From 41ebae947f2e2f3af3f48f21df626444ade289dd Mon Sep 17 00:00:00 2001 From: rldyourmnd Date: Thu, 3 Sep 2026 15:39:03 +0500 Subject: [PATCH] feat: public output keeps private topology private Generated by the setup-systems release publisher at 0.0.59. This repository is generated: propose changes through its public issues and pull requests. --- CHANGELOG.md | 14 ++++++++++++++ Cargo.lock | 8 ++++---- Cargo.toml | 8 ++++---- README.md | 2 +- install.ps1 | 2 +- install.sh | 2 +- references/opencode-baseline.json | 2 +- .../skills/nddev-builder/references/validation.md | 4 ++-- 8 files changed, 28 insertions(+), 14 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 15e1b97..7e31de5 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -20,6 +20,20 @@ sibling project the same week this note was added. ## [Unreleased] +## [0.0.59] - 2026-09-03 + +Public output no longer names the private authoring topology. The +publisher generates repository-local commit and pull-request text, then scans +all seven rendered trees and both messages before the first push. The scanner +also found six builder references carrying the same coordinate; their generated +source now describes only the source workspace and tells a public reader to use +the public repository's issues. + +The boundary has a mutation control: it plants a private coordinate assembled +from fragments and requires the scanner to refuse it, while the scanner and +public policy never contain the forbidden literal themselves. Historical +commits remain immutable and untouched. + ## [0.0.58] - 2026-09-02 A removal answers three ways when nothing records what this build diff --git a/Cargo.lock b/Cargo.lock index aca44ec..1ddc6d7 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -66,7 +66,7 @@ checksum = "877a4ace8713b0bcf2a4e7eec82529c029f1d0619886d18145fea96c3ffe5c0f" [[package]] name = "harness-runtime" -version = "0.0.58" +version = "0.0.59" dependencies = [ "provider-v3", "serde", @@ -128,7 +128,7 @@ dependencies = [ [[package]] name = "opencode-setup-system" -version = "0.0.58" +version = "0.0.59" dependencies = [ "harness-runtime", "provider-v3", @@ -147,7 +147,7 @@ dependencies = [ [[package]] name = "provider-v3" -version = "0.0.58" +version = "0.0.59" dependencies = [ "serde", "serde_json", @@ -209,7 +209,7 @@ dependencies = [ [[package]] name = "setup-core" -version = "0.0.58" +version = "0.0.59" dependencies = [ "miniz_oxide", "serde", diff --git a/Cargo.toml b/Cargo.toml index 5771d5e..87a3b7c 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -8,7 +8,7 @@ members = [ ] [workspace.package] -version = "0.0.58" +version = "0.0.59" edition = "2024" rust-version = "1.89" license = "AGPL-3.0-or-later" @@ -23,9 +23,9 @@ sha2 = "0.11" # `setup-core::archive`); an inflate loop is not, because its bugs are # memory-safety bugs and it is not improved by being hand-written here. miniz_oxide = "0.9" -setup-core = { path = "crates/setup-core", version = "0.0.58" } -provider-v3 = { path = "crates/provider-v3", version = "0.0.58" } -harness-runtime = { path = "crates/harness-runtime", version = "0.0.58" } +setup-core = { path = "crates/setup-core", version = "0.0.59" } +provider-v3 = { path = "crates/provider-v3", version = "0.0.59" } +harness-runtime = { path = "crates/harness-runtime", version = "0.0.59" } [workspace.lints.rust] unsafe_code = "forbid" diff --git a/README.md b/README.md index 7646e38..6724490 100644 --- a/README.md +++ b/README.md @@ -179,7 +179,7 @@ release is a convenience, not the authorised copy. ```bash docker run --rm -v "$HOME/.config:/config" \ - ghcr.io/nddev-opennetwork/opencode-setup-system:0.0.58 \ + ghcr.io/nddev-opennetwork/opencode-setup-system:0.0.59 \ status --target /config/ --json ``` diff --git a/install.ps1 b/install.ps1 index 356e487..d64ea2b 100644 --- a/install.ps1 +++ b/install.ps1 @@ -7,7 +7,7 @@ # powershell -ExecutionPolicy Bypass -File install.ps1 -Version 0.1.0 [CmdletBinding()] param( - [string]$Version = "0.0.58", + [string]$Version = "0.0.59", [string]$InstallDir = "$env:LOCALAPPDATA\Programs\opencode-setup-system" ) $ErrorActionPreference = "Stop" diff --git a/install.sh b/install.sh index 4ebeb06..5888882 100644 --- a/install.sh +++ b/install.sh @@ -14,7 +14,7 @@ set -eu REPO="NDDev-OpenNetwork/opencode-setup-system" BINARY="opencode-setup-system" -VERSION="${1:-0.0.58}" +VERSION="${1:-0.0.59}" PREFIX="${OPENCODE_INSTALL_DIR:-$HOME/.local/bin}" case "$(uname -s)" in diff --git a/references/opencode-baseline.json b/references/opencode-baseline.json index 401cbfd..26bede6 100644 --- a/references/opencode-baseline.json +++ b/references/opencode-baseline.json @@ -333,7 +333,7 @@ "version": "1.18.26", "verified_at": "2026-09-02T00:40:45+00:00" }, - "setup_catalogue_digest": "sha256:2812d268ce40bb989667dcd8afb5632ada2aa73882608decbbed752731d399a9", + "setup_catalogue_digest": "sha256:db280f58e88697d8c2b6c041e97da7af323227138b4f65a40baf14c7bdc26d06", "previous_software_artifacts": { "command": "opencode", "shape": "gzip-tar", diff --git a/setups/nddev-builder/home/skills/nddev-builder/references/validation.md b/setups/nddev-builder/home/skills/nddev-builder/references/validation.md index c32c28f..c707202 100644 --- a/setups/nddev-builder/home/skills/nddev-builder/references/validation.md +++ b/setups/nddev-builder/home/skills/nddev-builder/references/validation.md @@ -3,8 +3,8 @@ ## Which repository you are in decides what you can run This setup ships in two places and the commands below exist in only one of them. -**They belong to the private authoring monorepo, `NDDev-it-com/setup-systems`, -which renders this public tree.** A checkout of this public repository carries +**They belong to the source workspace that publishes this public tree.** A +checkout of this public repository carries `crates/`, `setups/`, `references/` and `scripts/evidence.py` -- and neither `scripts/gate.sh` nor `tools/`.