Skip to content

chore(main): release engine-and-dependents libraries#8146

Merged
JSONbored merged 4 commits into
mainfrom
release-please--branches--main--groups--engine-and-dependents
Jul 23, 2026
Merged

chore(main): release engine-and-dependents libraries#8146
JSONbored merged 4 commits into
mainfrom
release-please--branches--main--groups--engine-and-dependents

Conversation

@JSONbored

Copy link
Copy Markdown
Owner

🤖 I have created a release beep boop

engine: 3.5.0

3.5.0 (2026-07-23)

Features

  • calibration: deterministic seeded held-out/visible split of the backtest corpus (#8087) (#8097) (43b02c9)
  • calibration: Pareto-floor comparator between two BacktestScoreReports (#8086) (#8108) (0738a70)
  • calibration: pure BacktestCase corpus builder from fired/override events (#8093) (423a3d1)
  • calibration: pure confusion-matrix scorer for candidate rule classifiers (#8085) (#8098) (d07b057)
  • calibration: shared ORB+AMS signal-tracking module, with AMS wired live (#8079) (873ecf2)
  • engine: aggregate REGRESSED-verdict track-record statistics from persisted backtest CI results (#8140) (#8143) (4578fef)
  • engine: render backtest score and comparison reports as Markdown (#8088) (#8116) (5553138)
  • engine: represent idea targetRepo as an existing-vs-provision union (#7710) (d7042ef), closes #7635
  • governor: page PagerDuty on kill-switch trips (#8052) (8329069), closes #7666
  • review: add a config-as-code content-lane deliverable gate (#7703) (6c31631)
  • review: add config-as-code settings surface for the issue-planning tool (#7521) (37e7f86), closes #7429
  • review: add opt-in one-shot synchronize-amendment close policy (#7715) (a964eaf)
  • review: backtest confidence-threshold changes against real signal history in ORB's live gate (#8142) (9258836)
  • review: config-as-code manifest override for the loop-escalation sweep cron (#8018) (#8059) (f3cb090)
  • review: same-rule repeat alarm — detection + alert, no autonomous action (#8092) (321c192)
  • selfhost: per-repo opt-out for the active-review reconciliation sweep (#7880) (b76c91d)
  • visual: automatically detect hover interactions from CSS diffs (35631c3)
  • visual: automatically detect hover interactions from CSS diffs (5b8d150)
  • visual: capture hover/click interactions as animated GIF evidence (f4d27e6)
  • visual: capture hover/click/drag interactions as animated GIF evidence (c5d8671)
  • visual: maintainer-notify follow-up comment for unrelated visual findings (5c5c160)
  • visual: maintainer-notify follow-up comment for unrelated visual findings (3c50324)
  • visual: PR-intent-aware vision bug analysis + out-of-scope issue flagging (#7348) (e622684)
  • visual: support drag as an interaction-capture action (36319f9)

Fixes

  • advisory: redact the check-run leak terms sanitizePublicComment already caught (39a431b)
  • advisory: redact the check-run leak terms sanitizePublicComment already caught (3b956f4), closes #7074
  • content-lane: add snake_case aliases to protectedFrontmatterFields (#7445) (#7478) (37f6e06)
  • content-lane: add snake_case source-url aliases to sourceUrlFields (#7250) (#7269) (7571a78)
  • content-lane: recognize snake_case distribution and primary source fields (#7492) (90b01f6), closes #7446
  • draft: make draftPrClosePolicy config-as-code only (#7722) (30d039b)
  • engine: apply the JSON→YAML fallback in config-lint's canonical parser too (#7287) (d54bc35), closes #7244
  • engine: cap idea-intake acceptanceHints entry length (#7285) (93113d7), closes #7243
  • engine: correct mergeReadinessGateMode doc comment's sub-gate count (#7288) (341798a)
  • engine: diffFilePriority's vendored-directory pattern misses vendored/third_party/third-party/bower_components/jspm_packages (#7540) (1a019ab)
  • engine: don't charge per-file-skipped files against repo-map's aggregate budget (#7270) (e66f869)
  • engine: exclude evidence URLs from track-record blocklist scan (#7483) (ecf57ad), closes #7444
  • engine: extend #5831's repo-segment path-safety validation to governor/portfolio/worktree stores (#7554) (fadb5cc), closes #7525
  • engine: fold idea hints/constraints into the first draft's own explicit criteria (#7737) (0709850), closes #7730
  • engine: include inputTokenPattern in ruleSignature's deny-hook identity (#8126) (fbcba1e), closes #8013
  • engine: normalize computeMetadataDupRisk's self-skip repo comparison (#7734) (5430064), closes #7731
  • engine: preserve explicit zero pairwise calibration weights (#7477) (253dfcb), closes #7443
  • engine: protect the real post-#6203 autonomy/guardrail-config paths, not just their src/ shims (#8128) (d821cbd)
  • engine: redact secret-shaped titles from the public-safe results summary (#7279) (a0c3b33), closes #7249
  • engine: single-source the suspicious-label matcher so bestFitLabels can't drift (40c6349)
  • engine: single-source the suspicious-label matcher so bestFitLabels can't drift (0bcd64f), closes #7251
  • engine: tolerate a malformed repoFullName per-row in deny-hook blocker history (c0b4185)
  • engine: tolerate a malformed repoFullName per-row in deny-hook blocker history (744de48)
  • engine: treat a dangling dependsOn id as unsatisfied in plan-export ordering (#7738) (e8577cb), closes #7729
  • engine: trim attempt-id slug after truncation (#7551) (ed183a3)
  • miner: carry real assignees through the discovery-index supplement so the repo-owner exclusion applies (#7488) (e7cbb1b), closes #7442
  • miner: clamp out-of-contract usage from the iterate-loop running totals (#7246) (#7272) (d6134b2)
  • miner: grant Read/Bash in the agent-sdk driver's tool allowlist (#7245) (#7276) (d0617d1)
  • review: block the RFC 6598 CGNAT range in both safe-url twin guards (3c72fce)
  • review: block the RFC 6598 CGNAT range in both safe-url twin guards (3630700), closes #7253
  • review: close SSRF and lockfile-tamper detection gaps (#7826) (0ff0b8f)
  • review: correct the stale-base grounding fact and close the mergeable_state blind spot it depends on (#7686) (9e6691a)
  • review: ORB fairness analytics -- broken accuracy metric, public report, contributor trust profiles (#7581) (87843ab)
  • review: reject plain ws: in isSafeEndpointUrl, matching its own "secure" doc comment (#8131) (24929e3)
  • review: stop bare hotkey/coldkey mentions from false-positiving as secret leaks (#7994) (c73f518)
  • selfhost: stop delayed webhooks from resurrecting closed PRs' review tracking (#7839) (6ea4e28)
  • signals: single-source predicted-gate-engine isCodeFile so .kts counts as code (#7273) (c743eca), closes #7252
  • visual: address adversarial review findings on interaction capture (26a7a3b)
mcp: 3.5.0

3.5.0 (2026-07-23)

Features

  • api: REST + CLI mirror for loopover_watch_issues (#7153) (13cb8a3), closes #6746
  • engine: represent idea targetRepo as an existing-vs-provision union (#7710) (d7042ef), closes #7635
  • mcp: add remote + stdio + CLI surfaces for the selftune override audit (#7997) (050f8cb)
  • mcp: add remote + stdio MCP tool surfaces for loopover_get_activation_preview (#7887) (e8e5d89), closes #7799
  • mcp: add remote + stdio surfaces for loopover_get_ams_miner_cohort (#7935) (4f87f1a)
  • mcp: add remote + stdio surfaces for loopover_get_gate_config_effective (#7928) (03f9d9c), closes #7800
  • mcp: add remote + stdio surfaces for loopover_get_live_gate_thresholds (#7924) (510d25b), closes #7801
  • mcp: add remote + stdio surfaces for loopover_get_pr_maintainer_packet (#7926) (1257c20), closes #7802
  • mcp: add remote + stdio surfaces for loopover_get_registry_snapshot (#7917) (f27b9f0)
  • mcp: add remote + stdio surfaces for loopover_get_repo_focus_manifest (#7943) (bc042ed)
  • mcp: add remote + stdio surfaces for loopover_get_upstream_ruleset (#7921) (a97dd18), closes #7807
  • mcp: add REST route, CLI command, and stdio tool for loopover_plan_repo_issues (#7890) (b3e1bc3), closes #7764
  • mcp: register loopover_check_improvement_potential stdio tool (#7963) (a4c15d6)
  • mcp: register loopover_generate_contributor_issue_drafts as a local stdio tool (#7989) (6a55b8d)
  • mcp: register loopover_get_agent_audit_feed as a local stdio tool (#7971) (84a7878)
  • mcp: register loopover_get_automation_state as a local stdio tool (#7966) (ca738de)
  • mcp: register loopover_get_contributor_profile as a local stdio tool (#7760) (#7958) (3790ecd)
  • mcp: register loopover_get_outcome_calibration as a local stdio tool (#7877) (0af9f49)
  • mcp: register loopover_get_repo_onboarding_pack as a local (#7977) (b9aa25f)
  • mcp: register loopover_list_notifications as a local stdio tool (#7761) (#7965) (8c2950c)
  • mcp: register loopover_mark_notifications_read as a local stdio tool (#7950) (fa3581d), closes #7762
  • mcp: register loopover_propose_action as a local stdio tool (#7991) (7c1a21e)
  • mcp: register loopover_refresh_repo_docs as a local stdio tool (#7974) (4dccaa6), closes #7754
  • mcp: register loopover_watch_issues as a local stdio tool (#7961) (43099df), closes #7763

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @loopover/engine bumped from ^3.4.0 to ^3.5.0
miner: 3.5.0

3.5.0 (2026-07-23)

Features

  • calibration: shared ORB+AMS signal-tracking module, with AMS wired live (#8079) (873ecf2)
  • governor: page PagerDuty on kill-switch trips (#8052) (8329069), closes #7666
  • miner: add a dry-run full-execution mode to the cross-repo evaluation harness (#7668) (b764880), closes #7634
  • miner: add a hosted-container entry point for AMS cron-wake cycles (#7182) (#8070) (613e5fb)
  • miner: add a pr-outcomes CLI for the hosted contributor outcome history (#7998) (24ddd19)
  • miner: add AMS hosted-container health HTTP endpoint (#7177) (#7185) (53527e6)
  • miner: add tenant create/list/destroy control-plane admin CLI (#7284) (37ca8a5), closes #7275
  • miner: migrate policy-doc-cache onto the SqliteDriver store seam (aa95c0a)
  • miner: migrate policy-doc-cache onto the SqliteDriver store seam (5d19fe3), closes #7282
  • miner: roll the SqliteDriver seam onto the non-transactional local stores (#7558) (7cbaa5b)
  • miner: SqliteDriver store seam + migrate run-state (#7194) (c3660a2)
  • miner: wire the opt-in discovery-plane client into discover and attempt (#7220) (0959d4b), closes #7168
  • notifications: extend badge notifications to AMS attempt, governor-pause, and PR-outcome events (#8057) (17848e5), closes #7657

Fixes

  • engine: extend #5831's repo-segment path-safety validation to governor/portfolio/worktree stores (#7554) (fadb5cc), closes #7525
  • governor-state: make scalar-state saves atomic against concurrent writers (b031efa)
  • governor-state: make scalar-state saves atomic against concurrent writers (21e9d86), closes #7221
  • lint: avoid a comment-induced trailing-whitespace line in compiled opportunity-fanout.js (de94afb)
  • miner: add policy-doc-cache to doctor and migrate store lists (#7238) (#7263) (3aea7c7)
  • miner: bound the AMS export POST with a request timeout (#7237) (#7267) (a783cc1)
  • miner: carry real assignees through the discovery-index supplement so the repo-owner exclusion applies (#7488) (e7cbb1b), closes #7442
  • miner: fail closed on an unparseable lease in portfolio-queue findStuckItems (#8033) (bf8bb14), closes #8007
  • miner: fail closed when referencing PR has missing authorLogin (#7794) (#7824) (1b30e5b)
  • miner: log prompt-injection audit from buildTaskBrief (#7486) (8c2c81f)
  • miner: match the host's byte-range code-span exclusion + URL closing form in extractLinkedIssueNumbers (#7550) (f685074), closes #7527
  • miner: order pr-outcome map by event recency so disengagement streaks are correct (#7222) (#7239) (c953438)
  • miner: page contribution-profile label fetches past 100 (#8010) (#8040) (75daa84)
  • miner: purge contribution-profile-cache and governor-state's repo-scoped tables (#7091) (#7110) (6cb2c17)
  • miner: purge ranked-candidates, replay-snapshot, and deny-hook-synthesis stores by repo (#8009) (#8042) (8fcbfd9)
  • miner: reclaim worktree slots by lease age, not cross-container PID liveness (#7131) (237530a), closes #7085
  • miner: register ranked-candidates + deny-hook-synthesis in doctor/migrate store lists (#8036) (37369b9), closes #8008
  • miner: reject path-traversal repo segments in the 4 remaining normalizeRepoFullName parsers (#8065) (b788945), closes #7795
  • miner: reject path-traversal-shaped commitSha in replay-snapshot path planner (#7996) (2656eaa), closes #7796
  • miner: report a clean CLI failure when manage status collection throws (#7236) (#7266) (86d5d31)
  • miner: retry transient 5xx/rate-limit in contribution-profile getJson (#7126) (ec15d24), closes #7090
  • miner: retry transient live-state fetch in checkSubmissionFreshness before failing closed (#7129) (2183167), closes #7089
  • miner: scan coding-agent driver roots in env-reference generator (#6994) (#7154) (1d7248b)
  • miner: serialize repo clones across processes with a lockfile (#7084) (#7162) (051e969)
  • miner: size-guard cross-repo manifest by UTF-8 bytes, not UTF-16 length (#7223) (#7235) (92ccd34)
  • miner: sweep a claim with an unparseable claimedAt instead of retaining it forever (#7746) (352c49f), closes #7732
  • miner: wire policy_verdict_cache into purge/status/migrate local stores (#7136) (d0fbe82), closes #6987
  • portfolio: key the queue dashboard per-repo map by (apiBaseUrl, repoFullName) (#7241) (c7fbb82)
  • portfolio: scope per-repo WIP caps by forge host, not repo name alone (#7224) (#7261) (4cd3f24)
  • ranker: only flag default-goal-spec use when every ranked repo lacks one (#7226) (#7255) (a575ac2)
  • review: stop bare hotkey/coldkey mentions from false-positiving as secret leaks (#7994) (c73f518)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @loopover/engine bumped from ^3.4.0 to ^3.5.0

This PR was generated with Release Please. See documentation.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jul 23, 2026

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
loopover-ui 996d44e Commit Preview URL

Branch Preview URL
Jul 23 2026, 06:15 AM

@superagent-security

Copy link
Copy Markdown
Contributor

Superagent didn't find any vulnerabilities or security issues in this PR.

@codecov

codecov Bot commented Jul 23, 2026

Copy link
Copy Markdown

Bundle Report

Bundle size has no change ✅

@JSONbored JSONbored self-assigned this Jul 23, 2026
@codecov

codecov Bot commented Jul 23, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 92.04%. Comparing base (3fbde45) to head (996d44e).
⚠️ Report is 4 commits behind head on main.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #8146   +/-   ##
=======================================
  Coverage   92.04%   92.04%           
=======================================
  Files         765      765           
  Lines       77638    77638           
  Branches    23462    23463    +1     
=======================================
  Hits        71463    71463           
  Misses       5062     5062           
  Partials     1113     1113           
Flag Coverage Δ
shard-1 52.15% <ø> (-0.01%) ⬇️
shard-2 54.10% <ø> (ø)
shard-3 56.61% <ø> (-0.01%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

@loopover-orb loopover-orb Bot added the gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier. label Jul 23, 2026
@loopover-orb

loopover-orb Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Warning

⏸️ LoopOver review result - manual review recommended

Review updated: 2026-07-23 06:04:41 UTC

9 files · 1 AI reviewer · 1 blocker · CI green · dirty

⏸️ Suggested Action - Manual Review

Review summary
This is an automated release-please version-bump PR that syncs manifest/package.json/lockfile versions (3.4.x/3.4.1 -> 3.5.0) across engine/mcp/miner and appends the corresponding CHANGELOG entries. The version bumps are internally consistent: engine 3.4.1->3.5.0, mcp and miner 3.4.0->3.5.0, dependents' `@​loopover/engine` dependency ranges bumped to ^3.5.0, the miner's `expected-engine.version` file updated to 3.5.0, and package-lock.json mirrors all of it. No hand-written logic changed.

Nits — 4 non-blocking
  • The external brief's 'no SLSA/sigstore attestation' and 'long-file' package-lock.json flags are expected noise for an automated release-please PR and not actionable here.
  • This PR bundles release notes/version bumps for three packages together, but that's release-please's standard behavior, not a diff quality issue.
  • Confirm CI's publish step actually runs `npm run build` for loopover-engine before publish, since the changelog doesn't reflect any source changes beyond what was already merged to main.
  • Diff looks like trivial or whitespace-only churn — Reduce whitespace-only or formatting-only churn and keep the diff focused on substantive changes.

Concerns raised — review before merging

  • No linked issue detected: No closing reference or linked issue number was found in the PR metadata/body. — If this PR is intended to solve an issue, link it explicitly in the PR body.
📋 Copy for AI agents — paste into your coding agent
Fix the following blocker(s) from this PR review:

1. No linked issue detected: No closing reference or linked issue number was found in the PR metadata/body. — If this PR is intended to solve an issue, link it explicitly in the PR body.

Decision drivers

  • ❌ Code review — 1 blocker (1 reviewer)
  • ❌ Gate result — Blocking (Repo-configured hard blocker found.)
Context & advisory signals — never blocks the verdict
Signal Result Evidence
Linked issue ✅ No-issue rationale PR body explains why no issue is linked.
Related work ✅ No active overlap found No same-issue or scoped active PR overlap found.
Change scope ✅ 20/20 Low review scope from cached public metadata (no linked issue context).
Validation posture ✅ 25/25 PR body includes validation/test evidence.
Contributor workload ✅ 10/10 Author activity: 14 registered-repo PR(s), 14 merged, 228 issue(s).
Contributor context ✅ Confirmed Gittensor contributor JSONbored; Gittensor profile; 14 PR(s), 228 issue(s).
Improvement ℹ️ Insufficient signal risk: low · value: insufficient-signal
Review context
  • Author: JSONbored
  • Role context: owner (maintainer lane)
  • Public audience mode: oss maintainer
  • Lane context: Repository is configured for direct PR review.
  • Public profile languages: Python, TypeScript, Ruby, Go, JavaScript, MDX, Shell, Solidity
  • Official Gittensor activity: 14 PR(s), 228 issue(s).
  • PR-specific overlap: none found.
Contributor next steps
  • Start here: Treat this as maintainer-lane context rather than normal contributor-lane activity.
Signal definitions
  • Related work = same linked issue, overlapping active PRs, or title/path similarity.
  • Change scope = cached public metadata such as size labels, draft state, and review-burden hints.
  • Validation posture = whether the PR provides enough public validation/test evidence for maintainer review.
  • Contributor workload = public contributor activity and cleanup pressure, not a repo-wide quality failure.
  • Contributor context = public GitHub/Gittensor identity context; non-Gittensor status is not a blocker.
🧪 Chat with LoopOver

Ask LoopOver a question about this PR directly in a comment — grounded only in the same cached, public-safe facts shown above, never a new claim.

  • @loopover ask &lt;question&gt; answers contribution-quality Q&A with source citations and freshness.
  • @loopover chat &lt;question&gt; answers in natural prose from cached decision-pack facts via local inference (maintainer/collaborator; read-only).
  • A plain-language @loopover mention with a real question is routed to the closest matching read-only command automatically — no exact syntax required.

Full command reference: https://loopover.ai/docs/loopover-commands

🧪 Experimental — new and may change.

🟩 Safe / merged · 🟦 Advisory · 🟨 Held for review · 🟥 Blocked / closed


💰 Earn for open-source contributions like this. Gittensor lets GitHub contributors earn for the work they already do — register to start earning →.

Checked by LoopOver, a quiet PR intelligence layer for OSS maintainers.

  • Re-run LoopOver review

…hes--main--groups--engine-and-dependents

# Conflicts:
#	.release-please-manifest.json
@JSONbored
JSONbored merged commit 9c54a1e into main Jul 23, 2026
11 checks passed
@JSONbored
JSONbored deleted the release-please--branches--main--groups--engine-and-dependents branch July 23, 2026 06:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment