Skip to content

release: v0.4.0 — Apache-2.0, core@v0.8.0, and a marketplace path that resolves - #21

Merged
bkd-dotcom merged 1 commit into
mainfrom
release-v0.4.0
Sep 1, 2026
Merged

release: v0.4.0 — Apache-2.0, core@v0.8.0, and a marketplace path that resolves#21
bkd-dotcom merged 1 commit into
mainfrom
release-v0.4.0

Conversation

@bkd-dotcom

Copy link
Copy Markdown
Member

Cuts signetry-claude-code v0.4.0 — and the first release ever tagged in this
repository.

The 0.3.0 in the changelog is not a tag you can install

CHANGELOG.md has a ## [0.3.0] — 2026-07-26 entry, but git tag here is empty. That
release was cut in the pre-move repo and its tag did not come across the org move, so
the repo has been sitting at "0.3.0 plus six weeks of unreleased work" with nothing
installable to point at. 0.4.0 is the first tag that exists here, and the changelog
now says so explicitly rather than leaving a reader to discover it.

Fixed: the documented install command was a 404

README.md told Claude Code users to run:

/plugin marketplace add bkd-dotcom/signetry-claude-code

That repository has not existed since the move to the Signetry org — so the plugin's
primary, first-line install path could not work for anyone who followed the README.
Now Signetry/claude-code. The marketplace name in
/plugin install signetry@signetry-claude-code is unchanged and still correct: it
comes from marketplace.json's name field, not the repo path.

Versions and pins

was now
.claude-plugin/marketplace.json (metadata.version) 0.3.0 0.4.0
signetry/.claude-plugin/plugin.json 0.3.0 0.4.0
signetry-core (6 sites, 5 files: README, both hooks, MCP launcher, admit skill) core@v0.7.0 core@v0.8.0
advisory reviewer workflow reviewer@v0.2.0 reviewer@v0.3.0

The unreleased changelog bullet claimed the pins were core@v0.6.0 and
reviewer@v0.1.2. Since none of that block ever shipped, the delta an adopter actually
receives is core@v0.8.0 / reviewer@v0.3.0, and the bullet now states that — a
changelog entry describes the release it ships in, not the commit that wrote it.

core@v0.8.0 brings the receipt conformance spec and suite, the policy registry
(signetry policies, signetry init --policy), and placeholder-provenance reporting.

@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Signetry Reviewer — 🟣 Escalate to a designated reviewer

Escalate to a designated reviewer — this PR touches security-sensitive surface (.github/workflows/reviewer.yml). No blocking issue was found automatically, but a human owner should sign off.

Deterministic gates (the authority)

Gate Status
Required status check — unknown
Secret scan ✅ clean
CI permission / OIDC ✅ no forbidden change
Dependency skew ✅ ok
All green

Findings (1, 0 blocking)

  • 🟡 Change touches a protected path: .github/workflows/reviewer.yml .github/workflows/reviewer.yml (via cross-check)
    • .github/workflows/reviewer.yml matches a protected pattern (.github/workflows/*). Changes here alter shared/foundational surface and warrant a designated reviewer.
    • Fix: Route to a code owner / architecture reviewer.

Sensitive surface

This PR changes security-sensitive paths that warrant a designated reviewer:

  • .github/workflows/reviewer.yml

Merge

A designated reviewer / code owner should sign off before merge (sensitive surface).

This review is advisory. It never merges on its own judgement — the deterministic gates + a human are the authority. Findings can have false negatives; a green bot verdict is not a guarantee.

@bkd-dotcom
bkd-dotcom merged commit 0e22777 into main Sep 1, 2026
2 checks passed
@bkd-dotcom
bkd-dotcom deleted the release-v0.4.0 branch September 1, 2026 16:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant