Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 20 additions & 15 deletions .github/workflows/publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -104,10 +104,11 @@ jobs:
with:
subject-path: dist/localsetup-v*.tar.gz

- name: Publish GitHub release
- name: Prepare GitHub release draft
env:
GH_TOKEN: ${{ github.token }}
run: |
set -euo pipefail
version="$(cat VERSION)"
tag="v${version}"
if git rev-parse -q --verify "refs/tags/${tag}" >/dev/null; then
Expand All @@ -118,18 +119,22 @@ jobs:
exit 1
fi
fi
if gh release view "${tag}" >/dev/null 2>&1; then
gh release upload "${tag}" \
"dist/localsetup-v${version}.tar.gz" \
"dist/localsetup-v${version}.tar.gz.sha256" \
"dist/localsetup-v${version}.tar.gz.cdx.json" \
--clobber
else
gh release create "${tag}" \
"dist/localsetup-v${version}.tar.gz" \
"dist/localsetup-v${version}.tar.gz.sha256" \
"dist/localsetup-v${version}.tar.gz.cdx.json" \
--target "$GITHUB_SHA" \
--title "LocalSetup ${version}" \
--notes "Automated release for LocalSetup ${version}."
response="$(mktemp)"
errors="$(mktemp)"
trap 'rm -f "$response" "$errors"' EXIT
if gh api --include "repos/${GITHUB_REPOSITORY}/releases/tags/${tag}" >"$response" 2>"$errors"; then
echo "Release ${tag} already exists; reconcile its commit and assets before retrying." >&2
exit 1
elif ! grep -Eq '^HTTP/[0-9.]+ 404([[:space:]]|$)' "$response"; then
cat "$errors" >&2
echo "Could not establish that release ${tag} is absent; no draft created." >&2
exit 1
fi
gh release create "${tag}" \
"dist/localsetup-v${version}.tar.gz" \
"dist/localsetup-v${version}.tar.gz.sha256" \
"dist/localsetup-v${version}.tar.gz.cdx.json" \
--draft \
--target "$GITHUB_SHA" \
--title "LocalSetup ${version}" \
--notes "Draft awaiting the complete verified artifact set and release notes."
29 changes: 4 additions & 25 deletions .localsetup-release.json
Original file line number Diff line number Diff line change
@@ -1,31 +1,10 @@
{
"schema_version": 1,
"anchor": {
"commit": "1e03acd5a3bb339709cc8edc2596948674f73542",
"version": "4.4.0",
"tag": "v4.4.0"
"commit": "4eb7001370b1c49fe09dc3ee7b68b460fef9c82e",
"version": "4.22.6",
"tag": "v4.22.6"
},
"overrides": [
{
"commit": "99c804b20cc66e42eab25c81d50915951640b6f3",
"slice": "doctor-recorded-adapters",
"classification": "patch"
},
{
"commit": "8ee908f664eee3987d26a3bae062bbfc168422f3",
"slice": "doctor-recorded-adapters",
"classification": "patch"
},
{
"commit": "f33464ecc2b913a261ada49c0fdfd009c5fb2868",
"slice": "cryptography-maintenance",
"classification": "patch"
},
{
"commit": "a97333fefe8147e04dd7e5a8c684a5d64357aa64",
"slice": "lscli",
"classification": "minor"
}
],
"overrides": [],
"policy": "sequential-logical-slices"
}
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
<a href="ls/docs/PLATFORM_REGISTRY.md"><img src="https://img.shields.io/badge/platforms-cursor%20%7C%20claude--code%20%7C%20codex%20%7C%20openclaw%20%7C%20kilo%20%7C%20opencode-1f6feb" alt="Supported platforms"></a>
</p>

**Version:** 4.22.6<br>
**Version:** 4.22.7<br>

**LocalSetup gives coding agents a repo-local operating layer.**

Expand Down Expand Up @@ -71,7 +71,7 @@ Start with the [workflow packages guide](ls/docs/WORKFLOW_PACKAGES.md) for usage
<!-- facts-block:start -->
| Fact | Value |
|---|---|
| Current version | `4.22.6` |
| Current version | `4.22.7` |
| Supported platforms | `codex, claude-code, cursor, kilo, opencode, openclaw, github-copilot-cli, github-copilot-vscode, cline-cli, cline-vscode, amp-cli, goose-cli, pi-cli, hermes-agent, qwen-code-cli, kimi-cli, factory-droid, antigravity-app, gemini-cli, omp-cli` |
| Shipped skills | `103` |
| Workflow packages | `16` |
Expand Down
2 changes: 1 addition & 1 deletion VERSION
Original file line number Diff line number Diff line change
@@ -1 +1 @@
4.22.6
4.22.7
2 changes: 1 addition & 1 deletion ls/README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# LocalSetup Framework Engine

**Version:** 4.22.6<br>
**Version:** 4.22.7<br>

`ls/` is the engine that makes the public LocalSetup promise real. It stores the framework code, shipped skills, workflow packages, platform templates, docs, tests, and install manifests that turn a repository into a portable agent workspace.

Expand Down
12 changes: 6 additions & 6 deletions ls/config/branding.json
Original file line number Diff line number Diff line change
Expand Up @@ -427,25 +427,25 @@
},
{
"path": ".github/workflows/publish.yml",
"line_sha256": "2416beb161858dc9dc2b9944f4676a84a65f155fbb95a5259e137de506d346c0",
"line_sha256": "f485f655f9a8ce0ac0c0610cb91c3778321b9a62ac5333e4e43da982fb6ff815",
"token": "localsetup",
"count": 2,
"count": 1,
"kind": "compatibility_identifier",
"reason": "Release artifact filename, glob, or workflow artifact identifier; kept stable for downloads and verification."
},
{
"path": ".github/workflows/publish.yml",
"line_sha256": "a93d4a34f6b8abe906d586bb8c5aa6ab5405949126d75f80dcf9e44cd6b4e7ff",
"line_sha256": "ebd60c7aa861470f7d03b905e0fc7d23d8bdbd9eab37d45e6577e6c89fb7506e",
"token": "localsetup",
"count": 2,
"count": 1,
"kind": "compatibility_identifier",
"reason": "Release artifact filename, glob, or workflow artifact identifier; kept stable for downloads and verification."
},
{
"path": ".github/workflows/publish.yml",
"line_sha256": "23dbbeb4cbf566c79edd08a6445cb7abfb7f94aea3450e1807bca15ae29ca68b",
"line_sha256": "370e8a68f71b0a3cf0ceb0e899b5177807461a866eb58b70af1ffa6c0e2cfa84",
"token": "localsetup",
"count": 2,
"count": 1,
"kind": "compatibility_identifier",
"reason": "Release artifact filename, glob, or workflow artifact identifier; kept stable for downloads and verification."
},
Expand Down
2 changes: 1 addition & 1 deletion ls/docs/FEATURES.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ This is the full public capability catalog for LocalSetup. The [root README](../
## Generated Facts

<!-- facts-block:start -->
- Current version: `4.22.6`
- Current version: `4.22.7`
- Supported platforms: `codex, claude-code, cursor, kilo, opencode, openclaw, github-copilot-cli, github-copilot-vscode, cline-cli, cline-vscode, amp-cli, goose-cli, pi-cli, hermes-agent, qwen-code-cli, kimi-cli, factory-droid, antigravity-app, gemini-cli, omp-cli`
- Shipped skills: `103`
- Workflow packages: `16`
Expand Down
2 changes: 1 addition & 1 deletion ls/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ This is the public documentation map for LocalSetup. Start here when you want th
## Generated Facts

<!-- facts-block:start -->
- Current version: `4.22.6`
- Current version: `4.22.7`
- Supported platforms: `codex, claude-code, cursor, kilo, opencode, openclaw, github-copilot-cli, github-copilot-vscode, cline-cli, cline-vscode, amp-cli, goose-cli, pi-cli, hermes-agent, qwen-code-cli, kimi-cli, factory-droid, antigravity-app, gemini-cli, omp-cli`
- Shipped skills: `103`
- Workflow packages: `16`
Expand Down
4 changes: 2 additions & 2 deletions ls/docs/REPO_MAINTENANCE.md
Original file line number Diff line number Diff line change
Expand Up @@ -94,9 +94,9 @@ UV_CACHE_DIR=/tmp/localsetup-uv-cache uv run --locked python ls/tools/localsetup

- `pr-validation` is the required PR and merge-queue validation workflow.
- `generated docs and version sync` catches missing version-sync commits and generated-doc drift before merge.
- `framework validation py3.10` and `framework validation py3.12` cover the supported Python floor and current runtime.
- `framework validation py3.12` runs the Python 3.12 matrix entry, matching the supported Python floor.
- `shell smoke and framework audit` runs the shell wrapper, framework audit, and whitespace diff check.
- `publish` remains main-only and release-focused. It should not be a maintainer's first signal that version sync is missing.
- `publish` remains main-only and prepares a validated release draft. Complete its artifact inventory and notes before publication, following [VERSIONING.md](VERSIONING.md#github-release-workflow). It should not be a maintainer's first signal that version sync is missing.
- `triage` labels issues and PRs from metadata only. It must not check out or run untrusted pull request code.
- `triage` also bootstraps the maintainer label set used by issue forms and Dependabot. Run it manually once with `workflow_dispatch` before enabling Dependabot on a fresh repository.

Expand Down
6 changes: 3 additions & 3 deletions ls/docs/SKILLS.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,10 +4,10 @@ version: 4.22
owner_package: generate-docs
localsetup_provenance:
schema_version: 1
source_provenance_hash: aa225b3bfba81950501b0866317ec8fcd27daa1837de917ff6f4731edf965239
source_provenance_hash: 7606cd5551c8562625ea3e3f00b20c185eca9678cc99d4949a73141239152305
emitter: generate-docs
framework_version: 4.22.6
source_commit: d297ed234baa529c96bad872e51cfc0f31991489
framework_version: 4.22.7
source_commit: a8ab3af2d5ad5c30f678e4835340a141fa1c428f
artifact_sha256: 343858aac153c84fd907f5337bc49a95017ef66f2344a1d902516733549cf7e6
---
# Shipped skills catalog
Expand Down
23 changes: 21 additions & 2 deletions ls/docs/VERSIONING.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ LocalSetup uses the root `VERSION` file as the source of truth for the framework
## Current Version

- Source of truth: [`../../VERSION`](../../VERSION)
- Current value: `4.22.6`
- Current value: `4.22.7`
- Generated facts: [`_generated/facts.json`](_generated/facts.json)

## Policy
Expand Down Expand Up @@ -155,7 +155,26 @@ The `version-plan` output includes the selected `policy`, diagnostic `raw_bump`

## GitHub release workflow

On pushes to `main`, GitHub Actions verifies the computed version plan, confirms all version references and generated docs are committed, runs the framework validation suite, builds the public package artifact, verifies the tarball checksum and embedded artifact metadata, uploads the tarball plus `.sha256` and CycloneDX SBOM sidecars, attests the tarball when GitHub artifact attestation is available, and publishes tag/release `vX.Y.Z`. Existing tags must already point at the current commit or the workflow fails.
On pushes to `main`, GitHub Actions verifies the computed version plan, confirms all version references and generated docs are committed, runs the framework validation suite, builds the public package artifact, verifies the tarball checksum and embedded artifact metadata, uploads the tarball plus `.sha256` and CycloneDX SBOM sidecars, attests the tarball when GitHub artifact attestation is available, and prepares draft release `vX.Y.Z` at the validated commit. Existing tags must already point at that commit. Existing releases and uncertain API lookups stop preparation for explicit reconciliation; reruns never overwrite assets.

Complete the draft before publication. Attach the verified wheel/sdist and any
qualified native bundle, provenance, SBOM and corresponding source assets required
by the release. Verify the complete asset inventory, checksums, licenses, commit
identity and accurate release notes, then publish the existing draft:

```bash
gh release edit "v$(cat VERSION)" --notes-file release-notes.md
gh release edit "v$(cat VERSION)" --draft=false
```

These commands require existing publication authority and a reviewed payload.
`release-notes.md` denotes the prepared notes file; do not commit private release
preparation. Workflow success proves draft preparation, not completed publication.
Download the published assets and perform the exact-release acceptance checks.
With [immutable releases](https://docs.github.com/en/code-security/concepts/supply-chain-security/immutable-releases),
assets and the associated tag are fixed at publication. If required assets were
omitted, preserve that release and prepare a corrected patch release; do not
attempt to replace assets or move its tag.

## Verification

Expand Down
6 changes: 3 additions & 3 deletions ls/docs/WORKFLOW_QUICK_REF.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,10 +4,10 @@ version: 4.22
owner_package: generate-docs
localsetup_provenance:
schema_version: 1
source_provenance_hash: aa225b3bfba81950501b0866317ec8fcd27daa1837de917ff6f4731edf965239
source_provenance_hash: 7606cd5551c8562625ea3e3f00b20c185eca9678cc99d4949a73141239152305
emitter: generate-docs
framework_version: 4.22.6
source_commit: d297ed234baa529c96bad872e51cfc0f31991489
framework_version: 4.22.7
source_commit: a8ab3af2d5ad5c30f678e4835340a141fa1c428f
artifact_sha256: d463f0a8e4b4376945d747b5f5c35bf6cf6f552fee0f4ff6436a0cdd34549784
---
# Workflow quick reference
Expand Down
6 changes: 3 additions & 3 deletions ls/docs/WORKFLOW_REGISTRY.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,10 +4,10 @@ version: 4.22
owner_package: generate-docs
localsetup_provenance:
schema_version: 1
source_provenance_hash: aa225b3bfba81950501b0866317ec8fcd27daa1837de917ff6f4731edf965239
source_provenance_hash: 7606cd5551c8562625ea3e3f00b20c185eca9678cc99d4949a73141239152305
emitter: generate-docs
framework_version: 4.22.6
source_commit: d297ed234baa529c96bad872e51cfc0f31991489
framework_version: 4.22.7
source_commit: a8ab3af2d5ad5c30f678e4835340a141fa1c428f
artifact_sha256: 452fca485fafbcf02554a10723389a49513679b5f19b25ee3fe00acfdc3906c4
---
# Workflow and module registry (LocalSetup)
Expand Down
Loading
Loading