diff --git a/.claude-plugin/marketplace.json b/.claude-plugin/marketplace.json index 9e6ec928f..008774600 100644 --- a/.claude-plugin/marketplace.json +++ b/.claude-plugin/marketplace.json @@ -12,7 +12,7 @@ "description": "Turn feature requests into review-ready pull requests: issue, implementation, tests, a review-and-fix loop, and docs. Runs locally or on GitHub Actions, and is built for complex brownfield repos. Each week its retrospective reads what you actually merged and proposes improvements to your skill extensions.", "author": { "name": "Daniel Radman", "email": "daniel@radman.ai" }, "homepage": "https://github.com/The01Geek/prflow", - "version": "2.38.1", + "version": "2.38.2", "license": "MIT", "keywords": [ "implement", diff --git a/.claude-plugin/plugin.json b/.claude-plugin/plugin.json index 7b4b394a6..d18124ab2 100644 --- a/.claude-plugin/plugin.json +++ b/.claude-plugin/plugin.json @@ -1,7 +1,7 @@ { "name": "prflow", "displayName": "PRFlow", - "version": "2.38.1", + "version": "2.38.2", "description": "Turn feature requests into review-ready pull requests: issue, implementation, tests, a review-and-fix loop, and docs. Runs locally or on GitHub Actions, and is built for complex brownfield repos. Each week its retrospective reads what you actually merged and proposes improvements to your skill extensions.", "author": { "name": "Daniel Radman", diff --git a/.release/files.sha256 b/.release/files.sha256 index abff2c1ed..7d2bfc430 100644 --- a/.release/files.sha256 +++ b/.release/files.sha256 @@ -1,5 +1,5 @@ -ca033cb955e8f3385ebaedd1baed6e6d043776978ea663e77678810398dc5520 .claude-plugin/marketplace.json -ccca6124a39412480e415067988ddf715e36d3b287fef1ee57b13c4d1456dcea .claude-plugin/plugin.json +42de1193e793b802c22b9fe93f23906352855b3eabbdc9958ad38a445128b107 .claude-plugin/marketplace.json +43d4dcae8f30f042636f7ccf352f58da2741d99eacbcadb204d03cdf34b5296d .claude-plugin/plugin.json b81b9647cbf5e8fd8078f4ea5afa5ac51000687ac4586fa774b8ada97ff80b49 .gitattributes 3569df1f4094bb984d15b5c8bba72043e68615bfcad55b230661daae1ae3fb50 .github/CODEOWNERS d8cf5249d002c3686b669874fd605ee933606fd09f3e00357f2c7f48464ac78a .github/ISSUE_TEMPLATE/config.yml @@ -13,17 +13,17 @@ facfac1900a69019debe41c71942821cef551fb8e1e25b4368fffabd3be4a7fd .github/action a5642c1816e7e96167909f19671df8d89887df47d48b80fb67bd30eee1e4a26c .github/verify-release.py a0938b732ac36f44d25fe3325cbbc5e2a58376f181e7193706e6928fb92f71dd .github/workflows/devflow-implement.yml 3d5660177bdb71084f50078dbb55370a846479caf94d3d56e22f93ec90b53e4b .github/workflows/devflow.yml -e30c398b75cf601e0834a109664cef7dba29c24922beb7cf201cbb2b7a0ec782 .github/workflows/distribution-verify.yml +57cf38a7f05b6a5d072d2816e690acfd67743acca48facd266c3b5d13470ec42 .github/workflows/distribution-verify.yml 038b852c31965900ad2937c8bdbdf254b9e3374a84eed9b107f72d6d08518b04 .gitignore c3bfd19a8f504f74ee75cb46a0e53c9f7572bb42b0763232632494b6b7f88692 .prflow/config.example.json 29e7597db7fa1912f9a2c27c1ecba1f4a43089e00d0e1caa7c087730e7ec90ef .prflow/config.schema.json 2dc5f16cc30614f23cebdccbd1655027e74e390e98a7916b85993fb431f2bd62 .prflow/install-state.json de88ef01ff25c62f1ae6b978595b98383978f9d506ec1bb0e17c375486714e69 .prflow/lint-manifest.json 80fd2b66301ff216f72292a2c45d56340ff50329a083612fdd9be9d9742fa53c .prflow/tool-presets.json -bd519fcd997560e439cc783508bef9d93e0035018b80ff19b734a3298579d101 .release/source.json -2f431aaf4f4ffe604934adbce39ded0fff717196b6057e7f6be66a7fe3411225 CITATION.cff +b9d3421382f2f0efdd55332fb0ff443bd17703b4e213477b63b0fa5487b736b1 .release/source.json +fc3cc417b4fa007828230be1cd0ffcffa85b34dfadc34ae9015d6eba6e6d77f3 CITATION.cff 288c11f7a44605139bca53ded61ba56a1f4f9dabc53b038be4a509c2d22e93aa CODE_OF_CONDUCT.md -d0ad1cce7066b03c90a6cf27aaabcb3ba8f7321683f249e038d66541e05b04f6 CONTRIBUTING.md +919eda4e47ed7154d7ddc09f116143b63bc189dda6e52c70e0cc57082a717adb CONTRIBUTING.md 73f76d9d5da2bcd153813fef4b018945419a67233cf38e450afdb2761589782f LICENSE ea914a3b65b598558ebc8c0be50252fcd56bda818d4c457730cb5369eeef3ad1 LICENSES/README.md cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30 LICENSES/feature-dev-LICENSE @@ -81,12 +81,12 @@ f428b17460b29e4f591f271c726315a18788fded88c4266cc68d114bc00cb75c docs/external/ 3266046bbc46dd4419d6cd3121b4165a2dab15404b1a2885e2cc0acfb0ca4345 docs/external/docs/reference/release-notes-archive-2026.md da398080f766e22f2aed0562b32343a05685368eca6ccb6b533525bf162304f4 docs/external/docs/runs/cloud/auto-review.md 27e2a313495828cbbed309ddbf283c8c4d97f88432835536327b1b570d345c6f docs/external/docs/runs/cloud/index.md -b47de365053ff9dcb350f6ce92acb93766bcb6eae99ac4a4e8bdc4f530508c2f docs/external/docs/runs/cloud/installation.md +839af49761008daca596b594b0176d62c6010fab742a24fd2e1c602d05e00f90 docs/external/docs/runs/cloud/installation.md 8f33d27592a276bce20bd22ad0ec0a858d17dc723222be9229d04e5220545a55 docs/external/docs/runs/cloud/recovery.md a8ea7f4b7f9b8dd8005530e9ccda73cb7bf2d6d1710c6072c432ffa6e4ef5757 docs/external/docs/runs/cloud/runners.md 98c2aba17e9cb6473e747a9e997de05031a44592fd2b4f122f29550b49d6b9f3 docs/external/docs/runs/cloud/setup.md 1d3529fff694cc2f5050101cea1ded9e3bc9e5d7bc9acf60d1de4e713faf1be4 docs/external/docs/runs/cloud/triggers.md -47287ce498e56c889c9aea018d43baef80fb7c0c7faf44295cb896c58f412051 docs/external/docs/runs/cloud/updates.md +ae7bfa30dd0706cd4c21a394ef02ee6fda726efcd621951dd2b143e6d64b1347 docs/external/docs/runs/cloud/updates.md 1081917d247cb0f70634fc08e06f3556eb5ec85b5d90bb079643016d6def5d93 docs/external/docs/runs/index.md 2fdf5aad7db89957404dbdf134afed0263dbb07fbe3e5a73cfaa90bf4d62bea9 docs/external/docs/runs/local/client-commands.md 278f9cc41cabeece613cb0b8c47ff44a899f06552d7a86eec0bf5579ae2ab8fa docs/external/docs/runs/local/index.md @@ -113,7 +113,7 @@ a446d5352123a365890aceca2d484aec79c2131b629c888195078a3a546bb263 docs/external/ ea21749d200bc56d2abc4840bcde00bf1befcd9e5e6303111494721309659f14 docs/external/images/workflow-skill-map.svg 41f0b74f88999c22c5a9e4251fcd57fb9e22abfcf6dba48d4bfc126bf84458ee docs/external/images/workpad-resume.svg eb7455d26518550f79813e873937f1cab70602c0ee7e86516bda131d4272aa33 docs/external/index.mdx -ade7e669ea815aaed6d6d68a657cd36704f81175cae352560647c0b29f5317a0 docs/external/release-notes.md +00fe91e580f442d41a99492f6cd197ff97f89f82ac7a6d98287da6b8957e0322 docs/external/release-notes.md d66e62b8bf728b5f648b9a0be23f2cd0c541bdb949a07b0aad795be32da2ffd9 docs/external/style.css 5d4c888f0e8d822f00b62297010949dba765cc51fedbe0c43e8ff611241b7bec docs/ship-pr.png bd795c2b4c69558e720d59cd24b42b9b00422fb12327c891548a405a722c52e4 install.sh diff --git a/.release/source.json b/.release/source.json index 593a6ce39..f08ea5f53 100644 --- a/.release/source.json +++ b/.release/source.json @@ -1,9 +1,9 @@ { "exporter_policy_version": "1.0.0", - "payload_byte_count": 8518122, + "payload_byte_count": 8520533, "payload_file_count": 436, - "plugin_version": "2.38.1", + "plugin_version": "2.38.2", "schema_version": 1, - "source_commit": "ed99e77b913d84ec9788f36539cd4ca82ef8050c", - "source_commit_time": "2026-08-29T16:04:26-06:00" + "source_commit": "82b6b43fe40fd445af7806335505152270e01edb", + "source_commit_time": "2026-08-29T17:45:30-06:00" } diff --git a/CITATION.cff b/CITATION.cff index 07aadd0b3..7c4aa0779 100644 --- a/CITATION.cff +++ b/CITATION.cff @@ -14,7 +14,7 @@ authors: repository-code: "https://github.com/The01Geek/prflow" url: "https://github.com/The01Geek/prflow" license: MIT -version: 2.38.1 +version: 2.38.2 keywords: - claude-code - agentic-ai diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 8079722b1..35af58265 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -14,6 +14,11 @@ That has one practical consequence: **a pull request that edits these files cannot be merged as-is.** The next release would overwrite it. This is not a judgement about the change — it is how the publication pipeline works. +The required `distribution-verify` check runs on your pull request and should be +green. It verifies published releases against the digests in `.release/`, and an +ordinary pull request is not a release — so a passing check says nothing about +whether the change will be accepted. + ## What to do instead **Report a bug, ask a question, or request a feature.** Open an issue. Issues are diff --git a/docs/external/docs/runs/cloud/installation.md b/docs/external/docs/runs/cloud/installation.md index 47eccd2b5..74618537b 100644 --- a/docs/external/docs/runs/cloud/installation.md +++ b/docs/external/docs/runs/cloud/installation.md @@ -20,7 +20,7 @@ Add PRFlow's optional GitHub Actions tier to a repository. Skip this page if you ```bash - curl -fsSL https://raw.githubusercontent.com/The01Geek/prflow/v2.38.1/install.sh -o devflow-install.sh + curl -fsSL https://raw.githubusercontent.com/The01Geek/prflow/v2.38.2/install.sh -o devflow-install.sh ``` @@ -30,7 +30,7 @@ Add PRFlow's optional GitHub Actions tier to a repository. Skip this page if you The URL selects the installer. `DEVFLOW_REF` selects the payload it installs. Use the same value in both places. ```bash - DEVFLOW_REF=v2.38.1 bash devflow-install.sh + DEVFLOW_REF=v2.38.2 bash devflow-install.sh ``` A first installation applies immediately. Add `--dry-run`, or set `DEVFLOW_DRY_RUN=1`, to preview instead. @@ -71,7 +71,7 @@ Add PRFlow's optional GitHub Actions tier to a repository. Skip this page if you The workflows fetch the plugin at run time into `.prflow/vendor/prflow/`, using the `prflow_version` pin in `.prflow/config.json`. The fetched tree is ignored and is not committed. ```bash - DEVFLOW_REF=v2.38.1 bash devflow-install.sh + DEVFLOW_REF=v2.38.2 bash devflow-install.sh ``` Choose this for a small install diff and a small update diff. @@ -80,7 +80,7 @@ Add PRFlow's optional GitHub Actions tier to a repository. Skip this page if you The plugin tree is committed to your repository instead. ```bash - DEVFLOW_VENDOR=1 DEVFLOW_REF=v2.38.1 bash devflow-install.sh + DEVFLOW_VENDOR=1 DEVFLOW_REF=v2.38.2 bash devflow-install.sh ``` Choose this when you want no run-time fetch and want the plugin bytes auditable in your own history. Expect a much larger install and update diff. diff --git a/docs/external/docs/runs/cloud/updates.md b/docs/external/docs/runs/cloud/updates.md index a9e77fa05..506771234 100644 --- a/docs/external/docs/runs/cloud/updates.md +++ b/docs/external/docs/runs/cloud/updates.md @@ -18,16 +18,16 @@ The installer is review-first on an update: it previews by default, and it never Download the newer installer and pass the same new tag as the payload. ```bash - curl -fsSL https://raw.githubusercontent.com/The01Geek/prflow/v2.38.1/install.sh -o devflow-install.sh + curl -fsSL https://raw.githubusercontent.com/The01Geek/prflow/v2.38.2/install.sh -o devflow-install.sh # read devflow-install.sh, then: - DEVFLOW_REF=v2.38.1 bash devflow-install.sh + DEVFLOW_REF=v2.38.2 bash devflow-install.sh ``` On an existing installation this runs in dry-run mode. It does not intentionally change your repository, though it can create temporary files, and it does execute the script you downloaded. Read that file before you run it. ```bash - DEVFLOW_REF=v2.38.1 bash devflow-install.sh --apply + DEVFLOW_REF=v2.38.2 bash devflow-install.sh --apply ``` This refreshes the managed workflows, the composite actions and the configuration schema. It backfills newly added configuration keys and preserves the values and arrays you already set. diff --git a/docs/external/release-notes.md b/docs/external/release-notes.md index a4100f332..360c31738 100644 --- a/docs/external/release-notes.md +++ b/docs/external/release-notes.md @@ -11,6 +11,20 @@ This page summarizes user-visible PRFlow changes. For a complete change history, ## August 29, 2026 +- **A pull request from a fork can pass the release verification check.** Artifact + verification is skipped for an ordinary pull request, because the digest manifest describes + the published release and any edit is a mismatch. That exemption was gated on the pull + request coming from the repository itself, so a contribution from a fork was verified + against the manifest instead and failed on every file it changed — an outside contributor + saw a red required check they could do nothing about. Origin no longer decides it. A + release candidate is still verified whatever its origin, and a fork that touches the + verifier is still refused. +- **A published tree carrying no provenance is refused.** The guard that rejects a missing + `.release/source.json` keyed on the branch name alone, and a push carries the branch name + `main` rather than a release branch name — so deleting that one file reported the whole + check as passing, on the published branch as well as on the pull request that removed it. A + push without provenance, and a pull request that deletes provenance the branch it targets + carries, are both refused now. - **`/prflow:create-issue` now prints the drafted issue in chat only on request, keeping the saved-file path as the default presentation.** Step 4 writes the draft file and shows its path, the audit summary, the disclosures and the investigation record first — without the body — and @@ -43,8 +57,9 @@ This page summarizes user-visible PRFlow changes. For a complete change history, exemption that lets a maintainer change the verifier keyed on the branch name, and a fork chooses its own branch names — so a fork branch named `policy-update/…` skipped both the judge-comparison and the artifact verification, and reported the required check green on a - tree that had never been verified. Every exemption is now gated on the pull request coming - from the repository itself; a fork always takes the strict path. + tree that had never been verified. The judge-comparison step's exemptions are now gated on + the pull request coming from the repository itself, so a fork can never introduce or edit + the verifier that judges it. - **The shipped workflows now declare a least-privilege floor.** They carried no top-level `permissions:`, so in a repository whose default workflow permission is read-and-write, every job received a full read-write token whether it needed one or not. They now default