diff --git a/.forgejo/workflows/quality.yml b/.forgejo/workflows/quality.yml deleted file mode 100644 index ed6be61..0000000 --- a/.forgejo/workflows/quality.yml +++ /dev/null @@ -1,48 +0,0 @@ -# Roda no Forgejo (homelab). GitHub Actions ignora .forgejo/ -# Source of truth continua no GitHub — só faça push no GH. -name: quality - -on: - push: - pull_request: - -jobs: - quality: - runs-on: docker - steps: - - name: Checkout - uses: actions/checkout@v4 - - - name: Detect stack - id: stack - run: | - set -e - echo "repo=$(basename "$GITHUB_REPOSITORY")" - if [ -f package.json ]; then echo "has_node=true" >> "$GITHUB_OUTPUT"; else echo "has_node=false" >> "$GITHUB_OUTPUT"; fi - if [ -f pyproject.toml ] || [ -f requirements.txt ] || [ -f setup.py ]; then echo "has_py=true" >> "$GITHUB_OUTPUT"; else echo "has_py=false" >> "$GITHUB_OUTPUT"; fi - if [ -f Cargo.toml ]; then echo "has_rust=true" >> "$GITHUB_OUTPUT"; else echo "has_rust=false" >> "$GITHUB_OUTPUT"; fi - if [ -f go.mod ]; then echo "has_go=true" >> "$GITHUB_OUTPUT"; else echo "has_go=false" >> "$GITHUB_OUTPUT"; fi - ls -la - - - name: Node check (if any) - if: steps.stack.outputs.has_node == 'true' - run: | - if command -v node >/dev/null 2>&1; then node -v; else echo "node n/a in image — skip"; fi - if [ -f package-lock.json ] || [ -f pnpm-lock.yaml ] || [ -f yarn.lock ] || [ -f bun.lockb ] || [ -f bun.lock ]; then - echo "lockfile present" - fi - # ponytail: no install/test yet — add when repo has standard scripts - if [ -f package.json ] && command -v node >/dev/null 2>&1; then - node -e "const p=require('./package.json'); console.log('name=', p.name||'(none)', 'scripts=', Object.keys(p.scripts||{}).join(','))" - fi - - - name: Python check (if any) - if: steps.stack.outputs.has_py == 'true' - run: | - if command -v python3 >/dev/null 2>&1; then python3 --version; else echo "python n/a"; fi - - - name: Quality gate (smoke) - run: | - echo "quality OK on Forgejo runner" - echo "sha=${GITHUB_SHA}" - echo "ref=${GITHUB_REF}" \ No newline at end of file diff --git a/CHANGELOG.md b/CHANGELOG.md index 879396d..c1b485f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,6 +1,6 @@ # Changelog -## 0.9.0 - 2026-07-23 +## 0.9.0 - 2026-07-24 - Added outcome-aware policies VF010-VF013 for money, customer, privileged, and destructive-data actions. - Added structurally verified outcome contracts for approval, durable audit, idempotency, amount and counterparty limits, failure notification, and recovery. diff --git a/docs/codex-for-oss-application.md b/docs/codex-for-oss-application.md index 74437ca..edfc161 100644 --- a/docs/codex-for-oss-application.md +++ b/docs/codex-for-oss-application.md @@ -10,15 +10,11 @@ Prepared: 2026-07-22 Official form rechecked: 2026-07-22 -Submission reported complete: 2026-07-24 - -The maintainer reported that the application was submitted. The ChatGPT-account email, OpenAI Organization ID, confirmation page, and exact submission timestamp remain private and are not stored in this repository. - ## Recommendation Submit in **English**, even through the PT-BR form. OpenAI publishes no language requirement and no evidence that language changes selection odds. English is recommended only to reduce translation friction for a global technical review. -Submit now that v0.9.0 is public. Do not wait for arbitrary star, fork, or PR targets. Vibeflow's strongest evidence is its Codex-native engineering, first real 92-node audit, and a public maintenance loop that turned community feedback into tested policy features. +Submit immediately after the v0.9.0 release on 2026-07-24. Do not wait for arbitrary star, fork, or PR targets. Vibeflow's strongest evidence is its Codex-native engineering, first real 92-node audit, and a public maintenance loop that turned community feedback into tested policy features. ## Copy-and-paste form @@ -98,44 +94,30 @@ These translations are for review only. Paste the English versions above into th Use these links only if OpenAI requests verification; the form has no dedicated evidence field. - Public MIT repository: -- Executable release: +- Executable release after Friday launch: - Reproducible demo: - Release and Red Team audit: - CI history: - Launch discussion: - Public r/n8n feedback that shaped v0.9: -- Public runtime feedback and anonymized-corpus offer: -- Recorded static/runtime evidence boundary: - Engineering PRs: ## Evidence snapshot -Captured on 2026-07-23 after release: +Refresh this section on 2026-07-24 immediately before submission. Current candidate evidence: - public repository with MIT license; -- public `v0.9.0` release, with v0.8.0 preserved in release history; +- `v0.9.0` release candidate, with v0.8.0 already public; - 36 adversarial tests passing locally and in remote Node.js 20, 22, and 24 CI; - dependency-free CLI, GitHub Action, and installable Codex plugin; -- 7 maintainer PRs merged with green CI, including the v0.9 implementation and release-evidence PR; -- 4 stars, 0 forks, and no verified external contributor yet; +- 5 maintainer PRs merged with green CI, including the v0.9 implementation PR; +- 2 stars, 0 forks, and no verified external contributor yet; - public r/n8n launch thread with several substantive comments that directly shaped VF010-VF013; - first real audit: anonymized 92-node workflow, 3 blocking findings, 57 warnings, no workflow mutation; - Codex used across product repositioning, implementation, review, Red Team, remediation, packaging, CI, release, real-workflow audit, and the community-feedback-driven v0.9 cycle. Do not describe maintainer PRs, the maintainer's own workflow, clones, or unattributed stars as external adoption. -## Post-submission evidence snapshot - -Captured on 2026-07-24: - -- an external Reddit commenter publicly validated the static-preflight/runtime-observability split; -- the commenter reported fail-open Code execution, error-as-data, and AI-output truncation cases from a community-workflow corpus; -- the commenter offered to run anonymized failing workflows through Vibeflow and share false positives; -- the linked Pisama node and runtime project were independently verified, including their separate MIT and fair-code licensing boundaries; -- no workflow fixture, false-positive result, PR, contributor relationship, partnership, or integration had been received or established at capture time. - -This is evidence of substantive community engagement and a prospective evaluation path, not evidence of adoption or contribution. - ## Confidentiality boundary Do not submit or link the full real-workflow audit. Application materials must not include: @@ -151,17 +133,16 @@ The approved public description is: **“a real, production-scale 92-node conver - [x] Repository is public and not archived. - [x] GitHub username is public. -- [x] Role is primary maintainer. +- [x] Role is principal maintainer. - [x] Repository URL is correct. - [x] Both requested benefits are selected. - [x] All narrative answers are under 500 characters. - [x] Real-workflow evidence is anonymized. - [x] Early adoption is described honestly. -- [x] Supply the exact ChatGPT-account email privately in the form; do not retain it in the repository. -- [x] Supply the OpenAI Organization ID privately in the form; do not retain it in the repository. +- [ ] Insert the exact ChatGPT-account email. +- [ ] Insert and verify the OpenAI Organization ID. - [ ] Re-read the current Program Terms immediately before submission. - [ ] Save the confirmation page and submission timestamp privately. -- [x] Application submission reported complete by the maintainer on 2026-07-24. ## After submission diff --git a/docs/community-launch-v0.9.md b/docs/community-launch-v0.9.md index 09e2bda..33b90c3 100644 --- a/docs/community-launch-v0.9.md +++ b/docs/community-launch-v0.9.md @@ -16,26 +16,6 @@ The v0.9 scope came from the public [original r/n8n launch thread](https://www.r Captured on 2026-07-22: the thread had 3 votes and several substantive comments. Treat the comments as product evidence; do not present the vote count as broad adoption. -## Post-release runtime feedback — 2026-07-24 - -Reddit user [`Fit_Preference_1795`](https://www.reddit.com/r/n8n/comments/1v3is1w/comment/ozbyh0f/) publicly described the runtime counterpart to Vibeflow's static checks and offered to test anonymized failing workflows against Vibeflow. The report identified three failure classes: - -- a `continueOnFail` Code node crash that leaves the execution marked successful; -- an error object flowing through an item's JSON as ordinary data; -- truncated AI output reaching downstream nodes despite valid JSON and a successful node status. - -The commenter also noted that intentional token caps must be distinguished from accidental truncation to avoid false positives. These cases reinforce the product boundary: Vibeflow can detect deterministic fail-open configuration or require a structural completeness guard, but it cannot observe runtime output or prove that an alert is watched. - -The linked [`n8n-nodes-pisama`](https://github.com/Pisama-AI/n8n-nodes-pisama) community node is MIT-licensed and forwards execution telemetry. Runtime detection is implemented by the separate, self-hostable [`pisama-n8n`](https://github.com/Pisama-AI/pisama-n8n) service under a fair-code license. Its public [July 2026 corpus campaign](https://github.com/Pisama-AI/pisama-n8n/blob/main/eval/campaigns/2026-07-guard-campaign.md) records 70 committed workflows, 67 real executions, and 19 observed-and-detected failures. The comment's 69-workflow report and the repository campaign are different snapshots and must not be combined into one metric. - -Evidence status at capture time: - -- verified: substantive public technical feedback and a public offer to provide anonymized false-positive evidence; -- not yet verified: receipt of the workflows, Vibeflow verdicts, false-positive count, or a shared interoperability contract; -- not claimed: partnership, external contribution, external user adoption, or a shipped Pisama integration. - -The smallest useful follow-up is three anonymized cases: fail-open Code execution, error-as-data, and intentional versus accidental truncation. A new Vibeflow rule should be added only when paired unsafe/safe fixtures expose a deterministic static signal. - ## Reddit — r/n8n ### Title diff --git a/docs/launch.md b/docs/launch.md index a6cc2a0..8ab115a 100644 --- a/docs/launch.md +++ b/docs/launch.md @@ -1,6 +1,6 @@ # v0.9.0 launch checklist -Released: 2026-07-23 +Target: Friday, 2026-07-24 ## Release gate @@ -9,11 +9,9 @@ Released: 2026-07-23 - [x] Local `npm run verify` and `npm audit --omit=dev` pass. - [x] QA, adversarial Red Team, and Guardião reviews are documented. - [x] Pull request CI passes on Node.js 20, 22, and 24. -- [x] Release commit is merged and tagged `v0.9.0`. -- [x] Released CLI and pinned Codex marketplace install successfully. -- [x] GitHub release is public and marked latest. - -Release: +- [ ] Release commit is merged and tagged `v0.9.0`. +- [ ] Released CLI and pinned Codex marketplace install successfully. +- [ ] GitHub release is published on Friday. ## Positioning diff --git a/docs/release-audit.md b/docs/release-audit.md index 31672ad..aa4a4c7 100644 --- a/docs/release-audit.md +++ b/docs/release-audit.md @@ -1,10 +1,10 @@ -# Release audit — v0.9.0 +# Release audit — v0.9.0 candidate -Released: 2026-07-23 +Target release: 2026-07-24 ## Decision -**APTO** within Vibeflow's documented static-preflight boundary. +**APTO COM RESSALVAS** for the Friday release, pending merge, tag, and released-install checks listed below. No blocking defect remains in the reviewed static-analysis boundary. Vibeflow can verify structural evidence in an exported workflow, but it cannot enforce authorization, amount limits, counterparty identity, audit durability, or recovery behavior in the executing systems. @@ -16,9 +16,6 @@ No blocking defect remains in the reviewed static-analysis boundary. Vibeflow ca - Text, JSON, SARIF, configuration validation, package packing, and CLI exit behavior are exercised. - `npm run verify`, `npm audit --omit=dev`, JSON parsing, and `git diff --check` pass locally. - The package remains dependency-free and targets Node.js 20+. -- The public `v0.9.0` tag resolves to release commit `7552eeca7cfdd56376eab2007988b81a9726fba4`. -- The released GitHub CLI package passes the safe refund fixture with zero findings and reports VF010, VF012, and VF013 for the unsafe refund fixture. -- The released Codex marketplace installs `vibeflow@vibeflow` version `0.9.0` in an isolated `CODEX_HOME`. ## Red Team @@ -59,15 +56,15 @@ The graph checks use actual `main` edges, require dominating controls, and rejec - an exported graph cannot prove a referenced credential, approval identity, SQL policy, external API limit, notification, or compensation works at runtime; - custom/community nodes may need explicit impact declarations or new regression-backed adapters; - repository owners may intentionally weaken policy outside `--locked` mode; -- remote Node 20/22/24 CI and released `npx`/plugin installation passed. +- remote Node 20/22/24 CI passed; released `npx`/plugin installation can only be confirmed after the candidate is tagged. ## Release blockers - [x] Pull request CI passes on Node.js 20, 22, and 24. -- [x] Release commit is merged without unrelated changes. -- [x] `v0.9.0` tag and GitHub release are public. -- [x] Released CLI and Codex plugin install paths are smoke-tested. +- [ ] Release commit is merged without unrelated changes. +- [ ] `v0.9.0` tag and GitHub release are published on 2026-07-24. +- [ ] Released CLI and Codex plugin install paths are smoke-tested. ## Final gate -There are zero known critical or high security findings in the released static-analysis boundary. Runtime enforcement remains explicitly outside the product claim. +There are zero known critical or high security findings in the candidate. The release remains **APTO COM RESSALVAS** until the remaining remote gates above are complete; a failed gate blocks publication or requires an immediate corrective release. diff --git a/docs/roadmap.md b/docs/roadmap.md index 44791a6..91ce4ac 100644 --- a/docs/roadmap.md +++ b/docs/roadmap.md @@ -4,7 +4,7 @@ Ship the executable reset: CLI, nine configurable policies, fixtures, tests, SARIF, GitHub Action, and Codex plugin. -## 0.9.0 — shipped 2026-07-23 +## 0.9.0 — target 2026-07-24 Separate dangerous nodes from dangerous outcomes. Add VF010-VF013, explicit outcome contracts, graph evidence for policy gates, safe/unsafe refund fixtures, and clear runtime boundaries.