Skip to content

Release 0.7.0 candidate - #119

Draft
makeitfutureDev wants to merge 26 commits into
mainfrom
release/0.7.0
Draft

makeitfutureDev wants to merge 26 commits into
mainfrom
release/0.7.0

Conversation

@makeitfutureDev

@makeitfutureDev makeitfutureDev commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Candidate

Commit: 3f47b6f3b568dbe990e06ee7117512a7e388e696
Base: main at 710b3dc (0.6.0)

This candidate promotes the beta changes since 0.6.0: channel Codex login and sign-in flow, Codex MCP account scoping, file sharing into Slack threads, nested background report delivery, sticky engine failover, Overview charts, updater smoke behavior, and supporting fixes. It also removes the redundant channel login hint.

Automated gate

  • npm run test:coverage: 3,168 passed, 0 failed, 28 skipped; coverage 93.70% lines / 84.64% branches / 89.23% functions.
  • npm run check:static: passed.
  • npm run secret-scan: passed.
  • npm run test:security-coverage: 62 passed.
  • npm audit --omit=dev --audit-level=high: passed; two moderate advisories reported.
  • npm run check:dco -- origin/main..HEAD: passed, 16 commits signed off.
  • CI: DCO, hygiene, Node 22.13 and Node 24 test jobs passed.

Live QA completed on beta runtime code ee52be3

The release preparation commit changes package version and changelog only. The deployed beta runtime code is identical to the candidate's runtime code.

  • Agent file sharing, Apps actor: Codex thread, Claude thread. Both native files appeared in their root threads; downloaded bytes matched their fixtures exactly. Airtable Test Case FILE-AGENT-01 has both PASS runs.
  • Nested background report, Contact actor: Codex thread, Claude thread. Each nested final appeared once in the root thread; no invalid_thread_ts warning; completed job rows retired. Airtable AU-15 and AU-16 have PASS runs.
  • Earlier trial prompts sent from Tiberiu's Slack account are retained as historical evidence but excluded from release acceptance. All current QA prompts use the designated Apps and Contact actors.

Release gates still open

  • Dedicated Codex account isolation and account-scoped Cloud MCP behavior require disposable ChatGPT and API-key fixtures. The requester has been asked to set those up in QA channels without sharing credentials in chat.
  • Channel login UI and /model behavior, Overview live interaction, file-share refusal/scheduled cases, and the limited-account failover continuation remain without complete live release evidence in TEST-PLAN.md.
  • After those gates, confirm this exact candidate under the repository release policy. Keep this PR in draft until then; do not merge or tag solely because CI passed.

tbiyss and others added 26 commits September 28, 2026 15:19
…needed

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
… smoke

The update's engine smoke refused an update on Atlas because the Claude
plan had hit its weekly limit. That answer proves the CLI started in the
new container, authenticated and reached its provider, which is what the
smoke exists to prove. It now counts as reachable, with a "reachable but
usage-limited" note, before the update and after the restart. Real
failures (a bad login, a missing CLI, a wrong answer) still refuse the
update or roll it back.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
A request like "trimite fișierul" for a PDF ended in a "which Slack account?"
card: the agent's only bot-token upload (slack_upload_snippet) takes text, so
it fell through to a Composio Slack upload, which is a write as a person.

slack_share_file is the agent-side twin of the file explorer's Share button:
openConfinedFile proves the path is a regular file inside the channel folder
(no symlink, not the mounted operator home) and the bot uploads from that
proven descriptor, any type, up to 25 MB, into the current thread (top-level
for a scheduled run). Audited as channel_file_shared with via: "agent"; OPEN
in the control-plane classification like the explorer button.

The gateway-usage guide, the snippet and staging tool descriptions now route
"send the file here" to slack_share_file and keep Composio Slack uploads for
other channels and DMs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>
Signed-off-by: Tiberiu Socaci <tsocaci@makeitfuture.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants