expected_framework_version": expected_framework_version,
"artifact": properties.get("localsetup:artifact"),
"source_commit": properties.get("localsetup:source_commit"),
"component_count": len(components) if isinstance(components, list) else None,
diff --git a/ls/docs/FEATURES.md b/ls/docs/FEATURES.md
index 8da3fbe1..5b328b2c 100644
--- a/ls/docs/FEATURES.md
+++ b/ls/docs/FEATURES.md
@@ -11,7 +11,7 @@ This is the full public capability catalog for LocalSetup. The [root README](../
## Generated Facts
-- Current version: `4.44.2`
+- Current version: `4.44.3`
- Supported platforms: `codex, claude-code, cursor, kilo, opencode, openclaw, github-copilot-cli, github-copilot-vscode, cline-cli, cline-vscode, amp-cli, goose-cli, pi-cli, hermes-agent, qwen-code-cli, kimi-cli, factory-droid, antigravity-app, gemini-cli, omp-cli`
- Shipped skills: `105`
- Workflow packages: `18`
diff --git a/ls/docs/README.md b/ls/docs/README.md
index b3fee316..be8b2961 100644
--- a/ls/docs/README.md
+++ b/ls/docs/README.md
@@ -19,7 +19,7 @@ This is the public documentation map for LocalSetup. Start here when you want th
## Generated Facts
-- Current version: `4.44.2`
+- Current version: `4.44.3`
- Supported platforms: `codex, claude-code, cursor, kilo, opencode, openclaw, github-copilot-cli, github-copilot-vscode, cline-cli, cline-vscode, amp-cli, goose-cli, pi-cli, hermes-agent, qwen-code-cli, kimi-cli, factory-droid, antigravity-app, gemini-cli, omp-cli`
- Shipped skills: `105`
- Workflow packages: `18`
@@ -51,7 +51,7 @@ This is the public documentation map for LocalSetup. Start here when you want th
| [Harness automation](HARNESS_AUTOMATION.md) | Opt-in heartbeat activation, typed LSCli profiles, reserved actions/controller accounting, runtime artifacts, cron gating and command-policy boundaries. |
-Read the [current release guide](releases/4.44.2.md) for LocalSetup 4.44.2, including compatibility, updating, and verification. Find downloads in the [latest published release](https://github.com/CruxExperts/localsetup/releases/latest).
+Read the [current release guide](releases/4.44.3.md) for LocalSetup 4.44.3, including compatibility, updating, and verification. Find downloads in the [latest published release](https://github.com/CruxExperts/localsetup/releases/latest).
The [4.4.0 guide](releases/4.4.0.md) covers the earlier context and package consolidation.
diff --git a/ls/docs/SKILLS.md b/ls/docs/SKILLS.md
index 0beeee51..003f9a85 100644
--- a/ls/docs/SKILLS.md
+++ b/ls/docs/SKILLS.md
@@ -4,10 +4,10 @@ version: 4.44
owner_package: generate-docs
localsetup_provenance:
schema_version: 1
- source_provenance_hash: 6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67
+ source_provenance_hash: d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe
emitter: generate-docs
-framework_version: 4.44.2
-source_commit: ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe
+framework_version: 4.44.3
+source_commit: 213176b18d5683d0354d6de307692589e2879185
artifact_sha256: 73c1afab3e2ac3b53857cd025f86bd7ca57a0668c3093542ff2c9b4faf16ed88
---
# Shipped skills catalog
diff --git a/ls/docs/VERSIONING.md b/ls/docs/VERSIONING.md
index d9edddf9..e7879109 100644
--- a/ls/docs/VERSIONING.md
+++ b/ls/docs/VERSIONING.md
@@ -11,7 +11,7 @@ LocalSetup uses the root `VERSION` file as the source of truth for the framework
## Current Version
- Source of truth: [`../../VERSION`](../../VERSION)
-- Current value: `4.44.2`
+- Current value: `4.44.3`
- Generated facts: [`_generated/facts.json`](_generated/facts.json)
## 4.x major-line lock and one-time numbering reconciliation
diff --git a/ls/docs/WORKFLOW_QUICK_REF.md b/ls/docs/WORKFLOW_QUICK_REF.md
index 48339c51..4d8b72a2 100644
--- a/ls/docs/WORKFLOW_QUICK_REF.md
+++ b/ls/docs/WORKFLOW_QUICK_REF.md
@@ -4,10 +4,10 @@ version: 4.44
owner_package: generate-docs
localsetup_provenance:
schema_version: 1
- source_provenance_hash: 6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67
+ source_provenance_hash: d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe
emitter: generate-docs
-framework_version: 4.44.2
-source_commit: ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe
+framework_version: 4.44.3
+source_commit: 213176b18d5683d0354d6de307692589e2879185
artifact_sha256: 393552d58b8412c44afc9fbbd0aff0975a19010d587d5779e0346ef5ff2e05a7
---
# Workflow quick reference
diff --git a/ls/docs/WORKFLOW_REGISTRY.md b/ls/docs/WORKFLOW_REGISTRY.md
index a6980ae4..a9fb544e 100644
--- a/ls/docs/WORKFLOW_REGISTRY.md
+++ b/ls/docs/WORKFLOW_REGISTRY.md
@@ -4,10 +4,10 @@ version: 4.44
owner_package: generate-docs
localsetup_provenance:
schema_version: 1
- source_provenance_hash: 6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67
+ source_provenance_hash: d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe
emitter: generate-docs
-framework_version: 4.44.2
-source_commit: ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe
+framework_version: 4.44.3
+source_commit: 213176b18d5683d0354d6de307692589e2879185
artifact_sha256: 0407568324660bae06808812eb701709399b3cff93d4d8903dddf688487a6745
---
# Workflow and module registry (LocalSetup)
diff --git a/ls/docs/_generated/artifact-registry.json b/ls/docs/_generated/artifact-registry.json
index e5779e38..004fd45d 100644
--- a/ls/docs/_generated/artifact-registry.json
+++ b/ls/docs/_generated/artifact-registry.json
@@ -3,10 +3,10 @@
{
"artifact_sha256": "ab8055bd373816efa87ddeacddbe40a803e028a21df6c96221cd8a97d46b9dfc",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"path": "assets/README.md",
- "provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_inputs": [
"VERSION",
"ls/skills",
@@ -23,12 +23,12 @@
"type": "markdown"
},
{
- "artifact_sha256": "f6e64803aa48497b66e5560d89ca3984ff08fcc4dabf623ce4e8f26446e168b5",
+ "artifact_sha256": "a3f3b026229f7b15e8de0a978bf9466c5802d13607aa11718b08971571b547f4",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"path": "ls/docs/SKILLS.md",
- "provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_inputs": [
"VERSION",
"ls/skills",
@@ -45,12 +45,12 @@
"type": "markdown"
},
{
- "artifact_sha256": "37763150e91a2b7b04f5b7aeab1d92bff9a840606c374d2e685ba6b127281d53",
+ "artifact_sha256": "701a3db541bee33bda0144f0d299b03028eaca29c3da97bd9a260a322ac27e96",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"path": "ls/docs/WORKFLOW_QUICK_REF.md",
- "provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_inputs": [
"VERSION",
"ls/skills",
@@ -67,12 +67,12 @@
"type": "markdown"
},
{
- "artifact_sha256": "35cc8ee0d9958cff698eb2e71b4dad062437e4500aeb5fd4644ac8312a142432",
+ "artifact_sha256": "c33dba7b647970015759b50c6134f6300d7d7bc3b775076d4b2d55bc75368307",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"path": "ls/docs/WORKFLOW_REGISTRY.md",
- "provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_inputs": [
"VERSION",
"ls/skills",
@@ -89,12 +89,12 @@
"type": "markdown"
},
{
- "artifact_sha256": "90f24323afd8d9db7e5c04db065ada63f4f7662ebde82319aa025a1264e99456",
+ "artifact_sha256": "d3709f37152da7265126e78e69f478a3a21b031bf1a503bf391cf6ec7125457e",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"path": "ls/docs/_generated/docs-alignment-summary.md",
- "provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_inputs": [
"VERSION",
"ls/skills",
@@ -111,12 +111,12 @@
"type": "markdown"
},
{
- "artifact_sha256": "2985e1e711c9456aee4efbe6ba34e2bd47cc552d05a1653bb69fb1022f6f27d4",
+ "artifact_sha256": "15414a01e9e2bf4be8f28c7c74cb809123dc41c0903ad442b013528915451e13",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"path": "ls/docs/_generated/docs-asset-manifest.json",
- "provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_inputs": [
"VERSION",
"ls/skills",
@@ -133,12 +133,12 @@
"type": "json"
},
{
- "artifact_sha256": "5aff5f9601ad35005efe7f5fc66d7a04f5fa6048f29b675424c9c14285b6553a",
+ "artifact_sha256": "7a550e3fa70b0fbc791445dd0b5db3c4b1b5f21ca5be9c82871f29b30eab3ecf",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"path": "ls/docs/_generated/docs-audit-result.json",
- "provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_inputs": [
"VERSION",
"ls/skills",
@@ -155,12 +155,12 @@
"type": "json"
},
{
- "artifact_sha256": "7e19e8df5b8e3be17c3cb4abf50ab02fa9f0d2a872156b086b3e1b65b9eccc38",
+ "artifact_sha256": "f83ff9e8ea99a97ea607908a5af52c66f18119bd1b223cdc34cc2de83c31e030",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"path": "ls/docs/_generated/docs-inventory.json",
- "provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_inputs": [
"VERSION",
"ls/skills",
@@ -177,12 +177,12 @@
"type": "json"
},
{
- "artifact_sha256": "45f8c0ee7bf3614fd41152493d7a7f63e870c3e37ce7ad05ad294ce41d50795e",
+ "artifact_sha256": "98b023ebcbca14388626f9b76d3aa91f45aa01b4b1d8ea1f5bcaf3580fcf7644",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"path": "ls/docs/_generated/docs-truth-map.json",
- "provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_inputs": [
"VERSION",
"ls/skills",
@@ -199,12 +199,12 @@
"type": "json"
},
{
- "artifact_sha256": "ae4f132f10288ddd1663f112e5bcf7d80ee05352f8d00a5b0f327a634f1601e6",
+ "artifact_sha256": "0862637d27bf016c997afb895775c0c54b203fe62cdcd7ad306e0f393d44ff8e",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"path": "ls/docs/_generated/facts.json",
- "provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_inputs": [
"VERSION",
"ls/skills",
@@ -221,12 +221,12 @@
"type": "json"
},
{
- "artifact_sha256": "0dd5aaa38d0d549ba8b04eeb8a25c7c463c412233122c80102ef022c56fcd5b8",
+ "artifact_sha256": "7e97599e612d8ebaec402b0c5261cdf357087af0613d8eb113f20574c1a9d2dc",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"path": "ls/docs/_generated/implementation-file-map.md",
- "provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_inputs": [
"VERSION",
"ls/skills",
@@ -243,12 +243,12 @@
"type": "markdown"
},
{
- "artifact_sha256": "195c151259a9e15cd2db96a4b0b1a6a4f69d1e54948315df159d27b8cfb57c9b",
+ "artifact_sha256": "59482a1ce8e0061f878ef936498c163f280a7a4987035fea3421f5599608f9b8",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"path": "ls/docs/_generated/platform-adapters.md",
- "provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_inputs": [
"VERSION",
"ls/skills",
@@ -265,12 +265,12 @@
"type": "markdown"
},
{
- "artifact_sha256": "43acff76db0cc67ea1b4492046f8334053dce253573845b82541cebcd3fdd5f9",
+ "artifact_sha256": "312d639202399d41e8fa7487b203d07d3e34968db2df94a87d89d8c107fadd28",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"path": "ls/docs/_generated/plugin-packs.json",
- "provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_inputs": [
"VERSION",
"ls/skills",
@@ -287,12 +287,12 @@
"type": "json"
},
{
- "artifact_sha256": "0c70c694fa2bebec45783cf404f7a00cf5711e48ad17e085e2acc2632d0b85e5",
+ "artifact_sha256": "8d24882192effbb2aa995e3823d4dc527816dc72bc99dc95bcf5b483ed0dd69d",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"path": "ls/docs/_generated/plugin-packs.md",
- "provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_inputs": [
"VERSION",
"ls/skills",
@@ -309,12 +309,12 @@
"type": "markdown"
},
{
- "artifact_sha256": "150ddd8f4fd23a44bd70c48d5b066e576306d67e94e3c4b1952a63e0efd17245",
+ "artifact_sha256": "b3863e03074b480a276135d003ff19ff5eea0709c20033cd1a275790cf9e7a4c",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"path": "ls/docs/_generated/skill-packs.md",
- "provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_inputs": [
"VERSION",
"ls/skills",
@@ -331,12 +331,12 @@
"type": "markdown"
},
{
- "artifact_sha256": "65a109701dc89b69af3782e1a93f838ab4907ed851cec34810f8500527206f31",
+ "artifact_sha256": "7d2a886b66cd48e94bb40e6ff6a66534baf8d45423be7417ae21073bcb602a87",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"path": "ls/docs/_generated/skill-taxonomy.json",
- "provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_inputs": [
"VERSION",
"ls/skills",
@@ -353,12 +353,12 @@
"type": "json"
},
{
- "artifact_sha256": "c59ab26ce5fea9ea8380c3f8a6a7587311c765039fa61b5de6ee199592a8573f",
+ "artifact_sha256": "f2bc165f7628c9892927a9fba79f4bd91e2c90ecf981385c06c4c6f692c041e4",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"path": "ls/docs/_generated/skill_aliases.json",
- "provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_inputs": [
"VERSION",
"ls/skills",
@@ -375,12 +375,12 @@
"type": "json"
},
{
- "artifact_sha256": "0ad889772f88d478f4df293e6ef9ee89129a0072333c6a07ad90bcb7423b6051",
+ "artifact_sha256": "2cf2fe017ee761a0b6e62ea577ae2bca4a3dba3655615773a86a9682944df923",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"path": "ls/docs/_generated/workflow-catalog.json",
- "provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_inputs": [
"VERSION",
"ls/skills",
@@ -397,12 +397,12 @@
"type": "json"
},
{
- "artifact_sha256": "85c71ce6f38728916f15814cd1d94e4ddfe80219e2b6901154980cf09190b4c5",
+ "artifact_sha256": "11c6679ec57adca1063bacf0256b7b6bf5795c9dd1bdb1b0cef930c0dd9621dd",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"path": "ls/docs/migration/skill-alias-map.md",
- "provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_inputs": [
"VERSION",
"ls/skills",
@@ -421,16 +421,16 @@
],
"provenance": {
"artifact_path": "ls/docs/_generated/artifact-registry.json",
- "artifact_sha256": "af983ef8b38080c7dc3afecdac387a8c73d81da2e025ee8e6335b1d0ce05f21e",
+ "artifact_sha256": "07138cc55c9367824a36d100f1cac2949c386a055b47fe1352544bfbb3ae8312",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"schema_version": 1,
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_dirty": false,
- "source_provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_root_id": "ae93ec666af9b56a17213e46181088d8d30fe885b2e6a08a36d04e0129603ab6",
+ "source_provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_root_id": "f3def3b041a3e6061a0e969dd62f48785d6961a5d9a0e29bf46edcfc67c43ffb",
"source_tag": null,
- "source_tree_sha": "cfa4d4d3e862321008fc808af2470d02489a4b38"
+ "source_tree_sha": "0934dd0bb3220d0aaaef80c1e808471f64011b53"
},
"schema_version": 1
}
diff --git a/ls/docs/_generated/docs-alignment-summary.md b/ls/docs/_generated/docs-alignment-summary.md
index 5658f1c0..81e7ae74 100644
--- a/ls/docs/_generated/docs-alignment-summary.md
+++ b/ls/docs/_generated/docs-alignment-summary.md
@@ -4,11 +4,11 @@ version: 4.44
owner_package: docs-align
localsetup_provenance:
schema_version: 1
- source_provenance_hash: 6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67
+ source_provenance_hash: d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe
emitter: docs-align
-framework_version: 4.44.2
-source_commit: ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe
-artifact_sha256: c5bc73cf1da529df383fb2eb2eed25538e19ad06de47e43a49597f075705afe8
+framework_version: 4.44.3
+source_commit: 213176b18d5683d0354d6de307692589e2879185
+artifact_sha256: aa3f7cad7567c79800b7b6c2c118c6a81eea509a9285e81e1ab0dd445619a684
---
# Documentation Alignment Summary
@@ -16,8 +16,8 @@ This page is generated from repository inventory, source-truth manifests, asset
| Signal | Value |
|---|---:|
-| Version | `4.44.2` |
-| Documentation files inventoried | 513 |
+| Version | `4.44.3` |
+| Documentation files inventoried | 514 |
| Immutable upstream documents | 64 |
| Shipped skills | 105 |
| Workflow packages | 18 |
diff --git a/ls/docs/_generated/docs-asset-manifest.json b/ls/docs/_generated/docs-asset-manifest.json
index df296fd5..ee7473fc 100644
--- a/ls/docs/_generated/docs-asset-manifest.json
+++ b/ls/docs/_generated/docs-asset-manifest.json
@@ -112,14 +112,14 @@
"artifact_path": "ls/docs/_generated/docs-asset-manifest.json",
"artifact_sha256": "f2228883dbd18ae5996b2e66baff63b8819d7dfe101463396cc354fb8e46083f",
"emitter": "docs-align",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"schema_version": 1,
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_dirty": false,
- "source_provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_root_id": "ae93ec666af9b56a17213e46181088d8d30fe885b2e6a08a36d04e0129603ab6",
+ "source_provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_root_id": "f3def3b041a3e6061a0e969dd62f48785d6961a5d9a0e29bf46edcfc67c43ffb",
"source_tag": null,
- "source_tree_sha": "cfa4d4d3e862321008fc808af2470d02489a4b38"
+ "source_tree_sha": "0934dd0bb3220d0aaaef80c1e808471f64011b53"
},
"schema_version": "1.0"
}
diff --git a/ls/docs/_generated/docs-audit-result.json b/ls/docs/_generated/docs-audit-result.json
index 58d04714..bac03e2b 100644
--- a/ls/docs/_generated/docs-audit-result.json
+++ b/ls/docs/_generated/docs-audit-result.json
@@ -9,14 +9,14 @@
"artifact_path": "ls/docs/_generated/docs-audit-result.json",
"artifact_sha256": "e82619e42f31266261fa11fa954df7778b2d19b7f12d224a71a85ec1a8cf31a8",
"emitter": "docs-align",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"schema_version": 1,
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_dirty": false,
- "source_provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_root_id": "ae93ec666af9b56a17213e46181088d8d30fe885b2e6a08a36d04e0129603ab6",
+ "source_provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_root_id": "f3def3b041a3e6061a0e969dd62f48785d6961a5d9a0e29bf46edcfc67c43ffb",
"source_tag": null,
- "source_tree_sha": "cfa4d4d3e862321008fc808af2470d02489a4b38"
+ "source_tree_sha": "0934dd0bb3220d0aaaef80c1e808471f64011b53"
},
"schema_version": "1.0"
}
diff --git a/ls/docs/_generated/docs-inventory.json b/ls/docs/_generated/docs-inventory.json
index 2d9c750e..94f2cfff 100644
--- a/ls/docs/_generated/docs-inventory.json
+++ b/ls/docs/_generated/docs-inventory.json
@@ -175,8 +175,8 @@
"workflow"
],
"counts": {
- "docs": 513,
- "framework_docs": 87,
+ "docs": 514,
+ "framework_docs": 88,
"generated_docs": 5,
"platforms": 20,
"public_docs": 6,
@@ -1276,6 +1276,16 @@
"status": "ACTIVE",
"version": "4.44"
},
+ {
+ "class": "framework",
+ "has_frontmatter": true,
+ "managed_blocks": [],
+ "owner_package": "",
+ "owner_skill": "ls-github-publishing-workflow",
+ "path": "ls/docs/releases/4.44.3.md",
+ "status": "ACTIVE",
+ "version": "4.44"
+ },
{
"class": "framework",
"has_frontmatter": true,
@@ -5771,16 +5781,16 @@
],
"provenance": {
"artifact_path": "ls/docs/_generated/docs-inventory.json",
- "artifact_sha256": "76e7c4accd76424a62c6ea88293c2eec1c0b4b9203240dc9d2fd0fc480a57e5a",
+ "artifact_sha256": "ea158cf2d5f862a5fd62573333aa7c97b3b1c67d85fc486a899846e626dccfb8",
"emitter": "docs-align",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"schema_version": 1,
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_dirty": false,
- "source_provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_root_id": "ae93ec666af9b56a17213e46181088d8d30fe885b2e6a08a36d04e0129603ab6",
+ "source_provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_root_id": "f3def3b041a3e6061a0e969dd62f48785d6961a5d9a0e29bf46edcfc67c43ffb",
"source_tag": null,
- "source_tree_sha": "cfa4d4d3e862321008fc808af2470d02489a4b38"
+ "source_tree_sha": "0934dd0bb3220d0aaaef80c1e808471f64011b53"
},
"repo": ".",
"schema_version": "1.0",
diff --git a/ls/docs/_generated/docs-truth-map.json b/ls/docs/_generated/docs-truth-map.json
index fac15117..5b3e169e 100644
--- a/ls/docs/_generated/docs-truth-map.json
+++ b/ls/docs/_generated/docs-truth-map.json
@@ -126,16 +126,16 @@
],
"provenance": {
"artifact_path": "ls/docs/_generated/facts.json",
- "artifact_sha256": "9a883978ba8108e75a74f7d9acb1b7d7164168aa01268674e813c0633ce0ad11",
+ "artifact_sha256": "1c86d5a0c1bf795b08b525d54a4dd0976f9832a4812dd09da79176522a15cda9",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"schema_version": 1,
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_dirty": false,
- "source_provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_root_id": "ae93ec666af9b56a17213e46181088d8d30fe885b2e6a08a36d04e0129603ab6",
+ "source_provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_root_id": "f3def3b041a3e6061a0e969dd62f48785d6961a5d9a0e29bf46edcfc67c43ffb",
"source_tag": null,
- "source_tree_sha": "cfa4d4d3e862321008fc808af2470d02489a4b38"
+ "source_tree_sha": "0934dd0bb3220d0aaaef80c1e808471f64011b53"
},
"skill_count": 105,
"skills": [
@@ -1879,7 +1879,7 @@
"version": "1.0"
}
],
- "version": "4.44.2",
+ "version": "4.44.3",
"workflow_count": 18,
"workflows": [
{
@@ -2007,14 +2007,14 @@
"artifact_path": "ls/docs/_generated/skill-taxonomy.json",
"artifact_sha256": "6dbaf28f6a3169d873c87830a966e298aba185cb24fa376de49f7c60d04288a9",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"schema_version": 1,
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_dirty": false,
- "source_provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_root_id": "ae93ec666af9b56a17213e46181088d8d30fe885b2e6a08a36d04e0129603ab6",
+ "source_provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_root_id": "f3def3b041a3e6061a0e969dd62f48785d6961a5d9a0e29bf46edcfc67c43ffb",
"source_tag": null,
- "source_tree_sha": "cfa4d4d3e862321008fc808af2470d02489a4b38"
+ "source_tree_sha": "0934dd0bb3220d0aaaef80c1e808471f64011b53"
},
"schema_version": 1,
"skills": [
@@ -3551,16 +3551,16 @@
},
"provenance": {
"artifact_path": "ls/docs/_generated/docs-truth-map.json",
- "artifact_sha256": "935b0784177572111f67146b0d36fd50469d3388784aa1b822b98fbe59d90a88",
+ "artifact_sha256": "e71cd4c70d3d533253347ca4436e47a2ee1a9884d3ce552e0e6442bb06c99cba",
"emitter": "docs-align",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"schema_version": 1,
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_dirty": false,
- "source_provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_root_id": "ae93ec666af9b56a17213e46181088d8d30fe885b2e6a08a36d04e0129603ab6",
+ "source_provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_root_id": "f3def3b041a3e6061a0e969dd62f48785d6961a5d9a0e29bf46edcfc67c43ffb",
"source_tag": null,
- "source_tree_sha": "cfa4d4d3e862321008fc808af2470d02489a4b38"
+ "source_tree_sha": "0934dd0bb3220d0aaaef80c1e808471f64011b53"
},
"schema_version": "1.0",
"truths": {
@@ -3984,6 +3984,11 @@
"owner_skill": "ls-github-publishing-workflow",
"path": "ls/docs/releases/4.44.2.md"
},
+ {
+ "owner_package": "",
+ "owner_skill": "ls-github-publishing-workflow",
+ "path": "ls/docs/releases/4.44.3.md"
+ },
{
"owner_package": "",
"owner_skill": "ls-github-publishing-workflow",
@@ -5566,14 +5571,14 @@
}
},
"version": {
- "facts_version": "4.44.2",
- "pyproject_version": "4.44.2",
+ "facts_version": "4.44.3",
+ "pyproject_version": "4.44.3",
"sources": [
"VERSION",
"pyproject.toml",
"ls/docs/_generated/facts.json"
],
- "value": "4.44.2"
+ "value": "4.44.3"
},
"workflow_catalog": {
"sources": [
diff --git a/ls/docs/_generated/facts.json b/ls/docs/_generated/facts.json
index 8b07e3f4..b108a6c8 100644
--- a/ls/docs/_generated/facts.json
+++ b/ls/docs/_generated/facts.json
@@ -125,16 +125,16 @@
],
"provenance": {
"artifact_path": "ls/docs/_generated/facts.json",
- "artifact_sha256": "9a883978ba8108e75a74f7d9acb1b7d7164168aa01268674e813c0633ce0ad11",
+ "artifact_sha256": "1c86d5a0c1bf795b08b525d54a4dd0976f9832a4812dd09da79176522a15cda9",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"schema_version": 1,
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_dirty": false,
- "source_provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_root_id": "ae93ec666af9b56a17213e46181088d8d30fe885b2e6a08a36d04e0129603ab6",
+ "source_provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_root_id": "f3def3b041a3e6061a0e969dd62f48785d6961a5d9a0e29bf46edcfc67c43ffb",
"source_tag": null,
- "source_tree_sha": "cfa4d4d3e862321008fc808af2470d02489a4b38"
+ "source_tree_sha": "0934dd0bb3220d0aaaef80c1e808471f64011b53"
},
"skill_count": 105,
"skills": [
@@ -1878,7 +1878,7 @@
"version": "1.0"
}
],
- "version": "4.44.2",
+ "version": "4.44.3",
"workflow_count": 18,
"workflows": [
{
diff --git a/ls/docs/_generated/implementation-file-map.md b/ls/docs/_generated/implementation-file-map.md
index 447065dd..2d7115a6 100644
--- a/ls/docs/_generated/implementation-file-map.md
+++ b/ls/docs/_generated/implementation-file-map.md
@@ -1,11 +1,11 @@
---
localsetup_provenance:
schema_version: 1
- source_provenance_hash: 6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67
+ source_provenance_hash: d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe
emitter: generate-docs
-framework_version: 4.44.2
-source_commit: ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe
-artifact_sha256: 45e969f9a320d4fdb37545799c61e1755cb7ad758cc70e7f996d6d70be00c827
+framework_version: 4.44.3
+source_commit: 213176b18d5683d0354d6de307692589e2879185
+artifact_sha256: d520742ca107cb99ddb93daac1110d2c2c604cb5c50040fa93f22e82d769de64
---
# Implementation File Map
@@ -593,6 +593,8 @@ artifact_sha256: 45e969f9a320d4fdb37545799c61e1755cb7ad758cc70e7f996d6d70be00c82
| `keep` | `ls/docs/releases/4.44.1.md` |
| `keep` | `ls/docs/releases/4.44.2.json` |
| `keep` | `ls/docs/releases/4.44.2.md` |
+| `keep` | `ls/docs/releases/4.44.3.json` |
+| `keep` | `ls/docs/releases/4.44.3.md` |
| `keep` | `ls/docs/releases/5.6.2.json` |
| `keep` | `ls/docs/releases/5.6.2.md` |
| `keep` | `ls/docs/scrapling-cheat-sheet.md` |
diff --git a/ls/docs/_generated/platform-adapters.md b/ls/docs/_generated/platform-adapters.md
index 8991ce8c..bc3ed8c6 100644
--- a/ls/docs/_generated/platform-adapters.md
+++ b/ls/docs/_generated/platform-adapters.md
@@ -1,10 +1,10 @@
---
localsetup_provenance:
schema_version: 1
- source_provenance_hash: 6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67
+ source_provenance_hash: d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe
emitter: generate-docs
-framework_version: 4.44.2
-source_commit: ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe
+framework_version: 4.44.3
+source_commit: 213176b18d5683d0354d6de307692589e2879185
artifact_sha256: 5ce4949227d75f75f72c4ce822e3c0e7958e57a16acf1fdc16a050a35da5d212
---
# Platform Adapters
diff --git a/ls/docs/_generated/plugin-packs.json b/ls/docs/_generated/plugin-packs.json
index 108af720..452bb31b 100644
--- a/ls/docs/_generated/plugin-packs.json
+++ b/ls/docs/_generated/plugin-packs.json
@@ -384,14 +384,14 @@
"artifact_path": "ls/docs/_generated/plugin-packs.json",
"artifact_sha256": "10694f65c9b3a5ec0b56c979b22c85c6ef175b19cb7ae8e109c32047db071763",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"schema_version": 1,
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_dirty": false,
- "source_provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_root_id": "ae93ec666af9b56a17213e46181088d8d30fe885b2e6a08a36d04e0129603ab6",
+ "source_provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_root_id": "f3def3b041a3e6061a0e969dd62f48785d6961a5d9a0e29bf46edcfc67c43ffb",
"source_tag": null,
- "source_tree_sha": "cfa4d4d3e862321008fc808af2470d02489a4b38"
+ "source_tree_sha": "0934dd0bb3220d0aaaef80c1e808471f64011b53"
},
"schema_version": 1
}
diff --git a/ls/docs/_generated/plugin-packs.md b/ls/docs/_generated/plugin-packs.md
index db06c366..bc18cb88 100644
--- a/ls/docs/_generated/plugin-packs.md
+++ b/ls/docs/_generated/plugin-packs.md
@@ -1,10 +1,10 @@
---
localsetup_provenance:
schema_version: 1
- source_provenance_hash: 6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67
+ source_provenance_hash: d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe
emitter: generate-docs
-framework_version: 4.44.2
-source_commit: ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe
+framework_version: 4.44.3
+source_commit: 213176b18d5683d0354d6de307692589e2879185
artifact_sha256: e02a483284c21311b7766cc75341dc0cb10a976eae377fd1ee429ba8c33b7800
---
# Plugin Packs
diff --git a/ls/docs/_generated/skill-packs.md b/ls/docs/_generated/skill-packs.md
index ba7a6c50..2d4838b1 100644
--- a/ls/docs/_generated/skill-packs.md
+++ b/ls/docs/_generated/skill-packs.md
@@ -1,10 +1,10 @@
---
localsetup_provenance:
schema_version: 1
- source_provenance_hash: 6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67
+ source_provenance_hash: d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe
emitter: generate-docs
-framework_version: 4.44.2
-source_commit: ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe
+framework_version: 4.44.3
+source_commit: 213176b18d5683d0354d6de307692589e2879185
artifact_sha256: 7d82d4aff296de701c4b807383efd1a29c91da98d571fc81f31c8f544d3d7e04
---
# Skill And Workflow Packs
diff --git a/ls/docs/_generated/skill-taxonomy.json b/ls/docs/_generated/skill-taxonomy.json
index 7b38baa5..2702a149 100644
--- a/ls/docs/_generated/skill-taxonomy.json
+++ b/ls/docs/_generated/skill-taxonomy.json
@@ -13,14 +13,14 @@
"artifact_path": "ls/docs/_generated/skill-taxonomy.json",
"artifact_sha256": "6dbaf28f6a3169d873c87830a966e298aba185cb24fa376de49f7c60d04288a9",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"schema_version": 1,
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_dirty": false,
- "source_provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_root_id": "ae93ec666af9b56a17213e46181088d8d30fe885b2e6a08a36d04e0129603ab6",
+ "source_provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_root_id": "f3def3b041a3e6061a0e969dd62f48785d6961a5d9a0e29bf46edcfc67c43ffb",
"source_tag": null,
- "source_tree_sha": "cfa4d4d3e862321008fc808af2470d02489a4b38"
+ "source_tree_sha": "0934dd0bb3220d0aaaef80c1e808471f64011b53"
},
"schema_version": 1,
"skills": [
diff --git a/ls/docs/_generated/skill_aliases.json b/ls/docs/_generated/skill_aliases.json
index e12e775a..213e96f2 100644
--- a/ls/docs/_generated/skill_aliases.json
+++ b/ls/docs/_generated/skill_aliases.json
@@ -108,13 +108,13 @@
"artifact_path": "ls/docs/_generated/skill_aliases.json",
"artifact_sha256": "1722c982e3a57fba80937413be0cc2d4de4590e41b2b8d6a7f55d99bf0b9eaab",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"schema_version": 1,
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_dirty": false,
- "source_provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_root_id": "ae93ec666af9b56a17213e46181088d8d30fe885b2e6a08a36d04e0129603ab6",
+ "source_provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_root_id": "f3def3b041a3e6061a0e969dd62f48785d6961a5d9a0e29bf46edcfc67c43ffb",
"source_tag": null,
- "source_tree_sha": "cfa4d4d3e862321008fc808af2470d02489a4b38"
+ "source_tree_sha": "0934dd0bb3220d0aaaef80c1e808471f64011b53"
}
}
diff --git a/ls/docs/_generated/workflow-catalog.json b/ls/docs/_generated/workflow-catalog.json
index 769c879a..c46316a1 100644
--- a/ls/docs/_generated/workflow-catalog.json
+++ b/ls/docs/_generated/workflow-catalog.json
@@ -4,14 +4,14 @@
"artifact_path": "ls/docs/_generated/workflow-catalog.json",
"artifact_sha256": "975b246dd410e6393fcd601f10bbad641470355afac42c64e00252a1c7bb7425",
"emitter": "generate-docs",
- "framework_version": "4.44.2",
+ "framework_version": "4.44.3",
"schema_version": 1,
- "source_commit": "ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe",
+ "source_commit": "213176b18d5683d0354d6de307692589e2879185",
"source_dirty": false,
- "source_provenance_hash": "6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67",
- "source_root_id": "ae93ec666af9b56a17213e46181088d8d30fe885b2e6a08a36d04e0129603ab6",
+ "source_provenance_hash": "d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe",
+ "source_root_id": "f3def3b041a3e6061a0e969dd62f48785d6961a5d9a0e29bf46edcfc67c43ffb",
"source_tag": null,
- "source_tree_sha": "cfa4d4d3e862321008fc808af2470d02489a4b38"
+ "source_tree_sha": "0934dd0bb3220d0aaaef80c1e808471f64011b53"
},
"workflows": [
{
diff --git a/ls/docs/migration/skill-alias-map.md b/ls/docs/migration/skill-alias-map.md
index 9b2aa4b5..92a81daa 100644
--- a/ls/docs/migration/skill-alias-map.md
+++ b/ls/docs/migration/skill-alias-map.md
@@ -4,10 +4,10 @@ version: 4.44
owner_package: generate-docs
localsetup_provenance:
schema_version: 1
- source_provenance_hash: 6f5c26907e30347f7d8258fe7ff29b10992aca9cf0d71f73f979e3e7a1311b67
+ source_provenance_hash: d772a3cbe049ca55d4bdb809c8f6982b9250f0b64c5db8dce2f9a80def1ee5fe
emitter: generate-docs
-framework_version: 4.44.2
-source_commit: ac1e60dfd89c519b5b32cd32d4f4e0a3784000fe
+framework_version: 4.44.3
+source_commit: 213176b18d5683d0354d6de307692589e2879185
artifact_sha256: feec8f322054829e48dfa4b1c0d2c3d532cabbdd153a4a50b45babe566e30595
---
# Skill Alias Map
diff --git a/ls/docs/releases/4.44.3.json b/ls/docs/releases/4.44.3.json
new file mode 100644
index 00000000..c828d67e
--- /dev/null
+++ b/ls/docs/releases/4.44.3.json
@@ -0,0 +1,34 @@
+{
+ "schema_version": 1,
+ "version": "4.44.3",
+ "source_commit": "f44ecd55dcdc9e5516876b35001a99cb1e9d14b0",
+ "baseline_tag": "v4.44.1",
+ "summary": "LocalSetup 4.44.3 includes the approved release-documentation QC budget updates and corrects the framework version recorded and checked in CycloneDX SBOMs. Release SBOMs use the completed archive's VERSION; source and installed SBOMs use the repository VERSION when present and fall back to the installed framework distribution version when it is absent. It follows the published v4.44.1 baseline after two sequential patch slices; the pushed v4.44.2 tag and its draft assets remain unchanged and unpublished.",
+ "highlights": [
+ {
+ "text": "**Longer release-docs QC sessions:** Preparation defaults to 800 completion calls and a 9,000-second (150-minute) whole-session budget. The hosted publish job allows 165 minutes total, with a 15-minute grace period; individual provider requests use a separate 180-second fallback timeout.",
+ "evidence": [".github/workflows/publish.yml", "ls/core/release_docs/agent.py", "ls/tests/test_release_docs_agent.py", "ls/tests/test_release_docs_workflow.py"]
+ },
+ {
+ "text": "**Framework-versioned SBOMs:** Release SBOMs use the framework VERSION stored in the completed archive. Source and installed SBOMs use the repository VERSION when present and fall back to the installed distribution version when it is absent. `verify-release` rejects missing, malformed, or stale release SBOM application versions. The separate pack-format value in artifact metadata remains `3`.",
+ "evidence": ["ls/core/package.py", "ls/tests/test_install_flow_docs_package_a.py", "ls/tests/test_install_flow_package_version_provenance.py"]
+ },
+ {
+ "text": "**Corrected 4.x release arithmetic:** v4.44.1 is the published baseline. Sequential patch arithmetic maps the QC and SBOM fixes to 4.44.2 and 4.44.3. The pushed v4.44.2 tag and its draft assets remain unchanged and unpublished; the 4.x major-line lock and historical release evidence remain in force.",
+ "evidence": [".localsetup-release.json", "AGENTS.md", "VERSION", "ls/docs/VERSIONING.md", "ls/docs/releases/4.44.2.json", "ls/docs/releases/4.44.2.md"]
+ }
+ ],
+ "compatibility": [
+ "The 800-call and 9,000-second session budgets are configurable with QC_LLM_MAX_CALLS and QC_LLM_TOTAL_DEADLINE_SECONDS. QC_LLM_TIMEOUT_SECONDS continues to control each provider request separately.",
+ "Release SBOMs bind to the archive's framework VERSION. Source and installed SBOMs read repository VERSION when present and use the installed distribution version when it is absent; artifact metadata retains its separate pack-format version. Installation layout and public command names do not change.",
+ "The active major-line policy remains 4.x. Published v5.6.2 and v4.22.9 historical assets remain unchanged."
+ ],
+ "update": [
+ "Update LocalSetup through the [quickstart instructions](https://github.com/CruxExperts/LocalSetup/blob/v4.44.3/ls/docs/QUICKSTART.md#update).",
+ "Repository maintainers can configure the model-call budget independently from the per-request timeout."
+ ],
+ "verification": [
+ "Before release, require the full Python suite and publish workflow checks to pass. Verify that the signed v4.44.3 tag points to the accepted source commit.",
+ "Download the release archive with its `.sha256` checksum and `.cdx.json` SBOM sidecar, then run `verify-release` as described in this guide."
+ ]
+}
diff --git a/ls/docs/releases/4.44.3.md b/ls/docs/releases/4.44.3.md
new file mode 100644
index 00000000..fbf13a1a
--- /dev/null
+++ b/ls/docs/releases/4.44.3.md
@@ -0,0 +1,45 @@
+---
+status: ACTIVE
+version: 4.44
+owner_skill: ls-github-publishing-workflow
+---
+
+# LocalSetup 4.44.3
+
+LocalSetup 4.44.3 includes the approved release-documentation QC budget updates and corrects the framework version recorded and checked in CycloneDX SBOMs. Release SBOMs use the completed archive's VERSION; source and installed SBOMs use the repository VERSION when present and fall back to the installed framework distribution version when it is absent. It follows the published v4.44.1 baseline after two sequential patch slices; the pushed v4.44.2 tag and its draft assets remain unchanged and unpublished.
+
+## Highlights
+
+- **Longer release-docs QC sessions:** Preparation defaults to 800 completion calls and a 9,000-second (150-minute) whole-session budget. The hosted publish job allows 165 minutes total, with a 15-minute grace period; individual provider requests use a separate 180-second fallback timeout.
+- **Framework-versioned SBOMs:** Release SBOMs use the framework VERSION stored in the completed archive. Source and installed SBOMs use the repository VERSION when present and fall back to the installed distribution version when it is absent. `verify-release` rejects missing, malformed, or stale release SBOM application versions. The separate pack-format value in artifact metadata remains `3`.
+- **Corrected 4.x release arithmetic:** v4.44.1 is the published baseline. Sequential patch arithmetic maps the QC and SBOM fixes to 4.44.2 and 4.44.3. The pushed v4.44.2 tag and its draft assets remain unchanged and unpublished; the 4.x major-line lock and historical release evidence remain in force.
+
+After publication, see the [release and downloads](https://github.com/CruxExperts/localsetup/releases/tag/v4.44.3) for release assets.
+
+## Compatibility
+
+The 800-call and 9,000-second session budgets are configurable with QC_LLM_MAX_CALLS and QC_LLM_TOTAL_DEADLINE_SECONDS. QC_LLM_TIMEOUT_SECONDS continues to control each provider request separately.
+
+Release SBOMs bind to the archive's framework VERSION. Source and installed SBOMs read repository VERSION when present and use the installed distribution version when it is absent; artifact metadata retains its separate pack-format version. Installation layout and public command names do not change.
+
+The active major-line policy remains 4.x. Published v5.6.2 and v4.22.9 historical assets remain unchanged.
+
+## Update
+
+Update LocalSetup through the [quickstart instructions](https://github.com/CruxExperts/LocalSetup/blob/v4.44.3/ls/docs/QUICKSTART.md#update).
+
+Repository maintainers can configure the model-call budget independently from the per-request timeout.
+
+For installation and source refresh, read the [quickstart update instructions](../QUICKSTART.md#update). Adapter changes follow the [adapter ownership guide](../ADAPTER_OWNERSHIP.md).
+
+## Verify the download
+
+Before release, require the full Python suite and publish workflow checks to pass. Verify that the signed v4.44.3 tag points to the accepted source commit.
+
+Download the release archive with its `.sha256` checksum and `.cdx.json` SBOM sidecar, then run `verify-release` as described in this guide.
+
+Download the framework archive with both its `.sha256` checksum and `.cdx.json` SBOM sidecars. Keep all three files in the same directory before running `verify-release`.
+
+```bash
+uv run --locked python ls/tools/localsetup.py --source-root . verify-release /path/to/localsetup-v4.44.3.tar.gz
+```
diff --git a/ls/tests/test_install_flow_docs_package_a.py b/ls/tests/test_install_flow_docs_package_a.py
index abc1537a..9f9e1487 100644
--- a/ls/tests/test_install_flow_docs_package_a.py
+++ b/ls/tests/test_install_flow_docs_package_a.py
@@ -416,6 +416,100 @@ def test_package_command_creates_output_parent(tmp_path: Path) -> None:
assert Path(package["sbom"]).is_file()
+def test_cyclonedx_uses_framework_version_and_keeps_pack_version_in_metadata(tmp_path: Path) -> None:
+ from ls.core import package as pkg
+
+ root = make_temp_repo(tmp_path)
+ artifact = tmp_path / "localsetup-public.tar.gz"
+
+ package = build_public_artifact(root, artifact)
+
+ framework_version = (root / "VERSION").read_text(encoding="utf-8").strip()
+ (root / "VERSION").write_text("9.99.99\n", encoding="utf-8")
+ pkg.write_cyclonedx_sbom(root, artifact, package["manifest"])
+ sbom = json.loads(Path(package["sbom"]).read_text(encoding="utf-8"))
+ assert sbom["metadata"]["component"]["version"] == framework_version
+ with tarfile.open(artifact, "r:*") as archive:
+ metadata_member = archive.extractfile("ls/artifact-metadata.json")
+ assert metadata_member is not None
+ artifact_metadata = json.loads(metadata_member.read().decode("utf-8"))
+ assert artifact_metadata["version"] == package["manifest"]["version"] == 3
+
+
+def test_public_packaging_rejects_missing_framework_version(tmp_path: Path) -> None:
+ root = make_temp_repo(tmp_path)
+ (root / "VERSION").unlink()
+
+ with pytest.raises(ValueError, match="framework VERSION not found"):
+ build_public_artifact(root, tmp_path / "localsetup-public.tar.gz")
+
+
+@pytest.mark.parametrize(
+ ("entries", "message"),
+ [
+ ([b"4.44.2\n", b"4.44.2\n"], "exactly one"),
+ ([None], "regular file"),
+ ([b"x" * 129], "128-byte limit"),
+ ([b"invalid"], "invalid framework VERSION"),
+ ([], "framework VERSION not found"),
+ ],
+ ids=["duplicate", "dangling-symlink", "oversized", "malformed", "missing"],
+)
+def test_archive_framework_version_rejects_malformed_entries(
+ tmp_path: Path, entries: list[bytes | None], message: str
+) -> None:
+ from ls.core import package as pkg
+
+ artifact = tmp_path / "malformed.tar.gz"
+ with tarfile.open(artifact, "w:gz") as archive:
+ for data in entries:
+ member = tarfile.TarInfo("VERSION")
+ if data is None:
+ member.type = tarfile.SYMTYPE
+ member.linkname = "missing-target"
+ archive.addfile(member)
+ else:
+ member.size = len(data)
+ archive.addfile(member, io.BytesIO(data))
+
+ with pytest.raises(ValueError, match=message):
+ pkg._framework_version_from_artifact(artifact)
+
+ sbom = tmp_path / "malformed.cdx.json"
+ sbom.write_text(
+ json.dumps({"metadata": {"component": {"name": "localsetup"}}, "components": []}),
+ encoding="utf-8",
+ )
+ failure = pkg.verify_cyclonedx_sbom(sbom, artifact, {})
+ assert failure["ok"] is False
+ assert message in failure["error"]
+
+
+def test_verify_release_rejects_missing_or_wrong_sbom_framework_version(tmp_path: Path) -> None:
+ root = make_temp_repo(tmp_path)
+ artifact = tmp_path / "localsetup-public.tar.gz"
+ package = build_public_artifact(root, artifact)
+ sbom = Path(package["sbom"])
+ original = json.loads(sbom.read_text(encoding="utf-8"))
+ expected_version = (root / "VERSION").read_text(encoding="utf-8").strip()
+
+ for invalid_version in (None, "0.0.0", "3"):
+ payload = json.loads(json.dumps(original))
+ component = payload["metadata"]["component"]
+ if invalid_version is None:
+ component.pop("version")
+ else:
+ component["version"] = invalid_version
+ sbom.write_text(json.dumps(payload, indent=2) + "\n", encoding="utf-8")
+
+ verified = verify_release_artifact(artifact)
+
+ assert verified["ok"] is False
+ sbom_check = next(check for check in verified["checks"] if check["name"] == "sbom")
+ assert sbom_check["ok"] is False
+ assert sbom_check["expected_framework_version"] == expected_version
+
+
def test_package_command_fails_when_leak_scan_finds_private_file(tmp_path: Path) -> None:
root = make_temp_repo(tmp_path)
tool = root / "ls" / "tools" / "localsetup.py"
diff --git a/ls/tests/test_install_flow_package_version_provenance.py b/ls/tests/test_install_flow_package_version_provenance.py
index b698f819..4272bdb4 100644
--- a/ls/tests/test_install_flow_package_version_provenance.py
+++ b/ls/tests/test_install_flow_package_version_provenance.py
@@ -40,6 +40,7 @@ def test_package_helpers_cover_error_and_mismatch_branches(tmp_path: Path, monke
root = tmp_path / "repo"
root.mkdir()
+ (root / "VERSION").write_text("7.8.9\n", encoding="utf-8")
(root / "pyproject.toml").write_text(
"[project]\nname = \"demo\"\ndependencies = [\"plain-package>=1\", \"locked==2.0\"]\n",
encoding="utf-8",
@@ -82,6 +83,8 @@ def test_package_helpers_cover_error_and_mismatch_branches(tmp_path: Path, monke
monkeypatch.setattr(pkg, "load_pack_config", lambda repo: fake_pack)
monkeypatch.setattr("ls.core.manifests.load_pack_config", lambda repo: fake_pack)
assert pkg.write_source_sbom(root, output)["component_count"] == 2
+ source_sbom = json.loads(output.read_text(encoding="utf-8"))
+ assert source_sbom["metadata"]["component"]["version"] == "7.8.9"
target = tmp_path / "target"
(target / ".localsetup").mkdir(parents=True)
@@ -89,7 +92,10 @@ def test_package_helpers_cover_error_and_mismatch_branches(tmp_path: Path, monke
json.dumps({"installed_skills": [str(tmp_path / "ls-a")], "installed_workflows": [str(tmp_path / "wf")]}),
encoding="utf-8",
)
- assert pkg.write_installed_sbom(root, target, tmp_path / "installed.cdx.json")["component_count"] == 2
+ installed_output = tmp_path / "installed.cdx.json"
+ assert pkg.write_installed_sbom(root, target, installed_output)["component_count"] == 2
+ installed_sbom = json.loads(installed_output.read_text(encoding="utf-8"))
+ assert installed_sbom["metadata"]["component"]["version"] == "7.8.9"
missing_meta = tmp_path / "missing-meta.tar.gz"
with tarfile.open(missing_meta, "w:gz"):
@@ -153,6 +159,23 @@ def test_package_helpers_cover_error_and_mismatch_branches(tmp_path: Path, monke
}
+def test_framework_version_for_repo_falls_back_to_installed_distribution(
+ tmp_path: Path, monkeypatch: pytest.MonkeyPatch
+) -> None:
+ from ls.core import framework_version as version_module
+ from ls.core import package as pkg
+
+ monkeypatch.setattr(version_module, "_source_version_path", lambda: None)
+ monkeypatch.setattr(version_module.metadata, "version", lambda name: "9.8.7" if name == "localsetup" else "")
+
+ root = tmp_path / "site-packages"
+ root.mkdir()
+ assert pkg._framework_version_for_repo(root) == "9.8.7"
+
+ (root / "VERSION").write_text("7.6.5\n", encoding="utf-8")
+ assert pkg._framework_version_for_repo(root) == "7.6.5"
+
+
def test_versioning_pure_and_check_branches(tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
from ls.core import versioning as ver
diff --git a/ls/tests/test_sdk_artifacts.py b/ls/tests/test_sdk_artifacts.py
index 89e1eb6c..4cf25f53 100644
--- a/ls/tests/test_sdk_artifacts.py
+++ b/ls/tests/test_sdk_artifacts.py
@@ -73,6 +73,10 @@ def test_public_sbom_checks_full_vendor_metadata_and_manifest_binding(tmp_path):
member = tarfile.TarInfo("vendor/lscli/" + name)
member.size = len(content)
archive.addfile(member, io.BytesIO(content))
+ content = (ROOT / "VERSION").read_bytes()
+ member = tarfile.TarInfo("VERSION")
+ member.size = len(content)
+ archive.addfile(member, io.BytesIO(content))
content = (ROOT / "uv.lock").read_bytes()
member = tarfile.TarInfo("uv.lock")
member.size = len(content)
diff --git a/pyproject.toml b/pyproject.toml
index f7a80137..adc6ec05 100644
--- a/pyproject.toml
+++ b/pyproject.toml
@@ -4,7 +4,7 @@ build-backend = "setuptools.build_meta"
[project]
name = "localsetup"
-version = "4.44.2"
+version = "4.44.3"
description = "Global-first LocalSetup skill pack manager"
requires-python = ">=3.12"
dependencies = [
diff --git a/uv.lock b/uv.lock
index 07952d20..26c3e15d 100644
--- a/uv.lock
+++ b/uv.lock
@@ -547,7 +547,7 @@ wheels = [
[[package]]
name = "localsetup"
-version = "4.44.2"
+version = "4.44.3"
source = { editable = "." }
dependencies = [
{ name = "anyio" },