Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .agents/skills/agents-shipgate/assets/advisory-pr-comment.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
# Advisory PR comment.
# Recommended starting point: runs the scanner on every PR, posts a summary
# comment, uploads the report as an artifact, and never fails the job.
Expand All @@ -18,9 +18,9 @@
- uses: actions/checkout@v4
with:
fetch-depth: 0
- uses: ThreeMoonsLab/agents-shipgate@v1.1.0
- uses: ThreeMoonsLab/agents-shipgate@v1.2.0
with:
ci_mode: advisory
diff_base: target
pr_comment: 'true'
shipgate_version: '1.1.0'
shipgate_version: '1.2.0'
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/bug_report.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ body:
id: version
attributes:
label: Agents Shipgate version
placeholder: "v1.1.0"
placeholder: "v1.2.0"
validations:
required: true
- type: dropdown
Expand Down
4 changes: 2 additions & 2 deletions .well-known/agents-shipgate.json
Original file line number Diff line number Diff line change
Expand Up @@ -73,12 +73,12 @@
],
"package": {
"pypi": "agents-shipgate",
"github_action": "ThreeMoonsLab/agents-shipgate@v1.1.0",
"github_action": "ThreeMoonsLab/agents-shipgate@v1.2.0",
"github_repo": "ThreeMoonsLab/agents-shipgate"
},
"release_status": {
"track": "verify-capable release",
"latest_release": "v1.1.0"
"latest_release": "v1.2.0"
},
"install": {
"pipx": "pipx install agents-shipgate",
Expand Down
6 changes: 6 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,11 @@
# Changelog

## Unreleased

### Changes

- Move the published-release pins, examples and adoption prompts to `v1.2.0` (contract 41) now that it is published, re-capture the README and quickstart `diff` answers from the published `1.2.0`, and re-measure the pilot ledger's Route H dry run on it. No schema or contract change. (#778)

## 1.2.0 - 2026-09-30

An advisory-channel minor release. It adds `diff --application`, which compares
Expand Down
47 changes: 24 additions & 23 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,8 @@ and source locations, in the package that holds the changed code's agents unless
`--scope` names one. See [application comparison](docs/application-comparison.md)
for scoped applications, moves, exact refs and coverage limits. Version availability
is recorded in the [CHANGELOG entry](CHANGELOG.md#application-comparison-without-prior-setup):
it is new in 1.2.0, so until 1.2.0 is published, use a source build containing the feature.
it is new in 1.2.0, the newest published release, so an older install needs
`pipx upgrade agents-shipgate` first.

## What did this PR change?

Expand All @@ -64,12 +65,13 @@ entry per changed grant or replaced rule. If the PR targets another branch, pass
`--base upstream/<pr-base>`. On a PR that widens a Claude Code allow rule,
drops a denial and adds an MCP server:

The example below is from this source tree. Its conditional review guidance and
its `launch source is mutable` note are **not yet released**; the published
`1.1.0` prints the same comparison without that guidance section or note.
**Released in `1.2.0`:** the example below is from the published `1.2.0`,
installed from PyPI into a clean virtualenv outside any checkout and run in a
clone. The previous release, `1.1.0`, prints the same comparison without the
conditional review guidance section and the `launch source is mutable` note.

```text
Agent capability diff origin/main (7063f900) -> working tree
Agent capability diff origin/main (5d1b9e23) -> working tree

⚠ high added claude-code .mcp.json
billing (command name npx; env keys BILLING_TOKEN)
Expand All @@ -92,8 +94,8 @@ What this run established:
.mcp.json (claude-code): compared; 1 row

Review question: Does the team intend these 3 declared capability changes (from 4 rows)?
Compared: base 7063f900 → working tree at HEAD ac6fbdcf, agents-shipgate 1.1.0.
Reproduce in that working tree: agents-shipgate diff --base 7063f90046e90a1673fe98f993cb77f7063ef396
Compared: base 5d1b9e23 → working tree at HEAD 58d2ac0c, agents-shipgate 1.2.0.
Reproduce in that working tree: agents-shipgate diff --base 5d1b9e236525699910f4d93e334d2f4425927062
Permission review guidance:
Conditional review choices only; current control permissions still apply. A PR note grants no authority.
- Change 2: .claude/settings.json
Expand All @@ -119,8 +121,8 @@ like these; `No static host-grant changes detected.` when no compared grant
differs; or `Cannot compare against <base>: <reason>` when an input could not be
read, which is an input limit and never a quiet pass. Either of the first two
can open with `Not compared:` and a list of sources the change did not touch
and `diff` could not read; nothing is claimed about those. This source tree,
and not the published `1.1.0`, also has a fourth answer, `Partial comparison
and `diff` could not read; nothing is claimed about those. Since `1.2.0` there
is also a fourth answer, `Partial comparison
against <base> …: <reason>`, where the only inputs it could not read are
plugin directories whose references stop inside them: it names each one as
`Not compared: <directory>`, shows the changes outside it, and says they are
Expand All @@ -131,8 +133,8 @@ each gave, which changed with no compared grant changing (so a zero-row `env`
or `apiKeyHelper` edit is not mistaken for no change: a file is unchanged only
when its bytes are), which changed with no row attributed to them, which only
one side read or published, and, when
the comparison was refused, which source left an inventory incomplete. This
source tree, and not the published `1.1.0`, also names a changed input that a
the comparison was refused, which source left an inventory incomplete. Since
`1.2.0` it also names a changed input that a
bounded, documented candidate list recognises but no reader of this entry
reads — a plugin's `mcp.json`, a plugin manifest's `mcpServers`,
`.cursor/hooks.json`, a nested `.claude/settings.json`, an external marketplace
Expand All @@ -158,9 +160,7 @@ answer, the `--base <ref>` recovery when no base can be detected, and the
Supported shell changes then add conditional human choices. They establish no
intent or runtime access and grant no authority. The `launch source is mutable`
note identifies the unversioned `npx` package declared by the added server; it
changes neither the row's severity nor the widening count. The source tree still
reports version `1.2.0`; that version string does not make this a published-wheel
capture.
changes neither the row's severity nor the widening count.

When the answer is useful and you want it on every pull request, add
[`examples/github-actions/14-host-only-advisory-pr.yml`](examples/github-actions/14-host-only-advisory-pr.yml):
Expand Down Expand Up @@ -237,7 +237,7 @@ projection of it. Five-minute version:
Host configuration alone needs none of this: [What did this PR
change?](#what-did-this-pr-change) is the whole route. [Route
H](docs/quickstart.md#route-h--no-manifest) adds a snapshot audit and an
optional committed baseline for jobs that want them, and `v1.1.0`'s discovery
optional committed baseline for jobs that want them, and `v1.2.0`'s discovery
routes host-only repositories there through `host_boundary_candidates`.
Filename detection never establishes verified permissions.

Expand Down Expand Up @@ -282,7 +282,7 @@ declared and statically discoverable surface says. See
[Limitations](#limitations) and [ROADMAP.md](ROADMAP.md).

> [!IMPORTANT]
> **Status: `v1.1.0`, advisory.** The published release makes no qualification
> **Status: `v1.2.0`, advisory.** The published release makes no qualification
> claim. Its defaults are advisory, and blocking CI is a policy you opt into
> explicitly. The decision engine is deterministic; the accuracy evidence is
> small-n and incomplete, and the parts below their bars are stated here rather
Expand Down Expand Up @@ -319,7 +319,7 @@ no-op over one. Alternatives — `pip`, `uv`, and zero-install `uvx` — are in
**not** need Python 3.12; the CLI installs separately.

**Two lines, two promises.** The advisory line publishes rows a reviewer
reads, and no authority to block anything by default; `v1.1.0` is an advisory
reads, and no authority to block anything by default; `v1.2.0` is an advisory
release. The gate line publishes blocking verdicts and keeps every
qualification bar. Each `v*` version is declared on exactly one line in
[`.github/release-channels.json`](.github/release-channels.json). Neither line
Expand All @@ -330,16 +330,17 @@ two months out of reach.

| Line | Carries | Install | Promises | Cadence |
| --- | --- | --- | --- | --- |
| **Advisory** | `diff`, `check`, `audit --host`, drift, advisory PR comments | `pipx install agents-shipgate` (`v1.1.0`), or an unqualified preview pre-release | plain-language capability rows; **no blocking authority** unless you configure a blocking policy | 14 days |
| **Qualified gate** | blocking verdicts backed by qualification evidence, receipts, attestations | a `v*` release declared on the qualified line; `v1.1.0` is not one | every bar in [`release-evidence-policy-decision.md`](docs/release-evidence-policy-decision.md) | on evidence only |
| **Advisory** | `diff`, `check`, `audit --host`, drift, advisory PR comments | `pipx install agents-shipgate` (`v1.2.0`), or an unqualified preview pre-release | plain-language capability rows; **no blocking authority** unless you configure a blocking policy | 14 days |
| **Qualified gate** | blocking verdicts backed by qualification evidence, receipts, attestations | a `v*` release declared on the qualified line; `v1.2.0` is not one | every bar in [`release-evidence-policy-decision.md`](docs/release-evidence-policy-decision.md) | on evidence only |

**Read [which build you get](docs/quickstart.md#which-build-you-get) before you
start.** The newest published release is `v1.1.0`, which implements runtime
contract `40` — the agent control envelope, `current-control.json` and
start.** The newest published release is `v1.2.0`, which implements runtime
contract `41` — the agent control envelope, `current-control.json` and
`--format agent-boundary-json` included — and is what `pipx install
agents-shipgate` installs. It ships on the advisory channel and makes no
qualification claim. The quickstart says what an older `v1.0.0` or `v0.15.0`
install lacks, and what the unqualified preview does and does not come with.
qualification claim. The quickstart says what an older `v1.1.0`, `v1.0.0` or
`v0.15.0` install lacks, and what the unqualified preview does and does not
come with.

## Where to go next

Expand Down
11 changes: 6 additions & 5 deletions ROADMAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@

> **Naming.** This project is **Agents Shipgate** (display name) / `agents-shipgate` (package, CLI, repo). See [`AGENTS.md` § Naming (canonical)](AGENTS.md#naming-canonical) for the full convention.

**Latest release: `v1.1.0`**
**Latest release: `v1.2.0`**
([release page](https://github.com/ThreeMoonsLab/agents-shipgate/releases/latest))
— a legibility and presentation-correctness release on the **advisory** channel
with no qualification claim. This line is checked against the
— the release that adds application comparison (`diff --application`) on the
**advisory** channel, with no qualification claim. This line is checked against the
actual release tag by the `release-tag-consistency` job in
[`ci.yml`](.github/workflows/ci.yml) on every push to `main`.

Expand Down Expand Up @@ -70,8 +70,9 @@ follows the [non-goals](#explicit-non-goals) and
**Adoption > completeness.** `v1.0.0` is published on PyPI and GitHub from
`bace7c1871834e0b3eb98e6f60c0627725c53a59`, and #777 moved the pins to it.
`v1.1.0` followed on 2026-09-22 from
`e3c6cb0c7657d9c53d4e29b2061d04dcf99a4e9b` on the same channel, and the current
pins name it. The `v1.0.0` [advisory statement](https://github.com/ThreeMoonsLab/agents-shipgate/releases/download/v1.0.0/advisory-statement.json)
`e3c6cb0c7657d9c53d4e29b2061d04dcf99a4e9b` and `v1.2.0` on 2026-10-01 from
`7fc61ef43d8ec5c906bc690765f4a1297dff4fda`, both on the same channel; the
current pins name `v1.2.0`. The `v1.0.0` [advisory statement](https://github.com/ThreeMoonsLab/agents-shipgate/releases/download/v1.0.0/advisory-statement.json)
records advisory defaults, blocking opt-in and no qualification claim. That
publication supersedes the pre-release sequencing in the historical record
below; it does not satisfy the separate qualified-gate obligations in #572.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -85,15 +85,17 @@
"ffe9272f9a0defd732a9a37dbc1e9450e6051b217d6a39741b835657470f6cb4",
"a1d1ef2e4f1a4d8fe0f1e57b7c1c71aca0beb8d7bd2bc87063840fec59b6ad32",
"9ac853f0d5eabd1e79812c74587d9af27916309e7ad3154ff880fc3e8b9ff5fc",
"ae1495dc5c950baac583813076c59bb602dc42f84c39a6f4b32b7c4250f4728f"
"ae1495dc5c950baac583813076c59bb602dc42f84c39a6f4b32b7c4250f4728f",
"160256b5892d5fb18a0e66250f2eee08be7abf2e2d1473e2112d29ad747a7223"
],
"prompts/stabilize-strict-mode.md": [
"ac9a176738ab2538d725c29ba302637bac6b287588e07d952aae352f85ab98cc",
"3e5c320b57c57ce91d5dcdf2b584d71c229cb5b046bda944b68dc2056693ec6a",
"12810569a6aa655b4d8a6ed384142a430eef367bf6fab51b1a9e614aeff1c1a8",
"db9a702784c64229ed15157ce369c90a3d75c02e82c78d2c39cc55135857dc80",
"00da293e63792ccaf980f82d525ac12073807f41fd2d78c5a95498054053e364",
"f6e00cc67cd064721358361f2f47e9b68cb55359642419e6c978f5cb474c7fef"
"f6e00cc67cd064721358361f2f47e9b68cb55359642419e6c978f5cb474c7fef",
"45a9b3bfcd41aa616f74644f52c95abf4d146ca30164276ff4954ddf0ab7b314"
],
"prompts/verify-agent-diff.md": [
"0c939414da7900b8f03f2a743e0f6b8f4d96f409c1d5cde038e27a98318bf486",
Expand All @@ -117,7 +119,8 @@
"b6f87f58f70b5920442f342b5118419ef685ad9f4ff8b0ff87c2729a92929786",
"7fd2c718e5dad94b231409a72710e05af1b231c3d495d8796c501a7e9493a394",
"52c23e0b713d8064129332553350cb61d9e2b5254ed8f53ed99457cc3bc8c8f7",
"73576619d8d140935949f1ca2b7ccbcea8109ad3546f649b53cd2d3e71cb6672"
"73576619d8d140935949f1ca2b7ccbcea8109ad3546f649b53cd2d3e71cb6672",
"82e290efca0d7c11f7bcc86d054290ddc9566101cd3d66c9e3eb9a18ba23ae79"
],
"prompts/decide-shipgate-relevance.md": [
"1bf8b9d91f081a246dcff14a84810ca5384f8e0987e4e7a8c0c5df56b151564c",
Expand All @@ -136,7 +139,8 @@
"4f92d6d0b254e602c993516e1dc5b77c64c87b3e7b5cb4967ddd5a140dd2d510",
"cbdb4868a68b76c4e46611e8718ebe9950e6b1088e87691c7b23b82d3b1476d9",
"be3079a2f41b66d2db19cfea14c57ccd80ab9047ef7d69eccf30e97fa1beca5b",
"0f4285d7261dbaaab5a201061d9e2187d57e6d2af839fbfb170eae0630acaa62"
"0f4285d7261dbaaab5a201061d9e2187d57e6d2af839fbfb170eae0630acaa62",
"ab28dd4fd777e1ff1100fdd343d39eeb5ba5831295e0cf7435cda7fb61d2e01f"
],
"prompts/fix-top-finding.md": [
"3745aebbf34a47c01b06e74e6d387080bbda9272f0aeec6998457cffa758fc54",
Expand Down
3 changes: 2 additions & 1 deletion adoption-kits/codex-skill/.agents-shipgate-kit-metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,8 @@
"0ac78bcb69d0bfbcb72a8b78e013f00778536ce2600cf363fb27beeff66892a9",
"7ef7ccb331a0171f0fb5580df4dad32003b230b150886a40d317a954ace0fb55",
"89580914407edd5516db10c8d7725f22c1a919e827e9b820115007a7a6caab31",
"fc819304ad838e4976e92afe64eba20289772360e7c23bd99588d3e88019a2a2"
"fc819304ad838e4976e92afe64eba20289772360e7c23bd99588d3e88019a2a2",
"0ece178f492d7590713529539c009d30faedb29cfb111abb5cdfd9eec7ac7006"
]
},
"bootstrap_legacy_sha256": {
Expand Down
8 changes: 4 additions & 4 deletions docs/agent-contract-current.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Current Agent Contract

Runtime contract v41, unreleased, names the changed inputs a host comparison
Runtime contract v41, new in 1.2.0, names the changed inputs a host comparison
does not read (#821). A zero-row comparison used to print "No static
host-grant changes detected" for a pull request that added a Cursor plugin's
`mcp.json` or moved a marketplace plugin's pinned `sha`, exactly as for a
Expand Down Expand Up @@ -28,7 +28,7 @@ file this entry reads. `minimum_control_contract_version`
stays `21`, and a `0.20` verifier reads with the search not recorded. See
[the migration note](../STABILITY.md#unread-changed-inputs-821).

Still contract v41, unreleased: a plugin directory a host comparison cannot
Still contract v41, new in 1.2.0: a plugin directory a host comparison cannot
compare no longer hides the changes outside it (#808). Where every blocking
limit that refused the comparison is a plugin-reference limit bounded by its
plugin directory, and no compared source depends on that directory, verifier
Expand Down Expand Up @@ -91,7 +91,7 @@ comparable. It moves neither #821's verifier `0.21` nor its capability diff
`0.4`, and `minimum_control_contract_version` stays `21`. See
[the migration note](../STABILITY.md#workflow-agent-launches-contract-v41-823).

The same unreleased runtime contract v41 also names what changed in a hook and
The same runtime contract v41, new in 1.2.0, also names what changed in a hook and
in an MCP server's launch arguments (#819). Host-grants inventory, baseline and
drift schemas move to `0.7`: a hook grant adds `handlers[]` (each handler's
group `matcher`, its `command` as `{executable, sha256}` and its `timeout`)
Expand Down Expand Up @@ -775,7 +775,7 @@ Downstream repos generated with
`init --agent-instructions=default` get the minimal local copy at
`.shipgate/agent-contract.json`.

- Latest release: `v1.1.0`
- Latest release: `v1.2.0`
- In-tree runtime: `1.2.0` — see [pyproject.toml](../pyproject.toml)
- Runtime contract: `41` (minimum control contract: `21`)
- Current report schema: `1.0`, frozen, superseding `0.43` — [`docs/report-schema.v1.0.json`](report-schema.v1.0.json); the `1.x` rules are in [`docs/report-1-0-contract.md`](report-1-0-contract.md)
Expand Down
6 changes: 3 additions & 3 deletions docs/ai-search-summary.md
Original file line number Diff line number Diff line change
Expand Up @@ -113,9 +113,9 @@ Per-agent guides cover [Codex](agents/use-with-codex.md),
[Claude Code](agents/use-with-claude-code.md), and
[Cursor](agents/use-with-cursor.md).

The current source tree is `1.2.0` (runtime contract 41, unreleased). The
latest published release is `v1.1.0` (runtime contract 40), on the advisory
channel with no qualification claim. In report v1.0,
The current source tree is `1.2.0` (runtime contract 41). The latest
published release is `v1.2.0` (runtime contract 41), on the advisory channel
with no qualification claim. In report v1.0,
`passed` is an evidence-backed static verdict: the configured root has a
complete reachable binding graph, every reachable action has complete,
conflict-free identity, binding, effect, and authority evidence, all applicable
Expand Down
6 changes: 3 additions & 3 deletions docs/application-comparison.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
# Application comparison without prior setup

**Availability:** new in 1.2.0; see the [CHANGELOG entry](../CHANGELOG.md#application-comparison-without-prior-setup).
Until 1.2.0 is published, run the source checkout's `./shipgate` or a build
containing the feature.
**Availability:** new in 1.2.0, the newest published release; see the
[CHANGELOG entry](../CHANGELOG.md#application-comparison-without-prior-setup).
An older install has no `--application`: `pipx upgrade agents-shipgate`.

For an OpenAI Agents SDK or Google ADK application, compare committed PR refs:

Expand Down
Loading
Loading