{
  "schema": "libkungfu.agent-output-comparison/v1",
  "status": "observed-public-github-data",
  "collectedAt": "2026-08-12T12:57:58.009Z",
  "window": {
    "id": "bootstrap",
    "label": "v4 bootstrap window",
    "startInclusive": "2026-06-16T00:00:00.000Z",
    "endExclusive": "2026-07-16T00:00:00.000Z",
    "githubQualifier": "merged:2026-06-16T00:00:00Z..2026-07-15T23:59:59Z",
    "duration": "P30D"
  },
  "subjects": {
    "ax": {
      "label": "Google AX",
      "scope": "one public repository",
      "query": "repo:google/ax is:pr is:merged merged:2026-06-16T00:00:00Z..2026-07-15T23:59:59Z",
      "organizationForm": "multiple public contributor accounts working in one repository",
      "summary": {
        "mergedPullRequests": 102,
        "activeRepositories": 1,
        "authorAccounts": 5,
        "activeMergeDays": 21,
        "totalAdditions": 15516,
        "totalDeletions": 22484,
        "totalChangedFiles": 541,
        "changeSize": {
          "median": 141,
          "p25": 31,
          "p75": 388,
          "p90": 1051
        },
        "authors": [
          {
            "name": "rakyll",
            "count": 53
          },
          {
            "name": "wjjclaud",
            "count": 18
          },
          {
            "name": "joycel-github",
            "count": 16
          },
          {
            "name": "anj-s",
            "count": 8
          },
          {
            "name": "zbl94",
            "count": 7
          }
        ],
        "repositories": [
          {
            "name": "google/ax",
            "count": 102
          }
        ],
        "daily": [
          {
            "name": "2026-06-16",
            "count": 7
          },
          {
            "name": "2026-06-17",
            "count": 9
          },
          {
            "name": "2026-06-18",
            "count": 6
          },
          {
            "name": "2026-06-22",
            "count": 3
          },
          {
            "name": "2026-06-23",
            "count": 3
          },
          {
            "name": "2026-06-24",
            "count": 2
          },
          {
            "name": "2026-06-25",
            "count": 7
          },
          {
            "name": "2026-06-26",
            "count": 9
          },
          {
            "name": "2026-06-27",
            "count": 5
          },
          {
            "name": "2026-06-29",
            "count": 5
          },
          {
            "name": "2026-06-30",
            "count": 2
          },
          {
            "name": "2026-07-01",
            "count": 6
          },
          {
            "name": "2026-07-06",
            "count": 6
          },
          {
            "name": "2026-07-07",
            "count": 6
          },
          {
            "name": "2026-07-08",
            "count": 2
          },
          {
            "name": "2026-07-09",
            "count": 8
          },
          {
            "name": "2026-07-10",
            "count": 4
          },
          {
            "name": "2026-07-11",
            "count": 1
          },
          {
            "name": "2026-07-13",
            "count": 3
          },
          {
            "name": "2026-07-14",
            "count": 3
          },
          {
            "name": "2026-07-15",
            "count": 5
          }
        ],
        "workTypes": [
          {
            "name": "unclassified",
            "count": 84
          },
          {
            "name": "antigravity",
            "count": 3
          },
          {
            "name": "docs",
            "count": 3
          },
          {
            "name": "feat",
            "count": 3
          },
          {
            "name": "ax",
            "count": 2
          },
          {
            "name": "ci",
            "count": 2
          },
          {
            "name": "fix",
            "count": 2
          },
          {
            "name": "refactor",
            "count": 2
          },
          {
            "name": "tui",
            "count": 1
          }
        ]
      },
      "defaultBranchActivity": {
        "repository": "google/ax",
        "branch": "main",
        "commits": 101,
        "activeDays": 21,
        "authorAccounts": 5,
        "rolling7": {
          "minimumCommits": 13,
          "maximumCommits": 34,
          "minimumActiveDays": 3,
          "maximumActiveDays": 6,
          "observations": [
            {
              "endDay": "2026-06-22",
              "commits": 25,
              "activeDays": 4
            },
            {
              "endDay": "2026-06-23",
              "commits": 21,
              "activeDays": 4
            },
            {
              "endDay": "2026-06-24",
              "commits": 14,
              "activeDays": 4
            },
            {
              "endDay": "2026-06-25",
              "commits": 15,
              "activeDays": 4
            },
            {
              "endDay": "2026-06-26",
              "commits": 24,
              "activeDays": 5
            },
            {
              "endDay": "2026-06-27",
              "commits": 29,
              "activeDays": 6
            },
            {
              "endDay": "2026-06-28",
              "commits": 29,
              "activeDays": 6
            },
            {
              "endDay": "2026-06-29",
              "commits": 31,
              "activeDays": 6
            },
            {
              "endDay": "2026-06-30",
              "commits": 30,
              "activeDays": 6
            },
            {
              "endDay": "2026-07-01",
              "commits": 34,
              "activeDays": 6
            },
            {
              "endDay": "2026-07-02",
              "commits": 27,
              "activeDays": 5
            },
            {
              "endDay": "2026-07-03",
              "commits": 18,
              "activeDays": 4
            },
            {
              "endDay": "2026-07-04",
              "commits": 13,
              "activeDays": 3
            },
            {
              "endDay": "2026-07-05",
              "commits": 13,
              "activeDays": 3
            },
            {
              "endDay": "2026-07-06",
              "commits": 14,
              "activeDays": 3
            },
            {
              "endDay": "2026-07-07",
              "commits": 18,
              "activeDays": 3
            },
            {
              "endDay": "2026-07-08",
              "commits": 14,
              "activeDays": 3
            },
            {
              "endDay": "2026-07-09",
              "commits": 22,
              "activeDays": 4
            },
            {
              "endDay": "2026-07-10",
              "commits": 26,
              "activeDays": 5
            },
            {
              "endDay": "2026-07-11",
              "commits": 27,
              "activeDays": 6
            },
            {
              "endDay": "2026-07-12",
              "commits": 27,
              "activeDays": 6
            },
            {
              "endDay": "2026-07-13",
              "commits": 24,
              "activeDays": 6
            },
            {
              "endDay": "2026-07-14",
              "commits": 21,
              "activeDays": 6
            },
            {
              "endDay": "2026-07-15",
              "commits": 23,
              "activeDays": 6
            }
          ]
        },
        "daily": [
          {
            "name": "2026-06-16",
            "count": 7
          },
          {
            "name": "2026-06-17",
            "count": 9
          },
          {
            "name": "2026-06-18",
            "count": 6
          },
          {
            "name": "2026-06-22",
            "count": 3
          },
          {
            "name": "2026-06-23",
            "count": 3
          },
          {
            "name": "2026-06-24",
            "count": 2
          },
          {
            "name": "2026-06-25",
            "count": 7
          },
          {
            "name": "2026-06-26",
            "count": 9
          },
          {
            "name": "2026-06-27",
            "count": 5
          },
          {
            "name": "2026-06-29",
            "count": 5
          },
          {
            "name": "2026-06-30",
            "count": 2
          },
          {
            "name": "2026-07-01",
            "count": 6
          },
          {
            "name": "2026-07-06",
            "count": 6
          },
          {
            "name": "2026-07-07",
            "count": 6
          },
          {
            "name": "2026-07-08",
            "count": 2
          },
          {
            "name": "2026-07-09",
            "count": 8
          },
          {
            "name": "2026-07-10",
            "count": 4
          },
          {
            "name": "2026-07-11",
            "count": 1
          },
          {
            "name": "2026-07-13",
            "count": 3
          },
          {
            "name": "2026-07-14",
            "count": 3
          },
          {
            "name": "2026-07-15",
            "count": 4
          }
        ],
        "records": [
          {
            "sha": "cb4baf4e5a6ea2fd6f325f8c6d319a63f2243dcd",
            "url": "https://github.com/google/ax/commit/cb4baf4e5a6ea2fd6f325f8c6d319a63f2243dcd",
            "committedAt": "2026-06-16T04:13:22Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "go mod tidy (#88)",
            "message": "go mod tidy (#88)"
          },
          {
            "sha": "ff8242256523f0693917750afebb4e730964d0d8",
            "url": "https://github.com/google/ax/commit/ff8242256523f0693917750afebb4e730964d0d8",
            "committedAt": "2026-06-16T04:13:56Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Remove custom harness namespace and resources (#92)",
            "message": "Remove custom harness namespace and resources (#92)\n\n* Remove custom harness namespace and resources from deployment configuration\n\n* docs: simplify harness documentation and add support for custom antigravity images in install script\n\n* Remove the implementation details of the deployment script"
          },
          {
            "sha": "182eff8cbdff7e9a945807ab5277ffdfc5233d32",
            "url": "https://github.com/google/ax/commit/182eff8cbdff7e9a945807ab5277ffdfc5233d32",
            "committedAt": "2026-06-16T04:30:44Z",
            "author": "anj-s",
            "authorName": "anj-s",
            "committerName": "GitHub",
            "title": "ci: add go mod tidy verification step to workflow (#94)",
            "message": "ci: add go mod tidy verification step to workflow (#94)"
          },
          {
            "sha": "5daa7a03a95b69f525c8f6a534e6cdcbd7451b20",
            "url": "https://github.com/google/ax/commit/5daa7a03a95b69f525c8f6a534e6cdcbd7451b20",
            "committedAt": "2026-06-16T05:40:44Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Use SubstrateHarness if AX_SUBSTRATE=1 (#89)",
            "message": "Use SubstrateHarness if AX_SUBSTRATE=1 (#89)\n\n* Use SubstrateHarness if AX_SUBSTRATE=1\n\nFixes #87.\n\n* Don't allow multiple antigravity harnesses\n\nFixes  #96.\n\n* refactor: cliutil registers the substrate implementation\n\n* refactor: move Antigravity harness initialization from config to cliutil\n\n* feat: add substrate template parameter to antigravity harness initialization\n\n* refactor: rename antigravity template to ax-harness-template and remove redundant constant definition\n\n* refactor: remove unused defaultPort constant from config\n\n* refactor: remove AX_SUBSTRATE_ENDPOINT configuration and dependency from substrate harness"
          },
          {
            "sha": "c281998ce7472849ca15373a957e436f8574bb0a",
            "url": "https://github.com/google/ax/commit/c281998ce7472849ca15373a957e436f8574bb0a",
            "committedAt": "2026-06-16T14:37:57Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "refactor: remove ate build tag and consolidate server implementation (#119)",
            "message": "refactor: remove ate build tag and consolidate server implementation (#119)"
          },
          {
            "sha": "5bf40bf3b32231c12d69e8ebc877c4a901923c9e",
            "url": "https://github.com/google/ax/commit/5bf40bf3b32231c12d69e8ebc877c4a901923c9e",
            "committedAt": "2026-06-16T14:38:19Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "docs: update actor template name in wait command example (#115)",
            "message": "docs: update actor template name in wait command example (#115)"
          },
          {
            "sha": "7f535c9e96a7b77431ae92eb011e40c14a378315",
            "url": "https://github.com/google/ax/commit/7f535c9e96a7b77431ae92eb011e40c14a378315",
            "committedAt": "2026-06-16T20:52:32Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Add e2e substrate tests with mocks. (#82)",
            "message": "Add e2e substrate tests with mocks. (#82)"
          },
          {
            "sha": "c9d7691a630f7f01d151a1a2e89e963b35e2a1a4",
            "url": "https://github.com/google/ax/commit/c9d7691a630f7f01d151a1a2e89e963b35e2a1a4",
            "committedAt": "2026-06-17T19:26:10Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Update the deployment script with ateom image and wait step. (#121)",
            "message": "Update the deployment script with ateom image and wait step. (#121)"
          },
          {
            "sha": "fce99efceb01ea6a08bd0086197be5bd47788f45",
            "url": "https://github.com/google/ax/commit/fce99efceb01ea6a08bd0086197be5bd47788f45",
            "committedAt": "2026-06-17T20:55:04Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Remove trace command and related UI utilities (#126)",
            "message": "Remove trace command and related UI utilities (#126)\n\nWe can add this capability back once the event log is stable."
          },
          {
            "sha": "5425c993f475e064aecae1e669a17456f0866cb7",
            "url": "https://github.com/google/ax/commit/5425c993f475e064aecae1e669a17456f0866cb7",
            "committedAt": "2026-06-17T21:16:21Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Remove forking capabilities until controller2 is stable (#130)",
            "message": "Remove forking capabilities until controller2 is stable (#130)\n\n* Remove forking capabilities until controller2 is stable\n\n* chore: add Apache 2.0 license headers to generated python protobuf files"
          },
          {
            "sha": "37f2a0845bb540ce96527e8983bf4d9ce493abe8",
            "url": "https://github.com/google/ax/commit/37f2a0845bb540ce96527e8983bf4d9ce493abe8",
            "committedAt": "2026-06-17T21:19:18Z",
            "author": "anj-s",
            "authorName": "anj-s",
            "committerName": "GitHub",
            "title": "feat: reuse agent instance per conversation ID in antigravity harness server (#83)",
            "message": "feat: reuse agent instance per conversation ID in antigravity harness server (#83)"
          },
          {
            "sha": "afb7cb5a180ad85ce80f64070d0aac87e91f8950",
            "url": "https://github.com/google/ax/commit/afb7cb5a180ad85ce80f64070d0aac87e91f8950",
            "committedAt": "2026-06-17T21:21:53Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Build one comprehensive ax image for the ax-server and harness (#122)",
            "message": "Build one comprehensive ax image for the ax-server and harness (#122)"
          },
          {
            "sha": "c5d986c4f5b08cf462c86208c1b30c980b794d95",
            "url": "https://github.com/google/ax/commit/c5d986c4f5b08cf462c86208c1b30c980b794d95",
            "committedAt": "2026-06-17T21:28:42Z",
            "author": "anj-s",
            "authorName": "anj-s",
            "committerName": "GitHub",
            "title": "fix(harness): improve error message when model API key is missing (#85)",
            "message": "fix(harness): improve error message when model API key is missing (#85)"
          },
          {
            "sha": "79b3c8acd528f29ddcf39bf27f6680f40b4a6fb8",
            "url": "https://github.com/google/ax/commit/79b3c8acd528f29ddcf39bf27f6680f40b4a6fb8",
            "committedAt": "2026-06-17T22:09:31Z",
            "author": "anj-s",
            "authorName": "anj-s",
            "committerName": "GitHub",
            "title": "ax: implement monitor command and conversations API (#74)",
            "message": "ax: implement monitor command and conversations API (#74)"
          },
          {
            "sha": "da51f4b357e9c09c4dd34d016fa5a26cc92e778b",
            "url": "https://github.com/google/ax/commit/da51f4b357e9c09c4dd34d016fa5a26cc92e778b",
            "committedAt": "2026-06-17T22:19:46Z",
            "author": "anj-s",
            "authorName": "anj-s",
            "committerName": "GitHub",
            "title": "ax: implement monitor dashboard Web UI (#75)",
            "message": "ax: implement monitor dashboard Web UI (#75)"
          },
          {
            "sha": "db4f6766ca4db6053f18ca3735732ae6142dbff7",
            "url": "https://github.com/google/ax/commit/db4f6766ca4db6053f18ca3735732ae6142dbff7",
            "committedAt": "2026-06-17T22:20:33Z",
            "author": "anj-s",
            "authorName": "anj-s",
            "committerName": "GitHub",
            "title": "refactor: implement stateful Display and inject io.Writer (#84)",
            "message": "refactor: implement stateful Display and inject io.Writer (#84)"
          },
          {
            "sha": "20c3fbab9c744d670cf4cdfac9ef608dd264b10d",
            "url": "https://github.com/google/ax/commit/20c3fbab9c744d670cf4cdfac9ef608dd264b10d",
            "committedAt": "2026-06-18T05:53:41Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Build antigravity package directly from pip install. (#137)",
            "message": "Build antigravity package directly from pip install. (#137)\n\n* Build antigravity package directly from pip install.\n\n* Update script log and bump substrate version."
          },
          {
            "sha": "cc1e1ea85e1c1ebe30ce8570f53c0d43b19c8c70",
            "url": "https://github.com/google/ax/commit/cc1e1ea85e1c1ebe30ce8570f53c0d43b19c8c70",
            "committedAt": "2026-06-18T05:55:44Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Update ateomImage path in deployment manifest (#139)",
            "message": "Update ateomImage path in deployment manifest (#139)"
          },
          {
            "sha": "75f7232a0d9ccedfa4717cf3d05211d14bbf5cb2",
            "url": "https://github.com/google/ax/commit/75f7232a0d9ccedfa4717cf3d05211d14bbf5cb2",
            "committedAt": "2026-06-18T06:04:16Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Remove harness test fallback and delete harnesstest package (#138)",
            "message": "Remove harness test fallback and delete harnesstest package (#138)\n\nUpdates #77."
          },
          {
            "sha": "5bc08c4e5392c8a140de60d7a993c9ad701b5b7c",
            "url": "https://github.com/google/ax/commit/5bc08c4e5392c8a140de60d7a993c9ad701b5b7c",
            "committedAt": "2026-06-18T15:08:08Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Auto select KO_DOCKER_REPO and KO_DEFAULTPLATFORMS (#143)",
            "message": "Auto select KO_DOCKER_REPO and KO_DEFAULTPLATFORMS (#143)\n\n* Automate KO_DOCKER_REPO and KO_DEFAULTPLATFORMS configuration in installation script\n\n* Add runsc configuration for amd64 and arm64 in ax-deployment2 manifest\n\nFixes #144.\n\n* chore: remove redundant empty lines in install script\n\n* refactor: remove runsc configuration from deployment manifest\n\n* chore: remove redundant whitespace in ax-deployment2 manifest"
          },
          {
            "sha": "544db4c5608d8dc90dc153ceb61be51e5b8e5a6e",
            "url": "https://github.com/google/ax/commit/544db4c5608d8dc90dc153ceb61be51e5b8e5a6e",
            "committedAt": "2026-06-18T15:08:44Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Remove ATE agents (#148)",
            "message": "Remove ATE agents (#148)\n\nSubstrateHarness will replace this. SubstrateAgent is deadcode."
          },
          {
            "sha": "da9d20eccceef7ac23e6e877c11825f3e175c5b7",
            "url": "https://github.com/google/ax/commit/da9d20eccceef7ac23e6e877c11825f3e175c5b7",
            "committedAt": "2026-06-18T19:14:06Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Remove Colab agent support (#151)",
            "message": "Remove Colab agent support (#151)"
          },
          {
            "sha": "a470ffb0ebba3dd4d5c28c7cc415ea1daa08cb65",
            "url": "https://github.com/google/ax/commit/a470ffb0ebba3dd4d5c28c7cc415ea1daa08cb65",
            "committedAt": "2026-06-22T18:21:57Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Make controller2 use its own eventlog package (#153)",
            "message": "Make controller2 use its own eventlog package (#153)\n\n* Migrate controller2 to its own eventlog package\n\nThis will allow us to make schema changes to the event log easily without causing issues to the existing event log implementation.\n\n* refactor: update CLI harness to use eventlog from internal/controller2"
          },
          {
            "sha": "dc754ab7bdb3a939e84a479a8d78f41238c70a2b",
            "url": "https://github.com/google/ax/commit/dc754ab7bdb3a939e84a479a8d78f41238c70a2b",
            "committedAt": "2026-06-22T19:07:05Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Encapsulate event logging in a new logger (#154)",
            "message": "Encapsulate event logging in a new logger (#154)\n\n* Encapsulate event logging in a new logger\n\n- Extend ConversationEvent with harness metadata\n- Don't allow Exec requests to switch to a different harness\n\n* feat: add TODO for pending execution resumption logic in controller"
          },
          {
            "sha": "75d80d437ffb8032011bff5cfd351e228405289f",
            "url": "https://github.com/google/ax/commit/75d80d437ffb8032011bff5cfd351e228405289f",
            "committedAt": "2026-06-22T20:07:33Z",
            "author": "anj-s",
            "authorName": "anj-s",
            "committerName": "GitHub",
            "title": "fix(antigravity): Buffer sequential thoughts and text tokens to prevent token-by-token streaming (#157)",
            "message": "fix(antigravity): Buffer sequential thoughts and text tokens to prevent token-by-token streaming (#157)"
          },
          {
            "sha": "edb5c97fbf6f2367c8117220ba992b2c48835968",
            "url": "https://github.com/google/ax/commit/edb5c97fbf6f2367c8117220ba992b2c48835968",
            "committedAt": "2026-06-23T04:16:53Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Bump substrate version and update documentation. (#158)",
            "message": "Bump substrate version and update documentation. (#158)\n\n* Bump substrate and update schema.\n\n* Update documentation for deployment.\n\n* Update command.\n\n* Add error message in the script."
          },
          {
            "sha": "2ac395bae293e5e2332a25e5c1efb20a15d51fff",
            "url": "https://github.com/google/ax/commit/2ac395bae293e5e2332a25e5c1efb20a15d51fff",
            "committedAt": "2026-06-23T05:04:59Z",
            "author": "joycel-github",
            "authorName": "JoyceLiu",
            "committerName": "GitHub",
            "title": "Remove docker agent example (#159)",
            "message": "Remove docker agent example (#159)\n\nThe docker_agent example largely duplicates remote_agent (both\nimplement AX's native AgentService directly via gRPC). Removing it\nin favor of the simpler remote_agent example.\n\nFixes #132"
          },
          {
            "sha": "3438251c0415dc9db4dbaecf8a8078caa2f7b30d",
            "url": "https://github.com/google/ax/commit/3438251c0415dc9db4dbaecf8a8078caa2f7b30d",
            "committedAt": "2026-06-23T05:10:20Z",
            "author": "joycel-github",
            "authorName": "JoyceLiu",
            "committerName": "GitHub",
            "title": "Remove A2A agent and bridge (#160)",
            "message": "Remove A2A agent and bridge (#160)\n\nRemoves the A2A protocol integration end-to-end:\n\n- examples/a2a_agent/ (Python coding agent example)\n- internal/experimental/a2abridge/ (A2A <-> AX bridge)\n- internal/experimental/agent/a2a.go (A2A agent client)\n- internal/auth/ (only used by A2A)\n- RemoteAgentConfig.Protocol/Auth/Headers/A2A fields and\n  Registry.registerA2A (the protocol switch collapses to AXP)\n- github.com/a2aproject/a2a-go/v2 dep (via go mod tidy)\n- A2A mentions in ax.yaml, README.md, .gitignore\n\nFixes #128"
          },
          {
            "sha": "22a9daeddf3ed83e5aa92fd1d20d867debb7dba4",
            "url": "https://github.com/google/ax/commit/22a9daeddf3ed83e5aa92fd1d20d867debb7dba4",
            "committedAt": "2026-06-24T07:49:02Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "feat: Support Postgres as database on substrate. (#163)",
            "message": "feat: Support Postgres as database on substrate. (#163)\n\n* Support postgres as database on substrate.\n\n* Add postgres config in yaml.\n\n* Remove lock from postgres.\n\n* Remove --delete-all option."
          },
          {
            "sha": "094f057d9ffafdf46a474ad4d40875b248f57522",
            "url": "https://github.com/google/ax/commit/094f057d9ffafdf46a474ad4d40875b248f57522",
            "committedAt": "2026-06-24T21:24:07Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Remove ununsed ExecutionEvent from controller2 (#165)",
            "message": "Remove ununsed ExecutionEvent from controller2 (#165)"
          },
          {
            "sha": "96a21ce0405e0c566974c58f39490d54ab20bf5a",
            "url": "https://github.com/google/ax/commit/96a21ce0405e0c566974c58f39490d54ab20bf5a",
            "committedAt": "2026-06-25T16:44:32Z",
            "author": "zbl94",
            "authorName": "zbl94",
            "committerName": "GitHub",
            "title": "Add Interactions API harness (#162)",
            "message": "Add Interactions API harness (#162)\n\n* Add Interactions API harness\n\nAdds a Harness implementation that drives an Antigravity agent through the\nVertex GenAI Interactions API over HTTPS + Server-Sent Events, using the\nsteps-based request format and the client-side (\"local\") environment.\n\nThe harness executes every tool the agent yields internally: built-in\nenvironment tools (view_file, run_command, list_dir, move, delete_dir, and the\ncreate/edit/multi_edit/delete_file family) run against the local filesystem and\nshell, while third-party function tools are dispatched to a pluggable\nThirdPartyExecutor (currently a banking example until tool injection is wired).\nRun drives the full interaction loop to completion and streams the agent's text\nvia the Handler.\n\nIt is exposed over the HarnessService gRPC contract via InteractionsAPIServer\nand the interactionsapi-harness-server command, so the harness can run as a\nstandalone server reachable by any HarnessService client -- the substrate-ready\ndeployment model.\n\n* Rename Interactions API harness to Antigravity Interactions\n\nRename the harness's identity from \"Interactions API harness\" to\n\"Antigravity Interactions\" (Antigravity driven via the Vertex GenAI\nInteractions API), which more clearly describes what it is. References to\nthe actual Google \"Interactions API\" are left intact.\n\n- InteractionsAPIHarness     -> AntigravityInteractionsHarness\n- InteractionsAPIConfig       -> AntigravityInteractionsConfig\n- NewInteractionsAPIHarness   -> NewAntigravityInteractionsHarness\n- interactionsExecution       -> antigravityInteractionsExecution\n- internal/harness/interactionsapi*.go -> antigravityinteractions*.go\n- cmd/e2e demo, agent id (\"antigravity-interactions\"), and\n  AX_INTERACTIONS_* -> AX_ANTIGRAVITY_INTERACTIONS_* env vars\n\nThe harness uses an oauth2 token source (ADC/impersonation) instead of\nshelling out to gcloud, which adds golang.org/x/oauth2 and\ngoogle.golang.org/api as direct deps (go.mod/go.sum). The standalone\ninteractions harness server and its command are removed; the harness is\nexercised in-process via cmd/e2e.\n\n* Use ADC-only auth and export FunctionTool\n\nDrop the ImpersonateServiceAccount config knob and the\ngoogle.golang.org/api/impersonate dependency: the harness now obtains its\nbearer token solely from Application Default Credentials (no gcloud shell-out).\nCallers needing impersonation or end-user credentials supply their own\noauth2.TokenSource via the existing TokenSource override, keeping the harness\nidentity-agnostic.\n\nExport functionTool as FunctionTool so external packages can implement the\nThirdPartyExecutor seam (Declarations returns []FunctionTool).\n\n* Improve debug output and drop /workspace Cwd fallback\n\nDebug mode now logs each Run turn as a hierarchical block: a turn separator\nheader, then per function call FC i/total <name> with one indented line per\nargument (keys sorted), followed by FR <name> with the indented result. This\nmakes the FC/FR exchange and turn boundaries easy to follow.\n\nrun_command now honors the requested Cwd directly instead of falling back when\nthe directory is absent. The fallback existed only to tolerate the agent's\nphantom /workspace sandbox; with the client-side environment no longer carrying\nthe server sandbox system instructions, that assumption is gone.\n\n* Support a system instruction in the harness config\n\nAdd AntigravityInteractionsConfig.SystemInstruction, sent as the interaction's\nsystem_instruction field on every turn (so it persists across resumes). This\nlets a caller supply a free-form system prompt that steers the agent in addition\nto the agent's own instructions.\n\n* Read project/location from env, fix endpoint to production\n\nRemove the Project, Location, and Endpoint config fields. Cloud project and\nlocation now come from the standard GOOGLE_CLOUD_PROJECT and\nGOOGLE_CLOUD_LOCATION environment variables (consistent with the rest of AX),\nand the endpoint is a fixed public-production constant rather than\nconfiguration.\n\n* Raise default MaxTurns from 20 to 100\n\n20 interaction round-trips is too few for non-trivial coding tasks, which can\nneed many tool-call turns. Default to 100 for more headroom while still bounding\nrunaway loops."
          },
          {
            "sha": "819bb83a8f8c5261f5fa0eeae3f6a86eba397ff5",
            "url": "https://github.com/google/ax/commit/819bb83a8f8c5261f5fa0eeae3f6a86eba397ff5",
            "committedAt": "2026-06-25T17:17:41Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Implement resumption  of pending executions (#167)",
            "message": "Implement resumption  of pending executions (#167)\n\n* Implement execution resumption  for pending\n\n* refactor: rename configurableExecution to testExecution in controller tests\n\n* refactor: simplify harness execution error messages in controller"
          },
          {
            "sha": "9949a45cba5da31e09a020c9685aeae6840de9ab",
            "url": "https://github.com/google/ax/commit/9949a45cba5da31e09a020c9685aeae6840de9ab",
            "committedAt": "2026-06-25T19:27:23Z",
            "author": "anj-s",
            "authorName": "anj-s",
            "committerName": "GitHub",
            "title": "feat: Support preinstalled skills in Antigravity harness (#173)",
            "message": "feat: Support preinstalled skills in Antigravity harness (#173)"
          },
          {
            "sha": "b60ee71e3303a17161e9b51e3b4312cb11fce73a",
            "url": "https://github.com/google/ax/commit/b60ee71e3303a17161e9b51e3b4312cb11fce73a",
            "committedAt": "2026-06-25T21:17:30Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "- Deleted the deprecated old manifests/ directory. (#174)",
            "message": "- Deleted the deprecated old manifests/ directory. (#174)"
          },
          {
            "sha": "2774e2dc875aabced574581a6905b9e8a1061688",
            "url": "https://github.com/google/ax/commit/2774e2dc875aabced574581a6905b9e8a1061688",
            "committedAt": "2026-06-25T22:04:33Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Update deployment config and readme. (#177)",
            "message": "Update deployment config and readme. (#177)"
          },
          {
            "sha": "9737fd7033dbcda61354b21856fc4d575e5d0a34",
            "url": "https://github.com/google/ax/commit/9737fd7033dbcda61354b21856fc4d575e5d0a34",
            "committedAt": "2026-06-25T22:21:28Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Migrate controller and registry to internal/controller2 (#176)",
            "message": "Migrate controller and registry to internal/controller2 (#176)\n\n* Cleanup the repo and move to controller2\n\n* Migrate controller and registry to internal/controller2\n\n- Remove the legacy harness build tag\n\n* refactor: move GeminiConfig definition from internal/config to internal/gemini package\n\n* test: replace controller registry with dummy implementation and update dependency constraints in go.mod\n\n* chore: remove harness build and test steps from GitHub Actions workflow"
          },
          {
            "sha": "4aad1a66058e00a1318573f68caf9aff9c02f01e",
            "url": "https://github.com/google/ax/commit/4aad1a66058e00a1318573f68caf9aff9c02f01e",
            "committedAt": "2026-06-25T22:32:21Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Consolidate controller and config packages by removing v2 suffixes (#179)",
            "message": "Consolidate controller and config packages by removing v2 suffixes (#179)\n\nAlso remove ununsed ExecutionEvent from proto."
          },
          {
            "sha": "e7d5e2c8c6dac7f9a8e1f357689be1bd16be03e2",
            "url": "https://github.com/google/ax/commit/e7d5e2c8c6dac7f9a8e1f357689be1bd16be03e2",
            "committedAt": "2026-06-26T15:41:45Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Remove ununsed axepp (#182)",
            "message": "Remove ununsed axepp (#182)"
          },
          {
            "sha": "6d3a5f1798a678c30bd8b142f73de820d75a14d9",
            "url": "https://github.com/google/ax/commit/6d3a5f1798a678c30bd8b142f73de820d75a14d9",
            "committedAt": "2026-06-26T15:42:18Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Remove AgentService (#186)",
            "message": "Remove AgentService (#186)"
          },
          {
            "sha": "fa2a34588eb116ded63949eb8b5d0898081fae2a",
            "url": "https://github.com/google/ax/commit/fa2a34588eb116ded63949eb8b5d0898081fae2a",
            "committedAt": "2026-06-26T19:41:38Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Pass harness config through the incoming request (#193)",
            "message": "Pass harness config through the incoming request (#193)\n\n* Pass harness config from exec input.\n\n* Update generated proto.\n\n* Add a flag for inline config json."
          },
          {
            "sha": "2abfec209d6ce4cabf60b61f849d1ccee8590509",
            "url": "https://github.com/google/ax/commit/2abfec209d6ce4cabf60b61f849d1ccee8590509",
            "committedAt": "2026-06-26T21:31:59Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Remove dead code from the earlier controller (#196)",
            "message": "Remove dead code from the earlier controller (#196)\n\n* Remove dead code from the earlier controller\n\nRemove the agent package, AgentService related proto messages, and Gemini agents in favor of the new universal agent harness.\n\n* feat: update proto definitions to use google.protobuf.Struct for harness_config and replace agent fields with harness fields in ExecRequest"
          },
          {
            "sha": "f39e1f23b498ff170335e3b837d2d05bf64f054c",
            "url": "https://github.com/google/ax/commit/f39e1f23b498ff170335e3b837d2d05bf64f054c",
            "committedAt": "2026-06-26T21:52:07Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Remove ununsed internal_only field (#197)",
            "message": "Remove ununsed internal_only field (#197)"
          },
          {
            "sha": "4a7f140d7cd486066c32d7c42093d4aea3060aea",
            "url": "https://github.com/google/ax/commit/4a7f140d7cd486066c32d7c42093d4aea3060aea",
            "committedAt": "2026-06-26T21:53:59Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Move cmd/e2e to internal/cmd/e2e (#199)",
            "message": "Move cmd/e2e to internal/cmd/e2e (#199)\n\nFixes #187."
          },
          {
            "sha": "5259c754e314d73d3e3a7b4c7d1bbb7a95ea04d0",
            "url": "https://github.com/google/ax/commit/5259c754e314d73d3e3a7b4c7d1bbb7a95ea04d0",
            "committedAt": "2026-06-26T21:54:26Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Rename agent references to harness in docs and update roadmap (#198)",
            "message": "Rename agent references to harness in docs and update roadmap (#198)"
          },
          {
            "sha": "fd3e6e16d55ad4de5fd1a27e0a9fa646731adc5f",
            "url": "https://github.com/google/ax/commit/fd3e6e16d55ad4de5fd1a27e0a9fa646731adc5f",
            "committedAt": "2026-06-26T22:44:05Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Change the harness working directory. (#200)",
            "message": "Change the harness working directory. (#200)"
          },
          {
            "sha": "c06192d8e6369f4f07e589761ff04142b64bd516",
            "url": "https://github.com/google/ax/commit/c06192d8e6369f4f07e589761ff04142b64bd516",
            "committedAt": "2026-06-26T23:14:18Z",
            "author": "joycel-github",
            "authorName": "JoyceLiu",
            "committerName": "GitHub",
            "title": "Remove stateless-resumption hydration in antigravity harness server (#201)",
            "message": "Remove stateless-resumption hydration in antigravity harness server (#201)\n\nThe harness server had a dead code path for stateless resumption:\nclearing Conversation._steps each turn and rebuilding it from\nhistorical_messages = ax_messages[:-1]. But the ax controller never\nsends historical messages — it only sends the new turn's input — so\nhistorical_messages was always empty and the clear()+extend() was a\nno-op that reached into a private SDK attribute.\n\nThe Antigravity harness server is designed to be stateful: the cached\nAgent per conversation_id holds history across turns within the\nprocess lifetime. Make that intent explicit by:\n\n  - Deleting the unused hydrate_ax_history_to_steps helper.\n  - Removing the _steps.clear() + extend() block; replacing with a\n    comment explaining the stateful contract.\n  - Dropping now-unused Step/StepType/StepSource/StepTarget/StepStatus\n    imports.\n\nNo behavior change; the deleted block was a no-op against the SDK's\nreal conversation state (which lives in the Go-side localharness\nsubprocess, not in Python _steps)."
          },
          {
            "sha": "8ef2a047b0fcd05036c79daa2623847144ea5756",
            "url": "https://github.com/google/ax/commit/8ef2a047b0fcd05036c79daa2623847144ea5756",
            "committedAt": "2026-06-27T02:03:08Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Update skills dir on substrate. (#204)",
            "message": "Update skills dir on substrate. (#204)"
          },
          {
            "sha": "b6fe49a25db6319cbaef6cd110df26d768e2921f",
            "url": "https://github.com/google/ax/commit/b6fe49a25db6319cbaef6cd110df26d768e2921f",
            "committedAt": "2026-06-27T03:37:10Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Relocate antigravity agent source files from the examples directory (#205)",
            "message": "Relocate antigravity agent source files from the examples directory (#205)\n\n* Relocate antigravity agent source files from the examples directory\n\nFixes #188.\n\n* refactor: embed agent.py\n\n* chore: update default antigravity harness address from localhost to 127.0.0.1\n\n* refactor: remove unnecessary localhost resolution from harness server setup"
          },
          {
            "sha": "22153b43f6db848164ab232bec73d2375abb8d13",
            "url": "https://github.com/google/ax/commit/22153b43f6db848164ab232bec73d2375abb8d13",
            "committedAt": "2026-06-27T11:27:38Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Remove unused skills package (#209)",
            "message": "Remove unused skills package (#209)"
          },
          {
            "sha": "4aa817cccd77dc3cf1630e385fd50af4be080428",
            "url": "https://github.com/google/ax/commit/4aa817cccd77dc3cf1630e385fd50af4be080428",
            "committedAt": "2026-06-27T22:00:08Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Minimize the AX Docker image (1.35GB -> 360MB) for faster resumption on Substrate (#208)",
            "message": "Minimize the AX Docker image (1.35GB -> 360MB) for faster resumption on Substrate (#208)"
          },
          {
            "sha": "82bd8b2fc736811d719cf426b2b1f8724724dd1f",
            "url": "https://github.com/google/ax/commit/82bd8b2fc736811d719cf426b2b1f8724724dd1f",
            "committedAt": "2026-06-27T22:00:27Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Add a line with kubectl port-forward instructions (#211)",
            "message": "Add a line with kubectl port-forward instructions (#211)"
          },
          {
            "sha": "78f4a8f2299e03db6b93e352923794950fef21ea",
            "url": "https://github.com/google/ax/commit/78f4a8f2299e03db6b93e352923794950fef21ea",
            "committedAt": "2026-06-29T07:03:41Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Add structured Error in HarnessEnd (#215)",
            "message": "Add structured Error in HarnessEnd (#215)\n\n- Added Error message to proto\n- Removed error_message\n- Updated the autogenerated artifacts"
          },
          {
            "sha": "5067e191b2d41553f67b99ff07da922401aadf82",
            "url": "https://github.com/google/ax/commit/5067e191b2d41553f67b99ff07da922401aadf82",
            "committedAt": "2026-06-29T07:04:00Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Fix the auto collapsing traces (#216)",
            "message": "Fix the auto collapsing traces (#216)\n\nThe AX Dashboard uses live polling (every 3 seconds) to fetch updated trace data for the active conversation. Each time new trace data is retrieved, the dashboard completely regenerates the HTML for the execution trace cards using innerHTML. Because the cards were hardcoded to render with the collapsed and hidden classes by default, any cards the user had expanded would collapse every time the poll triggered. Since users are usually scrolling while reading the expanded trace details, this gave the impression that the history was collapsing during scrolling.\n\nFixes #202."
          },
          {
            "sha": "9ce12ed12cdfaaf17ed48b529a9be5b07d622ac5",
            "url": "https://github.com/google/ax/commit/9ce12ed12cdfaaf17ed48b529a9be5b07d622ac5",
            "committedAt": "2026-06-29T07:04:24Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Introduce version field to configuration with validation check (#218)",
            "message": "Introduce version field to configuration with validation check (#218)\n\nFixes #217."
          },
          {
            "sha": "b865df6568b4e1ea02c3abfda5ccbf7389ac55e1",
            "url": "https://github.com/google/ax/commit/b865df6568b4e1ea02c3abfda5ccbf7389ac55e1",
            "committedAt": "2026-06-29T17:19:08Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Update README based on the new controller implementation (#213)",
            "message": "Update README based on the new controller implementation (#213)\n\n* Update README based on the new controller implementation\n\n* Update the diagram with more details\n\n* Update README\n\n* Remove unncessary new line\n\n* Add changes to the roadmap\n\n* Update the extensions section\n\n* Add note about Agent Substrate\n\n* Add forking to the roadmap\n\n* Fix wording\n\n* Update tenancy model\n\n* Update wording\n\n* Update formatting\n\n* Add a History section\n\n* Update wording\n\n* Fix wording\n\n* Update wording\n\n* Update wording\n\n* update wording\n\n* Fix typo"
          },
          {
            "sha": "1743290c6c165a6c90e0388ed6f6dccb86eb9098",
            "url": "https://github.com/google/ax/commit/1743290c6c165a6c90e0388ed6f6dccb86eb9098",
            "committedAt": "2026-06-29T17:19:28Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Move Substrate package out of experimental (#214)",
            "message": "Move Substrate package out of experimental (#214)\n\nAgent Substrate is no longer experimental."
          },
          {
            "sha": "09beb2d12bc252bc070eebfc0e7780e9a2b2a69f",
            "url": "https://github.com/google/ax/commit/09beb2d12bc252bc070eebfc0e7780e9a2b2a69f",
            "committedAt": "2026-06-30T00:20:14Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Change bucket var name and bump substrate version. (#224)",
            "message": "Change bucket var name and bump substrate version. (#224)\n\n* Change bucket env var and bump substrate version.\n\n* Add TODO for atespace."
          },
          {
            "sha": "c6607d21ac3d5d0d8f251f2c12f1ea3f26217969",
            "url": "https://github.com/google/ax/commit/c6607d21ac3d5d0d8f251f2c12f1ea3f26217969",
            "committedAt": "2026-06-30T17:41:04Z",
            "author": "joycel-github",
            "authorName": "JoyceLiu",
            "committerName": "GitHub",
            "title": "antigravity: forward GOOGLE_CLOUD_{PROJECT,LOCATION} env to AGY config (#223)",
            "message": "antigravity: forward GOOGLE_CLOUD_{PROJECT,LOCATION} env to AGY config (#223)\n\nThe AGY SDK requires vertex/project/location on its AgentConfig but does\nnot read these env vars itself. Setting GOOGLE_GENAI_USE_VERTEXAI=True\nplus GOOGLE_CLOUD_PROJECT/LOCATION per the README's auth instructions\ntherefore reaches the credential check, then dies later inside AGY with\na confusing 'project and location, or an API key' error.\n\nHave the sidecar forward the env vars to gemini_config at startup, with\nprogrammatic config taking precedence. Validate fail-fast: if vertex is\nrequested but project/location are missing, raise ValueError at startup\nnaming the missing env var, instead of failing per-request later."
          },
          {
            "sha": "ee1d8cfd8fe748c88ba163416a485c04279e176f",
            "url": "https://github.com/google/ax/commit/ee1d8cfd8fe748c88ba163416a485c04279e176f",
            "committedAt": "2026-07-01T05:47:56Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Initial commit of the OpenTelemetry trace exposition (#226)",
            "message": "Initial commit of the OpenTelemetry trace exposition (#226)\n\nRefactor telemetry configuration and resolve deprecated GCP metadata calls:\n- Replace deprecated `metadata.ProjectID()` and `metadata.OnGCE()` with context-aware versions.\n- Update `telemetry.SetTraceProvider` to accept variadic `otlptracegrpc.Option`s and remove the hardcoded endpoint parameter.\n- Add `telemetry.WithGCPCredentials()` helper to encapsulate GCP-specific credentials.\n- Isolate GCP-specific server telemetry configuration into a new `serve_gcp.go` file.\n\nFix premature gRPC stream cancellation in the harness execution clients:\n- Update the client receive loop to drain the stream until `io.EOF` after receiving the `HarnessEnd` frame, preventing `CANCELLED` errors in telemetry.\n- Encapsulate the stream draining and message dispatching logic into a shared `drainStream` helper in a new `stream.go` file.\n- Clean up unused `io` imports in `antigravity.go` and `substrate.go`.\n\nFollow-up:\n- End-to-end trace context propagation to HarnessService deployments\n- End-to-end trace context propagation to Substrate calls"
          },
          {
            "sha": "d9c3412063dbde07794a6c929ebd8b23f7589353",
            "url": "https://github.com/google/ax/commit/d9c3412063dbde07794a6c929ebd8b23f7589353",
            "committedAt": "2026-07-01T09:55:08Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Rename Harness Service to AX Harness Server (#227)",
            "message": "Rename Harness Service to AX Harness Server (#227)\n\nTo keep the style consistent with AX Server"
          },
          {
            "sha": "b0e97874a68ab503a1ed42eadef1ffa9ad5eed20",
            "url": "https://github.com/google/ax/commit/b0e97874a68ab503a1ed42eadef1ffa9ad5eed20",
            "committedAt": "2026-07-01T17:00:07Z",
            "author": "zbl94",
            "authorName": "zbl94",
            "committerName": "GitHub",
            "title": "Add durable conversation resumability to the Antigravity Interactions harness (#180)",
            "message": "Add durable conversation resumability to the Antigravity Interactions harness (#180)\n\n* Add durable conversation resumability to the Antigravity Interactions harness\n\nIntroduce a small durable key-value store and use it to persist each\nconversation's interaction-chain cursor (the last interaction id), so a\nconversation can resume after a process restart instead of starting a new chain.\n\n- internal/storage: a minimal Store interface (Get/Put/Delete + ErrNotFound)\n  with documented semantics (atomicity, read-after-write, not-found-vs-error,\n  durability) and a single-writer concurrency model. Includes a filesystem\n  implementation (FileStore) that writes atomically via temp-file + rename.\n- harness: add AntigravityInteractionsConfig.StateStore; Start loads any\n  persisted cursor and Run persists it after each successful turn, so a fresh\n  Execution for the same conversation continues the existing interaction chain.\n- harness: document the single-writer-per-conversation expectation on the\n  Harness interface (the controller guarantees it), which is what makes the\n  last-write-wins store correct.\n\nAlso includes related harness improvements:\n- Retry HTTP 429 (rate limit) with exponential backoff + jitter, honoring\n  Retry-After; only 429 is retried since it is rejected before any interaction\n  is created.\n- Terminology cleanup: the within-Run FC/FR loop is the \"interaction loop\"\n  (continuation turns chained via previous_interaction_id), distinct from an\n  AX-level resume.\n\n* Scope resume-cursor persistence into the Antigravity Interactions harness\n\nAddress PR review feedback: instead of a repo-level internal/storage\nkey-value abstraction, keep resume-cursor persistence local to the\nAntigravity Interactions harness.\n\n- Remove the internal/storage package (Store interface + FileStore).\n- Add a harness-local, file-based cursorStore (cursorstore.go) with\n  load/save of the per-conversation resumeCursor. resumeCursor stays a\n  struct so it can grow (e.g. partial function-call results for\n  mid-tool-loop recovery) later.\n- Replace Config.StateStore with Config.StateDir. StateDir is now\n  required: NewAntigravityInteractionsHarness returns an error if it is\n  empty, and the constructor now returns (*Harness, error).\n- Add tests with a fake Interactions API (an http.RoundTripper) that\n  records each request and returns a canned SSE stream, covering the\n  resume-across-restart CUJ (a fresh harness over the same StateDir sends\n  the persisted previous_interaction_id), same-harness resume, the\n  required-StateDir error, and a cursorStore load/save round-trip.\n\n* Clarify single-writer as a caller expectation, not a controller guarantee\n\nAddress PR review: the controller does not currently enforce one Execution\nper conversation, so the StateDir doc comment shouldn't claim it does. Phrase\nsingle-writer (last-write-wins, no CAS) as an expectation the caller/deployment\nmust satisfy -- e.g. sticky routing of a conversation id to one worker, or\nresuming a worker from that conversation's snapshot."
          },
          {
            "sha": "0088d37d807840427b17c87d2fe566560123a218",
            "url": "https://github.com/google/ax/commit/0088d37d807840427b17c87d2fe566560123a218",
            "committedAt": "2026-07-01T17:20:52Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Remove weather tool and the custom system instructions (#231)",
            "message": "Remove weather tool and the custom system instructions (#231)"
          },
          {
            "sha": "b8c87febf06ccc09e09e40ec57820120cb599643",
            "url": "https://github.com/google/ax/commit/b8c87febf06ccc09e09e40ec57820120cb599643",
            "committedAt": "2026-07-01T17:26:14Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Add traces to the SQL event log implementation (#234)",
            "message": "Add traces to the SQL event log implementation (#234)"
          },
          {
            "sha": "89276a1246de83843bc0d7fedc854a3da322c925",
            "url": "https://github.com/google/ax/commit/89276a1246de83843bc0d7fedc854a3da322c925",
            "committedAt": "2026-07-01T18:40:10Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "TUI: add interactive /config menu for per-request harness config (#235)",
            "message": "TUI: add interactive /config menu for per-request harness config (#235)"
          },
          {
            "sha": "701777e498ea53f5131b4fc789441f43d77407bb",
            "url": "https://github.com/google/ax/commit/701777e498ea53f5131b4fc789441f43d77407bb",
            "committedAt": "2026-07-06T05:47:49Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Regenerate proto files (#241)",
            "message": "Regenerate proto files (#241)\n\n* Regenerate proto files\n\nFixes #240.\n\n* chore: add Apache 2.0 license headers to generated Python protobuf files"
          },
          {
            "sha": "cec995b72f1c9199663cea5190df13d45630b8bf",
            "url": "https://github.com/google/ax/commit/cec995b72f1c9199663cea5190df13d45630b8bf",
            "committedAt": "2026-07-06T05:48:05Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Fix spacing between AGY harness responses (#239)",
            "message": "Fix spacing between AGY harness responses (#239)\n\nThe AGY harness streams each contiguous block of assistant text as a separate TextContent message, with tool calls in between. The CLI display (cmd/ax/internal/display.go) tracks a state field to decide when to insert separating newlines  but the Content_ToolCall case was a pure no-op that left state == stateText.\n\nFixes #233."
          },
          {
            "sha": "a02465de3384fb7673b0369b9b58cd560bf708c6",
            "url": "https://github.com/google/ax/commit/a02465de3384fb7673b0369b9b58cd560bf708c6",
            "committedAt": "2026-07-06T17:13:18Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Make Postgres optional on substrate deployments (#236)",
            "message": "Make Postgres optional on substrate deployments (#236)\n\n* Make postgres optional.\n\n* Default requires postgres DSN from user."
          },
          {
            "sha": "72b51a4893f342eeb5857da21bc11ab5e4acc930",
            "url": "https://github.com/google/ax/commit/72b51a4893f342eeb5857da21bc11ab5e4acc930",
            "committedAt": "2026-07-06T17:30:46Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Rename ControllerService to ExecutionService (#242)",
            "message": "Rename ControllerService to ExecutionService (#242)"
          },
          {
            "sha": "e39b1232b2c90e09341b5d9366dd3762287312cf",
            "url": "https://github.com/google/ax/commit/e39b1232b2c90e09341b5d9366dd3762287312cf",
            "committedAt": "2026-07-06T21:00:57Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Move Harness implementations to their own packages (#243)",
            "message": "Move Harness implementations to their own packages (#243)\n\n* Move Harness implementations to their own packages\n\nFixes #232.\n\n* Shorten the constructor names"
          },
          {
            "sha": "b2cfc9bc0b9415910d6935801c38170058762564",
            "url": "https://github.com/google/ax/commit/b2cfc9bc0b9415910d6935801c38170058762564",
            "committedAt": "2026-07-06T22:18:42Z",
            "author": "joycel-github",
            "authorName": "JoyceLiu",
            "committerName": "GitHub",
            "title": "harness/python: normalize thought summary whitespace (#244)",
            "message": "harness/python: normalize thought summary whitespace (#244)\n\nModel thought summaries often contain runs of blank lines between\nsection headers (**Section A**\\n\\n\\n**Section B**) and trailing\nnewlines.\n\nPreviously, the Python AGY harness streamed these verbatim over gRPC.\nThis placed the burden of whitespace cleanup on downstream clients (like\ndisplay.go and the Web Dashboard), and caused visible 3+ newline runs\nand compounding newlines at the thought->text transition boundary.\n\nCollapse runs of 3+ newlines to a single blank line and strip\ntrailing newlines inside the Python adapter before sending over the wire.\nAppend exactly one trailing newline to ensure clients generate clean\nseparators when transitioning to text blocks.\n\nFixes #191."
          },
          {
            "sha": "948ca05b5233dcf8b5e4d48e598a332186ab46a8",
            "url": "https://github.com/google/ax/commit/948ca05b5233dcf8b5e4d48e598a332186ab46a8",
            "committedAt": "2026-07-07T01:04:28Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Serve /readyz from ax harness server. (#254)",
            "message": "Serve /readyz from ax harness server. (#254)\n\n* Serve readyz from ax harness.\n\n* Surface the correct error message from server."
          },
          {
            "sha": "ab717703a1165949ffea2eaea29e5dd1ea5b5aa1",
            "url": "https://github.com/google/ax/commit/ab717703a1165949ffea2eaea29e5dd1ea5b5aa1",
            "committedAt": "2026-07-07T01:12:23Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Remove examples/skills/ from the Dockerfile (#256)",
            "message": "Remove examples/skills/ from the Dockerfile (#256)\n\nFixes #253."
          },
          {
            "sha": "cca34eaa7676f7db3b89806a064f7ced3bb54b1d",
            "url": "https://github.com/google/ax/commit/cca34eaa7676f7db3b89806a064f7ced3bb54b1d",
            "committedAt": "2026-07-07T01:12:38Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Use /axharness folder in the snapshots bucket (#255)",
            "message": "Use /axharness folder in the snapshots bucket (#255)\n\nThe ax harness server will provide more than Antigravity."
          },
          {
            "sha": "ad6a89ebaad32ffdb5543d6e602bdfdc41fc3c82",
            "url": "https://github.com/google/ax/commit/ad6a89ebaad32ffdb5543d6e602bdfdc41fc3c82",
            "committedAt": "2026-07-07T01:13:46Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Rename KO_DOCKER_REPO to AX_IMAGE_REPO (#257)",
            "message": "Rename KO_DOCKER_REPO to AX_IMAGE_REPO (#257)\n\nFixes #247."
          },
          {
            "sha": "2ce514f6d61c62046cbd7da786081f8d4332f7d2",
            "url": "https://github.com/google/ax/commit/2ce514f6d61c62046cbd7da786081f8d4332f7d2",
            "committedAt": "2026-07-07T02:43:02Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Make /workspace the default working directory on Substrate (#259)",
            "message": "Make /workspace the default working directory on Substrate (#259)\n\nFixes #258."
          },
          {
            "sha": "c507098025f6619ce611bcf0f2b14386eb846fc4",
            "url": "https://github.com/google/ax/commit/c507098025f6619ce611bcf0f2b14386eb846fc4",
            "committedAt": "2026-07-07T23:50:17Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Introduce pythonsidecar package (#273)",
            "message": "Introduce pythonsidecar package (#273)\n\n* Introduce pythonsidecar package\n\n* chore: add Apache 2.0 license headers to pythonsidecar files\n\n* chore: add development todo notes to sidecar configuration struct"
          },
          {
            "sha": "e764d366a5c660315a6827f065ae1c13cd4a97a3",
            "url": "https://github.com/google/ax/commit/e764d366a5c660315a6827f065ae1c13cd4a97a3",
            "committedAt": "2026-07-08T16:42:27Z",
            "author": "zbl94",
            "authorName": "zbl94",
            "committerName": "GitHub",
            "title": "Serve the Antigravity Interactions harness over HarnessService (#274)",
            "message": "Serve the Antigravity Interactions harness over HarnessService (#274)\n\n* Serve the Antigravity Interactions harness over HarnessService\n\nAdd a Go HarnessService server for the Antigravity Interactions harness so\nit can run as a substrate actor, alongside the existing Python sidecar path.\n\n- internal/harness/antigravityinteractions/server.go: Serve(...) stands up\n  the gRPC HarnessService (plus gRPC health) and an HTTP /readyz endpoint\n  reflecting this server's own serving state, with graceful shutdown on\n  ctx-cancel or SIGINT/SIGTERM. Connect adapts the harness onto the wire\n  contract: a start frame drives one turn (Start -> Queue -> Run), each agent\n  message is streamed as a HarnessResponse{outputs} frame, and the stream\n  terminates with exactly one HarnessResponse{end} (COMPLETED/FAILED/\n  CANCELED); a mid-stream cancel frame cancels the run.\n- cmd/ax/harness.go: add a thin runAntigravityInteractionsHarness(ctx,\n  systemInstructions) entrypoint that builds the config and calls Serve; the\n  dispatch layer decides when to invoke it.\n- server_test.go: bufconn tests for the start->end contract and rejection of\n  a non-start first frame.\n\n* Persist resume cursors under .ax/cursors in the work dir\n\nPlace the Antigravity Interactions harness resume-cursor StateDir in a\ndedicated \".ax/cursors\" subdirectory under the actor working directory,\nrather than the work dir root. This keeps AX internal state out of the\nagent-visible workspace (so it isn't surfaced by list_dir and can't collide\nwith the agent's files) while staying within the snapshotted filesystem so\nit survives snapshot/restore.\n\n* Document why steering is not supported over Connect\n\nAdd a comment in the HarnessService Connect loop explaining that mid-run\nsteering is intentionally unsupported: the execution can accept steering via\nQueue, but the HarnessRequest oneof only defines {start, cancel}, so there is\nno wire frame to deliver input after start. Multi-turn conversation is\nexpressed as separate Connect executions that resume via the persisted cursor.\n\n* Persist resume cursors under ~/.ax/cursors\n\nMove the resume-cursor StateDir out of the agent's working directory to a\ndedicated ~/.ax/cursors under the user's home directory. The working directory\nis the agent's operating surface (it reads and edits files there, including\nhidden ones), so keeping AX internal state separate avoids the agent seeing or\nclobbering it. If the home directory cannot be resolved, the harness now fails\nwith an error rather than silently falling back to the current directory."
          },
          {
            "sha": "e1400ea634880eec0ed10fcbf7bd407abef65382",
            "url": "https://github.com/google/ax/commit/e1400ea634880eec0ed10fcbf7bd407abef65382",
            "committedAt": "2026-07-08T19:37:59Z",
            "author": "joycel-github",
            "authorName": "JoyceLiu",
            "committerName": "GitHub",
            "title": "Auto-start Antigravity Python sidecar from ax exec (#275)",
            "message": "Auto-start Antigravity Python sidecar from ax exec (#275)\n\nLocal mode (the default for ax exec) now forks the Antigravity Python\nsidecar via the pythonsidecar package (introduced in #273) so users\ndon't need to launch the harness server out of band. Modeled after\ncmd/ax/harness.go.\n\nAntigravityHarness.New takes an autoStart bool:\n- true  (cliutil, local mode): fork the sidecar, wait for TCPReady,\n  and install a signal handler that stops the sidecar on\n  ctrl-C / SIGTERM. Full lifecycle stays inside antigravity.go so\n  callers don't need a registry -> controller -> antigravity\n  teardown chain.\n- false (e2e demo, unit tests against harnesstest.MockHarnessServer):\n  pure gRPC-client constructor, no fork.\n\nClose stops the forked sidecar; the signal-handler goroutine is the\nprimary caller today.\n\nTests:\n- internal/harness/antigravity/antigravity_test.go covers both\n  autoStart paths via TestNew_AutoStartTrue_StubServer_ForksSidecar\n  (drives the real fork against a minimal stub Python module on\n  PYTHONPATH) and TestNew_AutoStartFalse_NilSidecar.\n- cmd/ax/internal/cliutil/cliutil_test.go's DefaultHarness test uses\n  the same stub-Python trick to exercise the end-to-end wiring\n  through NewControllerFromConfig.\n\ne2e demo (internal/cmd/e2e/main.go) still uses autoStart=false; TODO\nnotes a companion autoStart=true demo as follow-up."
          },
          {
            "sha": "3ed25c7ec5f315748683ddca9bd209a0ad777b8d",
            "url": "https://github.com/google/ax/commit/3ed25c7ec5f315748683ddca9bd209a0ad777b8d",
            "committedAt": "2026-07-09T00:43:48Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Antigravity interactions harness registry and config (#277)",
            "message": "Antigravity interactions harness registry and config (#277)"
          },
          {
            "sha": "81c84f77b2b205b921aa2a287b1a8f54547ffd85",
            "url": "https://github.com/google/ax/commit/81c84f77b2b205b921aa2a287b1a8f54547ffd85",
            "committedAt": "2026-07-09T02:28:18Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Embed python artifacts into ax (#276)",
            "message": "Embed python artifacts into ax (#276)\n\n* Embed python artifacts into ax\n\nAnd setup the AGY harness service at runtime.\n\n* refactor: remove directory and file filtering logic from setup walk function\n\n* refactor: rename installRequirements to install in python sidecar setup\n\n* refactor: simplify Sidecar configuration by passing PYTHONPATH directly to Start method and removing unnecessary environment and binary options\n\n* feat: configure pip install to use local site-packages and filter unwanted files during setup\n\n* feat: support appending to PYTHONPATH and update Python setup path resolution\n\n* refactor: remove redundant file filtering in sidecar setup directory traversal\n\n* refactor: simplify python package installation and add PyPI index URL to pip command\n\n* fix: remove extra index URL from pip install command\n\n* refactor: remove Sidecar.Setup method and move asset extraction logic to external standalone function\n\n* refactor: remove PythonPath configuration field from sidecar.Config in favor of direct global pythonPath usage\n\n* test: remove integration test for antigravity sidecar auto-start logic\n\n* fix: add pypi.org extra-index-url to python package installation command\n\n* refactor: remove Stdin support from pythonsidecar configuration and cleanup redundant harness definitions"
          },
          {
            "sha": "74731320788e8f21b3167b37ae52f48e3972190f",
            "url": "https://github.com/google/ax/commit/74731320788e8f21b3167b37ae52f48e3972190f",
            "committedAt": "2026-07-09T05:08:09Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Setup ~/.ax/antigravity once until a new update arrives (#278)",
            "message": "Setup ~/.ax/antigravity once until a new update arrives (#278)\n\n* Consolidate .ax directory path resolution into a centralized config helper\n\n* refactor: remove unused TargetDir field from SetupOptions in python sidecar tests\n\n* test: update setup test to use HOME directory and verify .ax subdirectory extraction\n\n* refactor: simplify directory path resolution and variable naming in python sidecar setup\n\n* perf: skip redundant file copying and pip installations when dependencies are up to date\n\n* fix: remove redundant check for non-existent requirements file in setup\n\n* refactor: track file updates during extraction to skip unnecessary pip installs\n\n* feat: add progress notification when installing Antigravity SDK\n\n* fix: ensure site-packages directory exists before returning path in setup\n\n* feat: add pypi simple index to pip install command for environment compatibility"
          },
          {
            "sha": "e1950e035ef48b7a8615575442d04115593bd922",
            "url": "https://github.com/google/ax/commit/e1950e035ef48b7a8615575442d04115593bd922",
            "committedAt": "2026-07-09T06:18:25Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Add instructions for accessing ax server via port-forwarding in install script (#280)",
            "message": "Add instructions for accessing ax server via port-forwarding in install script (#280)"
          },
          {
            "sha": "e84907da7936aabc1d89b10c3b828e67fde66c9f",
            "url": "https://github.com/google/ax/commit/e84907da7936aabc1d89b10c3b828e67fde66c9f",
            "committedAt": "2026-07-09T06:18:44Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "ax command should start without an ax.yaml (#279)",
            "message": "ax command should start without an ax.yaml (#279)\n\nFixes #260."
          },
          {
            "sha": "fef750f9065219139a7fdaa506e903fb51a889e5",
            "url": "https://github.com/google/ax/commit/fef750f9065219139a7fdaa506e903fb51a889e5",
            "committedAt": "2026-07-09T21:08:05Z",
            "author": "zbl94",
            "authorName": "zbl94",
            "committerName": "GitHub",
            "title": "Harden Antigravity Interactions harness HTTP client (#285)",
            "message": "Harden Antigravity Interactions harness HTTP client (#285)\n\n* Harden Antigravity Interactions harness HTTP client\n\nFix a substrate suspend/resume failure and tighten the config surface:\n\n- Disable HTTP keep-alives on the harness's default client. On substrate the\n  actor is suspended after a turn and resumed for the next (with a new routable\n  IP), which leaves any pooled keep-alive connection stale; reusing it made the\n  next turn's request fail. Opening a fresh connection per request avoids that\n  at the cost of an extra handshake.\n- Remove the public HTTPClient override from AntigravityInteractionsConfig.\n  External callers don't configure the harness's transport, and exposing it\n  risked silently reintroducing the keep-alive bug. New now always owns its\n  (keep-alive-disabled) client; tests inject a fake transport via an unexported\n  newWithHTTPClient seam.\n- Reorder AntigravityInteractionsConfig fields to list required (Agent,\n  StateDir) before optional, with clearer doc comments.\n\nBuild and package tests pass.\n\n* Explain why the HTTP transport is cloned, not newly created\n\nAddress review feedback: document that cloning DefaultTransport (rather than a\nbare &http.Transport{}) is intentional -- it inherits the production defaults\n(env proxy, dial/TLS/handshake timeouts, HTTP/2) and only overrides keep-alives.\nA fresh empty transport would silently drop those."
          },
          {
            "sha": "3f39ca3f917b01b10c39fe788e69ace363449360",
            "url": "https://github.com/google/ax/commit/3f39ca3f917b01b10c39fe788e69ace363449360",
            "committedAt": "2026-07-09T21:44:57Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Delete obsolete Makefile targets (#284)",
            "message": "Delete obsolete Makefile targets (#284)"
          },
          {
            "sha": "70a2581d4914d2481b3df0f4d7d76347b088df6e",
            "url": "https://github.com/google/ax/commit/70a2581d4914d2481b3df0f4d7d76347b088df6e",
            "committedAt": "2026-07-09T23:24:27Z",
            "author": "zbl94",
            "authorName": "zbl94",
            "committerName": "GitHub",
            "title": "Surface server error events in Antigravity Interactions harness (#288)",
            "message": "Surface server error events in Antigravity Interactions harness (#288)\n\nparseStreamedTurn only handled interaction.* and step.* SSE events; a\nserver-emitted \"error\" event fell through the switch and was silently\ndropped. The turn then returned as completed-but-empty, which:\n\n  - made a failure (e.g. INVALID_ARGUMENT for a malformed client tool\n    result) look like a blank \"no response\" turn, and\n  - persisted the failing interaction's id as a poisoned resume cursor.\n\nAdd an \"error\" case that returns a real error, plus a serverErrorMessage\nhelper that extracts message/status from the error payload. Now a\nturn-level server failure aborts the turn with a descriptive error\ninstead of being hidden.\n\nAdds tests for the error-event path and serverErrorMessage formatting."
          },
          {
            "sha": "fea5d230db6d6ef8cea3cf5fa19b69179f205d09",
            "url": "https://github.com/google/ax/commit/fea5d230db6d6ef8cea3cf5fa19b69179f205d09",
            "committedAt": "2026-07-10T00:44:00Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Run Antigravity Interactions as substrate actors (#287)",
            "message": "Run Antigravity Interactions as substrate actors (#287)\n\n* Run antigravity interactions as actor.\n\n* Add instructions for users.\n\n* Remove a comment.\n\n* Fix readme format."
          },
          {
            "sha": "65f0478ea1b0f503464d6aaf9ce5839105e7a01b",
            "url": "https://github.com/google/ax/commit/65f0478ea1b0f503464d6aaf9ce5839105e7a01b",
            "committedAt": "2026-07-10T03:45:26Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "GitHub",
            "title": "Replace Antigravity sidecar in-memory Agent cache with SDK-native resume (#289)",
            "message": "Replace Antigravity sidecar in-memory Agent cache with SDK-native resume (#289)\n\nThe Python sidecar previously kept a per-conversation Agent instance in\nan in-process dict (self._agents) with a lock, and relied on that cache\nto preserve conversation history across turns. This tied conversation\nstate to a single sidecar process lifetime: any restart, crash, or\nmulti-replica scaling would silently drop history.\n\nDelete the cache and use the Antigravity SDK's own per-conversation\npersistence instead. LocalAgentConfig accepts (conversation_id, save_dir);\nthe SDK's localharness persists trajectory state to\n{save_dir}/{sdk_conv_id}.db. Each turn now:\n\n1. Constructs a fresh Agent scoped to a per-AX-conversation save_dir\n   (~/.ax/antigravity/conversations/{ax_conv_id}/), so each AX\n   conversation gets its own directory with at most one .db file.\n2. If a .db exists there (from a prior turn), passes its stem as the\n   SDK's conversation_id to trigger resume. The SDK's conversation_id\n   is resume-only -- passing a non-existent id errors out -- hence\n   the discover-then-pass pattern.\n3. Runs the turn inside an async-with Agent(...) block, disposing at\n   the end. No process-level state.\n\nMirrors internal/harness/antigravityinteractions/DefaultStateDir()\nconvention (state under ~/.ax/, out of the agent's cwd/operating\nsurface). A TODO references issues #269 and #203 for the eventual\ncontroller-injected save_dir via harness_config.\n\nTest replaces test_grpc_connect_agent_reused (which asserted cache\nbehavior) with test_grpc_connect_agent_per_turn_with_save_dir, which\nasserts per-turn Agent construction and deterministic per-conv save_dir\nnaming.\n\nVerified end-to-end with ax exec --conversation <id>: turn 2 correctly\nrecalls a name introduced in turn 1 across a fresh sidecar process,\nwith only one .db file per conversation on disk. Different --conversation\nids remain isolated."
          },
          {
            "sha": "b71ba523cc08e69980b497e67887f6b54bf23fab",
            "url": "https://github.com/google/ax/commit/b71ba523cc08e69980b497e67887f6b54bf23fab",
            "committedAt": "2026-07-10T21:23:47Z",
            "author": "rakyll",
            "authorName": "Jaana Dogan",
            "committerName": "GitHub",
            "title": "Use GOOGLE_CLOUD_PROJECT variable and remove PROJECT_ID usage (#293)",
            "message": "Use GOOGLE_CLOUD_PROJECT variable and remove PROJECT_ID usage (#293)\n\n* Update install script to use GOOGLE_CLOUD_PROJECT instead of PROJECT_ID\n\nFixes #290.\n\n* Use GOOGLE_CLOUD_PROJECT variable and remove PROJECT_ID usage\n\nFixes #290."
          },
          {
            "sha": "c48baf33a0e9ba1fbad97c3439f3f46b3732c248",
            "url": "https://github.com/google/ax/commit/c48baf33a0e9ba1fbad97c3439f3f46b3732c248",
            "committedAt": "2026-07-10T21:34:17Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Update GOOGLE_CLOUD_PROJECT for interactions path. (#294)",
            "message": "Update GOOGLE_CLOUD_PROJECT for interactions path. (#294)"
          },
          {
            "sha": "4846d9090b8748cf7fd4c9a85c4a604a7ce56793",
            "url": "https://github.com/google/ax/commit/4846d9090b8748cf7fd4c9a85c4a604a7ce56793",
            "committedAt": "2026-07-11T00:30:26Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "GitHub",
            "title": "harness/python: fix stale thought summary test assertions (#291)",
            "message": "harness/python: fix stale thought summary test assertions (#291)\n\nPR #244 normalized thought summary text with a trailing '\\n' in\nharness_server.py but harness_server_test.py wasn't updated.\ntest_grpc_connect_success and test_grpc_connect_buffering assert\nagainst the pre-normalization strings and fail.\n\nThe drift went unnoticed because the Python tests aren't wired\ninto CI (.github/workflows/go.yml only runs go test ./...).\nWiring pytest into CI is the follow-up."
          },
          {
            "sha": "1b58b0943e5e1a4aab33e7d74edc083f1281cc1d",
            "url": "https://github.com/google/ax/commit/1b58b0943e5e1a4aab33e7d74edc083f1281cc1d",
            "committedAt": "2026-07-13T16:55:02Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "GitHub",
            "title": "Antigravity sidecar state dir from config (#292)",
            "message": "Antigravity sidecar state dir from config (#292)\n\n* antigravity: plumb sidecar state_dir from ax.yaml\n\nSidecar's trajectory storage directory was hardcoded in Python. This\nplumbs it through as a yaml config that users can override, matching\nthe pattern already used for the Interactions harness's state_dir.\n\nFlow:\n- ax.yaml: harnesses.antigravity.state_dir (optional; empty = default)\n- config.go: AntigravityHarnessConfig.StateDir field (yaml surface only,\n  no default logic on the Go side)\n- cliutil.go: passes yaml value as-is (empty string when unset)\n- antigravity Go client: appends --state-dir arg only when non-empty\n- Python sidecar: argparse --state-dir with default\n  ~/.ax/antigravity/conversations. Default is a transitional fallback\n  for substrate mode (where ActorTemplate doesn't inject the flag yet).\n  Removable once substrate can set the field via ActorTemplate.\n\nServicer's state_dir is required (no fallback) -- production path always\nreceives it from argparse; tests pass tmp_path.\n\nVerified end-to-end with ax exec:\n- No yaml state_dir  -> ~/.ax/antigravity/conversations/{conv_id}/\n- yaml state_dir: X  -> X/{conv_id}/\n- Different conversations remain isolated across both paths.\n\nCloses part of the local-mode gap in issue #269 (harness_config\ncontract design); a follow-up will do the same for substrate via\nActorTemplate.\n\n* antigravity: address PR review comments (P1/P2/P3)\n\n- P1: two Python tests referenced tmp_path without declaring the fixture;\n  add tmp_path to their signatures.\n- P2: state_dir CLI arg was not tilde-expanded, so ~/.ax/... became a\n  literal ~ dir. Add .expanduser().\n- P3: no Go-side test asserted --state-dir forwarding. Extract\n  buildSidecarArgs() as a small pure helper and add table test for the\n  empty/non-empty cases, plus a yaml parse test for\n  AntigravityHarnessConfig.StateDir.\n\n* antigravity: inline sidecar args build instead of separate helper\n\nFollow-up to review feedback: buildSidecarArgs was overkill for a 3-line\nconditional. Move it back into New() inline. Also drops the associated\nTestBuildSidecarArgs (the arg-forwarding rule is now covered only by\nend-to-end verification)."
          },
          {
            "sha": "7437b2f63389bf2ad633fe3eb6b0bb2be81d7296",
            "url": "https://github.com/google/ax/commit/7437b2f63389bf2ad633fe3eb6b0bb2be81d7296",
            "committedAt": "2026-07-13T16:55:24Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "GitHub",
            "title": "ci: run Python tests for the antigravity harness sidecar (#296)",
            "message": "ci: run Python tests for the antigravity harness sidecar (#296)\n\nThe 17 tests in python/antigravity/harness_server_test.py have never\nrun in CI. .github/workflows/go.yml only runs 'go test ./...' and the\nMakefile 'test' target likewise only runs Go. That let PR #244 land\nwith 2 stale assertions unnoticed (fixed in #291).\n\nAdds:\n- .github/workflows/python.yml -- dedicated Python workflow (kept\n  separate from the Go-only go.yml so each can evolve independently).\n- Makefile 'test-python' target for local parity.\n\nTest deps are inlined in the workflow rather than added as a separate\nrequirements-test.txt -- the diff is 2 packages ('pytest>=7.0',\n'pytest-timeout>=2.0'), not worth its own file. Version floors match\nthe upstream google-antigravity SDK's dev extras so this doesn't\ndrift as pytest evolves.\n\n--timeout=30 --timeout-method=thread guards against hung gRPC servers\nso a stuck test can't eat the whole workflow budget."
          },
          {
            "sha": "c7e9f295e392c7ae5f7336eb1fc0efbcc745bbfc",
            "url": "https://github.com/google/ax/commit/c7e9f295e392c7ae5f7336eb1fc0efbcc745bbfc",
            "committedAt": "2026-07-13T21:55:05Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "GitHub",
            "title": "parse harness config from request (#295)",
            "message": "parse harness config from request (#295)\n\n* antigravity: parse and validate request harness_config\n\nParse HarnessStart.harness_config (JSON-in-bytes) and overlay it onto\nthe server's default LocalAgentConfig before each turn.\n\n- Blocks a request from overriding AX-owned persistence fields\n  (save_dir, conversation_id) via _AX_MANAGED_CONFIG_FIELDS; these are\n  injected last so a request can't redirect trajectory storage.\n- Reconstructs the config (not model_copy) so the SDK re-validates the\n  overlaid values and surfaces its own error; invalid config fails the\n  turn with INVALID_ARGUMENT instead of crashing.\n- save_dir derives from the injected state_dir (#292) as\n  state_dir / conversation_id.\n\n* antigravity: address harness_config review comments\n\n- Inline _parse_harness_config into _build_config_for so the parsed\n  dict stays a local intermediate; the method's only boundary type is\n  the validated LocalAgentConfig (no dict[str, object] across a helper\n  boundary). Addresses the \"introduce a type for the config\" comment.\n- Make per-conv save_dir test assertions portable: compare against\n  str(tmp_path / conversation_id) instead of hardcoding \"/conv-1\", and\n  drop the now-vestigial Path.home monkeypatch (save_dir derives from\n  the injected state_dir since #292). Addresses the Windows path\n  separator comment.\n\n_AX_MANAGED_CONFIG_FIELDS keeps guarding both conversation_id and\nsave_dir on purpose: harness_config is a separate client-controlled\nsurface from the request's conversation_id, so blocking it prevents a\nrequest from redirecting another conversation's trajectory storage."
          },
          {
            "sha": "a953396b6d2fb5e9740b3c7718ce4ca2ac1e6781",
            "url": "https://github.com/google/ax/commit/a953396b6d2fb5e9740b3c7718ce4ca2ac1e6781",
            "committedAt": "2026-07-14T00:04:49Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "GitHub",
            "title": "antigravity: reject unknown harness_config fields (#301)",
            "message": "antigravity: reject unknown harness_config fields (#301)\n\nLocalAgentConfig uses pydantic's default extra=\"ignore\", so an\nunrecognized field in a request's harness_config -- e.g. a typo like\n\"system_instruction\" for \"system_instructions\" -- was silently dropped\nand the caller believed the override took effect when it did not.\n\nAdd _reject_disallowed_fields(overrides), which factors two key checks\ninto one helper and raises HarnessConfigError (mapped to\nINVALID_ARGUMENT) naming the offending field(s):\n  - fields that come from outside harness_config (_NON_HARNESS_CONFIG_\n    FIELDS: conversation_id from the runtime request, save_dir from the\n    server's state_dir), and\n  - unknown top-level fields.\n\nValidation is best-effort and top-level only: nested-key and value/type\nvalidation is delegated to the SDK's own LocalAgentConfig validation at\nconstruction time."
          },
          {
            "sha": "8eff724ca6833c507a5d8178bdbc9f13e5d9c280",
            "url": "https://github.com/google/ax/commit/8eff724ca6833c507a5d8178bdbc9f13e5d9c280",
            "committedAt": "2026-07-14T20:03:01Z",
            "author": "wjjclaud",
            "authorName": "Junjie Wang",
            "committerName": "GitHub",
            "title": "Interactions actor reads config from yaml. (#302)",
            "message": "Interactions actor reads config from yaml. (#302)"
          },
          {
            "sha": "9873c8747553031a1df660964b688c73fc74254d",
            "url": "https://github.com/google/ax/commit/9873c8747553031a1df660964b688c73fc74254d",
            "committedAt": "2026-07-14T20:28:49Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "GitHub",
            "title": "antigravity: stop exposing harness state_dir in ax.yaml (#304)",
            "message": "antigravity: stop exposing harness state_dir in ax.yaml (#304)\n\nstate_dir is an AGY SDK implementation detail (where trajectory /\nresume-cursor storage lives), not something AX users should configure.\nRemove the yaml surface for both built-in harnesses and derive the path\ninternally from config.AXAssetsDir().\n\n- config: drop StateDir from AntigravityHarnessConfig and\n  AntigravityInteractionsHarnessConfig.\n- antigravity: add DefaultStateDir() -> ~/.ax/antigravity/conversations,\n  mirroring antigravityinteractions.DefaultStateDir(). cliutil now passes\n  this into antigravity.New instead of the yaml value.\n- cliutil: interactions harness always uses DefaultStateDir(); drop the\n  yaml read + fallback.\n\nThe internal APIs (antigravity.New's stateDir arg, the required\nAntigravityInteractionsConfig.StateDir field, and the Python sidecar's\n--state-dir default) are unchanged -- only the user-facing ax.yaml knob\nis removed.\n\nAddresses rakyll's follow-up on #292."
          },
          {
            "sha": "37718e20bf2ee578eaa007e2a7709b71b19f6e87",
            "url": "https://github.com/google/ax/commit/37718e20bf2ee578eaa007e2a7709b71b19f6e87",
            "committedAt": "2026-07-15T00:40:31Z",
            "author": "zbl94",
            "authorName": "zbl94",
            "committerName": "GitHub",
            "title": "Add Gemini Enterprise Skill Registry integration for local harnesses (#300)",
            "message": "Add Gemini Enterprise Skill Registry integration for local harnesses (#300)\n\nMaterialize agentskills.io skills from the Gemini Enterprise Skill Registry\n(Vertex AI v1beta1) into on-disk folders before the harness starts, so the\nbuilt-in harnesses can use registry-hosted skills on the local `ax exec` /\n`ax serve` path.\n\n- internal/skills/geminienterprise: harness-agnostic package that reads\n  config.SkillsConfig, drives the registry client (ListSkills / GetSkill /\n  GetSkillRevision / skills:retrieve), safe-unzips payloads to\n  <target_dir>/<skill-id>/, and reports what it wrote. First-wins on\n  duplicate ids with a warning; fail-safe (a registry error never blocks\n  harness startup).\n- config: top-level `skills.registries[]` (harness-agnostic -- each actor\n  runs a single harness that consumes the materialized folder). Per-registry\n  selection (skills / query / all), required target_dir, and a validated\n  \"exactly one selection mode\" rule. Also wires the interactions harness's\n  system_instruction from ax.yaml.\n- cliutil: materializes skills once, up front, at controller construction;\n  for the interactions harness (no SKILLS_DIR concept) it appends a discovery\n  pointer to the system instruction.\n\nScope: local path only; the substrate/pod path does not yet read ax.yaml.\nVerified end-to-end against a live registry (by-id and by-query)."
          },
          {
            "sha": "4d38084e773bbdaf62072bde3b58976450dac570",
            "url": "https://github.com/google/ax/commit/4d38084e773bbdaf62072bde3b58976450dac570",
            "committedAt": "2026-07-15T17:27:16Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "GitHub",
            "title": "antigravity: format harness_server.py with black (#311)",
            "message": "antigravity: format harness_server.py with black (#311)"
          },
          {
            "sha": "f14e57d896b2838b383821346f405d7f363a91cf",
            "url": "https://github.com/google/ax/commit/f14e57d896b2838b383821346f405d7f363a91cf",
            "committedAt": "2026-07-15T17:28:01Z",
            "author": "joycel-github",
            "authorName": "Joyce Liu",
            "committerName": "GitHub",
            "title": "docs(readme): fix invalid harness in exec example (#309)",
            "message": "docs(readme): fix invalid harness in exec example (#309)\n\nThe exec example used `--harness coding`, but no \"coding\" harness\nexists; runHarness only accepts \"antigravity\" and\n\"antigravity-interactions\" and errors otherwise, so the command as\nwritten fails. Point the example at the real \"antigravity\" harness."
          },
          {
            "sha": "968348aea14492243d20837474d976fc1f714a98",
            "url": "https://github.com/google/ax/commit/968348aea14492243d20837474d976fc1f714a98",
            "committedAt": "2026-07-15T17:34:14Z",
            "author": "zbl94",
            "authorName": "zbl94",
            "committerName": "GitHub",
            "title": "Honor view_file line range and cap result size (#303)",
            "message": "Honor view_file line range and cap result size (#303)\n\n* Honor view_file line range and cap result size\n\nexecViewFile read the whole file and ignored the agent's StartLine/EndLine,\nso viewing a large file returned its entire content as the tool result --\na ~900KB blob for a 3k-line CSV stalled the following turn.\n\nImplement the Antigravity view_file contract (1-indexed inclusive line range\nwith slice-notation windowing) plus defensive caps:\n- StartLine/EndLine window (neither=first N lines; start-only=next N forward;\n  end-only=previous N backward; both=precise range, capped to N).\n- viewFileMaxLines / viewFileMaxBytes caps so a large file can never blob.\n- ContentOffset honored as the read position within the windowed content.\n\nThe result payload is just {\"content\": ...}; the view_file result schema is\ndefined server-side, so no extra fields are added.\n\nAdds intArg/intArgOK helpers and tests for windowing, byte cap, offset read,\nand range honoring.\n\n* view_file: UTF-8-safe byte cap + pagination metadata\n\nAddress review feedback on the byte cap:\n\n- applyByteWindow backs the cut off to the last complete UTF-8 rune so a\n  multi-byte character straddling viewFileMaxBytes is never split (raw byte\n  slicing could produce invalid UTF-8, corrupting the last char and JSON\n  serialization).\n- execViewFile returns the metadata the server needs to distinguish a\n  complete read from a paginated/byte-truncated one: content, start_line/\n  end_line (0-indexed inclusive served range), content_offset,\n  line_range_bytes (total bytes of the line range pre-byte-cap), and\n  num_lines/num_bytes. The server detects truncation via\n  content_offset+len(content) < line_range_bytes and prompts the model to\n  resume from that offset.\n\nA paired server change reads these fields instead of hardcoding\nstart_line=0/end_line=last.\n\nAdds tests for UTF-8 boundary capping, pagination metadata, and resume."
          }
        ]
      },
      "records": [
        {
          "repository": "google/ax",
          "number": 88,
          "url": "https://github.com/google/ax/pull/88",
          "title": "go mod tidy",
          "body": "",
          "author": "rakyll",
          "createdAt": "2026-06-16T03:19:00Z",
          "mergedAt": "2026-06-16T04:13:23Z",
          "additions": 0,
          "deletions": 52,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 92,
          "url": "https://github.com/google/ax/pull/92",
          "title": "Remove custom harness namespace and resources",
          "body": "Fixes #90. ",
          "author": "rakyll",
          "createdAt": "2026-06-16T03:52:20Z",
          "mergedAt": "2026-06-16T04:13:56Z",
          "additions": 4,
          "deletions": 85,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 94,
          "url": "https://github.com/google/ax/pull/94",
          "title": "ci: add go mod tidy verification step to workflow",
          "body": "## Summary\n- Added `Verify go mod tidy` step to the GitHub Actions Go workflow.\n- This step runs `go mod tidy` and verifies that there are no uncommitted changes in `go.mod` or `go.sum` (using `git diff --exit-code`).\n- This will automatically prevent any pull requests from landing untidy dependency files.\n\n## Type of Change\n- [x] New feature (non-breaking change which adds functionality)\n\n## Related Issues\n- Related to the manual cleanup in PR #88.\n\n## Test Plan\n- [x] Unit tests pass (`go test ./...`)\n- [x] Manually verified: Ran `go mod tidy && git diff --exit-code go.mod go.sum` locally in the workspace, confirming it exits with code 0 on a clean repo.",
          "author": "anj-s",
          "createdAt": "2026-06-16T04:27:45Z",
          "mergedAt": "2026-06-16T04:30:45Z",
          "additions": 5,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 89,
          "url": "https://github.com/google/ax/pull/89",
          "title": "Use SubstrateHarness if AX_SUBSTRATE=1",
          "body": "Fixes #87, #96, #95.",
          "author": "rakyll",
          "createdAt": "2026-06-16T03:29:46Z",
          "mergedAt": "2026-06-16T05:40:45Z",
          "additions": 77,
          "deletions": 107,
          "changedFiles": 7
        },
        {
          "repository": "google/ax",
          "number": 119,
          "url": "https://github.com/google/ax/pull/119",
          "title": "refactor: remove ate build tag",
          "body": "This build tag is no longer is needed because Substrate is public. ",
          "author": "rakyll",
          "createdAt": "2026-06-16T06:26:47Z",
          "mergedAt": "2026-06-16T14:37:58Z",
          "additions": 8,
          "deletions": 31,
          "changedFiles": 5
        },
        {
          "repository": "google/ax",
          "number": 115,
          "url": "https://github.com/google/ax/pull/115",
          "title": "docs: update actor template name in wait command example",
          "body": "We use ax-harness-template now, see https://github.com/google/ax/pull/89.",
          "author": "rakyll",
          "createdAt": "2026-06-16T05:43:42Z",
          "mergedAt": "2026-06-16T14:38:20Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 82,
          "url": "https://github.com/google/ax/pull/82",
          "title": "Add e2e substrate tests with mocks.",
          "body": "## Summary\r\n- Build and test with `-tags harness` in CI so the substrate/harness deployment path is actually compiled and exercised on every PR.\r\n- Add a hermetic end-to-end test for `SubstrateHarness` (Start → Run → Close) using in-process fakes for the substrate control plane and the actor's HarnessService.\r\n- Extract shared test mocks into `mocks_test.go` and move the mocks from `antigravity_test.go` onto the shared file, including:\r\n  - A fakeControlServer for substrate control plane\r\n  - A fakeHarnessServer for a harness service\r\n",
          "author": "wjjclaud",
          "createdAt": "2026-06-13T00:31:01Z",
          "mergedAt": "2026-06-16T20:52:33Z",
          "additions": 474,
          "deletions": 164,
          "changedFiles": 5
        },
        {
          "repository": "google/ax",
          "number": 121,
          "url": "https://github.com/google/ax/pull/121",
          "title": "Update the deployment script with ateom image and wait step.",
          "body": "## Summary\r\n- Build and **pin the `ateom-gvisor` worker image** from the `go.mod` pinned substrate module, instead of letting `ko apply` compile it from the AX module — so AX's `go.mod` stays tidy. Otherwise, we would need to override the `go mod tidy` with some indirect dependencies from substrate.\r\n- `install-ax.sh --deploy-ax-server` now **waits for the antigravity ActorTemplate to become Ready** (golden snapshot) before returning, with a small **progress spinner**.\r\n- Bump up substrate version.\r\n\r\nWill merge the Antigravity into ax image in a follow up for #120.\r\n\r\n## Tested\r\n`./internal/hack/install-ax.sh --deploy-ax-server`",
          "author": "wjjclaud",
          "createdAt": "2026-06-16T23:42:59Z",
          "mergedAt": "2026-06-17T19:26:11Z",
          "additions": 83,
          "deletions": 15,
          "changedFiles": 5
        },
        {
          "repository": "google/ax",
          "number": 126,
          "url": "https://github.com/google/ax/pull/126",
          "title": "Remove trace command and related UI utilities",
          "body": "We can add this capability back once the event log is stable.",
          "author": "rakyll",
          "createdAt": "2026-06-17T20:45:57Z",
          "mergedAt": "2026-06-17T20:55:04Z",
          "additions": 0,
          "deletions": 650,
          "changedFiles": 4
        },
        {
          "repository": "google/ax",
          "number": 130,
          "url": "https://github.com/google/ax/pull/130",
          "title": "Remove forking capabilities until controller2 is stable",
          "body": "",
          "author": "rakyll",
          "createdAt": "2026-06-17T20:57:43Z",
          "mergedAt": "2026-06-17T21:16:22Z",
          "additions": 70,
          "deletions": 1300,
          "changedFiles": 20
        },
        {
          "repository": "google/ax",
          "number": 83,
          "url": "https://github.com/google/ax/pull/83",
          "title": "feat: reuse agent instance per conversation ID in antigravity harness server",
          "body": "## Summary\n- Reuses `Agent` instances per `conversation_id` in the Python antigravity harness server to avoid recreating them on each Connect call.\n- Clears `conversation._steps` before extending it with history on each turn to prevent history duplication.\n- Introduces a `cleanup()` method to gracefully exit all active agent sessions upon server shutdown.\n- Added a `TODO` for future eviction/idle-timeout policy implementation.\n\n## Type of Change\n- [x] Bug fix\n- [ ] New feature\n- [ ] Refactor\n- [ ] Documentation\n- [ ] Breaking change\n\n## Related Issues\nCloses #65\n\n## Test Plan\n- [x] Unit tests pass: `pytest python/antigravity/harness_server_test.py` passes.\n- [x] Integration tests pass: `go test ./internal/harness/...` passes.\n- [x] Verified locally: Confirmed only 2 agents are instantiated when 3 turns are fired (2 for conv-1, 1 for conv-2).\n\n## Notes for Reviewer\n- Resolves the issue where agent sessions were stateless and recreated per gRPC Connect call.\n- Uses `asyncio.Lock` to ensure thread-safety when accessing/initializing the agent map.",
          "author": "anj-s",
          "createdAt": "2026-06-13T05:22:15Z",
          "mergedAt": "2026-06-17T21:19:18Z",
          "additions": 176,
          "deletions": 64,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 122,
          "url": "https://github.com/google/ax/pull/122",
          "title": "Build one comprehensive ax image for the ax-server and harness",
          "body": "## Summary\r\n- Replace the separate Antigravity image with a single comprehensive **`ax` image** (full Debian + Python + the Go `ax` binary), used by **both** the ax-server (`ax serve`) and the harness actor (`ax harness`).\r\n- `ax harness` now **forks the Antigravity Python sidecar** instead of serving the Go demo echo (which is removed).\r\n- Removed the separate Dockerfile for antigravity.\r\n\r\nUpdates #120.\r\n\r\n## Tested\r\nOn a cluster with substrate ready:\r\n1. `./internal/hack/install-ax.sh --deploy-ax-server`\r\n2. `kubectl port-forward -n ax rs/ax-server 8494:8494`\r\n3. `ax exec --server=localhost:8494 --input=\"what's the weather in NYC?\"`",
          "author": "wjjclaud",
          "createdAt": "2026-06-17T02:34:00Z",
          "mergedAt": "2026-06-17T21:21:54Z",
          "additions": 159,
          "deletions": 258,
          "changedFiles": 8
        },
        {
          "repository": "google/ax",
          "number": 85,
          "url": "https://github.com/google/ax/pull/85",
          "title": "fix(harness): improve error message when model API key is missing",
          "body": "## Summary\n- Implemented robust credentials validation inside the Antigravity Python harness server (`harness_server.py`) before entering the agent session context.\n- Validates environment variables (`GEMINI_API_KEY`, `GOOGLE_API_KEY`, `GOOGLE_GENAI_USE_VERTEXAI`, `GOOGLE_GENAI_USE_ENTERPRISE`) with explicit truthiness checking (e.g. ignoring `\"False\"` strings).\n- Validates programmatic credentials defined directly in configuration files, including top-level properties and nested `gemini_config` (supporting both shared and model-specific `models.default.api_key` properties).\n- Cleans up standard imports (moving `import os` to the top of `harness_server.py`).\n- Added pytest unit tests:\n  - `test_grpc_connect_missing_credentials`: verifies failure response when credentials are not configured.\n  - `test_grpc_connect_programmatic_credentials`: verifies success response when credentials are set programmatically inside the config file despite missing environment variables.\n- Updated `mock_config` fixture to inject mock env keys by default, ensuring existing success tests pass cleanly in clean CI environments.\n\n## Type of Change\n- [x] Bug fix\n- [ ] Refactor\n\n## Related Issues\nCloses #63\n\n## Test Plan\n- [x] Python tests pass: `pytest python/antigravity/harness_server_test.py`\n- [x] Go integration tests pass: `go test ./...`",
          "author": "anj-s",
          "createdAt": "2026-06-13T08:12:03Z",
          "mergedAt": "2026-06-17T21:28:43Z",
          "additions": 173,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 74,
          "url": "https://github.com/google/ax/pull/74",
          "title": "ax: implement monitor command and conversations API",
          "body": "## Summary\n- **AX Monitor CLI Command**: Added the `monitor` command to the `ax` CLI, registered in `cmd/ax/main.go`.\n- **Backend API**: Implemented a local HTTP API endpoint `/api/conversations` that queries the SQLite database to fetch and summarize AX conversation histories.\n- **SQLite Parsing Fixes**: Handled sqlite timestamps by scanning them as strings and parsing them manually in Go to avoid scan errors when using SQLite aggregations.\n- **Unit Tests**: Added `cmd/ax/monitor_test.go` to verify correctness of conversation fetching logic.\n\n## Type of Change\n- [x] New feature (non-breaking change which adds functionality)\n- [ ] Bug fix (non-breaking change which fixes an issue)\n- [ ] Refactor\n- [ ] Documentation\n- [ ] Breaking change (fix or feature that would cause existing functionality to not work as expected)\n\n## Related Issues\n*Part 4 of the Observability & Monitoring epic. Stacked on top of PR #70.*\n\n## Test Plan\n- **Automated Tests**: Unit tests pass:\n  ```bash\n  go test -v ./cmd/ax\n  ```\n- **Manual Verification**: Verified that command compilation works both with and without the `harness` build tag:\n  ```bash\n  go build -o bin/ax ./cmd/ax\n  go build -tags harness -o bin/ax_harness ./cmd/ax\n  ```\n\n## Notes for Reviewer\nThis is the fourth of 5 planned modular PRs to roll out comprehensive AX observability.\nIt exposes a backend JSON API for conversation lists.\n",
          "author": "anj-s",
          "createdAt": "2026-06-10T21:07:07Z",
          "mergedAt": "2026-06-17T22:09:31Z",
          "additions": 364,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "google/ax",
          "number": 75,
          "url": "https://github.com/google/ax/pull/75",
          "title": "ax: implement monitor dashboard Web UI",
          "body": "## Summary\n- **Premium Dashboard Frontend**: Added a beautiful dark-mode Single Page Application (SPA) in `cmd/ax/web/index.html`.\n- **Static Assets Embedding**: Configured Go's `//go:embed` to package the dashboard directly inside the `ax` CLI binary.\n- **Trace Visualization Integration**: Added an inline interactive execution trace viewer that loads and visualizes historical/active runs dynamically (migrated logic from the standalone `ax trace` command).\n- **Auto-Initialization**: Enforced database schema initialization in `ax monitor` to avoid runtime failures on empty databases.\n- **Environment Automation Script**: Created `hack/run-ax-environment.sh` to boot the python harness server, AX orchestrator (`ax serve`), and AX monitor dashboard in a single command, handling SIGINT cleanups gracefully.\n\n## Type of Change\n- [x] New feature (non-breaking change which adds functionality)\n- [ ] Bug fix\n- [ ] Refactor\n- [ ] Documentation\n- [ ] Breaking change\n\n## Related Issues\n*Part 5 of the Observability & Monitoring epic. Stacked on top of PR #74.*\n\n## Test Plan\n- **Automated Tests**: Unit tests pass:\n  ```bash\n  go test -v ./cmd/ax\n  ```\n- **Manual Verification**: Run the automated environment script, which launches all 3 servers and automatically opens the browser to the dashboard:\n  ```bash\n  export GEMINI_API_KEY=\"your-key\"\n  ./hack/run-ax-environment.sh\n  ```\n\n## Notes for Reviewer\nThis is the final PR in the Observability & Monitoring epic, completing the rollout of the premium local web dashboard.\n",
          "author": "anj-s",
          "createdAt": "2026-06-10T21:14:52Z",
          "mergedAt": "2026-06-17T22:19:47Z",
          "additions": 1490,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 84,
          "url": "https://github.com/google/ax/pull/84",
          "title": "refactor: implement stateful Display and inject io.Writer",
          "body": "## Summary\n- Refactored `Display` in the AX CLI client to implement a state machine that tracks the type of last printed chunk (`stateNone`, `stateText`, `stateThought`). This enables real-time concatenation of streamed output blocks (text and reasoning logs) and correctly places separating newlines.\n- Injected `io.Writer` interface dependency into `Display` (defaulting to `os.Stdout`).\n- Eliminated global standard output redirection pipes in tests, replacing them with a local thread-safe `bytes.Buffer` wrapper.\n- Enabled safe parallel execution of tests (`t.Parallel()`).\n- Removed redundant and performance-blocking `os.Stdout.Sync()` calls on TTY devices.\n- Cleaned up legacy unused dead code fields `loadingVisible` and `loadingStopCh`.\n\n## Type of Change\n- [x] Refactor\n- [ ] Bug fix\n\n## Related Issues\nCloses #64\n\n## Test Plan\n- [x] Unit tests pass: `go test -v ./cmd/ax/internal` passes.\n- [x] Integration tests pass: `go test ./...` passes.\n- [x] Manually verified: Streamed model and thought chunks print concatenated on a single line sequentially, transitioning to newlines only on state changes.",
          "author": "anj-s",
          "createdAt": "2026-06-13T06:25:33Z",
          "mergedAt": "2026-06-17T22:20:34Z",
          "additions": 258,
          "deletions": 51,
          "changedFiles": 3
        },
        {
          "repository": "google/ax",
          "number": 137,
          "url": "https://github.com/google/ax/pull/137",
          "title": "Build antigravity package directly from pip install.",
          "body": "- Build the `ax` image by `pip install`the Antigravity Python\r\n  deps directly from PyPI at build time, instead of pre-downloading a linux/amd64\r\n  wheel cache and installing it via a `wheels` build context.\r\n- Removes the separate `--fetch-wheels` option.",
          "author": "wjjclaud",
          "createdAt": "2026-06-18T02:58:22Z",
          "mergedAt": "2026-06-18T05:53:42Z",
          "additions": 14,
          "deletions": 104,
          "changedFiles": 6
        },
        {
          "repository": "google/ax",
          "number": 139,
          "url": "https://github.com/google/ax/pull/139",
          "title": "Update ateomImage path in deployment manifest",
          "body": "Updating the  ateomImage to fix the failing`./hack/install-ax.sh --deploy-ax-server`.",
          "author": "rakyll",
          "createdAt": "2026-06-18T05:37:18Z",
          "mergedAt": "2026-06-18T05:55:45Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 138,
          "url": "https://github.com/google/ax/pull/138",
          "title": "Remove harness test fallback and delete harnesstest package",
          "body": "Updates #77.",
          "author": "rakyll",
          "createdAt": "2026-06-18T05:20:43Z",
          "mergedAt": "2026-06-18T06:04:17Z",
          "additions": 73,
          "deletions": 150,
          "changedFiles": 5
        },
        {
          "repository": "google/ax",
          "number": 143,
          "url": "https://github.com/google/ax/pull/143",
          "title": "Auto select KO_DOCKER_REPO and KO_DEFAULTPLATFORMS",
          "body": "",
          "author": "rakyll",
          "createdAt": "2026-06-18T06:21:05Z",
          "mergedAt": "2026-06-18T15:08:09Z",
          "additions": 7,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 148,
          "url": "https://github.com/google/ax/pull/148",
          "title": "Remove ATE agents",
          "body": "SubstrateHarness will replace this capability. SubstrateAgent is dead code.",
          "author": "rakyll",
          "createdAt": "2026-06-18T07:30:28Z",
          "mergedAt": "2026-06-18T15:08:44Z",
          "additions": 9,
          "deletions": 218,
          "changedFiles": 4
        },
        {
          "repository": "google/ax",
          "number": 151,
          "url": "https://github.com/google/ax/pull/151",
          "title": "Remove Colab agent support",
          "body": "Doing some cleanups to prepare us to remove the Agent interface. We can rethink about this use case in the long term and can use the deleted implementation as a reference.\r\n\r\nFixes #127.",
          "author": "rakyll",
          "createdAt": "2026-06-18T18:34:46Z",
          "mergedAt": "2026-06-18T19:14:06Z",
          "additions": 1,
          "deletions": 1613,
          "changedFiles": 11
        },
        {
          "repository": "google/ax",
          "number": 153,
          "url": "https://github.com/google/ax/pull/153",
          "title": "Make controller2 use its own eventlog package",
          "body": "This will allow us to make schema changes to the event log easily without causing issues to the existing event log implementation.",
          "author": "rakyll",
          "createdAt": "2026-06-22T18:15:27Z",
          "mergedAt": "2026-06-22T18:21:58Z",
          "additions": 716,
          "deletions": 20,
          "changedFiles": 8
        },
        {
          "repository": "google/ax",
          "number": 154,
          "url": "https://github.com/google/ax/pull/154",
          "title": "Encapsulate event logging in a new logger",
          "body": "- Extend ConversationEvent with harness metadata\r\n- Don't allow Exec requests to switch to a different harness\r\n\r\nFollow-up:\r\n- Continue the same execution if it's not completed, or start a new execution if it's already completed.",
          "author": "rakyll",
          "createdAt": "2026-06-22T18:48:14Z",
          "mergedAt": "2026-06-22T19:07:05Z",
          "additions": 112,
          "deletions": 36,
          "changedFiles": 3
        },
        {
          "repository": "google/ax",
          "number": 157,
          "url": "https://github.com/google/ax/pull/157",
          "title": "fix(antigravity): Buffer sequential thoughts and text tokens to prevent token-by-token streaming",
          "body": "## Summary\n- Modified the Antigravity gRPC Harness server (`python/antigravity/harness_server.py`) to buffer contiguous blocks of sequential `Text` and `Thought` tokens. Consolidated tokens are yielded as a single `TextContent` message when the contiguous block ends or when a different message type (like a `ToolCall`) is received, adhering to the Interactions proto standard.\n- Refactored the buffering logic in `harness_server.py` using clean local helper functions (`flush_text()`, `flush_thought()`) to eliminate code duplication across boundary switches, tool calls, and loop flushes.\n- Kept GKE Substrate build and manifest changes reverted on this branch to ensure it is isolated cleanly from the infrastructure PR (#156).\n\n## Type of Change\n- [x] Bug fix\n- [ ] New feature\n- [x] Refactor\n- [ ] Documentation\n- [ ] Breaking change\n\n## Related Issues\nCloses #146\n\n## Test Plan\n- [x] Unit tests pass: Added python harness server tests (`python3 -m pytest python/antigravity/harness_server_test.py`) and ran all Go unit tests (`make test`).\n- [x] Manually verified: Deployed to GKE Substrate, port-forwarded `ax-server`, and ran client queries successfully, returning consolidated responses.\n\n## Notes for Reviewer\n- Resolves token-by-token streaming bugs where individual raw tokens were incorrectly emitted in separate `TextContent` envelopes.\n",
          "author": "anj-s",
          "createdAt": "2026-06-22T19:26:03Z",
          "mergedAt": "2026-06-22T20:07:34Z",
          "additions": 137,
          "deletions": 19,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 158,
          "url": "https://github.com/google/ax/pull/158",
          "title": "Bump substrate version and update documentation.",
          "body": "- Bump substrate version for latest updates.\r\n- Update documentation substrate version compatibility, and docker/podman authentication.\r\n  - Add instructions to sync user's substrate with ax's pinned version.\r\n  - Add instructions to run authentication command before deployment.",
          "author": "wjjclaud",
          "createdAt": "2026-06-22T23:57:21Z",
          "mergedAt": "2026-06-23T04:16:54Z",
          "additions": 45,
          "deletions": 18,
          "changedFiles": 5
        },
        {
          "repository": "google/ax",
          "number": 159,
          "url": "https://github.com/google/ax/pull/159",
          "title": "Remove docker agent example",
          "body": "## Summary\r\n- Removes `examples/docker_agent/` (6 files, 481 lines deleted) as part of Controller2 migration preparation as per \r\nhttps://github.com/google/ax/issues/132\r\n\r\n## Validation\r\n- `rg \"docker_agent|docker agent|Dockerfile for|examples/docker_agent\"` → no matches.\r\n- `go build ./...` → clean.\r\n- `go test ./...` → all packages pass.\r\n\r\nNo references to `docker_agent`, `DockerAgent`, or `docker-writer` exist outside the removed directory (the `KO_DOCKER_REPO` reference in the Makefile is unrelated).\r\n\r\nFixes #132",
          "author": "joycel-github",
          "createdAt": "2026-06-23T01:52:50Z",
          "mergedAt": "2026-06-23T05:04:59Z",
          "additions": 0,
          "deletions": 481,
          "changedFiles": 6
        },
        {
          "repository": "google/ax",
          "number": 160,
          "url": "https://github.com/google/ax/pull/160",
          "title": "Remove A2A agent and bridge",
          "body": "## Summary\r\nRemoves the A2A protocol integration end-to-end (24 files changed, -3608 lines) as part of Controller2 migration preparation https://github.com/google/ax/issues/128 \r\n\r\n**Deleted:**\r\n- `examples/a2a_agent/` — Python coding agent example\r\n- `internal/experimental/a2abridge/` — A2A ↔ AX bridge (11 files)\r\n- `internal/experimental/agent/a2a.go` — A2A agent client\r\n- `internal/auth/` — only consumer was A2A\r\n\r\n**Updated:**\r\n- `internal/config/config.go` — dropped `A2AConfig` and the `Protocol`/`Auth`/`Headers`/`A2A` fields on `RemoteAgentConfig` (only `registerA2A` read them)\r\n- `internal/controller/registry.go` — `registerA2A` removed; protocol switch collapses to the single AXP path\r\n- `ax.yaml`, `README.md`, `.gitignore` — removed A2A references\r\n- `go.mod` / `go.sum` — `go mod tidy` removed `github.com/a2aproject/a2a-go/v2`\r\n\r\n## Validation\r\n- No stale references: `grep \"a2a\\|A2A\\|a2abridge\\|a2aproject\"` across Go/YAML/Markdown/proto/Makefile/sh → no matches\r\n- `go build ./...` → clean\r\n- `go test ./...` → all packages pass\r\n\r\nFixes #128",
          "author": "joycel-github",
          "createdAt": "2026-06-23T02:02:53Z",
          "mergedAt": "2026-06-23T05:10:21Z",
          "additions": 2,
          "deletions": 3610,
          "changedFiles": 24
        },
        {
          "repository": "google/ax",
          "number": 163,
          "url": "https://github.com/google/ax/pull/163",
          "title": "feat: Support Postgres as database on substrate.",
          "body": "Add a durable, shared PostgreSQL event-log backend for the in-cluster ax-server, parallel to the per-pod ephemeral SQLite db. SQLite stays the default for local/dev; Postgres is used on substrate. Update #152.\r\n\r\n## What's changed\r\n**Event log (`internal/controller2/eventlog/`)**\r\n- `sql.go` (new): branched from the original sqlite.go as a shared library `sqlEventLog` implementing the `EventLog` interface once over `database/sql`.\r\n- `sql_test.go` (new): branched from the original sqlite_test.go, contains tests for shared event log logic.\r\n- `postgres.go` (new): constructor for postgres sqlEventLog.\r\n- `sqlite.go`: trimmed to its constructor for sqlite sqlEventLog.\r\n- No schema changes.\r\n\r\n**Call site**\r\n- `EventLogBuilder` picks Postgres when `AX_SUBSTRATE` is set, otherwise SQLite.\r\n- `harnessHandler.OnMessage` now sets `ExecResponse.Seq` from the append result (previously always `0`), so `ax exec` shows the real sequence number.\r\n\r\n**Deployment**\r\n- Add PostgresConfig in `config.go`.\r\n- Add postgres configs in yaml.\r\n- Split teardown: `--delete-ax-server` removes the server + harness but **preserves** the DB (keeps the namespace, Postgres, and PVC); `--delete-all` removes everything including the namespace/DB/PVC.\r\n\r\n## Tested\r\ne2e test on substrate: \r\n- `--deploy-ax-server` with postgres DB created.\r\n- `ax exec` shows correct seq number.\r\n- Query DB with `kubectl -n ax exec ax-eventlog-postgres-0 --   psql -U axuser -d axeventlog -c \"SELECT conversation_id, seq FROM conversation_log ORDER BY conversation_id, seq;\"`\r\n- `--delete-ax-server`, DB is preserved and queriable.\r\n- `--deploy-ax-server` again, and continue a previous conversation.",
          "author": "wjjclaud",
          "createdAt": "2026-06-23T18:29:33Z",
          "mergedAt": "2026-06-24T07:49:03Z",
          "additions": 686,
          "deletions": 455,
          "changedFiles": 13
        },
        {
          "repository": "google/ax",
          "number": 165,
          "url": "https://github.com/google/ax/pull/165",
          "title": "Remove ununsed ExecutionEvent from controller2",
          "body": "",
          "author": "rakyll",
          "createdAt": "2026-06-24T21:18:41Z",
          "mergedAt": "2026-06-24T21:24:08Z",
          "additions": 6,
          "deletions": 223,
          "changedFiles": 7
        },
        {
          "repository": "google/ax",
          "number": 162,
          "url": "https://github.com/google/ax/pull/162",
          "title": "Add Interactions API harness",
          "body": "Adds a Harness implementation that drives an Antigravity agent through the Vertex GenAI Interactions API over HTTPS + Server-Sent Events, using the steps-based request format and the client-side (\"local\") environment.\r\n\r\nThe harness executes every tool the agent yields internally: built-in environment tools (view_file, run_command, list_dir, move, delete_dir, and the create/edit/multi_edit/delete_file family) run against the local filesystem and shell, while third-party function tools are dispatched to a pluggable ThirdPartyExecutor (currently a banking example until tool injection is wired). Run drives the full interaction loop to completion and streams the agent's text via the Handler.\r\n\r\nIt is exposed over the HarnessService gRPC contract via InteractionsAPIServer and the interactionsapi-harness-server command, so the harness can run as a standalone server reachable by any HarnessService client -- the substrate-ready deployment model.",
          "author": "zbl94",
          "createdAt": "2026-06-23T17:40:43Z",
          "mergedAt": "2026-06-25T16:44:33Z",
          "additions": 1086,
          "deletions": 0,
          "changedFiles": 4
        },
        {
          "repository": "google/ax",
          "number": 167,
          "url": "https://github.com/google/ax/pull/167",
          "title": "Implement resumption  of pending executions",
          "body": "- Verify that pending executions are resumed and run before handling subsequent inputs.\r\n- Add comprehensive unit tests for the new resumption flow.",
          "author": "rakyll",
          "createdAt": "2026-06-25T06:46:09Z",
          "mergedAt": "2026-06-25T17:17:41Z",
          "additions": 282,
          "deletions": 20,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 173,
          "url": "https://github.com/google/ax/pull/173",
          "title": "feat: Support preinstalled skills in Antigravity harness",
          "body": "Implements preinstalled skills resolution inside the Antigravity Python harness. It reads and installs configured skills at startup, making them immediately available to the agent. Includes unit tests.",
          "author": "anj-s",
          "createdAt": "2026-06-25T19:15:26Z",
          "mergedAt": "2026-06-25T19:27:24Z",
          "additions": 31,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "google/ax",
          "number": 174,
          "url": "https://github.com/google/ax/pull/174",
          "title": "Migrate Substrate deployment to the latest manifests",
          "body": "- Deleted the deprecated old manifests/ directory.\r\n- Deleted the deprecated root hack/ directory.\r\n- Moved the new manifests and hack to root.",
          "author": "rakyll",
          "createdAt": "2026-06-25T19:21:26Z",
          "mergedAt": "2026-06-25T21:17:30Z",
          "additions": 285,
          "deletions": 847,
          "changedFiles": 9
        },
        {
          "repository": "google/ax",
          "number": 177,
          "url": "https://github.com/google/ax/pull/177",
          "title": "Update deployment config and readme. ",
          "body": "- Bump google-antigravity to latest version. Potentially fix the issue in #136.\r\n- Add SKILLS_DIR introduced in #173.\r\n- Update readme.\r\n\r\nTested with deployment on substrate and emoji skill works.",
          "author": "wjjclaud",
          "createdAt": "2026-06-25T21:59:15Z",
          "mergedAt": "2026-06-25T22:04:34Z",
          "additions": 13,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "google/ax",
          "number": 176,
          "url": "https://github.com/google/ax/pull/176",
          "title": "Migrate controller and registry to internal/controller2",
          "body": "- Remove internal/controller\r\n- Remove internal/config\r\n- Remove the legacy harness build tag\r\n- Remove the legacy ate build tag\r\n- Use the new config\r\n\r\nFollow ups:\r\n- Rename controller2 to controller\r\n- Rename config2 to config\r\n- Remove Gemini agent and planner",
          "author": "rakyll",
          "createdAt": "2026-06-25T21:57:31Z",
          "mergedAt": "2026-06-25T22:21:29Z",
          "additions": 253,
          "deletions": 4147,
          "changedFiles": 35
        },
        {
          "repository": "google/ax",
          "number": 179,
          "url": "https://github.com/google/ax/pull/179",
          "title": "Consolidate controller and config packages by removing v2 suffixes",
          "body": "Also remove ununsed ExecutionEvent from proto.",
          "author": "rakyll",
          "createdAt": "2026-06-25T22:28:07Z",
          "mergedAt": "2026-06-25T22:32:22Z",
          "additions": 141,
          "deletions": 268,
          "changedFiles": 22
        },
        {
          "repository": "google/ax",
          "number": 182,
          "url": "https://github.com/google/ax/pull/182",
          "title": "Remove ununsed axepp",
          "body": "This change removes the axepp component.\r\n\r\naxepp is no longer needed because the AX server now acts as the multi-tenant (MT) component, directly routing requests and coordinating session/actor resumption.",
          "author": "rakyll",
          "createdAt": "2026-06-26T04:53:32Z",
          "mergedAt": "2026-06-26T15:41:46Z",
          "additions": 2,
          "deletions": 220,
          "changedFiles": 4
        },
        {
          "repository": "google/ax",
          "number": 186,
          "url": "https://github.com/google/ax/pull/186",
          "title": "Remove AgentService",
          "body": "Fixes #184.",
          "author": "rakyll",
          "createdAt": "2026-06-26T05:18:13Z",
          "mergedAt": "2026-06-26T15:42:19Z",
          "additions": 177,
          "deletions": 1732,
          "changedFiles": 24
        },
        {
          "repository": "google/ax",
          "number": 193,
          "url": "https://github.com/google/ax/pull/193",
          "title": "Pass harness config through the incoming request",
          "body": "Allow users to select a harness and pass per-request harness configuration, which the controller threads to the harness and records in the event log. This replaces the legacy agent_id/agent_config request fields.\r\nThis is the first minimal change for #123 for the config plumbing part. There'll be some updates in the antigravity implementation to read and apply the configs.\r\n\r\n## Changes\r\n- proto/ax.proto:\r\n  - ExecRequest: agent_id/agent_config → harness_id/harness_config\r\n  - store the config as human-readable struct in the event log\r\n- Add harnessConfig in `Harness.Start`\r\n- CLI\r\n  -  Replaced `--agent` with `--harness` and added `--harness-config <file>`\r\n- python/antigravity/config.json: a sample per-request config\r\n\r\n## Not covered\r\nThese are not covered in this PR and need follow ups, because they need more changes than the target of this PR.\r\n- cmd/ax/dashboard.go, cmd/ax/dashboard_test.go\r\n-  cmd/ax/web/index.html\r\n-  README.md\r\n\r\n## Tested\r\nManual test: `ax exec --server=localhost:8494 --input=\"what's the weather in NYC?\" --harness-config=python/antigravity/config.json`\r\nThe harnessConfig is logged in db:\r\n`{\"conversation_id\":\"8bf65f4c-7c5d-4646-95a9-315941882114\",\"seq\":1,\"harness_config\":{\"model\":\"gemini-3.1-pro-preview\",\"system_instructions\":\"You are a friendly weather assistant. Use the get_weather tool and reply in one upbeat sentence. If possible, include emojis in your response.\"},\"messages\":[{\"role\":\"user\",\"content\":{\"text\":{\"text\":\"what's the weather in NYC?\"}}}],\"state\":\"STATE_PENDING\"}`",
          "author": "wjjclaud",
          "createdAt": "2026-06-26T18:40:19Z",
          "mergedAt": "2026-06-26T19:41:39Z",
          "additions": 164,
          "deletions": 98,
          "changedFiles": 15
        },
        {
          "repository": "google/ax",
          "number": 196,
          "url": "https://github.com/google/ax/pull/196",
          "title": "Remove dead code from the earlier controller",
          "body": "Remove the agent package, AgentService related proto messages, and Gemini agents in favor of the new universal agent harness. With the replacement of the old controller implementation, we no longer need agent abstractions.",
          "author": "rakyll",
          "createdAt": "2026-06-26T21:27:16Z",
          "mergedAt": "2026-06-26T21:32:00Z",
          "additions": 169,
          "deletions": 2676,
          "changedFiles": 16
        },
        {
          "repository": "google/ax",
          "number": 197,
          "url": "https://github.com/google/ax/pull/197",
          "title": "Remove ununsed internal_only field",
          "body": "This field is no longer needed because we removed the execution event log.",
          "author": "rakyll",
          "createdAt": "2026-06-26T21:39:46Z",
          "mergedAt": "2026-06-26T21:52:08Z",
          "additions": 6,
          "deletions": 26,
          "changedFiles": 3
        },
        {
          "repository": "google/ax",
          "number": 199,
          "url": "https://github.com/google/ax/pull/199",
          "title": "Move cmd/e2e to internal/cmd/e2e",
          "body": "Fixes #187.",
          "author": "rakyll",
          "createdAt": "2026-06-26T21:51:28Z",
          "mergedAt": "2026-06-26T21:54:00Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 198,
          "url": "https://github.com/google/ax/pull/198",
          "title": "Rename agent references to harness in docs and update roadmap",
          "body": "",
          "author": "rakyll",
          "createdAt": "2026-06-26T21:46:50Z",
          "mergedAt": "2026-06-26T21:54:27Z",
          "additions": 16,
          "deletions": 38,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 200,
          "url": "https://github.com/google/ax/pull/200",
          "title": "Isolate the harness working directory and ax source directory",
          "body": "## Summary\r\n- Run the Antigravity harness agent in a dedicated working directory `/ax`, separate from the application's own files, which now live under `/ax-app`.\r\n- This scopes the agent's default workspace to `/ax` so it can no longer read or modify its own source tree.\r\n\r\nFixes #145\r\nFixes #150\r\n\r\n### Caveats\r\nThis PR  denies the file-write tools (`create_file`/`edit_file`) on any path outside `/ax`. But because of the nature that substrate actor is running as root user on a worker, it's still possible if an arbitrary shell command tries to modify files outside the working directory. Proper policy is needed when antigravity allows such shell commands.\r\n\r\n## Tested\r\nExample run\r\n```\r\n⏺ what file can you read/write\r\n\r\nThinking: **Investigating File Access**\r\n\r\nI'm currently focused on determining the accessible files. I need to understand the structure within the active workspace, `/ax`, pointed towards CorpusName `/ax`. I'm exploring the directory contents or searching within `/ax` to identify the project type and available files for reading or writing.\r\n\r\n\r\n**Investigating /ax directory**\r\n\r\nI've discovered `/ax` is empty. Now I'm shifting focus to determine if other accessible directories exist or if read/write operations are possible within `/ax` or adjacent file paths. I'm also examining the system description for clues about workspaces, particularly the role of URIs and CorpusNames, as multiple URIs are involved.\r\n\r\n\r\n\r\nI can read and write files within the active workspace directory at [/ax](file:///ax). Additionally, I can create and update:\r\n\r\n* **Artifacts** in the artifact directory: [/root/.gemini/antigravity/brain/045e15fb21660153b271a6a9294628fb](file:///root/.gemini/antigravity/brain/045e15fb21660153b271a6a9294628fb)\r\n* **Scratch scripts/files** in the scratch directory: [/root/.gemini/antigravity/brain/045e15fb21660153b271a6a9294628fb/scratch/](file:///root/.gemini/antigravity/brain/045e15fb21660153b271a6a9294628fb/scratch/)\r\n\r\nCurrently, the workspace directory [/ax](file:///ax) is empty. Please let me know what files or projects you would like to create or work on!\r\n\r\n***\r\n\r\n### Summary of Work\r\n* **Workspace Check**: Verified the active workspace at [/ax](file:///ax) is currently empty and informed you about the locations where files can be read/written.\r\nseq=9\r\n\r\n⏺ can you update the file /ax-app/python/antigravity/harness_server.py?\r\n\r\nThinking: **Exploring File Access**\r\n\r\nI'm currently focused on the implications of a file path outside the user's apparent workspace. The initial request pointed to `/ax-app/python/antigravity/harness_server.py`, which is outside `/ax`. Now I'm exploring the access boundaries to see if that's permissible.\r\n\r\n\r\n**Clarifying Permissions Conflict**\r\n\r\nI've hit a snag. The system flagged a \"user denied permission\" error during tool execution. Now, I'm trying to discern if this is a deliberate user rejection or an automated system-level block. I need to be sure before I proceed with any further steps. I am consulting the user's workspace for more clues.\r\n\r\n\r\n**Pinpointing Access Restriction**\r\n\r\nI've determined my access is restricted to the active workspace, `/ax`. Attempts to interact with files outside of this directory, specifically `/ax-app/python/antigravity/harness_server.py`, were blocked due to permission restrictions. I am now certain the previous error was a system-level block, not user intent. I will inform the user on the reason of the error.\r\n\r\n\r\n\r\nI located the file at [/ax-app/python/antigravity/harness_server.py](file:///ax-app/python/antigravity/harness_server.py), but attempting to access it was denied with a permission error.\r\n\r\nSince my active workspace and code-modification boundaries are restricted to [/ax](file:///ax), I cannot view or update files outside of this workspace path, including those in `/ax-app`.\r\n\r\nIf you copy or move the file (or the relevant codebase) into [/ax](file:///ax), I will be more than happy to help you read, modify, and update it!\r\n\r\n***\r\n\r\n### Summary of Work\r\n* **Search for File**: Located the file [/ax-app/python/antigravity/harness_server.py](file:///ax-app/python/antigravity/harness_server.py) using search.\r\n* **Permission Check**: Attempted to view the file content, which was restricted due to workspace permission boundaries.\r\nseq=16\r\n```",
          "author": "wjjclaud",
          "createdAt": "2026-06-26T22:30:46Z",
          "mergedAt": "2026-06-26T22:44:05Z",
          "additions": 103,
          "deletions": 16,
          "changedFiles": 4
        },
        {
          "repository": "google/ax",
          "number": 201,
          "url": "https://github.com/google/ax/pull/201",
          "title": "Remove stateless-resumption hydration in antigravity harness server",
          "body": "The harness server had a dead code path for stateless resumption: clearing Conversation._steps each turn and rebuilding it from historical_messages = ax_messages[:-1]. But the ax controller doesn't send historical messages — it only sends the new turn's input — so historical_messages was empty  \r\n\r\nThe Antigravity harness server is designed to be stateful: the cached Agent per conversation_id holds history across turns within the process lifetime. Make that intent explicit by:\r\n\r\n  - Deleting the unused hydrate_ax_history_to_steps helper.\r\n  - Removing the _steps.clear() + extend() block; replacing with a comment explaining the stateful contract.\r\n  - Dropping now-unused Step/StepType/StepSource/StepTarget/StepStatus imports.\r\n\r\nNo behavior change; the deleted block was a no-op against the SDK's real conversation state (which lives in the Go-side localharness subprocess, not in Python _steps).",
          "author": "joycel-github",
          "createdAt": "2026-06-26T22:56:34Z",
          "mergedAt": "2026-06-26T23:14:19Z",
          "additions": 5,
          "deletions": 53,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 204,
          "url": "https://github.com/google/ax/pull/204",
          "title": "Update skills dir on substrate.",
          "body": "Update skills dir from `/ax-app/skills` to `/ax/skills`, so the harness is able to read/write/exec skills.",
          "author": "wjjclaud",
          "createdAt": "2026-06-27T01:55:26Z",
          "mergedAt": "2026-06-27T02:03:09Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 205,
          "url": "https://github.com/google/ax/pull/205",
          "title": "Relocate antigravity agent source files from the examples directory",
          "body": "Embed the `agent.py` into the `harness_server.py`.\r\n\r\nTested both locally and on Substrate.\r\n\r\nFixes #188.\r\nFixes #192. \r\nFixes #178.",
          "author": "rakyll",
          "createdAt": "2026-06-27T02:15:56Z",
          "mergedAt": "2026-06-27T03:37:11Z",
          "additions": 34,
          "deletions": 182,
          "changedFiles": 9
        },
        {
          "repository": "google/ax",
          "number": 209,
          "url": "https://github.com/google/ax/pull/209",
          "title": "Remove the unused skills package",
          "body": "",
          "author": "rakyll",
          "createdAt": "2026-06-27T06:35:11Z",
          "mergedAt": "2026-06-27T11:27:39Z",
          "additions": 5,
          "deletions": 602,
          "changedFiles": 5
        },
        {
          "repository": "google/ax",
          "number": 208,
          "url": "https://github.com/google/ax/pull/208",
          "title": "Minimize the AX Docker image (1.35GB -> 360MB) for faster resumption on Substrate",
          "body": "Update Dockerfile to use python:3.13-slim and install runtime dependencies.\r\n\r\nRevert the resolve_localhost removal. Even if /etc/hosts change is included in the Dockerfile, the entry disappears in runtime. Reverting the change to make AGY harness work on Substrate again. This is a hack and needs to be removed once we resolve the issue.\r\n\r\nSimplify the README and the instructions for Substrate deployment.",
          "author": "rakyll",
          "createdAt": "2026-06-27T05:49:39Z",
          "mergedAt": "2026-06-27T22:00:09Z",
          "additions": 57,
          "deletions": 36,
          "changedFiles": 3
        },
        {
          "repository": "google/ax",
          "number": 211,
          "url": "https://github.com/google/ax/pull/211",
          "title": "Add a line with kubectl port-forward instructions",
          "body": "Output looks like:\r\n\r\n```\r\n...\r\nnamespace/ax unchanged\r\nworkerpool.ate.dev/ax-harness-workerpool created\r\nactortemplate.ate.dev/ax-harness-template created\r\nservice/ax-eventlog-postgres unchanged\r\nsecret/ax-eventlog-postgres configured\r\nstatefulset.apps/ax-eventlog-postgres configured\r\nreplicaset.apps/ax-server created\r\nconfigmap/ax-server-config created\r\n[step]: wait for statefulset/ax-eventlog-postgres to be ready\r\nwaiting for postgres (timeout 5m)... done\r\n[step]: wait for actortemplate/ax-harness-template to be Ready\r\nwaiting for golden snapshot (timeout 5m)... done\r\n\r\nForward the AX server by running the following command (optional)\r\nkubectl port-forward -n ax rs/ax-server 8494:8494\r\n```\r\n\r\nFixes #169.",
          "author": "rakyll",
          "createdAt": "2026-06-27T16:05:03Z",
          "mergedAt": "2026-06-27T22:00:27Z",
          "additions": 4,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 215,
          "url": "https://github.com/google/ax/pull/215",
          "title": "Add structured Error in HarnessEnd",
          "body": "- Added Error message to proto\r\n- Removed error_message\r\n- Updated the autogenerated artifacts\r\n\r\nFixes #212.",
          "author": "rakyll",
          "createdAt": "2026-06-28T02:10:22Z",
          "mergedAt": "2026-06-29T07:03:42Z",
          "additions": 242,
          "deletions": 236,
          "changedFiles": 11
        },
        {
          "repository": "google/ax",
          "number": 216,
          "url": "https://github.com/google/ax/pull/216",
          "title": "Fix the auto collapsing traces",
          "body": "The dashboard uses live polling (every 3 seconds) to fetch updated trace data for the active conversation. Each time new trace data is retrieved, the dashboard completely regenerates the HTML for the execution trace cards using innerHTML. Because the cards were hardcoded to render with the collapsed and hidden classes by default, any cards the user had expanded would collapse every time the poll triggered. Since users are usually scrolling while reading the expanded trace details, this gave the impression that the history was collapsing during scrolling.\r\n\r\nFixes #202.",
          "author": "rakyll",
          "createdAt": "2026-06-28T02:50:27Z",
          "mergedAt": "2026-06-29T07:04:01Z",
          "additions": 25,
          "deletions": 4,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 218,
          "url": "https://github.com/google/ax/pull/218",
          "title": "Introduce version field to configuration with validation check",
          "body": "Fixes #217.",
          "author": "rakyll",
          "createdAt": "2026-06-28T03:21:20Z",
          "mergedAt": "2026-06-29T07:04:24Z",
          "additions": 28,
          "deletions": 0,
          "changedFiles": 6
        },
        {
          "repository": "google/ax",
          "number": 213,
          "url": "https://github.com/google/ax/pull/213",
          "title": "Update README based on the new controller implementation",
          "body": "",
          "author": "rakyll",
          "createdAt": "2026-06-27T23:47:38Z",
          "mergedAt": "2026-06-29T17:19:08Z",
          "additions": 87,
          "deletions": 22,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 214,
          "url": "https://github.com/google/ax/pull/214",
          "title": "Move Substrate package out of experimental",
          "body": "Agent Substrate is no longer experimental.",
          "author": "rakyll",
          "createdAt": "2026-06-28T01:59:09Z",
          "mergedAt": "2026-06-29T17:19:28Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "google/ax",
          "number": 224,
          "url": "https://github.com/google/ax/pull/224",
          "title": "Change bucket var name and bump substrate version.",
          "body": "- Rename Env var `BUCKET_NAME` → `AX_SNAPSHOTS_BUCKET` Fix #219.\r\n- Bump substrate version and update client with new schema.\r\n\r\nNote: Developers need to update their substrate to the pinned version after this PR. ",
          "author": "wjjclaud",
          "createdAt": "2026-06-29T23:29:55Z",
          "mergedAt": "2026-06-30T00:20:15Z",
          "additions": 28,
          "deletions": 18,
          "changedFiles": 7
        },
        {
          "repository": "google/ax",
          "number": 223,
          "url": "https://github.com/google/ax/pull/223",
          "title": "antigravity: forward GOOGLE_CLOUD_{PROJECT,LOCATION} env to AGY config",
          "body": "## Summary\nThe README documents `GOOGLE_CLOUD_PROJECT` / `GOOGLE_CLOUD_LOCATION` / `GOOGLE_GENAI_USE_VERTEXAI=True` as the way to run the antigravity sidecar against Vertex AI, but the AGY SDK does not read these env vars — it requires `vertex`/`project`/`location` explicitly on `LocalAgentConfig`. After [#177](https://github.com/google/ax/pull/177) bumped to `google-antigravity==0.1.5` (which restructured the config API), this surfaces as: user sets all 3 documented env vars → `ax exec` fails per-request with `A Gemini API key is required.`\n\nThis PR makes the sidecar read those env vars at startup and pass them to `LocalAgentConfig.__init__` so AGY's `@model_validator` picks them up. Also moves credential validation from per-request to startup with a single exit point in `main()` for symmetry with the vertex env validation.\n\n## Why pass to `__init__` rather than mutate\nAGY's `_apply_shorthand_configs` runs once at construction (as a `@pydantic.model_validator(mode=\"after\")`). Post-init mutation of `config.{vertex,project,location}` does NOT regenerate `config.models`, so AGY's per-endpoint `validate_endpoint()` still sees the default `GeminiAPIEndpoint(api_key=None)` and rejects the request. Passing via `__init__(**_vertex_kwargs_from_env())` lets the validator generate the correct `VertexEndpoint(project=..., location=...)`.\n\n## Changes\n- `python/antigravity/harness_server.py`:\n  - New `_env_use_vertex()` helper (env flag check).\n  - New `_vertex_kwargs_from_env()` — returns `dict` of `{vertex, project, location}` from env, or `{}` if env doesn't request Vertex. Raises `ValueError` if Vertex requested but project/location missing.\n  - `_build_default_config()` calls `LocalAgentConfig(..., **_vertex_kwargs_from_env())` so env values flow through AGY's `__init__` validators.\n  - `_has_credentials` rewritten to mirror AGY's per-endpoint validation: only `GEMINI_API_KEY` env, `config.api_key`, or `config.vertex=True + config.{project,location}` (dropped `GOOGLE_API_KEY` and per-model api_keys; AGY doesn't accept them).\n  - Credential check moved from per-request (`_run_turn`) to startup (`main`); single try/except in `main()` is the only exit point — helpers raise `ValueError`, `main` prints `ERROR: ...` to stderr and exits 1.\n  - Replaced `loaded_config` module global with `_build_default_config()` factory injected into the servicer constructor. TODOs mark where #194's per-request `harness_config` layering will plug in.\n  - Renamed module-private helpers to `_`-prefix (`_serve`, `_enhance_config_from_env`, `_resolve_localhost`).\n- `python/antigravity/harness_server_test.py`:\n  - 6 vertex env tests + 1 end-to-end `_build_default_config_picks_up_vertex_env` test + 2 credential tests (vertex requires project+location; Express Mode) + 2 servicer DI tests.\n  - Existing tests updated to inject config via constructor (no module-global mutation).\n\n## Verification\n\n**Unit tests:** 17/17 pass against `google-antigravity==0.1.5` (current PyPI wheel, uploaded 2026-06-25). `go build` + `go test`: clean.\n\n**End-to-end via `ax exec` → `ax serve` → sidecar → AGY → Vertex AI:**\n\n| Scenario | Env | Result |\n|---|---|---|\n| Vertex happy path | `GOOGLE_GENAI_USE_VERTEXAI=True` + `GOOGLE_CLOUD_PROJECT=cloud-ai-agentic-coding` + `GOOGLE_CLOUD_LOCATION=global` | Sidecar boots: `Vertex AI backend configured: project=... location=...`. `ax exec \"capital of France?\"` → real Vertex/Gemini response: `Paris is the capital of France.` |\n| Vertex + missing PROJECT | `GOOGLE_GENAI_USE_VERTEXAI=True` + `GOOGLE_CLOUD_LOCATION=us-east1` | Exits 1 at startup: `ERROR: Vertex AI backend requested but missing required config: project (set GOOGLE_CLOUD_PROJECT)` |\n| No credentials | (none) | Exits 1 at startup: `ERROR: No Gemini credentials configured. Set GEMINI_API_KEY (AI Studio) or GOOGLE_GENAI_USE_VERTEXAI=True + GOOGLE_CLOUD_{PROJECT,LOCATION} (Vertex AI).` |\n\nSidecar log: `[gRPC] Running chat query` → `[gRPC] Turn completed successfully`. No mocked-tool involvement — response is real model output from Vertex AI.\n\n## Out of scope\n- Per-request `harness_config` layering (#194) — TODO markers placed.\n- Substrate path: deployed via baked image / actor template, no env forwarding needed.\n\nCloses #225.",
          "author": "joycel-github",
          "createdAt": "2026-06-29T23:13:34Z",
          "mergedAt": "2026-06-30T17:41:05Z",
          "additions": 270,
          "deletions": 113,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 226,
          "url": "https://github.com/google/ax/pull/226",
          "title": "Initial commit of the OpenTelemetry trace exposition",
          "body": "Refactor telemetry configuration and resolve deprecated GCP metadata calls:\r\n- Replace deprecated `metadata.ProjectID()` and `metadata.OnGCE()` with context-aware versions.\r\n- Update `telemetry.SetTraceProvider` to accept variadic `otlptracegrpc.Option`s and remove the hardcoded endpoint parameter.\r\n- Add `telemetry.WithGCPCredentials()` helper to encapsulate GCP-specific credentials.\r\n- Isolate GCP-specific server telemetry configuration into a new `serve_gcp.go` file.\r\n\r\nFix premature gRPC stream cancellation in the harness execution clients:\r\n- Update the client receive loop to drain the stream until `io.EOF` after receiving the `HarnessEnd` frame, preventing `CANCELLED` errors in telemetry.\r\n- Encapsulate the stream draining and message dispatching logic into a shared `drainStream` helper in a new `stream.go` file.\r\n- Clean up unused `io` imports in `antigravity.go` and `substrate.go`.\r\n\r\nFollow-up:\r\n- End-to-end trace context propagation to HarnessService deployments\r\n- End-to-end trace context propagation to Substrate calls\r\n",
          "author": "rakyll",
          "createdAt": "2026-07-01T03:13:12Z",
          "mergedAt": "2026-07-01T05:47:56Z",
          "additions": 331,
          "deletions": 80,
          "changedFiles": 12
        },
        {
          "repository": "google/ax",
          "number": 227,
          "url": "https://github.com/google/ax/pull/227",
          "title": "Rename Harness Service to AX Harness Server",
          "body": "To keep the style consistent with AX Server.",
          "author": "rakyll",
          "createdAt": "2026-07-01T06:19:16Z",
          "mergedAt": "2026-07-01T09:55:08Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 180,
          "url": "https://github.com/google/ax/pull/180",
          "title": "Add durable conversation resumability to the Antigravity Interactions harness",
          "body": "\r\n\r\nIntroduce a small durable key-value store and use it to persist each conversation's interaction-chain cursor (the last interaction id), so a conversation can resume after a process restart instead of starting a new chain.\r\n\r\n- internal/storage: a minimal Store interface (Get/Put/Delete + ErrNotFound) with documented semantics (atomicity, read-after-write, not-found-vs-error, durability) and a single-writer concurrency model. Includes a filesystem implementation (FileStore) that writes atomically via temp-file + rename.\r\n- harness: add AntigravityInteractionsConfig.StateStore; Start loads any persisted cursor and Run persists it after each successful turn, so a fresh Execution for the same conversation continues the existing interaction chain.\r\n- harness: document the single-writer-per-conversation expectation on the Harness interface (the controller guarantees it), which is what makes the last-write-wins store correct.\r\n\r\nAlso includes related harness improvements:\r\n- Retry HTTP 429 (rate limit) with exponential backoff + jitter, honoring Retry-After; only 429 is retried since it is rejected before any interaction is created.\r\n- Terminology cleanup: the within-Run FC/FR loop is the \"interaction loop\" (continuation turns chained via previous_interaction_id), distinct from an AX-level resume.",
          "author": "zbl94",
          "createdAt": "2026-06-26T00:38:57Z",
          "mergedAt": "2026-07-01T17:00:08Z",
          "additions": 550,
          "deletions": 41,
          "changedFiles": 5
        },
        {
          "repository": "google/ax",
          "number": 231,
          "url": "https://github.com/google/ax/pull/231",
          "title": "Remove weather tool and the custom system instructions",
          "body": "Weather tool was for development and testing, and is now removed.\r\n\r\nFixes https://github.com/google/ax/issues/228.",
          "author": "rakyll",
          "createdAt": "2026-07-01T16:57:50Z",
          "mergedAt": "2026-07-01T17:20:53Z",
          "additions": 5,
          "deletions": 26,
          "changedFiles": 3
        },
        {
          "repository": "google/ax",
          "number": 234,
          "url": "https://github.com/google/ax/pull/234",
          "title": "Add traces to the SQL event log implementation",
          "body": "",
          "author": "rakyll",
          "createdAt": "2026-07-01T17:21:20Z",
          "mergedAt": "2026-07-01T17:26:15Z",
          "additions": 34,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 235,
          "url": "https://github.com/google/ax/pull/235",
          "title": "TUI: add interactive /config menu for per-request harness config",
          "body": "- **`/config` slash command** in the prompt box, with autocompletion suggestion.\r\n- **Menu** with three options: **View/edit config**, **Load from file**, **Cancel**.\r\n- **Per-request semantics:** the config applies to the next request only and does\r\n  **not** carry over\r\n\r\nTested both locally and on substrate.",
          "author": "wjjclaud",
          "createdAt": "2026-07-01T17:55:37Z",
          "mergedAt": "2026-07-01T18:40:11Z",
          "additions": 368,
          "deletions": 23,
          "changedFiles": 5
        },
        {
          "repository": "google/ax",
          "number": 241,
          "url": "https://github.com/google/ax/pull/241",
          "title": "Regenerate proto files",
          "body": "Fixes #240.",
          "author": "rakyll",
          "createdAt": "2026-07-03T22:05:10Z",
          "mergedAt": "2026-07-06T05:47:50Z",
          "additions": 134,
          "deletions": 41,
          "changedFiles": 7
        },
        {
          "repository": "google/ax",
          "number": 239,
          "url": "https://github.com/google/ax/pull/239",
          "title": "Fix spacing between AGY harness responses",
          "body": "The AGY harness streams each contiguous block of assistant text as a separate TextContent message, with tool calls in between. The CLI display (cmd/ax/internal/display.go) tracks a state field to decide when to insert separating newlines  but the Content_ToolCall case was a pure no-op that left state == stateText.\r\n\r\nFixes #233.",
          "author": "rakyll",
          "createdAt": "2026-07-03T21:42:42Z",
          "mergedAt": "2026-07-06T05:48:06Z",
          "additions": 44,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 236,
          "url": "https://github.com/google/ax/pull/236",
          "title": "Make Postgres optional on substrate deployments",
          "body": "### Changes\r\nAdds a `--no-postgres` flag to `hack/install-ax.sh` so a substrate deployment can\r\nskip the Postgres StatefulSet and run with an ephemeral **SQLite** event log\r\ninstead. Fix #168.\r\n- manifests/ax-postgres.yaml (new): Moved out from ax-deployment.yaml. The Postgres Service + Secret +\r\n  StatefulSet, applied only in the default (Postgres) mode.\r\n- hack/install-ax.sh:\r\n  - New `--no-postgres` flag.\r\n  - Default mode: applies ax-deployment.yaml + ax-postgres.yaml with\r\n    AX_SERVER_REPLICAS=3, resolves/generates the Postgres password, and waits\r\n    for the Postgres StatefulSet.\r\n  - `--no-postgres`: applies only ax-deployment.yaml with\r\n    AX_SERVER_REPLICAS=1, rewriting the ConfigMap's eventlog block to\r\n    sqlite: filename: \"/tmp/ax-eventlog/log.sqlite\".\r\n\r\n### Tested\r\n```\r\n./hack/install-ax.sh --deploy-ax-server               # Postgres (default, unchanged)\r\n./hack/install-ax.sh --deploy-ax-server --no-postgres # ephemeral SQLite\r\n```",
          "author": "wjjclaud",
          "createdAt": "2026-07-01T19:42:40Z",
          "mergedAt": "2026-07-06T17:13:19Z",
          "additions": 164,
          "deletions": 102,
          "changedFiles": 4
        },
        {
          "repository": "google/ax",
          "number": 242,
          "url": "https://github.com/google/ax/pull/242",
          "title": "Rename ControllerService to ExecutionService",
          "body": "",
          "author": "rakyll",
          "createdAt": "2026-07-06T05:58:12Z",
          "mergedAt": "2026-07-06T17:30:47Z",
          "additions": 98,
          "deletions": 191,
          "changedFiles": 11
        },
        {
          "repository": "google/ax",
          "number": 243,
          "url": "https://github.com/google/ax/pull/243",
          "title": "Move Harness implementations to their own packages",
          "body": "Fixes #232.",
          "author": "rakyll",
          "createdAt": "2026-07-06T20:47:26Z",
          "mergedAt": "2026-07-06T21:00:58Z",
          "additions": 149,
          "deletions": 133,
          "changedFiles": 13
        },
        {
          "repository": "google/ax",
          "number": 244,
          "url": "https://github.com/google/ax/pull/244",
          "title": "harness/python: normalize thought summary whitespace (#191)",
          "body": "Fixes #191.\n\n## Context\n\nGemini's thinking summaries contain runs of `\\n\\n\\n` between reasoning\nsections and often trailing `\\n\\n`. Previously, the Python AGY harness\nstreamed these payloads verbatim over gRPC to the AX controller. This\nmeant every downstream client (`cmd/ax/internal/display.go`, the Web\nDashboard, and any future one) would need to know to scrub Gemini's\nparticular whitespace quirks.\n\n## Fix\n\nNormalize the payload in the Python harness adapter — the same layer\nalready responsible for shielding downstream clients from\nmodel/SDK-specific representations. In `flush_thought()`:\n\n1. Collapse runs of 3+ newlines to a single blank line (`\\n{3,}` → `\\n\\n`).\n2. `rstrip()` trailing whitespace so the payload doesn't leak trailing\n   newlines into downstream renderers.\n3. Append exactly one trailing newline so downstream displays render\n   a blank line between the thinking block and whatever follows (next\n   thought, tool call, or answer text). Without this, `display.go`'s\n   single-newline transition would glue blocks together.\n\n## End-to-end validation\n\nVerified against a live `ax exec --harness antigravity` with a real\nVertex AI Gemini backend. Sample output:\n\n```\n⏺ what's the weather in New York City\n\nThinking: **Searching Web for Data**\n\nI'm currently focusing on acquiring the necessary weather data for New York City. Since I lack a direct tool, I'm preparing to utilize the `search_web` function to locate this information.\n\n**Exploring Web Search Options**\n\nI'm focusing on how to best retrieve New York City weather data. As I don't have a dedicated weather tool, I'll be employing the `search_web` function. My initial query will be \"weather in New York City.\"\n\nThinking: **Finding Weather Forecasts**\n\nI've successfully retrieved the New York City weather forecast using my search capabilities. I can now present these details to you.\n\n**Presenting Weather Data**\n\nI've successfully gathered the New York City weather forecast and am now ready to share the detailed information with you.\n\nIt is currently raining in New York City with a temperature of 69°F (21°C)...\n```\n\n- Single blank line between reasoning sections within a `Thinking:` block ✓\n- Single blank line between consecutive `Thinking:` blocks ✓\n- Single blank line between the last `Thinking:` block and the answer text ✓\n- No runs of 2+ blank lines anywhere ✓\n\nCompare to the buggy output in the issue where blank-line runs appeared\nin all three positions.\n\n## Alternatives considered\n\n* **Do the normalization in `cmd/ax/internal/display.go`.** Rejected\n  per Jaana's review: it would put model/SDK-specific whitespace\n  quirks into a generic renderer, and would need to be duplicated in\n  every other client (Web Dashboard, etc.). PR #239 handles\n  *structural* boundary spacing (between different `Content` types)\n  in the display, which is appropriate; but payload cleanup belongs\n  in the adapter.\n* **Rely on the AGY SDK to normalize.** The SDK documents\n  `thinking_delta` as a raw incremental substring, so a lossy\n  normalization there would break the SDK's contract for other\n  consumers.\n* **Skip the trailing `+ '\\n'` and let display handle separation.**\n  Live testing revealed this glues consecutive thinking blocks\n  together (no blank line between them) because `display.go`'s\n  thought-transition logic emits only one `\\n`. The trailing newline\n  produces the correct rendering with today's display code; if\n  display ownership of the transition changes later, the harness\n  contract can be revised.",
          "author": "joycel-github",
          "createdAt": "2026-07-06T20:48:31Z",
          "mergedAt": "2026-07-06T22:18:43Z",
          "additions": 13,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 254,
          "url": "https://github.com/google/ax/pull/254",
          "title": "Serve /readyz from ax harness server.",
          "body": "Fix #252.\r\n- ax harness now serves an HTTP /readyz endpoint (port 8081), gated on the Python harness's gRPC health. Substrate polls this endpoint during golden snapshotting and per-actor Run/Restore.\r\n- The ActorTemplate declares the matching readyz probe.\r\n- Bumps the pinned substrate version.\r\n- Fix an indeterministic/flaky error message in the RPC stream. It should return the actual server error.\r\n\r\nTested: Deploy and run on substrate.",
          "author": "wjjclaud",
          "createdAt": "2026-07-07T00:11:03Z",
          "mergedAt": "2026-07-07T01:04:29Z",
          "additions": 128,
          "deletions": 7,
          "changedFiles": 7
        },
        {
          "repository": "google/ax",
          "number": 256,
          "url": "https://github.com/google/ax/pull/256",
          "title": "Remove examples/skills/ from the Dockerfile",
          "body": "Fixes #253.",
          "author": "rakyll",
          "createdAt": "2026-07-07T01:07:34Z",
          "mergedAt": "2026-07-07T01:12:24Z",
          "additions": 5,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 255,
          "url": "https://github.com/google/ax/pull/255",
          "title": "Use /axharness folder in the snapshots bucket",
          "body": "The ax harness server will provide more than Antigravity.\r\n\r\nDepends on https://github.com/google/ax/pull/254.",
          "author": "rakyll",
          "createdAt": "2026-07-07T01:03:09Z",
          "mergedAt": "2026-07-07T01:12:38Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 257,
          "url": "https://github.com/google/ax/pull/257",
          "title": "Rename KO_DOCKER_REPO to AX_IMAGE_REPO",
          "body": "Fixes #247.",
          "author": "rakyll",
          "createdAt": "2026-07-07T01:12:00Z",
          "mergedAt": "2026-07-07T01:13:46Z",
          "additions": 10,
          "deletions": 10,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 259,
          "url": "https://github.com/google/ax/pull/259",
          "title": "Make /workspace the default working directory on Substrate",
          "body": "Fixes #258.",
          "author": "rakyll",
          "createdAt": "2026-07-07T01:39:15Z",
          "mergedAt": "2026-07-07T02:43:03Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 273,
          "url": "https://github.com/google/ax/pull/273",
          "title": "Introduce pythonsidecar package",
          "body": "We need an optional step to extract embedded python/ directory and install the Python modules for the local experience.",
          "author": "rakyll",
          "createdAt": "2026-07-07T21:38:37Z",
          "mergedAt": "2026-07-07T23:50:18Z",
          "additions": 433,
          "deletions": 15,
          "changedFiles": 3
        },
        {
          "repository": "google/ax",
          "number": 274,
          "url": "https://github.com/google/ax/pull/274",
          "title": "Serve the Antigravity Interactions harness over HarnessService",
          "body": "Add a Go HarnessService server for the Antigravity Interactions harness so it can run as a substrate actor, alongside the existing Python sidecar path.\r\n\r\n- internal/harness/antigravityinteractions/server.go: Serve(...) stands up the gRPC HarnessService (plus gRPC health) and an HTTP /readyz endpoint reflecting this server's own serving state, with graceful shutdown on ctx-cancel or SIGINT/SIGTERM. Connect adapts the harness onto the wire contract: a start frame drives one turn (Start -> Queue -> Run), each agent message is streamed as a HarnessResponse{outputs} frame, and the stream terminates with exactly one HarnessResponse{end} (COMPLETED/FAILED/ CANCELED); a mid-stream cancel frame cancels the run.\r\n- cmd/ax/harness.go: add a thin runAntigravityInteractionsHarness(ctx, systemInstructions) entrypoint that builds the config and calls Serve; the dispatch layer decides when to invoke it.\r\n- server_test.go: bufconn tests for the start->end contract and rejection of a non-start first frame.",
          "author": "zbl94",
          "createdAt": "2026-07-07T23:00:02Z",
          "mergedAt": "2026-07-08T16:42:28Z",
          "additions": 397,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "google/ax",
          "number": 275,
          "url": "https://github.com/google/ax/pull/275",
          "title": "Auto-start Antigravity Python sidecar from ax exec",
          "body": "Progresses #249 (autofork done; PYTHONPATH & pip install still user responsibility — see Scope + Known limitation)\n\n## Scope\n\nThis PR only wires the sidecar startup via `pythonsidecar`. It does **not** install the Python runtime dependencies of `python/antigravity/harness_server.py`. Users are expected to have them installed before running `ax exec`:\n\n```\npip install -r python/antigravity/requirements.txt\n```\n\n## Known limitation: set `PYTHONPATH` before `ax exec`\nLocal users need to manually prepend the repo root and `python/` to `PYTHONPATH`:\n```bash\nexport PYTHONPATH=\"$PWD:$PWD/python:$PYTHONPATH\"\n```\nWithout this, the sidecar fork fails with:\n```\nImportError: cannot import name 'content_pb2' from 'proto' (unknown location)\n```\n**Root cause.** `harness_server.py` uses `from python.proto import ax_pb2` (needs repo root on `sys.path`) while generated `ax_pb2.py` uses `from proto import content_pb2` (needs `python/` on `sys.path`). Python's default `sys.path` satisfies only one. This has been the case since PR #34 introduced the streaming harness.\n**Substrate is unaffected.** `cmd/ax/Dockerfile:64` sets `ENV PYTHONPATH=/ax-app:/ax-app/python`, so pods inherit it via the container image.\n**Follow-up.** `go:embed`-ing `python/` into the ax binary and pointing `PYTHONPATH` at the extracted cache dir. Out of scope for this PR.\n\n## Summary\n\n`ax exec` now forks the Antigravity Python sidecar automatically via `pythonsidecar` (#273). Users no longer need to run `ax harness` in a separate terminal.\n\n## Design rationale\n\nThis PR is intentionally minimal. An earlier attempt (#251, 1122 lines) shipped the full CUJ end-to-end — identity probe to distinguish AGY vs foreign sidecars, `Pdeathsig` for parent-crash cleanup, a shared autostart package for future harnesses, and an `AX_ANTIGRAVITY_NO_AUTOSTART` escape hatch. Post-review discussion converged on stacking the work as smaller PRs: land the minimum autofork here, add each capability as its own reviewable follow-up. This PR is that minimum. Known follow-ups (all `TODO`'d in code or tracked as issues):\n\n- Reuse an existing AGY sidecar via a named gRPC health service identity probe (currently: any port-in-use fails the fork)\n- Parent-crash cleanup (`Pdeathsig` on Linux)\n- Auto PYTHONPATH via `go:embed` (#270 / addressed by #276)\n- Auto `pip install` at first run\n\n## API\n\n- `antigravity.New(ctx, address, autoStart)` — when `autoStart=true`, forks the sidecar, waits for `TCPReady`, installs a signal handler that stops it on SIGINT/SIGTERM.\n- `cliutil.NewControllerFromConfig` passes `autoStart=true` in local mode.\n\nSubstrate mode and the e2e demo pass `autoStart=false` (unchanged behavior).\n\n## Tests\n1. unit test \n2. manual run \n\n(.venv) lhuan@lhuan:~/ax-test$ ./ax exec --input \"hi\"\nStarting gRPC harness server on 127.0.0.1:50053...\nConversation: 7b7974ff-0b58-445b-a836-ca41e3500f43\n\n⏺ hi\n\n[gRPC] Connect turn requested. conv_id=7b7974ff-0b58-445b-a836-ca41e3500f43\n[gRPC] Creating new Agent instance for conv_id=7b7974ff-0b58-445b-a836-ca41e3500f43\n[gRPC] Running chat query: hi\n[gRPC] Turn completed successfully.\nHello! How can I help you today?\nseq=2\n",
          "author": "joycel-github",
          "createdAt": "2026-07-08T00:56:53Z",
          "mergedAt": "2026-07-08T19:37:59Z",
          "additions": 137,
          "deletions": 41,
          "changedFiles": 5
        },
        {
          "repository": "google/ax",
          "number": 277,
          "url": "https://github.com/google/ax/pull/277",
          "title": "Antigravity interactions harness registry and config",
          "body": "Wires the built-in Antigravity Interactions harness into the controller for #271.\r\n- Config (internal/config): new antigravity interactions harness config.\r\n- Registry wiring (cmd/ax/internal/cliutil): registers for both local mode and substrate mode.\r\n- Default state dir: move the default state dir helper to the shared package.\r\n- Example yaml commented out for enabling in followups.\r\n\r\n### Tested\r\nOn local mode, uncomment config in `ax.yaml`\r\n`export GOOGLE_CLOUD_PROJECT=<project_ID>`\r\n`go run ./cmd/ax exec --harness antigravity-interactions --input \"hello\"`\r\n\r\n### Follow up\r\nRouting in `ax harness` for substrate mode.",
          "author": "wjjclaud",
          "createdAt": "2026-07-08T23:14:06Z",
          "mergedAt": "2026-07-09T00:43:49Z",
          "additions": 159,
          "deletions": 44,
          "changedFiles": 9
        },
        {
          "repository": "google/ax",
          "number": 276,
          "url": "https://github.com/google/ax/pull/276",
          "title": "Embed python artifacts into ax",
          "body": "This change embeds the python/ directory into the ax binary.\r\n\r\n- At runtime, it extracts the python/ directory to `~/.ax/python`.\r\n- It runs, `pip install -r requirements.txt`\r\n- And starts the AGY harness service.\r\n\r\nThis is a hack until `antigravityinteractions` package is ready to replace `antigravity`.\r\n\r\nTested:\r\n\r\n- [x]  Locally\r\n- [x]  On Substrate",
          "author": "rakyll",
          "createdAt": "2026-07-08T22:52:59Z",
          "mergedAt": "2026-07-09T02:28:19Z",
          "additions": 308,
          "deletions": 82,
          "changedFiles": 8
        },
        {
          "repository": "google/ax",
          "number": 278,
          "url": "https://github.com/google/ax/pull/278",
          "title": "Setup ~/.ax/antigravity once until a new update arrives",
          "body": "- Check if any files in the embed.FS has changed. If not, skip pip install.\r\n- Consolidate .ax directory path resolution into a centralized config helper\r\n",
          "author": "rakyll",
          "createdAt": "2026-07-09T02:45:58Z",
          "mergedAt": "2026-07-09T05:08:10Z",
          "additions": 64,
          "deletions": 46,
          "changedFiles": 4
        },
        {
          "repository": "google/ax",
          "number": 280,
          "url": "https://github.com/google/ax/pull/280",
          "title": "Add instructions for accessing ax server via port-forwarding in ax-install.sh",
          "body": "",
          "author": "rakyll",
          "createdAt": "2026-07-09T05:18:02Z",
          "mergedAt": "2026-07-09T06:18:26Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 279,
          "url": "https://github.com/google/ax/pull/279",
          "title": "ax command should start without an ax.yaml",
          "body": "Fixes #260.",
          "author": "rakyll",
          "createdAt": "2026-07-09T05:07:50Z",
          "mergedAt": "2026-07-09T06:18:45Z",
          "additions": 7,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 285,
          "url": "https://github.com/google/ax/pull/285",
          "title": "Harden Antigravity Interactions harness HTTP client",
          "body": "Fix a substrate suspend/resume failure and tighten the config surface:\r\n\r\n- Disable HTTP keep-alives on the harness's default client. On substrate the actor is suspended after a turn and resumed for the next (with a new routable IP), which leaves any pooled keep-alive connection stale; reusing it made the next turn's request fail. Opening a fresh connection per request avoids that at the cost of an extra handshake.\r\n- Remove the public HTTPClient override from AntigravityInteractionsConfig. External callers don't configure the harness's transport, and exposing it risked silently reintroducing the keep-alive bug. New now always owns its (keep-alive-disabled) client; tests inject a fake transport via an unexported newWithHTTPClient seam.\r\n- Reorder AntigravityInteractionsConfig fields to list required (Agent, StateDir) before optional, with clearer doc comments.\r\n\r\nBuild and package tests pass.",
          "author": "zbl94",
          "createdAt": "2026-07-09T19:41:28Z",
          "mergedAt": "2026-07-09T21:08:06Z",
          "additions": 44,
          "deletions": 27,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 284,
          "url": "https://github.com/google/ax/pull/284",
          "title": "Delete obsolete Makefile targets",
          "body": "- Container image is built from a Dockerfile and the existing targets in the Makefile are not used.\r\n- Remote agents is removed a part of the unified harness refactor.",
          "author": "rakyll",
          "createdAt": "2026-07-09T19:38:48Z",
          "mergedAt": "2026-07-09T21:44:58Z",
          "additions": 1,
          "deletions": 25,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 288,
          "url": "https://github.com/google/ax/pull/288",
          "title": "Surface server error events in Antigravity Interactions harness",
          "body": "parseStreamedTurn only handled interaction.* and step.* SSE events; a server-emitted \"error\" event fell through the switch and was silently dropped. The turn then returned as completed-but-empty, which:\r\n\r\n  - made a failure (e.g. INVALID_ARGUMENT for a malformed client tool result) look like a blank \"no response\" turn, and\r\n  - persisted the failing interaction's id as a poisoned resume cursor.\r\n\r\nAdd an \"error\" case that returns a real error, plus a serverErrorMessage helper that extracts message/status from the error payload. Now a turn-level server failure aborts the turn with a descriptive error instead of being hidden.\r\n\r\nAdds tests for the error-event path and serverErrorMessage formatting.",
          "author": "zbl94",
          "createdAt": "2026-07-09T22:26:34Z",
          "mergedAt": "2026-07-09T23:24:28Z",
          "additions": 101,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 287,
          "url": "https://github.com/google/ax/pull/287",
          "title": "Run Antigravity Interactions as substrate actors",
          "body": "A simple working version that serves both antigravity and interactions harness on substrate. Fix #271. \r\n- Add ax harness [harness-id] positional selection so the ax harness binary can serve either built-in harness based on the harness id in the execution request.\r\n- ActorTemplate\r\n  - Antigravity: `ax-harness-antigravity-template`\r\n  - Antigravity Interactions: `ax-harness-interactions-template`\r\n- Document the Vertex AI (Workload Identity) IAM prerequisite the interactions harness needs.\r\n\r\n### Tested\r\nDeploy: `./hack/install-ax.sh --deploy-ax-server --deploy-postgres`\r\nRun both harnesses:\r\n- `ax exec --server=localhost:8494 --harness=antigravity-interactions`\r\n- `ax exec --server=localhost:8494 --harness=antigravity`",
          "author": "wjjclaud",
          "createdAt": "2026-07-09T22:25:10Z",
          "mergedAt": "2026-07-10T00:44:00Z",
          "additions": 119,
          "deletions": 27,
          "changedFiles": 8
        },
        {
          "repository": "google/ax",
          "number": 289,
          "url": "https://github.com/google/ax/pull/289",
          "title": "Replace Antigravity sidecar in-memory Agent cache with SDK-native resume",
          "body": "## Problem\r\n\r\nAntigravity harness caches Agent per conversation in memory. Substrate snapshot won't include memory, and local server restarts when a conversation resumes. This setup doesn't work for conversation\r\nresumption.\r\n\r\n## Assumption \r\n\r\n1. Single writer so no lock needed \r\n\r\n## Fix\r\n\r\n1. Delete the cache. \r\n3. Use `LocalAgentConfig`'s native `(conversation_id,save_dir)` — SDK persists trajectory state to\r\n`{save_dir}/{sdk_conv_id}.db`. \r\n4. **Note:** Each AX conversation gets its own directory under `~/.ax/antigravity/conversations/{ax_conv_id}/`; on\r\nsubsequent turns we discover the SDK's hash-id from the `.db` filename\r\nand pass it back to resume.\r\n\r\n**This is because SDK's `conversation_id` is resume-only — passing a non-existent id errors.** Hence discover-then-pass, not pass-always. \r\n\r\nAlternatively we can store the {AX convs_id : AGY convs_id} separately but this simplify the overall logic and setup \r\n\r\n## Next\r\n\r\n`save_dir` is hardcoded here. Should be injected by controller via `harness_config` — see #269, #203. TODO in code.\r\n\r\n## Tasks\r\n\r\n- [x] Test local (`ax exec --conversation <id>` across fresh sidecar\r\n      processes → resume works, isolation works)\r\n- [x] Test substrate",
          "author": "joycel-github",
          "createdAt": "2026-07-09T23:30:48Z",
          "mergedAt": "2026-07-10T03:45:27Z",
          "additions": 149,
          "deletions": 175,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 293,
          "url": "https://github.com/google/ax/pull/293",
          "title": "Use GOOGLE_CLOUD_PROJECT variable and remove PROJECT_ID usage",
          "body": "Fixes https://github.com/google/ax/issues/290.",
          "author": "rakyll",
          "createdAt": "2026-07-10T17:26:16Z",
          "mergedAt": "2026-07-10T21:23:48Z",
          "additions": 10,
          "deletions": 10,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 294,
          "url": "https://github.com/google/ax/pull/294",
          "title": "Update GOOGLE_CLOUD_PROJECT for interactions path.",
          "body": "",
          "author": "wjjclaud",
          "createdAt": "2026-07-10T21:30:53Z",
          "mergedAt": "2026-07-10T21:34:18Z",
          "additions": 5,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 291,
          "url": "https://github.com/google/ax/pull/291",
          "title": "harness/python: fix stale thought summary test assertions",
          "body": "Fix 2 stale test assertions in `python/antigravity/harness_server_test.py`.\r\n\r\nformer PR changed the format but this test didn't get auto triggered  \r\n\r\nNext: make python test auto triggered ",
          "author": "joycel-github",
          "createdAt": "2026-07-10T08:10:37Z",
          "mergedAt": "2026-07-11T00:30:27Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 292,
          "url": "https://github.com/google/ax/pull/292",
          "title": "Antigravity sidecar state dir from config",
          "body": "Follow-up to #289.\r\n## Problem\r\nSidecar's trajectory storage directory was hardcoded in Python. No way\r\nfor users to relocate it.\r\n## Fix\r\nPlumb `state_dir` through: `ax.yaml` → `AntigravityHarnessConfig` → Go\r\nclient → sidecar `--state-dir` arg. Mirrors the existing\r\n`antigravity-interactions.state_dir` pattern.\r\nPython default (`~/.ax/antigravity/conversations`) kept as transitional\r\nfallback for substrate mode (ActorTemplate doesn't inject the flag\r\nyet); removable once it does.\r\n## Tasks\r\n- [x] Test local\r\n- [ ] Test substrate",
          "author": "joycel-github",
          "createdAt": "2026-07-10T09:46:37Z",
          "mergedAt": "2026-07-13T16:55:03Z",
          "additions": 56,
          "deletions": 35,
          "changedFiles": 8
        },
        {
          "repository": "google/ax",
          "number": 296,
          "url": "https://github.com/google/ax/pull/296",
          "title": "ci: run Python tests for the antigravity harness sidecar",
          "body": "\r\n- Wires the 17 antigravity harness sidecar tests (`python/antigravity/harness_server_test.py`) into CI. They have never run automatically — `.github/workflows/go.yml` only runs `go test ./...`, which is how the stale assertions fixed in #291 slipped through.\r\n- Adds `.github/workflows/python.yml`, a dedicated Python workflow kept separate from the Go-only `go.yml` so each can evolve independently.\r\n- Adds a `test-python` Makefile target for local parity.\r\n\r\n",
          "author": "joycel-github",
          "createdAt": "2026-07-11T00:40:30Z",
          "mergedAt": "2026-07-13T16:55:25Z",
          "additions": 63,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 295,
          "url": "https://github.com/google/ax/pull/295",
          "title": "parse harness config from request",
          "body": "Parse `HarnessStart.harness_config` (delivered to the sidecar as json in bytes )\r\ninto a JSON object and overlay it onto the server's `LocalAgentConfig` before each turn.\r\n\r\nMinimum parsing and validation logic in the adapter as intended  \r\n- Only blocks a request from overriding AX-owned setup (`save_dir`,\r\n  `conversation_id`); these are injected last so a request can't redirect\r\n  trajectory storage.\r\n- No distinction between request-time vs conversation-creation overrides\r\n  -- intentionally left to the harness behind the adapter.\r\n- No validation yet for fields only meaningful to a runtime request, not\r\n  harness_config (e.g. confirmation). Rejected today since\r\n  `LocalAgentConfig` doesn't accept them.\r\n\r\nConfig is reconstructed (not `model_copy`'d) so the SDK re-validates and\r\nsurfaces its own error; invalid config fails the turn with\r\n`INVALID_ARGUMENT` instead of crashing.\r\n\r\n## Next\r\n- Error on `LocalAgentConfig` unknown fields (pydantic silently drops\r\n  them today; TODO in code).\r\n- Merge the `state_dir` change from #292.\r\n\r\n## Verification\r\nLocal `ax exec --harness-config-json`: valid override applied, AX-owned\r\nfield rejected, SDK validation error surfaced, malformed JSON rejected,\r\nresume intact across a per-turn override.",
          "author": "joycel-github",
          "createdAt": "2026-07-11T00:24:12Z",
          "mergedAt": "2026-07-13T21:55:05Z",
          "additions": 165,
          "deletions": 17,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 301,
          "url": "https://github.com/google/ax/pull/301",
          "title": "antigravity: reject unknown harness_config fields",
          "body": "Add validation for unknown fields against `LocalAgentConfig`.\r\n\r\nclean up the TODO for validate and reject LocalAgentConfig unknown fields. \r\nLocalAgentConfig currently silently ignore the unknown fields. \r\n\r\n## Tested via `ax exec`\r\n\r\nUnknown field → rejected:\r\n```\r\n$ ax exec --harness-config-json '{\"system_instruction\":\"typo\"}' --input \"hi\"\r\nError: ... [3] Invalid harness_config: unknown config field(s): system_instruction\r\n``\r\n\r\nValid override → applied:\r\n```\r\n$ ax exec --harness-config-json '{\"system_instructions\":\"You are a pirate. One short sentence.\"}' --input \"What is 2+2?\"\r\nAhoy, 2+2 be makin' 4, ye scurvy dog!\r\n```\r\n",
          "author": "joycel-github",
          "createdAt": "2026-07-13T23:37:22Z",
          "mergedAt": "2026-07-14T00:04:50Z",
          "additions": 48,
          "deletions": 16,
          "changedFiles": 2
        },
        {
          "repository": "google/ax",
          "number": 302,
          "url": "https://github.com/google/ax/pull/302",
          "title": "[substrate] Interactions actor reads harness config from ax.yaml",
          "body": "Previously, the Antigravity Interactions harness always use default value on substrate deployment. Its config in ax.yaml is only used by local path.\r\n\r\n#### Changes\r\n- Through an env var `AX_CONFIG_CONTENT`, Antigravity Interactions harness reads its deploy config (agent, state_dir) from ax.yaml on the substrate/actor path, with fallback to built-in defaults.\r\n- Split the configMap into a separate file `manifests/ax.yaml`. It's used by both the controller ConfigMap and the actor's env var.\r\n- The config plumbing will be used by Antigravity Interactions harness skills registry on substrate mode.\r\n\r\n#### Tested\r\nDeployed and run on substrate. Both SDK and Interactions work.",
          "author": "wjjclaud",
          "createdAt": "2026-07-14T00:39:19Z",
          "mergedAt": "2026-07-14T20:03:02Z",
          "additions": 109,
          "deletions": 22,
          "changedFiles": 6
        },
        {
          "repository": "google/ax",
          "number": 304,
          "url": "https://github.com/google/ax/pull/304",
          "title": "antigravity: stop exposing harness state_dir in ax.yaml",
          "body": "remove state_dir from ax.yaml for both antigravity and interaction harness. \r\n\r\nthis is to resolve the follow-up from https://github.com/google/ax/pull/292#discussion_r3562628246",
          "author": "joycel-github",
          "createdAt": "2026-07-14T19:49:51Z",
          "mergedAt": "2026-07-14T20:28:49Z",
          "additions": 54,
          "deletions": 39,
          "changedFiles": 6
        },
        {
          "repository": "google/ax",
          "number": 300,
          "url": "https://github.com/google/ax/pull/300",
          "title": "Add GEAP Skill Registry integration for local harnesses",
          "body": "Materialize agentskills.io skills from the GEAP Skill Registry (Vertex AI v1beta1) into an on-disk skills directory before a harness starts, so the Antigravity and Antigravity Interactions harnesses can use registry-hosted skills on the local `ax exec` / `ax serve` path.\r\n\r\n- internal/skills/materialize: harness-agnostic package that reads config.SkillsConfig, drives the registry client (ListSkills / GetSkill / GetSkillRevision / skills:retrieve), safe-unzips payloads to <target_dir>/<skill-id>/, and reports what it wrote. First-wins on duplicate ids with a warning; fail-safe (a registry error never blocks harness startup).\r\n- config: harnesses.<id>.skills.registries[] with per-registry selection (skills / query / all), required target_dir, and a validated \"exactly one selection mode\" rule. Also wires the interactions harness's system_instruction from ax.yaml.\r\n- cliutil: materializes skills at controller construction; for the interactions harness (no SKILLS_DIR concept) it appends a discovery pointer to the system instruction.\r\n\r\nScope: local path only; the substrate/pod path does not yet read ax.yaml. Verified end-to-end against a live registry (by-id and by-query).",
          "author": "zbl94",
          "createdAt": "2026-07-13T20:20:50Z",
          "mergedAt": "2026-07-15T00:40:32Z",
          "additions": 1723,
          "deletions": 3,
          "changedFiles": 10
        },
        {
          "repository": "google/ax",
          "number": 311,
          "url": "https://github.com/google/ax/pull/311",
          "title": "antigravity format clean up - harness_server.py ",
          "body": "harness_server.py  is not formatted. When adding logical change, we only get irrelevant format delta and need to prompt to remove. Format this once. There is no real delta ",
          "author": "joycel-github",
          "createdAt": "2026-07-15T05:32:04Z",
          "mergedAt": "2026-07-15T17:27:16Z",
          "additions": 94,
          "deletions": 60,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 309,
          "url": "https://github.com/google/ax/pull/309",
          "title": "docs(readme): fix invalid harness in exec example",
          "body": "one line fix on ax harness sample command \n\nPart of #299",
          "author": "joycel-github",
          "createdAt": "2026-07-15T03:44:36Z",
          "mergedAt": "2026-07-15T17:28:02Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 310,
          "url": "https://github.com/google/ax/pull/310",
          "title": "docs(readme): refresh Antigravity setup, auth, and CLI usage",
          "body": "- Document the built-in Antigravity harness: local execution needs Python 3 + pip; AX auto-starts the Python sidecar and installs pinned SDK deps on first use.\n- Promote Authentication to its own section (Google AI Studio and Vertex AI/ADC) and earlier on ReadMe\n- Refresh Quick Start / Usage examples - document `--harness-config` / `--harness-config-json`, and add a per-request config example. Fix the example that referenced a nonexistent `coding` harness or wrong wordings \n\nStacked on #309. Part of #299",
          "author": "joycel-github",
          "createdAt": "2026-07-15T05:07:13Z",
          "mergedAt": "2026-07-15T17:28:16Z",
          "additions": 45,
          "deletions": 22,
          "changedFiles": 1
        },
        {
          "repository": "google/ax",
          "number": 303,
          "url": "https://github.com/google/ax/pull/303",
          "title": "Honor view_file line range and cap result size",
          "body": "execViewFile read the whole file and ignored the agent's StartLine/EndLine, so viewing a large file returned its entire content as the tool result -- a ~900KB blob for a 3k-line CSV stalled the following turn.\r\n\r\nImplement the Antigravity view_file contract (1-indexed inclusive line range with slice-notation windowing) plus defensive caps:\r\n- StartLine/EndLine window (neither=first N lines; start-only=next N forward; end-only=previous N backward; both=precise range, capped to N).\r\n- viewFileMaxLines / viewFileMaxBytes caps so a large file can never blob.\r\n\r\nAdds intArg/intArgOK helpers and tests for windowing, byte cap + offset resume, and range honoring.",
          "author": "zbl94",
          "createdAt": "2026-07-14T18:26:42Z",
          "mergedAt": "2026-07-15T17:34:14Z",
          "additions": 511,
          "deletions": 1,
          "changedFiles": 2
        }
      ],
      "developmentAttribution": {
        "repository": "google/ax",
        "branch": "main",
        "window": {
          "id": "ax-history-before-cutoff",
          "label": "AX public default-branch history before the comparison cutoff",
          "startInclusive": "2026-01-01T00:00:00.000Z",
          "endExclusive": "2026-08-01T00:00:00.000Z",
          "duration": "P212D"
        },
        "windowRelation": "repository-history-outside-measured-windows",
        "totalCommitsScanned": 608,
        "explicitlyAttributedCommits": 7,
        "byAgent": [
          {
            "agent": "Gemini",
            "commits": 7,
            "markerTypes": [
              {
                "name": "co-author-trailer",
                "count": 7
              }
            ]
          }
        ],
        "records": [
          {
            "agent": "Gemini",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: gemini-code-assist[bot]",
            "repository": "google/ax",
            "branch": "main",
            "sha": "5e030de39700fbfaabbcfafa9e9b7481bec5de4e",
            "url": "https://github.com/google/ax/commit/5e030de39700fbfaabbcfafa9e9b7481bec5de4e",
            "title": "Add a warning saying the project is in active development (#73)",
            "observedAt": "2026-02-27T19:14:42Z"
          },
          {
            "agent": "Gemini",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: gemini-code-assist[bot]",
            "repository": "google/ax",
            "branch": "main",
            "sha": "423549a5409b2dee1f5c45ea10b0c6facce62dd1",
            "url": "https://github.com/google/ax/commit/423549a5409b2dee1f5c45ea10b0c6facce62dd1",
            "title": "Fix the README section about the Python agent (#104)",
            "observedAt": "2026-03-17T02:12:40Z"
          },
          {
            "agent": "Gemini",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: gemini-code-assist[bot]",
            "repository": "google/ax",
            "branch": "main",
            "sha": "a5c1aff3a297808ae639d0bfdf37eb421aafdd4d",
            "url": "https://github.com/google/ax/commit/a5c1aff3a297808ae639d0bfdf37eb421aafdd4d",
            "title": "Small improvements in the exec loop. (#128)",
            "observedAt": "2026-03-24T01:30:19Z"
          },
          {
            "agent": "Gemini",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: gemini-code-assist[bot]",
            "repository": "google/ax",
            "branch": "main",
            "sha": "d694866ec5dba1c5010a277da3a3f4ccb10c2bdb",
            "url": "https://github.com/google/ax/commit/d694866ec5dba1c5010a277da3a3f4ccb10c2bdb",
            "title": "Move experimental docs to experimental (#264)",
            "observedAt": "2026-04-30T15:48:52Z"
          },
          {
            "agent": "Gemini",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: gemini-code-assist[bot]",
            "repository": "google/ax",
            "branch": "main",
            "sha": "a29c6e742e9c676baf47fd25ac2a0ffd6015e2f4",
            "url": "https://github.com/google/ax/commit/a29c6e742e9c676baf47fd25ac2a0ffd6015e2f4",
            "title": "Some more updates to the NOT section (#271)",
            "observedAt": "2026-04-30T18:42:30Z"
          },
          {
            "agent": "Gemini",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: gemini-code-assist[bot]",
            "repository": "google/ax",
            "branch": "main",
            "sha": "b42d530c8e5aca8ddd3f2d3da4a550366a3b01af",
            "url": "https://github.com/google/ax/commit/b42d530c8e5aca8ddd3f2d3da4a550366a3b01af",
            "title": "Update wording in Substrate instructructions (#278)",
            "observedAt": "2026-05-04T19:04:10Z"
          },
          {
            "agent": "Gemini",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: gemini-code-assist[bot]",
            "repository": "google/ax",
            "branch": "main",
            "sha": "f220cec527f394a31a2c14578a9b2d039dd41c9e",
            "url": "https://github.com/google/ax/commit/f220cec527f394a31a2c14578a9b2d039dd41c9e",
            "title": "sync code with latest substrate API changes (#348)",
            "observedAt": "2026-05-15T23:42:28Z"
          }
        ]
      }
    },
    "kungfu": {
      "label": "Kungfu Systems",
      "scope": "all public repositories in kungfu-systems with merged work in the window",
      "query": "org:kungfu-systems is:pr is:merged merged:2026-06-16T00:00:00Z..2026-07-15T23:59:59Z is:public",
      "organizationForm": "one human product owner directing Agent-mediated work across a public multi-repository system",
      "summary": {
        "mergedPullRequests": 2323,
        "activeRepositories": 11,
        "authorAccounts": 3,
        "activeMergeDays": 18,
        "totalAdditions": 1054380,
        "totalDeletions": 324206,
        "totalChangedFiles": 23395,
        "changeSize": {
          "median": 124,
          "p25": 10,
          "p75": 560,
          "p90": 1417
        },
        "authors": [
          {
            "name": "dongkeren",
            "count": 2261
          },
          {
            "name": "kungfu-origin",
            "count": 53
          },
          {
            "name": "app/kungfu-systems-release-bot",
            "count": 9
          }
        ],
        "repositories": [
          {
            "name": "kungfu-systems/buildchain",
            "count": 1072
          },
          {
            "name": "kungfu-systems/kungfu",
            "count": 695
          },
          {
            "name": "kungfu-systems/build-images",
            "count": 149
          },
          {
            "name": "kungfu-systems/kfd",
            "count": 108
          },
          {
            "name": "kungfu-systems/site-libkungfu-dev",
            "count": 58
          },
          {
            "name": "kungfu-systems/paper-observer-declared-timelines",
            "count": 57
          },
          {
            "name": "kungfu-systems/libnode",
            "count": 54
          },
          {
            "name": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
            "count": 52
          },
          {
            "name": "kungfu-systems/paper-kungfu-product-white-paper",
            "count": 46
          },
          {
            "name": "kungfu-systems/site-kungfu-tech",
            "count": 25
          },
          {
            "name": "kungfu-systems/homebrew-tap",
            "count": 7
          }
        ],
        "daily": [
          {
            "name": "2026-06-27",
            "count": 1
          },
          {
            "name": "2026-06-29",
            "count": 31
          },
          {
            "name": "2026-06-30",
            "count": 73
          },
          {
            "name": "2026-07-01",
            "count": 167
          },
          {
            "name": "2026-07-02",
            "count": 118
          },
          {
            "name": "2026-07-03",
            "count": 98
          },
          {
            "name": "2026-07-04",
            "count": 139
          },
          {
            "name": "2026-07-05",
            "count": 125
          },
          {
            "name": "2026-07-06",
            "count": 202
          },
          {
            "name": "2026-07-07",
            "count": 189
          },
          {
            "name": "2026-07-08",
            "count": 129
          },
          {
            "name": "2026-07-09",
            "count": 140
          },
          {
            "name": "2026-07-10",
            "count": 195
          },
          {
            "name": "2026-07-11",
            "count": 112
          },
          {
            "name": "2026-07-12",
            "count": 92
          },
          {
            "name": "2026-07-13",
            "count": 123
          },
          {
            "name": "2026-07-14",
            "count": 163
          },
          {
            "name": "2026-07-15",
            "count": 226
          }
        ],
        "workTypes": [
          {
            "name": "fix",
            "count": 482
          },
          {
            "name": "feat",
            "count": 445
          },
          {
            "name": "unclassified",
            "count": 430
          },
          {
            "name": "chore",
            "count": 368
          },
          {
            "name": "release",
            "count": 215
          },
          {
            "name": "docs",
            "count": 137
          },
          {
            "name": "ci",
            "count": 109
          },
          {
            "name": "refactor",
            "count": 67
          },
          {
            "name": "test",
            "count": 22
          },
          {
            "name": "build",
            "count": 19
          },
          {
            "name": "alpha",
            "count": 8
          },
          {
            "name": "shifu",
            "count": 6
          },
          {
            "name": "promote",
            "count": 4
          },
          {
            "name": "storage",
            "count": 4
          },
          {
            "name": "perf",
            "count": 3
          },
          {
            "name": "check",
            "count": 1
          },
          {
            "name": "diag",
            "count": 1
          },
          {
            "name": "rewind",
            "count": 1
          },
          {
            "name": "style",
            "count": 1
          }
        ]
      },
      "records": [
        {
          "repository": "kungfu-systems/kungfu",
          "number": 130,
          "url": "https://github.com/kungfu-systems/kungfu/pull/130",
          "title": "ci: fallback release verify runners outside official repo",
          "body": "Make the release-verify caller pass self-hosted runner labels only when the workflow runs in the official kungfu-systems/kungfu repository.\\n\\nForks and other repositories leave the label inputs empty, so the reusable workflow falls back to its GitHub-hosted defaults. This PR targets dev/v2/v2.4 and does not trigger the alpha/release heavy build workflow.",
          "author": "dongkeren",
          "createdAt": "2026-06-27T12:32:46Z",
          "mergedAt": "2026-06-27T12:33:21Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1",
          "title": "Launch buildchain v1 workspace",
          "body": "## Summary\n- migrate active buildchain workflows and actions into the buildchain v1 monorepo\n- build shipped actions with pnpm, tsup, and Node 24, committing dist/index.js bundles\n- exclude retired Airtable/dependency/collaborator/purge actions from v1 and keep retired workflows as explicit rejection paths\n- add manual agent-120 self-hosted runner smoke validation\n\n## Verification\n- pnpm run check\n- secret literal scan for GitHub/Airtable token patterns\n",
          "author": "dongkeren",
          "createdAt": "2026-06-29T06:14:24Z",
          "mergedAt": "2026-06-29T06:18:26Z",
          "additions": 15709,
          "deletions": 142,
          "changedFiles": 136
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 2,
          "url": "https://github.com/kungfu-systems/buildchain/pull/2",
          "title": "Add package manager adapter for actions",
          "body": "## Summary\n- add shared package-manager adapter for pnpm/yarn/npm detection, command generation, workspace discovery, and lockfile parsing\n- replace hard-coded Yarn calls in migrated actions with adapter calls\n- fail closed when consumer repos do not declare a package manager signal\n- remove unused @yarnpkg/lockfile dependency and rebuild action dist bundles\n\n## Verification\n- pnpm --config.verify-deps-before-run=false run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-06-29T06:57:50Z",
          "mergedAt": "2026-06-29T06:58:52Z",
          "additions": 526,
          "deletions": 104,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 3,
          "url": "https://github.com/kungfu-systems/buildchain/pull/3",
          "title": "feat: dogfood buildchain ref promotion",
          "body": "## Summary\n- add internal promote-buildchain-ref action\n- promote v1-alpha from alpha/v1/v1.0 and v1/v1.0 from release/v1/v1.0 after Verify succeeds\n- include alpha/release branches in Verify coverage\n\n## Verification\n- pnpm --config.verify-deps-before-run=false run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-06-29T07:13:00Z",
          "mergedAt": "2026-06-29T07:13:48Z",
          "additions": 455,
          "deletions": 4,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 4,
          "url": "https://github.com/kungfu-systems/buildchain/pull/4",
          "title": "fix: bundle buildchain promotion action deps",
          "body": "## Summary\n- bundle @actions/core and @actions/github into promote-buildchain-ref dist\n- switch the action entrypoint to ESM imports so ESM-only action SDK packages can be bundled\n\n## Verification\n- pnpm --config.verify-deps-before-run=false run check\n- git diff --check\n- explicit bundle scan for external @actions deps",
          "author": "dongkeren",
          "createdAt": "2026-06-29T07:19:45Z",
          "mergedAt": "2026-06-29T07:20:41Z",
          "additions": 84,
          "deletions": 17,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 5,
          "url": "https://github.com/kungfu-systems/buildchain/pull/5",
          "title": "fix: create missing buildchain promotion tags",
          "body": "## Summary\n- treat GitHub updateRef 422 Reference does not exist as a missing tag\n- keep creating the tag when v1-alpha does not exist yet\n- cover the GitHub API behavior in unit tests\n\n## Verification\n- pnpm --config.verify-deps-before-run=false run check\n- git diff --check\n- explicit bundle scan for external @actions deps",
          "author": "dongkeren",
          "createdAt": "2026-06-29T07:24:18Z",
          "mergedAt": "2026-06-29T07:25:07Z",
          "additions": 8,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 6,
          "url": "https://github.com/kungfu-systems/buildchain/pull/6",
          "title": "fix: create buildchain release patch tags",
          "body": "## Summary\n- create or reuse release-line patch tags such as 1.0.0 / 1.0.1 on release branch promotion\n- keep v1 and the current minor tag such as v1.0 aligned to the release patch commit\n- generalize release branch parsing for future minor lines such as release/v1/v1.1\n\n## Verification\n- pnpm --config.verify-deps-before-run=false run check\n- git diff --check\n- explicit bundle scan for external @actions deps",
          "author": "dongkeren",
          "createdAt": "2026-06-29T07:45:41Z",
          "mergedAt": "2026-06-29T07:46:49Z",
          "additions": 238,
          "deletions": 60,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 7,
          "url": "https://github.com/kungfu-systems/buildchain/pull/7",
          "title": "fix: match abv release tag semantics",
          "body": "## Summary\n- restore ABV-style buildchain exact tags: vX.Y.Z and vX.Y.Z-alpha.N\n- promote minor-line alpha tags like v1.0-alpha instead of v1-alpha\n- keep v1 movement guarded by the absence of the next minor tag, matching old action-bump-version behavior\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm --config.verify-deps-before-run=false run check\n- git diff --check\n- promote-buildchain-ref dist dependency scan\n\nNote: this fixes the canonical behavior after the earlier bare 1.0.0 tag implementation; it does not delete the accidental bare tag.",
          "author": "dongkeren",
          "createdAt": "2026-06-29T08:36:58Z",
          "mergedAt": "2026-06-29T08:37:46Z",
          "additions": 585,
          "deletions": 159,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 8,
          "url": "https://github.com/kungfu-systems/buildchain/pull/8",
          "title": "docs: clarify canonical buildchain release tags",
          "body": "## Summary\n- document that exact buildchain release/prerelease tags are v-prefixed\n- explicitly state that bare tags such as 1.0.0 are not maintained release entrypoints\n\n## Verification\n- pnpm --config.verify-deps-before-run=false run check\n- git diff --check\n\nThis PR is the real post-cleanup release carrier; after merge it should promote through alpha/release and produce v1.0.1.",
          "author": "dongkeren",
          "createdAt": "2026-06-29T08:50:43Z",
          "mergedAt": "2026-06-29T08:51:37Z",
          "additions": 6,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 9,
          "url": "https://github.com/kungfu-systems/buildchain/pull/9",
          "title": "fix(release): align buildchain promotion with source version state",
          "body": "## Summary\n- create source version commits during buildchain ref promotion\n- move release, alpha, dev, and floating tags to the corresponding version commits\n- discover version state from lerna/package/workspace metadata and degrade cleanly when none exists\n\n## Verification\n- pnpm --config.verify-deps-before-run=false run check",
          "author": "dongkeren",
          "createdAt": "2026-06-29T09:47:54Z",
          "mergedAt": "2026-06-29T09:48:46Z",
          "additions": 625,
          "deletions": 59,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 10,
          "url": "https://github.com/kungfu-systems/buildchain/pull/10",
          "title": "fix(release): close buildchain governance loop",
          "body": "## Summary\n- require protected PR channel lineage before buildchain ref promotion\n- require release sources to match the same-patch alpha tag tree\n- verify generated version-state trees before refs move\n- make buildchain top-level Release - New Version a self-release no-op so Buildchain Ref Promotion is authoritative\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm --config.verify-deps-before-run=false run check\n\n## Notes\n- alpha/v1/v1.0 and release/v1/v1.0 branch protection were configured to require one approving review, strict Verify / check, conversation resolution, and no force pushes/deletions.",
          "author": "dongkeren",
          "createdAt": "2026-06-29T12:06:15Z",
          "mergedAt": "2026-06-29T12:07:01Z",
          "additions": 618,
          "deletions": 40,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 12,
          "url": "https://github.com/kungfu-systems/buildchain/pull/12",
          "title": "Fix bump-version ESM action bundle",
          "body": "## Summary\n- make bump-version action runtime self-contained without @actions toolkit runtime dependencies\n- keep bump-version source and dist on ESM\n- add inventory guard for module action bundles\n\n## Verification\n- pnpm --config.verify-deps-before-run=false run check\n- node actions/bump-version/dist/index.js\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-06-29T12:21:24Z",
          "mergedAt": "2026-06-29T12:22:16Z",
          "additions": 521,
          "deletions": 82,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 13,
          "url": "https://github.com/kungfu-systems/buildchain/pull/13",
          "title": "Fix buildchain promotion status context",
          "body": "## Summary\n- align buildchain promotion governance input with the actual GitHub check context (`check`)\n- document that branch protection requires the `check` job from the Verify workflow\n\n## Verification\n- pnpm --config.verify-deps-before-run=false run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-06-29T12:26:01Z",
          "mergedAt": "2026-06-29T12:26:55Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 11,
          "url": "https://github.com/kungfu-systems/buildchain/pull/11",
          "title": "Prerelease v1.0.3-alpha.0",
          "body": "## Summary\nPromote buildchain dev/v1/v1.0 to alpha/v1/v1.0 to validate governance-closed buildchain self-promotion.\n\n## Validation\n- PR #10 Verify passed before merge to dev.\n- This PR should satisfy strict buildchain alpha lineage dev/v1/v1.0 -> alpha/v1/v1.0.",
          "author": "dongkeren",
          "createdAt": "2026-06-29T12:07:29Z",
          "mergedAt": "2026-06-29T12:28:12Z",
          "additions": 1139,
          "deletions": 122,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 14,
          "url": "https://github.com/kungfu-systems/buildchain/pull/14",
          "title": "Fix buildchain promotion branch protection fallback",
          "body": "## Summary\n\n- allow buildchain ref promotion to fall back to branch protected status when the GitHub Actions token cannot read branch protection details\n- keep same-repository merged PR lineage and required check governance as the strict release gate\n- align default required status context with the Verify workflow job name\n\n## Verification\n\n- pnpm --config.verify-deps-before-run=false run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-06-29T12:34:03Z",
          "mergedAt": "2026-06-29T12:35:02Z",
          "additions": 94,
          "deletions": 15,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 15,
          "url": "https://github.com/kungfu-systems/buildchain/pull/15",
          "title": "Prerelease v1.0.3-alpha.0",
          "body": "## Summary\n\nPromote the latest dev/v1/v1.0 governance fixes to the alpha channel before buildchain ref promotion.\n\nThis carries the GitHub Actions token branch-protection fallback into the alpha commit that runs the local promotion action.\n\n## Verification\n\n- Verify/check is required on this PR by branch protection.\n- Buildchain Ref Promotion will run after the protected alpha merge.",
          "author": "dongkeren",
          "createdAt": "2026-06-29T12:37:29Z",
          "mergedAt": "2026-06-29T12:41:04Z",
          "additions": 94,
          "deletions": 15,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 16,
          "url": "https://github.com/kungfu-systems/buildchain/pull/16",
          "title": "Fix promotion version-state verification",
          "body": "## Summary\n\n- preserve leading porcelain status whitespace when checking local verification changes\n- allow verification to touch discovered version-state manifests, not only the subset whose version changed\n- log detected version-state files and changed files for release auditability\n\n## Verification\n\n- pnpm --config.verify-deps-before-run=false run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-06-29T12:47:33Z",
          "mergedAt": "2026-06-29T12:48:20Z",
          "additions": 85,
          "deletions": 32,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 17,
          "url": "https://github.com/kungfu-systems/buildchain/pull/17",
          "title": "Prerelease v1.0.3-alpha.0",
          "body": "## Summary\n\nPromote the latest dev/v1/v1.0 release-governance verification fix to the alpha channel.\n\nThis includes the porcelain status preservation fix required for buildchain ref promotion to verify version-state manifests.\n\n## Verification\n\n- Verify/check is required on this PR by branch protection.\n- Buildchain Ref Promotion will run after the protected alpha merge.",
          "author": "dongkeren",
          "createdAt": "2026-06-29T12:49:54Z",
          "mergedAt": "2026-06-29T12:51:13Z",
          "additions": 85,
          "deletions": 32,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 18,
          "url": "https://github.com/kungfu-systems/buildchain/pull/18",
          "title": "Use promotion authority token for buildchain refs",
          "body": "## Summary\n\n- use BUILDCHAIN_PROMOTION_TOKEN for non-dry-run buildchain ref promotion\n- document the token as the controlled release authority equivalent to the old ABV runner\n\n## Verification\n\n- pnpm --config.verify-deps-before-run=false run check\n- git diff --check\n\n## Remote configuration\n\n- BUILDCHAIN_PROMOTION_TOKEN is configured as a repository Actions secret\n- alpha/v1/v1.0 and release/v1/v1.0 keep strict check + one approving review; admin enforcement is disabled so the controlled promotion token can move refs after action-level governance checks pass",
          "author": "dongkeren",
          "createdAt": "2026-06-29T12:55:21Z",
          "mergedAt": "2026-06-29T12:56:10Z",
          "additions": 8,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 19,
          "url": "https://github.com/kungfu-systems/buildchain/pull/19",
          "title": "Prerelease v1.0.3-alpha.0",
          "body": "## Summary\n\nPromote the latest dev/v1/v1.0 promotion-authority workflow change to the alpha channel.\n\nThis includes the repository secret wiring needed for Buildchain Ref Promotion to move protected channel refs after action-level ABV governance checks pass.\n\n## Verification\n\n- Verify/check is required on this PR by branch protection.\n- Buildchain Ref Promotion will run after the protected alpha merge.",
          "author": "dongkeren",
          "createdAt": "2026-06-29T12:57:33Z",
          "mergedAt": "2026-06-29T12:58:44Z",
          "additions": 8,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 20,
          "url": "https://github.com/kungfu-systems/buildchain/pull/20",
          "title": "Release v1.0.3",
          "body": "Promote the verified alpha line to the v1.0 release line.\\n\\nSource alpha evidence:\\n- alpha/v1/v1.0: 74128fba10b5864fdaf31bf9afd8a6fec682ba58\\n- v1.0.3-alpha.1: 74128fba10b5864fdaf31bf9afd8a6fec682ba58\\n- package version: 1.0.3-alpha.1\\n\\nExpected buildchain promotion:\\n- create exact release tag v1.0.3\\n- move floating tags v1 and v1.0 to the release version-state commit\\n- advance alpha/dev to the next prerelease version-state commit\\n- move v1.0-alpha to the new prerelease commit",
          "author": "dongkeren",
          "createdAt": "2026-06-29T13:02:41Z",
          "mergedAt": "2026-06-29T13:03:35Z",
          "additions": 1296,
          "deletions": 140,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 21,
          "url": "https://github.com/kungfu-systems/buildchain/pull/21",
          "title": "Fix settled alpha promotion no-op",
          "body": "Fix a governance idempotency gap found during the v1.0.3 dogfood release.\\n\\nProblem:\\n- release promotion correctly generates the next alpha version-state commit and updates alpha/dev/tags\\n- the alpha push Verify can then trigger a duplicate promotion run for the already-settled version-state SHA\\n- that duplicate run has no dev->alpha PR lineage and currently fails, leaving Actions red even though refs are already correct\\n\\nChange:\\n- keep protected-channel checks\\n- treat an alpha SHA as an already-promoted no-op only when alpha branch, dev branch, exact alpha tag, and floating alpha tag all point to the same SHA\\n- add a regression test proving no PR lookup and no ref writes happen in that settled state\\n\\nVerification:\\n- pnpm --config.verify-deps-before-run=false exec node --test tests/promote-buildchain-ref.test.mjs\\n- pnpm --config.verify-deps-before-run=false --filter ./actions/promote-buildchain-ref build\\n- pnpm --config.verify-deps-before-run=false run check\\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-06-29T13:09:54Z",
          "mergedAt": "2026-06-29T13:10:36Z",
          "additions": 145,
          "deletions": 33,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 22,
          "url": "https://github.com/kungfu-systems/buildchain/pull/22",
          "title": "Prerelease v1.0.4-alpha.0",
          "body": "Promote the settled-alpha no-op fix from dev to alpha.\\n\\nExpected buildchain promotion:\\n- create exact prerelease tag v1.0.4-alpha.1\\n- move alpha/v1/v1.0, dev/v1/v1.0, and v1.0-alpha to the generated version-state commit\\n- duplicate settled-alpha promotion runs should no-op rather than fail",
          "author": "dongkeren",
          "createdAt": "2026-06-29T13:11:34Z",
          "mergedAt": "2026-06-29T13:12:36Z",
          "additions": 145,
          "deletions": 33,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 23,
          "url": "https://github.com/kungfu-systems/buildchain/pull/23",
          "title": "Release v1.0.4",
          "body": "Promote the settled-alpha no-op fix to the v1.0 production line.\\n\\nSource alpha evidence:\\n- alpha/v1/v1.0: a4a38c098df037dbb28c6ef1db91409a542f75ad\\n- v1.0.4-alpha.1: a4a38c098df037dbb28c6ef1db91409a542f75ad\\n- duplicate settled-alpha promotion run no-opped successfully in run 28374725555\\n\\nExpected buildchain promotion:\\n- create exact release tag v1.0.4\\n- move v1 and v1.0 to the release version-state commit\\n- advance alpha/dev to the next prerelease version-state commit\\n- duplicate settled-alpha promotion runs should remain green",
          "author": "dongkeren",
          "createdAt": "2026-06-29T13:15:18Z",
          "mergedAt": "2026-06-29T13:16:16Z",
          "additions": 159,
          "deletions": 47,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 24,
          "url": "https://github.com/kungfu-systems/buildchain/pull/24",
          "title": "Prerelease v1.0.5-alpha.0",
          "body": "Promote buildchain lifecycle configuration changes from dev to alpha.",
          "author": "dongkeren",
          "createdAt": "2026-06-29T16:27:54Z",
          "mergedAt": "2026-06-29T16:29:05Z",
          "additions": 1931,
          "deletions": 143,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 25,
          "url": "https://github.com/kungfu-systems/buildchain/pull/25",
          "title": "Prerelease v1.0.5-alpha.0",
          "body": "Promote protected-branch version-state PR handling from dev to alpha.",
          "author": "dongkeren",
          "createdAt": "2026-06-29T16:37:18Z",
          "mergedAt": "2026-06-29T16:38:43Z",
          "additions": 544,
          "deletions": 99,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 27,
          "url": "https://github.com/kungfu-systems/buildchain/pull/27",
          "title": "Prerelease v1.0.5-alpha.0",
          "body": "Allow buildchain generated version-state pull requests to pass release verification.",
          "author": "dongkeren",
          "createdAt": "2026-06-29T16:44:03Z",
          "mergedAt": "2026-06-29T16:45:20Z",
          "additions": 113,
          "deletions": 13,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 28,
          "url": "https://github.com/kungfu-systems/buildchain/pull/28",
          "title": "Prerelease v1.0.5-alpha.1",
          "body": "Create the generated version-state commit for v1.0.5-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-06-29T16:46:37Z",
          "mergedAt": "2026-06-29T16:47:32Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 29,
          "url": "https://github.com/kungfu-systems/buildchain/pull/29",
          "title": "Release v1.0.5",
          "body": "Promote the verified v1.0.5 alpha line to release.",
          "author": "dongkeren",
          "createdAt": "2026-06-29T16:49:36Z",
          "mergedAt": "2026-06-29T16:50:24Z",
          "additions": 2560,
          "deletions": 227,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 30,
          "url": "https://github.com/kungfu-systems/buildchain/pull/30",
          "title": "Release v1.0.5",
          "body": "Create the generated version-state commit for v1.0.5.",
          "author": "dongkeren",
          "createdAt": "2026-06-29T16:51:35Z",
          "mergedAt": "2026-06-29T16:52:25Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 31,
          "url": "https://github.com/kungfu-systems/buildchain/pull/31",
          "title": "Prerelease v1.0.6-alpha.0",
          "body": "Create the generated version-state commit for v1.0.6-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-06-29T16:53:41Z",
          "mergedAt": "2026-06-29T16:55:55Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 32,
          "url": "https://github.com/kungfu-systems/buildchain/pull/32",
          "title": "Prerelease v1.0.6-alpha.0",
          "body": "Promote the fix that allows buildchain to recognize merged generated version-state PR commits during alpha promotion.\\n\\nValidation:\\n- pnpm run check\\n- dogfood failure reproduced by GitHub run 28388826496",
          "author": "dongkeren",
          "createdAt": "2026-06-29T17:01:12Z",
          "mergedAt": "2026-06-29T17:02:48Z",
          "additions": 174,
          "deletions": 39,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 33,
          "url": "https://github.com/kungfu-systems/buildchain/pull/33",
          "title": "feat: add buildchain config preflight action",
          "body": "## Summary\n- add `actions/validate-config` for Buildchain TOML/version-state/lifecycle preflight\n- expose `validateBuildchainConfig` in the core package\n- document migration preflight for heavyweight repositories such as libnode\n- add unit coverage proving validation does not execute lifecycle commands\n\n## Validation\n- corepack pnpm run test:unit\n- corepack pnpm --filter @kungfu-systems/buildchain-validate-config build\n- corepack pnpm run check\n- git diff --check\n\n## Notes\nThis action is intentionally preparation-only: it validates declarations and required lifecycle stage names, but does not run install/build/verify commands.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T02:03:03Z",
          "mergedAt": "2026-06-30T02:17:33Z",
          "additions": 403,
          "deletions": 31,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 34,
          "url": "https://github.com/kungfu-systems/buildchain/pull/34",
          "title": "Prerelease v1.0.6-alpha.0",
          "body": "## Summary\n- publish Buildchain config preflight support to the v1 alpha line\n- includes `actions/validate-config` and core `validateBuildchainConfig` support from #33\n\n## Release semantics\nThis is the normal Buildchain v1 dev-to-alpha prerelease path. It should move `v1.0-alpha` after Release - Verify and Buildchain Ref Promotion succeed; it must not move production `v1` or `v1.0`.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T02:18:01Z",
          "mergedAt": "2026-06-30T02:20:11Z",
          "additions": 403,
          "deletions": 31,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 35,
          "url": "https://github.com/kungfu-systems/buildchain/pull/35",
          "title": "Prerelease v1.0.6-alpha.1",
          "body": "Create the generated version-state commit for v1.0.6-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T02:21:27Z",
          "mergedAt": "2026-06-30T02:22:27Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 36,
          "url": "https://github.com/kungfu-systems/buildchain/pull/36",
          "title": "Release v1.0.6",
          "body": "## Summary\n- promote Buildchain config preflight support from alpha to production v1\n- includes `actions/validate-config` for no-build Buildchain TOML/lifecycle preflight\n\n## Release semantics\nThis is the normal Buildchain v1 alpha-to-release path. It should create `v1.0.6` and move production `v1` and `v1.0` only after Release - Verify, review, merge, and Buildchain Ref Promotion succeed.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T02:24:57Z",
          "mergedAt": "2026-06-30T02:26:20Z",
          "additions": 549,
          "deletions": 42,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 37,
          "url": "https://github.com/kungfu-systems/buildchain/pull/37",
          "title": "Release v1.0.6",
          "body": "Create the generated version-state commit for v1.0.6.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T02:27:28Z",
          "mergedAt": "2026-06-30T02:29:07Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 38,
          "url": "https://github.com/kungfu-systems/buildchain/pull/38",
          "title": "Prerelease v1.0.7-alpha.0",
          "body": "Create the generated version-state commit for v1.0.7-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T02:30:20Z",
          "mergedAt": "2026-06-30T02:31:18Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 39,
          "url": "https://github.com/kungfu-systems/buildchain/pull/39",
          "title": "fix: bundle action runtime dependencies",
          "body": "## Summary\n- bundle GitHub Actions runtime dependencies into committed dist outputs\n- centralize action tsup settings and strip generated trailing whitespace\n- add an inventory check that rejects unbundled @actions runtime imports\n\n## Verification\n- pnpm run build\n- git diff --check\n- pnpm run check\n- local validate-config execution against libnode buildchain.toml",
          "author": "dongkeren",
          "createdAt": "2026-06-30T02:59:19Z",
          "mergedAt": "2026-06-30T03:00:01Z",
          "additions": 1624,
          "deletions": 306,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 40,
          "url": "https://github.com/kungfu-systems/buildchain/pull/40",
          "title": "Prerelease v1.0.7-alpha.0",
          "body": "## Summary\n- promote the bundled action runtime dependency fix to the alpha channel\n\n## Verification\n- fix branch passed Verify / check in PR #39\n- pnpm run build\n- git diff --check\n- pnpm run check\n- local validate-config execution against libnode buildchain.toml",
          "author": "dongkeren",
          "createdAt": "2026-06-30T03:00:33Z",
          "mergedAt": "2026-06-30T03:01:48Z",
          "additions": 1624,
          "deletions": 306,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 41,
          "url": "https://github.com/kungfu-systems/buildchain/pull/41",
          "title": "Prerelease v1.0.7-alpha.1",
          "body": "Create the generated version-state commit for v1.0.7-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T03:03:06Z",
          "mergedAt": "2026-06-30T03:04:27Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 42,
          "url": "https://github.com/kungfu-systems/buildchain/pull/42",
          "title": "Release v1.0.7",
          "body": "## Summary\n- promote the bundled action runtime dependency fix from alpha to release\n\n## Verification\n- PR #39 Verify / check passed\n- PR #40 Release - Verify and Verify passed\n- PR #41 generated version-state checks passed\n- Buildchain Ref Promotion aligned v1.0-alpha and v1.0.7-alpha.1",
          "author": "dongkeren",
          "createdAt": "2026-06-30T03:06:58Z",
          "mergedAt": "2026-06-30T03:07:51Z",
          "additions": 1625,
          "deletions": 307,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 43,
          "url": "https://github.com/kungfu-systems/buildchain/pull/43",
          "title": "Release v1.0.7",
          "body": "Create the generated version-state commit for v1.0.7.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T03:09:08Z",
          "mergedAt": "2026-06-30T03:10:26Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 44,
          "url": "https://github.com/kungfu-systems/buildchain/pull/44",
          "title": "Prerelease v1.0.8-alpha.0",
          "body": "Create the generated version-state commit for v1.0.8-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T03:11:47Z",
          "mergedAt": "2026-06-30T03:13:06Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 45,
          "url": "https://github.com/kungfu-systems/buildchain/pull/45",
          "title": "Add reusable build surface",
          "body": "## Summary\n- add the Buildchain reusable build workflow for caller-provided platform matrices and lifecycle commands\n- add run-lifecycle action and deterministic artifact manifest generation\n- add a libnode-shaped fixture and documentation for the reusable surface\n\n## Verification\n- pnpm run check\n- local CLI/action fixture smoke",
          "author": "dongkeren",
          "createdAt": "2026-06-30T04:10:28Z",
          "mergedAt": "2026-06-30T04:22:22Z",
          "additions": 946,
          "deletions": 1,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 46,
          "url": "https://github.com/kungfu-systems/buildchain/pull/46",
          "title": "Prerelease v1.0.8-alpha.0",
          "body": "## Summary\nPromote dev/v1/v1.0 to alpha/v1/v1.0 for the reusable build surface release candidate.\n\n## Verification\n- Verify workflow and Build Surface Fixture checks must pass on this PR.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T04:22:49Z",
          "mergedAt": "2026-06-30T04:23:51Z",
          "additions": 946,
          "deletions": 1,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 47,
          "url": "https://github.com/kungfu-systems/buildchain/pull/47",
          "title": "Prerelease v1.0.8-alpha.1",
          "body": "Create the generated version-state commit for v1.0.8-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T04:25:01Z",
          "mergedAt": "2026-06-30T04:26:01Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 48,
          "url": "https://github.com/kungfu-systems/buildchain/pull/48",
          "title": "Release v1.0.8",
          "body": "## Summary\nPromote alpha/v1/v1.0 to release/v1/v1.0 for Buildchain v1.0.8.\n\n## Verification\n- Alpha line is at v1.0.8-alpha.1\n- Verify and Build Surface Fixture checks must pass on this PR.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T04:28:15Z",
          "mergedAt": "2026-06-30T04:29:19Z",
          "additions": 947,
          "deletions": 2,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 49,
          "url": "https://github.com/kungfu-systems/buildchain/pull/49",
          "title": "Release v1.0.8",
          "body": "Create the generated version-state commit for v1.0.8.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T04:30:30Z",
          "mergedAt": "2026-06-30T04:31:33Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 50,
          "url": "https://github.com/kungfu-systems/buildchain/pull/50",
          "title": "Prerelease v1.0.9-alpha.0",
          "body": "Create the generated version-state commit for v1.0.9-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T04:32:57Z",
          "mergedAt": "2026-06-30T04:34:22Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 1,
          "url": "https://github.com/kungfu-systems/build-images/pull/1",
          "title": "Add image publish workflow",
          "body": "## Summary\n\n- add a manifest DAG resolver and image-family build script\n- add a trusted Publish Images workflow for release tags and maintainer dispatch\n- document the GHCR publish path and runner boundary\n\n## Validation\n\n- pnpm run check\n- git diff --check\n\n## Safety\n\n- normal Verify remains read-only\n- GHCR writes are isolated to the Publish Images workflow\n- no self-hosted runner Docker or sudo permissions are required\n",
          "author": "dongkeren",
          "createdAt": "2026-06-30T04:51:56Z",
          "mergedAt": "2026-06-30T04:54:01Z",
          "additions": 347,
          "deletions": 3,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 2,
          "url": "https://github.com/kungfu-systems/build-images/pull/2",
          "title": "Fix image publish script invocation",
          "body": "## Summary\n\n- invoke the image build script through bash in the Publish Images workflow\n- advance the package version to 1.0.0-alpha.1 for the next alpha publish tag\n\n## Validation\n\n- pnpm install --lockfile-only\n- pnpm run check\n- git diff --check\n",
          "author": "dongkeren",
          "createdAt": "2026-06-30T04:56:15Z",
          "mergedAt": "2026-06-30T04:56:38Z",
          "additions": 2,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 3,
          "url": "https://github.com/kungfu-systems/build-images/pull/3",
          "title": "Pull published images by digest",
          "body": "## Summary\n\n- pull each published image back from GHCR by digest after push\n- advance package version to 1.0.0-alpha.2 for the next alpha publish tag\n\n## Validation\n\n- pnpm install --lockfile-only\n- pnpm run check\n- git diff --check\n",
          "author": "dongkeren",
          "createdAt": "2026-06-30T05:04:30Z",
          "mergedAt": "2026-06-30T05:05:02Z",
          "additions": 4,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 51,
          "url": "https://github.com/kungfu-systems/buildchain/pull/51",
          "title": "feat: formalize reusable build contract",
          "body": "## Summary\n- add runner presets and custom matrix resolution for the reusable build workflow\n- add artifact name templates, expected artifact checks, compact summaries, and aggregate build summary output\n- dogfood the new contract through the libnode-shaped fixture and document the reusable surface\n\n## Verification\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-06-30T05:13:35Z",
          "mergedAt": "2026-06-30T05:14:44Z",
          "additions": 900,
          "deletions": 52,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 4,
          "url": "https://github.com/kungfu-systems/build-images/pull/4",
          "title": "Add published image consumer smoke",
          "body": "## Summary\n\n- add images.lock.json for the accepted alpha image digests\n- add a Consumer Smoke workflow that pulls published images by digest\n- add lock verification and published-image smoke scripts\n\n## Validation\n\n- pnpm run check\n- python3 scripts/verify-image-lock.py\n- bash -n scripts/smoke-published-images.sh scripts/build-image-family.sh\n- git diff --check\n\n## Safety\n\n- workflow uses GitHub-hosted ubuntu-24.04\n- package access is read-only\n- no self-hosted runner Docker access is required\n",
          "author": "dongkeren",
          "createdAt": "2026-06-30T05:16:22Z",
          "mergedAt": "2026-06-30T05:17:16Z",
          "additions": 211,
          "deletions": 1,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 52,
          "url": "https://github.com/kungfu-systems/buildchain/pull/52",
          "title": "Prerelease v1.0.9-alpha.0",
          "body": "Promote Buildchain reusable contract changes from dev to alpha for v1.0.9-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T05:15:41Z",
          "mergedAt": "2026-06-30T05:17:36Z",
          "additions": 900,
          "deletions": 52,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 53,
          "url": "https://github.com/kungfu-systems/buildchain/pull/53",
          "title": "Prerelease v1.0.9-alpha.1",
          "body": "Create the generated version-state commit for v1.0.9-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T05:18:37Z",
          "mergedAt": "2026-06-30T05:19:55Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 5,
          "url": "https://github.com/kungfu-systems/build-images/pull/5",
          "title": "Pin pnpm in node build image",
          "body": "## Summary\n- replace corepack prepare with an explicit pnpm global install in the node24-pnpm image\n- bump the package pre-release version to v1.0.0-alpha.3\n\n## Validation\n- pnpm run check\n- git diff --check\n\n## Rollout\n- merge after Verify and Consumer Smoke pass\n- tag v1.0.0-alpha.3 from main after merge\n- publish images from the tag workflow\n",
          "author": "dongkeren",
          "createdAt": "2026-06-30T05:22:02Z",
          "mergedAt": "2026-06-30T05:22:38Z",
          "additions": 2,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 54,
          "url": "https://github.com/kungfu-systems/buildchain/pull/54",
          "title": "Release v1.0.9",
          "body": "Promote Buildchain reusable contract alpha v1.0.9-alpha.1 to production v1.0.9.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T05:21:59Z",
          "mergedAt": "2026-06-30T05:23:12Z",
          "additions": 901,
          "deletions": 53,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 55,
          "url": "https://github.com/kungfu-systems/buildchain/pull/55",
          "title": "Release v1.0.9",
          "body": "Create the generated version-state commit for v1.0.9.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T05:24:29Z",
          "mergedAt": "2026-06-30T05:25:52Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 56,
          "url": "https://github.com/kungfu-systems/buildchain/pull/56",
          "title": "Prerelease v1.0.10-alpha.0",
          "body": "Create the generated version-state commit for v1.0.10-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T05:27:14Z",
          "mergedAt": "2026-06-30T05:28:23Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 6,
          "url": "https://github.com/kungfu-systems/build-images/pull/6",
          "title": "Avoid pnpm corepack shim collision",
          "body": "## Summary\n- install pinned pnpm without enabling the corepack pnpm shim first\n- verify corepack remains available during the image build\n- bump the package pre-release version to v1.0.0-alpha.4 because v1.0.0-alpha.3 failed during publish\n\n## Validation\n- pnpm run check\n- git diff --check\n\n## Rollout\n- merge after Verify and Consumer Smoke pass\n- tag v1.0.0-alpha.4 from main after merge\n- publish images from the tag workflow\n",
          "author": "dongkeren",
          "createdAt": "2026-06-30T05:28:02Z",
          "mergedAt": "2026-06-30T05:28:38Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 7,
          "url": "https://github.com/kungfu-systems/build-images/pull/7",
          "title": "Update published image lock to alpha.4",
          "body": "## Summary\n- update images.lock.json to v1.0.0-alpha.4 digests from publish run 28422527580\n- make the node24-pnpm published-image smoke assert pnpm 11.7.0 exactly\n\n## Validation\n- pnpm run check\n- git diff --check\n\n## Rollout\n- merge after Verify and Consumer Smoke pass\n",
          "author": "dongkeren",
          "createdAt": "2026-06-30T05:34:32Z",
          "mergedAt": "2026-06-30T05:36:32Z",
          "additions": 10,
          "deletions": 11,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 8,
          "url": "https://github.com/kungfu-systems/build-images/pull/8",
          "title": "Prepare v1.0.0 release",
          "body": "## Summary\n- promote the build-images package version from v1.0.0-alpha.4 to v1.0.0\n\n## Validation\n- pnpm run check\n- git diff --check\n\n## Rollout\n- merge after Verify and Consumer Smoke pass\n- tag v1.0.0 from main\n- publish the stable image set from the tag workflow\n- update images.lock.json to stable digests after publish\n",
          "author": "dongkeren",
          "createdAt": "2026-06-30T05:38:55Z",
          "mergedAt": "2026-06-30T05:41:12Z",
          "additions": 3,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 9,
          "url": "https://github.com/kungfu-systems/build-images/pull/9",
          "title": "Update published image lock to v1.0.0",
          "body": "## Summary\n- update images.lock.json to the stable v1.0.0 image digests from publish run 28423021368\n\n## Validation\n- pnpm run check\n- git diff --check\n\n## Rollout\n- merge after Verify and Consumer Smoke pass\n",
          "author": "dongkeren",
          "createdAt": "2026-06-30T05:46:04Z",
          "mergedAt": "2026-06-30T05:46:58Z",
          "additions": 6,
          "deletions": 6,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 57,
          "url": "https://github.com/kungfu-systems/buildchain/pull/57",
          "title": "feat(release): add major-gate promotion",
          "body": "## Summary\n- replace the legacy main release channel with the major-gate PR target\n- add Buildchain self-promotion support for release/vX/vX.Y -> major-gate\n- publish the next major as v(X+1).0.0 and prepare v(X+1).0.1-alpha.0\n- remove the manual bump-major workflow path\n\n## Verification\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-06-30T10:42:44Z",
          "mergedAt": "2026-06-30T10:44:05Z",
          "additions": 543,
          "deletions": 117,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 58,
          "url": "https://github.com/kungfu-systems/buildchain/pull/58",
          "title": "Prerelease v1.0.10-alpha.0",
          "body": "Promote dev/v1/v1.0 to alpha/v1/v1.0 after major-gate support landed.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T10:44:35Z",
          "mergedAt": "2026-06-30T10:46:49Z",
          "additions": 543,
          "deletions": 117,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 59,
          "url": "https://github.com/kungfu-systems/buildchain/pull/59",
          "title": "Prerelease v1.0.10-alpha.1",
          "body": "Create the generated version-state commit for v1.0.10-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T10:47:59Z",
          "mergedAt": "2026-06-30T10:49:33Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 60,
          "url": "https://github.com/kungfu-systems/buildchain/pull/60",
          "title": "Release v1.0.10",
          "body": "Promote alpha/v1/v1.0 to release/v1/v1.0 after v1.0.10-alpha.1 passed verification.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T10:51:49Z",
          "mergedAt": "2026-06-30T10:52:58Z",
          "additions": 544,
          "deletions": 118,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 61,
          "url": "https://github.com/kungfu-systems/buildchain/pull/61",
          "title": "Release v1.0.10",
          "body": "Create the generated version-state commit for v1.0.10.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T10:54:16Z",
          "mergedAt": "2026-06-30T10:55:41Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 62,
          "url": "https://github.com/kungfu-systems/buildchain/pull/62",
          "title": "Prerelease v1.0.11-alpha.0",
          "body": "Create the generated version-state commit for v1.0.11-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T10:57:04Z",
          "mergedAt": "2026-06-30T10:58:20Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 63,
          "url": "https://github.com/kungfu-systems/buildchain/pull/63",
          "title": "Prepare v2.0.0",
          "body": "Promote the current production release line through major-gate to publish Buildchain v2.0.0.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T11:02:00Z",
          "mergedAt": "2026-06-30T11:03:04Z",
          "additions": 544,
          "deletions": 118,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 65,
          "url": "https://github.com/kungfu-systems/buildchain/pull/65",
          "title": "Fix major-gate version-state verification",
          "body": "## Summary\n- recognize buildchain/version-state/major-gate refs in bump-version verification\n- treat major-gate version-state PRs as verify-only patch releases so their titles stay Release vN.0.0\n- remove Buildchain's old repo-local channel bump trigger now that buildchain-ref-promotion owns the self-hosted dogfood loop\n\n## Verification\n- pnpm exec node --test tests/bump-version-ref.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-06-30T11:09:20Z",
          "mergedAt": "2026-06-30T11:10:32Z",
          "additions": 32,
          "deletions": 20,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 66,
          "url": "https://github.com/kungfu-systems/buildchain/pull/66",
          "title": "Prerelease v1.0.11-alpha.0",
          "body": "Promote dev/v1/v1.0 to alpha/v1/v1.0 for the major-gate version-state verification fix.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T11:10:59Z",
          "mergedAt": "2026-06-30T11:12:19Z",
          "additions": 32,
          "deletions": 20,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 67,
          "url": "https://github.com/kungfu-systems/buildchain/pull/67",
          "title": "Prerelease v1.0.11-alpha.1",
          "body": "Create the generated version-state commit for v1.0.11-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T11:13:38Z",
          "mergedAt": "2026-06-30T11:15:00Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 68,
          "url": "https://github.com/kungfu-systems/buildchain/pull/68",
          "title": "Release v1.0.11",
          "body": "Promote verified alpha v1.0.11-alpha.1 to release/v1/v1.0 so the major-gate version-state verification fix is available before dogfooding v2.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T11:16:46Z",
          "mergedAt": "2026-06-30T11:18:11Z",
          "additions": 33,
          "deletions": 21,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 69,
          "url": "https://github.com/kungfu-systems/buildchain/pull/69",
          "title": "Release v1.0.11",
          "body": "Create the generated version-state commit for v1.0.11.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T11:19:32Z",
          "mergedAt": "2026-06-30T11:20:43Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 70,
          "url": "https://github.com/kungfu-systems/buildchain/pull/70",
          "title": "Prerelease v1.0.12-alpha.0",
          "body": "Create the generated version-state commit for v1.0.12-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T11:22:09Z",
          "mergedAt": "2026-06-30T11:23:20Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 71,
          "url": "https://github.com/kungfu-systems/buildchain/pull/71",
          "title": "Prepare v2.0.0",
          "body": "Promote the current v1 release line through major-gate to publish Buildchain v2 as a real dogfood release. This includes the v1.0.11 fix that lets generated major-gate version-state PRs pass protected verification.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T11:24:59Z",
          "mergedAt": "2026-06-30T11:26:00Z",
          "additions": 33,
          "deletions": 21,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 72,
          "url": "https://github.com/kungfu-systems/buildchain/pull/72",
          "title": "Release v2.0.0",
          "body": "Create the generated version-state commit for v2.0.0.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T11:27:22Z",
          "mergedAt": "2026-06-30T11:28:12Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 73,
          "url": "https://github.com/kungfu-systems/buildchain/pull/73",
          "title": "Fix major-gate default branch advancement",
          "body": "## Summary\n- update the repository default branch to the newly prepared dev/vN/vN.0 line during major-gate promotion\n- cover the behavior in promote-buildchain-ref tests\n- rebuild the bundled action dist\n\n## Verification\n- pnpm exec node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-06-30T11:35:05Z",
          "mergedAt": "2026-06-30T11:36:21Z",
          "additions": 75,
          "deletions": 48,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 74,
          "url": "https://github.com/kungfu-systems/buildchain/pull/74",
          "title": "Prerelease v2.0.1-alpha.0",
          "body": "Promote the v2 default-branch advancement fix to alpha/v2/v2.0.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T11:36:41Z",
          "mergedAt": "2026-06-30T11:38:05Z",
          "additions": 75,
          "deletions": 48,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 75,
          "url": "https://github.com/kungfu-systems/buildchain/pull/75",
          "title": "Prerelease v2.0.1-alpha.1",
          "body": "Create the generated version-state commit for v2.0.1-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T11:39:17Z",
          "mergedAt": "2026-06-30T11:40:29Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 76,
          "url": "https://github.com/kungfu-systems/buildchain/pull/76",
          "title": "Release v2.0.1",
          "body": "Promote verified v2.0.1-alpha.1 to release/v2/v2.0. This release includes automatic default-branch advancement during future major-gate promotions.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T11:42:19Z",
          "mergedAt": "2026-06-30T11:43:35Z",
          "additions": 76,
          "deletions": 49,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 77,
          "url": "https://github.com/kungfu-systems/buildchain/pull/77",
          "title": "Release v2.0.1",
          "body": "Create the generated version-state commit for v2.0.1.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T11:44:50Z",
          "mergedAt": "2026-06-30T11:46:17Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 78,
          "url": "https://github.com/kungfu-systems/buildchain/pull/78",
          "title": "Prerelease v2.0.2-alpha.0",
          "body": "Create the generated version-state commit for v2.0.2-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T11:47:48Z",
          "mergedAt": "2026-06-30T11:49:25Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 79,
          "url": "https://github.com/kungfu-systems/buildchain/pull/79",
          "title": "feat(release): support anchored manual version strategy",
          "body": "Summary:\n- add an anchored/manual version strategy with explicit anchor manifests\n- expose version strategy and anchor manifest details through validation and promotion surfaces\n- update the libnode-shaped fixture and docs to model manual upstream anchor handoff\n\nValidation:\n- pnpm exec node --test tests/buildchain-config.test.mjs tests/promote-buildchain-ref.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-06-30T15:12:58Z",
          "mergedAt": "2026-06-30T15:14:22Z",
          "additions": 690,
          "deletions": 115,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 80,
          "url": "https://github.com/kungfu-systems/buildchain/pull/80",
          "title": "Prerelease v2.0.2-alpha.0",
          "body": "Promote dev/v2/v2.0 to alpha/v2/v2.0 after anchored manual version strategy support.\n\nValidation already completed on #79:\n- check\n- libnode-shaped reusable contract matrix",
          "author": "dongkeren",
          "createdAt": "2026-06-30T15:15:02Z",
          "mergedAt": "2026-06-30T15:17:30Z",
          "additions": 690,
          "deletions": 115,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 81,
          "url": "https://github.com/kungfu-systems/buildchain/pull/81",
          "title": "Prerelease v2.0.2-alpha.1",
          "body": "Create the generated version-state commit for v2.0.2-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T15:18:50Z",
          "mergedAt": "2026-06-30T15:20:53Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 82,
          "url": "https://github.com/kungfu-systems/buildchain/pull/82",
          "title": "Release v2.0.2",
          "body": "Promote alpha/v2/v2.0 to release/v2/v2.0 for Buildchain v2.0.2.\n\nIncludes anchored/manual version strategy support and the updated libnode-shaped reusable surface fixture.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T15:22:56Z",
          "mergedAt": "2026-06-30T15:24:22Z",
          "additions": 691,
          "deletions": 116,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 83,
          "url": "https://github.com/kungfu-systems/buildchain/pull/83",
          "title": "Release v2.0.2",
          "body": "Create the generated version-state commit for v2.0.2.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T15:25:46Z",
          "mergedAt": "2026-06-30T15:28:28Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 84,
          "url": "https://github.com/kungfu-systems/buildchain/pull/84",
          "title": "Prerelease v2.0.3-alpha.0",
          "body": "Create the generated version-state commit for v2.0.3-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T15:29:52Z",
          "mergedAt": "2026-06-30T15:31:18Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 85,
          "url": "https://github.com/kungfu-systems/buildchain/pull/85",
          "title": "docs: align buildchain references with v2",
          "body": "Summary:\n- update Buildchain documentation and action README examples from v1 to v2\n- update reusable workflow defaults and Buildchain self-references to v2\n- keep third-party action versions and non-Buildchain remote path defaults unchanged\n\nValidation:\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-06-30T16:03:05Z",
          "mergedAt": "2026-06-30T16:04:15Z",
          "additions": 150,
          "deletions": 150,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 86,
          "url": "https://github.com/kungfu-systems/buildchain/pull/86",
          "title": "Prerelease v2.0.3-alpha.0",
          "body": "Promote dev/v2/v2.0 to alpha/v2/v2.0 after aligning Buildchain documentation and workflow defaults with v2.\n\nValidation on #85:\n- pnpm run check\n- Build Surface Fixture matrix",
          "author": "dongkeren",
          "createdAt": "2026-06-30T16:04:40Z",
          "mergedAt": "2026-06-30T16:05:55Z",
          "additions": 150,
          "deletions": 150,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 87,
          "url": "https://github.com/kungfu-systems/buildchain/pull/87",
          "title": "Prerelease v2.0.3-alpha.1",
          "body": "Create the generated version-state commit for v2.0.3-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T16:07:10Z",
          "mergedAt": "2026-06-30T16:08:22Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 88,
          "url": "https://github.com/kungfu-systems/buildchain/pull/88",
          "title": "Release v2.0.3",
          "body": "Promote alpha/v2/v2.0 to release/v2/v2.0 for Buildchain v2.0.3.\n\nIncludes v2 documentation/reference alignment and workflow default updates.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T16:10:04Z",
          "mergedAt": "2026-06-30T16:11:19Z",
          "additions": 151,
          "deletions": 151,
          "changedFiles": 36
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 89,
          "url": "https://github.com/kungfu-systems/buildchain/pull/89",
          "title": "Release v2.0.3",
          "body": "Create the generated version-state commit for v2.0.3.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T16:12:38Z",
          "mergedAt": "2026-06-30T16:14:00Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 90,
          "url": "https://github.com/kungfu-systems/buildchain/pull/90",
          "title": "Prerelease v2.0.4-alpha.0",
          "body": "Create the generated version-state commit for v2.0.4-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T16:15:33Z",
          "mergedAt": "2026-06-30T16:17:58Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 91,
          "url": "https://github.com/kungfu-systems/buildchain/pull/91",
          "title": "fix: default batch pull request refs to v2",
          "body": "## Summary\n- default batch-pull-request branch selection to dev/v2/v2.0 -> alpha/v2/v2.0\n- rebuild the packaged action bundle\n\n## Verification\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-06-30T16:21:33Z",
          "mergedAt": "2026-06-30T16:23:08Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 92,
          "url": "https://github.com/kungfu-systems/buildchain/pull/92",
          "title": "Prerelease v2.0.4-alpha.0",
          "body": "Promote verified dev changes into the alpha channel for Buildchain v2.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T16:24:55Z",
          "mergedAt": "2026-06-30T16:26:36Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 93,
          "url": "https://github.com/kungfu-systems/buildchain/pull/93",
          "title": "Prerelease v2.0.4-alpha.1",
          "body": "Create the generated version-state commit for v2.0.4-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T16:27:56Z",
          "mergedAt": "2026-06-30T16:29:14Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 94,
          "url": "https://github.com/kungfu-systems/buildchain/pull/94",
          "title": "Release v2.0.4",
          "body": "Promote verified alpha state into the Buildchain v2.0 release channel.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T16:31:09Z",
          "mergedAt": "2026-06-30T16:32:31Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 95,
          "url": "https://github.com/kungfu-systems/buildchain/pull/95",
          "title": "Release v2.0.4",
          "body": "Create the generated version-state commit for v2.0.4.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T16:33:55Z",
          "mergedAt": "2026-06-30T16:35:30Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 96,
          "url": "https://github.com/kungfu-systems/buildchain/pull/96",
          "title": "Prerelease v2.0.5-alpha.0",
          "body": "Create the generated version-state commit for v2.0.5-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-06-30T16:36:53Z",
          "mergedAt": "2026-06-30T16:38:17Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 97,
          "url": "https://github.com/kungfu-systems/buildchain/pull/97",
          "title": "feat: add publish gate channels",
          "body": "## Summary\n- add reusable build publish gate inputs/outputs (`publish-channel`, `publish-refs-json`, `publish-allowed`, `publish-reason`)\n- separate trusted event verification from publish eligibility so PRs can verify without publishing\n- document default alpha/release/major channels and custom channel regex contracts\n\n## Verification\n- pnpm run check\n- git diff --check\n- CLI smoke: release push on refs/heads/release/v2/v2.0 resolves publish-allowed=true\n",
          "author": "dongkeren",
          "createdAt": "2026-06-30T23:57:49Z",
          "mergedAt": "2026-06-30T23:59:02Z",
          "additions": 377,
          "deletions": 25,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 98,
          "url": "https://github.com/kungfu-systems/buildchain/pull/98",
          "title": "Prerelease v2.0.5-alpha.0",
          "body": "## Summary\n- promote dev/v2/v2.0 to alpha/v2/v2.0\n- dogfood Buildchain publish gate/channel outputs on the alpha release path\n\n## Verification\n- source PR #97 passed check and Build Surface Fixture\n",
          "author": "dongkeren",
          "createdAt": "2026-06-30T23:59:39Z",
          "mergedAt": "2026-07-01T00:01:21Z",
          "additions": 377,
          "deletions": 25,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 99,
          "url": "https://github.com/kungfu-systems/buildchain/pull/99",
          "title": "Prerelease v2.0.5-alpha.1",
          "body": "Create the generated version-state commit for v2.0.5-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T00:02:38Z",
          "mergedAt": "2026-07-01T00:03:57Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 100,
          "url": "https://github.com/kungfu-systems/buildchain/pull/100",
          "title": "Release v2.0.5",
          "body": "## Summary\n- promote alpha/v2/v2.0 to release/v2/v2.0\n- publish Buildchain v2 with reusable publish gate/channel outputs\n\n## Verification\n- alpha version-state PR #99 passed Release - Verify, Verify, and Build Surface Fixture\n- v2.0.5-alpha.1 and v2.0-alpha point to the alpha version-state commit\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T00:06:34Z",
          "mergedAt": "2026-07-01T00:07:54Z",
          "additions": 378,
          "deletions": 26,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 101,
          "url": "https://github.com/kungfu-systems/buildchain/pull/101",
          "title": "Release v2.0.5",
          "body": "Create the generated version-state commit for v2.0.5.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T00:09:13Z",
          "mergedAt": "2026-07-01T00:10:27Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 102,
          "url": "https://github.com/kungfu-systems/buildchain/pull/102",
          "title": "Prerelease v2.0.6-alpha.0",
          "body": "Create the generated version-state commit for v2.0.6-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T00:12:05Z",
          "mergedAt": "2026-07-01T00:13:24Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 103,
          "url": "https://github.com/kungfu-systems/buildchain/pull/103",
          "title": "feat: lock publish gate source state",
          "body": "## Summary\n- resolve publish-gate source branches to immutable SHAs before checkout/build/summary\n- emit resolved release manifests with version-state and anchor evidence\n- add source-lock verification helpers and package-set publish planning semantics\n- document the reusable publish source contract and inventory it as a hard surface\n\n## Verification\n- corepack pnpm run check\n- local libnode-shaped resolved release manifest smoke\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T00:56:53Z",
          "mergedAt": "2026-07-01T01:04:29Z",
          "additions": 988,
          "deletions": 34,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 104,
          "url": "https://github.com/kungfu-systems/buildchain/pull/104",
          "title": "Prerelease v2.0.6-alpha.0",
          "body": "## Summary\nPromote Buildchain dev/v2/v2.0 to alpha/v2/v2.0 for the publish gate source-lock release train.\n\n## Verification\n- dev PR #103 Verify passed\n- dev PR #103 Build Surface Fixture passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T01:05:20Z",
          "mergedAt": "2026-07-01T01:07:35Z",
          "additions": 988,
          "deletions": 34,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 105,
          "url": "https://github.com/kungfu-systems/buildchain/pull/105",
          "title": "Prerelease v2.0.6-alpha.1",
          "body": "Create the generated version-state commit for v2.0.6-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T01:08:48Z",
          "mergedAt": "2026-07-01T01:10:22Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 106,
          "url": "https://github.com/kungfu-systems/buildchain/pull/106",
          "title": "Release v2.0.6",
          "body": "## Summary\nPromote Buildchain v2.0 alpha source-lock release to production.\n\n## Evidence\n- alpha exact tag: v2.0.6-alpha.1\n- v2.0-alpha, alpha/v2/v2.0, and dev/v2/v2.0 point at d490fbe\n- Build Surface Fixture passed on #104 and generated #105\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T01:12:26Z",
          "mergedAt": "2026-07-01T01:14:06Z",
          "additions": 989,
          "deletions": 35,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 107,
          "url": "https://github.com/kungfu-systems/buildchain/pull/107",
          "title": "Release v2.0.6",
          "body": "Create the generated version-state commit for v2.0.6.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T01:15:15Z",
          "mergedAt": "2026-07-01T01:16:48Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 108,
          "url": "https://github.com/kungfu-systems/buildchain/pull/108",
          "title": "Prerelease v2.0.7-alpha.0",
          "body": "Create the generated version-state commit for v2.0.7-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T01:18:07Z",
          "mergedAt": "2026-07-01T01:19:49Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 109,
          "url": "https://github.com/kungfu-systems/buildchain/pull/109",
          "title": "feat: make publish-gate major canonical",
          "body": "## Summary\n\n- make `publish-gate/major` the canonical Buildchain next-major gate across workflow triggers and promotion logic\n- keep `major-gate` as an explicit legacy compatibility alias\n- update release docs and inventory stable refs to v2, with inventory checks preventing drift\n- rebuild affected action bundles\n\n## Validation\n\n- `corepack pnpm run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T02:01:38Z",
          "mergedAt": "2026-07-01T02:03:17Z",
          "additions": 190,
          "deletions": 122,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 110,
          "url": "https://github.com/kungfu-systems/buildchain/pull/110",
          "title": "Prerelease v2.0.7-alpha.0",
          "body": "## Summary\n\nPromote Buildchain dev/v2/v2.0 to alpha/v2/v2.0 after making `publish-gate/major` the canonical major gate.\n\n## Validation\n\n- PR #109 checks passed\n- `corepack pnpm run check` passed locally on the source branch\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T02:04:08Z",
          "mergedAt": "2026-07-01T02:06:42Z",
          "additions": 190,
          "deletions": 122,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 111,
          "url": "https://github.com/kungfu-systems/buildchain/pull/111",
          "title": "Prerelease v2.0.7-alpha.1",
          "body": "Create the generated version-state commit for v2.0.7-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T02:07:57Z",
          "mergedAt": "2026-07-01T02:09:59Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 112,
          "url": "https://github.com/kungfu-systems/buildchain/pull/112",
          "title": "Release v2.0.7",
          "body": "Promote alpha/v2/v2.0 to release/v2/v2.0 for Buildchain v2.0.7 after publish-gate/major semantic closure dogfood.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T02:11:32Z",
          "mergedAt": "2026-07-01T02:13:04Z",
          "additions": 191,
          "deletions": 123,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 113,
          "url": "https://github.com/kungfu-systems/buildchain/pull/113",
          "title": "Release v2.0.7",
          "body": "Create the generated version-state commit for v2.0.7.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T02:14:13Z",
          "mergedAt": "2026-07-01T02:15:38Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 114,
          "url": "https://github.com/kungfu-systems/buildchain/pull/114",
          "title": "Prerelease v2.0.8-alpha.0",
          "body": "Create the generated version-state commit for v2.0.8-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T02:16:57Z",
          "mergedAt": "2026-07-01T02:18:28Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 115,
          "url": "https://github.com/kungfu-systems/buildchain/pull/115",
          "title": "Complete action ESM migration",
          "body": "## Summary\n- migrate all shipped active action sources to ESM boundaries\n- require action packages to declare type=module and build ESM bundles with tsup\n- remove legacy CommonJS core compatibility files\n- extend inventory checks and document the ESM contract\n\n## Verification\n- corepack pnpm run check\n- rg -n \"require\\(|module\\.exports|exports\\.|require\\.main|createRequire|package-manager\\.cjs|buildchain-config\\.cjs\" actions packages tests scripts -S --glob '!**/dist/**'\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T02:45:54Z",
          "mergedAt": "2026-07-01T02:47:35Z",
          "additions": 1168,
          "deletions": 1878,
          "changedFiles": 70
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 116,
          "url": "https://github.com/kungfu-systems/buildchain/pull/116",
          "title": "Prerelease v2.0.8-alpha.0",
          "body": "Promote the current dev/v2/v2.0 state to the v2.0 alpha channel.\n\nExpected Buildchain promotion result:\n- create or reuse v2.0.8-alpha.1\n- move v2.0-alpha\n- align alpha/v2/v2.0 and dev/v2/v2.0 to the generated version-state commit\n\nIncludes:\n- Complete action ESM migration from #115",
          "author": "dongkeren",
          "createdAt": "2026-07-01T02:48:38Z",
          "mergedAt": "2026-07-01T02:50:20Z",
          "additions": 1168,
          "deletions": 1878,
          "changedFiles": 70
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 117,
          "url": "https://github.com/kungfu-systems/buildchain/pull/117",
          "title": "Support CJS dependencies in ESM action bundles",
          "body": "## Summary\n- inject a Node ESM createRequire bridge in the shared action tsup config\n- rebuild committed action dist bundles so bundled CJS dependencies can resolve Node built-ins under type=module\n\n## Why\nThe first ESM migration PR passed local checks but the dogfood alpha promotion failed at action module load with Dynamic require of \"os\" is not supported. This keeps the action package/source boundary ESM while making bundled CJS dependencies work in Node's ESM runtime.\n\n## Verification\n- corepack pnpm run check\n- node actions/promote-buildchain-ref/dist/index.js  # reaches expected missing token input validation\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T02:53:07Z",
          "mergedAt": "2026-07-01T02:54:29Z",
          "additions": 33,
          "deletions": 0,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 118,
          "url": "https://github.com/kungfu-systems/buildchain/pull/118",
          "title": "Prerelease v2.0.8-alpha.0",
          "body": "Promote the repaired dev/v2/v2.0 state to the v2.0 alpha channel.\n\nThis retries alpha promotion after #116 exposed an ESM bundle runtime boundary and #117 fixed it with an explicit Node ESM createRequire bridge.\n\nExpected Buildchain promotion result:\n- create v2.0.8-alpha.1\n- move v2.0-alpha\n- align alpha/v2/v2.0 and dev/v2/v2.0 to the generated version-state commit",
          "author": "dongkeren",
          "createdAt": "2026-07-01T02:54:57Z",
          "mergedAt": "2026-07-01T02:57:01Z",
          "additions": 33,
          "deletions": 0,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 119,
          "url": "https://github.com/kungfu-systems/buildchain/pull/119",
          "title": "Prerelease v2.0.8-alpha.1",
          "body": "Create the generated version-state commit for v2.0.8-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T02:58:15Z",
          "mergedAt": "2026-07-01T02:59:49Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 120,
          "url": "https://github.com/kungfu-systems/buildchain/pull/120",
          "title": "Release v2.0.8",
          "body": "Promote the tested v2.0 alpha channel to production.\n\nExpected Buildchain promotion result:\n- create v2.0.8\n- move v2.0 and v2\n- align release/v2/v2.0 to the generated production version-state commit\n- prepare v2.0.9-alpha.0 and move dev/alpha/v2.0 plus v2.0-alpha to the next alpha source state\n\nIncludes:\n- full active action ESM migration\n- ESM action bundle runtime bridge for bundled CJS dependencies",
          "author": "dongkeren",
          "createdAt": "2026-07-01T03:01:50Z",
          "mergedAt": "2026-07-01T03:03:17Z",
          "additions": 1202,
          "deletions": 1879,
          "changedFiles": 74
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 121,
          "url": "https://github.com/kungfu-systems/buildchain/pull/121",
          "title": "Release v2.0.8",
          "body": "Create the generated version-state commit for v2.0.8.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T03:04:34Z",
          "mergedAt": "2026-07-01T03:06:09Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 122,
          "url": "https://github.com/kungfu-systems/buildchain/pull/122",
          "title": "Prerelease v2.0.9-alpha.0",
          "body": "Create the generated version-state commit for v2.0.9-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T03:07:37Z",
          "mergedAt": "2026-07-01T03:09:08Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 123,
          "url": "https://github.com/kungfu-systems/buildchain/pull/123",
          "title": "fix: resolve publish-source locks without git ls-remote",
          "body": "## Summary\n- resolve current publish-gate push refs from GITHUB_SHA without remote access\n- resolve non-current publish source refs through the GitHub REST refs API using GITHUB_TOKEN\n- make lock and verify use the same resolver and add slash-heavy publish-gate tests\n\n## Validation\n- corepack pnpm exec node --test tests/build-surface.test.mjs\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T03:42:19Z",
          "mergedAt": "2026-07-01T03:43:40Z",
          "additions": 268,
          "deletions": 84,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 124,
          "url": "https://github.com/kungfu-systems/buildchain/pull/124",
          "title": "Prerelease v2.0.9-alpha.0",
          "body": "Promote the publish-source lock fix through the Buildchain v2.0 alpha gate.\n\nIncluded change:\n- #123 fix publish-source lock resolution for GitHub Actions publish-gate refs\n\nValidation on #123:\n- check\n- libnode-shaped reusable workflow matrix",
          "author": "dongkeren",
          "createdAt": "2026-07-01T03:44:27Z",
          "mergedAt": "2026-07-01T03:46:35Z",
          "additions": 268,
          "deletions": 84,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 125,
          "url": "https://github.com/kungfu-systems/buildchain/pull/125",
          "title": "Prerelease v2.0.9-alpha.1",
          "body": "Create the generated version-state commit for v2.0.9-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T03:47:47Z",
          "mergedAt": "2026-07-01T03:50:31Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 126,
          "url": "https://github.com/kungfu-systems/buildchain/pull/126",
          "title": "Release v2.0.9",
          "body": "Promote Buildchain v2.0.9-alpha.1 to release so the publish-source lock fix becomes available from the v2 channel.\n\nIncluded change:\n- #123 fix publish-source lock resolution for GitHub Actions publish-gate refs\n\nAlpha evidence:\n- v2.0.9-alpha.1 -> 2481091b5c28c8354d4a900c0345d2b987ca1bc4",
          "author": "dongkeren",
          "createdAt": "2026-07-01T03:52:45Z",
          "mergedAt": "2026-07-01T03:54:17Z",
          "additions": 269,
          "deletions": 85,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 127,
          "url": "https://github.com/kungfu-systems/buildchain/pull/127",
          "title": "Release v2.0.9",
          "body": "Create the generated version-state commit for v2.0.9.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T03:55:36Z",
          "mergedAt": "2026-07-01T03:57:16Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 128,
          "url": "https://github.com/kungfu-systems/buildchain/pull/128",
          "title": "Prerelease v2.0.10-alpha.0",
          "body": "Create the generated version-state commit for v2.0.10-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T03:58:47Z",
          "mergedAt": "2026-07-01T04:00:09Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 129,
          "url": "https://github.com/kungfu-systems/buildchain/pull/129",
          "title": "feat: add web-surface deployment contract",
          "body": "## Summary\n- add buildchain.toml web-surface project/channel/deploy/retention/security validation\n- add dry-run web-surface manifest, deploy-plan, and cleanup-plan CLI helpers\n- add web-surface-shaped fixture, tests, and user docs\n- expose project/channel/deploy metadata from actions/validate-config\n\n## Verification\n- pnpm run test:unit\n- pnpm run check\n- node scripts/web-surface.mjs --mode validate --cwd fixtures/web-surface-shaped\n- node scripts/web-surface.mjs --mode cleanup-plan --cwd fixtures/web-surface-shaped --aliases pr-123,sha-abcdef123456\n\n## Safety\n- dry-run only for deploy and cleanup plans\n- no AWS, DNS, CloudFront, credential, or self-hosted runner operations performed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T05:02:13Z",
          "mergedAt": "2026-07-01T05:03:37Z",
          "additions": 1586,
          "deletions": 122,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 130,
          "url": "https://github.com/kungfu-systems/buildchain/pull/130",
          "title": "feat: add Buildchain publish transaction",
          "body": "## Summary\n- add reusable publish transaction core with evidence validation, idempotent artifact planning, recovery states, and local recovery CLI\n- wire promote-buildchain-ref to optional lifecycle.publish / publish-command gating before exact/floating refs finalize\n- document the publish transaction protocol and add a multi-artifact fixture\n\n## Verification\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T05:33:33Z",
          "mergedAt": "2026-07-01T05:35:01Z",
          "additions": 1957,
          "deletions": 73,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 131,
          "url": "https://github.com/kungfu-systems/buildchain/pull/131",
          "title": "Prerelease v2.0.10-alpha.0",
          "body": "Promote Buildchain publish transaction work from dev to alpha.\n\nIncludes PR #130:\n- lifecycle.publish publish transaction core\n- promote-buildchain-ref publish evidence gate\n- recovery CLI and docs\n\nVerification before promotion:\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T05:36:21Z",
          "mergedAt": "2026-07-01T05:38:48Z",
          "additions": 3494,
          "deletions": 146,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 132,
          "url": "https://github.com/kungfu-systems/buildchain/pull/132",
          "title": "Prerelease v2.0.10-alpha.1",
          "body": "Create the generated version-state commit for v2.0.10-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T05:40:01Z",
          "mergedAt": "2026-07-01T05:41:35Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 133,
          "url": "https://github.com/kungfu-systems/buildchain/pull/133",
          "title": "Release v2.0.10",
          "body": "Promote Buildchain publish transaction from alpha to release.\n\nExpected release:\n- exact tag: v2.0.10\n- floating tags: v2.0 and v2\n- next alpha prepared by Buildchain after release promotion\n\nEvidence:\n- alpha tag v2.0.10-alpha.1 points at c4c245f006fdbe287b0a2997e92df33144f20a1b\n- alpha/dev refs and v2.0-alpha are aligned",
          "author": "dongkeren",
          "createdAt": "2026-07-01T05:43:27Z",
          "mergedAt": "2026-07-01T05:45:09Z",
          "additions": 3495,
          "deletions": 147,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 134,
          "url": "https://github.com/kungfu-systems/buildchain/pull/134",
          "title": "Release v2.0.10",
          "body": "Create the generated version-state commit for v2.0.10.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T05:46:23Z",
          "mergedAt": "2026-07-01T05:47:54Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 135,
          "url": "https://github.com/kungfu-systems/buildchain/pull/135",
          "title": "Prerelease v2.0.11-alpha.0",
          "body": "Create the generated version-state commit for v2.0.11-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T05:49:21Z",
          "mergedAt": "2026-07-01T05:51:26Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 131,
          "url": "https://github.com/kungfu-systems/kungfu/pull/131",
          "title": "chore(core): use latest libnode alpha",
          "body": "## Summary\n- update @kungfu-tech/libnode to 22.22.3-kf.0\n- refresh pnpm lock entries for the new platform-split libnode packages\n- allow the freshly published libnode alpha packages through pnpm minimum release age policy\n\n## Verification\n- ./kungfu-code install --lockfile-only --frozen-lockfile\n- git diff --check\n- npm/pnpm metadata checks against registry.npmjs.org for the new libnode package set\n\n## Notes\n- The local npm proxy at 192.168.100.222:4873 initially did not expose the newly published darwin/linux platform packages, so official npm registry was used to verify metadata and tarball integrity.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T06:39:19Z",
          "mergedAt": "2026-07-01T06:42:36Z",
          "additions": 39,
          "deletions": 12,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 136,
          "url": "https://github.com/kungfu-systems/buildchain/pull/136",
          "title": "refactor(actions): retire legacy buildchain actions",
          "body": "## Summary\n- keep only validate-config, run-lifecycle, and promote-buildchain-ref under actions/\n- retire legacy migrated action packages and remove their workspace lockfile entries\n- replace bump-version verify-only workflow usage with Buildchain release-line scripts\n- fail closed for retired .release-verify prebuild/publish/approve paths\n\n## Verification\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T06:42:21Z",
          "mergedAt": "2026-07-01T06:44:01Z",
          "additions": 307,
          "deletions": 13548,
          "changedFiles": 121
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 137,
          "url": "https://github.com/kungfu-systems/buildchain/pull/137",
          "title": "feat(release): harden publish transactions",
          "body": "## Summary\n- persist publish transaction state/evidence to durable buildchain/release-state refs before publish/finalization\n- restore durable state/evidence on fresh runners before deciding whether to publish or finalize\n- expose transaction exact tag/release SHA/state ref outputs and document the registry truth/CLI boundary\n- add fresh-runner restore, fail-closed durable persistence, and controlled repair/material drift tests\n\n## Verification\n- pnpm run test:unit\n- pnpm run check\n- pnpm -r --filter \"./actions/**\" build",
          "author": "dongkeren",
          "createdAt": "2026-07-01T07:05:31Z",
          "mergedAt": "2026-07-01T07:06:53Z",
          "additions": 731,
          "deletions": 136,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 138,
          "url": "https://github.com/kungfu-systems/buildchain/pull/138",
          "title": "Release v2.0.11 alpha",
          "body": "Promote dev/v2/v2.0 to alpha/v2/v2.0 for Buildchain publish transaction hardening.\n\nIncludes PR #137: durable publish transaction state/evidence, fresh-runner recovery tests, action outputs, and registry truth docs.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T07:08:12Z",
          "mergedAt": "2026-07-01T07:16:00Z",
          "additions": 1038,
          "deletions": 13684,
          "changedFiles": 130
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 139,
          "url": "https://github.com/kungfu-systems/buildchain/pull/139",
          "title": "Prepare v2.0.11-alpha.1",
          "body": "Create the generated version-state commit for v2.0.11-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T07:17:03Z",
          "mergedAt": "2026-07-01T07:18:38Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 140,
          "url": "https://github.com/kungfu-systems/buildchain/pull/140",
          "title": "Release v2.0.11",
          "body": "Promote Buildchain publish transaction hardening from alpha to release.\n\nAlpha evidence:\n- alpha PR #138 merged\n- generated alpha version-state PR #139 merged\n- v2.0.11-alpha.1 points at 9b079fad9b06aab8c0143fcc391f30bc16b4b11b\n- Buildchain Ref Promotion run 28500591470 passed",
          "author": "kungfu-origin",
          "createdAt": "2026-07-01T07:20:29Z",
          "mergedAt": "2026-07-01T07:22:21Z",
          "additions": 1039,
          "deletions": 13685,
          "changedFiles": 131
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 141,
          "url": "https://github.com/kungfu-systems/buildchain/pull/141",
          "title": "Release v2.0.11",
          "body": "Create the generated version-state commit for v2.0.11.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T07:23:28Z",
          "mergedAt": "2026-07-01T07:25:08Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 142,
          "url": "https://github.com/kungfu-systems/buildchain/pull/142",
          "title": "Prepare v2.0.12-alpha.0",
          "body": "Create the generated version-state commit for v2.0.12-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T07:26:26Z",
          "mergedAt": "2026-07-01T07:28:47Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 143,
          "url": "https://github.com/kungfu-systems/buildchain/pull/143",
          "title": "docs: clarify buildchain v2 surfaces",
          "body": "## Summary\n- clarify that .build.yml is the active Buildchain-native reusable workflow surface\n- document hidden legacy reusable workflows as migration/fail-closed boundaries, not modern publish surfaces\n- align publish transaction examples and release governance wording with lifecycle.publish transaction semantics\n\n## Verification\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T07:46:05Z",
          "mergedAt": "2026-07-01T07:47:45Z",
          "additions": 51,
          "deletions": 18,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 10,
          "url": "https://github.com/kungfu-systems/build-images/pull/10",
          "title": "ci: publish images through buildchain transaction",
          "body": "## Summary\n- move image publishing into Buildchain promote-buildchain-ref publish transactions\n- write Buildchain publish evidence for GHCR image digests\n- make exact image publish reruns reuse matching existing image tags and fail closed on material drift\n- keep Publish Images as manual dry-build only so tag pushes do not double-publish\n\n## Verification\n- corepack pnpm run check\n- local buildchain validate-config action with require lifecycle stages verify,publish\n- simulated publish evidence validated by buildchain core validatePublishEvidence\n\nGoal: build-images-buildchain-e2e",
          "author": "dongkeren",
          "createdAt": "2026-07-01T07:49:30Z",
          "mergedAt": "2026-07-01T07:55:50Z",
          "additions": 270,
          "deletions": 55,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 11,
          "url": "https://github.com/kungfu-systems/build-images/pull/11",
          "title": "ci: publish images through buildchain transaction",
          "body": "## Summary\n- move image publishing into Buildchain promote-buildchain-ref publish transactions\n- write Buildchain publish evidence for GHCR image digests\n- make exact image publish reruns reuse matching existing image tags and fail closed on material drift\n- document the required feature -> dev -> alpha promotion path\n\n## Verification\n- corepack pnpm run check\n- Buildchain validate-config simulated with lifecycle stages verify,publish\n- simulated publish evidence validated by Buildchain core validatePublishEvidence\n\nThis PR intentionally targets dev/v1/v1.1. A follow-up protected PR from dev/v1/v1.1 to alpha/v1/v1.1 is required for Buildchain promotion governance.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T07:57:57Z",
          "mergedAt": "2026-07-01T07:58:54Z",
          "additions": 261,
          "deletions": 55,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 12,
          "url": "https://github.com/kungfu-systems/build-images/pull/12",
          "title": "ci: promote buildchain transaction changes to alpha",
          "body": "## Summary\n- promote the Buildchain publish transaction integration from dev/v1/v1.1 to alpha/v1/v1.1 through the governed Buildchain path\n- includes the feature -> dev -> alpha process note added after the direct feature -> alpha attempt failed governance validation\n\n## Verification\n- PR #11 feature -> dev checks passed\n- corepack pnpm run check passed locally on feature/buildchain-e2e\n\nThis PR is intentionally dev/v1/v1.1 -> alpha/v1/v1.1 so Buildchain Ref Promotion can verify the protected channel lineage.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T07:59:18Z",
          "mergedAt": "2026-07-01T08:00:16Z",
          "additions": 4,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 144,
          "url": "https://github.com/kungfu-systems/buildchain/pull/144",
          "title": "feat: add npm package CLI surface",
          "body": "## Summary\n- make @kungfu-systems/buildchain a publishable npm package with a buildchain CLI\n- add repository init, config validation, lifecycle manifest commands, and core exports\n- add npm Trusted Publishing workflow for exact release tags, publishing prereleases with dist-tag alpha and stable releases with latest\n\n## Verification\n- pnpm run test:unit\n- pnpm run check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n\n## Publish boundary\n- npm publish runs only from exact v-prefixed release tags\n- alpha exact tags publish with npm dist-tag alpha\n- stable exact tags publish with npm dist-tag latest\n- floating refs such as v2, v2.0, and v2.0-alpha do not publish",
          "author": "dongkeren",
          "createdAt": "2026-07-01T08:06:32Z",
          "mergedAt": "2026-07-01T08:08:09Z",
          "additions": 901,
          "deletions": 3,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 145,
          "url": "https://github.com/kungfu-systems/buildchain/pull/145",
          "title": "fix: skip occupied alpha transaction versions",
          "body": "## Summary\n- Treat durable buildchain/release-state alpha refs as occupied exact-version slots during alpha version selection\n- Keep actual tags as the only reusable exact refs, so failed transaction slots advance to the next prerelease\n- Document and test the recovery behavior for publish transaction reruns\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm run check",
          "author": "kungfu-origin",
          "createdAt": "2026-07-01T08:12:34Z",
          "mergedAt": "2026-07-01T08:14:11Z",
          "additions": 198,
          "deletions": 48,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 146,
          "url": "https://github.com/kungfu-systems/buildchain/pull/146",
          "title": "ci: promote buildchain transaction version skip to alpha",
          "body": "## Summary\n- Promote the durable publish-transaction version-skip fix from dev to alpha\n- Keeps buildchain @v2 release path machine-managed through the normal channel promotion flow\n\n## Validation\n- dev/v2/v2.0 Verify run 28503448848 passed",
          "author": "kungfu-origin",
          "createdAt": "2026-07-01T08:15:29Z",
          "mergedAt": "2026-07-01T08:17:45Z",
          "additions": 1150,
          "deletions": 69,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 147,
          "url": "https://github.com/kungfu-systems/buildchain/pull/147",
          "title": "feat: add npm publish dry-run",
          "body": "## Summary\n- add a shared npm publish dry-run script for package preflight validation\n- expose buildchain npm dry-run in the CLI\n- add manual workflow_dispatch dry-run for the npm publish workflow while keeping real publish limited to exact release tag pushes\n\n## Verification\n- node scripts/npm-publish-dry-run.mjs --json\n- pnpm run check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n\n## Publish boundary\n- manual workflow dispatch runs dry-run only\n- exact release tag push remains the only path to real npm publish\n- alpha releases still use dist-tag alpha and stable releases use latest",
          "author": "dongkeren",
          "createdAt": "2026-07-01T08:18:40Z",
          "mergedAt": "2026-07-01T08:20:26Z",
          "additions": 338,
          "deletions": 24,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 148,
          "url": "https://github.com/kungfu-systems/buildchain/pull/148",
          "title": "Prepare v2.0.12-alpha.1",
          "body": "Create the generated version-state commit for v2.0.12-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T08:18:50Z",
          "mergedAt": "2026-07-01T08:20:56Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 149,
          "url": "https://github.com/kungfu-systems/buildchain/pull/149",
          "title": "fix: tolerate advanced dev during alpha finalization",
          "body": "## Summary\n- Let alpha finalization skip dev sync when dev already advanced non-fast-forward\n- Still completes exact alpha and floating alpha tags for the reviewed alpha commit\n- Adds regression coverage and governance docs for this recovery boundary\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm run check",
          "author": "kungfu-origin",
          "createdAt": "2026-07-01T08:30:03Z",
          "mergedAt": "2026-07-01T08:31:52Z",
          "additions": 157,
          "deletions": 17,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 150,
          "url": "https://github.com/kungfu-systems/buildchain/pull/150",
          "title": "ci: promote dev updates to alpha",
          "body": "## Summary\n- Promote current dev/v2/v2.0 to alpha/v2/v2.0 after alpha-finalization recovery fix\n- Lets Buildchain generate the next alpha version-state and complete tags without rewinding dev\n\n## Validation\n- dev/v2/v2.0 Verify run 28504410986 passed",
          "author": "kungfu-origin",
          "createdAt": "2026-07-01T08:32:41Z",
          "mergedAt": "2026-07-01T08:36:07Z",
          "additions": 495,
          "deletions": 41,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 151,
          "url": "https://github.com/kungfu-systems/buildchain/pull/151",
          "title": "release: promote buildchain v2.0.12",
          "body": "## Summary\n- Promote alpha/v2/v2.0 to release/v2/v2.0\n- Includes publish-transaction alpha version occupancy handling and advanced-dev alpha finalization recovery\n- Updates @v2 after Buildchain Ref Promotion completes\n\n## Validation\n- alpha/v2/v2.0 Verify run 28504642879 passed\n- Buildchain Ref Promotion run 28504676433 created v2.0.12-alpha.1",
          "author": "kungfu-origin",
          "createdAt": "2026-07-01T08:38:00Z",
          "mergedAt": "2026-07-01T08:42:23Z",
          "additions": 1607,
          "deletions": 72,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 152,
          "url": "https://github.com/kungfu-systems/buildchain/pull/152",
          "title": "feat(cli): explain release-line dry runs",
          "body": "## Summary\n- add a Buildchain release-line dry-run planner shared by the CLI and promotion action logs\n- support both `buildchain release --dry-run` and `buildchain release dry-run`\n- document the difference between release-line dry-run and npm publish dry-run\n\n## Verification\n- `pnpm run check`\n- `pnpm run pack:check`\n- `node scripts/release-line-dry-run.mjs --target-ref alpha/v2/v2.0 --sha aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa`",
          "author": "dongkeren",
          "createdAt": "2026-07-01T08:39:55Z",
          "mergedAt": "2026-07-01T08:43:42Z",
          "additions": 666,
          "deletions": 56,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 153,
          "url": "https://github.com/kungfu-systems/buildchain/pull/153",
          "title": "Release v2.0.12",
          "body": "Create the generated version-state commit for v2.0.12.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T08:43:36Z",
          "mergedAt": "2026-07-01T08:45:14Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 154,
          "url": "https://github.com/kungfu-systems/buildchain/pull/154",
          "title": "Prepare v2.0.13-alpha.0",
          "body": "Create the generated version-state commit for v2.0.13-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T08:46:58Z",
          "mergedAt": "2026-07-01T08:48:37Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 155,
          "url": "https://github.com/kungfu-systems/buildchain/pull/155",
          "title": "fix: update existing durable release state refs",
          "body": "## Summary\n- update durable release transaction persistence to recover when createRef races an already-created state ref\n- make the git mock reject duplicate createRef calls like GitHub does\n- add regression coverage for state ref visibility races\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm run check",
          "author": "kungfu-origin",
          "createdAt": "2026-07-01T08:54:32Z",
          "mergedAt": "2026-07-01T08:56:07Z",
          "additions": 153,
          "deletions": 46,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 156,
          "url": "https://github.com/kungfu-systems/buildchain/pull/156",
          "title": "fix: promote durable state ref update to alpha",
          "body": "## Summary\n- promote the durable release state ref update fix from dev to alpha\n- unblocks retrying publish transactions when GitHub createRef races an existing state ref\n\n## Validation\n- dev Verify passed on merge commit e8492cce",
          "author": "kungfu-origin",
          "createdAt": "2026-07-01T08:57:29Z",
          "mergedAt": "2026-07-01T08:59:31Z",
          "additions": 782,
          "deletions": 65,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 157,
          "url": "https://github.com/kungfu-systems/buildchain/pull/157",
          "title": "feat(release): publish npm through promotion transaction",
          "body": "## Summary\n- publish Buildchain's npm package from the promote-buildchain-ref transaction via lifecycle.publish\n- keep .github/workflows/npm-publish.yml as manual dry-run only to avoid tag-push duplicate publishes\n- add npm transaction evidence, idempotency, registry digest checks, and fail-closed registry lookup behavior\n- update docs and inventory guardrails for the new promotion-owned npm publish path\n\n## Verification\n- node scripts/check-inventory.mjs\n- node --test tests/publish-transaction.test.mjs\n- pnpm run check\n- pnpm run pack:check\n\nNo real npm publish was run.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T08:58:29Z",
          "mergedAt": "2026-07-01T08:59:48Z",
          "additions": 485,
          "deletions": 65,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 132,
          "url": "https://github.com/kungfu-systems/kungfu/pull/132",
          "title": "build(core): adopt @kungfu-tech/libnode 22.22.3-kf.1",
          "body": "## What\n\n- Bump `@kungfu-tech/libnode` `22.22.3-kf.0` → `22.22.3-kf.1` and refresh the lockfile.\n- Disable pnpm's minimum-release-age supply-chain gate (`minimumReleaseAge: 0`), replacing the per-version allow-list.\n\n## Why\n\nkf.0 only shipped the versioned `libnode.127.dylib`, so the core native binding failed to link (`ld: library 'node' not found`, `-lnode` needs the unversioned name). kf.1 ships the unversioned shared library on macOS and Linux, fixing the link step.\n\nWe publish first-party libnode platform builds and consume them immediately; the release-age gate blocked every fresh bump until it aged past the cutoff and forced a growing per-version allow-list. Turning it off keeps libnode work unblocked.\n\n## Verify\n\nOn macOS arm64, a clean `rebuild:core` + `verify --full` passes 6/6 (C++ compile + link + Nuitka freeze + kfc runtime smoke, `kfc --version` = 4.0.0-alpha.0).",
          "author": "dongkeren",
          "createdAt": "2026-07-01T08:59:15Z",
          "mergedAt": "2026-07-01T09:00:36Z",
          "additions": 23,
          "deletions": 23,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 158,
          "url": "https://github.com/kungfu-systems/buildchain/pull/158",
          "title": "feat: promote npm transaction config to alpha",
          "body": "## Summary\n- promote dev changes that wire Buildchain npm publish through the publish transaction lifecycle\n- brings alpha workflow/config back in sync after the durable state ref fix promotion\n\n## Validation\n- dev Verify passed after the merged PRs",
          "author": "dongkeren",
          "createdAt": "2026-07-01T09:01:26Z",
          "mergedAt": "2026-07-01T09:03:11Z",
          "additions": 485,
          "deletions": 65,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 159,
          "url": "https://github.com/kungfu-systems/buildchain/pull/159",
          "title": "fix: force-update durable release state race refs",
          "body": "## Summary\n- force-update machine-managed durable release-state refs when GitHub reports createRef already exists after getRef missed it\n- keep the normal visible-state-ref path on non-forced fast-forward updates\n- add a regression assertion for the createRef visibility race fallback\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm run check",
          "author": "kungfu-origin",
          "createdAt": "2026-07-01T09:06:40Z",
          "mergedAt": "2026-07-01T09:08:14Z",
          "additions": 9,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 160,
          "url": "https://github.com/kungfu-systems/buildchain/pull/160",
          "title": "fix: promote durable state race force update to alpha",
          "body": "## Summary\n- promote the durable release-state race fix from dev to alpha\n- allows machine-managed release-state refs to recover from GitHub getRef/createRef visibility races\n\n## Validation\n- dev/v2/v2.0 Verify passed on dca38c73fb9029e4f111a7619204a265c0827105",
          "author": "kungfu-origin",
          "createdAt": "2026-07-01T09:09:01Z",
          "mergedAt": "2026-07-01T09:10:55Z",
          "additions": 9,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 161,
          "url": "https://github.com/kungfu-systems/buildchain/pull/161",
          "title": "chore(npm): publish buildchain under kungfu-tech scope",
          "body": "## Summary\n- change the public Buildchain npm package name to @kungfu-tech/buildchain\n- update CLI docs, README, publish transaction docs, and inventory guardrails\n- keep private action workspace package names under @kungfu-systems because they are not published\n\n## Verification\n- node scripts/check-inventory.mjs\n- pnpm run check\n- pnpm run pack:check\n\nBootstrap dry-run for @kungfu-tech/buildchain succeeded with version 0.0.0-bootstrap.0 and dist-tag bootstrap; no real npm publish in this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T09:11:23Z",
          "mergedAt": "2026-07-01T09:13:03Z",
          "additions": 33,
          "deletions": 33,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 162,
          "url": "https://github.com/kungfu-systems/buildchain/pull/162",
          "title": "chore: promote npm scope fix to alpha",
          "body": "## Summary\n- promote the npm package scope fix from dev to alpha\n- expected to publish buildchain under @kungfu-tech/buildchain during the promotion transaction\n\n## Validation\n- dev/v2/v2.0 Verify passed on 61b1054bc3c1f4d42f62ad561a515bb263d7721e",
          "author": "kungfu-origin",
          "createdAt": "2026-07-01T09:13:55Z",
          "mergedAt": "2026-07-01T09:15:55Z",
          "additions": 33,
          "deletions": 33,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 163,
          "url": "https://github.com/kungfu-systems/buildchain/pull/163",
          "title": "Prepare v2.0.13-alpha.5",
          "body": "Create the generated version-state commit for v2.0.13-alpha.5.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T09:26:21Z",
          "mergedAt": "2026-07-01T09:28:00Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 164,
          "url": "https://github.com/kungfu-systems/buildchain/pull/164",
          "title": "fix: resume finalizing alpha transactions",
          "body": "## Summary\n- resume the current alpha version-state when a matching durable release-state ref exists and the exact tag is still missing\n- keep ordinary protected-branch alpha promotions on the existing generated version-state PR path\n- cover the finalization case where dev has already advanced and the durable state ref occupies the current alpha version\n\n## Verification\n- corepack pnpm exec node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm run check",
          "author": "kungfu-origin",
          "createdAt": "2026-07-01T09:33:34Z",
          "mergedAt": "2026-07-01T09:35:19Z",
          "additions": 114,
          "deletions": 51,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 18,
          "url": "https://github.com/kungfu-systems/libnode/pull/18",
          "title": "release: promote libnode 22.22.3-kf.2 to alpha",
          "body": "Promote libnode 22.22.3-kf.2 through the Buildchain alpha channel.\\n\\n- Uses stable buildchain @v2 transaction publishing\\n- Includes darwin/linux alias packaging fix\\n- Includes Windows .dll/.lib/header package gates\\n- Version state: package.json and libnode.release.json = 22.22.3-kf.2",
          "author": "dongkeren",
          "createdAt": "2026-07-01T09:08:47Z",
          "mergedAt": "2026-07-01T09:39:34Z",
          "additions": 5,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 166,
          "url": "https://github.com/kungfu-systems/buildchain/pull/166",
          "title": "chore: promote alpha finalization recovery",
          "body": "## Summary\n- promote the alpha finalization recovery fix into alpha/v2/v2.0\n- enables protected version-state PR merge commits with matching durable release-state refs to resume finalization instead of selecting the next alpha version\n\n## Verification\n- dev/v2/v2.0 Verify: https://github.com/kungfu-systems/buildchain/actions/runs/28508035813\n- PR #164 CI passed before merge",
          "author": "kungfu-origin",
          "createdAt": "2026-07-01T09:37:16Z",
          "mergedAt": "2026-07-01T09:40:48Z",
          "additions": 114,
          "deletions": 51,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 165,
          "url": "https://github.com/kungfu-systems/buildchain/pull/165",
          "title": "fix(release): allow chained alpha version-state promotion",
          "body": "## Summary\n- allow alpha promotion governance to accept generated version-state merge commits even when the next alpha version must be generated because an earlier release-state ref is occupied\n- add a regression test for chained alpha version-state promotion\n- rebuild promote-buildchain-ref dist\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check\n\nThis fixes the failed Buildchain Ref Promotion run 28507651024 before continuing the release.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T09:34:29Z",
          "mergedAt": "2026-07-01T09:41:23Z",
          "additions": 154,
          "deletions": 52,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 167,
          "url": "https://github.com/kungfu-systems/buildchain/pull/167",
          "title": "fix(release): skip stale alpha transactions",
          "body": "## Summary\n- skip stale current-alpha publish transactions when the alpha merge commit has changed\n- retry selection against the next alpha prerelease instead of reusing mismatched durable state\n- add regression coverage for stale alpha transaction identity\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T09:45:19Z",
          "mergedAt": "2026-07-01T09:47:23Z",
          "additions": 218,
          "deletions": 73,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 168,
          "url": "https://github.com/kungfu-systems/buildchain/pull/168",
          "title": "chore: promote stale transaction recovery",
          "body": "Promote the stale alpha transaction recovery fix to the alpha channel so Buildchain can continue the publish transaction.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T09:48:11Z",
          "mergedAt": "2026-07-01T09:50:34Z",
          "additions": 328,
          "deletions": 81,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 169,
          "url": "https://github.com/kungfu-systems/buildchain/pull/169",
          "title": "Prepare v2.0.13-alpha.6",
          "body": "Create the generated version-state commit for v2.0.13-alpha.6.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T09:52:09Z",
          "mergedAt": "2026-07-01T09:53:44Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 170,
          "url": "https://github.com/kungfu-systems/buildchain/pull/170",
          "title": "fix(release): rebase durable state ref updates",
          "body": "## Summary\n- retry durable release-state updates on non-fast-forward by rebuilding the state commit on the latest ref head\n- preserve durable state history instead of force-updating on update races\n- add regression coverage for a newer release-state head appearing between read and update\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T09:57:53Z",
          "mergedAt": "2026-07-01T09:59:43Z",
          "additions": 166,
          "deletions": 79,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 172,
          "url": "https://github.com/kungfu-systems/buildchain/pull/172",
          "title": "chore: sync alpha state back to dev",
          "body": "Merge the alpha version-state finalization back into dev so the next dev-to-alpha promotion is strictly up to date.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T10:02:22Z",
          "mergedAt": "2026-07-01T10:04:33Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 171,
          "url": "https://github.com/kungfu-systems/buildchain/pull/171",
          "title": "chore: promote durable state retry",
          "body": "Promote durable release-state non-fast-forward retry handling to alpha before finalizing the Buildchain npm release.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T10:00:03Z",
          "mergedAt": "2026-07-01T10:06:03Z",
          "additions": 166,
          "deletions": 79,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 174,
          "url": "https://github.com/kungfu-systems/buildchain/pull/174",
          "title": "Prepare v2.0.13-alpha.9",
          "body": "Create the generated version-state commit for v2.0.13-alpha.9.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T10:07:37Z",
          "mergedAt": "2026-07-01T10:09:04Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 176,
          "url": "https://github.com/kungfu-systems/buildchain/pull/176",
          "title": "fix(release): finalize version-state merge transactions",
          "body": "## Summary\n- allow alpha version-state merge commits to finalize the existing publish transaction when the merge commit contains the published version-state head\n- prevent finalization runs from treating the matching version-state transaction as stale and skipping to the next alpha\n- add regression coverage for alpha version-state merge finalization\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T10:13:21Z",
          "mergedAt": "2026-07-01T10:16:11Z",
          "additions": 190,
          "deletions": 46,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 175,
          "url": "https://github.com/kungfu-systems/buildchain/pull/175",
          "title": "Prepare v2.0.13-alpha.10",
          "body": "Create the generated version-state commit for v2.0.13-alpha.10.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T10:10:43Z",
          "mergedAt": "2026-07-01T10:17:55Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 179,
          "url": "https://github.com/kungfu-systems/buildchain/pull/179",
          "title": "chore: sync alpha into dev before finalization fix promotion",
          "body": "Sync the current alpha version-state merge point back into dev so the dev-to-alpha finalization recovery promotion can satisfy protected-branch up-to-date requirements.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T10:19:21Z",
          "mergedAt": "2026-07-01T10:20:52Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 177,
          "url": "https://github.com/kungfu-systems/buildchain/pull/177",
          "title": "chore: promote version-state finalization recovery",
          "body": "Promote the version-state merge transaction finalization fix to alpha before finalizing the current Buildchain alpha release.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T10:17:05Z",
          "mergedAt": "2026-07-01T10:22:40Z",
          "additions": 190,
          "deletions": 46,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 181,
          "url": "https://github.com/kungfu-systems/buildchain/pull/181",
          "title": "Prepare v2.0.13-alpha.13",
          "body": "Create the generated version-state commit for v2.0.13-alpha.13.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T10:24:15Z",
          "mergedAt": "2026-07-01T10:25:38Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 182,
          "url": "https://github.com/kungfu-systems/buildchain/pull/182",
          "title": "chore: promote buildchain v2.0.13 to release",
          "body": "Promote the finalized Buildchain alpha line to the v2.0 release line. This carries the publish transaction hardening and version-state finalization fixes into the production release path.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T10:28:28Z",
          "mergedAt": "2026-07-01T10:30:23Z",
          "additions": 1909,
          "deletions": 224,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 183,
          "url": "https://github.com/kungfu-systems/buildchain/pull/183",
          "title": "Release v2.0.13",
          "body": "Create the generated version-state commit for v2.0.13.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T10:31:44Z",
          "mergedAt": "2026-07-01T10:33:26Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 19,
          "url": "https://github.com/kungfu-systems/libnode/pull/19",
          "title": "fix: prevent default node-gyp install during publish",
          "body": "## Summary\\n- add a no-op install guard so publish verification does not trigger package-manager default node-gyp rebuild from binding.gyp\\n- keep source package gate strict by allowing only the fixed no-op install script\\n\\n## Verification\\n- corepack pnpm verify-package-source\\n- corepack pnpm verify-release\\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T10:13:36Z",
          "mergedAt": "2026-07-01T10:36:19Z",
          "additions": 7,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 13,
          "url": "https://github.com/kungfu-systems/build-images/pull/13",
          "title": "ci: pin buildchain alpha promotion actions",
          "body": "## Summary\n- pin Buildchain workflow actions to v2.0.13-alpha.13 for the E2E validation lane\n- keep image publishing inside the existing Buildchain publish transaction path\n\n## Validation\n- corepack pnpm run check\n- Verify push run 28511021219 passed using the exact Buildchain action tag\n\n## Notes\n- Buildchain v2.0.13-alpha.13 is the first observed alpha in this continuation with npm alpha, exact tag, v2.0-alpha, release-state, and promotion run all complete.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-01T10:29:41Z",
          "mergedAt": "2026-07-01T10:36:42Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 14,
          "url": "https://github.com/kungfu-systems/build-images/pull/14",
          "title": "Promote dev/v1/v1.1 to alpha/v1/v1.1",
          "body": "Promote the latest build-images Buildchain alpha action pin from dev to alpha.\\n\\nEvidence before opening:\\n- PR #13 merged to dev/v1/v1.1 at 4a6edfb0f283f326be92f8ab144a49ccc5a1504f.\\n- PR #13 Verify and Consumer Smoke checks were green.\\n- Buildchain alpha is pinned to v2.0.13-alpha.13 in the workflow.\\n\\nPost-merge validation target:\\n- Verify alpha branch succeeds.\\n- Buildchain Ref Promotion runs lifecycle.publish with durable publish transaction enabled.\\n- GHCR images are public and evidence is durable.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T10:37:17Z",
          "mergedAt": "2026-07-01T10:38:21Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 184,
          "url": "https://github.com/kungfu-systems/buildchain/pull/184",
          "title": "fix(release): finalize release version-state transactions",
          "body": "Allow release and major version-state merge commits to finalize existing publish transactions, matching the alpha path.\\n\\nVerification:\\n- node --test tests/promote-buildchain-ref.test.mjs\\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T10:37:34Z",
          "mergedAt": "2026-07-01T10:39:35Z",
          "additions": 115,
          "deletions": 28,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 185,
          "url": "https://github.com/kungfu-systems/buildchain/pull/185",
          "title": "fix(release): accept transaction ancestors",
          "body": "Allow version-state finalization to recognize the published transaction commit as an ancestor, so a later tooling-only fix merge can still finalize already-published release transactions.\\n\\nVerification:\\n- node --test tests/promote-buildchain-ref.test.mjs\\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T10:41:32Z",
          "mergedAt": "2026-07-01T10:43:13Z",
          "additions": 35,
          "deletions": 15,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 187,
          "url": "https://github.com/kungfu-systems/buildchain/pull/187",
          "title": "fix(release): recover v2.0 finalization",
          "body": "## Summary\n- backport release finalization fixes onto release/v2/v2.0\n- allow only line-scoped recovery branches to target the matching release line\n- keep generic fix/* branches rejected by release-line policy\n\n## Verification\n- node --test tests/release-line-policy.test.mjs tests/promote-buildchain-ref.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T10:49:24Z",
          "mergedAt": "2026-07-01T10:51:19Z",
          "additions": 198,
          "deletions": 36,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 15,
          "url": "https://github.com/kungfu-systems/build-images/pull/15",
          "title": "ci: pass GitHub token to publish lifecycle",
          "body": "Fix the Buildchain publish lifecycle environment so scripts/verify-ghcr-public.sh can read GitHub Package visibility during promotion.\\n\\nWhy:\\n- Alpha promotion run 28511544519 pushed public images but lifecycle.publish failed because package visibility lookup ran without GITHUB_TOKEN and got 401.\\n- The public manifest path itself verifies successfully for the pushed tags.\\n\\nValidation:\\n- corepack pnpm run check\\n- git diff --check\\n\\nExpected release validation after merge:\\n- dev -> alpha promotion reruns Buildchain Ref Promotion.\\n- lifecycle.publish verifies public GHCR packages and writes durable publish evidence before refs move.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T10:51:09Z",
          "mergedAt": "2026-07-01T10:52:00Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 16,
          "url": "https://github.com/kungfu-systems/build-images/pull/16",
          "title": "Promote publish lifecycle token fix to alpha",
          "body": "Promote the GITHUB_TOKEN lifecycle fix into alpha so Buildchain publish transaction can verify public GHCR package visibility before finalizing refs.\\n\\nEvidence:\\n- PR #15 merged to dev after green Verify and Consumer Smoke.\\n- Previous alpha promotion run 28511544519 proved images were pushed/public but failed before evidence/finalization because lifecycle.publish lacked GITHUB_TOKEN.\\n\\nExpected validation:\\n- alpha Verify succeeds;\\n- Buildchain Ref Promotion completes with publish-transaction=true;\\n- release-state is complete and public GHCR manifest checks pass.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T10:52:15Z",
          "mergedAt": "2026-07-01T10:53:09Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 188,
          "url": "https://github.com/kungfu-systems/buildchain/pull/188",
          "title": "fix(release): allow scoped v2.0 recovery promotion",
          "body": "## Summary\n- allow line-scoped buildchain recovery PRs to satisfy strict release promotion when the diff is limited to version state plus promotion recovery files\n- keep ordinary release code drift rejected\n- rebuild promote-buildchain-ref dist\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs tests/release-line-policy.test.mjs\n- pnpm --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T10:56:58Z",
          "mergedAt": "2026-07-01T10:58:52Z",
          "additions": 236,
          "deletions": 52,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 189,
          "url": "https://github.com/kungfu-systems/buildchain/pull/189",
          "title": "Prepare v2.0.14-alpha.0",
          "body": "Create the generated version-state commit for v2.0.14-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T11:00:14Z",
          "mergedAt": "2026-07-01T11:01:52Z",
          "additions": 407,
          "deletions": 61,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 190,
          "url": "https://github.com/kungfu-systems/buildchain/pull/190",
          "title": "fix(release): align recovery governance on dev",
          "body": "## Summary\n- bring the line-scoped release recovery policy back to dev without release/alpha version-state commits\n- bring the scoped buildchain recovery promotion gate back to dev\n- keeps package.json on the dev line unchanged\n\n## Verification\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T11:05:01Z",
          "mergedAt": "2026-07-01T11:06:43Z",
          "additions": 291,
          "deletions": 52,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 17,
          "url": "https://github.com/kungfu-systems/build-images/pull/17",
          "title": "ci: pin buildchain alpha 14",
          "body": "## Summary\n- pin Buildchain workflow actions to v2.0.14-alpha.0\n- keep the build-images publish transaction flow on the latest durable-state finalization fix\n\n## Validation\n- corepack pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T11:07:25Z",
          "mergedAt": "2026-07-01T11:08:14Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 18,
          "url": "https://github.com/kungfu-systems/build-images/pull/18",
          "title": "chore: promote buildchain alpha 14 to alpha",
          "body": "## Summary\n- promote dev/v1/v1.1 to alpha/v1/v1.1\n- exercises Buildchain v2.0.14-alpha.0 on the build-images alpha publish transaction lane\n\n## Validation\n- PR #17 Verify and Consumer Smoke passed before merge",
          "author": "dongkeren",
          "createdAt": "2026-07-01T11:08:34Z",
          "mergedAt": "2026-07-01T11:09:56Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 191,
          "url": "https://github.com/kungfu-systems/buildchain/pull/191",
          "title": "fix(release): resume post-publish alpha transactions",
          "body": "## Summary\n- preserve post-published durable transaction states instead of forcing publish_failed after artifacts are already published\n- resume a matching incomplete alpha durable state ref before minting a new alpha version\n- add coverage for occupied state refs, matching alpha resume, and post-publish durable write failures\n\n## Validation\n- corepack pnpm exec node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T11:29:03Z",
          "mergedAt": "2026-07-01T11:30:43Z",
          "additions": 327,
          "deletions": 51,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 20,
          "url": "https://github.com/kungfu-systems/libnode/pull/20",
          "title": "fix: build libnode through node-gyp dependency graph",
          "body": "## Summary\\n- run the libnode build through the node-gyp dependency graph so the libnode target produces platform binaries before packaging\\n- remove the split make + KF_SKIP_MAKE_LIBNODE build sequence that could leave dist without libnode.so on release push runners\\n\\n## Verification\\n- python3 tomllib parse of buildchain.toml\\n- corepack pnpm verify-package-source\\n- corepack pnpm verify-release\\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T10:44:48Z",
          "mergedAt": "2026-07-01T11:35:46Z",
          "additions": 23,
          "deletions": 23,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 193,
          "url": "https://github.com/kungfu-systems/buildchain/pull/193",
          "title": "chore(release): sync dev with alpha version state",
          "body": "## Summary\n- merge the current alpha version-state package version back into dev/v2/v2.0\n- unblock the next dev-to-alpha promotion PR after alpha generated v2.0.14-alpha.0\n\n## Validation\n- corepack pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T11:34:22Z",
          "mergedAt": "2026-07-01T11:35:51Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 192,
          "url": "https://github.com/kungfu-systems/buildchain/pull/192",
          "title": "chore(release): promote buildchain alpha",
          "body": "## Summary\nPromote dev/v2/v2.0 to alpha/v2/v2.0 after PR #191 fixed durable post-publish alpha transaction recovery.\n\n## Validation\n- PR #191 checks passed\n- dev branch includes post-publish transaction recovery tests and rebuilt action bundle",
          "author": "dongkeren",
          "createdAt": "2026-07-01T11:31:19Z",
          "mergedAt": "2026-07-01T11:37:41Z",
          "additions": 327,
          "deletions": 51,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 194,
          "url": "https://github.com/kungfu-systems/buildchain/pull/194",
          "title": "Prepare v2.0.14-alpha.1",
          "body": "Create the generated version-state commit for v2.0.14-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T11:39:24Z",
          "mergedAt": "2026-07-01T11:40:43Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 19,
          "url": "https://github.com/kungfu-systems/build-images/pull/19",
          "title": "ci: pin buildchain alpha 15",
          "body": "## Summary\n- update Buildchain workflow pins from v2.0.14-alpha.0 to v2.0.14-alpha.1\n- v2.0.14-alpha.1 includes durable post-publish alpha transaction recovery and completed Buildchain alpha release-state\n\n## Validation\n- corepack pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T11:44:03Z",
          "mergedAt": "2026-07-01T11:45:02Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 20,
          "url": "https://github.com/kungfu-systems/build-images/pull/20",
          "title": "chore(release): promote build-images alpha",
          "body": "## Summary\nPromote build-images dev/v1/v1.1 to alpha/v1/v1.1 after pinning Buildchain v2.0.14-alpha.1.\n\n## Validation\n- PR #19 checks passed\n- Buildchain v2.0.14-alpha.1 release-state is complete and npm dist-tag alpha points to it",
          "author": "dongkeren",
          "createdAt": "2026-07-01T11:45:31Z",
          "mergedAt": "2026-07-01T11:46:41Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 195,
          "url": "https://github.com/kungfu-systems/buildchain/pull/195",
          "title": "fix(release): keep alpha state scans readonly",
          "body": "## Summary\n- read historical durable release-state refs without restoring them into the promotion workspace\n- keep restoreDurableReleaseTransaction responsible for the explicit local restore path\n- add regression coverage so skipped alpha durable states do not leave .buildchain/release-state files behind\n\n## Verification\n- corepack pnpm exec node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T11:55:37Z",
          "mergedAt": "2026-07-01T11:57:12Z",
          "additions": 153,
          "deletions": 75,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 196,
          "url": "https://github.com/kungfu-systems/buildchain/pull/196",
          "title": "chore(release): promote readonly state scan fix",
          "body": "## Summary\n- promote the readonly durable release-state scan fix into the v2.0 alpha channel\n- this should unblock downstream build-images alpha promotion by avoiding historical .buildchain/release-state files in the workspace\n\n## Verification\n- dev/v2/v2.0 Verify run 28515754889 passed\n- PR #195 checks passed before merge",
          "author": "dongkeren",
          "createdAt": "2026-07-01T11:57:59Z",
          "mergedAt": "2026-07-01T11:59:32Z",
          "additions": 153,
          "deletions": 75,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 197,
          "url": "https://github.com/kungfu-systems/buildchain/pull/197",
          "title": "feat(web-surface): add merge promotion cleanup contract",
          "body": "## Summary\n\n- add a reusable Buildchain web-surface workflow for PR previews, closed-PR cleanup, push-main staging plans, and gated production plans\n- separate staging access control from edge Basic Auth with explicit access_control and edge_auth fields\n- extend web-surface cleanup planning with closed-PR event metadata, apply/no-op modes, manifest keys, and adapter cleanup steps\n\n## Verification\n\n- pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T11:59:05Z",
          "mergedAt": "2026-07-01T12:00:36Z",
          "additions": 552,
          "deletions": 117,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 198,
          "url": "https://github.com/kungfu-systems/buildchain/pull/198",
          "title": "Prepare v2.0.14-alpha.2",
          "body": "Create the generated version-state commit for v2.0.14-alpha.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T12:00:59Z",
          "mergedAt": "2026-07-01T12:02:47Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 21,
          "url": "https://github.com/kungfu-systems/build-images/pull/21",
          "title": "ci: pin buildchain alpha 2",
          "body": "## Summary\n- pin build-images verify and promotion workflows to buildchain v2.0.14-alpha.2\n- alpha.2 contains the readonly durable state scan fix needed for build-images promotion\n\n## Verification\n- corepack pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T12:06:09Z",
          "mergedAt": "2026-07-01T12:07:16Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 22,
          "url": "https://github.com/kungfu-systems/build-images/pull/22",
          "title": "chore(release): promote build-images alpha",
          "body": "## Summary\n- promote the buildchain v2.0.14-alpha.2 pin into the build-images alpha channel\n- reruns the alpha image publish path with the readonly durable state scan fix\n\n## Verification\n- dev/v1/v1.1 Verify run 28516311794 passed\n- PR #21 checks passed before merge",
          "author": "dongkeren",
          "createdAt": "2026-07-01T12:07:45Z",
          "mergedAt": "2026-07-01T12:09:06Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 200,
          "url": "https://github.com/kungfu-systems/buildchain/pull/200",
          "title": "Sync dev with alpha version state",
          "body": "Sync dev/v2/v2.0 with the current alpha version-state commit so the protected dev-to-alpha promotion PR can be merged without bypassing branch protection.\\n\\nOnly package.json version state changes from 2.0.14-alpha.1 to 2.0.14-alpha.2.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-01T12:12:34Z",
          "mergedAt": "2026-07-01T12:13:59Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 199,
          "url": "https://github.com/kungfu-systems/buildchain/pull/199",
          "title": "Promote dev/v2/v2.0 to alpha",
          "body": "Promote the reviewed Buildchain dev line into alpha so the web-surface merge promotion reusable workflow is available from the alpha channel.\\n\\nIncludes PR #197: feat(web-surface): add merge promotion cleanup contract.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T12:09:26Z",
          "mergedAt": "2026-07-01T12:15:21Z",
          "additions": 552,
          "deletions": 117,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 201,
          "url": "https://github.com/kungfu-systems/buildchain/pull/201",
          "title": "Prepare v2.0.14-alpha.3",
          "body": "Create the generated version-state commit for v2.0.14-alpha.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T12:16:59Z",
          "mergedAt": "2026-07-01T12:18:46Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 23,
          "url": "https://github.com/kungfu-systems/build-images/pull/23",
          "title": "ci: pin buildchain alpha 3",
          "body": "## Summary\n- pin Buildchain validate-config and promote-buildchain-ref actions to v2.0.14-alpha.3\n- keep the build-images release transaction workflow otherwise unchanged\n\n## Verification\n- corepack pnpm run check\n- git diff --check\n\n## Release evidence\n- buildchain v2.0.14-alpha.3 npm alpha is published\n- buildchain exact tag v2.0.14-alpha.3 and v2.0-alpha resolve to the completed release commit\n- durable buildchain release-state 2-0-14-alpha-3 is complete\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T12:21:19Z",
          "mergedAt": "2026-07-01T12:22:08Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 24,
          "url": "https://github.com/kungfu-systems/build-images/pull/24",
          "title": "Promote dev/v1/v1.1 to alpha",
          "body": "## Summary\nPromote the current dev line to alpha so Buildchain v2 can publish the next build-images alpha with Buildchain v2.0.14-alpha.3.\n\n## Notes\n- The dev line includes PR #23, which pins Buildchain actions to v2.0.14-alpha.3.\n- Expected result: Buildchain Ref Promotion publishes the next image-family alpha as public GHCR images and completes durable release-state finalization.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T12:22:19Z",
          "mergedAt": "2026-07-01T12:23:07Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 4,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/4",
          "title": "Use Buildchain web-surface reusable workflow",
          "body": "Adopt the Buildchain v2 web-surface reusable workflow for the site promotion path.\\n\\nChanges:\\n- PR events use Buildchain preview and PR-close cleanup planning.\\n- Pushes to main use Buildchain staging planning from the merged main SHA.\\n- Workflow dispatch keeps production behind an explicit production_approved input and GitHub Environment gate.\\n- Staging is declared as managed-network controlled access with no Basic Auth edge secret.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-01T12:23:02Z",
          "mergedAt": "2026-07-01T12:23:43Z",
          "additions": 34,
          "deletions": 65,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 21,
          "url": "https://github.com/kungfu-systems/libnode/pull/21",
          "title": "release: retry libnode 22.22.3-kf.2 alpha publish",
          "body": "Follow-up for 22.22.3-kf.2 alpha publish.\\n\\nFixes publish-job verification so Buildchain can verify the release manifest without re-initializing the Node source checkout in the publish transaction job.\\n\\nValidation:\\n- corepack pnpm verify-release\\n- no-node temporary verify-release path\\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T12:08:42Z",
          "mergedAt": "2026-07-01T12:27:59Z",
          "additions": 2,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 133,
          "url": "https://github.com/kungfu-systems/kungfu/pull/133",
          "title": "fix(core): bundle pykungfu and libnode into dist/kfc on Windows freeze",
          "body": "## What\n\nOn Windows, copy `pykungfu.<abi>.pyd` + `libnode.dll` into `dist/kfc` after the Nuitka freeze (`run-freeze.js`). macOS/Linux are unaffected — the helper returns early.\n\n## Why\n\nThe MSVC multi-config generator emits `pykungfu.pyd` into `build/` and `libnode.dll` into `build/<config>`, unlike the single-config layout on macOS/Linux where both sit in `build/<config>`. The freeze follows `import pykungfu` with `PYTHONPATH=build/<config>`, so on Windows it neither finds pykungfu nor bundles libnode.dll (Python 3.8+ ignores PATH for extension-module DLL deps). The frozen kfc then fails at runtime:\n\n```\nModuleNotFoundError: No module named 'pykungfu'   # then DLL load failed once found\n```\n\nmacOS/Linux resolve libnode via rpath and Nuitka bundles it, so `dist/kfc` is self-contained there.\n\n## Verify\n\n`verify --full` on Windows x64 now passes **6/6** (previously 5/6; the sole failure was the kfc runtime smoke). macOS arm64 and Linux x64 remain 6/6.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T12:29:22Z",
          "mergedAt": "2026-07-01T12:30:05Z",
          "additions": 51,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 202,
          "url": "https://github.com/kungfu-systems/buildchain/pull/202",
          "title": "fix(release): resume published transactions with evidence",
          "body": "## Summary\n- pass restored publish evidence and validation into the early resume gate\n- reuse restored evidence during recovery planning instead of failing before finalization\n- add regression coverage for a durable published alpha transaction with persisted evidence\n\n## Verification\n- corepack pnpm exec node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm run check\n- git diff --check\n\n## Why\nA transient GitHub API failure after image publish can leave the durable transaction in `published` with valid `evidence.json`. Fresh reruns must validate that evidence and continue to finalization instead of requiring a repair for already-published artifacts.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T12:28:52Z",
          "mergedAt": "2026-07-01T12:30:26Z",
          "additions": 113,
          "deletions": 54,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 203,
          "url": "https://github.com/kungfu-systems/buildchain/pull/203",
          "title": "Promote dev/v2/v2.0 to alpha",
          "body": "## Summary\nPromote the published-transaction evidence rerun fix to alpha.\n\n## Included\n- PR #202: restore durable evidence into the early resume gate so transient post-publish reruns can finalize instead of requiring repair.\n\n## Expected release\n- next alpha on v2.0 line\n- npm dist-tag alpha updated after Buildchain Ref Promotion\n- exact tag and durable release-state complete after version-state finalization\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T12:30:36Z",
          "mergedAt": "2026-07-01T12:32:07Z",
          "additions": 113,
          "deletions": 54,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 204,
          "url": "https://github.com/kungfu-systems/buildchain/pull/204",
          "title": "Prepare v2.0.14-alpha.4",
          "body": "Create the generated version-state commit for v2.0.14-alpha.4.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T12:33:53Z",
          "mergedAt": "2026-07-01T12:35:17Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 25,
          "url": "https://github.com/kungfu-systems/build-images/pull/25",
          "title": "ci: pin buildchain alpha 4",
          "body": "## Summary\n- pin Buildchain validate-config and promote-buildchain-ref actions to v2.0.14-alpha.4\n- keep the build-images release transaction workflow otherwise unchanged\n\n## Verification\n- corepack pnpm run check\n- git diff --check\n\n## Release evidence\n- buildchain v2.0.14-alpha.4 npm alpha is published\n- buildchain exact tag v2.0.14-alpha.4 and v2.0-alpha resolve to the completed release commit\n- durable buildchain release-state 2-0-14-alpha-4 is complete\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T12:37:44Z",
          "mergedAt": "2026-07-01T12:38:32Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 26,
          "url": "https://github.com/kungfu-systems/build-images/pull/26",
          "title": "Promote dev/v1/v1.1 to alpha",
          "body": "## Summary\nPromote the current dev line to alpha so Buildchain v2.0.14-alpha.4 can publish/finalize the next build-images alpha.\n\n## Included\n- PR #25: pin Buildchain actions to v2.0.14-alpha.4, which carries the published-transaction evidence rerun fix.\n\n## Expected result\n- Buildchain Ref Promotion publishes the next image-family alpha as public GHCR images.\n- Durable release-state reaches complete; if a transient GitHub API error recurs post-publish, rerun should resume from evidence.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T12:38:48Z",
          "mergedAt": "2026-07-01T12:39:49Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 27,
          "url": "https://github.com/kungfu-systems/build-images/pull/27",
          "title": "Prepare v1.1.1-alpha.8",
          "body": "Create the generated version-state commit for v1.1.1-alpha.8.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T12:45:02Z",
          "mergedAt": "2026-07-01T12:45:48Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 22,
          "url": "https://github.com/kungfu-systems/libnode/pull/22",
          "title": "fix: ignore buildchain publish artifacts",
          "body": "Allow Buildchain publish jobs to download GitHub artifact evidence under github-artifacts/ without tripping version-state cleanliness checks.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T13:03:03Z",
          "mergedAt": "2026-07-01T13:33:58Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 205,
          "url": "https://github.com/kungfu-systems/buildchain/pull/205",
          "title": "feat(build): add Linux container preset surface",
          "body": "## Summary\n- add digest-pinned Linux container preset support to the reusable build workflow\n- split native and Linux container build jobs while preserving artifact manifests and summaries\n- dogfood kungfu-verify in the build surface fixture\n\n## Verification\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T13:49:18Z",
          "mergedAt": "2026-07-01T13:52:49Z",
          "additions": 755,
          "deletions": 176,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 207,
          "url": "https://github.com/kungfu-systems/buildchain/pull/207",
          "title": "release: promote dev to alpha v2.0",
          "body": "## Summary\n- promote the latest dev/v2/v2.0 Buildchain changes to alpha/v2/v2.0\n- includes Linux container preset support for the reusable build surface\n\n## Verification\n- PR #205 checks passed, including Linux x64 container dogfood\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T13:53:16Z",
          "mergedAt": "2026-07-01T13:54:50Z",
          "additions": 755,
          "deletions": 176,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 208,
          "url": "https://github.com/kungfu-systems/buildchain/pull/208",
          "title": "Prepare v2.0.14-alpha.5",
          "body": "Create the generated version-state commit for v2.0.14-alpha.5.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T13:56:24Z",
          "mergedAt": "2026-07-01T13:57:53Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 209,
          "url": "https://github.com/kungfu-systems/buildchain/pull/209",
          "title": "release: promote alpha to release v2.0",
          "body": "## Summary\n- promote Buildchain v2.0 alpha to the release line\n- includes Linux container preset support for the reusable build surface\n\n## Verification\n- alpha v2.0.14-alpha.5 published and refs aligned\n- Build Surface Fixture passed with Linux x64 container\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T14:00:08Z",
          "mergedAt": "2026-07-01T14:01:53Z",
          "additions": 1755,
          "deletions": 328,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 206,
          "url": "https://github.com/kungfu-systems/buildchain/pull/206",
          "title": "feat(web-surface): add explicit static apply modes",
          "body": "## Summary\n- add explicit dry-run-default `deploy-apply` and `cleanup-apply` execution for `aws-s3-cloudfront`\n- let deploy/cleanup apply consume saved web-surface plan JSON\n- recompute and verify deploy artifact hashes before running AWS operations from saved plans\n- keep operation-level audit output and fail non-zero after writing failed apply results\n\n## Validation\n- `pnpm run check`\n- `pnpm run package`\n\n## Notes\n- No live AWS mutation was executed in this branch.\n- Live apply still requires `--dry-run false` plus scoped GitHub/AWS credentials.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T13:50:15Z",
          "mergedAt": "2026-07-01T14:03:19Z",
          "additions": 816,
          "deletions": 19,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 210,
          "url": "https://github.com/kungfu-systems/buildchain/pull/210",
          "title": "Release v2.0.14",
          "body": "Create the generated version-state commit for v2.0.14.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T14:03:18Z",
          "mergedAt": "2026-07-01T14:05:50Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 211,
          "url": "https://github.com/kungfu-systems/buildchain/pull/211",
          "title": "release: promote dev to alpha v2.0",
          "body": "## Summary\n- promote dev/v2/v2.0 to the alpha test channel after web-surface apply support landed\n- carries the explicit dry-run-default deploy/cleanup apply layer for web-surface repositories\n\n## Validation\n- source PR #206 merged into dev/v2/v2.0\n- dev branch Verify succeeded at 13c021dc472c5249abe861257579cd95841ae042\n- local `node scripts/release-line-dry-run.mjs --target-ref alpha/v2/v2.0 --sha 13c021dc472c5249abe861257579cd95841ae042` completed without mutating refs\n\n## Notes\n- alpha promotion only advances the test channel; production refs are unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-01T14:05:25Z",
          "mergedAt": "2026-07-01T14:07:13Z",
          "additions": 816,
          "deletions": 19,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 212,
          "url": "https://github.com/kungfu-systems/buildchain/pull/212",
          "title": "Prepare v2.0.15-alpha.0",
          "body": "Create the generated version-state commit for v2.0.15-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T14:09:13Z",
          "mergedAt": "2026-07-01T14:10:39Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 23,
          "url": "https://github.com/kungfu-systems/libnode/pull/23",
          "title": "release: promote libnode 22.22.3-kf.2",
          "body": "Promote libnode 22.22.3-kf.2 from alpha to release/latest through Buildchain v2 semantics.\\n\\nAlpha evidence: https://github.com/kungfu-systems/libnode/actions/runs/28521479078",
          "author": "dongkeren",
          "createdAt": "2026-07-01T14:10:33Z",
          "mergedAt": "2026-07-01T14:33:08Z",
          "additions": 38,
          "deletions": 29,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 28,
          "url": "https://github.com/kungfu-systems/build-images/pull/28",
          "title": "ci: pin buildchain 2.0.14",
          "body": "## Summary\n- pin Buildchain workflow actions to the stable v2.0.14 release tag\n\n## Validation\n- npm view @kungfu-tech/buildchain@2.0.14\n- gh api repos/kungfu-systems/buildchain/git/ref/tags/v2.0.14\n- corepack pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T14:49:05Z",
          "mergedAt": "2026-07-01T14:51:26Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 29,
          "url": "https://github.com/kungfu-systems/build-images/pull/29",
          "title": "Promote dev/v1/v1.1 to alpha",
          "body": "## Summary\n- promote the stable Buildchain v2.0.14 workflow pin to alpha/v1/v1.1\n\n## Validation\n- PR #28 checks passed\n- dev/v1/v1.1 workflows now use v2.0.14",
          "author": "dongkeren",
          "createdAt": "2026-07-01T14:51:51Z",
          "mergedAt": "2026-07-01T14:52:36Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 30,
          "url": "https://github.com/kungfu-systems/build-images/pull/30",
          "title": "Prepare v1.1.1-alpha.9",
          "body": "Create the generated version-state commit for v1.1.1-alpha.9.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T14:57:25Z",
          "mergedAt": "2026-07-01T14:58:26Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 213,
          "url": "https://github.com/kungfu-systems/buildchain/pull/213",
          "title": "fix(release): promote existing npm artifacts for release tags",
          "body": "## Summary\n- add a release-only existing npm artifact promotion path for publish transactions\n- use registry dist.integrity as release evidence when KF_NPM_RELEASE_REQUIRES_EXISTING=true\n- add dist-tag promotion without rerunning lifecycle.publish for existing npm packages\n\n## Verification\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T14:56:59Z",
          "mergedAt": "2026-07-01T14:58:29Z",
          "additions": 292,
          "deletions": 66,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 214,
          "url": "https://github.com/kungfu-systems/buildchain/pull/214",
          "title": "release: promote buildchain v2.0 alpha",
          "body": "Promote dev/v2/v2.0 into alpha/v2/v2.0 so the release existing npm artifact promotion fix can enter Buildchain v2.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T14:59:57Z",
          "mergedAt": "2026-07-01T15:01:56Z",
          "additions": 292,
          "deletions": 66,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 215,
          "url": "https://github.com/kungfu-systems/buildchain/pull/215",
          "title": "Prepare v2.0.15-alpha.1",
          "body": "Create the generated version-state commit for v2.0.15-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T15:03:43Z",
          "mergedAt": "2026-07-01T15:06:41Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 217,
          "url": "https://github.com/kungfu-systems/buildchain/pull/217",
          "title": "feat(web-surface): add release apply workflow",
          "body": "## Summary\n- add opt-in live apply jobs for reusable web-surface preview, cleanup, staging, and production paths\n- fail closed when live AWS apply is requested with placeholder deploy targets\n- document the release tag protection contract: exact tags are immutable, floating channel tags remain machine-mutable\n\n## Tests\n- pnpm install --frozen-lockfile\n- node --test tests/web-surface.test.mjs tests/build-surface.test.mjs\n- bash scripts/check-workflows.sh\n- pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T15:20:17Z",
          "mergedAt": "2026-07-01T15:22:04Z",
          "additions": 714,
          "deletions": 12,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 218,
          "url": "https://github.com/kungfu-systems/buildchain/pull/218",
          "title": "release: promote dev to alpha v2.0",
          "body": "## Summary\n- promote the latest dev/v2/v2.0 changes to alpha/v2/v2.0\n- includes web-surface release apply workflow and release tag protection documentation\n\n## Verification\n- PR #217 checks passed before merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T15:22:45Z",
          "mergedAt": "2026-07-01T15:24:19Z",
          "additions": 714,
          "deletions": 12,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 220,
          "url": "https://github.com/kungfu-systems/buildchain/pull/220",
          "title": "fix(publish): resume partial finalization safely",
          "body": "## Summary\n- allow publish transaction finalization reruns from channel merge commits that contain the recorded release material\n- accept existing exact tags at the transaction release/material SHA while completing missing floating refs\n- cover partial alpha and release finalization recovery paths\n\n## Tests\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T15:38:45Z",
          "mergedAt": "2026-07-01T15:40:36Z",
          "additions": 488,
          "deletions": 93,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 221,
          "url": "https://github.com/kungfu-systems/buildchain/pull/221",
          "title": "release: promote dev to alpha v2.0",
          "body": "## Summary\n- promote the latest dev/v2/v2.0 changes to alpha/v2/v2.0\n- includes web-surface release apply workflow and publish finalization recovery hardening\n\n## Verification\n- PR #217 checks passed before merge\n- PR #220 checks passed before merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T15:41:22Z",
          "mergedAt": "2026-07-01T15:43:02Z",
          "additions": 488,
          "deletions": 93,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 222,
          "url": "https://github.com/kungfu-systems/buildchain/pull/222",
          "title": "fix(publish): accept finalized exact tag heads",
          "body": "## Summary\n- accept existing exact tags that point at a previous finalized channel head containing the transaction release material\n- keep unrelated exact tag SHAs as hard recovery conflicts\n- extend partial finalization tests to cover exact tags on earlier merge heads\n\n## Tests\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T15:48:15Z",
          "mergedAt": "2026-07-01T15:49:56Z",
          "additions": 95,
          "deletions": 59,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 223,
          "url": "https://github.com/kungfu-systems/buildchain/pull/223",
          "title": "release: promote dev to alpha v2.0",
          "body": "## Summary\n- promote finalized exact tag recovery fix to alpha/v2/v2.0\n- carries the already-merged web-surface apply workflow and publish finalization hardening\n\n## Verification\n- PR #222 checks passed before merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T15:50:26Z",
          "mergedAt": "2026-07-01T15:51:52Z",
          "additions": 95,
          "deletions": 59,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 225,
          "url": "https://github.com/kungfu-systems/buildchain/pull/225",
          "title": "release: recover buildchain v2.0.15 promotion",
          "body": "Line-scoped recovery PR for the Buildchain v2.0.15 release promotion.\\n\\nThis carries the same alpha/v2/v2.0 release material as #224, with the package version conflict resolved to the alpha material version so Buildchain can finalize the stable release transaction.\\n\\nVerification:\\n- pnpm run check\\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T16:00:29Z",
          "mergedAt": "2026-07-01T16:02:05Z",
          "additions": 2295,
          "deletions": 139,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 216,
          "url": "https://github.com/kungfu-systems/buildchain/pull/216",
          "title": "release: promote buildchain v2.0.15",
          "body": "Promote buildchain v2.0.15 to stable.\n\nIncludes release publish transaction support for promoting existing npm artifacts by dist-tag, which libnode needs for non-bit-reproducible native tarballs.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T15:09:01Z",
          "mergedAt": "2026-07-01T16:02:07Z",
          "additions": 2295,
          "deletions": 139,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 226,
          "url": "https://github.com/kungfu-systems/buildchain/pull/226",
          "title": "fix(publish): recover release source material validation",
          "body": "Fix Buildchain release finalization recovery when exact alpha remains on the original version-state commit but floating alpha has advanced to a newer material head that the current release source contains.\\n\\nVerification:\\n- node --test tests/promote-buildchain-ref.test.mjs\\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T16:09:07Z",
          "mergedAt": "2026-07-01T16:10:55Z",
          "additions": 227,
          "deletions": 90,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 227,
          "url": "https://github.com/kungfu-systems/buildchain/pull/227",
          "title": "fix(publish): recover generated release parent validation",
          "body": "Handle the current v2.0.15 release recovery shape where the generated stable version-state commit has a release-line recovery parent that differs from floating alpha only by allowed Buildchain recovery files.\\n\\nVerification:\\n- node --test tests/promote-buildchain-ref.test.mjs\\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-01T16:14:25Z",
          "mergedAt": "2026-07-01T16:16:24Z",
          "additions": 76,
          "deletions": 54,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 228,
          "url": "https://github.com/kungfu-systems/buildchain/pull/228",
          "title": "Release v2.0.15",
          "body": "Create the generated version-state commit for v2.0.15.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T16:18:08Z",
          "mergedAt": "2026-07-01T16:19:39Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 134,
          "url": "https://github.com/kungfu-systems/kungfu/pull/134",
          "title": "feat(spec): add @kungfu-tech/spec portable fact-ledger format bundle (0.1)",
          "body": "Add framework/spec = @kungfu-tech/spec: the portable fact-ledger format bundle and the manifest contract that connects the monorepo to any consumer.\n\n- Manifest contract (schema/manifest.schema.json): domain-free format namespace, three separated version axes (spec 0.1 / package version / build provenance), six categories + three handbooks, resolvable docs_url base.\n- Walking skeleton: aggregate.js builds a real, schema-valid bundle (overview, format spec, kungfu/python/node handbooks, seeded machine categories); verify.js is the integration drift gate.\n- spec 0.1 is pre-release: not a publishable release; the format may change until 1.0.\n- CONSUMING.md documents how the docs site consumes the bundle.\n\nContent is intentionally minimal to prove the publish -> consume -> render pipeline end to end.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T16:19:10Z",
          "mergedAt": "2026-07-01T16:20:26Z",
          "additions": 1045,
          "deletions": 0,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 135,
          "url": "https://github.com/kungfu-systems/kungfu/pull/135",
          "title": "feat(core): minimal fact-ledger slice (journal spine without runtime)",
          "body": "Two standalone tools embedding the yijinjing journal spine without the trading runtime: fact_ledger_host appends a causal chain of Json events and exits; fact_ledger_export independently reopens the directory and emits stable JSONL plus a run manifest with content checksums and an explicit capture boundary. Guarded behind KUNGFU_WITH_FACT_LEDGER_SLICE (default off); node/python bindings and existing behaviour untouched.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T16:19:54Z",
          "mergedAt": "2026-07-01T16:21:28Z",
          "additions": 742,
          "deletions": 0,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 229,
          "url": "https://github.com/kungfu-systems/buildchain/pull/229",
          "title": "Prepare v2.0.16-alpha.0",
          "body": "Create the generated version-state commit for v2.0.16-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T16:21:15Z",
          "mergedAt": "2026-07-01T16:22:51Z",
          "additions": 259,
          "deletions": 100,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 230,
          "url": "https://github.com/kungfu-systems/buildchain/pull/230",
          "title": "docs: add public repository onboarding",
          "body": "## Summary\n\nAdd the public repository documentation set required for kungfu-systems repositories and align Buildchain with the Kungfu repository documentation shape.\n\n## Changes\n\n- Add AGENTS, CONTRIBUTING, SECURITY, LICENSE, LICENSE-POLICY, docs/MAP, issue config, and PR template.\n- Route README readers through the documentation map and public onboarding docs.\n- Include public documentation entrypoints in the npm package file list.\n- Extend inventory checks so the public docs surface remains required.\n\n## Verification\n\n- pnpm run check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n- git diff --check\n- public-safety scan for Atlas/private/AI-maintenance wording\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-01T16:48:16Z",
          "mergedAt": "2026-07-01T16:49:49Z",
          "additions": 605,
          "deletions": 4,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 231,
          "url": "https://github.com/kungfu-systems/buildchain/pull/231",
          "title": "fix(web-surface): upload hidden plan artifacts",
          "body": "## Summary\n\n- allow the reusable web-surface workflow to upload `.buildchain` plan files\n- preserve hidden files in uploaded static artifacts as well\n- add a workflow contract assertion for hidden artifact uploads\n\n## Validation\n\n- pnpm run check\n\n## Context\n\nsite-kungfu-tech PR #6 proved that apply jobs cannot download the plan artifact when upload-artifact ignores hidden paths.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T23:14:49Z",
          "mergedAt": "2026-07-01T23:16:16Z",
          "additions": 3,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 232,
          "url": "https://github.com/kungfu-systems/buildchain/pull/232",
          "title": "release: promote dev to alpha v2.0",
          "body": "## Summary\n\nPromote current dev/v2/v2.0 to alpha/v2/v2.0 so the reusable web-surface artifact upload fix is available through v2.0-alpha.\n\nIncluded changes since the current alpha include public docs onboarding and the web-surface hidden plan artifact fix.\n\n## Validation\n\n- dev PR #231 passed Verify and Build Surface Fixture\n- alpha branch Verify will run on this PR and after merge\n\n## Context\n\nsite-kungfu-tech PR #6 needs this alpha ref to rerun the reusable preview apply path without site-local AWS glue.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T23:16:52Z",
          "mergedAt": "2026-07-01T23:18:23Z",
          "additions": 608,
          "deletions": 4,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 233,
          "url": "https://github.com/kungfu-systems/buildchain/pull/233",
          "title": "feat(publish): add explicit npm release modes",
          "body": "## Summary\n\n- add an explicit publish contract for `publish-final-version` vs `promote-existing-version`\n- keep the normal stable npm path on Trusted Publishing with distinct final versions\n- require npm token preflight before same-version dist-tag promotion can write release-state or move tags\n- pass publish contract env into lifecycle publishing and support libnode-style final versions with `BUILDCHAIN_NPM_DIST_TAG=latest`\n\n## Verification\n\n- `node --test tests/buildchain-config.test.mjs tests/publish-transaction.test.mjs tests/promote-buildchain-ref.test.mjs`\n- `pnpm run build`\n- `pnpm run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T23:20:56Z",
          "mergedAt": "2026-07-01T23:22:37Z",
          "additions": 805,
          "deletions": 120,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 234,
          "url": "https://github.com/kungfu-systems/buildchain/pull/234",
          "title": "Promote dev/v2/v2.0 to alpha",
          "body": "## Summary\n\nPromote the Buildchain libnode trusted-release contract changes from dev to alpha.\n\n## Verification\n\n- PR #233 checks passed before merge into dev/v2/v2.0\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T23:23:17Z",
          "mergedAt": "2026-07-01T23:24:48Z",
          "additions": 805,
          "deletions": 120,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 235,
          "url": "https://github.com/kungfu-systems/buildchain/pull/235",
          "title": "Promote alpha/v2/v2.0 to release",
          "body": "## Summary\n\nPromote Buildchain v2.0 line from alpha to release after the libnode trusted-release contract changes reached alpha.\n\n## Verification\n\n- PR #233 passed checks and merged into dev/v2/v2.0\n- PR #234 passed checks and merged into alpha/v2/v2.0\n- Buildchain Ref Promotion run 28554449708 completed successfully\n- `npm view @kungfu-tech/buildchain@2.0.16 version dist-tags --json` returned E404 before release\n",
          "author": "dongkeren",
          "createdAt": "2026-07-01T23:31:54Z",
          "mergedAt": "2026-07-01T23:33:26Z",
          "additions": 1414,
          "deletions": 125,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 236,
          "url": "https://github.com/kungfu-systems/buildchain/pull/236",
          "title": "Release v2.0.16",
          "body": "Create the generated version-state commit for v2.0.16.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T23:34:48Z",
          "mergedAt": "2026-07-01T23:36:44Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 237,
          "url": "https://github.com/kungfu-systems/buildchain/pull/237",
          "title": "Prepare v2.0.17-alpha.0",
          "body": "Create the generated version-state commit for v2.0.17-alpha.0.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-01T23:41:54Z",
          "mergedAt": "2026-07-01T23:58:52Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 6,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/6",
          "title": "ci: enable reusable web-surface apply flow",
          "body": "## Summary\n\n- enable Buildchain reusable web-surface preview apply, preview cleanup, and staging apply\n- replace placeholder CloudFront distribution ids with the live preview and staging distributions\n- keep production apply disabled behind the existing explicit gate\n\n## Validation\n\n- npm run build\n- npm run check\n- Buildchain validate / preview plan / cleanup plan / staging plan with concrete CloudFront distributions\n\n## Notes\n\nThis PR is intended to prove the shared Buildchain reusable workflow can own the real preview apply path without site-local AWS glue.",
          "author": "dongkeren",
          "createdAt": "2026-07-01T23:12:38Z",
          "mergedAt": "2026-07-02T00:52:27Z",
          "additions": 12,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 31,
          "url": "https://github.com/kungfu-systems/build-images/pull/31",
          "title": "ci: pin buildchain 2.0.16",
          "body": "## Summary\n- pin Buildchain workflow actions to stable v2.0.16\n- pick up finalization recovery fixes from Buildchain PRs #220/#222/#226/#227\n\n## Validation\n- npm view @kungfu-tech/buildchain@2.0.16\n- corepack pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T01:01:22Z",
          "mergedAt": "2026-07-02T01:03:29Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 238,
          "url": "https://github.com/kungfu-systems/buildchain/pull/238",
          "title": "fix(web-surface): honor explicit root deploy prefix",
          "body": "## Summary\n- Treat an explicitly configured deploy prefix, including an empty string, as authoritative.\n- Normalize root-prefix CloudFront invalidations to `/*` instead of `//*`.\n- Add coverage for bucket-root staging deploys.\n\n## Verification\n- `pnpm run check`\n\n## Context\n`site-kungfu-tech` staging uses a dedicated domain at `https://staging.kungfu.tech/`. Without explicit root prefix support, a staging apply writes to `staging/index.html` while the domain root serves `index.html`.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T00:56:24Z",
          "mergedAt": "2026-07-02T01:04:41Z",
          "additions": 41,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 32,
          "url": "https://github.com/kungfu-systems/build-images/pull/32",
          "title": "Promote dev/v1/v1.1 to alpha",
          "body": "## Summary\n- promote the Buildchain v2.0.16 workflow pin to alpha/v1/v1.1\n\n## Validation\n- PR #31 checks passed\n- dev/v1/v1.1 workflows now use v2.0.16",
          "author": "dongkeren",
          "createdAt": "2026-07-02T01:04:03Z",
          "mergedAt": "2026-07-02T01:05:18Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 239,
          "url": "https://github.com/kungfu-systems/buildchain/pull/239",
          "title": "Promote dev/v2/v2.0 to alpha",
          "body": "## Summary\n\nPromote the Buildchain web-surface root deploy prefix fix from dev to alpha.\n\n## Verification\n\n- PR #238 checks passed before merge into dev/v2/v2.0\n- Local `pnpm run check` passed on PR #238\n- dev/v2/v2.0 Verify passed after merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T01:06:12Z",
          "mergedAt": "2026-07-02T01:07:51Z",
          "additions": 41,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 24,
          "url": "https://github.com/kungfu-systems/libnode/pull/24",
          "title": "ci: publish libnode alpha through buildchain final-version mode",
          "body": "## Summary\n- declare libnode's Buildchain publish contract as publish-final-version/trusted-publishing\n- publish platform packages before the main package and include artifact roles for Buildchain ordering\n- allow anchored libnode npm versions to use alpha prerelease form and bump to 22.22.3-kf.3-alpha.0\n\n## Validation\n- corepack pnpm verify-release\n- node --check .gyp/npm-publish-tarballs.js\n- node --check .gyp/libnode-release-verify.js\n- git diff --check\n- buildchain validate --require-version-state\n- dry-run against existing package tarballs confirmed publish-final-version does not run npm dist-tag add",
          "author": "dongkeren",
          "createdAt": "2026-07-02T00:56:44Z",
          "mergedAt": "2026-07-02T01:19:10Z",
          "additions": 47,
          "deletions": 25,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 7,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/7",
          "title": "fix: deploy staging and production at domain roots",
          "body": "## Summary\n- Declare bucket-root deploy prefixes for staging and production.\n- Keep preview prefixes unchanged.\n\n## Verification\n- `npm run check`\n- `npm run build`\n- Local Buildchain dry-run using the root-prefix fix confirms staging sync target is `s3://kungfu-tech-staging-727884401362-us-east-1` and CloudFront invalidation is `/*`.\n\n## Dependency\nRequires Buildchain PR #238 to be promoted to `v2.0-alpha`; current released Buildchain ignores empty prefixes.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T00:58:33Z",
          "mergedAt": "2026-07-02T01:22:54Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 240,
          "url": "https://github.com/kungfu-systems/buildchain/pull/240",
          "title": "fix(web-surface): preserve metadata on root deploys",
          "body": "## Summary\n- Keep `.buildchain/*` metadata when syncing a web-surface artifact to a bucket root with `--delete`.\n- Preserve existing non-root prefix behavior.\n- Extend root-prefix deploy coverage to assert the metadata exclude.\n\n## Verification\n- `pnpm run check`\n\n## Context\nAfter site-kungfu-tech PR #7, staging root deploys correctly updated `https://staging.kungfu.tech/`, but root sync deleted older `.buildchain/deployments/staging/*` records before writing the current manifest. This keeps Buildchain deployment metadata outside static artifact deletion.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T01:25:50Z",
          "mergedAt": "2026-07-02T01:39:08Z",
          "additions": 18,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 25,
          "url": "https://github.com/kungfu-systems/libnode/pull/25",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.0",
          "body": "## Summary\n- promote dev/v22/v22.22 to alpha/v22/v22.22\n- publish libnode package set version 22.22.3-kf.3-alpha.0 with npm dist-tag alpha\n- exercise Buildchain publish-final-version + trusted-publishing release path\n\n## Expected Buildchain behavior\n- build Linux x64, macOS ARM64, and Windows x64 platform packages\n- publish platform packages before @kungfu-tech/libnode\n- use npm Trusted Publishing, not npm token-backed dist-tag promotion",
          "author": "dongkeren",
          "createdAt": "2026-07-02T01:19:41Z",
          "mergedAt": "2026-07-02T01:40:34Z",
          "additions": 47,
          "deletions": 25,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 241,
          "url": "https://github.com/kungfu-systems/buildchain/pull/241",
          "title": "Promote dev/v2/v2.0 to alpha",
          "body": "## Summary\n\nPromote the Buildchain web-surface root metadata preservation fix from dev to alpha.\n\n## Verification\n\n- PR #240 checks passed before merge into dev/v2/v2.0\n- dev/v2/v2.0 Verify passed after merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T01:40:24Z",
          "mergedAt": "2026-07-02T01:42:12Z",
          "additions": 18,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 242,
          "url": "https://github.com/kungfu-systems/buildchain/pull/242",
          "title": "Promote alpha/v2/v2.0 to release",
          "body": "## Summary\n\nPromote the current Buildchain alpha line to stable release after merging PRs #240 and #241.\n\n## Expected release\n\n- v2.0.17\n\n## Verification\n\n- PR #240 checks passed and merged into dev/v2/v2.0\n- PR #241 checks passed and merged into alpha/v2/v2.0\n- Buildchain Ref Promotion updated v2.0-alpha to 0b086146e8defd47bcd62bf11a8c5e99625f6e30\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T01:49:24Z",
          "mergedAt": "2026-07-02T01:52:22Z",
          "additions": 59,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 243,
          "url": "https://github.com/kungfu-systems/buildchain/pull/243",
          "title": "Release v2.0.17",
          "body": "Create the generated version-state commit for v2.0.17.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T02:00:34Z",
          "mergedAt": "2026-07-02T02:02:24Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 244,
          "url": "https://github.com/kungfu-systems/buildchain/pull/244",
          "title": "Prepare v2.0.18-alpha.0",
          "body": "Create the generated version-state commit for v2.0.18-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T02:03:44Z",
          "mergedAt": "2026-07-02T02:05:42Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 245,
          "url": "https://github.com/kungfu-systems/buildchain/pull/245",
          "title": "Add Buildchain observability toolkit",
          "body": "## Summary\n- add @kungfu-tech/buildchain/logging JSONL event and summary SDK\n- add CLI log/mark/span/doctor/release explain/transaction inspect surfaces\n- emit lifecycle framework/user observability into artifact manifest and summary\n\n## Validation\n- pnpm run check\n- node bin/buildchain.mjs lifecycle run verify --artifact-name buildchain-dogfood --artifact-path package.json",
          "author": "dongkeren",
          "createdAt": "2026-07-02T02:33:41Z",
          "mergedAt": "2026-07-02T02:35:05Z",
          "additions": 810,
          "deletions": 35,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 246,
          "url": "https://github.com/kungfu-systems/buildchain/pull/246",
          "title": "Promote v2.1 observability toolkit to alpha",
          "body": "## Summary\nPromote Buildchain v2.1 observability toolkit from dev to alpha.\n\n## Expected Buildchain semantics\n- source: dev/v2/v2.1\n- target: alpha/v2/v2.1\n- expected exact tag: first v2.1 alpha\n- npm dist-tag: alpha through publish transaction",
          "author": "dongkeren",
          "createdAt": "2026-07-02T02:36:25Z",
          "mergedAt": "2026-07-02T02:38:23Z",
          "additions": 810,
          "deletions": 35,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 247,
          "url": "https://github.com/kungfu-systems/buildchain/pull/247",
          "title": "Prepare v2.1.0-alpha.0",
          "body": "Create the generated version-state commit for v2.1.0-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T02:41:32Z",
          "mergedAt": "2026-07-02T02:43:36Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 248,
          "url": "https://github.com/kungfu-systems/buildchain/pull/248",
          "title": "Promote v2.1 observability toolkit to release",
          "body": "## Summary\nPromote Buildchain v2.1.0 from alpha to release.\n\n## Expected Buildchain semantics\n- source: alpha/v2/v2.1\n- target: release/v2/v2.1\n- exact release tag: v2.1.0\n- floating tags: v2.1 and v2 if this is the newest production minor\n- npm dist-tag: latest through publish transaction",
          "author": "dongkeren",
          "createdAt": "2026-07-02T02:45:35Z",
          "mergedAt": "2026-07-02T02:47:14Z",
          "additions": 811,
          "deletions": 36,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 136,
          "url": "https://github.com/kungfu-systems/kungfu/pull/136",
          "title": "feat(core): extract yijinjing journal core into standalone static library",
          "body": "Extract the yijinjing journal core into a standalone static library (src/libyijinjing, target yijinjing -> libyijinjing.a): schema leaf gains PageEnd/AssembleMode, the god-header common.h sheds rx/nng into yijinjing/rx.h, typed frame dump and master-kv verification become runtime-installed seams, core sources compile once and libkungfu links the target. The fact-ledger slice now links only the core (no shared-library deps beyond libc++/libSystem) and src/libyijinjing/check-deps.sh guards the dependency direction. libkungfu + slice build green; run_slice.sh verifies end to end.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T02:44:22Z",
          "mergedAt": "2026-07-02T02:50:11Z",
          "additions": 720,
          "deletions": 460,
          "changedFiles": 54
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 249,
          "url": "https://github.com/kungfu-systems/buildchain/pull/249",
          "title": "Release v2.1.0",
          "body": "Create the generated version-state commit for v2.1.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T02:48:36Z",
          "mergedAt": "2026-07-02T02:51:21Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 250,
          "url": "https://github.com/kungfu-systems/buildchain/pull/250",
          "title": "Prepare v2.1.1-alpha.0",
          "body": "Create the generated version-state commit for v2.1.1-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T02:52:44Z",
          "mergedAt": "2026-07-02T02:54:05Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 1,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/1",
          "title": "feat(site): add libkungfu developer substrate hub",
          "body": "## Summary\n\n- add a generated static site for the libkungfu.dev developer substrate hub\n- render hub, core, and Buildchain surfaces from fixture manifests\n- switch the repository to the shared Buildchain web-surface workflow\n- update deployment docs for libkungfu.dev, core.libkungfu.dev, and buildchain.libkungfu.dev\n\n## Verification\n\n- npm run build\n- npm run check\n- node /Users/dkr/Code/kungfu-systems/buildchain/scripts/web-surface.mjs --mode validate --cwd .\n- Buildchain deploy-plan for preview, staging, and production channels\n- Playwright browser render check for the generated homepage\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T03:03:50Z",
          "mergedAt": "2026-07-02T03:07:59Z",
          "additions": 952,
          "deletions": 223,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 137,
          "url": "https://github.com/kungfu-systems/kungfu/pull/137",
          "title": "refactor(core): narrow the yijinjing namespace to the journal core",
          "body": "Move the runtime components practice, cache and index out of kungfu::yijinjing into top-level namespaces (kungfu::practice / kungfu::cache / kungfu::index) so the namespace boundary matches the physical boundary drawn by the libyijinjing extraction. References that had been resolving through the old enclosing namespace are explicitly qualified with yijinjing::, matching the existing wingchun convention. Include paths unchanged, no compatibility aliases, pure rename (83 files, symmetric replacement). libkungfu + fact-ledger slice build green; run_slice.sh verifies end to end; check-deps.sh passes.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T03:11:45Z",
          "mergedAt": "2026-07-02T03:14:10Z",
          "additions": 334,
          "deletions": 334,
          "changedFiles": 83
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 26,
          "url": "https://github.com/kungfu-systems/libnode/pull/26",
          "title": "release: finalize libnode 22.22.3-kf.3",
          "body": "## Summary\n- advance the release channel from the latest alpha source to final npm version 22.22.3-kf.3\n- keep the Node anchor at v22.22.3 and libnode revision 3\n- rely on Buildchain v2 publish-final-version + Trusted Publishing for latest publication\n\n## Validation\n- corepack pnpm verify-release\n- git diff --check\n- node --check .gyp/libnode-release-verify.js\n- node --check .gyp/npm-publish-tarballs.js\n- node /Users/dkr/Code/kungfu-systems/buildchain/bin/buildchain.mjs validate --require-version-state\n\n## Release intent\nMerging this PR into release/v22/v22.22 should publish @kungfu-tech/libnode and platform packages as 22.22.3-kf.3 with npm dist-tag latest.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T02:50:32Z",
          "mergedAt": "2026-07-02T03:29:12Z",
          "additions": 47,
          "deletions": 25,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 138,
          "url": "https://github.com/kungfu-systems/kungfu/pull/138",
          "title": "refactor(core): move nanomsg and webserver out of the yijinjing namespace",
          "body": "Second half of the namespace narrowing: nanomsg and webserver are runtime transport components, moved to kungfu::nanomsg / kungfu::webserver so the namespace boundary matches the physical core boundary. References in moved files explicitly qualified with yijinjing:: per the established convention; include paths unchanged; no aliases. The orphaned socket/ headers are deliberately left untouched (nothing includes or references them; removal is a separate decision). Pure rename, 9 files, symmetric replacement; all targets build green, run_slice.sh and check-deps.sh pass.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T03:49:10Z",
          "mergedAt": "2026-07-02T03:53:52Z",
          "additions": 33,
          "deletions": 430,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 139,
          "url": "https://github.com/kungfu-systems/kungfu/pull/139",
          "title": "docs(adr): adopt KFD-1 release versioning via ADR-0010 with welded-surface register",
          "body": "Merge docs/kfd-adoption into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T03:50:11Z",
          "mergedAt": "2026-07-02T03:57:29Z",
          "additions": 88,
          "deletions": 0,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 251,
          "url": "https://github.com/kungfu-systems/buildchain/pull/251",
          "title": "docs: adopt KFD-1 release versioning with a welded-surface register",
          "body": "Adds docs/versioning.md (welded-surface register + decision log) and a MAP row. Documentation only; no registered surface is touched (patch per KFD-1).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:04:32Z",
          "mergedAt": "2026-07-02T04:05:13Z",
          "additions": 40,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 33,
          "url": "https://github.com/kungfu-systems/build-images/pull/33",
          "title": "docs: adopt KFD-1 with welded surfaces and a decision log",
          "body": "Appends Welded Surfaces and Decision Log sections to docs/release-and-tags.md. Documentation only; no registered surface is touched (patch per KFD-1).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:06:05Z",
          "mergedAt": "2026-07-02T04:06:32Z",
          "additions": 33,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 2,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/2",
          "title": "ci(site): enable Buildchain web-surface apply",
          "body": "## Summary\n- point web-surface deploy config at the provisioned libkungfu.dev CloudFront distributions\n- enable Buildchain preview apply, preview cleanup apply, and staging apply through GitHub OIDC roles\n- keep production apply disabled\n\n## Validation\n- npm run build\n- npm run check\n- Buildchain web-surface validate\n- Buildchain preview and staging deploy-plan\n- Buildchain preview and staging deploy-apply dry-run",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:07:21Z",
          "mergedAt": "2026-07-02T04:09:16Z",
          "additions": 9,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 252,
          "url": "https://github.com/kungfu-systems/buildchain/pull/252",
          "title": "Add release passport binary distribution",
          "body": "## Summary\n- add Buildchain v2.2 release passport, artifact evidence, impact ledger, agent index, and release check contracts\n- add GitHub-hosted binary distribution workflow with self-hosted compatibility fixture\n- dogfood Buildchain observability through standalone builder API logs and workflow mark/span/log summary events\n- document v2.2 versioning semantics and release passport usage\n\n## Verification\n- pnpm run check\n- standalone SEA smoke: build, version, help, mark/log summary\n- release passport dogfood over generated binary/log assets\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:15:33Z",
          "mergedAt": "2026-07-02T04:17:18Z",
          "additions": 1705,
          "deletions": 0,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 140,
          "url": "https://github.com/kungfu-systems/kungfu/pull/140",
          "title": "feat(core): make the yijinjing core embeddable standalone",
          "body": "Makes src/libyijinjing/CMakeLists.txt self-sufficient so a third-party project can consume the journal core via add_subdirectory alone: dependency targets resolved only when no enclosing build provides them, C++20 declared at target level (std::atomic_ref carries the ADR-0001 publication protocol), vendored hana fallback, parent output/optimization variables optional. EMBEDDING.md pins the contract: source embedding of the static target is the single supported distribution form; .so/ABI stability and standalone package artifacts are deliberately not offered, with three concrete escalation criteria. Verified both ways: an external scratch project builds and re-reads a causally chained journal via add_subdirectory alone; the in-tree build (libkungfu, slice, run_slice.sh, check-deps.sh) is unchanged and green.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:20:00Z",
          "mergedAt": "2026-07-02T04:23:37Z",
          "additions": 124,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 253,
          "url": "https://github.com/kungfu-systems/buildchain/pull/253",
          "title": "Promote v2.2 release passport binary distribution to alpha",
          "body": "## Summary\nPromote Buildchain v2.2 release passport and binary distribution surface from dev to alpha.\n\n## Expected Buildchain behavior\n- create exact alpha version tag v2.2.0-alpha.0\n- move v2.2-alpha to the alpha release material\n- prepare the next dev/alpha source state for v2.2\n- publish npm alpha and trigger binary release passport assets on the exact tag\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:18:09Z",
          "mergedAt": "2026-07-02T04:26:50Z",
          "additions": 1909,
          "deletions": 10,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 254,
          "url": "https://github.com/kungfu-systems/buildchain/pull/254",
          "title": "Fix v2.2 binary distribution on Windows",
          "body": "## Summary\n- resolve Windows package manager command shims when building the standalone binary\n- add a regression test for pnpm/npx .cmd resolution\n\n## Verification\n- node --check scripts/build-standalone-binary.mjs && node --test tests/cli.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:34:42Z",
          "mergedAt": "2026-07-02T04:36:11Z",
          "additions": 23,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 27,
          "url": "https://github.com/kungfu-systems/libnode/pull/27",
          "title": "ci: declare libnode release manifest version state",
          "body": "## Summary\n- declare libnode.release.json#npmVersion as a Buildchain version-state file\n- advance the alpha package version to 22.22.3-kf.3-alpha.1 so release final can differ from alpha only by version-state files\n\n## Why\nBuildchain rejected the final release because release source differed from v22.22.0-alpha.1 in libnode.release.json, while only package.json was declared as version state.\n\n## Validation\n- corepack pnpm verify-release\n- git diff --check\n- node /Users/dkr/Code/kungfu-systems/buildchain/bin/buildchain.mjs validate --require-version-state",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:05:53Z",
          "mergedAt": "2026-07-02T04:36:51Z",
          "additions": 7,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 255,
          "url": "https://github.com/kungfu-systems/buildchain/pull/255",
          "title": "Fix alpha exact tag reuse after completed transactions",
          "body": "## Summary\n- do not reuse a completed alpha transaction's exact tag for new alpha material\n- keep partial finalization recovery intact for published/finalizing transactions\n- add regression coverage for completed transaction exact-tag reuse\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:43:28Z",
          "mergedAt": "2026-07-02T04:44:59Z",
          "additions": 186,
          "deletions": 53,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 256,
          "url": "https://github.com/kungfu-systems/buildchain/pull/256",
          "title": "Prepare v2.2.0-alpha.1",
          "body": "Create the generated version-state commit for v2.2.0-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:46:25Z",
          "mergedAt": "2026-07-02T04:47:52Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 257,
          "url": "https://github.com/kungfu-systems/buildchain/pull/257",
          "title": "Fix Windows standalone binary shell execution",
          "body": "## Summary\n- run Windows package-manager .cmd shims through shell when building standalone binaries\n- keep command resolution explicit and covered by CLI tests\n\n## Verification\n- node --check scripts/build-standalone-binary.mjs && node --test tests/cli.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:51:41Z",
          "mergedAt": "2026-07-02T04:53:20Z",
          "additions": 11,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 258,
          "url": "https://github.com/kungfu-systems/buildchain/pull/258",
          "title": "Prepare v2.2.0-alpha.2",
          "body": "Create the generated version-state commit for v2.2.0-alpha.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:54:50Z",
          "mergedAt": "2026-07-02T04:57:43Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 259,
          "url": "https://github.com/kungfu-systems/buildchain/pull/259",
          "title": "Release Buildchain v2.2.0",
          "body": "Promotes the verified v2.2 alpha line to the v2.2 release line.\\n\\nEvidence before release promotion:\\n- v2.2.0-alpha.2 exact tag and v2.2-alpha floating tag both point to 9276eb0f6fab5ca7b50af5c27cfb4a246a7d4a55.\\n- npm alpha is @kungfu-tech/buildchain@2.2.0-alpha.2.\\n- Binary Distribution run 28566553311 passed for linux-x64, darwin-arm64, and windows-x64.\\n- Release passport, checksums, binary assets, and Buildchain observability log events/summaries were uploaded to the GitHub Release.\\n\\nRelease target: v2.2.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T05:01:24Z",
          "mergedAt": "2026-07-02T05:02:57Z",
          "additions": 2126,
          "deletions": 63,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 260,
          "url": "https://github.com/kungfu-systems/buildchain/pull/260",
          "title": "Release v2.2.0",
          "body": "Create the generated version-state commit for v2.2.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T05:04:25Z",
          "mergedAt": "2026-07-02T05:06:09Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 28,
          "url": "https://github.com/kungfu-systems/libnode/pull/28",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.1",
          "body": "## Summary\n- promote the version-state manifest fix from dev to alpha\n- publish alpha package set 22.22.3-kf.3-alpha.1 as the release baseline\n\n## Why\nThe final release gate requires release source to differ from the latest alpha source only by declared version-state files. This alpha establishes libnode.release.json#npmVersion as declared version state before retrying final release.\n\n## Expected result\nMerging into alpha/v22/v22.22 should run Release - New Version and publish the package set with npm dist-tag alpha.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T04:37:14Z",
          "mergedAt": "2026-07-02T05:06:23Z",
          "additions": 7,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 261,
          "url": "https://github.com/kungfu-systems/buildchain/pull/261",
          "title": "Prepare v2.2.1-alpha.0",
          "body": "Create the generated version-state commit for v2.2.1-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T05:07:45Z",
          "mergedAt": "2026-07-02T05:10:13Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 141,
          "url": "https://github.com/kungfu-systems/kungfu/pull/141",
          "title": "refactor(core): converge on target-scoped source layout",
          "body": "Every library owns its headers: src/include splits into src/libkungfu/include and src/libwingchun/include, matching src/libyijinjing; dormant wingchun sources move out of the libkungfu tree; include propagation becomes target-scoped throughout. Validated: full build green on macOS arm64, yijinjing dependency guard passes, fact-ledger slice end-to-end green with zero extra dynamic deps, freeze staging covered. Also syncs the pnpm lockfile with the spec package's rimraf dependency.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T05:40:31Z",
          "mergedAt": "2026-07-02T05:40:37Z",
          "additions": 93,
          "deletions": 46,
          "changedFiles": 139
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 262,
          "url": "https://github.com/kungfu-systems/buildchain/pull/262",
          "title": "feat(release): publish release passport site bundle",
          "body": "## Summary\n- reposition README around Buildchain Release Passport consumption, verification, npm, toolkit, and site facts\n- add release evidence bundle generation and prevent loose binary asset collisions\n- publish generated dist/site facts inside @kungfu-tech/buildchain\n- document binary distribution, toolkit observability, product mechanism, install, and site bundle contracts\n\n## Verification\n- pnpm run check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/",
          "author": "dongkeren",
          "createdAt": "2026-07-02T05:45:14Z",
          "mergedAt": "2026-07-02T05:46:45Z",
          "additions": 1577,
          "deletions": 264,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 263,
          "url": "https://github.com/kungfu-systems/buildchain/pull/263",
          "title": "promote: dev v2.2 to alpha",
          "body": "## Summary\nPromote dev/v2/v2.2 to alpha/v2/v2.2 for the next Buildchain v2.2 alpha.\n\n## Verification\n- Source PR #262 checks passed before merge\n- Buildchain Ref Promotion will create the version-state alpha PR if required",
          "author": "dongkeren",
          "createdAt": "2026-07-02T05:47:17Z",
          "mergedAt": "2026-07-02T05:48:48Z",
          "additions": 1577,
          "deletions": 264,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 264,
          "url": "https://github.com/kungfu-systems/buildchain/pull/264",
          "title": "fix(site): keep generated facts version agnostic",
          "body": "## Summary\n- stop copying package.json version into generated dist/site facts\n- keep package version as package.json#version so version-state commits do not stale the site bundle\n\n## Verification\n- pnpm run check\n- simulated package.json version bump followed by node scripts/generate-site-bundle.mjs --check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T05:51:10Z",
          "mergedAt": "2026-07-02T05:52:40Z",
          "additions": 8,
          "deletions": 5,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 265,
          "url": "https://github.com/kungfu-systems/buildchain/pull/265",
          "title": "promote: dev v2.2 to alpha after site bundle fix",
          "body": "## Summary\nPromote the site bundle version-state fix and release passport bundle changes to alpha/v2/v2.2.\n\n## Verification\n- PR #264 checks passed\n- Buildchain Ref Promotion should prepare v2.2.1-alpha.1",
          "author": "dongkeren",
          "createdAt": "2026-07-02T05:53:00Z",
          "mergedAt": "2026-07-02T05:54:31Z",
          "additions": 8,
          "deletions": 5,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 29,
          "url": "https://github.com/kungfu-systems/libnode/pull/29",
          "title": "release: publish libnode 22.22.3-kf.3",
          "body": "## Summary\n- finalize libnode 22.22.3-kf.3 from the published alpha baseline\n- carry buildchain.toml version-state declaration for libnode.release.json so strict release tree comparison accepts both version files\n\n## Verification\n- corepack pnpm verify-release\n- git diff --check\n- node /Users/dkr/Code/kungfu-systems/buildchain/bin/buildchain.mjs validate --require-version-state",
          "author": "dongkeren",
          "createdAt": "2026-07-02T05:36:36Z",
          "mergedAt": "2026-07-02T05:55:15Z",
          "additions": 5,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 266,
          "url": "https://github.com/kungfu-systems/buildchain/pull/266",
          "title": "Prepare v2.2.1-alpha.1",
          "body": "Create the generated version-state commit for v2.2.1-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T05:55:59Z",
          "mergedAt": "2026-07-02T05:57:19Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 267,
          "url": "https://github.com/kungfu-systems/buildchain/pull/267",
          "title": "release: Buildchain v2.2.1",
          "body": "## Summary\nPromote alpha/v2/v2.2 to release/v2/v2.2 for Buildchain v2.2.1.\n\n## Evidence\n- v2.2.1-alpha.1 exact tag exists\n- npm alpha dist-tag points to 2.2.1-alpha.1\n- Binary Distribution for v2.2.1-alpha.1 passed and published release passport bundle assets\n\n## Expected\n- Buildchain Ref Promotion creates v2.2.1 release version-state PR\n- npm stable publishes 2.2.1 with latest dist-tag\n- Binary Distribution publishes v2.2.1 assets without loose raw binaries",
          "author": "dongkeren",
          "createdAt": "2026-07-02T06:01:01Z",
          "mergedAt": "2026-07-02T06:02:31Z",
          "additions": 1581,
          "deletions": 265,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 268,
          "url": "https://github.com/kungfu-systems/buildchain/pull/268",
          "title": "Release v2.2.1",
          "body": "Create the generated version-state commit for v2.2.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T06:03:54Z",
          "mergedAt": "2026-07-02T06:05:20Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 269,
          "url": "https://github.com/kungfu-systems/buildchain/pull/269",
          "title": "Prepare v2.2.2-alpha.0",
          "body": "Create the generated version-state commit for v2.2.2-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T06:06:54Z",
          "mergedAt": "2026-07-02T06:09:08Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 270,
          "url": "https://github.com/kungfu-systems/buildchain/pull/270",
          "title": "fix(release): allow anchored version material in release gate",
          "body": "## Summary\n- allow strict release tree gate to accept anchored/manual release material changes limited to declared version.files plus the configured anchor manifest\n- require a valid alpha-to-release promotion PR plus lifecycle.verify or verification-command before applying that anchored/manual exception\n- update release docs, dry-run wording, tests, and the committed promote action bundle\n\n## Verification\n- pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T06:28:42Z",
          "mergedAt": "2026-07-02T06:30:20Z",
          "additions": 261,
          "deletions": 48,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 271,
          "url": "https://github.com/kungfu-systems/buildchain/pull/271",
          "title": "release: promote v2.2 anchored release gate fix to alpha",
          "body": "## Summary\n- Promote the anchored/manual release tree gate fix from dev to alpha.\n- This should produce the next v2.2.2 alpha version-state after merge.\n\n## Verification\n- PR #270 checks passed.\n- Local pnpm run check passed on the source fix branch.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T06:31:01Z",
          "mergedAt": "2026-07-02T06:32:33Z",
          "additions": 261,
          "deletions": 48,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 272,
          "url": "https://github.com/kungfu-systems/buildchain/pull/272",
          "title": "Prepare v2.2.2-alpha.1",
          "body": "Create the generated version-state commit for v2.2.2-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T06:34:07Z",
          "mergedAt": "2026-07-02T06:35:51Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 273,
          "url": "https://github.com/kungfu-systems/buildchain/pull/273",
          "title": "release: promote anchored release gate fix to v2.2.2",
          "body": "## Summary\n- Promote the anchored/manual release tree gate fix from alpha to release.\n- Expected stable release: v2.2.2.\n\n## Verification\n- v2.2.2-alpha.1 promotion completed.\n- Binary Distribution for v2.2.2-alpha.1 completed successfully.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T06:39:25Z",
          "mergedAt": "2026-07-02T06:41:00Z",
          "additions": 262,
          "deletions": 49,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 274,
          "url": "https://github.com/kungfu-systems/buildchain/pull/274",
          "title": "Release v2.2.2",
          "body": "Create the generated version-state commit for v2.2.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T06:42:28Z",
          "mergedAt": "2026-07-02T06:43:57Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 275,
          "url": "https://github.com/kungfu-systems/buildchain/pull/275",
          "title": "Prepare v2.2.3-alpha.0",
          "body": "Create the generated version-state commit for v2.2.3-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T06:45:22Z",
          "mergedAt": "2026-07-02T06:47:21Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 276,
          "url": "https://github.com/kungfu-systems/buildchain/pull/276",
          "title": "fix(release): keep active dev branch current",
          "body": "## Summary\n\n- update release promotion so the latest minor line moves the repository default branch to its dev branch\n- refresh manual workflow defaults from v2.0 to v2.2\n- clarify that the npm package exposes importable toolkit APIs for JavaScript build code, while the CLI and binary are workflow/shell surfaces\n\n## Verification\n\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:06:51Z",
          "mergedAt": "2026-07-02T07:08:26Z",
          "additions": 230,
          "deletions": 87,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 142,
          "url": "https://github.com/kungfu-systems/kungfu/pull/142",
          "title": "refactor(core): home capability slices and gate them in verify --full",
          "body": "Capability slices get a home and a convention: framework/core/slices/<name>/ with a probe statement, sources and a one-command run script; the fact-ledger slice moves in as the first resident and its run script now asserts the zero-extra-dylib cut-proof itself. verify --full builds and runs all slices plus the yijinjing dependency-direction guard, so a core capability regression fails the repository gate instead of relying on manual scripts. Quick verify keeps its seconds-level semantics.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:12:02Z",
          "mergedAt": "2026-07-02T07:12:07Z",
          "additions": 161,
          "deletions": 22,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 278,
          "url": "https://github.com/kungfu-systems/buildchain/pull/278",
          "title": "release: promote current dev v2.2 to alpha",
          "body": "Promote the current dev/v2/v2.2 head into alpha before publishing the next stable buildchain release. This brings the active dev branch current with the anchored/manual release tree and toolkit observability updates.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:12:37Z",
          "mergedAt": "2026-07-02T07:14:28Z",
          "additions": 230,
          "deletions": 87,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 277,
          "url": "https://github.com/kungfu-systems/buildchain/pull/277",
          "title": "release: publish buildchain v2.2.3",
          "body": "Promote alpha/v2/v2.2 to release/v2/v2.2 so the stable v2 tag includes anchored/manual release tree handling needed by libnode publish gates.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:09:57Z",
          "mergedAt": "2026-07-02T07:16:11Z",
          "additions": 231,
          "deletions": 88,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 279,
          "url": "https://github.com/kungfu-systems/buildchain/pull/279",
          "title": "Prepare v2.2.3-alpha.1",
          "body": "Create the generated version-state commit for v2.2.3-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:15:59Z",
          "mergedAt": "2026-07-02T07:18:48Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 280,
          "url": "https://github.com/kungfu-systems/buildchain/pull/280",
          "title": "release: publish buildchain v2.2.3 after alpha refresh",
          "body": "Promote the refreshed alpha/v2/v2.2 line to release/v2/v2.2 after dev/v2/v2.2 was merged and v2.2.3-alpha.1 was fixed as the exact alpha material.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:20:55Z",
          "mergedAt": "2026-07-02T07:22:39Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 281,
          "url": "https://github.com/kungfu-systems/buildchain/pull/281",
          "title": "Release v2.2.3",
          "body": "Create the generated version-state commit for v2.2.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:24:10Z",
          "mergedAt": "2026-07-02T07:25:55Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 283,
          "url": "https://github.com/kungfu-systems/buildchain/pull/283",
          "title": "fix(release): allow anchored target PR version material",
          "body": "Allow anchored/manual release promotion to accept a reviewed same-repository PR merged into the target release branch when the diff from the exact alpha tag is limited to declared version-state and anchor manifest paths. This covers libnode's final release PR shape while keeping code changes after alpha rejected.\\n\\nValidation:\\n- node --test --test-name-pattern \"strict anchored release promotion accepts reviewed target PR\" tests/promote-buildchain-ref.test.mjs\\n- node --test --test-name-pattern \"strict release promotion|strict anchored release promotion|anchored manual release verifies\" tests/promote-buildchain-ref.test.mjs\\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:33:42Z",
          "mergedAt": "2026-07-02T07:35:23Z",
          "additions": 229,
          "deletions": 52,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 284,
          "url": "https://github.com/kungfu-systems/buildchain/pull/284",
          "title": "release: promote anchored target PR fix to alpha",
          "body": "Promote the anchored/manual target PR release gate fix from dev/v2/v2.2 into alpha before preparing the next stable buildchain release for libnode publishing.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:35:55Z",
          "mergedAt": "2026-07-02T07:37:36Z",
          "additions": 229,
          "deletions": 52,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 285,
          "url": "https://github.com/kungfu-systems/buildchain/pull/285",
          "title": "Prepare v2.2.4-alpha.0",
          "body": "Create the generated version-state commit for v2.2.4-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:39:07Z",
          "mergedAt": "2026-07-02T07:40:52Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 282,
          "url": "https://github.com/kungfu-systems/buildchain/pull/282",
          "title": "Prepare v2.2.4-alpha.0",
          "body": "Create the generated version-state commit for v2.2.4-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:27:22Z",
          "mergedAt": "2026-07-02T07:51:49Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 286,
          "url": "https://github.com/kungfu-systems/buildchain/pull/286",
          "title": "release: publish buildchain v2.2.4",
          "body": "Promote v2.2.4-alpha.0 to stable so libnode release publishing can use the anchored/manual target PR release gate fix.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:42:53Z",
          "mergedAt": "2026-07-02T07:53:45Z",
          "additions": 230,
          "deletions": 53,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 288,
          "url": "https://github.com/kungfu-systems/buildchain/pull/288",
          "title": "Release v2.2.4",
          "body": "Create the generated version-state commit for v2.2.4.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:55:19Z",
          "mergedAt": "2026-07-02T07:57:09Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 289,
          "url": "https://github.com/kungfu-systems/buildchain/pull/289",
          "title": "Prepare v2.2.5-alpha.0",
          "body": "Create the generated version-state commit for v2.2.5-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T07:58:47Z",
          "mergedAt": "2026-07-02T08:00:49Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 143,
          "url": "https://github.com/kungfu-systems/kungfu/pull/143",
          "title": "test(core): pin the embedding contract with a standalone consumer slice",
          "body": "The source/static embedding contract of the yijinjing core (EMBEDDING.md, adopted with the distribution-form decision) previously had no machine guard: it was validated once with a scratch project outside the repository. This adds slices/embedding — a standalone CMake project that consumes src/libyijinjing via add_subdirectory without the kungfu parent build, builds from scratch in a throwaway directory, writes a causal chain and asserts the assemble round trip. verify --full picks it up through the regular slice discovery.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:10:20Z",
          "mergedAt": "2026-07-02T08:10:25Z",
          "additions": 225,
          "deletions": 0,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 290,
          "url": "https://github.com/kungfu-systems/buildchain/pull/290",
          "title": "fix(release): key anchored transactions by package version",
          "body": "## Summary\n- key anchored/manual publish transactions by the declared package version instead of the anchor line tag\n- keep verification using the anchor release version while publish lifecycle receives the package version\n- add a libnode-shaped regression test and rebuild the promote action bundle\n\n## Verification\n- corepack pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:13:28Z",
          "mergedAt": "2026-07-02T08:15:22Z",
          "additions": 213,
          "deletions": 58,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 291,
          "url": "https://github.com/kungfu-systems/buildchain/pull/291",
          "title": "release: promote buildchain dev to alpha",
          "body": "## Summary\n- promote the current dev/v2/v2.2 line into alpha after the anchored transaction version fix\n\n## Verification\n- dev push Verify run 28575627774 succeeded\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:16:24Z",
          "mergedAt": "2026-07-02T08:18:27Z",
          "additions": 213,
          "deletions": 58,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 292,
          "url": "https://github.com/kungfu-systems/buildchain/pull/292",
          "title": "Prepare v2.2.5-alpha.1",
          "body": "Create the generated version-state commit for v2.2.5-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:20:12Z",
          "mergedAt": "2026-07-02T08:21:55Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 293,
          "url": "https://github.com/kungfu-systems/buildchain/pull/293",
          "title": "release: publish buildchain v2.2.5",
          "body": "## Summary\n- promote alpha/v2/v2.2 to release/v2/v2.2 after publishing 2.2.5-alpha.1\n- includes anchored/manual transaction identity fix for libnode\n\n## Verification\n- alpha version-state PR #292 merged\n- Buildchain Ref Promotion run 28576013639 succeeded\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:23:44Z",
          "mergedAt": "2026-07-02T08:25:20Z",
          "additions": 214,
          "deletions": 59,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 294,
          "url": "https://github.com/kungfu-systems/buildchain/pull/294",
          "title": "Release v2.2.5",
          "body": "Create the generated version-state commit for v2.2.5.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:26:48Z",
          "mergedAt": "2026-07-02T08:28:22Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 295,
          "url": "https://github.com/kungfu-systems/buildchain/pull/295",
          "title": "Prepare v2.2.6-alpha.0",
          "body": "Create the generated version-state commit for v2.2.6-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:29:47Z",
          "mergedAt": "2026-07-02T08:31:36Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 144,
          "url": "https://github.com/kungfu-systems/kungfu/pull/144",
          "title": "feat(core): prove bundle-only decoding with a schema-registry slice",
          "body": "Events carry only an opaque msg_type on the wire; this adds the schema-registry capability slice pinning the self-describing-format promise. The producer emits content-addressed .bfbs blobs plus per-run manifest schema bindings; the decoder links no generated code and no compiled type registry, decoding named typed fields through FlatBuffers runtime reflection, across two coexisting schema versions. Also stakes out the msg_type allocation ranges (docs/msg-type-ranges.md), moves the fact-ledger probe types into the slice range, and shares the sha256 helper under slices/common. All three slices plus the yijinjing dependency guard pass.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:37:40Z",
          "mergedAt": "2026-07-02T08:37:45Z",
          "additions": 521,
          "deletions": 11,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 296,
          "url": "https://github.com/kungfu-systems/buildchain/pull/296",
          "title": "fix(release): recover stale alpha transactions",
          "body": "## Summary\n- replace stale unfinished alpha publish transactions when version-state finalization is resuming the same declared version\n- keep completed transactions immutable and preserve exact-tag safety\n- cover same-version stale alpha recovery with durable state/evidence assertions\n\n## Tests\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:45:26Z",
          "mergedAt": "2026-07-02T08:47:05Z",
          "additions": 104,
          "deletions": 57,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 297,
          "url": "https://github.com/kungfu-systems/buildchain/pull/297",
          "title": "release: promote dev to alpha v2.2.6 recovery",
          "body": "## Summary\n- promote dev/v2/v2.2 to alpha/v2/v2.2 after stale alpha transaction recovery fix\n- keep the declared 2.2.6-alpha.0 version state on the alpha line\n\n## Tests\n- verified in PR #296: pnpm run check\n- this PR should let Buildchain finalization recreate the unfinished alpha transaction for v2.2.6-alpha.0",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:47:35Z",
          "mergedAt": "2026-07-02T08:49:57Z",
          "additions": 104,
          "deletions": 57,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 298,
          "url": "https://github.com/kungfu-systems/buildchain/pull/298",
          "title": "fix(release): ignore local stale transaction residue",
          "body": "## Summary\n- treat local-only release transaction files as non-authoritative cache when durable state is absent\n- replace stale local residue before publishing current alpha material\n- add coverage for self-hosted/dirty runner residue blocking alpha finalization\n\n## Tests\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:59:38Z",
          "mergedAt": "2026-07-02T09:01:50Z",
          "additions": 150,
          "deletions": 23,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 299,
          "url": "https://github.com/kungfu-systems/buildchain/pull/299",
          "title": "release: promote dev to alpha v2.2.6 transaction recovery",
          "body": "## Summary\n- promote dev/v2/v2.2 to alpha/v2/v2.2 with local-only stale transaction recovery\n- recover the unfinished v2.2.6-alpha.0 finalization without bumping to a new alpha\n\n## Tests\n- verified in PR #298: pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:02:22Z",
          "mergedAt": "2026-07-02T09:04:58Z",
          "additions": 150,
          "deletions": 23,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 300,
          "url": "https://github.com/kungfu-systems/buildchain/pull/300",
          "title": "fix(release): prefer declared alpha version state",
          "body": "## Summary\n- treat configured alpha version state as current even before its durable transaction branch exists\n- prevent older open durable alpha transactions from outranking the package-declared alpha version\n- add regression coverage for stale durable state selection\n\n## Tests\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:10:20Z",
          "mergedAt": "2026-07-02T09:12:59Z",
          "additions": 151,
          "deletions": 44,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 31,
          "url": "https://github.com/kungfu-systems/libnode/pull/31",
          "title": "ci(buildchain): add libnode build diagnostics",
          "body": "## Summary\n- add buildchain toolkit validation through the package JS API\n- capture libnode build diagnostics and timing snapshots across install, build, verify, package, and source preparation\n- pin @kungfu-tech/buildchain 2.2.5 for the diagnostics integration\n\n## Verification\n- corepack pnpm install --frozen-lockfile\n- corepack pnpm run buildchain:validate\n- node .gyp/libnode-release-verify.js\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n- node -c .gyp/buildchain-diagnostics.js\n- node -c .gyp/buildchain-validate.js\n- corepack pnpm exec prettier --check .gyp/*.js src/js/*.js\n- git diff --check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T08:43:52Z",
          "mergedAt": "2026-07-02T09:12:59Z",
          "additions": 582,
          "deletions": 33,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 301,
          "url": "https://github.com/kungfu-systems/buildchain/pull/301",
          "title": "release: promote dev to alpha v2.2.6 declared state recovery",
          "body": "Promote the declared-alpha transaction recovery fix from dev to alpha.\n\nThis includes the fix that makes a declared alpha version state outrank older resumable durable alpha transactions, so the next alpha promotion should create v2.2.6-alpha.0 instead of resuming stale v2.2.5-alpha.0 state.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:14:40Z",
          "mergedAt": "2026-07-02T09:16:12Z",
          "additions": 151,
          "deletions": 44,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 145,
          "url": "https://github.com/kungfu-systems/kungfu/pull/145",
          "title": "feat(gui): read live journal events and join a running master",
          "body": "Merge feature/v4-capability-sdk into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:20:44Z",
          "mergedAt": "2026-07-02T09:20:49Z",
          "additions": 694,
          "deletions": 133,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 34,
          "url": "https://github.com/kungfu-systems/build-images/pull/34",
          "title": "ci: follow buildchain v2 toolkit",
          "body": "## Summary\n- switch build-images Buildchain action refs from exact v2.0.16 to floating v2\n- add a Buildchain toolkit wrapper for v2 stable CLI observability\n- wrap image-family builds with Buildchain observability spans and verify the generated log\n\n## Validation\n- pnpm run check\n- git diff --check\n- shellcheck scripts/buildchain-toolkit.sh scripts/publish-image-family.sh\n- Buildchain toolkit smoke: version 2.2.5, span + verify observability-log passed",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:36:33Z",
          "mergedAt": "2026-07-02T09:37:33Z",
          "additions": 62,
          "deletions": 6,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 302,
          "url": "https://github.com/kungfu-systems/buildchain/pull/302",
          "title": "feat(web-surface): support first-class host mappings",
          "body": "## Summary\n- add named web-surface host mappings with per-channel preview/staging/production URLs\n- emit per-surface URL/binding outputs from the reusable web-surface workflow\n- support per-surface AWS deploy overrides, live concrete target checks, docs, and the libkungfu.dev-shaped fixture\n\n## Validation\n- pnpm run check\n\n## Release line\n- This is recorded as the v2.3 minor surface in docs/versioning.md.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:35:59Z",
          "mergedAt": "2026-07-02T09:37:33Z",
          "additions": 1089,
          "deletions": 260,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 35,
          "url": "https://github.com/kungfu-systems/build-images/pull/35",
          "title": "Promote dev/v1/v1.1 to alpha",
          "body": "## Summary\n- promote Buildchain v2 floating action refs and image build observability to alpha/v1/v1.1\n\n## Validation\n- PR #34 checks passed\n- dev/v1/v1.1 now uses Buildchain action refs @v2 and Buildchain toolkit observability wrapper",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:38:03Z",
          "mergedAt": "2026-07-02T09:38:56Z",
          "additions": 95,
          "deletions": 6,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 303,
          "url": "https://github.com/kungfu-systems/buildchain/pull/303",
          "title": "Prepare v2.3.0-alpha.0",
          "body": "## Summary\n- open the v2.3 minor line for the web-surface host mapping surface\n- carry the merged first-class host mapping implementation from dev/v2/v2.2\n- seed version state at 2.3.0-alpha.0 via buildchain.toml version.files\n\n## Validation\n- node bin/buildchain.mjs validate --require-version-state\n- implementation PR #302 passed pnpm run check and libnode-shaped reusable workflow checks",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:40:25Z",
          "mergedAt": "2026-07-02T09:41:58Z",
          "additions": 1394,
          "deletions": 284,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 304,
          "url": "https://github.com/kungfu-systems/buildchain/pull/304",
          "title": "Release v2.3.0",
          "body": "## Summary\n- release the v2.3 web-surface host mapping surface\n- promote the tested v2.3.0-alpha.0 alpha material to production\n\n## Evidence\n- alpha exact tag: v2.3.0-alpha.0\n- alpha promotion run: https://github.com/kungfu-systems/buildchain/actions/runs/28580737392\n- npm alpha package: @kungfu-tech/buildchain@2.3.0-alpha.0\n\n## Expected Buildchain behavior\n- create exact release tag v2.3.0\n- move floating tags v2.3 and v2 as appropriate\n- publish @kungfu-tech/buildchain@2.3.0 to npm latest\n- prepare next alpha v2.3.1-alpha.0",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:45:25Z",
          "mergedAt": "2026-07-02T09:47:00Z",
          "additions": 1394,
          "deletions": 284,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 36,
          "url": "https://github.com/kungfu-systems/build-images/pull/36",
          "title": "Prepare v1.1.1-alpha.10",
          "body": "Create the generated version-state commit for v1.1.1-alpha.10.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:46:54Z",
          "mergedAt": "2026-07-02T09:47:58Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 305,
          "url": "https://github.com/kungfu-systems/buildchain/pull/305",
          "title": "Release v2.3.0",
          "body": "Create the generated version-state commit for v2.3.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:48:35Z",
          "mergedAt": "2026-07-02T09:50:30Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 306,
          "url": "https://github.com/kungfu-systems/buildchain/pull/306",
          "title": "Prepare v2.3.1-alpha.0",
          "body": "Create the generated version-state commit for v2.3.1-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T09:51:56Z",
          "mergedAt": "2026-07-02T09:53:34Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 3,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/3",
          "title": "ci(site): adopt Buildchain v2.3 surface hosts",
          "body": "## Summary\n- declare hub/core/buildchain as first-class Buildchain web surfaces\n- switch the reusable web-surface workflow to Buildchain v2.3\n- update deploy and rollback docs for host-level preview/staging\n\n## Verification\n- npm run build\n- npm run check\n- git diff --check\n- Buildchain v2.3 web-surface validate\n- Buildchain v2.3 preview/staging deploy-plan\n- Buildchain v2.3 preview/staging deploy-apply dry-run\n",
          "author": "dongkeren",
          "createdAt": "2026-07-02T10:18:00Z",
          "mergedAt": "2026-07-02T10:23:00Z",
          "additions": 47,
          "deletions": 13,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 146,
          "url": "https://github.com/kungfu-systems/kungfu/pull/146",
          "title": "build(api): declare typescript so the type gate is self-contained",
          "body": "Merge feature/v4-default-kfx into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T10:24:09Z",
          "mergedAt": "2026-07-02T10:24:14Z",
          "additions": 2533,
          "deletions": 33345,
          "changedFiles": 209
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 147,
          "url": "https://github.com/kungfu-systems/kungfu/pull/147",
          "title": "feat(cli): promote kungfu to the canonical CLI command",
          "body": "## What\n\n- `@kungfu-tech/core` now installs both `kungfu` and `kfc` bins pointing at the same entry (`lib/kfc.js`): `kungfu` is the canonical end-user command, `kfc` stays a short alias and remains the runtime binary name.\n- Docs switch command examples to `kungfu` where they teach what to type (CLI handbook, debugging, adapters, spec overview) and keep `kfc` where they describe the runtime (architecture, design-philosophy, buildchain).\n- `concepts.md` / `known-limits.md` / `CONTRIBUTING.md` updated: the reserved `kungfu` name is now realized as the CLI facade; the richer end-user shell remains planned under the same name.\n- Welded-surface register: `kfc-cli` → `kungfu-cli` with an additive decision-log entry (pre-release, no line open, nothing removed).\n\n## Why\n\nThe `kungfu` name was reserved for the end-user CLI. Realizing it now, before any release line opens, is the only free window: after release the command name is a welded surface and a rename would be a major break. The freeze pipeline and `dist/kfc` internals are untouched — the bin map is the only mechanical change.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T11:16:39Z",
          "mergedAt": "2026-07-02T12:06:32Z",
          "additions": 46,
          "deletions": 38,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 4,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/4",
          "title": "Render Buildchain npm site facts",
          "body": "## Summary\n- replace the Buildchain surface fixture with the pinned @kungfu-tech/buildchain@2.3.0 npm package dist/site bundle\n- render package provenance, docs, CLI, workflow, release model, product mechanism, and machine artifact facts from the package\n- run npm ci from the official npm registry before the Buildchain web-surface build\n\n## Validation\n- npm ci --ignore-scripts --registry=https://registry.npmjs.org/\n- npm run build\n- npm run check\n- git diff --check\n- node node_modules/@kungfu-tech/buildchain/scripts/web-surface.mjs --mode validate --cwd .\n- preview/staging deploy-plan dry-runs",
          "author": "dongkeren",
          "createdAt": "2026-07-02T12:25:13Z",
          "mergedAt": "2026-07-02T12:26:41Z",
          "additions": 279,
          "deletions": 104,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 148,
          "url": "https://github.com/kungfu-systems/kungfu/pull/148",
          "title": "build: finish the pnpm migration for the workspace-level build chain",
          "body": "## What\n\nRunning the workspace build end to end (`./kungfu-code build` → freeze → verify → app) surfaced three yarn-era leftovers that break the root build chain under pnpm:\n\n1. **wsrun runs package scripts with yarn** — corepack rejects yarn under the pinned `packageManager`, so root `build`/`format` (the `foreach`/`format` runners) never worked post-migration. Fix: `--bin pnpm`.\n2. **patch-package cannot find pm2** — the root postinstall looked for `node_modules/pm2` at the workspace root, but pnpm nests it under `framework/api`, so every fresh install failed. Fix: move the pm2 named-pipe patch to pnpm-native `patchedDependencies` and retire patch-package (script, devDependency, and patch file format).\n3. **electron missing from `allowBuilds`** — its install script never ran, no Electron binary was fetched, and the reference GUI could not start from a fresh install.\n\nAlso records PR #147 in the versioning decision log (kungfu-cli register update).\n\n## Validation\n\nOn this branch, end to end on macOS arm64: `CI=1 ./kungfu-code build` compiles core and freezes `dist/kfc` (nuitka), `./kungfu-code verify` passes 5/5 including the runtime smoke (`kungfu --version` → 4.0.0-alpha.0, `kfc` alias likewise), pm2 patch verified applied in `framework/api/node_modules/pm2/paths.js`, and the reference GUI starts (electron-vite preview; main process loads all 20 native exports).\n\n## Known limits (out of scope, pre-existing)\n\n- `kfs craft dev` (artifact app path) still fails on webpack-era phantom deps in `framework/api/toolkit/utils.js` (`html-webpack-plugin`) — the known frontend-foundation follow-up; the sdk `build` script has the same class of issue (`webpack` undeclared).\n- `format:js` is broken workspace-wide: prettier is declared nowhere after the toolchain dependency-container retirement.\n- `prebuilt.libkungfu.cc` serves an expired certificate, so prebuilt fetch falls back to source builds (slower, not incorrect).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T12:40:16Z",
          "mergedAt": "2026-07-02T14:08:38Z",
          "additions": 16,
          "deletions": 155,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 149,
          "url": "https://github.com/kungfu-systems/kungfu/pull/149",
          "title": "fix(gui): home the packaged runtime under userData",
          "body": "Merge feature/v4-default-kfx into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T14:17:12Z",
          "mergedAt": "2026-07-02T14:17:18Z",
          "additions": 6,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 150,
          "url": "https://github.com/kungfu-systems/kungfu/pull/150",
          "title": "docs(adr): ADR-0011, first cut of the v4 capability SDK contract",
          "body": "Merge feature/v4-adr-0011-capability-sdk into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T14:27:47Z",
          "mergedAt": "2026-07-02T14:27:53Z",
          "additions": 78,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 151,
          "url": "https://github.com/kungfu-systems/kungfu/pull/151",
          "title": "feat(rewind): define the capture event schema as open-layer types",
          "body": "## What\n\nThe event contract for the `kungfu trace` capture layer, as the first Rewind component:\n\n- `framework/core/src/python/kungfu/rewind/rewind_events.fbs` — `RunBegin`/`RunEnd`, `ModelRequest`/`ModelResponse`, `ToolCall`/`ToolResult`, `RetryMarker` under `kungfu.rewind.fb`, following the longfist fb evolution discipline (tail-append only, no id reuse, no `required`).\n- **Open-layer placement, not kernel**: msg_types `30001–30099`. The capture skeleton (nanosecond timing via `gen_time`, frame-level causality via `trigger_frame_uid`) rides the existing frame header; tables add run identity, cross-layer span correlation (`span_id`/`parent_span_id`/`CaptureLayer`), payload bodies, and status/retry facts. Payloads are JSON strings — full local fidelity at capture, redaction only at export.\n- Trace bundles bind these msg_types to the schema's content-addressed `.bfbs` per run and decode by reflection alone — the exact mechanism `slices/schema-registry` pins.\n- `msg-type-ranges.md`: adds an informative first-party open-layer allocation table (binding authority stays with each run's manifest).\n- `docs/versioning.md`: registers welded surface `rewind-event-schema` (integration + cross-time; additive decision-log entry).\n\n## Why open layer\n\nRewind is a product on top of the substrate, not part of it. Welding its event types into the longfist closed set would couple the kernel registry to application churn; the open layer exists precisely for self-describing application schemas, and using it here dogfoods the schema-registry mechanism on the first real product.\n\n## Validation\n\nSchema compiles clean with the conan-provided flatc 25.9.23 (`--cpp --scoped-enums`, `-b --schema`, `--python`). Build wiring (`.bfbs` generation/packaging) intentionally lands with its consumer — the capture supervisor — in the next change.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T15:03:16Z",
          "mergedAt": "2026-07-02T15:05:53Z",
          "additions": 184,
          "deletions": 0,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 152,
          "url": "https://github.com/kungfu-systems/kungfu/pull/152",
          "title": "docs(adr): accept ADR-0011, the capability SDK is implemented and consumed",
          "body": "Merge feature/v4-sdk-reborn into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T15:12:12Z",
          "mergedAt": "2026-07-02T15:12:18Z",
          "additions": 1150,
          "deletions": 2633,
          "changedFiles": 81
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 153,
          "url": "https://github.com/kungfu-systems/kungfu/pull/153",
          "title": "feat(rewind): kungfu trace wraps a run and produces the local store",
          "body": "## What\n\nThe capture supervisor's L0 slice — the first runnable piece of Kungfu Rewind:\n\n- **`kungfu trace [--run-id] -- <command>`** (new console command): assigns a run id, injects the capture environment (`KUNGFU_REWIND_RUN_ID`) into an unmodified child process tree, brackets the run with `RunBegin`/`RunEnd` journal frames, and emits the trace bundle's format pieces — a content-addressed `.bfbs` blob plus a manifest binding every rewind msg_type to it — so the run decodes without this runtime (the mechanism `slices/schema-registry` pins).\n- **Standalone single-writer journal from python**, same shape as the C++ slices: no master, no-op publisher, private bus. One binding addition exposes `noop_publisher` to python.\n- `kungfu.rewind` grows `events.py` (FlatBuffers serializers for the 7 event tables), `bundle.py` (blob + manifest emission), `supervisor.py` (L0); `flatbuffers` (pure python) joins the console dependencies; the flatc-generated accessors are checked in next to the schema together with the `.bfbs`.\n- **Fixture** `tests/fixtures/rewind-demo-happy/`: the demo agent sees only injected environment — traced code needs no modification (the release red line, self-enforced) — and `check_capture.py` asserts the frames round-trip, all msg_types are bound, and the schema blob is content-addressed.\n\n## Validation\n\n- Fixture end to end: 11/11 assertions pass (RunBegin/RunEnd round-trip via `assemble.read_bytes` + reflection-free accessors, manifest bindings complete, blob hash verified).\n- `./kungfu-code verify`: 5/5 including the runtime smoke.\n- `ruff format` clean on all new python.\n\n## Scope\n\nModel wire capture (L1 proxy) and in-process tool hooks (L2, over the announced ingest endpoint) land next; this change is deliberately the smallest end-to-end loop.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T15:45:03Z",
          "mergedAt": "2026-07-02T15:47:11Z",
          "additions": 1450,
          "deletions": 0,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 154,
          "url": "https://github.com/kungfu-systems/kungfu/pull/154",
          "title": "feat(rewind): capture model calls at the wire",
          "body": "## What\n\nCapture layer L1 — the model-wire proxy, completing the G2 capture evidence:\n\n- The supervisor runs a local proxy (ephemeral localhost port) and points the child's model SDKs at it through the base-url environment variables (`OPENAI_BASE_URL`, `OPENAI_API_BASE`, `ANTHROPIC_BASE_URL`). No code change in the traced program — env injection only.\n- Every request forwards to the upstream the run would have used untraced (the parent environment's own base urls, falling back to provider defaults; anthropic paths route to the anthropic upstream, everything else openai-compatible). Each call lands as a `ModelRequest`/`ModelResponse` pair: provider, model, bodies as sent/received, finish reason, token usage, wire latency, span-id correlation, provenance `ModelWire`.\n- **Headers are never captured** — that is where API keys live; capture takes JSON bodies only. Redaction remains an export-time concern by design.\n- **Single-writer discipline by construction**: capture layers enqueue serialized events; one writer thread drains in arrival order. The journal writer is never touched from handler threads.\n- Fixture upgraded to a real model call: the demo agent posts a chat completion the way an SDK would, a deterministic local mock serves as upstream, and `check_capture` asserts the full round-trip — **24 assertions green**.\n\n## Validation\n\n- Fixture end to end 24/24 (run bracketing + model request/response facts + span correlation + bundle manifest/blob).\n- `ruff format` clean; python-only change, no build-chain surface touched.\n\n## Scope\n\nL2 in-process hooks (tool/framework semantics over the announced ingest endpoint) and the G3 completeness assertions land next.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T15:52:43Z",
          "mergedAt": "2026-07-02T15:56:03Z",
          "additions": 367,
          "deletions": 13,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 155,
          "url": "https://github.com/kungfu-systems/kungfu/pull/155",
          "title": "feat(rewind): capture tool semantics in-process, gate the fixtures in verify",
          "body": "## What\n\nCapture layer L2, completing the G3 (event completeness) evidence, plus the fixtures becoming a release gate:\n\n- **In-process hooks over an announced endpoint**: the supervisor starts a local ingest listener and prepends a hook directory to the child's `PYTHONPATH`; python's site machinery pulls in `sitecustomize`, which installs a meta-path finder that patches known frameworks **after** they import, at their natural seams (user-facing call + per-attempt boundary). No eager imports, no user code changes.\n- **Child-side hook is pure stdlib and best-effort by hard rule** — the traced environment owes us nothing, and a traced program must behave exactly like an untraced one (every hook operation degrades silently; a user `sitecustomize` shadowed by ours is chained through). Events travel as line-delimited JSON to the announced endpoint; the framing is swappable behind the endpoint without touching the hook protocol.\n- **Single-writer discipline holds**: ingest validates, serializes, enqueues; the one writer thread stays the only journal writer.\n- `ToolCall`/`ToolResult`/`RetryMarker` land with provenance `InProcessHook`: per-attempt calls, error detail on the failed attempt, output on the retried one, and the retry edge linking both spans.\n- **Fixture**: a stand-in tool framework (capability probe, not a product — it knows nothing about kungfu) plus a flaky tool failing once then succeeding; `check_capture` asserts **43 facts** end to end.\n- **`verify --full` gains stage 6**: every `tests/fixtures/rewind-demo-*/run.sh` is now a build-chain gate — a red fixture means the capture contract regressed (build dogfoods the product, per ADR-0009).\n\n## Validation\n\n- Fixture 43/43 green (run bracketing, model wire facts, tool per-attempt facts, retry linkage, result-to-call correlation, bundle manifest/blob).\n- `ruff format` clean (flatc-generated `fb/` deliberately left as emitted); `node --check verify.js` clean; python-only.\n\n## Known limits (recorded)\n\n- Cross-layer parent linking (tool span → wire model span) is timeline-ordered, not span-linked yet; frame-level `trigger_frame_uid` chaining and the cross-runtime fixture belong to the G7/G-Moat line.\n- Streaming (SSE) responses are captured verbatim, not parsed into usage facts.\n- Adapter table ships with the demo-toolkit entry; real framework adapters (LangChain et al.) grow in the adapter table by the same pattern.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T16:04:38Z",
          "mergedAt": "2026-07-02T16:11:10Z",
          "additions": 508,
          "deletions": 3,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 8,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/8",
          "title": "ci(infra): verify site infrastructure outputs",
          "body": "## Summary\\n- mirror the private infra output contract into infra/outputs.json\\n- verify buildchain.toml deployment targets and GitHub Actions role ARNs against the infra contract\\n- document that AWS resource lifecycle changes belong in infra-kungfu-sites\\n\\n## Verification\\n- npm run build\\n- npm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T16:42:19Z",
          "mergedAt": "2026-07-02T16:44:19Z",
          "additions": 111,
          "deletions": 1,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 5,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/5",
          "title": "ci(infra): verify site infrastructure outputs",
          "body": "## Summary\\n- mirror the private infra output contract into infra/outputs.json\\n- verify buildchain.toml deployment targets and GitHub Actions role ARNs against the infra contract\\n- document that AWS resource lifecycle changes belong in infra-kungfu-sites\\n\\n## Verification\\n- npm ci --ignore-scripts --registry=https://registry.npmjs.org/\\n- npm run build\\n- npm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-02T16:42:19Z",
          "mergedAt": "2026-07-02T16:44:19Z",
          "additions": 116,
          "deletions": 0,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 156,
          "url": "https://github.com/kungfu-systems/kungfu/pull/156",
          "title": "fix(core): arm every sqlite connection against cross-process contention",
          "body": "Merge feature/v4-config-db-lock-fix into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T17:11:05Z",
          "mergedAt": "2026-07-02T17:11:10Z",
          "additions": 94,
          "deletions": 21,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 32,
          "url": "https://github.com/kungfu-systems/libnode/pull/32",
          "title": "ci: authorize buildchain diagnostics alpha publish",
          "body": "Authorize the Buildchain diagnostics dogfood alpha source for 22.22.3-kf.3-alpha.2.\\n\\nEvidence before alpha authorization:\\n- Release - New Version run 28604378358 completed all native platform build/verify jobs.\\n- Windows x64, Linux x64, and macOS ARM64 uploaded deterministic artifacts, artifact manifests, and diagnostics artifacts.\\n- Buildchain aggregate summary and aggregate diagnostics summary jobs completed.\\n- npm publish did not run because alpha/v22/v22.22 was still locked to the previous alpha source SHA.\\n\\nThis PR targets only the alpha line; it is not a release/latest publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T16:35:23Z",
          "mergedAt": "2026-07-02T17:12:24Z",
          "additions": 36,
          "deletions": 17,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 33,
          "url": "https://github.com/kungfu-systems/libnode/pull/33",
          "title": "ci: stage Buildchain diagnostics alpha channel",
          "body": "Stages the Buildchain diagnostics dogfood changes on dev/v22/v22.22 so alpha publication can flow through the required dev -> alpha channel PR.\\n\\n- keeps publication on alpha only\\n- advances the attempted unpublished alpha.2 to 22.22.3-kf.3-alpha.3\\n- preserves Buildchain publish-gate/source-lock publication semantics\\n\\nAfter this lands on dev, the next step is a dev/v22/v22.22 -> alpha/v22/v22.22 channel PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T17:41:25Z",
          "mergedAt": "2026-07-02T18:02:18Z",
          "additions": 69,
          "deletions": 599,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 34,
          "url": "https://github.com/kungfu-systems/libnode/pull/34",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.3",
          "body": "Channel PR for alpha publication through Buildchain governance.\\n\\n- source: dev/v22/v22.22\\n- target: alpha/v22/v22.22\\n- npm version: 22.22.3-kf.3-alpha.3\\n- alpha only; no release/latest publication\\n- supersedes the unpublished alpha.2 publish-gate attempt that failed governance because it came from a feature -> alpha PR instead of dev -> alpha.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T18:02:43Z",
          "mergedAt": "2026-07-02T18:25:18Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 307,
          "url": "https://github.com/kungfu-systems/buildchain/pull/307",
          "title": "feat(diagnostics): merge toolkit diagnostics into v2.3",
          "body": "## Summary\n- port the diagnostics toolkit, workflow diagnostics artifacts, and source-lock publish gate from the validated feature branch onto current v2.3\n- keep v2.3 version state at 2.3.1-alpha.0\n\n## Validation\n- pnpm run check\n- libnode dogfood alpha: @kungfu-tech/libnode@22.22.3-kf.3-alpha.3 and platform packages published under alpha\n- libnode publish-gate validated dev -> alpha source-lock via PR #33/#34\n\n## Notes\n- This PR is the v2.3 integration branch for feature/toolkit-diagnostics-feedback.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T18:51:30Z",
          "mergedAt": "2026-07-02T18:53:14Z",
          "additions": 4379,
          "deletions": 164,
          "changedFiles": 38
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 157,
          "url": "https://github.com/kungfu-systems/kungfu/pull/157",
          "title": "feat(rewind): one causal chain across python and node in one journal",
          "body": "## What\n\nGate **G7 (cross-runtime single journal)** — the machine-checkable half of G-Moat, and the attribution load-bearing wall: without this, Rewind's success would only prove a generic local tracer.\n\n- **Node hook** (`hook/rewind_hook.js`): injected via `NODE_OPTIONS --require` (the node counterpart of sitecustomize), pure node built-ins, same hard rules as the python hook — best-effort everywhere, socket `unref()` so tracing never keeps the traced process alive, frameworks patched after require at the same natural seams via a minimal require interceptor.\n- **Cross-runtime span propagation**: the python hook maintains the active span in `KUNGFU_REWIND_PARENT_SPAN` around each tool invocation (restored after, exception-safe); child processes inherit their causal parent through the environment, and the other runtime's spans root under it. One causal chain, two runtimes, one journal.\n- **Fixture** `tests/fixtures/rewind-demo-cross-runtime/` (auto-gated by `verify --full` stage 6): python agent → model call (wire) → tool delegated to a node process (node twin of the stand-in framework). **12 assertions**, the decisive ones:\n  - cross-runtime causal edge: node ToolCall's `parent_span_id` **equals** the python delegate's `span_id`;\n  - shared `run_id` across runtimes; single nanosecond timeline ordering the boundary; results correlate to calls across runtimes; the entire chain lives in one journal location.\n- A generic baseline (per-runtime logs joined offline / OTLP viewer) cannot satisfy these facts — that is the point of the assertion design.\n\n## Validation\n\n- Cross-runtime fixture 12/12 green; happy-path fixture regression 43/43 green; `ruff format` + `node --check` clean.\n\n## Scope\n\nNext change adds the forensic-replay surface (`kungfu rewind show/verify`: native journal walk vs bundle reflection decode, consistency diff) — v1 is forensic replay; deterministic rerun stays a next-stage differentiator gate.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T23:32:03Z",
          "mergedAt": "2026-07-02T23:34:47Z",
          "additions": 528,
          "deletions": 2,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 158,
          "url": "https://github.com/kungfu-systems/kungfu/pull/158",
          "title": "docs(deps): register local modifications to vendored dependencies",
          "body": "Merge docs/v4-vendored-deps-register into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T23:36:17Z",
          "mergedAt": "2026-07-02T23:36:21Z",
          "additions": 27,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 159,
          "url": "https://github.com/kungfu-systems/kungfu/pull/159",
          "title": "feat(rewind): forensic replay — the record proves it self-describes",
          "body": "## What\n\nThe forensic-replay surface (the second half of the G-Moat machine gate):\n\n- **`kungfu rewind show --run <id>`** — reconstructs the run's causal tree from the journal alone through the native path (runtime reader + generated accessors): model spans, tool spans with their **cross-runtime nesting**, retry edges, per-span timing.\n- **`kungfu rewind verify --run <id> [--bundle <dir>]`** — re-decodes every frame a second, independent way: the bundle's manifest bindings + content-addressed `.bfbs` blob, walked through **FlatBuffers reflection with no generated event code**, then diffs the two paths fact by fact. Identical output proves the trace bundle decodes without the runtime that wrote it; schema drift, blob tampering, or binding gaps surface as concrete per-frame diffs. `reflection_fb.py` is flatc-generated from `reflection.fbs` (the schema of schemas) — checked in like the rest of the generated code.\n- **Fixture** `tests/fixtures/rewind-demo-forensic-replay/` (auto-gated by `verify --full`): records a cross-runtime run, asserts the tree renders with the node tool nested under the python delegate, asserts both decode paths agree over all frames, and asserts a **tampered schema blob makes verify fail** — the falsification that keeps the check honest.\n\nSample tree from the fixture:\n\n```\nrun fixturereplay…  command: python3 …/demo_agent.py\n  status: exit_code=0\n    - model openai/demo-model  [ok, 11.5ms]\n    - tool delegate  [ok, 38.9ms]\n      - tool node-lookup  [ok, 0.0ms]\n```\n\n## Disclosure (per the validation discipline)\n\nv1 replay scope is **forensic** — re-open, walk, verify. Deterministic re-execution is a next-stage differentiator gate by design, stated in the module header.\n\n## Validation\n\nForensic fixture green end to end (tree + verify + tamper rejection); happy-path 43/43 and cross-runtime 12/12 regressions green; `ruff format` clean; python-only.",
          "author": "dongkeren",
          "createdAt": "2026-07-02T23:43:05Z",
          "mergedAt": "2026-07-02T23:48:09Z",
          "additions": 1923,
          "deletions": 0,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 160,
          "url": "https://github.com/kungfu-systems/kungfu/pull/160",
          "title": "fix(core): route terminate diagnostics through the stackwalker",
          "body": "Merge docs/v4-vendored-deps-register into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-02T23:58:51Z",
          "mergedAt": "2026-07-02T23:58:55Z",
          "additions": 36,
          "deletions": 11,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 161,
          "url": "https://github.com/kungfu-systems/kungfu/pull/161",
          "title": "docs(core): pin down why holdon is not publish",
          "body": "Merge docs/v4-rx-holdon-semantics into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-03T00:26:11Z",
          "mergedAt": "2026-07-03T00:26:16Z",
          "additions": 11,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 162,
          "url": "https://github.com/kungfu-systems/kungfu/pull/162",
          "title": "fix(core): stop the event loop structurally on subscriber errors",
          "body": "Merge fix/v4-rx-structured-interrupt into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-03T00:55:53Z",
          "mergedAt": "2026-07-03T00:55:57Z",
          "additions": 21,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 163,
          "url": "https://github.com/kungfu-systems/kungfu/pull/163",
          "title": "fix(rewind): fixture mocks must not outlive their run",
          "body": "## What\n\nTwo harness bugs that `verify --full` stage 6 itself surfaced the first time it ran the rewind fixtures under `spawnSync` — the gate catching its own probes:\n\n1. **Disarmed cleanup trap**: ending `run.sh` with `exec` replaced the shell, so the `EXIT` trap never fired and the background mock model leaked (several multi-hour mock processes accumulated across manual runs).\n2. **Pipe-EOF deadlock**: the leaked mock inherited the captured stdout pipe; a harness waiting for pipe EOF (`spawnSync`) waited forever — stage 6 hung on a fixture that had actually passed.\n\nFix: the mock detaches from stdio at spawn (`>/dev/null 2>&1`) and the final check runs without `exec` so the trap actually fires. The reasoning is recorded as a comment at the spawn site in all three fixtures.\n\n## Validation\n\n`./kungfu-code verify --full`: **14/14 passed** — full rebuild + freeze + runtime smoke + 3 capability slices + yijinjing dependency guard + all 3 rewind fixtures green under the gated (spawnSync) environment, no leftover processes.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T01:18:28Z",
          "mergedAt": "2026-07-03T01:20:05Z",
          "additions": 20,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 308,
          "url": "https://github.com/kungfu-systems/buildchain/pull/308",
          "title": "feat(diagnostics): infer process-tree parallelism",
          "body": "## Summary\n- capture redacted process command lines in process-tree samples\n- infer requested parallelism from sampled build-tool descendants when wrapper commands hide the real build command\n- include process-tree evidence and candidates in process summaries\n\n## Validation\n- pnpm exec node --test tests/cli.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T01:36:22Z",
          "mergedAt": "2026-07-03T01:38:06Z",
          "additions": 195,
          "deletions": 30,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 164,
          "url": "https://github.com/kungfu-systems/kungfu/pull/164",
          "title": "build(artifact): revive the app assembly on the platform stack",
          "body": "## What\n\nThe frontend-foundation surgery that unblocks the GUI line — net **-752 lines**:\n\n- **artifact revived as a thin delegation layer** (its scripts still called the retired webpack-era `kfs craft` verbs, so every root app verb was dead): `dev`/`app`/`build` forward to the reference GUI's electron-vite verbs, `package`/`dist` to its electron-builder `pack`/`dist`, `cli` to the TUI. The dogfood identity stays — the runnable/packageable product surface is the reference app with its default kfx — without duplicating an app shell.\n- **The Electron binary becomes a precondition the verbs enforce**, not an install side effect: pnpm's build-script scheduling has been observed to leave `electron` without its `dist/` on fresh worktrees (package present, install script never ran, `pnpm ignored-builds` reports none — mechanism unclear, recorded as observation). `ensure-electron.mjs` no-ops in milliseconds when the binary is present and runs electron's own `install.js` in place when it is not; wired explicitly into `dev`/`start`/`pack`/`dist`.\n- **Last webpack remnants removed**: `framework/api/toolkit/` was dead wood poisoned by a top-level `html-webpack-plugin` require — its only consumer was a try/catch in core's `lib/kfc.js` that always fell back (now simplified to the byte-identical fallback behavior). `codeEditor/` inside it referenced a package that no longer exists.\n- **Root `rebuild` script renamed to `rebuild:all`**: the name shadowed pnpm's built-in `rebuild` command workspace-wide, which blocked the natural repair lever for the electron case above.\n\n## Validation\n\n- `./kungfu-code app` launches the Electron app end to end (process alive, main process loads all 20 native exports).\n- `./kungfu-code --filter @kungfu-tech/artifact-kungfu run package` produces `Kungfu.app` (darwin-arm64, electron-builder).\n- `ensure-electron` verified on both paths (present → fast no-op; missing → fetches once and validates).\n- `./kungfu-code verify` 5/5; no dangling `kfs craft` / `api/toolkit` references repo-wide.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T01:56:28Z",
          "mergedAt": "2026-07-03T02:00:40Z",
          "additions": 59,
          "deletions": 811,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 309,
          "url": "https://github.com/kungfu-systems/buildchain/pull/309",
          "title": "feat(workflows): gate buildchain runtime overrides",
          "body": "## Summary\n- keep Buildchain reusable workflow runtime refs stable by default with empty buildchain-ref inputs\n- allow trusted workflow_dispatch runs to validate train refs or exact runtime SHAs after resolving them to immutable commits\n- record runtime ref, SHA, stability class, trust decision, and rollback evidence in summaries and web-surface manifests\n\n## Validation\n- pnpm exec node --test tests/build-surface.test.mjs tests/cli.test.mjs\n- pnpm run check:workflows\n- pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T02:22:45Z",
          "mergedAt": "2026-07-03T02:24:45Z",
          "additions": 697,
          "deletions": 24,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 165,
          "url": "https://github.com/kungfu-systems/kungfu/pull/165",
          "title": "feat(core): add event-dispatch latency probe and baseline bench",
          "body": "Merge feature/event-dispatch-baseline into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-03T02:45:25Z",
          "mergedAt": "2026-07-03T02:45:30Z",
          "additions": 512,
          "deletions": 3,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 166,
          "url": "https://github.com/kungfu-systems/kungfu/pull/166",
          "title": "feat(gui): the Rewind inspector — recorded runs become a diagnosable face",
          "body": "## What\n\nRewind grows its first user-visible face — the reference app's third default kfx, carrying gates G5 (find the failing step fast) and G6 (demo carrier), and the stage for the G-Moat agent-QA half:\n\n- **Rewind inspector kfx** (three panes, house style — dark/dense/monospace):\n  - *run list*: status dot, event/error counts, start time; empty state points at `kungfu trace -- …`;\n  - *causal trace tree*: model/tool/retry spans with their **cross-runtime nesting** (the node tool renders under the python delegate), failed nodes marked ✗, per-span latency;\n  - *node detail*: status/latency/tokens/finish-reason/error facts plus pretty-printed input/output bodies — the G5 questions (which step failed, what went in, what came back) answered in two clicks.\n- **Capability SDK grows the rewind domain** beside the ADR-0011 five handles, same factory style: `openRewind → runs()/loadRun()/refresh()`, decoding open-layer events via flatc-generated TS accessors (checked in like the python side) and rebuilding **the same causal tree the CLI's forensic replay walks** — one fact model, two surfaces. `flatbuffers` (TS runtime) joins api dependencies.\n- **Native frame gains `dataBytes()`** (~5 lines): the raw-payload path for open-layer frames whose schemas live outside the compiled longfist registry (`data()`/`dataAsString()` only speak the closed set).\n\n## Validation\n\n- Headless capability smoke over a captured two-run home: run list with error counts; retry (attempt=2) and error facts present; cross-runtime child correctly nested under its python parent.\n- App boots against the same home (binding loaded, 20 exports); `tsc --noEmit` (api), `electron-vite build`, `biome check` all clean.\n\n## Scope notes\n\n- No new UI dependencies — hand-rolled compact components consistent with the existing kfx; the richer component stack (virtualized tables, flow graph, editors) grows later per the design reserve.\n- G5/G6 formal gate runs (agent-QA + full demo three-pack) are the next line; this change delivers the diagnosable surface they run on.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T02:45:46Z",
          "mergedAt": "2026-07-03T02:58:26Z",
          "additions": 1572,
          "deletions": 5,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 167,
          "url": "https://github.com/kungfu-systems/kungfu/pull/167",
          "title": "docs(adr): record the v4 freeze decision for the reactive event layer",
          "body": "Merge docs/adr0005-event-freeze into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-03T03:27:54Z",
          "mergedAt": "2026-07-03T03:27:59Z",
          "additions": 29,
          "deletions": 7,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 310,
          "url": "https://github.com/kungfu-systems/buildchain/pull/310",
          "title": "docs(workflows): document runtime train handoff",
          "body": "## Summary\n- document runtime train validation handoff\n- clarify trains are temporary fast-use and rollback channels, not pending merge targets\n- require normal dev mainline and alpha/release closeout after validation\n\n## Validation\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T03:48:05Z",
          "mergedAt": "2026-07-03T03:48:18Z",
          "additions": 174,
          "deletions": 7,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 168,
          "url": "https://github.com/kungfu-systems/kungfu/pull/168",
          "title": "fix(yijinjing): fix Windows crash stack traces — rewrite walker and ship PDBs",
          "body": "## What\n\nWindows crash reports carried no usable native stack. Two parts:\n\n1. **Rewrite the stackwalker** (`fix(yijinjing)`): the hand-rolled StackWalk64 walk, seeded from a manual STACKFRAME with DbgHelp `fInvadeProcess=FALSE` and no registered unwind tables, produced garbage frames and no symbols on x64. Replaced with the OS unwinder (`RtlCaptureStackBackTrace` for the current thread, `StackWalk64` from the exception `CONTEXT` for SEH) symbolized via `SymFromAddr` / `SymGetLineFromAddr64`. Architecture-neutral (x64 + ARM64), DbgHelp serialized behind one process-wide mutex. Collapses the file from ~2000 lines to ~350 and removes the dead vendored walker and VC5/6 compatibility code.\n\n2. **Ship PDBs** (`build(windows)`): the MSVC build emitted no debug info, so even with a correct walker kungfu frames would resolve only to `module+offset` in the field. Build with `/Z7` + `/DEBUG /OPT:REF /OPT:ICF`, copy each native's PDB into `dist/kfc` at freeze, and fail the freeze if a shipped kungfu native lacks its PDB. See `docs/windows-crash-symbols.md`.\n\n## Validation\n\nThe walker was validated with a standalone harness compiling the real `StackWalker.cpp` + `stacktrace.cpp` under VS2022: before → garbage frames / no symbols; after → fully symbolized stacks for both the SEH crash path and the capture path, including exact `file:line` at the fault site. The full in-tree Windows `.node` build is currently blocked by unrelated toolchain issues (cmake-js/Ninja resource-compiler, rocksdb MSVC mismatch), so these changes are not yet exercised end-to-end there; the freeze-time PDB check fails safe when symbols are missing.\n\n## Version impact\n\nPatch — internal bug fix plus build hardening, no public interface change.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T03:40:32Z",
          "mergedAt": "2026-07-03T03:54:36Z",
          "additions": 474,
          "deletions": 2103,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 169,
          "url": "https://github.com/kungfu-systems/kungfu/pull/169",
          "title": "docs(rewind): the onboarding page, hardened by a stranger walking it",
          "body": "## What\n\nThe Rewind onboarding surface plus the completed demo three-pack — the substance behind gates G9 (docs onboarding), G6 (demo three-pack) and the fresh-reader validation loop:\n\n- **`docs/rewind.md`** — the complete stranger path: install → capture → diagnose (CLI + app) → forensic replay → delete/privacy → demos → honest known limits. Routed from `MAP.md`.\n- **Hardened by an actual fresh walk-through**: a reader following only this page (no source access) captured a failing agent run, diagnosed it in **one command**, correctly articulated the cross-runtime causal chain of a second run, ran `verify` and interpreted it — and reported eight friction points, all fixed here: the capture command spelling that survives shell re-exec (macOS dyld quirk documented in known limits), run-id assignment stated, the show-vs-app split for input/output bodies made honest, the two on-disk directories explained, exit-code propagation and upstream discovery documented, the missing per-node runtime tag acknowledged as a schema addition on the list.\n- **Demo three-pack completed** (each 12-assertion gated, auto-run by `verify --full`):\n  - `rewind-demo-tool-failure/` — a tool failing for real: single call, errored result carrying the actual contract violation, failed run status, ✗ in the rendered tree;\n  - `rewind-demo-model-drift/` — the model picks a tool that does not exist: the drift is visible in the model node's recorded output, the consequence in the routing step right after it, ordered on the timeline.\n- **Two small product improvements the walk-through motivated**: the CLI tree renders failed nodes as `✗ error — <detail>` (was a bare status code), and the app accepts `KFE_INITIAL_VIEW` to open straight onto a chosen view (deep-linking for demos and drills).\n\n## Validation\n\n- All five fixtures green standalone (tool-failure and model-drift 12/12 each; happy 43, cross-runtime 12, forensic full regression).\n- gui lint/build clean; ruff clean; the fresh-reader walk-through itself is the G9 evidence (transcript recorded in the control-plane records).\n\n## Notes\n\nThe reader's attribution answer is worth quoting in spirit: for a single-process failure a generic per-process log diagnoses equally well — the differentiated value shows exactly where the plan said it would: the cross-runtime causal edge, the two-path `verify`, and wire capture with zero agent modification.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T03:57:43Z",
          "mergedAt": "2026-07-03T04:02:29Z",
          "additions": 685,
          "deletions": 2,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 311,
          "url": "https://github.com/kungfu-systems/buildchain/pull/311",
          "title": "feat(infra): add infra contract evidence surface",
          "body": "## Summary\n- add provider-neutral infra-contract config, CLI, plan/artifact/propagation contracts\n- add manual-observed and Terraform-shaped fixtures with fail-closed apply semantics\n- document infra-contract lifecycle and expose docs/CLI metadata in generated site bundle\n\n## Validation\n- node --check scripts/infra-contract-core.mjs scripts/infra-contract.mjs bin/buildchain.mjs scripts/init-repo.mjs\n- node --test tests/cli.test.mjs tests/infra-contract.test.mjs tests/buildchain-config.test.mjs\n- pnpm run generate:site && pnpm run check:site\n- pnpm run check\n\nTrain ref for consumer validation: train/v2/v2.4/infra-contract",
          "author": "dongkeren",
          "createdAt": "2026-07-03T04:16:42Z",
          "mergedAt": "2026-07-03T04:19:19Z",
          "additions": 1277,
          "deletions": 124,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 312,
          "url": "https://github.com/kungfu-systems/buildchain/pull/312",
          "title": "fix(infra): require saved plans for apply gates",
          "body": "## Summary\n- require `infra-contract apply` to consume a saved infra-contract plan\n- reject missing, stale, source-mismatched, or input-drifted plans before any adapter mutation can run\n- document the saved-plan apply gate and cover it from core and CLI tests\n\n## Validation\n- `node --check scripts/infra-contract-core.mjs scripts/infra-contract.mjs bin/buildchain.mjs`\n- `node --test tests/cli.test.mjs tests/infra-contract.test.mjs tests/buildchain-config.test.mjs`\n- `corepack pnpm run generate:site && corepack pnpm run check:site`\n- `corepack pnpm run check`\n\nNo package release or live infrastructure mutation is included in this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T04:45:34Z",
          "mergedAt": "2026-07-03T04:47:20Z",
          "additions": 237,
          "deletions": 8,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 170,
          "url": "https://github.com/kungfu-systems/kungfu/pull/170",
          "title": "feat(rewind): export a run as one portable file; ship the app as an installer",
          "body": "## What\n\nThe distribution face — gates **G8 (export bundle)** and **G1 (installers, macOS arm64 first)**:\n\n- **`rewind export --run <id>`** → one portable `.rewind.zip` (journal pages + the self-describing bundle, layout-preserving). **`rewind open <file>`** extracts anywhere, runs the same two-path verification as a local run before showing anything, prints the causal tree, and leaves a fully functional home behind. Offline, no services.\n- **`rewind-demo-export` fixture** proves it the hard way: capture → export → **delete the original home** → open in a fresh location → verify green + full tree (retry annotation included). Auto-discovered by `verify --full`.\n- **Installable app**: electron-builder targets grow `dmg` + `zip` (pack verb unchanged). Validated end to end: `dist` produced the dmg, it was mounted, `Kungfu.app` copied out (simulated install) and launched from the installed copy against a captured home — binding loads (20 exports), Rewind inspector renders identically to the workspace build. Unsigned pre-release; quarantine note documented. Linux/Windows + signing stay with the release pipeline (documented as the next gate).\n- **Tree-builder bug fixed in both surfaces**: a RetryMarker shares its span_id with the attempt that follows it; both the CLI and GUI tree builders opened a span for it, which the ToolCall then overwrote in place — node rendered twice, retry edge lost. Retries are now annotations on the attempt's span: `(retry #2)` in the CLI, retry-tinted label + detail facts in the app.\n- Docs: install section covers the dmg path; export/open section added; the on-disk journal path corrected to the real layout (`journal/system/rewind/<run-id>`).\n\n## Validation\n\n- All six rewind fixtures green (new export fixture: verify-after-delete + tree assertions).\n- api tsc clean, gui lint/build clean, ruff format clean.\n- dmg install → standalone launch → inspector renders: verified on darwin-arm64.\n\n## Notes\n\nInstaller size is hefty (~1.25GB dmg) — the frozen kfc runtime ships inside. Size optimization is real follow-up work but not a gate for the pre-release window.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T04:46:29Z",
          "mergedAt": "2026-07-03T04:49:01Z",
          "additions": 421,
          "deletions": 35,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 313,
          "url": "https://github.com/kungfu-systems/buildchain/pull/313",
          "title": "feat(infra): add dry-run-first contract propagation",
          "body": "## Summary\n- add `infra-contract --mode propagation-apply` as the execution layer for downstream contract PR propagation\n- keep propagation dry-run by default with machine-readable planned operations\n- require `--dry-run false`, `--approval-id`, and explicit consumer workspaces before creating branches, commits, pushes, or GitHub PRs\n\n## Validation\n- `node --check scripts/infra-contract-core.mjs scripts/infra-contract.mjs bin/buildchain.mjs`\n- `node --test tests/cli.test.mjs tests/infra-contract.test.mjs tests/buildchain-config.test.mjs`\n- `corepack pnpm run generate:site && corepack pnpm run check:site`\n- `corepack pnpm run check`\n\nNo package release, live infrastructure mutation, or real consumer PR creation is included in this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T04:54:51Z",
          "mergedAt": "2026-07-03T04:56:28Z",
          "additions": 371,
          "deletions": 6,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 314,
          "url": "https://github.com/kungfu-systems/buildchain/pull/314",
          "title": "feat(infra): capture custom command adapter evidence",
          "body": "## Summary\n- record custom-command validate/plan/observe hooks as adapter evidence by default without executing them\n- support explicit `--execute-adapter-commands true` for non-mutating validate/plan/observe evidence capture\n- fail closed when adapter evidence commands fail and preserve JSON stdout as machine-readable evidence\n\n## Validation\n- `node --check scripts/infra-contract-core.mjs scripts/infra-contract.mjs bin/buildchain.mjs`\n- `node --test tests/cli.test.mjs tests/infra-contract.test.mjs tests/buildchain-config.test.mjs`\n- `corepack pnpm run generate:site && corepack pnpm run check:site`\n- `corepack pnpm run check`\n\nNo package release, live infrastructure mutation, or real consumer PR creation is included in this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T05:04:36Z",
          "mergedAt": "2026-07-03T05:06:27Z",
          "additions": 273,
          "deletions": 3,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 315,
          "url": "https://github.com/kungfu-systems/buildchain/pull/315",
          "title": "feat(infra): execute approved custom command apply",
          "body": "## Summary\n- add an input hash to infra-contract plans so apply freshness checks ignore dynamic adapter evidence while still detecting desired/contract/consumer drift\n- execute custom-command apply hooks only after saved plan freshness, approval id, `--dry-run false`, and `--execute-adapter-commands true`\n- keep non-custom infrastructure adapters fail-closed before mutation execution\n\n## Validation\n- `node --check scripts/infra-contract-core.mjs scripts/infra-contract.mjs bin/buildchain.mjs`\n- `node --test tests/infra-contract.test.mjs tests/cli.test.mjs tests/buildchain-config.test.mjs`\n- `corepack pnpm run generate:site && corepack pnpm run check:site`\n- `corepack pnpm run check`\n\nNo package release, live cloud/IaC mutation, or real consumer PR creation is included in this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T05:16:48Z",
          "mergedAt": "2026-07-03T05:18:27Z",
          "additions": 303,
          "deletions": 14,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 316,
          "url": "https://github.com/kungfu-systems/buildchain/pull/316",
          "title": "test(infra): add static provider contract fixtures",
          "body": "## Summary\n- add static aws-cloudformation and pulumi infra-contract fixtures with desired and observed output shapes\n- cover both fixtures through validate, plan, contract, and propagation-plan tests without provider credentials or live calls\n- document the safe provider fixture set for infra-contract adapters\n\n## Validation\n- `node --test tests/infra-contract.test.mjs tests/buildchain-config.test.mjs`\n- `corepack pnpm run generate:site && corepack pnpm run check:site && corepack pnpm run check`\n\nNo package release, live cloud/IaC mutation, or real consumer PR creation is included in this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T05:25:37Z",
          "mergedAt": "2026-07-03T05:27:14Z",
          "additions": 161,
          "deletions": 0,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 317,
          "url": "https://github.com/kungfu-systems/buildchain/pull/317",
          "title": "feat(infra): bundle infra contract lifecycle evidence",
          "body": "## Summary\n- add an infra-contract evidence-bundle contract that binds desired, plan, approval, apply, observe, contract, and propagation evidence to a verified artifact hash\n- expose buildchain infra-contract --mode evidence-bundle with apply/propgation result inputs\n- document the lifecycle bundle and cover artifact/apply/propagation mismatch failures\n\n## Tests\n- node --check scripts/infra-contract-core.mjs && node --check scripts/infra-contract.mjs && node --check bin/buildchain.mjs\n- node --test tests/infra-contract.test.mjs tests/cli.test.mjs tests/buildchain-config.test.mjs\n- corepack pnpm run generate:site\n- corepack pnpm run check:site\n- corepack pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T05:38:48Z",
          "mergedAt": "2026-07-03T05:40:30Z",
          "additions": 341,
          "deletions": 0,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 318,
          "url": "https://github.com/kungfu-systems/buildchain/pull/318",
          "title": "feat(infra): plan provider adapter commands",
          "body": "## Summary\n- record planned command evidence for built-in infra adapters across validate/plan/apply/observe stages\n- keep built-in provider commands planned-only until concrete executors exist; only custom-command hooks execute through the existing explicit switch\n- update infra-contract docs and site CLI registry\n\n## Tests\n- node --check scripts/infra-contract-core.mjs && node --check scripts/infra-contract.mjs && node --check scripts/generate-site-bundle.mjs && node --check bin/buildchain.mjs\n- node --test tests/infra-contract.test.mjs tests/cli.test.mjs tests/buildchain-config.test.mjs\n- corepack pnpm run generate:site && corepack pnpm run check:site\n- corepack pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T05:51:30Z",
          "mergedAt": "2026-07-03T05:53:04Z",
          "additions": 116,
          "deletions": 18,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 319,
          "url": "https://github.com/kungfu-systems/buildchain/pull/319",
          "title": "feat(infra): execute configured provider commands",
          "body": "## Summary\n- allow `[infra.commands]` hooks to execute for any infra adapter, not just `custom-command`\n- keep built-in provider command templates planned-only unless a repository declares concrete commands\n- preserve apply gates: saved fresh plan, approval id, `--dry-run false`, and `--execute-adapter-commands true`\n\n## Validation\n- `node --check scripts/infra-contract-core.mjs && node --check scripts/infra-contract.mjs && node --check scripts/generate-site-bundle.mjs && node --check bin/buildchain.mjs`\n- `node --test tests/infra-contract.test.mjs tests/cli.test.mjs tests/buildchain-config.test.mjs`\n- `corepack pnpm run generate:site`\n- `corepack pnpm run check:site`\n- `corepack pnpm run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T06:04:33Z",
          "mergedAt": "2026-07-03T06:06:13Z",
          "additions": 141,
          "deletions": 27,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 320,
          "url": "https://github.com/kungfu-systems/buildchain/pull/320",
          "title": "feat(infra): verify lifecycle evidence bundles",
          "body": "## Summary\n- add `buildchain verify infra-contract-evidence-bundle <file>` as a read-only fail-closed verifier\n- verify bundle hash, contract artifact hash, lifecycle stage presence, and desired/plan/approval/observe/propagation bindings\n- document the verifier and add it to the generated CLI registry\n\n## Validation\n- `node --check scripts/infra-contract-core.mjs && node --check scripts/infra-contract.mjs && node --check scripts/generate-site-bundle.mjs && node --check bin/buildchain.mjs`\n- `node --test tests/infra-contract.test.mjs tests/cli.test.mjs tests/buildchain-config.test.mjs`\n- `corepack pnpm run generate:site && corepack pnpm run check:site`\n- `corepack pnpm run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T06:19:59Z",
          "mergedAt": "2026-07-03T06:21:47Z",
          "additions": 252,
          "deletions": 0,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 171,
          "url": "https://github.com/kungfu-systems/kungfu/pull/171",
          "title": "fix(yijinjing): make POSIX crash dump async-signal-safe",
          "body": "## Summary\n\nThe crash signal handler produced its stack dump using calls that are not\nasync-signal-safe: `std::ofstream`, `localtime`/`strftime`, spdlog logging, and\nmalloc-backed `backtrace_symbols`/`__cxa_demangle`. When a fatal signal is\nraised after heap corruption — precisely the case where a stack trace matters\nmost — those calls could deadlock or double-fault, so no report was written.\nThis rewrites the POSIX crash dump path to use only async-signal-safe\nprimitives.\n\n## Related issue\n\nN/A\n\n## Changes\n\n- Rewrite the POSIX `print_stack_trace()` to use only async-signal-safe building\n  blocks: preallocated buffers, `open`/`write`, hand-rolled integer formatting,\n  and `backtrace_symbols_fd` (which does not allocate).\n- Symbol names are intentionally left mangled to avoid `__cxa_demangle` (which\n  allocates and is not async-signal-safe); demangle offline with `c++filt`.\n- Add `prepare_stack_trace()`, called once when handlers are installed, to force\n  the lazy dynamic-linker resolution behind `backtrace()` out of the handler.\n- Drop the `KF_LOG_*` (spdlog) calls on the fatal signal branches so logging can\n  no longer allocate or block before the dump is written.\n- The POSIX `print_stack_trace` signature gains an optional `int signum`\n  (defaulted), source-compatible with all existing callers.\n\nBehavior note: `print_stack_trace()` is also used by non-signal catch blocks\n(`rx.h` and the node bindings). Those now also emit mangled names and use a\n`hs_err_pid<pid>_<epoch>.log` filename. Reliability improves; symbol\ndemangling moves offline to `c++filt`.\n\nWindows is intentionally out of scope for this PR; the SEH / dbghelp path is\ntracked separately.\n\n## Verification\n\n- The rewritten POSIX routine compiles cleanly under\n  `clang++ -std=c++17 -Wall -Wextra` with no warnings.\n- A standalone harness reproducing the primitives produces a complete stack\n  trace for a plain SIGSEGV, an `abort()`, and — critically — a SIGSEGV raised\n  after deliberate heap corruption. A control that mimics the previous\n  malloc/stdio approach writes no report at all under the same heap corruption.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (behavior note above)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T05:30:15Z",
          "mergedAt": "2026-07-03T06:34:54Z",
          "additions": 128,
          "deletions": 132,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 321,
          "url": "https://github.com/kungfu-systems/buildchain/pull/321",
          "title": "fix(infra): verify evidence bundle validation summary",
          "body": "## Summary\n- Recompute infra-contract evidence bundle validation summary booleans during verification\n- Fail closed when validation summary fields are stale or misleading, even if bundleHash was refreshed\n- Document the stronger verifier contract and refresh the site CLI registry\n\n## Verification\n- node --check scripts/infra-contract-core.mjs scripts/infra-contract.mjs scripts/generate-site-bundle.mjs bin/buildchain.mjs\n- node --test tests/infra-contract.test.mjs tests/cli.test.mjs tests/buildchain-config.test.mjs\n- corepack pnpm run generate:site && corepack pnpm run check:site\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T06:33:29Z",
          "mergedAt": "2026-07-03T06:34:58Z",
          "additions": 125,
          "deletions": 6,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 172,
          "url": "https://github.com/kungfu-systems/kungfu/pull/172",
          "title": "feat(gui): the work dashboard becomes the first screen",
          "body": "Merge feature/default-profile-work-dashboard into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-03T06:35:51Z",
          "mergedAt": "2026-07-03T06:43:11Z",
          "additions": 2802,
          "deletions": 13,
          "changedFiles": 40
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 322,
          "url": "https://github.com/kungfu-systems/buildchain/pull/322",
          "title": "feat(infra): add mutation-free ci evidence mode",
          "body": "## Summary\n- Add `buildchain infra-contract --mode ci` as a single mutation-free evidence-chain entrypoint\n- Make `init --type infra-contract` wire lifecycle.verify to the CI mode and upload specific infra-contract JSON artifacts\n- Document the standard CI evidence chain and refresh the site CLI registry\n\n## Verification\n- node --check scripts/infra-contract.mjs scripts/infra-contract-core.mjs scripts/init-repo.mjs scripts/generate-site-bundle.mjs bin/buildchain.mjs\n- node --test tests/infra-contract.test.mjs tests/cli.test.mjs tests/buildchain-config.test.mjs\n- corepack pnpm run generate:site && corepack pnpm run check:site\n- corepack pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T06:45:38Z",
          "mergedAt": "2026-07-03T06:48:35Z",
          "additions": 189,
          "deletions": 10,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 323,
          "url": "https://github.com/kungfu-systems/buildchain/pull/323",
          "title": "docs(release): record infra contract v2.4 surface",
          "body": "## Summary\n- Record infra-contract lifecycle as the Buildchain v2.4 minor surface in docs/versioning.md\n- Align the release decision log with the already-merged infra-contract CLI, project type, evidence, propagation, and CI mode surfaces\n\n## Verification\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T06:56:45Z",
          "mergedAt": "2026-07-03T06:58:22Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 324,
          "url": "https://github.com/kungfu-systems/buildchain/pull/324",
          "title": "Release passport evidence for v2.3.1",
          "body": "## Summary\n- add the unified release passport evidence chain\n- generate and persist buildchain-release-passport from publish transactions\n- preserve caller-provided passport product.name instead of hardcoding Buildchain\n\n## Validation\n- node --test tests/release-passport.test.mjs tests/cli.test.mjs tests/promote-buildchain-ref.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:00:10Z",
          "mergedAt": "2026-07-03T07:02:28Z",
          "additions": 1693,
          "deletions": 98,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 325,
          "url": "https://github.com/kungfu-systems/buildchain/pull/325",
          "title": "Release passport evidence for v2.4",
          "body": "## Summary\n- add the unified release passport evidence chain on the v2.4 line\n- generate and persist buildchain-release-passport from publish transactions\n- preserve caller-provided passport product.name instead of hardcoding Buildchain\n\n## Validation\n- node --test tests/release-passport.test.mjs tests/cli.test.mjs tests/promote-buildchain-ref.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:00:36Z",
          "mergedAt": "2026-07-03T07:02:33Z",
          "additions": 1693,
          "deletions": 98,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 326,
          "url": "https://github.com/kungfu-systems/buildchain/pull/326",
          "title": "Promote v2.3 passport changes to alpha",
          "body": "## Summary\n- promote the v2.3 release passport and publish transaction passport changes to alpha\n- includes product.name propagation fix for release passports\n\n## Source\n- dev/v2/v2.3 @ a8d0c6282797d56a52e4aebb7afc870fdd5f42bb\n\n## Validation\n- branch PR checks will run Verify and Build Surface Fixture",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:03:05Z",
          "mergedAt": "2026-07-03T07:04:49Z",
          "additions": 7044,
          "deletions": 229,
          "changedFiles": 55
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 327,
          "url": "https://github.com/kungfu-systems/buildchain/pull/327",
          "title": "test(infra): cover remaining infra contract adapters",
          "body": "## Summary\n- add static infra-contract fixtures for OpenTofu, AWS CDK, and AWS CLI shapes\n- extend provider fixture coverage to assert built-in command plans and observe evidence\n- update infra-contract docs so the safe fixture set matches supported built-in adapters\n\n## Validation\n- node --test tests/infra-contract.test.mjs tests/buildchain-config.test.mjs tests/cli.test.mjs\n- pnpm run check\n\nTrain note: this PR targets dev/v2/v2.4; train/v2/v2.4/infra-contract remains a validation pointer and should be resynced after merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:14:12Z",
          "mergedAt": "2026-07-03T07:16:04Z",
          "additions": 211,
          "deletions": 4,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 328,
          "url": "https://github.com/kungfu-systems/buildchain/pull/328",
          "title": "fix(release): retry transient GitHub commit reads",
          "body": "## Summary\n- retry transient GitHub Git Data API getCommit failures in promotion\n- cover runner-style 500 other side closed reads in promote action tests\n- rebuild the committed promote action bundle\n\n## Verification\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:15:37Z",
          "mergedAt": "2026-07-03T07:17:46Z",
          "additions": 111,
          "deletions": 86,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 329,
          "url": "https://github.com/kungfu-systems/buildchain/pull/329",
          "title": "fix(release): retry transient GitHub commit reads",
          "body": "## Summary\n- retry transient GitHub Git Data API getCommit failures in promotion\n- carry the v2.3 release retry fix into the v2.4 development line\n- rebuild the committed promote action bundle\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs tests/release-passport.test.mjs tests/cli.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:19:24Z",
          "mergedAt": "2026-07-03T07:21:07Z",
          "additions": 109,
          "deletions": 84,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 330,
          "url": "https://github.com/kungfu-systems/buildchain/pull/330",
          "title": "release(v2.3): promote retry-capable 2.3 alpha",
          "body": "## Summary\n- promote the v2.3 release passport changes plus the promotion getCommit retry fix to alpha\n- re-run the protected alpha promotion after the previous runner-side GitHub API 500 failure\n\n## Verification\n- dev/v2/v2.3 PR checks passed in #324 and #328\n- promotion will run from the protected Verify workflow path after merge",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:21:33Z",
          "mergedAt": "2026-07-03T07:23:17Z",
          "additions": 111,
          "deletions": 86,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 173,
          "url": "https://github.com/kungfu-systems/kungfu/pull/173",
          "title": "test(atlas): import fixture proves the read-only projection end to end",
          "body": "Merge feature/atlas-import-projection into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:25:20Z",
          "mergedAt": "2026-07-03T07:25:25Z",
          "additions": 1917,
          "deletions": 3,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 331,
          "url": "https://github.com/kungfu-systems/buildchain/pull/331",
          "title": "Prepare v2.3.1-alpha.1",
          "body": "Create the generated version-state commit for v2.3.1-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:25:17Z",
          "mergedAt": "2026-07-03T07:27:00Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 174,
          "url": "https://github.com/kungfu-systems/kungfu/pull/174",
          "title": "fix(yijinjing): harden Windows crash dump against handler deadlock",
          "body": "## Summary\n\nHarden the Windows crash-dump path so it can no longer deadlock or double-fault\ninside the crash handler. This is the Windows follow-up to the POSIX\nasync-signal-safe rewrite (#171) and the stackwalker rewrite (#168), whose scope\nnote explicitly deferred crash-handler safety.\n\n`print_stack_trace` is reached from `hero.cpp`'s SEH `__except` filter, the CRT\nsignal handler, and ~30 non-fatal `catch` blocks in the node bindings / `rx.h`.\nIt previously used `KF_LOG_CRITICAL` (spdlog), `std::ofstream`, `std::localtime`\nand heap `std::string` building. The faulting thread may already hold the spdlog\nor CRT lock, so the dump could hang or re-fault — precisely in the\nheap-corruption access-violation case where the stack is most needed.\n\n## Changes\n\n- `stacktrace.cpp` (Windows): rewrite the dump to avoid the lock-taking calls —\n  preallocated path buffer, `GetLocalTime` + hand-rolled integer formatting,\n  `CreateFileA`/`WriteFile` through a small `std::streambuf` instead of\n  `std::ofstream`, and a statically-allocated SEH exception-code description.\n  Add a Windows `prepare_stack_trace()` that warms up DbgHelp once at\n  handler-install time so the crash path only does symbol lookups.\n- `signal.cpp`: drop `KF_LOG_CRITICAL` from the fatal signal branch and install\n  `SetUnhandledExceptionFilter` as a process-wide backstop for crashes raised\n  outside `hero::produce`'s SEH frame (real `EXCEPTION_POINTERS`, unlike the\n  contextless CRT signal path).\n- `StackWalker.cpp`: remove the per-frame `std::ostringstream` and the\n  `KF_LOG_CRITICAL` echo from the native-stack loop; emit the native stack first\n  in the report so a heap-corruption-truncated dump still contains it.\n\nReport format changes; module + symbol + line are preserved. DbgHelp's own heap\nuse and `std::ostream` locale facets remain (documented residual); out-of-process\n/ minidump capture is future work.\n\n## Validation\n\nStandalone MSVC harness (VS 2026 / MSVC 19.51) compiling the real\n`stacktrace.cpp` + `StackWalker.cpp`, mirroring the handler install, triggering\neach scenario in its own process (20s watchdog):\n\n| scenario | via SEUF | via SEH `__except` |\n| --- | --- | --- |\n| access violation | full symbolized stack (module+symbol+line) | full symbolized stack |\n| heap corruption then AV | no hang; stack captured (module+offset), degrades under corruption | no hang; degrades under corruption |\n| stack overflow | no hang; system info captured, native frames limited by exhaustion | no hang |\n| non-fatal `catch` path | full symbolized stack, returns normally | — |\n\nNo scenario hung or double-faulted (the previous spdlog path would deadlock on\nthe held lock under heap corruption). Stack overflow defeating the native walk\nis a known limitation, documented in the code.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:29:16Z",
          "mergedAt": "2026-07-03T07:30:46Z",
          "additions": 240,
          "deletions": 92,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 332,
          "url": "https://github.com/kungfu-systems/buildchain/pull/332",
          "title": "release(v2.3): publish 2.3.1",
          "body": "## Summary\n- promote v2.3.1-alpha.1 from alpha to stable release\n- publish the unified release passport / publish transaction passport release material\n- include the promotion getCommit retry fix used to complete alpha finalization\n\n## Verification\n- alpha promotion completed successfully at e9ab3a5\n- v2.3.1-alpha.1 and v2.3-alpha point at e9ab3a5\n- protected release promotion will run after this PR merges",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:29:46Z",
          "mergedAt": "2026-07-03T07:31:28Z",
          "additions": 7103,
          "deletions": 263,
          "changedFiles": 55
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 333,
          "url": "https://github.com/kungfu-systems/buildchain/pull/333",
          "title": "Release v2.3.1",
          "body": "Create the generated version-state commit for v2.3.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:33:37Z",
          "mergedAt": "2026-07-03T07:35:14Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 334,
          "url": "https://github.com/kungfu-systems/buildchain/pull/334",
          "title": "Prepare v2.3.2-alpha.0",
          "body": "Create the generated version-state commit for v2.3.2-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:37:23Z",
          "mergedAt": "2026-07-03T07:39:32Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 335,
          "url": "https://github.com/kungfu-systems/buildchain/pull/335",
          "title": "fix(infra): require apply identity gates",
          "body": "## Summary\n- require target environment and provider-neutral identity_ref for non-disabled infra-contract apply\n- bind identity_ref into plan, artifact, and apply evidence\n- document managed apply target/identity gates and cover missing environment/identity before mutation\n\n## Verification\n- node --test tests/infra-contract.test.mjs tests/buildchain-config.test.mjs tests/cli.test.mjs\n- corepack pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:37:36Z",
          "mergedAt": "2026-07-03T07:39:34Z",
          "additions": 204,
          "deletions": 34,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 336,
          "url": "https://github.com/kungfu-systems/buildchain/pull/336",
          "title": "fix(release): preserve finalization passport evidence",
          "body": "## Summary\n- carry persisted publish transaction evidence and publish contract through version-state finalization\n- generate release passports from the transaction source SHA instead of the finalization merge SHA\n- extend promotion tests to assert persisted passport and check-report remain trusted\n\n## Validation\n- pnpm --filter \"./actions/promote-buildchain-ref\" build\n- node --test tests/promote-buildchain-ref.test.mjs tests/release-passport.test.mjs tests/cli.test.mjs\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:55:04Z",
          "mergedAt": "2026-07-03T07:56:36Z",
          "additions": 157,
          "deletions": 47,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 175,
          "url": "https://github.com/kungfu-systems/kungfu/pull/175",
          "title": "feat(rewind): capture an unmodified LangChain agent via the adapter table",
          "body": "Add a LangChain adapter to the in-process capture hook's adapter table: patch BaseTool.run once langchain_core.tools imports, so a real create_agent (langgraph) run's tool calls land in the journal with zero code change. Model turns are already captured at the wire proxy. A new rewind-demo-langchain fixture runs a genuine langchain agent against a deterministic mock model and asserts the full fact set in one journal (both model turns, the tool call from the real seam, causal bracketing); verify's double-path decode holds on the real run and verify --full picks the fixture up automatically.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:56:59Z",
          "mergedAt": "2026-07-03T07:57:05Z",
          "additions": 470,
          "deletions": 3,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 337,
          "url": "https://github.com/kungfu-systems/buildchain/pull/337",
          "title": "fix(release): preserve finalization passport evidence",
          "body": "## Summary\n- port the finalization passport evidence fix from v2.3 to v2.4\n- carry persisted publish transaction evidence and publish contract through version-state finalization\n- keep release passport source SHA and trusted publishing checks tied to the original publish transaction\n\n## Validation\n- pnpm --filter \"./actions/promote-buildchain-ref\" build\n- node --test tests/promote-buildchain-ref.test.mjs tests/release-passport.test.mjs\n- pnpm run check\n- git diff --check\n\nCherry-picked-from: 56db41a",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:58:23Z",
          "mergedAt": "2026-07-03T08:00:48Z",
          "additions": 157,
          "deletions": 47,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 338,
          "url": "https://github.com/kungfu-systems/buildchain/pull/338",
          "title": "chore(release): promote 2.4 alpha",
          "body": "Promote the Buildchain 2.4 development line into the alpha channel.\\n\\nThis starts the governed 2.4 release flow after the infra-contract lifecycle work landed on dev/v2/v2.4.\\n\\nExpected follow-up: Buildchain Ref Promotion publishes the 2.4 alpha version state and npm evidence before production release promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T07:59:46Z",
          "mergedAt": "2026-07-03T08:01:57Z",
          "additions": 5896,
          "deletions": 218,
          "changedFiles": 61
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 339,
          "url": "https://github.com/kungfu-systems/buildchain/pull/339",
          "title": "Prepare v2.4.0-alpha.0",
          "body": "Create the generated version-state commit for v2.4.0-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:07:04Z",
          "mergedAt": "2026-07-03T08:08:17Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 340,
          "url": "https://github.com/kungfu-systems/buildchain/pull/340",
          "title": "fix(release): ignore invalid optional build summaries",
          "body": "## Summary\n- ignore missing or invalid optional build summary inputs when collecting release passports\n- keep release passport validation strict for explicitly accepted JSON inputs\n- add regression coverage for path-like non-JSON build-summary artifacts\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:15:38Z",
          "mergedAt": "2026-07-03T08:16:45Z",
          "additions": 58,
          "deletions": 44,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 341,
          "url": "https://github.com/kungfu-systems/buildchain/pull/341",
          "title": "chore(release): promote 2.4 alpha",
          "body": "Promote dev/v2/v2.4 to alpha/v2/v2.4 after the release-passport optional build-summary fix.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:17:14Z",
          "mergedAt": "2026-07-03T08:18:48Z",
          "additions": 58,
          "deletions": 44,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 342,
          "url": "https://github.com/kungfu-systems/buildchain/pull/342",
          "title": "Prepare v2.4.0-alpha.1",
          "body": "Create the generated version-state commit for v2.4.0-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:20:51Z",
          "mergedAt": "2026-07-03T08:22:22Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 343,
          "url": "https://github.com/kungfu-systems/buildchain/pull/343",
          "title": "fix(release): ignore missing optional dist-tag evidence",
          "body": "## Summary\n- guard optional dist-tag evidence paths before release passport collection\n- keep missing stale evidence paths from being parsed as JSON strings\n- update finalization regression coverage for missing optional dist-tag evidence\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:26:47Z",
          "mergedAt": "2026-07-03T08:28:11Z",
          "additions": 42,
          "deletions": 62,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 344,
          "url": "https://github.com/kungfu-systems/buildchain/pull/344",
          "title": "chore(release): promote 2.4 alpha",
          "body": "Promote dev/v2/v2.4 to alpha/v2/v2.4 after the optional dist-tag evidence passport fix.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:28:46Z",
          "mergedAt": "2026-07-03T08:30:16Z",
          "additions": 42,
          "deletions": 62,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 345,
          "url": "https://github.com/kungfu-systems/buildchain/pull/345",
          "title": "Prepare v2.4.0-alpha.2",
          "body": "Create the generated version-state commit for v2.4.0-alpha.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:32:18Z",
          "mergedAt": "2026-07-03T08:33:37Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 346,
          "url": "https://github.com/kungfu-systems/buildchain/pull/346",
          "title": "chore(release): release 2.4",
          "body": "Promote alpha/v2/v2.4 to release/v2/v2.4 for Buildchain 2.4 production release. Alpha v2.4.0-alpha.2 is finalized with release passport evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:36:29Z",
          "mergedAt": "2026-07-03T08:37:59Z",
          "additions": 5891,
          "deletions": 219,
          "changedFiles": 61
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 347,
          "url": "https://github.com/kungfu-systems/buildchain/pull/347",
          "title": "Release v2.4.0",
          "body": "Create the generated version-state commit for v2.4.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:40:06Z",
          "mergedAt": "2026-07-03T08:41:28Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 348,
          "url": "https://github.com/kungfu-systems/buildchain/pull/348",
          "title": "Prepare v2.4.1-alpha.0",
          "body": "Create the generated version-state commit for v2.4.1-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:43:49Z",
          "mergedAt": "2026-07-03T08:44:48Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 176,
          "url": "https://github.com/kungfu-systems/kungfu/pull/176",
          "title": "refactor(gui): built-in kfx migrate to the v2 contract",
          "body": "Merge feature/shell-foundation into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-03T08:48:13Z",
          "mergedAt": "2026-07-03T08:48:17Z",
          "additions": 812,
          "deletions": 168,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 349,
          "url": "https://github.com/kungfu-systems/buildchain/pull/349",
          "title": "feat(release): enrich release passports",
          "body": "## Summary\n- add release-passport-product-name to promote-buildchain-ref\n- backfill the durable release-state SHA into buildchain.release.json after the first passport upload and persist the updated passport\n- document the consumer passport audit entrypoint and cover product-name/SHA backfill in tests\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs tests/release-passport.test.mjs\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T09:33:37Z",
          "mergedAt": "2026-07-03T09:35:20Z",
          "additions": 114,
          "deletions": 66,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 350,
          "url": "https://github.com/kungfu-systems/buildchain/pull/350",
          "title": "Promote v2.4 dev to alpha",
          "body": "Promote dev/v2/v2.4 to alpha/v2/v2.4 for release passport product-name and durable state SHA backfill validation.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T09:35:44Z",
          "mergedAt": "2026-07-03T09:37:38Z",
          "additions": 114,
          "deletions": 66,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 351,
          "url": "https://github.com/kungfu-systems/buildchain/pull/351",
          "title": "Prepare v2.4.1-alpha.1",
          "body": "Create the generated version-state commit for v2.4.1-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T09:39:38Z",
          "mergedAt": "2026-07-03T09:41:19Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 352,
          "url": "https://github.com/kungfu-systems/buildchain/pull/352",
          "title": "Promote v2.4 alpha to release",
          "body": "Promote alpha/v2/v2.4 to release/v2/v2.4 for stable 2.4.1 after validating release passport product-name and durable state SHA backfill.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T09:43:48Z",
          "mergedAt": "2026-07-03T09:45:32Z",
          "additions": 115,
          "deletions": 67,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 353,
          "url": "https://github.com/kungfu-systems/buildchain/pull/353",
          "title": "Release v2.4.1",
          "body": "Create the generated version-state commit for v2.4.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T09:47:21Z",
          "mergedAt": "2026-07-03T09:49:06Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 354,
          "url": "https://github.com/kungfu-systems/buildchain/pull/354",
          "title": "Prepare v2.4.2-alpha.0",
          "body": "Create the generated version-state commit for v2.4.2-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T09:51:22Z",
          "mergedAt": "2026-07-03T09:53:00Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 177,
          "url": "https://github.com/kungfu-systems/kungfu/pull/177",
          "title": "feat(core): native FlatBuffers schema compilation and the kfx open layer",
          "body": "Let a kfx author define a FlatBuffers event schema and insert it into a run dynamically — the point of the hana->FB migration. libkungfu compiles a .fbs to a .bfbs in-process via the FlatBuffers library it already links (Parser::Parse + Serialize), with no flatc binary and no subprocess; compilation is tiered by trust (sandboxed third-party schemas get hard bounds). Exposed as pykungfu.yijinjing.compile_schema and a 'kungfu schema compile' CLI verb. A compiled schema is content-addressed and bound to a msg_type in the run manifest (third-party kfx band 40000-49999), and events of that type decode by reflection over the .bfbs in every runtime: the Python BundleDecoder (extended to the full scalar set plus float/double/vectors) and a new TS ReflectionDecoder capability for the Electron inspector. A rewind-demo-kfx-schema fixture runs the whole loop under 'kungfu trace' and is auto-gated by verify --full; the same in-run event decodes identically through C++/Python and TS.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T09:59:29Z",
          "mergedAt": "2026-07-03T09:59:34Z",
          "additions": 2141,
          "deletions": 14,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 178,
          "url": "https://github.com/kungfu-systems/kungfu/pull/178",
          "title": "test(kfx): distribution fixture proves the tgz lifecycle",
          "body": "Merge feature/kfx-distribution into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-03T10:00:51Z",
          "mergedAt": "2026-07-03T10:00:57Z",
          "additions": 1733,
          "deletions": 459,
          "changedFiles": 36
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 179,
          "url": "https://github.com/kungfu-systems/kungfu/pull/179",
          "title": "Extension devkit: scaffold, docs and fixture for view kfx",
          "body": "## What\n\nCloses the developer-facing gap in the kfx distribution chain: a newcomer can go from an empty directory to an installed view extension without reading platform sources.\n\n- `kfs create extension <dir>` scaffolds a view kfx (same token mechanism as `create app`): manifest with `kungfuConfig.config.view`, a minimal `View` component on the contract tokens, build/clean scripts, README. `--workspace` wires `workspace:*` deps.\n- `docs/extensions.md` fills the MAP's `to write` slot: facet/package/suite vocabulary, scaffold-to-install quickstart, `kungfuConfig` field reference tied to `framework/kfx` types, the build externals contract, discovery roots, install lifecycle, and the honest status of runtime facets (mid-migration, per `known-limits.md`). MAP row goes `stable`.\n- `tests/fixtures/kfx-demo-scaffold/` proves the chain end to end: scaffold → build → load-contract assertion (named `View` export, only shell-provided modules required) → `npm pack` → `kungfu kfx install`/`list`/`remove` in a clean home. Picked up automatically by `verify --full` via the `kfx-demo-` prefix.\n\n## Validation\n\n- Scaffold → build → contract assertion → pack ran green offline from a clean directory; the tgz contains exactly `dist/`, `package.json`, `README.md`.\n- `create app` regression-smoked (workspace token, non-empty-dir refusal); `node --check` and biome on `kfs.js` (the one formatter finding predates this change).\n- The fixture's install stage requires a built `dist/kfc` (same precondition as `kfx-demo-install`); first full run lands with the next `verify --full` on a built tree.\n\n## Not in scope\n\nLoader/CLI/contract semantics are only consumed, never changed; the runtime facet build chain stays as documented status.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T10:35:48Z",
          "mergedAt": "2026-07-03T10:36:02Z",
          "additions": 367,
          "deletions": 10,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 9,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/9",
          "title": "ci(site): run web surface on Buildchain 2.4",
          "body": "## Summary\n- run the web surface workflow on Buildchain v2.4\n- consume checked infra output evidence without applying cloud changes by default\n- keep preview, cleanup, staging, and production apply switches disabled\n\n## Validation\n- bash -n scripts/check-site.sh\n- node --check scripts/check-infra-outputs.mjs\n- bash scripts/build-site.sh && bash scripts/check-site.sh\n- git diff --check\n- shellcheck scripts/check-site.sh\n\n## Safety\n- No live cloud apply is enabled by this PR.\n- Preview, cleanup, staging, and production apply switches remain false by default.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T10:14:58Z",
          "mergedAt": "2026-07-03T10:38:11Z",
          "additions": 30,
          "deletions": 9,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 6,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/6",
          "title": "feat(site): consume Buildchain 2.4 bundle",
          "body": "## Summary\n- pin the site runtime to the Buildchain v2.4 package\n- consume checked infra output evidence without applying cloud changes by default\n- keep preview, cleanup, staging, and production apply switches disabled\n\n## Validation\n- npm ci --ignore-scripts --registry=https://registry.npmjs.org/\n- npm run build\n- npm run check\n- bash -n scripts/check-site.sh\n- node --check scripts/check-infra-outputs.mjs\n- node --check scripts/render-site.mjs\n- git diff --check\n- shellcheck scripts/check-site.sh\n\n## Safety\n- No live cloud apply is enabled by this PR.\n- Preview, cleanup, staging, and production apply switches remain false by default.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T10:14:58Z",
          "mergedAt": "2026-07-03T10:38:15Z",
          "additions": 47,
          "deletions": 32,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 180,
          "url": "https://github.com/kungfu-systems/kungfu/pull/180",
          "title": "feat(rewind): framework adapters become a kfx runtime facet",
          "body": "Make framework capture adapters a kfx extension form (config.adapter) instead of kernel code — the first v4 runtime facet. The trace supervisor scans the same extension roots the GUI shell does, finds packages declaring a python or node adapter, and injects the adapter source into the traced child, where the dependency-free capture hook loads it and it registers its patcher (register_adapter in python; globalThis.__kungfuRewind in node). Discovery lives in the supervisor so the hooks stay dependency-free. LangChain support moves out of core into extensions/langchain-adapter; the kernel's built-in table keeps only the demo toolkit probe. @kungfu-tech/kfx gains the KfxAdapterDecl contract type, kfs kfx build tolerates an adapter-only package (an adapter ships source, nothing to bundle), and docs/extensions.md plus shell-and-kfx.md grow the adapter facet and its per-runtime registration recipe. Verified: external python and node adapters found on the extension root capture a toy framework under kungfu trace; the langchain fixture captures an unmodified real agent from the package with no adapter code in core; cross-runtime and happy fixtures still pass.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T11:26:29Z",
          "mergedAt": "2026-07-03T11:26:34Z",
          "additions": 342,
          "deletions": 57,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 181,
          "url": "https://github.com/kungfu-systems/kungfu/pull/181",
          "title": "fix(yijinjing): write a minidump alongside the Windows crash report",
          "body": "## What\n\nOn a fatal native crash, write a `MiniDumpNormal` `.dmp` next to the existing\ntext `hs_err_*.log`, sharing the same `pid_timestamp` stem. Builds on #174\n(crash-handler deadlock hardening).\n\n## Why\n\nThe text report resolves symbols in-process via DbgHelp, which allocates on the\ncrashing heap. Under heap corruption -- the case most worth diagnosing -- that\ntruncates or degrades to `module+offset`. A minidump snapshots memory and the\nmodule list and defers symbolization to offline analysis with the matching PDB,\nso it usually survives heap-corruption crashes that truncate the text stack.\n\n## Behavior\n\n- The dump is written only on real faults carrying an exception context (the SEH\n  `__except` in `hero::produce` and the `SetUnhandledExceptionFilter` backstop).\n  The non-fatal `print_stack_trace()` diagnostic path (node/rx catch blocks)\n  stays text-only.\n- Ordering (settled by on-hardware validation): exception line first, then the\n  minidump, then the fragile DbgHelp stack walk -- so the fault is recorded even\n  if a later step faults, and the robust dump runs before the risky symbol walk.\n- Stack overflow: the dump is skipped (too little stack is left to run\n  `MiniDumpWriteDump`; it would only fault). The text report still records the\n  exception.\n- The dump is written to a `.part` sibling and renamed on success, so a `.dmp`\n  file always means a complete minidump.\n- `MiniDumpNormal` (thread stacks + module list + handles, no full working set)\n  keeps the footprint and privacy surface small.\n\n## Limitations (accepted)\n\nStill in-process: extreme heap corruption or a stack overflow can defeat the dump\ntoo. Out-of-process capture would remove that but adds a permanent\nresident-process + IPC maintenance surface, which is not justified here; it was\nevaluated and declined. Residual tiers are documented in\n`framework/core/docs/windows-crash-symbols.md`.\n\n## Validation\n\nStandalone MSVC harness compiling the real `stacktrace.cpp` + `StackWalker.cpp`,\none process per scenario with a 20s watchdog, across AV / heap-corruption AV /\nstack overflow / non-fatal catch, on both the SEUF and SEH paths:\n\n- No deadlock or double-fault in any scenario (the process always exits).\n- Common AVs: full symbolized log + valid ~48KB minidump every run.\n- Recoverable heap corruption: full log + valid minidump; total corruption: a\n  text stub with the exception line, no dump, no stray file.\n- Stack overflow: dump skipped, text-only. Non-fatal catch: text-only.\n- No 0-byte `.dmp` and no `.part` leftovers.\n\nNo public header or ABI change (`print_stack_trace` signature is unchanged; the\nhelper is file-local). `dbghelp.lib` was already linked, so there is no build\nchange.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T11:29:54Z",
          "mergedAt": "2026-07-03T11:31:05Z",
          "additions": 159,
          "deletions": 7,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 35,
          "url": "https://github.com/kungfu-systems/libnode/pull/35",
          "title": "ci: adopt buildchain 2.4.1 diagnostics",
          "body": "## Summary\n- switch libnode workflows to the published buildchain 2.4.1 refs\n- declare native diagnostics/cache directories in buildchain.toml\n- split libnode make/build/package lifecycle so buildchain observes the real native build\n- fail fast when libnode build outputs are missing\n\n## Validation\n- Build workflow 28655688895 succeeded on Linux x64, macOS ARM64, and Windows x64\n- npm 22.22.3-kf.3-alpha.4 is intentionally not published from this PR\n\n## Notes\nThis PR prepares the release/passport path without pushing publish-gate. Actual npm publishing remains gated by publish-gate.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T11:16:16Z",
          "mergedAt": "2026-07-03T11:39:14Z",
          "additions": 67,
          "deletions": 14,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 7,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/7",
          "title": "chore(site): refresh Buildchain site bundle to 2.4.1",
          "body": "## Summary\n- bump the pinned @kungfu-tech/buildchain package from 2.4.0 to 2.4.1\n- refresh generated source metadata and local assertions for the Buildchain site bundle\n- update repository docs that name the pinned Buildchain artifact\n\n## Validation\n- npm view @kungfu-tech/buildchain@2.4.1 version dist.integrity dist.tarball --registry=https://registry.npmjs.org/\n- npm ci --ignore-scripts --registry=https://registry.npmjs.org/ && npm run build && npm run check\n- git diff --check\n- bash -n scripts/build-site.sh scripts/check-site.sh\n- node --check scripts/render-site.mjs\n- node --check scripts/check-infra-outputs.mjs\n- shellcheck scripts/build-site.sh scripts/check-site.sh\n\n## Safety\n- Live apply remains disabled by default.\n- No AWS, DNS, CloudFront, WAF, IAM, GitHub environment, or deployment mutation was run.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T13:32:37Z",
          "mergedAt": "2026-07-03T13:33:22Z",
          "additions": 23,
          "deletions": 21,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 182,
          "url": "https://github.com/kungfu-systems/kungfu/pull/182",
          "title": "chore(extensions): retire trading-specific reference extensions",
          "body": "## What\n\nRetire four trading-specific reference extensions inherited from the\nframework's quantitative-trading origins:\n\n- `extensions/sim` — simulated broker (Python)\n- `extensions/xtp` — XTP broker gateway demo (C++)\n- `extensions/bar` — bar/candle operator (C++)\n- `extensions/matcher-101` — order matcher (C++)\n\nAlso drops the four packages from the `artifact` dogfood assembly and refreshes\nthe lockfile (30 → 26 workspace projects).\n\n## Why\n\nThese are leftovers from the trading-execution era, not part of the v4\njournal-first platform surface. `xtp` in particular is a real broker-counter\nadapter that is not usable outside that context.\n\n## Coverage note\n\nThe reference extensions double as build-time coverage probes. This change is\nmid-transition:\n\n- **Python path** — still covered by the neutral `indexer-live` extension.\n- **C++ path** — its neutral probe is being introduced separately, so the C++\n  extension path is temporarily without a dedicated build-time probe. This is\n  documented in `docs/architecture.md` rather than left silent.\n\n## Validation\n\nPure removal + lockfile refresh; `pnpm install --frozen-lockfile` is consistent\nand no workspace package references the removed extensions. Relying on the\n`buildchain-validate` CI gate for the full build/assembly check.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T13:54:10Z",
          "mergedAt": "2026-07-03T13:55:05Z",
          "additions": 6,
          "deletions": 4598,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 10,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/10",
          "title": "feat(site): enable gated production release workflow",
          "body": "## Summary\\n- add a repository AGENTS.md router\\n- wire the production OIDC role from infra outputs\\n- gate production apply on manual workflow_dispatch approval\\n- document the production Buildchain release command shape\\n\\n## Validation\\n- bash scripts/build-site.sh && bash scripts/check-site.sh\\n- actionlint .github/workflows/buildchain-web-surface.yml\\n- node /Users/dkr/Code/kungfu-systems/buildchain/scripts/web-surface.mjs --mode validate --cwd .\\n- node /Users/dkr/Code/kungfu-systems/buildchain/scripts/web-surface.mjs --mode deploy-plan --cwd . --channel production --source-sha <branch-head> --artifact-path dist\\n\\n## Release note\\nProduction apply remains manual and disabled by default until production_approved=true is supplied.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T14:03:42Z",
          "mergedAt": "2026-07-03T14:05:25Z",
          "additions": 99,
          "deletions": 22,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 8,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/8",
          "title": "feat(site): wire production release contract",
          "body": "## Summary\\n- wire the planned production role reference from infra outputs\\n- keep production apply disabled while production remains pending\\n- document readiness checks for libkungfu.dev production surfaces\\n- add manual Buildchain runtime validation pass-through\\n\\n## Validation\\n- npm ci --ignore-scripts --registry=https://registry.npmjs.org/ && npm run build && npm run check\\n- actionlint .github/workflows/buildchain-web-surface.yml\\n- node /Users/dkr/Code/kungfu-systems/buildchain/scripts/web-surface.mjs --mode validate --cwd .\\n- node /Users/dkr/Code/kungfu-systems/buildchain/scripts/web-surface.mjs --mode deploy-plan --cwd . --channel production --source-sha <branch-head> --artifact-path dist\\n\\n## Release note\\nThis PR does not enable production apply for libkungfu.dev.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T14:03:43Z",
          "mergedAt": "2026-07-03T14:05:31Z",
          "additions": 39,
          "deletions": 10,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 183,
          "url": "https://github.com/kungfu-systems/kungfu/pull/183",
          "title": "feat(kfx): the sandboxed-ipc trust tier — capabilities become a real boundary",
          "body": "Land the sandboxed-ipc kfx trust tier so installing a third-party view stops being blind trust. Today every kfx runs node-integrated in the shared renderer and can reach anything via window.require; a sandboxed view now runs in an isolated renderer (nodeIntegration:false, contextIsolation:true, sandbox:true) with no node, reaching only the capabilities its manifest declared, over IPC to a trusted host that rejects anything undeclared. Proven live in real Electron: window.require/process/Buffer are absent, a declared call round-trips, an undeclared one is rejected. resolveRuntimeTier is the single source of the trust decision (installed third-party is sandboxed, and a manifest may not elevate); createSandboxedView adds a network-denied session partition and a memory cap. A headless verify --full gate (kfx-demo-sandbox-boundary) asserts the enforcement. The adapter facet stays node-integrated (it runs inside the traced program's own process; its schema compilation is bounded separately). docs/extensions.md and shell-and-kfx.md document the tier as landed. The trusted path is unchanged; wiring the shell's loader to route sandboxed views is a tracked follow-up.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T14:06:31Z",
          "mergedAt": "2026-07-03T14:11:32Z",
          "additions": 475,
          "deletions": 11,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 36,
          "url": "https://github.com/kungfu-systems/libnode/pull/36",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.4",
          "body": "## Summary\n- merge dev/v22/v22.22 buildchain 2.4.1 diagnostics changes into alpha/v22/v22.22\n- advance anchored libnode alpha version to 22.22.3-kf.3-alpha.4\n- prepare alpha channel ref so publish-gate source SHA and target alpha ref match buildchain 2.4.1 release passport semantics\n\n## Validation\n- dev PR #35 Build and Buildchain Preflight passed\n- publish-gate run 28662820381 built all three platform artifacts successfully but failed before npm publish because alpha/v22/v22.22 still pointed at the previous alpha SHA\n- this PR updates alpha via branch protection instead of direct protected-branch push",
          "author": "dongkeren",
          "createdAt": "2026-07-03T13:47:37Z",
          "mergedAt": "2026-07-03T14:27:37Z",
          "additions": 67,
          "deletions": 14,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 355,
          "url": "https://github.com/kungfu-systems/buildchain/pull/355",
          "title": "fix(publish): fail fast on stale channel refs",
          "body": "## Summary\n- verify publish-gate source locks against their target channel refs before heavy build matrices\n- expose `buildchain publish-source verify-channel-ref` for reusable and custom publish jobs\n- move adjacent web-surface apply input and binary release upload checks before high-cost work\n\n## Validation\n- `node --test tests/build-surface.test.mjs tests/cli.test.mjs`\n- `bash scripts/check-workflows.sh`\n- `git diff --check`\n- `pnpm run check`\n\n## Safety\n- No publish, GitHub Release upload, cloud deploy, or release promotion was run.\n- The new gate fails before source checkout/build matrices when alpha/release channel refs do not match `publish-source-sha`.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T14:32:46Z",
          "mergedAt": "2026-07-03T14:34:52Z",
          "additions": 402,
          "deletions": 4,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 356,
          "url": "https://github.com/kungfu-systems/buildchain/pull/356",
          "title": "fix(publish): preflight channel PR lineage",
          "body": "## Summary\\n- verify publish source channel PR lineage in the reusable build trust gate before heavy matrices\\n- require alpha source-locks to come from merged same-repository dev-to-alpha PRs and release source-locks from alpha-to-release PRs\\n- document the earlier fail-fast behavior and cover CLI/workflow tests\\n\\n## Verification\\n- corepack pnpm@11.7.0 install --frozen-lockfile\\n- node --test tests/build-surface.test.mjs tests/cli.test.mjs\\n- bash scripts/check-workflows.sh\\n- node scripts/check-inventory.mjs\\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:14:32Z",
          "mergedAt": "2026-07-03T15:18:13Z",
          "additions": 304,
          "deletions": 16,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 357,
          "url": "https://github.com/kungfu-systems/buildchain/pull/357",
          "title": "feat(web-surface): support release PR production publishes",
          "body": "## Summary\n- add Buildchain-owned release PR intent resolution for web-surface production publishes\n- allow opt-in main-push production when the associated merged PR matches the release label and source branch prefix\n- document the release-PR publish contract and update workflow coverage\n\n## Validation\n- pnpm run check\n\n## Release note\nThis is a Buildchain v2.4 web-surface runtime change required before site-kungfu-tech can switch production publishing to release PR merge semantics.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:20:32Z",
          "mergedAt": "2026-07-03T15:22:03Z",
          "additions": 194,
          "deletions": 16,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 358,
          "url": "https://github.com/kungfu-systems/buildchain/pull/358",
          "title": "chore(release): promote v2.4 alpha",
          "body": "Promote dev/v2/v2.4 to alpha/v2/v2.4 so Buildchain can publish the next v2.4 alpha through the governed channel path.\n\nIncludes the reusable build preflight/source-lock lineage validation change from #356.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:21:07Z",
          "mergedAt": "2026-07-03T15:23:40Z",
          "additions": 884,
          "deletions": 20,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 359,
          "url": "https://github.com/kungfu-systems/buildchain/pull/359",
          "title": "chore(actions): sync run-lifecycle dist",
          "body": "Synchronize the generated run-lifecycle action bundle with the source after #357.\n\nThe alpha promotion run failed because version verification rebuilt action dist and detected a dirty actions/run-lifecycle/dist/index.js outside version state. This PR contains only the generated dist sync.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:26:58Z",
          "mergedAt": "2026-07-03T15:28:44Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 360,
          "url": "https://github.com/kungfu-systems/buildchain/pull/360",
          "title": "chore(release): retry v2.4 alpha promotion",
          "body": "Retry the governed dev/v2/v2.4 -> alpha/v2/v2.4 promotion after syncing the run-lifecycle dist bundle in #359.\n\nThe previous alpha promotion PR #358 merged correctly, but the promotion transaction failed because generated action dist drifted during version-state verification.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:29:05Z",
          "mergedAt": "2026-07-03T15:30:44Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 361,
          "url": "https://github.com/kungfu-systems/buildchain/pull/361",
          "title": "Prepare v2.4.2-alpha.1",
          "body": "Create the generated version-state commit for v2.4.2-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:32:47Z",
          "mergedAt": "2026-07-03T15:34:26Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 184,
          "url": "https://github.com/kungfu-systems/kungfu/pull/184",
          "title": "feat(sdk): build C++ kfx extensions via kfs, add a libkungfu FlatBuffers probe",
          "body": "## What\n\nAdds first-class C++ kfx extension support to the v4 SDK, plus a neutral\nreference probe that reinstates the C++ dogfood coverage lane.\n\nBefore this, `kfs` only built view extensions (esbuild) and adapter facets\n(ship source); a package with C++ sources had no working v4 build path (the old\n`build/kungfu.cmake` and the v2/v3 `*-cpp-101` examples are dead). This wires\nC++ back in cleanly, libkungfu-only.\n\n## Changes\n\n- **`kfs kfx build`** detects a `CMakeLists.txt` at the package root and drives\n  CMake with the core's conan toolchain, pinned to the core's Python, compiling\n  `src/cpp/` into a native pybind11 module under `dist/`.\n- **`extensions/probe-cpp`** — a neutral C++ kfx:\n  - `src/cpp/probe.cpp`: round-trips a value through libkungfu's generated\n    FlatBuffers `Order` table and calls a real libkungfu symbol\n    (`yijinjing::time::now_in_nano`), so it genuinely links libkungfu.\n  - `cmake/kungfu.cmake`: a fresh, libkungfu-only build helper — no libwingchun,\n    no separate `flatc` binary (it consumes libkungfu's generated FB headers),\n    `find_package(pybind11/flatbuffers)` via the conan configs.\n- **`verify`** builds the probe under `--full` (after `rebuild:core`) and\n  asserts the native module exists, so a core capability regression surfaces as\n  a C++ build failure.\n- **`docs/architecture.md`**: the C++ coverage path is now covered by\n  `probe-cpp`; the Python and JS/TS paths are noted as still being reinstated.\n\n## Validation\n\nLocal macOS arm64: `./kungfu-code rebuild:core` then `kfs kfx build` in\n`extensions/probe-cpp` produces `probe_cpp.cpython-313-darwin.so`, `otool -L`\nshows it links `@rpath/libkungfu.dylib`, and loading it under the core Python\nruns `fb_roundtrip(7) == 7` and `now_in_nano() > 0`. Relying on the\n`buildchain-validate` CI gate for the full cross-platform build.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:32:02Z",
          "mergedAt": "2026-07-03T15:35:25Z",
          "additions": 243,
          "deletions": 5,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 362,
          "url": "https://github.com/kungfu-systems/buildchain/pull/362",
          "title": "Promote v2.4 alpha to release",
          "body": "Promote Buildchain v2.4 alpha state to the stable release line after the release-PR publish semantics and run-lifecycle dist sync passed alpha promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:36:59Z",
          "mergedAt": "2026-07-03T15:38:45Z",
          "additions": 886,
          "deletions": 22,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 363,
          "url": "https://github.com/kungfu-systems/buildchain/pull/363",
          "title": "Release v2.4.2",
          "body": "Create the generated version-state commit for v2.4.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:40:44Z",
          "mergedAt": "2026-07-03T15:42:18Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 11,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/11",
          "title": "ci: publish production from Buildchain release PR merges",
          "body": "## Summary\n\n- enable Buildchain v2.4 release-PR production publish semantics for kungfu.tech\n- keep manual production dispatch as an explicit fallback\n- document the release PR shape and update the infra output guard\n\n## Verification\n\n- bash scripts/build-site.sh && bash scripts/check-site.sh\n- actionlint .github/workflows/buildchain-web-surface.yml\n\nMerging this release PR is the production approval event. Buildchain should publish production from the resulting main push only after verifying the same-repository merged PR, the buildchain-release label, and the feature/release- branch prefix.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:45:41Z",
          "mergedAt": "2026-07-03T15:46:52Z",
          "additions": 47,
          "deletions": 23,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 364,
          "url": "https://github.com/kungfu-systems/buildchain/pull/364",
          "title": "Prepare v2.4.3-alpha.0",
          "body": "Create the generated version-state commit for v2.4.3-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T15:44:21Z",
          "mergedAt": "2026-07-03T15:46:56Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 185,
          "url": "https://github.com/kungfu-systems/kungfu/pull/185",
          "title": "feat(sdk): build Python AOT kfx extensions via kfs, repair the engage bridges",
          "body": "## What\n\nAdds first-class **Python AOT** kfx extension support to the v4 SDK, a neutral\nreference probe that reinstates the Python dogfood coverage lane, and repairs\nthe two `engage` bridges it depends on (both were stale against the currently\nbundled tool versions).\n\nFollows the C++ path added earlier; together they restore two of the three\nextension coverage lanes described in `docs/architecture.md`.\n\n## Changes\n\n- **`kfs kfx build`** detects `kungfuBuild.python` and: installs the extension's\n  declared dependencies via `kungfu engage pdm`, then Nuitka-compiles\n  `src/python/<Pkg>` into a native module via `kungfu engage nuitka --module`\n  under `dist/`.\n- **`extensions/probe-python`** — a neutral Python AOT kfx: declares `pydantic`,\n  imports it plus the `kungfu` runtime binding, and compiles to a native module.\n- **`bridging/nuitka`** — delegate to Nuitka's own entry point\n  (`nuitka.__main__.main`) instead of re-implementing option parsing / plugin\n  loading, which crashed on Nuitka 4.1 (`from nuitka import Options` — gone).\n  The engaged scons / data-composer / binding-LIBPATH injection is preserved.\n- **`bridging/pdm`** — forward the subcommand args explicitly\n  (`Core().main(sys.argv[1:])`) so `engage pdm install` runs instead of printing\n  the bare help screen.\n- **`framework/core` deps** — pin `hishel<1.0`: pdm 2.21 imports\n  `hishel._serializers` (the 0.0.x API); the loose transitive bound otherwise\n  resolved to hishel 1.x which dropped it, breaking `engage pdm`.\n- **`verify`** builds and asserts the python probe module under `--full`.\n- **`docs/architecture.md`** — the Python AOT path is now covered by\n  `probe-python`.\n\n## Validation\n\nLocal macOS arm64: `kfs kfx build` in `extensions/probe-python` runs\n`engage pdm install` (installs pydantic 2.14) and `engage nuitka --module`,\nproducing `ProbePython.cpython-313-darwin.so`; loading the compiled module with\nits installed dependency runs `probe(11) == 11`. Relying on `buildchain-validate`\nCI for the full cross-platform build.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T16:20:53Z",
          "mergedAt": "2026-07-03T16:28:40Z",
          "additions": 351,
          "deletions": 170,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 186,
          "url": "https://github.com/kungfu-systems/kungfu/pull/186",
          "title": "feat(gui): embed sandboxed views in an isolated WebContentsView over a capability relay",
          "body": "Completes the runtime integration the loader tier seam left open. The shell now routes a `sandboxed-ipc` view to an isolated renderer instead of blank-rendering it.\n\n## What\n- **`main/sandbox-manager`** — embeds a sandboxed view as a child `WebContentsView` (node stripped, network denied, its own session), positioned over the shell's content area, and relays its capability invokes. Main reads the view bundle (trusted) and injects it into the isolated harness, so the sandbox never gets `fs`/`require`.\n- **`renderer/sandbox-view-harness`** — the isolated page: builds `caps` from the bridge with the api guest, CommonJS-wraps the injected bundle over the shell's externals contract (one React + the capability surface), and mounts `<View caps shell/>` in a real React root.\n- **`renderer/sandbox-host-service`** + **`sandbox-client`** + **`main.tsx`** — the shell registers a view's trusted capability host, asks main to embed it, and keeps the overlay synced to its content rect.\n- **`sandbox-view`** — the isolation posture (webPreferences, locked-down partition, resource guard) is factored into shared helpers; the guard now reads the pid each sample so an embedded view (no OS process at construction) is covered.\n- **`electron.vite.config`** — builds the sandbox preload and the harness page.\n\n## Why this shape\nThe real capabilities live in the trusted node-integrated renderer (they hold the native binding), so the capability path is three hops:\n\n```\nsandboxed view --IPC--> main (SandboxManager, a pure relay)\n  --IPC--> trusted renderer's capability host (the real caps)\n```\n\nMain is a pure relay: it never sees the real capabilities and never interprets the `{cap,method,args}` payload — the declared-only enforcement stays in the trusted renderer's `createCapabilityHost`, co-located with the caps it guards. This keeps the guest↔host callback/subscription protocol intact end to end.\n\n## Validation\n`tsc` clean · `biome check` clean · `electron-vite build` green (preload + harness page emitted) · a headless Electron harness driving these production modules asserts, all passing: tier routing; isolation (no `require`/`process`); bridge exposes declared keys only; a declared capability round-trips through the relay; an undeclared capability is rejected host-side; a third-party bundle mounts live in the isolated renderer; `setBounds` positions the overlay; an over-limit view is killed by the resource guard.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-03T16:30:30Z",
          "mergedAt": "2026-07-03T16:30:58Z",
          "additions": 874,
          "deletions": 49,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 187,
          "url": "https://github.com/kungfu-systems/kungfu/pull/187",
          "title": "docs(architecture): JS/TS coverage is the existing view extensions",
          "body": "The JS/TS extension coverage lane was never missing — the reference view extensions (rewind-inspector, work-dashboard, config-manager, journal-manager) build with esbuild via `kfs kfx build`. Corrects the wording introduced alongside the python-AOT probe that called it 'still being reinstated'. With the cpp (probe-cpp) and python-AOT (probe-python) probes, all three extension coverage lanes are now accurately documented.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T16:35:30Z",
          "mergedAt": "2026-07-03T16:36:04Z",
          "additions": 4,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 37,
          "url": "https://github.com/kungfu-systems/libnode/pull/37",
          "title": "ci: use buildchain v2 for libnode alpha",
          "body": "## Summary\n- switch libnode workflows/actions from pinned buildchain v2.4.1 to floating stable v2\n- bump the anchored alpha package version to 22.22.3-kf.3-alpha.5\n\n## Validation\n- corepack pnpm verify-release\n- git diff --check\n\nThis prepares the next alpha for the strict buildchain publish-gate flow.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T16:09:51Z",
          "mergedAt": "2026-07-03T16:41:37Z",
          "additions": 7,
          "deletions": 7,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 38,
          "url": "https://github.com/kungfu-systems/libnode/pull/38",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.5",
          "body": "Promote dev/v22/v22.22 to alpha/v22/v22.22 for @kungfu-tech/libnode 22.22.3-kf.3-alpha.5.\\n\\nThis channel PR carries the alpha.5 semver bump and switches libnode workflows to the floating stable buildchain @v2 tag so future stable buildchain upgrades do not require routine libnode workflow edits.\\n\\nExpected publish path after merge:\\n- merge this reviewed PR into alpha/v22/v22.22\\n- push publish-gate/alpha/v22/v22.22/22.22.3-kf.3-alpha.5 to the resulting alpha HEAD\\n- let Buildchain trusted publishing publish the root and platform npm packages\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T16:42:01Z",
          "mergedAt": "2026-07-03T17:18:19Z",
          "additions": 7,
          "deletions": 7,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 39,
          "url": "https://github.com/kungfu-systems/libnode/pull/39",
          "title": "build: preserve libnode package aliases",
          "body": "## Summary\\n- package Unix libnode aliases as hardlinks so npm tarballs keep libnode.dylib/libnode.so without duplicating the binary\\n- require platform tarballs to contain the alias entry during Buildchain publish evidence preparation\\n- bump alpha package version to 22.22.3-kf.3-alpha.6\\n\\n## Verification\\n- corepack pnpm verify-release\\n- corepack pnpm verify-package-source\\n- node --check .gyp/node-platform-package.js && node --check .gyp/npm-publish-tarballs.js\\n- git diff --check\\n- local fake package-set validation through .gyp/npm-publish-tarballs.js",
          "author": "dongkeren",
          "createdAt": "2026-07-03T18:03:33Z",
          "mergedAt": "2026-07-03T18:24:58Z",
          "additions": 19,
          "deletions": 7,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 40,
          "url": "https://github.com/kungfu-systems/libnode/pull/40",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.6",
          "body": "## Summary\\n- promote libnode alpha.6 from dev to alpha\\n- includes hardlink alias packaging fix for darwin/linux platform tarballs\\n\\n## Verification\\n- PR #39 Build passed on Linux x64, macOS ARM64, Windows x64\\n- release path will run Buildchain strict channel verification before publish",
          "author": "dongkeren",
          "createdAt": "2026-07-03T18:25:22Z",
          "mergedAt": "2026-07-03T18:47:51Z",
          "additions": 19,
          "deletions": 7,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 41,
          "url": "https://github.com/kungfu-systems/libnode/pull/41",
          "title": "build: materialize libnode aliases after install",
          "body": "## Summary\n- switch platform alias handling from hardlinks to install-time materialization\n- keep darwin/linux tarballs free of alias copies while requiring helper + postinstall\n- bump alpha package version to 22.22.3-kf.3-alpha.7\n\n## Validation\n- corepack pnpm verify-release\n- corepack pnpm verify-package-source\n- node --check .gyp/node-platform-package.js\n- node --check .gyp/npm-publish-tarballs.js\n- git diff --check\n- fake npm package-set validation via .gyp/npm-publish-tarballs.js",
          "author": "dongkeren",
          "createdAt": "2026-07-03T19:12:09Z",
          "mergedAt": "2026-07-03T19:36:57Z",
          "additions": 15,
          "deletions": 12,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 42,
          "url": "https://github.com/kungfu-systems/libnode/pull/42",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.7",
          "body": "## Summary\n- promote libnode alpha.7 alias materialization fix into the alpha channel\n- keep buildchain workflow on floating stable v2\n- publish through buildchain publish-gate after channel merge\n\n## Validation\n- PR #41 buildchain checks passed after rerunning transient Linux configure SIGSEGV\n- Windows x64 and macOS ARM64 passed on the initial run\n- Linux x64 passed on failed-job rerun",
          "author": "dongkeren",
          "createdAt": "2026-07-03T19:37:28Z",
          "mergedAt": "2026-07-03T19:56:37Z",
          "additions": 15,
          "deletions": 12,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 188,
          "url": "https://github.com/kungfu-systems/kungfu/pull/188",
          "title": "Rename the runtime command from kfc to kungfu",
          "body": "Rename the runtime command and its packaged artifacts from `kfc` to `kungfu`, so the product exposes a single canonical name end to end.\n\n## What changed\n\n- **core** freezes the standalone runtime as `kungfu` under `dist/kungfu` (nuitka entry output + `binary.module_path`); the launcher and `kfs` resolve the executable and shared runtime dir there.\n- **packaging** ships `core/dist/kungfu` to `Resources/kungfu`, and the binding install rpath points at `Resources/kungfu`; the gui/tui/api and the SDK app template resolve the runtime and the `kungfu` executable there.\n- **install to PATH** — the reference app gains a VS Code–style \"Install 'kungfu' Command in PATH\" menu action: it ships a small wrapper that locates the bundled runtime and execs it, and symlinks `/usr/local/bin/kungfu` (elevating only when that directory is not user-writable).\n- **runtime identifiers** — the runtime env contract (`KFC_*` → `KUNGFU_*`) is renamed in sync across the writers (api/gui/tui/sdk) and readers (core binding loader, Python variants/cli); TS/JS helpers, the freeze/spec internals, the binding variant suffix, the Windows delay-load hook, and the CLI group all take the `kungfu` name.\n- **public surface** — the `kfc` bin alias is dropped (`kungfu` is the sole command), the prebuilt package name becomes `kungfu-v*`, examples/fixtures invoke `kungfu`, and the docs describe a single `kungfu` runtime and CLI.\n\n## Deliberately kept\n\n- Invisible internal build filenames (`kfc.py`, `kfc.spec`, the `kfc.dist`/`kfc-nuitka` intermediates, the `lib/kfc.js` launcher, `.devtools/kfc.py`) — never user-visible, so renaming them buys nothing.\n- The `Kf*` domain model (`KfConfig`/`KfCategory`/`KfLocation`/…) is a separate namespace and is untouched.\n- Dated ADR / versioning-ledger records that mention the former alias are left as accurate history.\n\n## Verification\n\nA from-scratch core build produces a runnable `dist/kungfu/kungfu` that presents as `kungfu` in `--help`; the packed app carries `Resources/kungfu/kungfu` (rpath resolves in the packaged layout) and the bundled CLI wrapper runs `kungfu` from PATH end to end.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-03T23:55:00Z",
          "mergedAt": "2026-07-04T00:06:20Z",
          "additions": 500,
          "deletions": 319,
          "changedFiles": 86
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 12,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/12",
          "title": "feat(homepage): add cost state proof first screen",
          "body": "## Summary\n- Replaces the initial kungfu.tech screen with the Cost / State / Proof product promise.\n- Adds a realistic local control pane preview for cost waste, work state, and evidence.\n- Keeps the open-source trust layer visible below the first screen.\n\n## Checks\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n- Browser smoke at desktop and mobile widths: no horizontal overflow, console clean.\n\n## Deployment\n- Source-only change. No production apply or release action is included in this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-03T16:11:04Z",
          "mergedAt": "2026-07-04T00:34:05Z",
          "additions": 429,
          "deletions": 71,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 365,
          "url": "https://github.com/kungfu-systems/buildchain/pull/365",
          "title": "fix(release): retry durable state finalization",
          "body": "## Summary\n- Retry transient GitHub API failures for durable release-state reads and writes.\n- Clear stale transaction failure values when finalization reaches complete.\n- Improve native diagnostics: ccache text fallback, full process commands, Windows sampling, requested parallelism detection, and first-class native cache/compiler-cache fields.\n\n## Verification\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-04T00:46:52Z",
          "mergedAt": "2026-07-04T00:48:28Z",
          "additions": 736,
          "deletions": 231,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 366,
          "url": "https://github.com/kungfu-systems/buildchain/pull/366",
          "title": "chore(release): promote v2.4 dev to alpha",
          "body": "## Summary\n- Promote dev/v2/v2.4 into alpha/v2/v2.4 for Buildchain 2.4.3-alpha validation.\n- Includes durable release-state retry/finalization reliability and native diagnostics improvements.\n\n## Verification\n- PR checks must pass before merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T00:49:47Z",
          "mergedAt": "2026-07-04T00:51:36Z",
          "additions": 736,
          "deletions": 231,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 189,
          "url": "https://github.com/kungfu-systems/kungfu/pull/189",
          "title": "Rename the internal freeze-entry files to kungfu",
          "body": "Follow-up to the kfc→kungfu rename: rename the remaining internal freeze-entry files so the source tree reads as kungfu throughout, with no user-visible surface change.\n\n- `src/python/kfc.py` → `kungfu_cli.py` (the nuitka/pyinstaller entry — it cannot be `kungfu.py` without shadowing the sibling `kungfu` package)\n- `.devtools/kfc.py` → `.devtools/kungfu_cli.py`\n- `kfc.spec` → `kungfu.spec`\n- `lib/kfc.js` → `lib/kungfu-cli.js` (`lib/kungfu.js` is the binding loader)\n- `.gyp/freeze-kfc.sh` → `freeze-kungfu.sh`\n\nThe nuitka intermediates follow the entry basename (`kungfu_cli.dist` / `kungfu_cli.bin`, `build/kungfu-nuitka`); the freeze script, conanfile, `package.json` bin/scripts, spec, and the tests/bench references are updated to match.\n\nVerified by a re-freeze: `src/python/kungfu_cli.py` compiles into `kungfu_cli.dist` and produces a runnable `dist/kungfu/kungfu`; the renamed launcher `lib/kungfu-cli.js` runs it too.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T00:53:42Z",
          "mergedAt": "2026-07-04T00:54:36Z",
          "additions": 45,
          "deletions": 45,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 367,
          "url": "https://github.com/kungfu-systems/buildchain/pull/367",
          "title": "Prepare v2.4.3-alpha.1",
          "body": "Create the generated version-state commit for v2.4.3-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T00:53:46Z",
          "mergedAt": "2026-07-04T00:55:31Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 190,
          "url": "https://github.com/kungfu-systems/kungfu/pull/190",
          "title": "refactor(examples): retire legacy trading examples, move the build probes here",
          "body": "The examples/ tree held v3 trading samples (strategy / operator / report / slicetool) whose build scripts call `kfs` commands that no longer exist under v4 — they don't build. Removes them.\n\nMoves the two dogfood build probes from `extensions/` to `examples/` and renames them `@kungfu-tech/examples-probe-{cpp,python}`: they exist to exercise the C++ and python-AOT extension build paths, not to be installed as products, so `examples/` is their proper home and the name no longer implies a shipped kfx.\n\nverify still builds and asserts both probes (paths + package names updated); docs/architecture.md points at the new locations. Locally both probes build from examples/ (probe-cpp -> probe_cpp .so; probe-python -> engage pdm pydantic + engage nuitka -> ProbePython .so, probe(21)==21).",
          "author": "dongkeren",
          "createdAt": "2026-07-04T00:55:41Z",
          "mergedAt": "2026-07-04T00:56:15Z",
          "additions": 19,
          "deletions": 1218,
          "changedFiles": 39
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 368,
          "url": "https://github.com/kungfu-systems/buildchain/pull/368",
          "title": "chore(release): promote v2.4 alpha to release",
          "body": "## Summary\n- Promote alpha/v2/v2.4 into release/v2/v2.4 for Buildchain 2.4.3 stable.\n- Includes durable release-state retry/finalization reliability and native diagnostics improvements already validated in alpha.\n\n## Verification\n- Alpha v2.4.3-alpha.1 release and Binary Distribution completed successfully.\n- PR checks must pass before merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T00:59:16Z",
          "mergedAt": "2026-07-04T01:01:11Z",
          "additions": 737,
          "deletions": 232,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 369,
          "url": "https://github.com/kungfu-systems/buildchain/pull/369",
          "title": "Release v2.4.3",
          "body": "Create the generated version-state commit for v2.4.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T01:03:21Z",
          "mergedAt": "2026-07-04T01:05:00Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 371,
          "url": "https://github.com/kungfu-systems/buildchain/pull/371",
          "title": "Prepare v2.4.4-alpha.0",
          "body": "Create the generated version-state commit for v2.4.4-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T01:07:22Z",
          "mergedAt": "2026-07-04T01:09:12Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 13,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/13",
          "title": "ci: enable standard Buildchain release flow",
          "body": "## Summary\n\n- enable Buildchain preview apply, preview cleanup apply, and staging apply for site-kungfu-tech\n- document the standard flow: feature PR preview, normal merge to staging, release PR merge to production\n- update infra output checks so the workflow must keep preview/staging apply enabled while preserving production release PR gates\n\n## Verification\n\n- bash -n scripts/build-site.sh scripts/check-site.sh\n- node --check scripts/check-infra-outputs.mjs\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n- actionlint .github/workflows/buildchain-web-surface.yml\n- git diff --check\n\n## Dependency\n\nThe preview/staging apply jobs are already supported by Buildchain v2.4. The release PR page staging-review comment depends on the companion Buildchain PR landing and being promoted to the v2.4 workflow ref.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T01:05:06Z",
          "mergedAt": "2026-07-04T01:15:36Z",
          "additions": 24,
          "deletions": 18,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 370,
          "url": "https://github.com/kungfu-systems/buildchain/pull/370",
          "title": "feat(web-surface): comment staging URL on release PRs",
          "body": "## Summary\n\n- add a Buildchain web-surface release PR review comment with the staging review URL and production target\n- keep the comment scoped to same-repository release PRs that match `production-release-on-main`, `production-release-label`, and `production-release-head-prefix`\n- document the operator flow: verify staging from the release PR page, then merge as the production approval\n\n## Verification\n\n- node --check scripts/web-surface-release-pr-review.mjs\n- node --test tests/build-surface.test.mjs\n- pnpm run check:workflows\n- actionlint .github/workflows/.web-surface.yml\n- pnpm run check:site\n- pnpm run check\n- git diff --check\n\n## Notes\n\nThis makes the standard web-surface flow visible in GitHub: feature PRs publish preview, normal main merges publish staging, and release PR pages point operators at staging before merge publishes production.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T01:05:05Z",
          "mergedAt": "2026-07-04T01:41:51Z",
          "additions": 260,
          "deletions": 0,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 191,
          "url": "https://github.com/kungfu-systems/kungfu/pull/191",
          "title": "refactor(api): retire pm2 and the dead trading process-management layer",
          "body": "v4 does not start trading processes (td/md/strategy/ledger/master); the runtime loads in-process and kfx views are isolated by the Electron sandbox (`WebContentsView` + declared-capability IPC relay), so the pm2-based process supervisor in `framework/api` is dead — nothing in gui/tui/developer/extensions calls it.\n\nRemoves the pm2 dependency + `patches/[email-redacted]` + the patchedDependencies entry; deletes `processUtils.ts`, `pm2Custom.ts`, `hooks/preStartProcessHook.ts`, `actions/tradingTask.ts` (pm2-only, zero external consumers); excises the dead pm2 functions from `busiUtils.ts` and their references in `actions/index.ts` / `hooks/index.ts` / `typings/global.d.ts`; decouples `resolveStartProcessOptionsHook` from the pm2 `StartOptions` type. Documents the in-process / Electron-sandbox process model in `docs/architecture.md`.\n\nNet -3132 lines. `framework/api` type-checks clean (`tsc --noEmit`, 0 errors); no pm2 references remain, and no external package imports the removed exports.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T01:43:30Z",
          "mergedAt": "2026-07-04T01:45:04Z",
          "additions": 15,
          "deletions": 3132,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 43,
          "url": "https://github.com/kungfu-systems/libnode/pull/43",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.8",
          "body": "Promote dev/v22/v22.22 to alpha/v22/v22.22 for libnode 22.22.3-kf.3-alpha.8.\n\n- Publish channel: alpha\n- Expected npm version: 22.22.3-kf.3-alpha.8\n- Buildchain runtime: @v2 stable\n\nThis should trigger the publish-gate source lock flow with one alpha build after merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T01:22:38Z",
          "mergedAt": "2026-07-04T01:47:34Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 372,
          "url": "https://github.com/kungfu-systems/buildchain/pull/372",
          "title": "feat(web-surface): persist release feedback passports",
          "body": "## Summary\n- add web-surface staging/production release feedback comments and passport artifacts after apply\n- record responsibility actors, gate evidence, source event, run, target, rollback, and failure context\n- separate anchored/manual internal tags from published version labels in release passports\n\n## Validation\n- node --check scripts/web-surface-release-feedback.mjs\n- node --test tests/build-surface.test.mjs\n- node --test tests/release-passport.test.mjs\n- pnpm run build\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-04T01:52:53Z",
          "mergedAt": "2026-07-04T01:54:37Z",
          "additions": 589,
          "deletions": 48,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 373,
          "url": "https://github.com/kungfu-systems/buildchain/pull/373",
          "title": "chore(release): promote v2.4 dev to alpha",
          "body": "Promote Buildchain dev/v2/v2.4 to alpha/v2/v2.4 for the release feedback/passport changes and PR #370.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T01:55:14Z",
          "mergedAt": "2026-07-04T01:56:57Z",
          "additions": 849,
          "deletions": 48,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 374,
          "url": "https://github.com/kungfu-systems/buildchain/pull/374",
          "title": "Prepare v2.4.4-alpha.1",
          "body": "Create the generated version-state commit for v2.4.4-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T01:58:59Z",
          "mergedAt": "2026-07-04T02:00:42Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 375,
          "url": "https://github.com/kungfu-systems/buildchain/pull/375",
          "title": "chore(release): promote v2.4 alpha to release",
          "body": "Promote Buildchain v2.4.4 alpha to release after release feedback/passport changes and alpha validation.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T02:04:48Z",
          "mergedAt": "2026-07-04T02:06:31Z",
          "additions": 850,
          "deletions": 49,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 192,
          "url": "https://github.com/kungfu-systems/kungfu/pull/192",
          "title": "docs(architecture): document the repository layout and a placement rule",
          "body": "Gives new packages a standard home so placement doesn't drift. Completes the repository-layout block (adds `framework/kfx` and `framework/spec`, lists `kungfu-code`), drops the retired `developer/toolchain`, adds a short **Contracts** layer entry for kfx/spec, and adds a **Where a new package goes** rule.\n\nThe rule: `framework/` = a runtime component or a publishable contract/library others build **on** (imported as a dependency — core/api/kfx/spec/gui/tui); `developer/` = a build-time **tool** others build **with** (invoked, a devDependency — sdk/kfs); `extensions/` = kfx plugins; `examples/` = samples and build-coverage probes; `artifact` = the installer. By this rule a format spec is a contract (framework) and the kfs CLI is a tool (developer), even with a single package there.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T02:04:26Z",
          "mergedAt": "2026-07-04T02:10:09Z",
          "additions": 44,
          "deletions": 13,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 376,
          "url": "https://github.com/kungfu-systems/buildchain/pull/376",
          "title": "Release v2.4.4",
          "body": "Create the generated version-state commit for v2.4.4.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T02:08:30Z",
          "mergedAt": "2026-07-04T02:10:15Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 377,
          "url": "https://github.com/kungfu-systems/buildchain/pull/377",
          "title": "Prepare v2.4.5-alpha.0",
          "body": "Create the generated version-state commit for v2.4.5-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T02:12:34Z",
          "mergedAt": "2026-07-04T02:15:22Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 194,
          "url": "https://github.com/kungfu-systems/kungfu/pull/194",
          "title": "Ship the fact-ledger schemas and the Ink TUI in the packaged app",
          "body": "The installed app now exercises the full runtime: the fact-ledger features work frozen, and the Ink reference TUI ships and runs.\n\n## Fact-ledger schema blobs (`kungfu trace` / rewind / work / atlas)\n\nThe `*_events.bfbs` reflection schemas were never bundled into the frozen runtime, and were read via `dirname(__file__)` — not a real directory inside the standalone binary — so `kungfu trace` failed with `NotADirectoryError`. Ship the blobs flat next to the binding (the `kungfubuildinfo.json` pattern) and resolve them through a `schema_data_path` helper that tries the source layout first, then the binding directory.\n\n## Reference TUI in the dmg\n\nThe Ink TUI was not shipped at all. Bundle it to a single self-contained ES module (esbuild; ESM is required for Ink 5 / yoga-layout top-level await), stub Ink's optional `react-devtools-core`, add a `require` shim for bundled CJS deps, ship it under `Resources/tui`, and add a `kungfu tui` command that runs it through kungfu's embedded Node runtime (`libnode`) — the same bridge `kungfu cli` uses — with `KUNGFU_DIR` pointed at the shipped runtime so it loads `kungfu_node.node` in-process.\n\n## Verification\n\nFrom the packaged app: `kungfu trace -- echo ...` captures a run and writes its bundle; `kungfu tui` loads the in-process binding and renders the ledger view.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T02:18:03Z",
          "mergedAt": "2026-07-04T02:19:05Z",
          "additions": 140,
          "deletions": 6,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 193,
          "url": "https://github.com/kungfu-systems/kungfu/pull/193",
          "title": "fix(gui): boot the sandboxed-view app and surface installed views",
          "body": "Running the full reference app end to end — not just the headless capability harness — surfaced three defects on the embedded sandboxed-view path. Each is fixed here; the production isolation posture is unchanged.\n\n## Fixes\n\n1. **App fails to start.** The electron main/preload externalized the pure-TS workspace packages `@kungfu-tech/api` and `@kungfu-tech/kfx`, so at runtime node's ESM loader tried to resolve their extensionless `src` imports (`export * from './types'`) and threw `ERR_MODULE_NOT_FOUND`. Bundle them into main/preload instead; the native `@kungfu-tech/core` stays external and is `require()`d at runtime.\n\n2. **Installed third-party view invisible.** An installed (sandboxed-ipc) view loaded into the registry but never appeared in the shell nav, because the nav only listed `system` views or views in the active profile's built-in `kfx` list. Surface installed sandboxed views independently of the profile.\n\n3. **Sandboxed view blank in development.** A sandboxed view's locked-down partition denies all non-`file:`/`devtools:` requests. In development the harness page is served over the renderer dev-server origin (`ELECTRON_RENDERER_URL`, an http origin), so it was blocked (`ERR_BLOCKED_BY_CLIENT`) and the view rendered blank. Allow that origin through in development only; production has no such env and still passes only `file:`/`devtools:`.\n\n## Verification\n\nRan the reference app against a real native-backed runtime with a third-party view installed into `<home>/extensions`, and verified in the live app:\n\n- the third-party view is classified `sandboxed-ipc` and renders in an isolated renderer with no node (`window.require`/`process` absent);\n- its declared `ledger` capability round-trips over IPC to the real runtime and returns live health/anchors/records;\n- an undeclared capability is absent on the guest and a forged call is rejected at the host;\n- the view is killed when it breaches the working-set cap, while the shell survives;\n- the embedded view tracks the window on resize.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T02:07:50Z",
          "mergedAt": "2026-07-04T02:22:43Z",
          "additions": 14,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 378,
          "url": "https://github.com/kungfu-systems/buildchain/pull/378",
          "title": "Add consumer issue reporting action",
          "body": "## Summary\n- add first-class `actions/report-buildchain-issue` for consumer workflows to create or update Buildchain issues\n- add `@kungfu-tech/buildchain/issue-reporting` toolkit API with fingerprint dedupe, redaction, GitHub API retry/backoff, and label fallback\n- document the GitHub App token trust model and register the action in Buildchain inventory/site facts\n\n## Verification\n- `pnpm run test:unit`\n- `pnpm -r --filter \"./actions/**\" build`\n- `pnpm run check`\n- bundled action dry-run smoke via `node actions/report-buildchain-issue/dist/index.js`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T02:53:53Z",
          "mergedAt": "2026-07-04T02:55:38Z",
          "additions": 1019,
          "deletions": 1,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 379,
          "url": "https://github.com/kungfu-systems/buildchain/pull/379",
          "title": "Promote dev/v2/v2.4 to alpha",
          "body": "## Summary\n- promote Buildchain consumer issue reporting surface into the alpha channel\n\n## Source\n- dev/v2/v2.4 @ bf3e1eaf2b5bda720391b32805be2665f7e31720\n- includes PR #378\n\n## Verification\n- PR #378 Verify and Build Surface Fixture checks passed before merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T02:56:04Z",
          "mergedAt": "2026-07-04T02:58:20Z",
          "additions": 1019,
          "deletions": 1,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 380,
          "url": "https://github.com/kungfu-systems/buildchain/pull/380",
          "title": "Prepare v2.4.5-alpha.1",
          "body": "Create the generated version-state commit for v2.4.5-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T03:00:33Z",
          "mergedAt": "2026-07-04T03:02:03Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 381,
          "url": "https://github.com/kungfu-systems/buildchain/pull/381",
          "title": "Promote v2.4 alpha to release",
          "body": "## Summary\n- promote Buildchain 2.4.5 alpha into the release channel\n- includes first-class consumer issue reporting action/API from PR #378\n\n## Source\n- alpha/v2/v2.4 @ 92bc8bacb95dbf9208084d92aae1259217255867\n- alpha npm: @kungfu-tech/buildchain@2.4.5-alpha.1\n- alpha release passport: v2.4.5-alpha.1\n\n## Verification\n- PR #379 checks passed before alpha merge\n- PR #380 checks passed before alpha version-state merge\n- Buildchain Ref Promotion runs 28692842200 and 28692935004 succeeded\n- Binary Distribution run 28692958103 succeeded\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T03:05:51Z",
          "mergedAt": "2026-07-04T03:07:37Z",
          "additions": 1020,
          "deletions": 2,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 382,
          "url": "https://github.com/kungfu-systems/buildchain/pull/382",
          "title": "Release v2.4.5",
          "body": "Create the generated version-state commit for v2.4.5.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T03:09:45Z",
          "mergedAt": "2026-07-04T03:11:32Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 383,
          "url": "https://github.com/kungfu-systems/buildchain/pull/383",
          "title": "Prepare v2.4.6-alpha.0",
          "body": "Create the generated version-state commit for v2.4.6-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T03:14:07Z",
          "mergedAt": "2026-07-04T03:16:01Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 386,
          "url": "https://github.com/kungfu-systems/buildchain/pull/386",
          "title": "feat(release): add RC passport promotion evidence",
          "body": "## Summary\n- add reusable build release-candidate passport generation and artifacts\n- add promote-only RC passport validation before promotion side effects\n- extend Buildchain issue reporting with workflow-friction mode and cooldown dedupe\n- dogfood RC passport output in the build-surface fixture workflow\n\n## Verification\n- pnpm run check\n- node --test tests/issue-reporting.test.mjs tests/release-candidate.test.mjs tests/build-surface.test.mjs\n- node --test tests/promote-buildchain-ref.test.mjs\n- git diff --check\n\n## Notes\n- No consumer repository PRs were opened.\n- Buildchain self feedback is fail-soft and requires issues:write on the reporting workflow.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T04:21:30Z",
          "mergedAt": "2026-07-04T04:23:26Z",
          "additions": 1241,
          "deletions": 125,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 196,
          "url": "https://github.com/kungfu-systems/kungfu/pull/196",
          "title": "Make kungfu tui cwd-independent and let trace run -c commands",
          "body": "Two robustness fixes surfaced by dogfooding the packaged app.\n\n- **`kungfu tui` was cwd-dependent and could crash.** It derived its runtime home from `cwd/demo-runtime`, so it showed a different (usually empty) ledger per directory and crashed with a native exception when the cwd was not writable. Default `KF_RUNTIME_DIR` to the same `<home>/runtime` the rest of the CLI uses (`ctx.runtime_dir`), so the TUI opens the real runtime regardless of where it is launched.\n\n- **`kungfu trace -- sh -c '...'` tripped Nuitka's self-execution guard.** Tracing a child command whose arguments include `-c` was mistaken by Nuitka's deployment mode for the frozen binary being asked to self-execute. The runtime never re-executes itself, so the freeze now passes `--no-deployment-flag=self-execution`.\n\nVerified on a fresh build: `kungfu trace -- sh -c 'echo a; echo b'` captures the run; `kungfu tui` launched from a read-only directory renders against the home runtime instead of crashing.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T04:24:46Z",
          "mergedAt": "2026-07-04T04:25:25Z",
          "additions": 10,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 387,
          "url": "https://github.com/kungfu-systems/buildchain/pull/387",
          "title": "chore(release): promote v2.4 dev to alpha",
          "body": "## Summary\nPromote the verified dev/v2/v2.4 head into alpha/v2/v2.4 for Buildchain release publication.\n\nIncludes #386: RC passport promotion evidence and workflow-friction feedback.\n\n## Verification\n- dev/v2/v2.4 Verify run 28694793859 passed\n- PR #386 Verify and Build Surface Fixture passed; RC artifact was generated.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T04:24:55Z",
          "mergedAt": "2026-07-04T04:26:26Z",
          "additions": 1241,
          "deletions": 125,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 388,
          "url": "https://github.com/kungfu-systems/buildchain/pull/388",
          "title": "Prepare v2.4.6-alpha.1",
          "body": "Create the generated version-state commit for v2.4.6-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T04:28:31Z",
          "mergedAt": "2026-07-04T04:30:21Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 389,
          "url": "https://github.com/kungfu-systems/buildchain/pull/389",
          "title": "chore(release): promote v2.4 alpha to release",
          "body": "## Summary\nPromote the verified alpha/v2/v2.4 line into release/v2/v2.4 for Buildchain production publication.\n\nIncludes #386 and alpha publication v2.4.6-alpha.1.\n\n## Verification\n- alpha Verify run 28694950698 passed\n- alpha promotion finalization run 28694970815 passed\n- npm alpha dist-tag is 2.4.6-alpha.1\n- v2.4.6-alpha.1 and v2.4-alpha point at alpha/v2/v2.4.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T04:32:54Z",
          "mergedAt": "2026-07-04T04:34:27Z",
          "additions": 1242,
          "deletions": 126,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 390,
          "url": "https://github.com/kungfu-systems/buildchain/pull/390",
          "title": "Release v2.4.6",
          "body": "Create the generated version-state commit for v2.4.6.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T04:36:18Z",
          "mergedAt": "2026-07-04T04:37:53Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 391,
          "url": "https://github.com/kungfu-systems/buildchain/pull/391",
          "title": "Prepare v2.4.7-alpha.0",
          "body": "Create the generated version-state commit for v2.4.7-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T04:40:13Z",
          "mergedAt": "2026-07-04T04:42:52Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 197,
          "url": "https://github.com/kungfu-systems/kungfu/pull/197",
          "title": "build(core): pin clang-format via uv for reproducible C++ formatting",
          "body": "Pin clang-format==20.1.8 as a uv-managed dependency (PyPI wheel, same lane as ruff) so C++ formatting is byte-identical across machines. run-format-cpp.js and the pre-commit hook use the uv-provided binary; the C++ tree is reformatted to the pinned version.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T05:10:26Z",
          "mergedAt": "2026-07-04T05:10:31Z",
          "additions": 179,
          "deletions": 139,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 195,
          "url": "https://github.com/kungfu-systems/kungfu/pull/195",
          "title": "docs(adr): ADR-0013 — extension isolation and the trusted channel on the runtime plane",
          "body": "Extends ADR-0011's tier model from the GUI view plane to the runtime plane (adapters loaded by the trace supervisor, and future runtime facets).\n\n**Decision (proposed):**\n- Resolve the tier on two axes — trust (source-verified first-party vs third-party) × co-residence (in-process instrumentation vs isolatable independent compute) — instead of one conflated tier.\n- **Default tier:** an untrusted independent-compute facet runs default-deny in an OS-sandboxed child process (macOS Seatbelt; Linux Landlock + seccomp + namespaces), with the capability relay as its sole egress (the same transport-agnostic capability proxy ADR-0011 uses, over child-process IPC).\n- **Trusted channel:** a source-verified first-party facet keeps in-process zero-copy access to the journal.\n- **Instrumentation is gated, not contained:** a capture-side adapter must co-reside in the traced process, so an untrusted adapter is refused rather than sandboxed.\n- **Trust by verifiable origin, never by path:** replace the extension-root-derived trust with a build-time frozen first-party set (key + content hash), as a pluggable source-authority verdict; signature verification can be added later without rewriting the tier decision.\n\nDocs-only; `proposed` status; implementation deferred to a follow-up. Residual risk (OS-sandbox escape, Seatbelt coarseness, capability surface as the real boundary, supply-chain trust root) is recorded in the ADR.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T04:16:09Z",
          "mergedAt": "2026-07-04T05:22:31Z",
          "additions": 131,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 392,
          "url": "https://github.com/kungfu-systems/buildchain/pull/392",
          "title": "fix(release): require PR-stage RC evidence for promotion",
          "body": "## Summary\n- make buildchain-ref-promotion resolve and consume PR-stage RC passport/build-summary artifacts before promotion\n- record locked source Git tree SHA in build summary and RC passport, and accept channel merge commits only by exact head/merge SHA or tree equivalence\n- classify workflow friction for duplicate PRs, duplicate heavy builds, and late fail-fast; write full copyable issue body to summary when issue reporting fails\n\n## Validation\n- pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T05:26:37Z",
          "mergedAt": "2026-07-04T05:28:26Z",
          "additions": 946,
          "deletions": 94,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 393,
          "url": "https://github.com/kungfu-systems/buildchain/pull/393",
          "title": "release: promote v2.4.7 alpha",
          "body": "## Summary\n- promote dev/v2/v2.4 into alpha/v2/v2.4 for v2.4.7 validation\n- PR-stage Build Surface Fixture must produce the RC passport consumed by buildchain-ref-promotion after merge\n\n## Validation\n- dev branch includes PR #392 with local `pnpm run check` and green PR checks\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T05:29:09Z",
          "mergedAt": "2026-07-04T05:31:23Z",
          "additions": 946,
          "deletions": 94,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 198,
          "url": "https://github.com/kungfu-systems/kungfu/pull/198",
          "title": "build: extend format coverage to the whole tree via root biome.json",
          "body": "Add a root biome.json covering all JS/TS outside framework/core (ignoring generated, fixtures, build, JSON). framework/api, framework/spec, extension views, the SDK template and repo-root scripts are now formatted to the biome baseline, and the pre-commit dispatch is widened repo-wide. Pure formatting + tooling; no behavior change.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T05:41:21Z",
          "mergedAt": "2026-07-04T05:41:26Z",
          "additions": 695,
          "deletions": 321,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 395,
          "url": "https://github.com/kungfu-systems/buildchain/pull/395",
          "title": "fix(release): wire RC promotion workflow on default branch",
          "body": "## Summary\n- update default-branch Buildchain Ref Promotion workflow so workflow_run promotions can consume target-commit PR-stage RC evidence\n- add workflow-friction reporter action/core to the default branch so failure reporting can create/dedupe Buildchain issues or write summary fallback\n- keep old target commits compatible by disabling promote-only RC only when the checked-out target commit lacks the resolver script\n\n## Validation\n- pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T05:40:24Z",
          "mergedAt": "2026-07-04T05:42:29Z",
          "additions": 1163,
          "deletions": 0,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 394,
          "url": "https://github.com/kungfu-systems/buildchain/pull/394",
          "title": "Prepare v2.4.7-alpha.1",
          "body": "Create the generated version-state commit for v2.4.7-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T05:33:17Z",
          "mergedAt": "2026-07-04T05:42:56Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 397,
          "url": "https://github.com/kungfu-systems/buildchain/pull/397",
          "title": "fix(release): match RC workflow runs by PR",
          "body": "## Summary\n- match PR-stage release candidate runs by pull request instead of display title\n- keep workflow-name filtering optional and avoid confusing PR titles with workflow names\n- emit absolute artifact paths when the resolver downloads RC evidence outside the workspace\n\n## Validation\n- node --check scripts/release-candidate-resolver.mjs\n- node --test tests/release-candidate.test.mjs\n- pnpm run check\n\n## Release note\nThis fixes alpha/release promotion resolving PR-stage RC passports for version-state PRs whose workflow run title is the PR title rather than the workflow name.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T05:49:48Z",
          "mergedAt": "2026-07-04T05:53:07Z",
          "additions": 18,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 398,
          "url": "https://github.com/kungfu-systems/buildchain/pull/398",
          "title": "fix(release): run promotion guards from default branch",
          "body": "## Summary\n- checkout the default-branch promotion runtime before checking out the target commit\n- resolve RC passport evidence from the default workflow runtime, before target checkout and before publish side effects\n- run workflow-friction classification/reporting from the default workflow runtime so failed promotions get copyable evidence even when the target commit is stale\n\n## Validation\n- bash scripts/check-workflows.sh\n- node --check scripts/release-candidate-resolver.mjs\n- node --check scripts/workflow-friction-report.mjs\n- pnpm run check\n\n## Context\nGitHub workflow_run evaluates the workflow file from the repository default branch. This makes the default-branch promotion entry the strict gate for v2.4 alpha/release promotion reruns.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T05:52:20Z",
          "mergedAt": "2026-07-04T05:53:59Z",
          "additions": 606,
          "deletions": 44,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 399,
          "url": "https://github.com/kungfu-systems/buildchain/pull/399",
          "title": "fix(release): match RC runs by head ref fallback",
          "body": "## Summary\n- fall back from empty workflow run pull_requests arrays to PR head SHA / same-repo head branch matching\n- cover GitHub pull_request runs where the Actions API returns pull_requests: []\n\n## Validation\n- node --check scripts/release-candidate-resolver.mjs\n- node --test tests/release-candidate.test.mjs\n- pnpm run check\n\n## Context\nGitHub returned pull_requests: [] for the PR-stage Build Surface Fixture run on #394, while head_sha/head_branch still identified the version-state PR run.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T05:58:05Z",
          "mergedAt": "2026-07-04T06:00:06Z",
          "additions": 39,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 400,
          "url": "https://github.com/kungfu-systems/buildchain/pull/400",
          "title": "fix(release): match RC runs when PR links are empty",
          "body": "## Summary\n- update the default-branch promotion runtime resolver to match PR-stage runs by PR head SHA / same-repo head branch when GitHub returns pull_requests: []\n\n## Validation\n- node --check scripts/release-candidate-resolver.mjs\n- bash scripts/check-workflows.sh\n- pnpm run check\n\n## Context\nThe #394 Build Surface Fixture run has the correct head_sha/head_branch and artifacts, but the Actions API returns an empty pull_requests array.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T05:59:10Z",
          "mergedAt": "2026-07-04T06:00:51Z",
          "additions": 12,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 401,
          "url": "https://github.com/kungfu-systems/buildchain/pull/401",
          "title": "fix(release): bind RC passport channel from PR base",
          "body": "## Summary\n- normalize RC target channels so publish-channel none is not treated as a real channel\n- derive PR-stage RC channel from the PR base ref, e.g. alpha/v2/v2.4 -> alpha\n- tolerate legacy RC passports that recorded target.channel as none when source identity still matches\n- rebuild the promote-buildchain-ref action bundle\n\n## Validation\n- node --test tests/release-candidate.test.mjs tests/promote-buildchain-ref.test.mjs\n- pnpm run check\n\n## Context\nThe strict default promotion entry successfully resolved #394 PR-stage RC evidence and enabled promote-only-release-candidate, but the old RC passport contained target.channel: none because publish-channel defaulted to none during PR-stage builds.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T06:05:21Z",
          "mergedAt": "2026-07-04T06:07:34Z",
          "additions": 108,
          "deletions": 42,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 402,
          "url": "https://github.com/kungfu-systems/buildchain/pull/402",
          "title": "fix(release): preserve promotion runtime for reports",
          "body": "## Summary\n- restore the default-branch promotion runtime after target checkout and install\n- keep workflow-friction classifier/report action available when promotion fails after target checkout\n\n## Validation\n- bash scripts/check-workflows.sh\n- pnpm run check\n\n## Context\nThe target checkout deletes the earlier promotion-runtime checkout. Without restoring it, post-promote failure classification and issue summary fallback can lose the runtime scripts/action.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T06:06:38Z",
          "mergedAt": "2026-07-04T06:08:49Z",
          "additions": 7,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 403,
          "url": "https://github.com/kungfu-systems/buildchain/pull/403",
          "title": "release: promote v2.4.7 alpha",
          "body": "## Summary\n- promote latest v2.4 release governance fixes to alpha\n- includes strict RC passport consumption, PR-stage run matching fallbacks, RC channel binding, and workflow-friction reporting runtime fixes\n\n## Validation\n- dev PR checks passed on #397, #399, #401\n- default promotion entry checks passed on #398, #400, #402\n\n## Release intent\nThis alpha promotion should publish the next v2.4 alpha candidate through promote-only release-candidate evidence before release promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T06:09:19Z",
          "mergedAt": "2026-07-04T06:17:57Z",
          "additions": 165,
          "deletions": 48,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 199,
          "url": "https://github.com/kungfu-systems/kungfu/pull/199",
          "title": "build: converge on a single biome config and remove prettier",
          "body": "Collapse the JS/TS toolchain onto one root biome.json (delete duplicate per-package configs/scripts, declare biome once at root), remove prettier entirely (core build scripts now use biome), drop dead eslintrc. Pure tooling + formatting.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T06:23:46Z",
          "mergedAt": "2026-07-04T06:23:51Z",
          "additions": 40,
          "deletions": 241,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 406,
          "url": "https://github.com/kungfu-systems/buildchain/pull/406",
          "title": "fix(release): retry promotion PR lineage API reads",
          "body": "## Summary\n- wrap promotion PR lineage lookups in the existing transient GitHub API retry helper\n- cover `GET /commits/{sha}/pulls` 500/other-side-closed retry behavior\n- rebuild the promote-buildchain-ref action bundle\n\n## Validation\n- node --test --test-name-pattern=\"channel promotion PR lineage retries|publish transaction retries transient durable release-state reads\" tests/promote-buildchain-ref.test.mjs\n- pnpm --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- pnpm run check\n\n## Release note\nThis fixes the transient GitHub API 500 observed in Buildchain Ref Promotion run 28697487524 after RC passport resolution had already succeeded.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T06:23:23Z",
          "mergedAt": "2026-07-04T06:25:28Z",
          "additions": 122,
          "deletions": 58,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 407,
          "url": "https://github.com/kungfu-systems/buildchain/pull/407",
          "title": "release: promote v2.4.7 alpha retry fix",
          "body": "## Summary\n- promote dev/v2/v2.4 to alpha/v2/v2.4 after adding transient GitHub API retry coverage for promotion PR lineage reads\n- keeps the legal dev -> alpha promotion lineage for RC passport promote-only validation\n\n## Context\n- Buildchain Ref Promotion run 28697487524 resolved PR-stage RC evidence and set promote-only-release-candidate=true, then failed on transient GitHub API 500 from `GET /commits/{sha}/pulls`.\n- PR #406 fixes that API read path.\n\n## Validation\n- PR #406: pnpm run check\n- this PR should produce fresh PR-stage RC passport artifacts for promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T06:26:03Z",
          "mergedAt": "2026-07-04T06:28:15Z",
          "additions": 122,
          "deletions": 58,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 200,
          "url": "https://github.com/kungfu-systems/kungfu/pull/200",
          "title": "feat(rewind): add provider cost adapters — discovery + Codex/Claude parse layer",
          "body": "Provider cost adapters (parse layer): discover Codex/Claude CLIs (incl. macOS Codex App bundle) and parse their structured output into a normalized, honestly-attributed CostSnapshot. Codex exec --json (tokens only, no pricing) and Claude --print json (total_cost_usd + session + cache-split usage). Parse-only, pure stdlib, no journal/wire/credentials; new fixture asserts the contract under verify.js stage 6.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T06:32:33Z",
          "mergedAt": "2026-07-04T06:32:37Z",
          "additions": 1062,
          "deletions": 0,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 408,
          "url": "https://github.com/kungfu-systems/buildchain/pull/408",
          "title": "release: promote v2.4.7",
          "body": "## Summary\n- promote Buildchain v2.4.7 from alpha/v2/v2.4 to release/v2/v2.4\n- carries RC passport strict promotion, workflow-friction reporter integration, and transient GitHub API retry fixes\n\n## Alpha evidence\n- PR #407 merged to alpha/v2/v2.4\n- Verify run: 28697715023\n- Buildchain Ref Promotion run: 28697736411\n- Promotion consumed PR-stage RC evidence with promote-only-release-candidate=true\n- Alpha tag: v2.4.7-alpha.1\n\n## Validation\n- PR #406: pnpm run check\n- PR #407: Verify, Release - Verify, and Build Surface Fixture checks passed",
          "author": "dongkeren",
          "createdAt": "2026-07-04T06:31:19Z",
          "mergedAt": "2026-07-04T06:34:39Z",
          "additions": 1156,
          "deletions": 123,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 409,
          "url": "https://github.com/kungfu-systems/buildchain/pull/409",
          "title": "Release v2.4.7",
          "body": "Create the generated version-state commit for v2.4.7.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T06:36:41Z",
          "mergedAt": "2026-07-04T06:38:41Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 410,
          "url": "https://github.com/kungfu-systems/buildchain/pull/410",
          "title": "Prepare v2.4.8-alpha.0",
          "body": "Create the generated version-state commit for v2.4.8-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T06:41:00Z",
          "mergedAt": "2026-07-04T06:42:39Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 201,
          "url": "https://github.com/kungfu-systems/kungfu/pull/201",
          "title": "chore: add opt-in @ts-check type safety to the JS tooling layer",
          "body": "Add // @ts-check + JSDoc across the bootstrap/tooling/entry JS (zero compilation), plus a tsconfig.tools.json + check:types script. Type-checking surfaced and fixed real defects (a socket null-race and an undefined-key lookup in rewind_hook.js, an unknown-catch in verify.js). No runtime behavior change.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T07:06:06Z",
          "mergedAt": "2026-07-04T07:06:11Z",
          "additions": 644,
          "deletions": 140,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 202,
          "url": "https://github.com/kungfu-systems/kungfu/pull/202",
          "title": "fix(core): report signal-killed subprocesses as failures, not success",
          "body": "Merge fix/shell-signal-kill-exit-code into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-04T07:24:22Z",
          "mergedAt": "2026-07-04T07:24:29Z",
          "additions": 140,
          "deletions": 6,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 44,
          "url": "https://github.com/kungfu-systems/libnode/pull/44",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.9",
          "body": "Promote dev/v22/v22.22 to alpha/v22/v22.22 for libnode 22.22.3-kf.3-alpha.9.\n\n- Publish channel: alpha\n- Expected npm version: 22.22.3-kf.3-alpha.9\n- Buildchain runtime: @v2 stable\n\nThis should trigger the publish-gate source lock flow with one alpha build after merge.\n\nVerification before PR:\n- node .gyp/libnode-release-verify.js\n- git diff --check\n- corepack pnpm verify-package-source\n- corepack pnpm pack --dry-run",
          "author": "dongkeren",
          "createdAt": "2026-07-04T07:14:20Z",
          "mergedAt": "2026-07-04T07:33:30Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 203,
          "url": "https://github.com/kungfu-systems/kungfu/pull/203",
          "title": "feat(gui): managed terminal — PTY-backed terminal capability + view",
          "body": "Managed terminal: PTY-backed terminal capability (trusted-renderer PTY host) + sandboxed-ipc xterm view + node-pty (Electron 42 ABI). Verified: typecheck, gui build, kfs bundle, 26-assert capability behavior test, and an Electron render smoke (PTY output renders into the DOM). Full kungfu-shell end-to-end deferred to a native build.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T07:52:44Z",
          "mergedAt": "2026-07-04T07:52:49Z",
          "additions": 572,
          "deletions": 1,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 204,
          "url": "https://github.com/kungfu-systems/kungfu/pull/204",
          "title": "feat(kfx): grant view trust by source-authority verdict, not by path (ADR-0013 Phase 0)",
          "body": "First implementation slice of ADR-0013: grant a view the node-integrated tier by a **source-authority verdict**, never by which extension root it loaded from.\n\n**The hole:** `resolveRuntimeTier` trusted a view whenever it loaded from any root other than the install root — so a `KF_EXTENSION_PATH` entry (or any writable built-in root) conferred full `node-integrated` trust.\n\n**The change:**\n- **kfx** — `FirstPartyManifest` + `authorizeFirstParty(manifest, key, contentHash)`: a view is trusted only if its key is in the frozen first-party set and, when pinned, its bundle content hash matches. This is the pluggable verdict — a signature check can be a second implementation without touching `resolveRuntimeTier`, which now takes a `trusted` boolean.\n- **gui loader** — resolve the tier from the manifest (`KF_FIRST_PARTY_MANIFEST`) + bundle hash; path no longer confers trust. A missing manifest trusts nothing but the shell's own `system` views (safe default, never a path fallback).\n- **manifest generation** — derived from a *fixed* first-party root (never `KF_EXTENSION_PATH`). Dev generates it at startup, keys only (bundles rebuild constantly → trusted by key). Packaged points at a build-baked resource with pinned hashes.\n\n**Design note (surfaced during grounding):** content-hash trust conflicts with dev source builds (hashes change every rebuild). Resolved by making the verdict identity-based — packaged pins `key+hash`, dev trusts first-party `key` unpinned — so both modes close the `KF_EXTENSION_PATH` hole.\n\n**Gate:** `tests/fixtures/kfx-demo-trust-authority` (verify --full stage 6, 10 assertions) — a third-party key on another root is sandboxed, a first-party key is node-integrated only with matching content, a tampered bundle is rejected, no manifest trusts nothing but system views.\n\n**Follow-up (out of scope here):** the packaged pinned-manifest bake rides with built-in-extension shipping (a separate pre-existing gap); until then packaged apps trust only system views. Untrusted capture-side adapters (the runtime plane) are a later slice.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T07:54:21Z",
          "mergedAt": "2026-07-04T07:59:05Z",
          "additions": 296,
          "deletions": 21,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 205,
          "url": "https://github.com/kungfu-systems/kungfu/pull/205",
          "title": "build(core): build the native addon from source on install",
          "body": "The self-hosted prebuilt host (prebuilt.libkungfu.cc) has an expired cert and publishes no 4.0 binary, so the node-pre-gyp download on install always failed. 4.0 now builds the native addon from source on install (skips when already built). Removes vestigial binary/install config from api and indexer-live. Verified end to end: a clean install compiles kungfu_node.node in ~10min. Follow-up: retire the node-pre-gyp/node-gyp/binding.gyp orchestration (it only circles back to run-conan.js) and distribute via npm platform packages.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:15:00Z",
          "mergedAt": "2026-07-04T08:15:04Z",
          "additions": 19,
          "deletions": 25,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 411,
          "url": "https://github.com/kungfu-systems/buildchain/pull/411",
          "title": "feat(release): add release-candidate promote-only flow",
          "body": "## Summary\n- emit PR-stage release-candidate bundles from the reusable build summary job\n- add a promote-only reusable workflow that resolves one merged PR RC, downloads it, validates tree-equivalent source locks, locks publish-gate, and then publishes without rerunning the heavy matrix\n- teach promote-buildchain-ref and release passports to record built-source vs promotion-channel SHA/tree evidence\n- add workflow friction issue fallback helper and docs for native package promote-only semantics\n\n## Validation\n- pnpm install --frozen-lockfile\n- pnpm -r --filter \"./actions/**\" build\n- pnpm run check\n\n## Dogfood boundary\n- Verified through Buildchain fixture/unit coverage only. No consumer repo PRs were opened and no consumer three-platform heavy build was triggered.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:02:52Z",
          "mergedAt": "2026-07-04T08:15:30Z",
          "additions": 555,
          "deletions": 53,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 206,
          "url": "https://github.com/kungfu-systems/kungfu/pull/206",
          "title": "feat(rewind): refuse untrusted adapters at the trace supervisor (ADR-0013 Phase 1)",
          "body": "Extends the ADR-0013 source-authority verdict from the GUI view plane (Phase 0, #204) to the **runtime/capture plane**.\n\n**The hole:** a capture-side `adapter` facet is injected by the trace supervisor into the traced program **in-process**, and the supervisor injected *every* discovered adapter with no trust check. Installing a third-party adapter, or pointing `KF_EXTENSION_PATH` at one, gave it full in-process reach over the run.\n\n**Why refuse, not sandbox:** an adapter runs inside the traced program's own process by construction (it patches the framework's tool seam) — isolating it would defeat the instrumentation. So an untrusted adapter is **refused, not contained**; injecting third-party code into a run requires the trusted channel (source verification).\n\n**The change:**\n- `first_party.py` — the first-party key set, read from the shared manifest (`KF_FIRST_PARTY_MANIFEST`, the same one the GUI loader uses) or, in a source checkout, derived from the product's own `extensions/` tree. A frozen build with no baked manifest trusts none.\n- `discover_adapters` now returns `(entries, dirs, refused)`; only a package whose key is in the first-party set is injected. The supervisor logs each refusal on stderr.\n- `test_adapter_trust` — an untrusted adapter is refused whether it sits on `KF_EXTENSION_PATH` or the install root; a first-party adapter is injected. Trust is by set membership, never by root.\n\n**No regression:** the `rewind-demo-langchain` fixture runs from source (`uv run python .devtools/kungfu_cli.py`), so the first-party set is derived from the real `extensions/` tree and `langchain-adapter` stays trusted.\n\n**Follow-up (shared with Phase 0):** the packaged/frozen path needs the baked first-party manifest (rides with built-in-extension shipping); until then a frozen build refuses adapters.\n\nBuilds on #204.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:15:25Z",
          "mergedAt": "2026-07-04T08:17:04Z",
          "additions": 193,
          "deletions": 9,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 412,
          "url": "https://github.com/kungfu-systems/buildchain/pull/412",
          "title": "release: promote v2.4 native promote-only flow to alpha",
          "body": "Promote Buildchain v2.4 native promote-only release-candidate flow to alpha.\\n\\nIncludes PR-stage release-candidate artifacts, post-merge promote-only reuse, tree-equivalent source lock validation, publish-gate wrapper semantics, and workflow friction reporting coverage.\\n\\nValidation before channel PR:\\n- pnpm run check\\n- PR #411 checks: Verify/check and Build Surface Fixture all passed",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:16:58Z",
          "mergedAt": "2026-07-04T08:19:07Z",
          "additions": 555,
          "deletions": 53,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 413,
          "url": "https://github.com/kungfu-systems/buildchain/pull/413",
          "title": "Prepare v2.4.8-alpha.1",
          "body": "Create the generated version-state commit for v2.4.8-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:21:16Z",
          "mergedAt": "2026-07-04T08:23:05Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 414,
          "url": "https://github.com/kungfu-systems/buildchain/pull/414",
          "title": "release: promote v2.4.8",
          "body": "Promote Buildchain v2.4.8 from alpha to release.\\n\\nAlpha evidence:\\n- v2.4.8-alpha.1 tag: 374ef2699e0ae850213bb58835881cc410209870\\n- npm alpha: @kungfu-tech/buildchain@2.4.8-alpha.1\\n- Buildchain Ref Promotion runs 28700335036 and 28700431091 completed successfully\\n\\nThis promotes the native promote-only release-candidate flow implemented through PR #411.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-04T08:25:36Z",
          "mergedAt": "2026-07-04T08:27:13Z",
          "additions": 556,
          "deletions": 54,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 415,
          "url": "https://github.com/kungfu-systems/buildchain/pull/415",
          "title": "Release v2.4.8",
          "body": "Create the generated version-state commit for v2.4.8.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:29:10Z",
          "mergedAt": "2026-07-04T08:31:03Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 416,
          "url": "https://github.com/kungfu-systems/buildchain/pull/416",
          "title": "Prepare v2.4.9-alpha.0",
          "body": "Create the generated version-state commit for v2.4.9-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:33:36Z",
          "mergedAt": "2026-07-04T08:35:31Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 207,
          "url": "https://github.com/kungfu-systems/kungfu/pull/207",
          "title": "feat(capability): subprocess transport + Python guest for the relay (ADR-0013 Phase 2)",
          "body": "The capability relay (`sandbox.ts`) was transport-agnostic but shipped only the Electron IPC channel (GUI plane). This adds the **CLI-plane channel**: a sandboxed guest can run in a child process, reaching only its declared capabilities over the child's stdio.\n\n- `api/capability/subprocess.ts` — pure newline-delimited-JSON stdio framing, **decoupled from the host** (the caller composes it with `createCapabilityHost`), so it serves any host and is testable without a capability instance. The host holds the real caps; an undeclared capability is rejected there, never reachable.\n- `kungfu/capability` (`guest.py`) — the **Python port** of `createCapabilityGuest`: a child builds its capability object from the declared set alone, marshals callback args as `{\"__sandboxCallback\"}` markers, and receives bridged events on a background reader thread.\n- fixture `kfx-demo-subprocess-caps` (verify --full stage 6) — a Node host + a **Python guest over a real subprocess** prove a declared call round-trips, an undeclared capability is absent, and a subscription bridges host→guest.\n\nValidated: fixture passes end-to-end (Node ↔ Python), `subprocess.ts` typechecks, `guest.py` ruff-clean.\n\nBuilds on the two-tier trust work (#204 Phase 0, #206 Phase 1). This is the default-tier *transport*; the OS-sandbox launcher that isolates the child is Phase 3.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:43:57Z",
          "mergedAt": "2026-07-04T08:44:48Z",
          "additions": 314,
          "deletions": 0,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 417,
          "url": "https://github.com/kungfu-systems/buildchain/pull/417",
          "title": "fix(release): expose RC workflow selection",
          "body": "## Summary\n- add release-candidate workflow file/name inputs to the promote-only wrapper, defaulting consumers to build.yml / Build\n- pass artifact-name and workflow selectors into release-candidate-resolver\n- filter RC passport/summary artifact selection by artifact-name to avoid same-run ambiguity\n- document the consumer defaults\n\n## Verification\n- node --check scripts/release-candidate-resolver.mjs\n- node --test tests/release-candidate.test.mjs tests/build-surface.test.mjs\n- bash scripts/check-workflows.sh\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:46:54Z",
          "mergedAt": "2026-07-04T08:48:48Z",
          "additions": 69,
          "deletions": 8,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 418,
          "url": "https://github.com/kungfu-systems/buildchain/pull/418",
          "title": "chore(release): promote v2.4 alpha",
          "body": "## Summary\n- Promote dev/v2/v2.4 to alpha/v2/v2.4 after PR #417.\n- This exercises the release-candidate build and post-merge promote-only release path.\n\n## Release intent\n- Channel: alpha\n- Source: dev/v2/v2.4\n- Target: alpha/v2/v2.4\n\n## Verification\n- PR #417 passed Verify and Build Surface Fixture before merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:49:16Z",
          "mergedAt": "2026-07-04T08:51:00Z",
          "additions": 69,
          "deletions": 8,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 419,
          "url": "https://github.com/kungfu-systems/buildchain/pull/419",
          "title": "Prepare v2.4.9-alpha.1",
          "body": "Create the generated version-state commit for v2.4.9-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:53:13Z",
          "mergedAt": "2026-07-04T08:54:42Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 208,
          "url": "https://github.com/kungfu-systems/kungfu/pull/208",
          "title": "feat(rewind): add CostSnapshot open-layer event (msg_type 30008)",
          "body": "Mint the wire form of the parsed cost contract: rewind open-layer CostSnapshot (msg_type 30008), SCHEMA_VERSION 1->2, tail-only additive. Fixture rewind-demo-cost-wire proves round-trip + honesty bits + schema-only reflection decode + bundle binding.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:55:55Z",
          "mergedAt": "2026-07-04T08:56:00Z",
          "additions": 729,
          "deletions": 5,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 209,
          "url": "https://github.com/kungfu-systems/kungfu/pull/209",
          "title": "feat(capability): OS sandbox launcher for the default tier — macOS (ADR-0013 Phase 3)",
          "body": "The isolation base for the default tier: launch an untrusted guest inside an OS default-deny sandbox so its **only egress is the capability relay** (Phase 2) on its stdio. Filesystem writes and the network are denied; reads are allowed (an interpreter must read its own runtime — a coarse boundary the ADR records as residual risk).\n\n- `sandbox-launcher.ts` — wrap a command in a Seatbelt profile via `sandbox-exec` on macOS. **Linux (Landlock + seccomp + namespaces) is not implemented yet and is refused, not run unconfined** — a silent no-op sandbox is worse than a visible gap.\n- fixture `kfx-demo-sandbox-launch` (verify --full stage 6, macOS only) — composes launcher + transport + host: a guest under the sandbox relays a capability call through its stdio, while a filesystem write and a network connection are **both denied**.\n\n**Validated on macOS arm64** (this machine): relay works through the sandbox, `/tmp` write → PermissionError, socket connect → PermissionError, no leak file created.\n\nCompletes the default-tier isolation: Phase 1 refuses untrusted in-process adapters, Phase 2 gave the relay a subprocess channel, Phase 3 confines that subprocess. Builds on #204/#206/#207. Remaining: Phase 4 (install-time trust consent), the Linux launcher, and the packaged first-party-manifest bake.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:58:13Z",
          "mergedAt": "2026-07-04T08:58:30Z",
          "additions": 159,
          "deletions": 0,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 210,
          "url": "https://github.com/kungfu-systems/kungfu/pull/210",
          "title": "docs(governance): define provider-risk boundaries",
          "body": "Merge docs/open-source-provider-governance into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:58:22Z",
          "mergedAt": "2026-07-04T08:59:02Z",
          "additions": 281,
          "deletions": 0,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 420,
          "url": "https://github.com/kungfu-systems/buildchain/pull/420",
          "title": "chore(release): promote v2.4.9",
          "body": "## Summary\n- Promote alpha/v2/v2.4 to release/v2/v2.4 after Buildchain RC wrapper fix.\n- Stable release should publish Buildchain 2.4.9 and move v2/v2.4 refs.\n\n## Release intent\n- Channel: release\n- Source: alpha/v2/v2.4\n- Target: release/v2/v2.4\n- Alpha verified: 2.4.9-alpha.1\n\n## Verification\n- PR #417 merged after Verify and Build Surface Fixture passed.\n- PR #418 produced PR-stage RC artifacts and alpha promote-only resolved RC evidence.\n- Alpha finalization published npm alpha dist-tag 2.4.9-alpha.1 and moved v2.4-alpha.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T08:57:22Z",
          "mergedAt": "2026-07-04T08:59:48Z",
          "additions": 70,
          "deletions": 9,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 421,
          "url": "https://github.com/kungfu-systems/buildchain/pull/421",
          "title": "docs(governance): define provider-risk boundaries",
          "body": "Add public governance boundaries for trademarks, official services, and upstream provider compliance.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:00:50Z",
          "mergedAt": "2026-07-04T09:00:56Z",
          "additions": 281,
          "deletions": 0,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 422,
          "url": "https://github.com/kungfu-systems/buildchain/pull/422",
          "title": "Release v2.4.9",
          "body": "Create the generated version-state commit for v2.4.9.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:01:54Z",
          "mergedAt": "2026-07-04T09:03:52Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 423,
          "url": "https://github.com/kungfu-systems/buildchain/pull/423",
          "title": "Prepare v2.4.10-alpha.0",
          "body": "Create the generated version-state commit for v2.4.10-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:06:26Z",
          "mergedAt": "2026-07-04T09:08:00Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 211,
          "url": "https://github.com/kungfu-systems/kungfu/pull/211",
          "title": "feat(kfx): disclose the trust verdict at install time (ADR-0013 Phase 4)",
          "body": "`kungfu kfx install` extracted a package with no word about the trust it would run at — the install-time trust prompt ADR-0013 and `docs/extensions.md` called for. This discloses it, so the trust grant is informed.\n\n- A package is **first-party (trusted)** or **third-party (untrusted)** by source, never by the install path.\n- Each declared facet's consequence is stated at install:\n  - a **view** runs `node-integrated` (trusted) or `sandboxed-ipc` (untrusted, isolated + declared capabilities only);\n  - an **untrusted adapter will be REFUSED** at trace time — it runs in-process in the traced program and cannot be sandboxed, so only a source-verified first-party adapter may inject.\n- `kfx list` gains the same first-party/third-party marker (and a `trusted` field in `--json`).\n\n`first_party.is_first_party(key)` is the shared membership check; `test_kfx_trust_notice` covers trusted/untrusted × view/adapter. Reuses the frozen first-party set from #206.\n\nCompletes the ADR-0013 implementation surface (Phases 0-4): trust by verifiable origin, refuse untrusted in-process adapters, sandboxed transport, OS isolation, and now the install-time consent surface. Remaining follow-ups: the Linux launcher and the packaged first-party-manifest bake.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:08:42Z",
          "mergedAt": "2026-07-04T09:08:45Z",
          "additions": 89,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 425,
          "url": "https://github.com/kungfu-systems/buildchain/pull/425",
          "title": "fix(release): update default branch before pending version PR",
          "body": "## Summary\n- update release promotion so the active dev line becomes the GitHub default branch before returning a pending next-alpha version-state PR\n- add regression coverage for protected alpha branches that require a generated version-state PR\n- rebuild the promote-buildchain-ref action bundle\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check\n\nNo alpha promotion is requested for this change.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:28:12Z",
          "mergedAt": "2026-07-04T09:29:50Z",
          "additions": 119,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 213,
          "url": "https://github.com/kungfu-systems/kungfu/pull/213",
          "title": "feat(rewind): managed provider run emits a CostSnapshot event",
          "body": "run_managed launches codex/claude in structured-output mode, parses usage via the cost adapters, and emits a CostSnapshot journal event (msg_type 30008) bound to the run. Process runner + emit sink injected; fixture rewind-demo-managed-run proves the wiring flatbuffers-only.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:31:35Z",
          "mergedAt": "2026-07-04T09:31:41Z",
          "additions": 398,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 214,
          "url": "https://github.com/kungfu-systems/kungfu/pull/214",
          "title": "feat(capability): Linux OS sandbox launcher via bubblewrap (ADR-0013)",
          "body": "Implements the default-tier OS sandbox on **Linux**, so the isolation base is no longer macOS-only (Phase 3 shipped Seatbelt; Linux was explicitly refused).\n\n- `sandbox-launcher.ts` — on Linux, wrap the guest in **bubblewrap** (`bwrap --unshare-all --ro-bind / / --proc /proc --dev /dev --die-with-parent`): a read-only root (every write denied), an unshared empty network namespace (no network), its own user/pid/mount namespaces, dies with the parent. Inherited stdio is untouched, so the capability relay still flows. This is the practical unprivileged sandbox where raw namespaces are blocked (Ubuntu's AppArmor unprivileged-userns restriction) but bwrap is permitted; **if bwrap is absent the launch is refused, never run unconfined**.\n- `isOsSandboxSupported()` now reports Linux support by bwrap presence; the `kfx-demo-sandbox-launch` fixture runs on Linux too (skip logic moved into `parent.mjs`), and its denial assertions accept `OSError` (EPERM on Seatbelt, EROFS / no-route on bwrap).\n\n**Validated on real hardware (both platforms):**\n- macOS arm64: relay works, `/tmp` write → PermissionError, socket → PermissionError.\n- Linux (Ubuntu 24.04, kernel 6.8, bwrap): relay works through the sandbox, `/tmp` write denied, network denied, no leak file — the fixture's 3 assertions pass end-to-end.\n\nFollow-up remaining: the packaged first-party-manifest bake. Landlock (available on the kernel) could later add finer-grained read confinement; bwrap's read-only root is the coarse boundary the ADR records as residual risk.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:32:30Z",
          "mergedAt": "2026-07-04T09:34:12Z",
          "additions": 66,
          "deletions": 23,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 212,
          "url": "https://github.com/kungfu-systems/kungfu/pull/212",
          "title": "docs(governance): add PR risk checklist",
          "body": "## Summary\n\nAdd a lightweight governance risk checklist to the pull request template.\n\n## Verification\n\n- git diff --check\n- public leakage scan for Atlas/Codex/Claude/AI-maintenance/local paths\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR only updates the PR template so future changes surface these boundaries explicitly.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-04T09:22:35Z",
          "mergedAt": "2026-07-04T09:38:36Z",
          "additions": 14,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 424,
          "url": "https://github.com/kungfu-systems/buildchain/pull/424",
          "title": "docs(governance): add PR risk checklist",
          "body": "## Summary\n\nAdd a lightweight governance risk checklist to the pull request template.\n\n## Verification\n\n- git diff --check\n- public leakage scan for Atlas/Codex/Claude/AI-maintenance/local paths\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR only updates the PR template so future changes surface these boundaries explicitly.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-04T09:22:35Z",
          "mergedAt": "2026-07-04T09:38:40Z",
          "additions": 14,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 14,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/14",
          "title": "feat(trust): add public trust entrypoint",
          "body": "## Summary\n\nAdd a public trust page and homepage entrypoint for Kungfu's trust posture.\n\n## Changes\n\n- Add `/trust/index.html` with open source, local-first, release evidence, provider compliance, branding, and acceptable-use boundaries.\n- Link the trust page from the homepage.\n- Add a PR template with the governance risk checklist.\n- Extend build/check scripts to verify the trust page.\n\n## Verification\n\n- bash -n scripts/build-site.sh scripts/check-site.sh\n- bash scripts/build-site.sh\n- bash scripts/check-site.sh\n- git diff --check\n- public leakage scan for Atlas/AI-maintenance/local paths\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above",
          "author": "kungfu-origin",
          "createdAt": "2026-07-04T09:22:35Z",
          "mergedAt": "2026-07-04T09:38:43Z",
          "additions": 213,
          "deletions": 0,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 426,
          "url": "https://github.com/kungfu-systems/buildchain/pull/426",
          "title": "feat(release): complete promote-only native wrapper",
          "body": "## Summary\n- make release-candidate-promote.yml a complete promote-only native package wrapper\n- resolve, download, and validate PR-stage payload artifacts before promotion\n- generate or pass publish-required-artifacts-json and forward package set, dist-tag, trusted publishing, required status check, and release passport inputs\n- preserve build-free promotion semantics so channel merge reuses the PR-stage native matrix output\n\n## Validation\n- node --test tests/release-candidate.test.mjs tests/build-surface.test.mjs\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:42:26Z",
          "mergedAt": "2026-07-04T09:44:03Z",
          "additions": 309,
          "deletions": 8,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 215,
          "url": "https://github.com/kungfu-systems/kungfu/pull/215",
          "title": "feat(first-party): bake the frozen manifest for packaged/frozen builds (ADR-0013)",
          "body": "Closes the last ADR-0013 gap: a frozen CLI and a packaged app have no source `extensions/` tree, so the first-party set was empty and they trusted **only** system views (adapters all refused). Bake the manifest at build time and read it at runtime, so both grant trust by verifiable source.\n\n- **generation** — `gen-first-party-manifest.mjs` + an electron-builder `beforePack` hook write `first-party.json` into `dist/kungfu` (which ships to `Resources/kungfu`). The **pinned** build records each built view bundle's content hash; a key whose bundle is not built is **omitted** (stays untrusted) rather than trusted by key alone — an unpinned entry in a shipped manifest would be forgeable.\n- **frozen CLI read-path** — `first_party.py` resolves the set as `KF_FIRST_PARTY_MANIFEST`, then the manifest baked next to the executable, then a source scan (dev).\n- **packaged GUI** — main points the packaged manifest at `Resources/kungfu/first-party.json`.\n\n**Validated (units):** the generator pins built bundles and omits unbuilt ones; the beforePack hook bakes the manifest; the supervisor reads the baked manifest next to a (simulated) executable, with the env manifest taking precedence; TS typechecks, Python ruff-clean, pytest added. The full electron-builder package run is not exercised in CI here — the hook is proven in isolation.\n\nThis completes the ADR-0013 implementation surface end to end (design → decision C → Phases 0-4 → dual-platform OS isolation → packaged bake). Follow-up beyond trust: shipping built-in extensions to a read-only packaged location, and Landlock read-confinement on Linux.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:53:14Z",
          "mergedAt": "2026-07-04T09:53:17Z",
          "additions": 134,
          "deletions": 11,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 428,
          "url": "https://github.com/kungfu-systems/buildchain/pull/428",
          "title": "feat(release): derive npm RC required artifacts",
          "body": "## Summary\n- derive default npm publish-required-artifacts-json from downloaded PR-stage .tgz payloads\n- read package/package.json for real scoped package name/version and compute npm sha512 integrity from tarball bytes\n- mark publish-package-main as role=main and other npm tarballs as role=platform\n- keep release-candidate-promote.yml build-free and declarative for consumers\n\n## Validation\n- node --test tests/release-candidate.test.mjs tests/build-surface.test.mjs\n- corepack pnpm run check\n- bash scripts/check-workflows.sh\n\n## Release\n- dev-only per instruction; do not promote alpha/release yet",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:56:13Z",
          "mergedAt": "2026-07-04T09:57:53Z",
          "additions": 191,
          "deletions": 11,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 427,
          "url": "https://github.com/kungfu-systems/buildchain/pull/427",
          "title": "chore(release): promote v2.4 alpha",
          "body": "## Summary\n- promote dev/v2/v2.4 to alpha/v2/v2.4 after PR #426\n- publishes the Buildchain release-candidate promote wrapper changes through the alpha channel\n\n## Validation\n- dev/v2/v2.4 Verify succeeded on 012cdcde47b96e1d45715722e1988fe2434d08fc",
          "author": "dongkeren",
          "createdAt": "2026-07-04T09:45:36Z",
          "mergedAt": "2026-07-04T10:02:37Z",
          "additions": 904,
          "deletions": 14,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 216,
          "url": "https://github.com/kungfu-systems/kungfu/pull/216",
          "title": "fix(core): include <queue> in yijinjing journal.h",
          "body": "journal.h declares std::priority_queue has_data_journals_heap_ but only included <mutex>; it failed to compile on gcc/libstdc++ (priority_queue does not name a template type). Caught by a native core build on Linux. One-line include fix.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:03:20Z",
          "mergedAt": "2026-07-04T10:03:25Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 429,
          "url": "https://github.com/kungfu-systems/buildchain/pull/429",
          "title": "Prepare v2.4.10-alpha.1",
          "body": "Create the generated version-state commit for v2.4.10-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:04:48Z",
          "mergedAt": "2026-07-04T10:06:34Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 430,
          "url": "https://github.com/kungfu-systems/buildchain/pull/430",
          "title": "feat(release): dogfood RC promote wrapper",
          "body": "## Summary\n- route Buildchain self-promotion through the declarative release-candidate-promote reusable workflow\n- derive channel and target SHA in the wrapper so callers only pass release intent inputs\n- move workflow-friction reporting into the wrapper and update tests/inventory docs to forbid hand-wired resolver/promote steps\n\n## Verification\n- corepack pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:17:00Z",
          "mergedAt": "2026-07-04T10:18:48Z",
          "additions": 130,
          "deletions": 139,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 431,
          "url": "https://github.com/kungfu-systems/buildchain/pull/431",
          "title": "chore(release): promote v2.4 alpha",
          "body": "## Summary\n- promote dev/v2/v2.4 into alpha/v2/v2.4 after the dogfood RC promote wrapper change\n- this validates Buildchain self-promotion through declarative release-candidate-promote inputs\n\n## Verification\n- dev branch checks are green on PR #430\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:19:16Z",
          "mergedAt": "2026-07-04T10:21:23Z",
          "additions": 130,
          "deletions": 139,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 432,
          "url": "https://github.com/kungfu-systems/buildchain/pull/432",
          "title": "fix(release): allow self-promotion artifact reads",
          "body": "## Summary\n- grant actions: read to the Buildchain self-promotion caller so the declarative RC promote wrapper can resolve PR-stage artifacts\n- add inventory and unit coverage for that permission contract\n\n## Verification\n- bash scripts/check-workflows.sh\n- node scripts/check-inventory.mjs\n- node --test tests/build-surface.test.mjs\n- corepack pnpm run check\n\n## Notes\n- fixes the startup failure observed in Buildchain Ref Promotion run 28703197341 after PR #431 merged to alpha\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:25:31Z",
          "mergedAt": "2026-07-04T10:27:20Z",
          "additions": 3,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 433,
          "url": "https://github.com/kungfu-systems/buildchain/pull/433",
          "title": "chore(release): promote v2.4 alpha",
          "body": "## Summary\n- promote the self-promotion artifact-read permission fix into alpha/v2/v2.4\n- rerun Buildchain dogfood promotion through the declarative RC promote wrapper\n\n## Verification\n- dev branch PR #432 is green\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:27:41Z",
          "mergedAt": "2026-07-04T10:29:14Z",
          "additions": 3,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 435,
          "url": "https://github.com/kungfu-systems/buildchain/pull/435",
          "title": "fix(release): prepare package manager in promote wrapper",
          "body": "## Summary\n- install promotion dependencies inside release-candidate-promote.yml according to the declarative package-manager input\n- set Buildchain self dogfood to package-manager: pnpm without adding hand-wired setup or resolver steps\n- cover the wrapper setup and self dogfood declaration in build-surface tests\n\n## Verification\n- bash scripts/check-workflows.sh\n- node scripts/check-inventory.mjs\n- node --test tests/build-surface.test.mjs\n- corepack pnpm run check\n\n## Notes\n- follows up Buildchain Ref Promotion run 28703376291, where the wrapper resolved the PR-stage RC but failed because pnpm was not available for lifecycle.verify\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:33:23Z",
          "mergedAt": "2026-07-04T10:34:57Z",
          "additions": 40,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 436,
          "url": "https://github.com/kungfu-systems/buildchain/pull/436",
          "title": "chore(release): promote v2.4 alpha",
          "body": "## Summary\n- promote the package-manager preparation fix into alpha/v2/v2.4\n- rerun Buildchain self dogfood through release-candidate-promote.yml without hand-wired setup steps\n\n## Verification\n- dev branch PR #435 is green\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:35:18Z",
          "mergedAt": "2026-07-04T10:36:53Z",
          "additions": 40,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 437,
          "url": "https://github.com/kungfu-systems/buildchain/pull/437",
          "title": "Prepare v2.4.10-alpha.2",
          "body": "Create the generated version-state commit for v2.4.10-alpha.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:39:12Z",
          "mergedAt": "2026-07-04T10:40:59Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 217,
          "url": "https://github.com/kungfu-systems/kungfu/pull/217",
          "title": "feat(rewind): record human control decisions (ApprovalDecision, msg_type 30009)",
          "body": "ApprovalDecision open-layer event (30009): approve/deny/interrupt/resume recorded as a run fact; approvals.apply_decision returns the ControlAction a session driver applies (SIGINT / input). Provider approval-prompt detection is out of scope; interrupt/resume ride the terminal capability's kill/write. Fixture rewind-demo-approval + native-validatable.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:42:20Z",
          "mergedAt": "2026-07-04T10:42:24Z",
          "additions": 540,
          "deletions": 7,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 438,
          "url": "https://github.com/kungfu-systems/buildchain/pull/438",
          "title": "chore(release): promote v2.4.10",
          "body": "## Summary\n- promote alpha/v2/v2.4 to release/v2/v2.4 for Buildchain v2.4.10\n- includes declarative release-candidate-promote wrapper dogfood, npm artifact evidence generation, and self-promotion package-manager preparation\n\n## Verification\n- alpha promotion completed successfully through release-candidate-promote.yml\n- npm alpha dist-tag is 2.4.10-alpha.2\n- v2.4.10-alpha.2 and v2.4-alpha point at adba091\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:44:03Z",
          "mergedAt": "2026-07-04T10:45:55Z",
          "additions": 1078,
          "deletions": 154,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 218,
          "url": "https://github.com/kungfu-systems/kungfu/pull/218",
          "title": "build(core): prebuilt platform-package distribution + self-contained dist/kungfu",
          "body": "Ship @kungfu-tech/core prebuilt native binaries as npm platform packages: install becomes a no-op, build stages a self-contained dist/kungfu (bundling libnode), and the platform package packs it. Also decouples build from node-pre-gyp, fixes a Windows node-path space bug, stages versioned ELF sonames on linux, and de-vendors pybind11 (conan-provided). Validated on macOS arm64 and linux x64.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:48:25Z",
          "mergedAt": "2026-07-04T10:48:30Z",
          "additions": 528,
          "deletions": 18897,
          "changedFiles": 67
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 439,
          "url": "https://github.com/kungfu-systems/buildchain/pull/439",
          "title": "Release v2.4.10",
          "body": "Create the generated version-state commit for v2.4.10.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:47:50Z",
          "mergedAt": "2026-07-04T10:49:33Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 440,
          "url": "https://github.com/kungfu-systems/buildchain/pull/440",
          "title": "Prepare v2.4.11-alpha.0",
          "body": "Create the generated version-state commit for v2.4.11-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:52:04Z",
          "mergedAt": "2026-07-04T10:53:55Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 441,
          "url": "https://github.com/kungfu-systems/buildchain/pull/441",
          "title": "fix(release): use buildchain issue token for friction reports",
          "body": "## Summary\n- add an optional `buildchain-issue-token` reusable workflow secret for Buildchain-owned workflow-friction issue reporting\n- fallback issue reporting token through `BUILDCHAIN_PROMOTION_TOKEN` before `github.token`\n- document consumer mapping and add regression coverage so the report step cannot regress to fixed consumer `github.token`\n\n## Verification\n- corepack pnpm@11.7.0 run check:workflows\n- node --test tests/build-surface.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:25:35Z",
          "mergedAt": "2026-07-04T11:27:15Z",
          "additions": 24,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 442,
          "url": "https://github.com/kungfu-systems/buildchain/pull/442",
          "title": "release: promote Buildchain 2.4 issue-token fix to alpha",
          "body": "## Summary\n- promote the workflow-friction issue-token fix from dev to alpha\n- keeps release-candidate-promote issue reporting cross-repository capable\n\n## Verification\n- PR #441 checks passed\n- local `corepack pnpm@11.7.0 run check` passed before merge",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:27:43Z",
          "mergedAt": "2026-07-04T11:30:02Z",
          "additions": 24,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 444,
          "url": "https://github.com/kungfu-systems/buildchain/pull/444",
          "title": "fix(release): mint buildchain issue token from app credentials",
          "body": "## Summary\n- let `release-candidate-promote.yml` mint a Buildchain issue-report token from GitHub App credentials\n- keep explicit issue token / promotion token / `github.token` fallbacks for existing consumers\n- update wrapper docs so consumers pass declarative App credentials instead of hand-wiring token creation\n\n## Verification\n- corepack pnpm@11.7.0 run check:workflows\n- node --test tests/build-surface.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:34:36Z",
          "mergedAt": "2026-07-04T11:36:09Z",
          "additions": 71,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 443,
          "url": "https://github.com/kungfu-systems/buildchain/pull/443",
          "title": "Prepare v2.4.11-alpha.1",
          "body": "Create the generated version-state commit for v2.4.11-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:32:32Z",
          "mergedAt": "2026-07-04T11:36:53Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 219,
          "url": "https://github.com/kungfu-systems/kungfu/pull/219",
          "title": "fix(core): stage dist/kungfu completely on Windows",
          "body": "On Windows, run-build.js stage() staged nothing usable into dist/kungfu: single-config Ninja emits the addons into build/ (not build/<buildType>), glob.sync received a backslash path it treats as an escape, and *.pyd was missing from the pattern list. Search both build dirs on Windows, use glob's cwd option, and add *.pyd. Verified on a Windows self-hosted build: dist/kungfu now bundles kungfu_node.node, pykungfu.pyd, drone.node, link_node.node and libnode.dll. No behavior change on macOS/Linux.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:37:07Z",
          "mergedAt": "2026-07-04T11:37:12Z",
          "additions": 27,
          "deletions": 7,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 220,
          "url": "https://github.com/kungfu-systems/kungfu/pull/220",
          "title": "feat(rewind): managed-run CLI — run a provider and report its cost",
          "body": "One command joins the chain: discover the provider, run it under management (managed_run), bracket the run on a real journal (RunBegin/CostSnapshot/RunEnd), finalize a trace bundle, and print the cost with attribution + a proof path. Verified end to end against a real claude --print run.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:37:41Z",
          "mergedAt": "2026-07-04T11:37:45Z",
          "additions": 149,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 445,
          "url": "https://github.com/kungfu-systems/buildchain/pull/445",
          "title": "release: promote Buildchain issue app token support to alpha",
          "body": "## Summary\n- promote GitHub App-backed Buildchain issue token support into alpha\n- includes prior issue-token fallback fix plus wrapper-level App installation token creation\n\n## Verification\n- PR #444 checks passed\n- local `corepack pnpm@11.7.0 run check` passed",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:37:17Z",
          "mergedAt": "2026-07-04T11:40:58Z",
          "additions": 71,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 446,
          "url": "https://github.com/kungfu-systems/buildchain/pull/446",
          "title": "Prepare v2.4.11-alpha.2",
          "body": "Create the generated version-state commit for v2.4.11-alpha.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:43:34Z",
          "mergedAt": "2026-07-04T11:45:27Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 447,
          "url": "https://github.com/kungfu-systems/buildchain/pull/447",
          "title": "release: promote Buildchain 2.4.11",
          "body": "## Summary\n- promote Buildchain 2.4.11 to the stable release channel\n- includes `release-candidate-promote.yml` GitHub App-backed workflow-friction issue reporting\n- includes issue-token fallback support and docs/tests\n\n## Verification\n- PR #441 checks passed and merged\n- PR #444 checks passed and merged\n- PR #445 alpha promotion succeeded\n- alpha dist-tag is 2.4.11-alpha.2",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:47:22Z",
          "mergedAt": "2026-07-04T11:49:15Z",
          "additions": 86,
          "deletions": 4,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 448,
          "url": "https://github.com/kungfu-systems/buildchain/pull/448",
          "title": "Release v2.4.11",
          "body": "Create the generated version-state commit for v2.4.11.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:51:24Z",
          "mergedAt": "2026-07-04T11:53:05Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 449,
          "url": "https://github.com/kungfu-systems/buildchain/pull/449",
          "title": "Prepare v2.4.12-alpha.0",
          "body": "Create the generated version-state commit for v2.4.12-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:55:24Z",
          "mergedAt": "2026-07-04T11:57:03Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 221,
          "url": "https://github.com/kungfu-systems/kungfu/pull/221",
          "title": "docs(adr): ADR-0014 extension execution contract — uniform capability surface",
          "body": "Record the developer-facing execution contract on top of ADR-0013's trust boundary: one uniform asynchronous capability surface across trust tiers (one source runs unchanged in either tier), zero-copy preserved for the trusted tier via an in-process short-circuit, and restriction expressed as transparent interception rather than API removal so later confinement does not force extensions to be rewritten. Status proposed; implementation deferred to a follow-up.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T11:58:30Z",
          "mergedAt": "2026-07-04T11:58:35Z",
          "additions": 189,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 15,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/15",
          "title": "feat(layout): generate shared header and footer",
          "body": "## Summary\n\nGenerate the site header and footer from one shared layout source so the home and trust pages cannot drift independently.\n\n## Changes\n\n- Add `site/shared-layout.json` as the single source for brand, navigation, and footer content.\n- Add `scripts/render-shared-layout.mjs` to rewrite marked header/footer regions in each page.\n- Run the renderer from `scripts/build-site.sh` and validate drift from `scripts/check-site.sh`.\n- Update the home and trust pages to use shared header/footer markers and matching `site-*` layout classes.\n- Document the shared layout workflow in `README.md`.\n\n## Verification\n\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `bash -n scripts/build-site.sh scripts/check-site.sh`\n- `git diff --check`\n- Playwright DOM smoke on desktop home and mobile trust pages: one header, one footer, matching nav links, matching footer text, no horizontal overflow.\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, signed URLs, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis touches official site branding/navigation/footer presentation only. The shared source keeps the visible Kungfu brand, repository, feedback, trust, security, and footer text consistent across pages.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Site checks pass\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T10:45:48Z",
          "mergedAt": "2026-07-04T13:16:06Z",
          "additions": 237,
          "deletions": 26,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 222,
          "url": "https://github.com/kungfu-systems/kungfu/pull/222",
          "title": "feat(gui): managed-run inbox in the terminal + kungfu managed-run command",
          "body": "The GUI terminal opens on an inbox of managed-run profiles; picking one runs a provider under management and reports its cost. Adds the 'kungfu managed-run' console subcommand and reworks the terminal view into an inbox + run terminal. Verified end to end in the GUI against a real claude run.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T13:28:47Z",
          "mergedAt": "2026-07-04T13:28:52Z",
          "additions": 277,
          "deletions": 47,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 45,
          "url": "https://github.com/kungfu-systems/libnode/pull/45",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.9",
          "body": "Publish @kungfu-tech/libnode 22.22.3-kf.3-alpha.9 through the Buildchain v2 release-candidate promotion flow.\\n\\nThis PR includes the libnode-side migration to the stable Buildchain v2 release-candidate promote wrapper so the PR build produces the reusable release-candidate evidence and the alpha branch push promotes that evidence to npm without a second heavy build.\\n\\nExpected flow:\\n- one alpha channel PR: dev/v22/v22.22 -> alpha/v22/v22.22\\n- one three-platform Build workflow run\\n- Release - New Version promote-only publish after merge\\n\\nVerified before opening:\\n- corepack pnpm verify-package-source\\n- git diff --check\\n- npm official registry returns 404 for 22.22.3-kf.3-alpha.9 before publish\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T13:21:26Z",
          "mergedAt": "2026-07-04T13:40:24Z",
          "additions": 37,
          "deletions": 136,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 46,
          "url": "https://github.com/kungfu-systems/libnode/pull/46",
          "title": "ci: align release candidate artifact patterns",
          "body": "Fix the libnode-side Release - New Version declaration so Buildchain v2 release-candidate-promote can resolve the PR-stage payload artifacts produced by the Build workflow.\\n\\nProblem observed in Release - New Version run 28708019670 after PR #45 merged:\\n- Buildchain resolver expected at least 4 PR-stage payload artifacts but found 1.\\n- The PR Build run 28707537788 actually produced platform payload artifacts named libnode-macos-arm64-*, libnode-linux-x64-*, and libnode-windows-x64-*.\\n- The libnode wrapper had declared npm/os names libnode-darwin-arm64-* and libnode-win32-x64-* and required 4 payload containers.\\n\\nThis PR aligns the wrapper with the Buildchain artifact names and the three-platform payload count.\\n\\nThis is an extra PR caused by the previous libnode declaration bug; the prior three-platform Build run was already successful but the old alpha-side workflow could not promote it.\\n\\nVerified locally:\\n- actionlint .github/workflows/release-new-version.yml\\n- YAML parse\\n- git diff --check\\n- offline pattern check against PR #45 artifact names matched 3 payload artifacts\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T13:47:13Z",
          "mergedAt": "2026-07-04T14:10:12Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 223,
          "url": "https://github.com/kungfu-systems/kungfu/pull/223",
          "title": "feat(capability): uniform capability surface across trust tiers (ADR-0014 first delivery)",
          "body": "Assemble the binding-less guest host into one uniform asynchronous capability surface across trust tiers: the trusted co-resident tier short-circuits in-process and keeps zero-copy by reference, the default tier runs in an OS sandbox and reaches the host over the stdio relay (serialized copies). Adds the missing Node child-side guest proxy, a permissive first-delivery profile with independent write/network restriction knobs, and serializes relay frames with the bigint rule. Verified on macOS (Seatbelt) and Linux (bubblewrap): a JavaScript and a Python facet run unchanged in both tiers, and the restriction knobs narrow what a facet reaches without re-adapting it. ADR-0014 accepted.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T14:22:28Z",
          "mergedAt": "2026-07-04T14:22:33Z",
          "additions": 1132,
          "deletions": 67,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 47,
          "url": "https://github.com/kungfu-systems/libnode/pull/47",
          "title": "ci: test buildchain rc promote allow repository",
          "body": "Temporarily route Release - New Version through Buildchain train ref train/v2/v2.5/rc-promote-allow-repository so we can verify the release-candidate-promote allow-repository fix against libnode.\\n\\nContext:\\n- PR #46 fixed libnode artifact-pattern/count declaration.\\n- Release - New Version run 28708787668 resolved PR-stage RC evidence successfully but failed in promote-buildchain-ref with: Ref promotion is limited to kungfu-systems/buildchain; got kungfu-systems/libnode.\\n- The provided Buildchain train ref exposes allow-repository and defaults it to the caller repository.\\n\\nVerified locally:\\n- actionlint .github/workflows/release-new-version.yml\\n- YAML parse\\n- git diff --check\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T14:27:46Z",
          "mergedAt": "2026-07-04T14:54:31Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 224,
          "url": "https://github.com/kungfu-systems/kungfu/pull/224",
          "title": "refactor(core,api): remove legacy CLI commands and reduce api to the capability SDK",
          "body": "Remove the old quant-trading legacy: the login/backtest/run/assemble/tool/slicetool CLI commands and the serverless account module; the dead `cli` command (superseded by tui). Reduce @kungfu-tech/api to the capability SDK — the entire non-capability tree (trading config/data/stores, old-app config/utils/language/typings) is unused by v4 (gui/tui consume only /capability). Also fixes the guest-harness capability modules to build clean under the reference surfaces. @kungfu-tech/api, gui and tui all build clean.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T14:57:30Z",
          "mergedAt": "2026-07-04T14:57:35Z",
          "additions": 56,
          "deletions": 17374,
          "changedFiles": 86
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 453,
          "url": "https://github.com/kungfu-systems/buildchain/pull/453",
          "title": "feat(governance): add dev PR auto-merge workflow",
          "body": "## Summary\n- add a reusable dev PR auto-merge workflow for protected semver dev branches\n- add a Buildchain-owned policy engine for ready labels, block labels, approvals, required checks, same-repository heads, branch prefixes, max merges, dry-run, and sequential merge revalidation\n- document protected dev branch semantics and register the workflow in package-owned site facts\n\n## Verification\n- pnpm run check\n\n## Release line\n- target: dev/v2/v2.5\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T15:09:34Z",
          "mergedAt": "2026-07-04T15:11:34Z",
          "additions": 862,
          "deletions": 0,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 454,
          "url": "https://github.com/kungfu-systems/buildchain/pull/454",
          "title": "release: promote Buildchain 2.5 to alpha",
          "body": "Promote the reviewed Buildchain 2.5 development line into the alpha channel.\\n\\nRelease path:\\n- dev/v2/v2.5 -> alpha/v2/v2.5\\n- follow-up alpha/v2/v2.5 -> release/v2/v2.5 after alpha promotion completes\\n\\nValidation already completed on the dev PR and Buildchain fixture matrix; this PR intentionally uses the protected release-governance path so Buildchain Ref Promotion owns version-state, tags, passport, and npm trusted publishing evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T15:25:30Z",
          "mergedAt": "2026-07-04T15:27:31Z",
          "additions": 1076,
          "deletions": 60,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 457,
          "url": "https://github.com/kungfu-systems/buildchain/pull/457",
          "title": "release: promote Buildchain 2.5.0",
          "body": "Promote the tested Buildchain 2.5 alpha channel to the production release channel.\\n\\nRelease path:\\n- alpha/v2/v2.5 -> release/v2/v2.5\\n- tested alpha tag: v2.5.0-alpha.0\\n\\nBuildchain Ref Promotion owns the final version-state commit, exact v2.5.0 tag, floating v2.5/v2 refs, release passport, and next alpha preparation.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T15:30:37Z",
          "mergedAt": "2026-07-04T15:32:33Z",
          "additions": 1076,
          "deletions": 60,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 458,
          "url": "https://github.com/kungfu-systems/buildchain/pull/458",
          "title": "Release v2.5.0",
          "body": "Create the generated version-state commit for v2.5.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T15:34:52Z",
          "mergedAt": "2026-07-04T15:36:35Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 459,
          "url": "https://github.com/kungfu-systems/buildchain/pull/459",
          "title": "Prepare v2.5.1-alpha.0",
          "body": "Create the generated version-state commit for v2.5.1-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T15:39:12Z",
          "mergedAt": "2026-07-04T15:41:04Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 225,
          "url": "https://github.com/kungfu-systems/kungfu/pull/225",
          "title": "refactor: retire the dormant wingchun module",
          "body": "Remove the wingchun trading-semantics module end to end: the dead node-side instrument methods on Watcher, the entire pykungfu.wingchun binding surface, the headers-only src/libwingchun tree and its packaging manifest entries, and the disabled kungfu.wingchun python strategy framework with its unreferenced practice leaves. Core builds clean (configure/compile, 19/19 linked). Net 115 files, -32460.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T15:48:45Z",
          "mergedAt": "2026-07-04T15:48:50Z",
          "additions": 6,
          "deletions": 32460,
          "changedFiles": 115
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 460,
          "url": "https://github.com/kungfu-systems/buildchain/pull/460",
          "title": "fix: preserve Windows lifecycle sampler evidence",
          "body": "## Summary\n- make Windows process-tree sampling distinguish sampler unavailable from an empty process tree\n- capture wrapped lifecycle command stdout/stderr tails and exit evidence in process-summary and lifecycle error events\n- add regressions for Windows sampler fallback/unavailable state and sampled lifecycle failure evidence\n\n## Validation\n- pnpm run check\n\nNo consumer/libnode build was triggered.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T16:06:36Z",
          "mergedAt": "2026-07-04T16:15:35Z",
          "additions": 246,
          "deletions": 40,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 461,
          "url": "https://github.com/kungfu-systems/buildchain/pull/461",
          "title": "promote: dev to alpha v2.5",
          "body": "## Summary\nPromote the Windows lifecycle sampler evidence fix from dev/v2/v2.5 to alpha/v2/v2.5.\n\nIncludes PR #460: Windows process-tree sampler availability, wrapped command exit evidence, and Buildchain fixture dogfood for Windows descendants.\n\n## Validation\n- PR #460 check passed\n- PR #460 Build Surface Fixture passed on Linux/macOS/Windows\n- Windows diagnostics artifact: sampler unavailable=false, sampleCount=2, root cmd.exe with node descendant\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T16:16:07Z",
          "mergedAt": "2026-07-04T16:20:27Z",
          "additions": 246,
          "deletions": 40,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 462,
          "url": "https://github.com/kungfu-systems/buildchain/pull/462",
          "title": "Prepare v2.5.1-alpha.1",
          "body": "Create the generated version-state commit for v2.5.1-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T16:22:37Z",
          "mergedAt": "2026-07-04T16:24:27Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 463,
          "url": "https://github.com/kungfu-systems/buildchain/pull/463",
          "title": "release: promote Buildchain 2.5.1",
          "body": "## Summary\nPromote Buildchain v2.5.1 from alpha/v2/v2.5 to release/v2/v2.5.\n\nIncludes Windows lifecycle sampler fix from PR #460 and alpha version-state PR #462.\n\n## Validation\n- PR #460 Build Surface Fixture passed on Linux/macOS/Windows\n- Latest Windows diagnostics artifact: sampler unavailable=false, sampleCount=2, root cmd.exe with node descendant\n- Alpha promote-only publish completed: @kungfu-tech/buildchain alpha=2.5.1-alpha.1\n",
          "author": "dongkeren",
          "createdAt": "2026-07-04T16:24:51Z",
          "mergedAt": "2026-07-04T16:28:51Z",
          "additions": 247,
          "deletions": 41,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 464,
          "url": "https://github.com/kungfu-systems/buildchain/pull/464",
          "title": "Release v2.5.1",
          "body": "Create the generated version-state commit for v2.5.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T16:30:56Z",
          "mergedAt": "2026-07-04T16:32:56Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 465,
          "url": "https://github.com/kungfu-systems/buildchain/pull/465",
          "title": "Prepare v2.5.2-alpha.0",
          "body": "Create the generated version-state commit for v2.5.2-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T16:35:38Z",
          "mergedAt": "2026-07-04T16:37:24Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 226,
          "url": "https://github.com/kungfu-systems/kungfu/pull/226",
          "title": "feat: Windows AppContainer support for the sandbox membrane (ADR-0014)",
          "body": "Extend the uniform capability surface's default tier to Windows: the launcher applies an AppContainer via a native CreateProcess (libyijinjing spawn_app_container, exposed through the node binding), the host owns two named pipes as the relay, and the guest reaches the host over them. The full guest-host matrix runs green on Windows — a JavaScript and a Python facet, both trust tiers, over the AppContainer + named-pipe relay — alongside the existing macOS (Seatbelt) and Linux (bubblewrap) support. Includes the window-station grant a USER32-linked guest needs to initialize, link deps (userenv/advapi32/user32), and DeriveCapabilitySidsFromName resolved dynamically for SDK portability. Restriction knobs on Windows (network capability / write confinement) are a follow-up: AppContainer confines by capability and ACL rather than by syscall, which needs a further-restricted token to demonstrate write denial.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T22:36:28Z",
          "mergedAt": "2026-07-04T22:36:33Z",
          "additions": 844,
          "deletions": 26,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 227,
          "url": "https://github.com/kungfu-systems/kungfu/pull/227",
          "title": "refactor: fold the kfs SDK into the 'kungfu sdk' subcommand",
          "body": "Retire the standalone kfs command and reach the application-assembly toolkit as 'kungfu sdk': rename developer/sdk to sdk.js, add the sdk console subcommand (runs the SDK through embedded libnode like 'kungfu tui'), migrate every extension/example build to 'kungfu sdk kfx build', remove the kfs launcher/freeze chain (kungfu.spec/conanfile/run-freeze), and update docs, ADR-0009 and the welded-surface register. Net 44 files, +156 -221.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T23:54:26Z",
          "mergedAt": "2026-07-04T23:54:30Z",
          "additions": 156,
          "deletions": 221,
          "changedFiles": 44
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 228,
          "url": "https://github.com/kungfu-systems/kungfu/pull/228",
          "title": "refactor: rename the 'tui' command to 'cockpit'",
          "body": "Name the terminal reference surface by its experience: kungfu tui -> kungfu cockpit (an operator surface — monitor + config + mission ops). The Ink renderer stays the tui substrate (framework/tui, @kungfu-tech/tui, tui.mjs, Resources/tui); only the command/experience name changes. ~6 files, no package/dir/packaging changes.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T00:41:47Z",
          "mergedAt": "2026-07-05T00:41:52Z",
          "additions": 10,
          "deletions": 8,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 48,
          "url": "https://github.com/kungfu-systems/libnode/pull/48",
          "title": "ci: use stable buildchain v2 for release promotion",
          "body": "## Summary\n- remove the temporary Buildchain train runtime override\n- return release promotion to the stable floating Buildchain v2 wrapper\n\n## Validation\n- git diff --check\n- verified release-new-version.yml no longer contains buildchain-ref/train override\n\n## Release note\nThis PR is expected to trigger one Build PR-stage native matrix before alpha promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-04T15:43:35Z",
          "mergedAt": "2026-07-05T00:48:49Z",
          "additions": 0,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 229,
          "url": "https://github.com/kungfu-systems/kungfu/pull/229",
          "title": "refactor: retire the legacy indexer-live extension",
          "body": "indexer-live never migrated to v4: defunct 'kungfu sdk strategy/project' build verbs, no runtime caller for its slice-location hooks, unread useFor:replay manifest field, and a vestigial import of the removed pykungfu.wingchun binding. The rewind/replay path does not route through it. Remove the extension + its artifact dependency; no live capability affected.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T00:58:42Z",
          "mergedAt": "2026-07-05T00:58:46Z",
          "additions": 0,
          "deletions": 115,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 231,
          "url": "https://github.com/kungfu-systems/kungfu/pull/231",
          "title": "refactor: rename the kungfu.console package to kungfu.cli",
          "body": "The internal package is the CLI command-dispatch framework (commands/variants/bridging); 'console' reads ambiguously beside the cockpit operator surface. Rename kungfu.console -> kungfu.cli, updating every absolute import, the bridging run_module string, and two doc links. find_packages auto-discovers the package (packaging untouched); the runtime 'console' service location and PyInstaller's console flag are left alone. 34 files.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T01:21:54Z",
          "mergedAt": "2026-07-05T01:21:59Z",
          "additions": 23,
          "deletions": 23,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 230,
          "url": "https://github.com/kungfu-systems/kungfu/pull/230",
          "title": "fix(gui): ship a single core runtime in app bundle",
          "body": "## Summary\n- stop production packaging from copying workspace @kungfu-tech/core trees into the Electron app node_modules\n- ship the frozen runtime only from Contents/Resources/kungfu\n- add an afterPack bundle audit/prune hook and a manual audit:bundle command\n\n## Validation\n- ./kungfu-code build:core\n- ./kungfu-code freeze\n- ./kungfu-code package:app\n- ./kungfu-code verify\n- pnpm --filter @kungfu-tech/gui run audit:bundle -- framework/gui/dist/mac-arm64/Kungfu.app\n- packaged CLI entries returned 4.0.0-alpha.0\n- bounded GUI smoke loaded KFE_MAIN_OK\n\n## Bundle Result\n- Kungfu.app: 1.1G\n- Contents/Resources/kungfu: 744M\n- Contents/Resources/app: 32M\n- duplicate @kungfu-tech/core package trees: 0\n- .venv directories in app resources: 0\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T01:21:47Z",
          "mergedAt": "2026-07-05T01:22:43Z",
          "additions": 224,
          "deletions": 8,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 466,
          "url": "https://github.com/kungfu-systems/buildchain/pull/466",
          "title": "feat(patrol): add cadence patrol workflows",
          "body": "## Summary\n- add Buildchain patrol protocol workflow plus daily, weekly, and monthly reusable wrappers\n- dogfood the three cadence wrappers in Buildchain with scheduled/manual callers\n- add patrol engine tests, workflow contract tests, inventory coverage, and release governance docs\n\n## Verification\n- pnpm run check\n- daily/weekly/monthly local patrol dry-runs against dev/v2/v2.5\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:08:11Z",
          "mergedAt": "2026-07-05T02:09:59Z",
          "additions": 1014,
          "deletions": 2,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 467,
          "url": "https://github.com/kungfu-systems/buildchain/pull/467",
          "title": "chore(release): promote v2.5 patrol cadence to alpha",
          "body": "## Summary\n- Promote the patrol cadence workflow implementation from dev to alpha.\n\n## Release intent\n- Source: dev/v2/v2.5\n- Target: alpha/v2/v2.5\n- Expected promotion: next alpha for v2.5\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:10:47Z",
          "mergedAt": "2026-07-05T02:13:31Z",
          "additions": 1014,
          "deletions": 2,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 468,
          "url": "https://github.com/kungfu-systems/buildchain/pull/468",
          "title": "Prepare v2.5.2-alpha.1",
          "body": "Create the generated version-state commit for v2.5.2-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:15:57Z",
          "mergedAt": "2026-07-05T02:18:01Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 469,
          "url": "https://github.com/kungfu-systems/buildchain/pull/469",
          "title": "chore(release): promote v2.5.2 patrol cadence to stable",
          "body": "## Summary\n- Promote v2.5.2-alpha.1 to the stable v2.5 release line.\n\n## Release intent\n- Source: alpha/v2/v2.5\n- Target: release/v2/v2.5\n- Tested alpha: v2.5.2-alpha.1\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:20:36Z",
          "mergedAt": "2026-07-05T02:22:19Z",
          "additions": 1015,
          "deletions": 3,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 232,
          "url": "https://github.com/kungfu-systems/kungfu/pull/232",
          "title": "docs(skill): define Kungfu Skill architecture",
          "body": "## Summary\n- add ADR-0015 for Kungfu Skill as the agent context layer above kfx\n- add docs/skills.md covering SKILL.md minimal source, catalog/envelope injection, Node/Python manage modes, and kfx dependency composition\n- link the new design from README, docs/MAP.md, and ADR index\n\n## Validation\n- git diff --check\n\n## Risk\n- documentation only; implementation is explicitly marked as not yet landed",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:24:38Z",
          "mergedAt": "2026-07-05T02:25:40Z",
          "additions": 575,
          "deletions": 0,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 470,
          "url": "https://github.com/kungfu-systems/buildchain/pull/470",
          "title": "Release v2.5.2",
          "body": "Create the generated version-state commit for v2.5.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:24:09Z",
          "mergedAt": "2026-07-05T02:25:44Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 471,
          "url": "https://github.com/kungfu-systems/buildchain/pull/471",
          "title": "Prepare v2.5.3-alpha.0",
          "body": "Create the generated version-state commit for v2.5.3-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:28:12Z",
          "mergedAt": "2026-07-05T02:31:07Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 472,
          "url": "https://github.com/kungfu-systems/buildchain/pull/472",
          "title": "fix(patrol): allow weekly monthly reusable startup",
          "body": "## Summary\\n- grant weekly/monthly patrol wrappers the write-scoped permissions required by the shared patrol reusable core\\n- grant Buildchain weekly/monthly dogfood callers matching permissions so workflow_dispatch starts successfully\\n- add build-surface regression assertions for patrol wrapper and dogfood permissions\\n\\n## Verification\\n- node --test tests/build-surface.test.mjs tests/buildchain-patrol.test.mjs tests/dev-pr-auto-merge.test.mjs\\n- node scripts/check-inventory.mjs\\n- bash scripts/check-workflows.sh\\n- pnpm run check\\n\\n## Dogfood context\\n- daily dogfood dry-run passed on v2.5.2: run 28727207108\\n- weekly/monthly v2.5.2 dry-runs failed at startup because callers had read-only permissions while the nested reusable core requires write scopes",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:43:57Z",
          "mergedAt": "2026-07-05T02:45:47Z",
          "additions": 20,
          "deletions": 8,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 233,
          "url": "https://github.com/kungfu-systems/kungfu/pull/233",
          "title": "docs(skill): anchor skills in accountable agent work",
          "body": "## Summary\n- Anchor Kungfu Skills in accountable delegated agent work, not generic action-first agent skills.\n- Clarify that skill audit events belong to the responsibility trail / journal-backed proof model.\n- Keep the existing Skill -> catalog -> context envelope -> KFX trust gate architecture unchanged.\n\n## Verification\n- git diff --check\n- git show --check HEAD\n\n## Risk\n- Documentation-only change.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:44:54Z",
          "mergedAt": "2026-07-05T02:45:54Z",
          "additions": 29,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 473,
          "url": "https://github.com/kungfu-systems/buildchain/pull/473",
          "title": "Promote v2.5 patrol permission fix to alpha",
          "body": "## Summary\\n- promote the weekly/monthly patrol startup permission fix from dev to alpha\\n- required for Buildchain weekly/monthly dogfood workflow_dispatch to start successfully\\n\\n## Verification\\n- PR #472 checks passed\\n- dev/v2/v2.5 Verify run 28727318863 passed\\n- local pnpm run check passed before #472",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:46:57Z",
          "mergedAt": "2026-07-05T02:48:50Z",
          "additions": 20,
          "deletions": 8,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 474,
          "url": "https://github.com/kungfu-systems/buildchain/pull/474",
          "title": "Prepare v2.5.3-alpha.1",
          "body": "Create the generated version-state commit for v2.5.3-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:50:54Z",
          "mergedAt": "2026-07-05T02:52:47Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 475,
          "url": "https://github.com/kungfu-systems/buildchain/pull/475",
          "title": "Release v2.5.3 patrol permission fix",
          "body": "## Summary\\n- release Buildchain v2.5.3 with weekly/monthly patrol startup permission fix\\n- keeps daily/weekly/monthly dogfood wrappers startable when using the shared patrol core\\n\\n## Verification\\n- PR #472 checks passed\\n- local pnpm run check passed\\n- alpha promotion finalized as v2.5.3-alpha.1\\n- alpha/dev/v2.5 refs point at 10c00402f1e5500db3ed887881b6809ebdc3c635",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:55:26Z",
          "mergedAt": "2026-07-05T02:57:15Z",
          "additions": 21,
          "deletions": 9,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 476,
          "url": "https://github.com/kungfu-systems/buildchain/pull/476",
          "title": "Release v2.5.3",
          "body": "Create the generated version-state commit for v2.5.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T02:59:17Z",
          "mergedAt": "2026-07-05T03:01:15Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 477,
          "url": "https://github.com/kungfu-systems/buildchain/pull/477",
          "title": "Prepare v2.5.4-alpha.0",
          "body": "Create the generated version-state commit for v2.5.4-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T03:03:35Z",
          "mergedAt": "2026-07-05T03:05:35Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 234,
          "url": "https://github.com/kungfu-systems/kungfu/pull/234",
          "title": "feat(skill): add first Kungfu Skill CLI slice",
          "body": "## Summary\n- add framework/skill schemas, fixtures, and TypeScript helpers for SKILL.md-based Kungfu Skills\n- add Python skill parser/catalog/context registry plus kungfu skill validate/install/list/catalog/context/read/explain\n- add SDK skill scaffolding and update skill docs/ADR to first-slice implementation status\n\n## Verification\n- ./kungfu-code build:core\n- pnpm --filter @kungfu-tech/core run freeze\n- framework/core/dist/kungfu/kungfu --version\n- framework/core/dist/kungfu/kungfu -H /tmp/kungfu-skill-home skill validate framework/skill/fixtures/minimal --json\n- framework/core/dist/kungfu/kungfu -H /tmp/kungfu-skill-home skill context --path framework/skill/fixtures --source cli --manager python --json\n- framework/core/dist/kungfu/kungfu -H /tmp/kungfu-skill-home skill explain trace-failure-investigator --path framework/skill/fixtures --json\n- PYTHONPATH=framework/core/src/python uv run --frozen --project framework/core pytest framework/core/tests/python/test_skill.py\n- pnpm --filter @kungfu-tech/skill run build\n- uv run --frozen --project framework/core ruff check framework/core/src/python/kungfu/skill framework/core/src/python/kungfu/cli/commands/skill.py framework/core/tests/python/test_skill.py\n- node developer/sdk/src/sdk.js create skill /tmp/kungfu-skill-sdk-smoke --name \"Smoke Skill\"\n- ./kungfu-code verify\n\n## Follow-up scope\n- Node/Electron GUI manager injection\n- persistent audit events for advertised/read skills\n- kfx dependency install/dedup binding through the kfx registry\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T03:05:00Z",
          "mergedAt": "2026-07-05T03:05:37Z",
          "additions": 1108,
          "deletions": 44,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 478,
          "url": "https://github.com/kungfu-systems/buildchain/pull/478",
          "title": "fix(release): protect managed dev channel branches",
          "body": "## Summary\n- protect managed dev/alpha/release channel branches after Buildchain creates or advances them\n- require one approving review on managed channel branch protection\n- add promote-buildchain-ref coverage for created dev branch protection\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check\n- verified all current kungfu-systems dev branches require one approving review\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T04:05:28Z",
          "mergedAt": "2026-07-05T04:07:20Z",
          "additions": 218,
          "deletions": 47,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 235,
          "url": "https://github.com/kungfu-systems/kungfu/pull/235",
          "title": "feat(kfx-sandbox): Windows AppContainer restriction knobs — external-egress network observable + container-SID write-ACE deny-write",
          "body": "Windows AppContainer restriction knobs for the kfx sandbox (ADR-0014):\n\n- deny-network: an external-egress observable (short-timeout connect to TEST-NET 192.0.2.1) — the internetClient capability gates external egress only, so loopback and interface-presence both miss it; run-knobs uses this observable on win32.\n- deny-write: governed by the container SID's own write ACE (a lowbox token does not honour the user's own ACEs). The launcher passes the guest a scratch dir and grants the container SID write on it only under a permissive profile; deny-write leaves it ungranted so the write is refused. The runtime's TEMP is redirected to the AppContainer's own folder so it starts under every profile.\n- read-path ACLs codified into the launcher (grant the container SID read+execute on the interpreter/guest dirs + ancestor traverse), removing the need for manual icacls.\n- host fail-fast: the Windows host no longer deadlocks if a guest exits before connecting its relay pipes.\n\nFollow-up (tracked separately): named-pipe relay handshake robustness and deny-network guest startup under empty capabilities.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T05:06:03Z",
          "mergedAt": "2026-07-05T05:06:08Z",
          "additions": 393,
          "deletions": 27,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 236,
          "url": "https://github.com/kungfu-systems/kungfu/pull/236",
          "title": "docs: add facts before trust philosophy",
          "body": "## Summary\n- add docs/facts-before-trust.md as a public, engineering-facing philosophy article\n- link it from README, docs/MAP.md, and docs/design-philosophy.md\n- keep the public framing focused on facts before trust and local proof before control\n\n## Validation\n- git diff --check\n- verified facts-before-trust links resolve from README, docs/MAP.md, and docs/design-philosophy.md\n- checked public docs for Atlas / AI-maintenance leakage terms",
          "author": "dongkeren",
          "createdAt": "2026-07-05T05:35:07Z",
          "mergedAt": "2026-07-05T05:35:45Z",
          "additions": 167,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 237,
          "url": "https://github.com/kungfu-systems/kungfu/pull/237",
          "title": "feat(skill): inject context into managed runs",
          "body": "## Summary\n- add shared Python and TypeScript Skill context providers with on-demand prompt injection\n- let CLI managed-run build Python contexts and accept Node-generated context files\n- let Electron main write a GUI-managed Skill context envelope for child managed runs\n- add golden fixtures that keep Python and Node catalog/context envelopes schema-equivalent\n\n## Verification\n- PYTHONPATH=framework/core/src/python uv --project framework/core run python -m pytest framework/core/tests/python/test_skill.py -q\n- pnpm --filter @kungfu-tech/skill run test:golden\n- pnpm --filter @kungfu-tech/gui run build\n- pnpm --filter @kungfu-tech/tui run build\n- ./kungfu-code build:core\n- ./kungfu-code freeze\n- framework/core/dist/kungfu/kungfu --version\n- framework/core/dist/kungfu/kungfu --home /tmp/kf-skill-smoke skill context --path framework/skill/fixtures/minimal --json\n- framework/core/dist/kungfu/kungfu managed-run --help\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T05:55:58Z",
          "mergedAt": "2026-07-05T05:57:19Z",
          "additions": 625,
          "deletions": 16,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 479,
          "url": "https://github.com/kungfu-systems/buildchain/pull/479",
          "title": "feat(build): add S3 artifact relay transfer mode",
          "body": "## Summary\n\n- add opt-in `artifact-transfer-mode: s3-to-github-artifacts` to the reusable Buildchain build workflow\n- upload heavy platform payloads from build runners to S3, then rehydrate and verify them on a GitHub-hosted relay job before uploading standard GitHub artifacts\n- keep default `github-artifacts` behavior unchanged for forks and ordinary consumers\n- add Buildchain dogfood dispatch support for the relay mode through declarative workflow inputs\n- document org/repo variable and OIDC role configuration without hard-coding Kungfu private values\n\n## AWS/organization setup\n\n- Created AWS China bucket `kungfu-buildchain-artifact-relay` in `cn-north-1`.\n- Enabled public access block, SSE-S3 encryption, and 7-day lifecycle cleanup for `buildchain-artifacts/`.\n- Added GitHub OIDC China audience `sts.amazonaws.com.cn` to the existing provider.\n- Created OIDC roles `BuildchainArtifactRelayUpload` and `BuildchainArtifactRelayDownload` scoped to `repo:kungfu-systems/*:*` and the relay bucket prefix.\n- Set `kungfu-systems` org variables for bucket, region, prefix, role ARNs, and OIDC audience.\n\n## Validation\n\n- `node --check scripts/artifact-relay-s3.mjs`\n- `node --test tests/build-surface.test.mjs`\n- `bash scripts/check-workflows.sh`\n- `pnpm run check`\n- AWS read-only verification of OIDC audience, S3 public access block, bucket encryption, and lifecycle configuration\n\n## Risk\n\n- Relay mode is opt-in and fails before heavy matrix scheduling if bucket/region/role configuration is missing.\n- S3 objects are deleted only after GitHub artifact upload succeeds; failed relay runs retain objects for investigation and lifecycle cleanup removes stale payloads later.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T05:58:44Z",
          "mergedAt": "2026-07-05T06:12:51Z",
          "additions": 1096,
          "deletions": 7,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 480,
          "url": "https://github.com/kungfu-systems/buildchain/pull/480",
          "title": "release: promote dev v2.5 to alpha",
          "body": "Promote dev/v2/v2.5 to alpha/v2/v2.5 for the S3 artifact relay release.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:13:30Z",
          "mergedAt": "2026-07-05T06:15:24Z",
          "additions": 1314,
          "deletions": 54,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 482,
          "url": "https://github.com/kungfu-systems/buildchain/pull/482",
          "title": "fix: derive release candidate channel from PR base",
          "body": "Fix release-candidate generation for channel PR builds by deriving alpha/release/major from the PR base ref when publish-channel remains none.\\n\\nValidation:\\n- bash scripts/check-workflows.sh\\n- node --test tests/build-surface.test.mjs",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:18:16Z",
          "mergedAt": "2026-07-05T06:20:03Z",
          "additions": 24,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 484,
          "url": "https://github.com/kungfu-systems/buildchain/pull/484",
          "title": "chore: record alpha channel merge in dev topology",
          "body": "No file content changes. This records the already-merged alpha channel commit as a dev parent so the next dev/v2/v2.5 -> alpha/v2/v2.5 promotion PR is mergeable after the failed RC-passport promotion attempt.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:23:21Z",
          "mergedAt": "2026-07-05T06:26:24Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 483,
          "url": "https://github.com/kungfu-systems/buildchain/pull/483",
          "title": "release: promote dev v2.5 to alpha",
          "body": "Promote dev/v2/v2.5 to alpha/v2/v2.5 after the artifact relay and release-candidate channel derivation fixes.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:20:16Z",
          "mergedAt": "2026-07-05T06:28:14Z",
          "additions": 24,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 485,
          "url": "https://github.com/kungfu-systems/buildchain/pull/485",
          "title": "Prepare v2.5.4-alpha.1",
          "body": "Create the generated version-state commit for v2.5.4-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:30:19Z",
          "mergedAt": "2026-07-05T06:32:09Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 486,
          "url": "https://github.com/kungfu-systems/buildchain/pull/486",
          "title": "Release v2.5.4 artifact relay",
          "body": "Promote alpha/v2/v2.5 to release/v2/v2.5 after alpha publish of @kungfu-tech/buildchain@2.5.4-alpha.1.\\n\\nIncludes S3 artifact relay transfer mode, RC channel derivation, and the dev/alpha topology repair needed for the stable release path.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:33:09Z",
          "mergedAt": "2026-07-05T06:36:19Z",
          "additions": 1338,
          "deletions": 56,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 487,
          "url": "https://github.com/kungfu-systems/buildchain/pull/487",
          "title": "Release v2.5.4",
          "body": "Create the generated version-state commit for v2.5.4.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:38:26Z",
          "mergedAt": "2026-07-05T06:40:26Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 489,
          "url": "https://github.com/kungfu-systems/buildchain/pull/489",
          "title": "Fix release finalization non-fast-forward recovery",
          "body": "Fix Buildchain release finalization when the generated next-alpha commit cannot fast-forward the alpha channel ref.\\n\\nThe action now routes protected channel non-fast-forward updates through a generated version-state PR instead of failing after npm publish. This addresses workflow friction issue #488.\\n\\nValidation:\\n- node --test tests/promote-buildchain-ref.test.mjs\\n- bash scripts/check-workflows.sh\\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:47:41Z",
          "mergedAt": "2026-07-05T06:51:04Z",
          "additions": 156,
          "deletions": 44,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 490,
          "url": "https://github.com/kungfu-systems/buildchain/pull/490",
          "title": "chore(release): restore v2.5 channel topology",
          "body": "Restore v2.5 channel ancestry after the release channel had diverged from dev/alpha.\\n\\nThis PR intentionally keeps dev content unchanged while making alpha/v2/v2.5 and release/v2/v2.5 ancestors of dev again so future alpha/release promotions can finalize with normal fast-forward semantics.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:52:01Z",
          "mergedAt": "2026-07-05T06:53:43Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 491,
          "url": "https://github.com/kungfu-systems/buildchain/pull/491",
          "title": "release: promote v2.5.5 alpha",
          "body": "Promote the v2.5 line from dev to alpha with the release finalization recovery fix and S3 artifact relay support.\\n\\nThis keeps the release candidate path on the standard Buildchain channel workflow before stable promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:54:28Z",
          "mergedAt": "2026-07-05T06:56:18Z",
          "additions": 157,
          "deletions": 45,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 492,
          "url": "https://github.com/kungfu-systems/buildchain/pull/492",
          "title": "Prepare v2.5.5-alpha.0",
          "body": "Create the generated version-state commit for v2.5.5-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:58:25Z",
          "mergedAt": "2026-07-05T07:00:22Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 495,
          "url": "https://github.com/kungfu-systems/buildchain/pull/495",
          "title": "chore(release): make release ancestry visible to alpha",
          "body": "Repair the v2.5 channel graph after earlier squash-based channel promotion.\\n\\nThis PR keeps alpha content unchanged while making release/v2/v2.5 an ancestor of alpha/v2/v2.5 so the real alpha -> release promotion PR can merge cleanly and still satisfy Buildchain lineage rules.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:07:56Z",
          "mergedAt": "2026-07-05T07:09:43Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 493,
          "url": "https://github.com/kungfu-systems/buildchain/pull/493",
          "title": "release: promote v2.5.5 to stable",
          "body": "Promote Buildchain v2.5.5 from alpha to release.\\n\\nThis release includes first-class S3 artifact relay support and release finalization recovery for non-fast-forward next-alpha updates. The channel merge must use a merge commit to preserve alpha lineage.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:01:29Z",
          "mergedAt": "2026-07-05T07:11:38Z",
          "additions": 157,
          "deletions": 45,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 496,
          "url": "https://github.com/kungfu-systems/buildchain/pull/496",
          "title": "Prepare v2.5.5-alpha.1",
          "body": "Create the generated version-state commit for v2.5.5-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:11:53Z",
          "mergedAt": "2026-07-05T07:14:31Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 498,
          "url": "https://github.com/kungfu-systems/buildchain/pull/498",
          "title": "Release v2.5.5",
          "body": "Create the generated version-state commit for v2.5.5.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:13:36Z",
          "mergedAt": "2026-07-05T07:15:26Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 239,
          "url": "https://github.com/kungfu-systems/kungfu/pull/239",
          "title": "docs: state fact-first product goal",
          "body": "## Summary\n- state the product goal in README: make fact-first responsibility the path of least resistance\n- add a Product Goal section to docs/facts-before-trust.md\n- connect the goal from docs/design-philosophy.md\n\n## Validation\n- git diff --check\n- checked the public docs patch for Atlas or AI-maintenance leakage terms",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:16:27Z",
          "mergedAt": "2026-07-05T07:17:18Z",
          "additions": 34,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 238,
          "url": "https://github.com/kungfu-systems/kungfu/pull/238",
          "title": "feat(gui,terminal): managed session workspace with main-process host (ADR-0016 stage 1)",
          "body": "Multi-pane managed session workspace in the GUI: run and watch several PTY-backed agent sessions on one screen. Adds the tmux durability backend to the terminal capability (detach/discover/reattach), runs the session host in the main process behind KF_TERMINAL_HOST=main (ADR-0016 stage 1), persists and restores the workspace layout, and fixes real-app blockers found on device (renderer node: bundling, discover race, sizing, and loading each kfx view's sibling stylesheet).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T06:51:27Z",
          "mergedAt": "2026-07-05T07:19:45Z",
          "additions": 1955,
          "deletions": 225,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 500,
          "url": "https://github.com/kungfu-systems/buildchain/pull/500",
          "title": "fix(release): bind finalization to transaction alpha source",
          "body": "## Summary\n- bind release finalization to the alpha source recorded by the durable release transaction\n- avoid selecting a later next-alpha tag when stable release-state finalization resumes after next-alpha has advanced\n- add a regression test for the 2.5.5 finalization failure mode\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- bash scripts/check-workflows.sh\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:26:06Z",
          "mergedAt": "2026-07-05T07:27:53Z",
          "additions": 245,
          "deletions": 50,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 501,
          "url": "https://github.com/kungfu-systems/buildchain/pull/501",
          "title": "chore(release): restore v2.5 channel topology after v2.5.5",
          "body": "## Summary\n- restore dev channel ancestry after v2.5.5 alpha/release promotions\n- keep dev tree content unchanged with an ours merge so subsequent promotions satisfy lineage checks\n\n## Validation\n- git merge-base ancestry checks before/after topology merge",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:29:16Z",
          "mergedAt": "2026-07-05T07:31:03Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 502,
          "url": "https://github.com/kungfu-systems/buildchain/pull/502",
          "title": "release: promote dev v2.5 to alpha",
          "body": "## Summary\n- promote current dev/v2/v2.5 to alpha after S3 artifact relay and release-finalization fixes\n\n## Notes\n- uses the protected dev-to-alpha channel PR path\n- no consumer repository build is triggered",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:31:27Z",
          "mergedAt": "2026-07-05T07:33:09Z",
          "additions": 246,
          "deletions": 51,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 503,
          "url": "https://github.com/kungfu-systems/buildchain/pull/503",
          "title": "Prepare v2.5.5-alpha.2",
          "body": "Create the generated version-state commit for v2.5.5-alpha.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:35:24Z",
          "mergedAt": "2026-07-05T07:37:15Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 240,
          "url": "https://github.com/kungfu-systems/kungfu/pull/240",
          "title": "fix(deps): update vulnerable toolchain packages",
          "body": "## Summary\n- update Python dependency floors for current advisory fixes in framework/core\n- upgrade GUI build tooling to Vite 6 and electron-vite 5\n- move vulnerable tar/js-yaml transitive edges to patched versions through pnpm workspace overrides\n- refresh uv and pnpm lockfiles\n\n## Validation\n- `uv lock --check`\n- `./kungfu-code audit --audit-level low` reports no known vulnerabilities\n- `git diff --check`\n- package JSON parse check for root, framework/core, and framework/gui manifests\n\n## Known blocker\n- `./kungfu-code install --frozen-lockfile --lockfile-only` still fails because `framework/core/package.json` references unpublished optional packages: `@kungfu-tech/core-darwin-arm64`, `@kungfu-tech/core-linux-x64`, and `@kungfu-tech/core-win32-x64` at `4.0.0-alpha.0`. This is separate from the vulnerability updates and blocks full `build:app` validation in the current local mirror/registry state.\n\n## Risk\n- Vite/electron-vite and Python packaging tools move across major versions; follow-up GUI/core build validation is needed after the optional platform package issue is resolved.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:36:57Z",
          "mergedAt": "2026-07-05T07:37:54Z",
          "additions": 1092,
          "deletions": 987,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 504,
          "url": "https://github.com/kungfu-systems/buildchain/pull/504",
          "title": "release: promote v2.5.5 to stable",
          "body": "## Summary\n- promote current alpha/v2/v2.5 to release/v2/v2.5\n- includes S3 artifact relay support and release finalization alpha-source fix\n\n## Notes\n- merge via protected alpha-to-release channel PR\n- promote-only path should reuse PR-stage release candidate evidence",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:37:42Z",
          "mergedAt": "2026-07-05T07:39:25Z",
          "additions": 246,
          "deletions": 51,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 1,
          "url": "https://github.com/kungfu-systems/kfd/pull/1",
          "title": "docs: add fact-first accountability KFD",
          "body": "## What\n\nAdds KFD-2 as the organization-level principle for fact-first product accountability: responsibility should be the path of least resistance.\n\nAlso extends the KFD registry model with `kind` so entries can distinguish principles from procedures. KFD-1 is marked as a procedure; KFD-2 is marked as a principle and explicitly does not supersede KFD-1.\n\n## Registry agreement\n\n- [x] `node scripts/check.mjs` passes\n- [x] `npm run check` passes\n- [x] Decision texts remain append-only; supersession over rewrite\n\n## Version impact (per KFD-1)\n\n- [x] minor-impact registry schema additive (`kind`)\n- [ ] patch-only content operation\n- [ ] major machine surface breakage\n\n## Notes\n\nNewer KFD numbers do not implicitly override older decisions. Supersession or override must be explicit in the later KFD and recorded in `registry.json`; otherwise conflicting active KFDs are a registry defect.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:39:04Z",
          "mergedAt": "2026-07-05T07:40:02Z",
          "additions": 162,
          "deletions": 9,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 507,
          "url": "https://github.com/kungfu-systems/buildchain/pull/507",
          "title": "fix(release): title generated version-state PRs",
          "body": "## Summary\n- default generated version-state fallback PR title/body before GitHub API creation\n- pass explicit protected-update PR metadata for alpha, release, and major finalization branch updates\n- cover protected dev finalization with a unit test\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:48:27Z",
          "mergedAt": "2026-07-05T07:50:16Z",
          "additions": 72,
          "deletions": 40,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 508,
          "url": "https://github.com/kungfu-systems/buildchain/pull/508",
          "title": "chore(release): restore v2.5 channel topology",
          "body": "## Summary\n- restore dev/v2/v2.5 ancestry over the current alpha and release channel heads\n- keep the tree exactly on current dev; this is a topology-only merge before the next alpha/release promotion\n\n## Validation\n- topology-only merge using -s ours\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:51:09Z",
          "mergedAt": "2026-07-05T07:52:51Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 509,
          "url": "https://github.com/kungfu-systems/buildchain/pull/509",
          "title": "release: promote v2.5 dev to alpha",
          "body": "## Summary\n- promote current dev/v2/v2.5 to alpha/v2/v2.5\n- includes S3 artifact relay support and release finalization fixes\n\n## Validation\n- PR checks\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-05T07:53:02Z",
          "mergedAt": "2026-07-05T07:54:44Z",
          "additions": 73,
          "deletions": 41,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 242,
          "url": "https://github.com/kungfu-systems/kungfu/pull/242",
          "title": "feat(rewind): capture managed-run responses",
          "body": "## Summary\n\n- Capture provider response text for `kungfu managed-run` and emit a Supervisor-layer `ModelResponse` (`msg_type 30004`) next to the existing `CostSnapshot`.\n- Write a hash-bound `response.json` sidecar into the Rewind bundle manifest and expose `--print-response` for provider smoke tests.\n- Cover both `codex exec --json` and `claude --print --output-format json` response extraction paths in the managed-run fixture.\n- Allow the newly introduced `electron-winstaller` install script in pnpm `allowBuilds`; inspected script only selects the host-arch 7z vendor binary, which preserves GUI/Windows packaging behavior.\n\n## Verification\n\n- `uv --project framework/core run ruff check framework/core/src/python/kungfu/rewind/managed_run.py framework/core/src/python/kungfu/rewind/managed_cli.py framework/core/src/python/kungfu/cli/commands/managed_run.py tests/fixtures/rewind-demo-managed-run/check_managed_run.py`\n- `uv --project framework/core run python tests/fixtures/rewind-demo-managed-run/check_managed_run.py tests/fixtures/rewind-demo-managed-run`\n- `PYTHONPATH=framework/core/src/python uv --project framework/core run pytest framework/core/tests/python/test_skill.py`\n- `git diff --check`\n- `./kungfu-code build:core`\n- `./kungfu-code freeze`\n- `./kungfu-code verify`\n- `framework/core/dist/kungfu/kungfu managed-run --help | rg -- '--print-response|--skill-path|--provider'`\n- Real Claude managed-run with `framework/skill/fixtures/minimal`: response sidecar and journal `ModelResponse` contain `kungfu.skill-context/v1` and the advertised skill hash.\n- Real Codex managed-run with `framework/skill/fixtures/minimal`: response sidecar and journal `ModelResponse` contain `kungfu.skill-context/v1` and the advertised skill hash.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:01:37Z",
          "mergedAt": "2026-07-05T08:02:58Z",
          "additions": 273,
          "deletions": 6,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 511,
          "url": "https://github.com/kungfu-systems/buildchain/pull/511",
          "title": "fix(release): skip stale published alpha state",
          "body": "## Summary\n- treat stale alpha durable state with published material as occupied\n- let alpha promotion choose the next prerelease instead of reusing an already-published npm version\n- cover stale published alpha state with a unit test\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm --filter \"./actions/promote-buildchain-ref\" build\n- pnpm run check\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:02:13Z",
          "mergedAt": "2026-07-05T08:03:57Z",
          "additions": 211,
          "deletions": 62,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 512,
          "url": "https://github.com/kungfu-systems/buildchain/pull/512",
          "title": "chore(release): restore v2.5 topology after alpha retry",
          "body": "## Summary\n- restore dev/v2/v2.5 ancestry over the current alpha and release channel heads after the failed alpha retry\n- keep the tree exactly on current dev before re-promoting alpha\n\n## Validation\n- topology-only merge using -s ours\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:04:25Z",
          "mergedAt": "2026-07-05T08:06:07Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 513,
          "url": "https://github.com/kungfu-systems/buildchain/pull/513",
          "title": "release: promote v2.5 dev to alpha",
          "body": "## Summary\n- retry v2.5 dev to alpha promotion after stale published alpha-state fix\n- includes S3 artifact relay support and release finalization recovery fixes\n\n## Validation\n- PR checks\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:06:20Z",
          "mergedAt": "2026-07-05T08:08:04Z",
          "additions": 211,
          "deletions": 62,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 243,
          "url": "https://github.com/kungfu-systems/kungfu/pull/243",
          "title": "fix(kfx-sandbox): fix the Windows AppContainer relay spawn hang",
          "body": "Root-cause and fix the intermittent Windows AppContainer relay spawn hang: ancestor traverse ACL grants on large user-profile directories (C:\\Users\\<user>, AppData) triggered NTFS inheritance re-propagation and blocked spawn synchronously. Skip ancestor grants where ALL APPLICATION PACKAGES already has traverse. Also harden the host relay handshake (listen-readiness, timeout, retry). Verified on a real Windows machine: the knob matrix (permissive/denyWrite/denyNetwork) runs green in one pass and the js/py x trusted/sandbox matrix is 4/4 green, both without manual icacls.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:08:01Z",
          "mergedAt": "2026-07-05T08:08:05Z",
          "additions": 266,
          "deletions": 101,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 515,
          "url": "https://github.com/kungfu-systems/buildchain/pull/515",
          "title": "feat(release): add surface-aware impact classification",
          "body": "## Summary\n- add surface-aware release impact fields to release passports (`versionImpact` and `surfaceImpacts`)\n- verify that the final version impact matches the highest declared surface impact\n- expose surface impact rationale through release explanation output\n- document the KFD registry schema case where content remains patch but an additive machine registry schema change requires minor-impact review\n\n## Validation\n- `node --test tests/release-passport.test.mjs`\n- `pnpm run check`\n\n## Release impact\nMinor-impact release governance surface: this adds additive release passport / impact ledger fields and validation while preserving existing passport consumers.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:10:52Z",
          "mergedAt": "2026-07-05T08:12:57Z",
          "additions": 315,
          "deletions": 80,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 516,
          "url": "https://github.com/kungfu-systems/buildchain/pull/516",
          "title": "fix(release): ignore published alpha history states",
          "body": "## Summary\n\n- prevent published alpha durable states from being resumed only because their transaction commit is in channel history\n- keep ancestry-based recovery for unpublished material, but require exact source/material matches once artifacts or evidence exist\n- add regression coverage for stale published alpha state selection\n\n## Validation\n\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm --filter \"./actions/promote-buildchain-ref\" build\n- pnpm run check\n- git diff --check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:16:34Z",
          "mergedAt": "2026-07-05T08:18:26Z",
          "additions": 64,
          "deletions": 62,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 517,
          "url": "https://github.com/kungfu-systems/buildchain/pull/517",
          "title": "chore(release): restore v2.5 topology after alpha history",
          "body": "## Summary\n\n- merge the current alpha/v2/v2.5 channel history back into dev/v2/v2.5 using the ours strategy\n- preserve release topology after a failed alpha promotion attempt without changing files\n\n## Validation\n\n- git merge -s ours --no-ff origin/alpha/v2/v2.5\n- git status --short\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:19:16Z",
          "mergedAt": "2026-07-05T08:21:02Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 518,
          "url": "https://github.com/kungfu-systems/buildchain/pull/518",
          "title": "release: promote v2.5 dev to alpha",
          "body": "## Summary\n\n- promote dev/v2/v2.5 to alpha/v2/v2.5 after S3 artifact relay and release-state fixes\n- expected path is promote-only, reusing PR-stage evidence and avoiding an extra heavy native matrix after merge\n\n## Validation\n\n- dev channel PR checks and Buildchain dogfood passed before merge\n- topology restored via #517\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:21:26Z",
          "mergedAt": "2026-07-05T08:23:09Z",
          "additions": 339,
          "deletions": 102,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 519,
          "url": "https://github.com/kungfu-systems/buildchain/pull/519",
          "title": "Prepare v2.5.5-alpha.3",
          "body": "Create the generated version-state commit for v2.5.5-alpha.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:25:18Z",
          "mergedAt": "2026-07-05T08:27:09Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 520,
          "url": "https://github.com/kungfu-systems/buildchain/pull/520",
          "title": "release: promote v2.5.5 to stable",
          "body": "## Summary\n\n- promote alpha/v2/v2.5 to release/v2/v2.5 after v2.5.5-alpha.3 validation\n- publish stable Buildchain release with S3 artifact relay and release-state fixes\n\n## Validation\n\n- alpha promotion completed successfully in Buildchain Ref Promotion run 28734672617\n- alpha version-state PR #519 merged\n- npm alpha dist-tag is 2.5.5-alpha.3\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:27:35Z",
          "mergedAt": "2026-07-05T08:31:07Z",
          "additions": 526,
          "deletions": 108,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 524,
          "url": "https://github.com/kungfu-systems/buildchain/pull/524",
          "title": "fix(release): scan candidate runs for RC artifacts",
          "body": "## Summary\n\n- scan all matching successful PR-stage Build Surface Fixture runs until one contains release-candidate passport artifacts\n- keep the newest-run ordering but skip successful reruns that lack RC passport/summary artifacts\n- add regression coverage for the release-channel failure seen after #520\n\n## Validation\n\n- node --test tests/release-candidate.test.mjs\n- pnpm run check\n- git diff --check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:36:57Z",
          "mergedAt": "2026-07-05T08:38:44Z",
          "additions": 156,
          "deletions": 14,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 525,
          "url": "https://github.com/kungfu-systems/buildchain/pull/525",
          "title": "chore(release): restore v2.5 topology after release RC fix",
          "body": "## Summary\n\n- merge the current release/v2/v2.5 channel history back into dev/v2/v2.5 using the ours strategy\n- preserve topology after the release RC resolver fix without changing files\n\n## Validation\n\n- git merge -s ours --no-ff origin/release/v2/v2.5\n- git diff --stat origin/dev/v2/v2.5..HEAD\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:39:41Z",
          "mergedAt": "2026-07-05T08:41:17Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 521,
          "url": "https://github.com/kungfu-systems/buildchain/pull/521",
          "title": "Prepare v2.5.5-alpha.3",
          "body": "Create the generated version-state commit for v2.5.5-alpha.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:29:06Z",
          "mergedAt": "2026-07-05T08:41:19Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 526,
          "url": "https://github.com/kungfu-systems/buildchain/pull/526",
          "title": "release: promote v2.5 dev to alpha",
          "body": "## Summary\n\n- promote dev/v2/v2.5 to alpha/v2/v2.5 after RC resolver fallback fix\n- expected path remains promote-only; PR verify build jobs should skip heavy release build\n\n## Validation\n\n- resolver fix merged in #524\n- topology restored in #525\n- npm alpha dist-tag currently 2.5.5-alpha.3\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:41:40Z",
          "mergedAt": "2026-07-05T08:43:25Z",
          "additions": 157,
          "deletions": 15,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 527,
          "url": "https://github.com/kungfu-systems/buildchain/pull/527",
          "title": "Prepare v2.5.5-alpha.4",
          "body": "Create the generated version-state commit for v2.5.5-alpha.4.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:45:46Z",
          "mergedAt": "2026-07-05T08:47:35Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 244,
          "url": "https://github.com/kungfu-systems/kungfu/pull/244",
          "title": "feat(skill): verify managed context envelopes",
          "body": "## Summary\n- add `kungfu skill verify` to run real managed providers against Skill context envelopes and validate Rewind response evidence\n- add Node manager context file writer/CLI and wire Electron GUI context generation through the shared Node skill package\n- document Python/Node manager verification paths and extend golden fixture coverage\n\n## Validation\n- `./kungfu-code build:core`\n- `./kungfu-code freeze`\n- `./kungfu-code verify`\n- `uv --project framework/core run ruff check framework/core/src/python/kungfu/cli/commands/skill.py framework/core/src/python/kungfu/rewind/managed_cli.py`\n- `PYTHONPATH=framework/core/src/python uv --project framework/core run pytest framework/core/tests/python/test_skill.py`\n- `./kungfu-code --filter @kungfu-tech/skill run build`\n- `./kungfu-code --filter @kungfu-tech/skill run test:golden`\n- `./kungfu-code --filter @kungfu-tech/gui run build`\n- frozen `kungfu skill verify --provider codex --manager python --json` -> ok\n- frozen Node-generated context + `kungfu skill verify --provider claude --skill-context-file ... --manager node --json` -> ok\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:49:24Z",
          "mergedAt": "2026-07-05T08:50:11Z",
          "additions": 426,
          "deletions": 31,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 529,
          "url": "https://github.com/kungfu-systems/buildchain/pull/529",
          "title": "feat(release): require surface impact gates",
          "body": "## Summary\n- require surfaceImpacts[] for production release passports and major publish gates\n- expose release-passport-impact-json in promote-buildchain-ref so generated production passports can satisfy the gate\n- document the new requirement and cover production versus alpha behavior in tests\n\n## Validation\n- node --check packages/core/release-passport.js actions/promote-buildchain-ref/lib.js actions/promote-buildchain-ref/index.js bin/buildchain.mjs\n- node --test tests/release-passport.test.mjs\n- node --test tests/cli.test.mjs\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:49:24Z",
          "mergedAt": "2026-07-05T08:51:09Z",
          "additions": 291,
          "deletions": 88,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 528,
          "url": "https://github.com/kungfu-systems/buildchain/pull/528",
          "title": "release: promote v2.5.5 to stable",
          "body": "## Summary\n\n- promote alpha/v2/v2.5 to release/v2/v2.5 after v2.5.5-alpha.4 validation\n- includes S3 artifact relay and release-candidate resolver fallback fix\n\n## Validation\n\n- alpha promotion completed successfully in Buildchain Ref Promotion run 28735175401\n- alpha version-state PR #527 merged\n- npm alpha dist-tag is 2.5.5-alpha.4\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:48:06Z",
          "mergedAt": "2026-07-05T08:51:36Z",
          "additions": 157,
          "deletions": 15,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 533,
          "url": "https://github.com/kungfu-systems/buildchain/pull/533",
          "title": "fix(release): treat occupied release-state versions as published",
          "body": "## Summary\n- treat stable release-state refs as occupied patch versions when selecting the next release tag\n- prevent version-state stale replacement from deleting transactions that already have published material\n- require published finalization transactions to cover the current required artifacts before reuse\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm --filter \"./actions/promote-buildchain-ref\" build\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:01:09Z",
          "mergedAt": "2026-07-05T09:03:52Z",
          "additions": 103,
          "deletions": 53,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 534,
          "url": "https://github.com/kungfu-systems/buildchain/pull/534",
          "title": "chore(release): restore v2.5 topology after state fix",
          "body": "## Summary\n- merge release/v2/v2.5 topology back into dev/v2/v2.5 with ours strategy\n- preserve dev content after the release-state version selection fix\n\n## Validation\n- topology-only merge commit",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:05:02Z",
          "mergedAt": "2026-07-05T09:06:46Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 530,
          "url": "https://github.com/kungfu-systems/buildchain/pull/530",
          "title": "Prepare v2.5.5-alpha.4",
          "body": "Create the generated version-state commit for v2.5.5-alpha.4.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T08:49:28Z",
          "mergedAt": "2026-07-05T09:06:48Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 535,
          "url": "https://github.com/kungfu-systems/buildchain/pull/535",
          "title": "release: promote v2.5 dev to alpha",
          "body": "Promote dev/v2/v2.5 to alpha/v2/v2.5 after release-state version selection fix and topology restore.\n\nExpected behavior:\n- Buildchain selects the next available alpha version after occupied release-state versions.\n- Promotion uses publish-gate alpha semantics.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:07:08Z",
          "mergedAt": "2026-07-05T09:10:33Z",
          "additions": 345,
          "deletions": 92,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 537,
          "url": "https://github.com/kungfu-systems/buildchain/pull/537",
          "title": "fix(release): skip occupied release-state for next alpha",
          "body": "## Summary\n- include stable release-state refs when selecting the next alpha patch\n- prevents alpha from continuing on a patch whose final version already has durable published state\n\n## Validation\n- pnpm --filter \"./actions/promote-buildchain-ref\" build\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:14:44Z",
          "mergedAt": "2026-07-05T09:16:43Z",
          "additions": 56,
          "deletions": 47,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 538,
          "url": "https://github.com/kungfu-systems/buildchain/pull/538",
          "title": "chore(release): restore v2.5 alpha topology after alpha skip fix",
          "body": "## Summary\n- merge alpha/v2/v2.5 topology back into dev/v2/v2.5 with ours strategy\n- preserve dev content after next-alpha release-state occupancy fix\n\n## Validation\n- topology-only merge commit",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:17:27Z",
          "mergedAt": "2026-07-05T09:19:17Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 539,
          "url": "https://github.com/kungfu-systems/buildchain/pull/539",
          "title": "release: promote v2.5 dev to alpha",
          "body": "Promote dev/v2/v2.5 to alpha/v2/v2.5 after next-alpha release-state occupancy fix.\n\nExpected behavior:\n- Buildchain skips occupied stable release-state patch 2.5.5.\n- Alpha promotion prepares the next patch alpha instead of continuing v2.5.5-alpha.N.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:19:42Z",
          "mergedAt": "2026-07-05T09:21:38Z",
          "additions": 56,
          "deletions": 47,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 540,
          "url": "https://github.com/kungfu-systems/buildchain/pull/540",
          "title": "Prepare v2.5.6-alpha.0",
          "body": "Create the generated version-state commit for v2.5.6-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:24:05Z",
          "mergedAt": "2026-07-05T09:25:54Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 245,
          "url": "https://github.com/kungfu-systems/kungfu/pull/245",
          "title": "feat(skill): audit context usage",
          "body": "## Summary\n- record `SkillAdvertised` audit sidecars in managed-run bundles and reference them from `manifest.json`\n- record `SkillLoaded` events when `kungfu skill read` loads full `SKILL.md` content\n- add `kungfu skill audit` to inspect run bundle evidence or standalone audit files\n\n## Validation\n- `uv --project framework/core run ruff check framework/core/src/python/kungfu/skill/audit.py framework/core/src/python/kungfu/skill/__init__.py framework/core/src/python/kungfu/cli/commands/skill.py framework/core/src/python/kungfu/rewind/managed_cli.py framework/core/tests/python/test_skill.py`\n- `PYTHONPATH=framework/core/src/python uv --project framework/core run pytest framework/core/tests/python/test_skill.py`\n- `./kungfu-code build:core`\n- `./kungfu-code --filter @kungfu-tech/skill run build`\n- `./kungfu-code --filter @kungfu-tech/skill run test:golden`\n- `./kungfu-code freeze`\n- `./kungfu-code verify`\n- frozen `kungfu skill verify --provider codex --manager python --json` + `kungfu skill audit --run-id ...` -> `SkillAdvertised`\n- frozen `kungfu skill read ... --audit-file ... --json` + `kungfu skill audit --audit-file ...` -> `SkillLoaded`\n- frozen Node-generated GUI context + `kungfu skill verify --skill-context-file ... --manager node --json` + `skill audit --run-id ...` -> `manager=node`, `source=gui`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:26:43Z",
          "mergedAt": "2026-07-05T09:27:32Z",
          "additions": 367,
          "deletions": 16,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 541,
          "url": "https://github.com/kungfu-systems/buildchain/pull/541",
          "title": "release: promote v2.5.6 to stable",
          "body": "Promote alpha/v2/v2.5 to release/v2/v2.5 for stable v2.5.6.\n\nExpected behavior:\n- publish-gate release locks the channel merge commit\n- release promotion reuses the PR-stage RC artifacts\n- no heavy build is rerun after merge",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:27:06Z",
          "mergedAt": "2026-07-05T09:31:21Z",
          "additions": 358,
          "deletions": 96,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 544,
          "url": "https://github.com/kungfu-systems/buildchain/pull/544",
          "title": "test(release): cover major surface impact gate",
          "body": "## Summary\n- add a release passport regression test for publish-gate/major without surfaceImpacts[]\n- assert the verifier fails closed with the major-gate requirement\n\n## Validation\n- node --test tests/release-passport.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:30:55Z",
          "mergedAt": "2026-07-05T09:32:52Z",
          "additions": 17,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 545,
          "url": "https://github.com/kungfu-systems/buildchain/pull/545",
          "title": "Release v2.5.6",
          "body": "Create the generated version-state commit for v2.5.6.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:33:30Z",
          "mergedAt": "2026-07-05T09:35:17Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 542,
          "url": "https://github.com/kungfu-systems/buildchain/pull/542",
          "title": "Prepare v2.5.6-alpha.0",
          "body": "Create the generated version-state commit for v2.5.6-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:28:14Z",
          "mergedAt": "2026-07-05T09:38:08Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 246,
          "url": "https://github.com/kungfu-systems/kungfu/pull/246",
          "title": "per-session OS windows behind a flag (ADR-0016 stage 2)",
          "body": "Add the per-session OS window (ADR-0016 stage 2): pop a managed session out of the in-shell grid into its own restorable window, placed on the display it was last on. Pure F7 placement + a main-process window registry + a windows[] layer on WorkspaceLayout; pop-out is a shell service so the view stays electron-free. Behind KF_SESSION_WINDOWS (default off); window content is a stage-2 placeholder. Includes a fix so app quit does not wipe the persisted layout. Validated on a real machine (pop out / cross-display move / quit / restore with clamp).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:38:16Z",
          "mergedAt": "2026-07-05T09:38:22Z",
          "additions": 755,
          "deletions": 14,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 546,
          "url": "https://github.com/kungfu-systems/buildchain/pull/546",
          "title": "Prepare v2.5.7-alpha.0",
          "body": "Create the generated version-state commit for v2.5.7-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:37:45Z",
          "mergedAt": "2026-07-05T09:39:26Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 247,
          "url": "https://github.com/kungfu-systems/kungfu/pull/247",
          "title": "perf(kfx-sandbox): skip ancestor traverse grant the container SID already holds",
          "body": "Merge fix/kfx-win-roaming-traverse-skip into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T09:54:58Z",
          "mergedAt": "2026-07-05T09:55:03Z",
          "additions": 40,
          "deletions": 21,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 248,
          "url": "https://github.com/kungfu-systems/kungfu/pull/248",
          "title": "feat(skill): bind kfx dependencies",
          "body": "## Summary\n- add Skill kfx dependency binding documents under the Kungfu home\n- resolve declared kfx dependencies against the shared kfx registry without copying kfx payloads per skill\n- expose `kungfu skill deps` plus Python and Node binding helpers\n- record `SkillDependenciesBound` audit events and support multi-event JSONL audit reads\n\n## Verification\n- `uv --project framework/core run ruff check framework/core/src/python/kungfu/skill framework/core/src/python/kungfu/cli/commands/skill.py framework/core/tests/python/test_skill.py`\n- `PYTHONPATH=framework/core/src/python uv --project framework/core run pytest framework/core/tests/python/test_skill.py`\n- `./kungfu-code --filter @kungfu-tech/skill run build`\n- `./kungfu-code --filter @kungfu-tech/skill run test:golden`\n- `./kungfu-code build:core`\n- `./kungfu-code freeze`\n- frozen `framework/core/dist/kungfu/kungfu` install/deps smoke with two skills sharing one kfx registry entry\n- `./kungfu-code verify`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T10:08:07Z",
          "mergedAt": "2026-07-05T10:08:41Z",
          "additions": 711,
          "deletions": 21,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 249,
          "url": "https://github.com/kungfu-systems/kungfu/pull/249",
          "title": "test: port the verification gate's shell scripts to Node (cross-platform)",
          "body": "Port all 24 bash run.sh drivers (20 fixtures + 3 capability slices + the yijinjing dependency guard) to pure-Node run.mjs so verify --full runs on every platform pnpm runs on, Windows included. Adds two shared harnesses, a verify.js stage 0a guard against reintroducing .sh, and a CONTRIBUTING convention. Also fixes verify --full's build order (freeze before the dogfood probes, which now build via 'kungfu sdk kfx build' and need the frozen runtime). Behavior-preserving: run.sh-passing fixtures pass as run.mjs; the 3 kfx failures are pre-existing (identical on the original run.sh) and tracked separately.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T10:59:12Z",
          "mergedAt": "2026-07-05T10:59:17Z",
          "additions": 1640,
          "deletions": 1015,
          "changedFiles": 52
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 547,
          "url": "https://github.com/kungfu-systems/buildchain/pull/547",
          "title": "fix(release): gate promotion on push verifies",
          "body": "## Summary\n- prevent Buildchain Ref Promotion from running for pull_request Verify workflow_run events\n- keep manual dry-run promotion available\n- add inventory and test coverage for the push-only promotion gate\n\n## Issue coverage\n- Covers repeated workflow-friction issues where PR Verify or version-state PR Verify triggered promote-only publication attempts before a channel push.\n- Leaves existing libnode workflow-file fallback issues as already fixed by the current workflow-friction classifier tests.\n\n## Verification\n- node --test tests/build-surface.test.mjs tests/release-candidate.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-05T11:47:06Z",
          "mergedAt": "2026-07-05T11:48:54Z",
          "additions": 6,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 549,
          "url": "https://github.com/kungfu-systems/buildchain/pull/549",
          "title": "chore(release): restore v2.5 topology after friction fix",
          "body": "## Summary\n- merge alpha/v2/v2.5 version-state history back into dev/v2/v2.5 after the workflow-friction fix\n- preserve the push-only promotion gate from #547 while restoring the channel topology required for alpha promotion\n\n## Validation\n- pnpm run check\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-05T11:53:38Z",
          "mergedAt": "2026-07-05T11:55:31Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 548,
          "url": "https://github.com/kungfu-systems/buildchain/pull/548",
          "title": "release: promote workflow-friction fix to alpha",
          "body": "## Summary\n- promote the push-only Buildchain Ref Promotion gate to alpha\n- prevents pull_request Verify workflow_run events from starting promote-only publication attempts\n\n## Verification\n- PR #547 checks passed\n- dev/v2/v2.5 Verify passed after merge\n\n## Expected release behavior\n- PR-stage checks should build/verify only.\n- Buildchain Ref Promotion should only run after the alpha branch push Verify succeeds.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T11:50:02Z",
          "mergedAt": "2026-07-05T11:57:22Z",
          "additions": 23,
          "deletions": 1,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 2,
          "url": "https://github.com/kungfu-systems/kfd/pull/2",
          "title": "docs(release): add production impact ledger",
          "body": "## Summary\n- add `release-impact.json` as the Buildchain surface-aware ledger for KFD production passports\n- make `node scripts/check.mjs` validate the ledger alongside registry/document agreement\n- document the `release-passport-impact-json: release-impact.json` release input\n\n## Validation\n- node --check scripts/check.mjs\n- node scripts/check.mjs\n- jq . release-impact.json\n- node /Users/dkr/Code/kungfu-systems/buildchain/bin/buildchain.mjs validate --cwd .",
          "author": "dongkeren",
          "createdAt": "2026-07-05T11:59:27Z",
          "mergedAt": "2026-07-05T12:00:10Z",
          "additions": 99,
          "deletions": 4,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 550,
          "url": "https://github.com/kungfu-systems/buildchain/pull/550",
          "title": "Prepare v2.5.7-alpha.1",
          "body": "Create the generated version-state commit for v2.5.7-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T11:59:36Z",
          "mergedAt": "2026-07-05T12:01:27Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 250,
          "url": "https://github.com/kungfu-systems/kungfu/pull/250",
          "title": "feat(skill): expose dependency state to managers",
          "body": "## Summary\n- add a `kungfu.skill-manager/v1` Node manager view that joins installed skills with kfx dependency binding state\n- write `KF_SKILL_MANAGER_FILE` from Electron main and expose it through `shell.info.skillManager`\n- add the first-party `skill-manager` system view to show resolved/unresolved kfx dependencies before agent launch\n\n## Validation\n- `./kungfu-code --filter @kungfu-tech/skill run build`\n- `./kungfu-code --filter @kungfu-tech/skill run test:golden`\n- `./kungfu-code --filter @kungfu-tech/kfx run build`\n- `./kungfu-code --filter @kungfu-tech/gui run build`\n- `./kungfu-code exec biome check framework/skill/src/index.ts framework/skill/scripts/golden.mjs framework/skill/scripts/manager.mjs framework/gui/src/main/index.ts framework/gui/src/main/skill-context.ts framework/gui/src/renderer/src/runtime.ts framework/gui/src/renderer/src/shell-state.ts framework/kfx/src/index.ts extensions/system/package.json extensions/system/skill-manager/package.json extensions/system/skill-manager/src/view/index.tsx`\n- `node --experimental-transform-types framework/skill/scripts/manager.mjs --home <tmp> --path framework/skill/fixtures/minimal --path framework/skill/fixtures/with-frontmatter`\n- `node ../../../developer/sdk/src/sdk.js kfx build` from `extensions/system/skill-manager`\n\n## Notes\n- Full `./kungfu-code lint` is not a clean signal on this branch because existing unrelated files currently fail Biome import/style rules; changed-file Biome check passes.\n- The package script `kungfu sdk kfx build` resolves to the local global `/usr/local/bin/kungfu` on this machine, which lacks `sdk`; the view bundle was verified through the repo SDK entrypoint directly.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:04:08Z",
          "mergedAt": "2026-07-05T12:04:41Z",
          "additions": 617,
          "deletions": 9,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 551,
          "url": "https://github.com/kungfu-systems/buildchain/pull/551",
          "title": "Prepare v2.5.7-alpha.1",
          "body": "Create the generated version-state commit for v2.5.7-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:03:34Z",
          "mergedAt": "2026-07-05T12:05:40Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 251,
          "url": "https://github.com/kungfu-systems/kungfu/pull/251",
          "title": "refactor(core): finish the .sh→node migration (benches + tree-wide guard)",
          "body": "Ports the two ADR-0005 dispatch benches to .mjs (shared _bench.mjs), removes the orphaned freeze-kungfu.sh (superseded by run-freeze.js), and hardens verify stage 0a to guard the whole tree against reintroduced .sh (was 3 whitelisted dirs). Repo is now zero .sh.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:06:34Z",
          "mergedAt": "2026-07-05T12:06:39Z",
          "additions": 370,
          "deletions": 244,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 552,
          "url": "https://github.com/kungfu-systems/buildchain/pull/552",
          "title": "release: promote workflow-friction fix to stable",
          "body": "## Summary\n- promote Buildchain v2.5.7-alpha.1 to the stable v2.5 release line\n- includes #547 push-only promotion gate for Buildchain Ref Promotion so PR-stage Verify no longer triggers publishing\n- carries alpha-tested version-state and binary distribution evidence\n\n## Validation\n- #547 CI passed and merged to dev/v2/v2.5\n- #548 dev -> alpha checks passed and alpha promote-only completed\n- #550 version-state PR passed and binary distribution completed for v2.5.7-alpha.1\n- #551 dev version-state sync passed and merged\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:06:58Z",
          "mergedAt": "2026-07-05T12:08:36Z",
          "additions": 24,
          "deletions": 2,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 553,
          "url": "https://github.com/kungfu-systems/buildchain/pull/553",
          "title": "Release v2.5.7",
          "body": "Create the generated version-state commit for v2.5.7.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:10:45Z",
          "mergedAt": "2026-07-05T12:12:33Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 554,
          "url": "https://github.com/kungfu-systems/buildchain/pull/554",
          "title": "Prepare v2.5.8-alpha.0",
          "body": "Create the generated version-state commit for v2.5.8-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:15:11Z",
          "mergedAt": "2026-07-05T12:17:03Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 50,
          "url": "https://github.com/kungfu-systems/libnode/pull/50",
          "title": "ci: enable buildchain s3 relay for alpha publishing",
          "body": "## Summary\n- enable Buildchain S3 artifact relay for Build, Release - Verify, and Release - New Version\n- bump alpha version to 22.22.3-kf.3-alpha.10 for the validation publish\n\n## Validation\n- ruby YAML parse for modified workflows\n- jq parse for package.json and libnode.release.json\n- corepack pnpm verify-release\n- corepack pnpm verify-package-source\n- git diff --check\n\nAfter this PR build validates relay mode, publish-gate/alpha will publish the alpha package set through the same Buildchain S3 relay path.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:02:14Z",
          "mergedAt": "2026-07-05T12:24:43Z",
          "additions": 6,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 555,
          "url": "https://github.com/kungfu-systems/buildchain/pull/555",
          "title": "chore(release): sync dev after v2.5.7 release",
          "body": "## Summary\n- sync dev/v2/v2.5 to the prepared v2.5.8-alpha.0 state after the v2.5.7 release\n- closes the post-release topology gap where alpha advanced but dev remained at v2.5.7-alpha.1\n\n## Validation\n- v2.5.7 stable release completed\n- v2.5.8-alpha.0 next-alpha binary distribution completed\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:24:57Z",
          "mergedAt": "2026-07-05T12:26:46Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 252,
          "url": "https://github.com/kungfu-systems/kungfu/pull/252",
          "title": "build(repo): move the pre-commit hook to node (cross-platform format + lint guard)",
          "body": "JS-ify the pre-commit hook so it works on Windows: all logic moves to precommit.mjs (staged .sh guard, clang-format/ruff format, biome check --write that blocks on unfixable lint), .githooks/pre-commit becomes a thin POSIX exec-node shim, and the no-bash scan is extracted to no-bash-guard.mjs shared with verify stage 0a. Validated on macOS: sh-block / format+restage / lint-block all behave.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:34:10Z",
          "mergedAt": "2026-07-05T12:34:15Z",
          "additions": 271,
          "deletions": 115,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 253,
          "url": "https://github.com/kungfu-systems/kungfu/pull/253",
          "title": "fix(skill): load manager view in gui renderer",
          "body": "## Summary\n- load the Skill Manager JSON from the renderer runtime fallback path when the shell info payload is unavailable\n- let the Skill Manager system view read KF_SKILL_MANAGER_FILE directly as a last-resort fallback\n- keep the rendered dependency table available for GUI dogfood runs with a precomputed Node manager state\n\n## Validation\n- node ../../../developer/sdk/src/sdk.js kfx build (extensions/system/skill-manager)\n- ./kungfu-code --filter @kungfu-tech/gui run build\n- ./kungfu-code exec biome check framework/gui/src/renderer/src/runtime.ts extensions/system/skill-manager/src/view/index.tsx\n- launched the GUI with KF_RUNTIME_DIR, KF_SKILL_PATH, KF_SKILL_MANAGER_FILE, and KFE_INITIAL_VIEW=skill-manager; verified the Skill Manager page shows 2 installed skills and 1 unresolved required kfx",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:38:55Z",
          "mergedAt": "2026-07-05T12:39:54Z",
          "additions": 35,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 51,
          "url": "https://github.com/kungfu-systems/libnode/pull/51",
          "title": "release: publish libnode 22.22.3-kf.3-alpha.10",
          "body": "## Summary\n- promote dev/v22/v22.22 to alpha/v22/v22.22\n- publish @kungfu-tech/libnode 22.22.3-kf.3-alpha.10\n- validate Buildchain S3 artifact relay on the release-candidate build\n\n## Expected Buildchain flow\n- Build workflow runs with release-candidate=true for alpha base\n- self-hosted platform jobs upload heavy payloads through S3 relay\n- relay-artifacts jobs rehydrate normal GitHub artifacts\n- merging this PR triggers Release - New Version promote/publish\n\n## Prior validation\n- PR #50 Build run 28740199617 passed Linux x64, macOS arm64, Windows x64 and all relay artifact jobs.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:25:15Z",
          "mergedAt": "2026-07-05T12:45:55Z",
          "additions": 6,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 254,
          "url": "https://github.com/kungfu-systems/kungfu/pull/254",
          "title": "feat(gui,terminal): render the live terminal in a per-session window (ADR-0016 stage 3)",
          "body": "Replace the stage-2 placeholder in each per-session OS window with the real terminal view, mounted against one runId over the main-process session host, so a session renders identically in the in-shell grid and in its own window. Adds a node-integrated session-window renderer entry, the electron-vite html entry for it, and dispatches the terminal kfx View on shell.params.sessionWindowRunId. Also namespaces terminal-host relay subscriptions by webContents id so the shell and each session window (now separate guest renderers on one host) no longer collide subIds and silently kill an unrelated pane, with destroyed-sender cleanup. Behind KF_SESSION_WINDOWS, default off; type-checks, builds, and passed a real-machine check (pop-out live terminal, grid pane survives pop-out, cross-display drag, quit/relaunch restore).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:50:43Z",
          "mergedAt": "2026-07-05T12:50:48Z",
          "additions": 329,
          "deletions": 61,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 255,
          "url": "https://github.com/kungfu-systems/kungfu/pull/255",
          "title": "docs(kfx): ADR-0017 dual-host loading + the service facet, and a topology page",
          "body": "Merge docs/kfx-dual-entry-adr into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T13:15:52Z",
          "mergedAt": "2026-07-05T13:15:57Z",
          "additions": 349,
          "deletions": 1,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 256,
          "url": "https://github.com/kungfu-systems/kungfu/pull/256",
          "title": "refactor(repo): relocate root dev tooling into scripts/ and convert to ESM",
          "body": "De-clutters the repo root: moves verify/install-hooks/prebuild/precommit/no-bash-guard into scripts/ (per-package scripts/ convention) and converts the .js tooling + kungfu-code entrypoint to ESM (.mjs; surgical rename, not root type:module, which would flip the CJS test fixtures). All refs updated (package.json, pre-commit shim, kungfu-code sh/cmd wrappers, CONTRIBUTING). Validated on macOS: verify --help / quick run / guard / kungfu-code proxy / precommit all work.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T13:36:27Z",
          "mergedAt": "2026-07-05T13:36:33Z",
          "additions": 67,
          "deletions": 52,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 257,
          "url": "https://github.com/kungfu-systems/kungfu/pull/257",
          "title": "fix(repo): make the pre-commit formatters spawn on Windows",
          "body": "precommit.mjs spawned biome/pnpm/ruff/clang-format without shell:isWin, so on Windows node could not launch their .cmd shims (ENOENT), and checking only r.status meant a failed biome spawn falsely blocked the commit. Add shell:isWin (matching verify.mjs) and treat a spawn error as warn-and-skip. Validated on macOS (shell:false path unchanged): sh-block / format+restage / lint-block all still behave.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T13:55:02Z",
          "mergedAt": "2026-07-05T13:55:07Z",
          "additions": 28,
          "deletions": 13,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 258,
          "url": "https://github.com/kungfu-systems/kungfu/pull/258",
          "title": "feat(skill): show static agent skill inventory",
          "body": "## Summary\n\n- add a read-only Codex/Claude agent skill inventory to the Skill Manager data model\n- surface agent-native skill roots, effective skills, shadowed duplicates, parse state, hashes, mtimes, and safe path metadata in the Skill Manager GUI\n- skip generated Python `.venv` directories in the no-bash guard so the standard uv/Nuitka build output does not break verification\n\n## Verification\n\n- `./kungfu-code exec biome check framework/skill/src/index.ts framework/skill/scripts/golden.mjs extensions/system/skill-manager/src/view/index.tsx framework/gui/src/renderer/src/main.tsx framework/skill/schema/skill-manager.schema.json scripts/no-bash-guard.mjs`\n- `./kungfu-code --filter @kungfu-tech/skill test:golden`\n- `./kungfu-code --filter @kungfu-tech/skill build`\n- `./kungfu-code --filter @kungfu-tech/gui build`\n- `./kungfu-code build:core && ./kungfu-code freeze && ./kungfu-code verify`\n- `PATH=\"$PWD/framework/core/dist/kungfu:$PATH\" ./kungfu-code --filter @kungfu-tech/kfx-view-skill-manager build`\n\n## Safety\n\n- does not read provider credentials, session logs, auth files, or billing state\n- reads only local skill roots and `SKILL.md` metadata needed for name/description/hash/mtime\n- does not mutate agent homes, skill roots, symlinks, or identity-pool configuration\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T14:11:50Z",
          "mergedAt": "2026-07-05T14:12:39Z",
          "additions": 866,
          "deletions": 2,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 556,
          "url": "https://github.com/kungfu-systems/buildchain/pull/556",
          "title": "feat(passport): verify artifacts through release passport discovery",
          "body": "## Summary\n- add subject-centric `buildchain verify|inspect|explain artifact` CLI surfaces\n- discover detached release passports through explicit flags, sidecar pointers, package pointers, local indexes, GitHub Release defaults, and custom locators\n- verify the release passport and require the subject digest to appear in passport artifacts, artifact evidence, publish evidence, or package-set evidence\n- dogfood artifact verification in the Buildchain binary distribution workflow\n\n## Validation\n- `node --test tests/release-passport.test.mjs`\n- `node --test tests/cli.test.mjs`\n- `pnpm run check`\n\n## Notes\n- Opened `dev/v2/v2.6`, set it as the repository default branch, and matched the v2.5 dev branch protection with one required approval.\n- No alpha or release publication was performed.\n\nAgent: Codex\nGoal: 2026-07-05-buildchain-artifact-passport-discovery\nMission: kungfu-technical-stewardship\nMission-Lens: principal-engineer\nMission-Track: external\nMission-Role: supporting\nMission-Importance: medium",
          "author": "dongkeren",
          "createdAt": "2026-07-05T14:23:52Z",
          "mergedAt": "2026-07-05T14:25:40Z",
          "additions": 1249,
          "deletions": 0,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 261,
          "url": "https://github.com/kungfu-systems/kungfu/pull/261",
          "title": "feat(gui,terminal): freeze a popped-out session's grid tile, and wire selection copy (ADR-0016 stage 4)",
          "body": "Merge feature/session-grid-overview into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T14:35:16Z",
          "mergedAt": "2026-07-05T14:35:22Z",
          "additions": 146,
          "deletions": 14,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 262,
          "url": "https://github.com/kungfu-systems/kungfu/pull/262",
          "title": "refactor(kfx): extract host-agnostic planKfx from the gui loader",
          "body": "Extract the discovery + trust/tier decision half of the gui kfx loader into planKfx in @kungfu-tech/kfx: fs/path/crypto injected, returns a neutral load plan (KfxPlanEntry) that instantiates no View/DOM/Electron. The gui loader becomes a thin planKfx + renderer-landing wrapper; KfxEntry = KfxPlanEntry & { View }. One load rule, ready for a second host to import (ADR-0017 stage 1). Pure refactor: kfx typecheck green, gui typecheck unchanged (only pre-existing base errors), load-decision equivalence checked across system/pinned/unpinned/untrusted/suite/dedup cases.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T14:36:34Z",
          "mergedAt": "2026-07-05T14:36:40Z",
          "additions": 281,
          "deletions": 201,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 260,
          "url": "https://github.com/kungfu-systems/kungfu/pull/260",
          "title": "docs: align architecture docs with skills and kfx sandbox",
          "body": "## Summary\n\n- Update public architecture docs for Kungfu Skills as the agent-facing layer above kfx.\n- Align kfx docs with source-authority trust, runtime-plane sandboxing, adapter refusal, and the proposed service facet.\n- Register Skill/KFX contract surfaces in the documentation map and versioning register so future agents can route architecture and version-impact questions from public docs.\n- Refresh known limits and concepts so current Skill/KFX/sandbox terminology is grounded from public docs.\n\n## Validation\n\n- `git diff --check origin/dev/v4/v4.0...HEAD`\n- targeted local-link check over the 9 changed docs\n- stale-phrase grep for old trust/shell wording\n- GitHub checks: Buildchain Validate, DCO\n\n## Known validation boundaries\n\n- `./kungfu-code lint` currently fails on pre-existing non-doc code style/import diagnostics outside this docs patch.\n- `./kungfu-code verify` quick mode fails in this fresh worktree because frozen `framework/core/dist/kungfu` / `kfc` artifacts are not present.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-05T14:34:12Z",
          "mergedAt": "2026-07-05T14:49:31Z",
          "additions": 218,
          "deletions": 87,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 263,
          "url": "https://github.com/kungfu-systems/kungfu/pull/263",
          "title": "build(core): adopt C++23",
          "body": "Raise the project C++ standard 20→23 (conan dep cppstd stays 17, decoupled). Validated clean builds on macOS (AppleClang 21) and Linux (GCC 13.3); only boost::hana emits deprecation warnings. Windows/MSVC build was env-blocked (missing _WINDOWS platform macro in the ad-hoc vcvars shell), not a C++23 incompatibility — a proper DARKHERO build verification is a fast-follow. Adopting now to keep the long-term core on a modern standard.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T14:50:32Z",
          "mergedAt": "2026-07-05T14:50:36Z",
          "additions": 6,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 264,
          "url": "https://github.com/kungfu-systems/kungfu/pull/264",
          "title": "docs(core): update C++ standard references to C++23",
          "body": "CONTRIBUTING and the yijinjing EMBEDDING guide still said C++20; align them with the adopted CMAKE_CXX_STANDARD 23 (and CMake >= 3.20).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T14:55:45Z",
          "mergedAt": "2026-07-05T14:55:50Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 557,
          "url": "https://github.com/kungfu-systems/buildchain/pull/557",
          "title": "fix(passport): verify release passport before persistence",
          "body": "## Summary\n- verify collected release passports before durable persistence and again after release-state SHA backfill\n- omit trusted publishing evidence for npm-token releases so verifier does not treat token auth as failed trusted publishing\n- add a regression test proving invalid production passport evidence blocks durable passport persistence\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm -r --filter \"./actions/promote-buildchain-ref\" build\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-05T15:05:51Z",
          "mergedAt": "2026-07-05T15:07:45Z",
          "additions": 221,
          "deletions": 62,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 265,
          "url": "https://github.com/kungfu-systems/kungfu/pull/265",
          "title": "build(core): gradual mypy baseline + pilot type annotations",
          "body": "Python was ~6% annotated with no type checker. Adds mypy as a lenient, growing baseline (untyped defs skipped; native/unstubbed imports ignored; a 7-module snapshot of pre-existing errors ignored) wired into verify as stage 0b, and fully annotates rewind/adapters.py as the pilot. Modules opt into real checking as they gain annotations — no big-bang. Follow-up: fix the 7 snapshotted modules and expand annotation coverage.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T15:10:23Z",
          "mergedAt": "2026-07-05T15:10:29Z",
          "additions": 135,
          "deletions": 6,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 266,
          "url": "https://github.com/kungfu-systems/kungfu/pull/266",
          "title": "refactor(core): clear the mypy baseline snapshot (fix 7 modules)",
          "body": "Fix the 7 pre-existing type-error modules and remove the ignore-errors override — mypy now checks the whole kungfu package clean. Native pykungfu bindings typed Any, click decorators cast to CLI, click.Choice takes list(), tabulate marked untyped, managed-run provider table gets a _ProviderSpec TypedDict.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T15:22:37Z",
          "mergedAt": "2026-07-05T15:22:42Z",
          "additions": 29,
          "deletions": 29,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 267,
          "url": "https://github.com/kungfu-systems/kungfu/pull/267",
          "title": "refactor(core): annotate rewind first_party + cost_wire",
          "body": "Gradual typing goal Stage 1: annotate the first-party trust-set resolver and the cost snapshot->event bridge. mypy zero-override baseline stays green.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T15:45:05Z",
          "mergedAt": "2026-07-05T15:45:09Z",
          "additions": 15,
          "deletions": 9,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 268,
          "url": "https://github.com/kungfu-systems/kungfu/pull/268",
          "title": "refactor(core): annotate rewind events + fix cost_wire narrowing",
          "body": "Gradual typing goal Stage 1: annotate rewind/events.py (10 FlatBuffers serializers). Typing cost_snapshot surfaced a real float|None vs float mismatch in cost_wire — fixed by narrowing on snapshot.cost_usd. mypy zero-override baseline green.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T15:54:05Z",
          "mergedAt": "2026-07-05T15:54:10Z",
          "additions": 83,
          "deletions": 47,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 269,
          "url": "https://github.com/kungfu-systems/kungfu/pull/269",
          "title": "feat(kfx): add the config.service facet to planKfx",
          "body": "Merge feature/kfx-service-facet into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T16:05:05Z",
          "mergedAt": "2026-07-05T16:05:10Z",
          "additions": 186,
          "deletions": 35,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 270,
          "url": "https://github.com/kungfu-systems/kungfu/pull/270",
          "title": "test(capability): prove the service facet's os-sandbox network membrane",
          "body": "Merge feature/kfx-service-host into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T20:36:49Z",
          "mergedAt": "2026-07-05T20:36:55Z",
          "additions": 187,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 271,
          "url": "https://github.com/kungfu-systems/kungfu/pull/271",
          "title": "feat(capability): resolve a service's sandbox profile from a user grant",
          "body": "Merge feature/kfx-service-authz into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T23:24:45Z",
          "mergedAt": "2026-07-05T23:24:51Z",
          "additions": 382,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 272,
          "url": "https://github.com/kungfu-systems/kungfu/pull/272",
          "title": "feat(tui): land a discovered service kfx through the service host",
          "body": "Merge feature/kfx-service-dogfood into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-05T23:48:36Z",
          "mergedAt": "2026-07-05T23:48:42Z",
          "additions": 411,
          "deletions": 0,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 3,
          "url": "https://github.com/kungfu-systems/kfd/pull/3",
          "title": "docs: add non-coercive intelligence KFD",
          "body": "## Summary\n\n- add KFD-3: Non-coercive intelligence\n- define transparent value, stable choice, and explainable constraints as the stance toward humans and agents\n- update registry, README, and docs map\n\n## Verification\n\n- node scripts/check.mjs\n- git diff --check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T00:11:26Z",
          "mergedAt": "2026-07-06T00:11:52Z",
          "additions": 164,
          "deletions": 0,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 273,
          "url": "https://github.com/kungfu-systems/kungfu/pull/273",
          "title": "rewind: attribute managed-run cost to the GUI session, decode events by reflection",
          "body": "Two additive fact-base changes on the rewind path:\n- managed-run takes the GUI session runId (--run-id) so CostSnapshot/journal facts share one identity with the on-screen session.\n- the rewind capability decodes events by reflection over the manifest-bound .bfbs (no generated event classes); CostSnapshot and future event types decode with no per-type code. Also recovers schema-default scalars the reflection decoder was dropping.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T00:20:21Z",
          "mergedAt": "2026-07-06T00:20:26Z",
          "additions": 279,
          "deletions": 143,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 274,
          "url": "https://github.com/kungfu-systems/kungfu/pull/274",
          "title": "feat(tui): load kfx through the shared planKfx rule",
          "body": "Merge feature/kfx-tui-plan into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T01:07:54Z",
          "mergedAt": "2026-07-06T01:08:00Z",
          "additions": 237,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 275,
          "url": "https://github.com/kungfu-systems/kungfu/pull/275",
          "title": "refactor(core): annotate the capability sandbox guest (Stage 2)",
          "body": "Gradual typing goal Stage 2 — kfx sandbox boundary: fully annotate capability/guest.py (the whole capability/ Python surface). mypy zero-override baseline green.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T01:09:37Z",
          "mergedAt": "2026-07-06T01:09:42Z",
          "additions": 20,
          "deletions": 12,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 276,
          "url": "https://github.com/kungfu-systems/kungfu/pull/276",
          "title": "refactor(core): annotate the package + skill public API (Stage 3)",
          "body": "Gradual typing goal Stage 3 — SDK/public API: annotate kungfu/__init__.py and the skill public surface (context/catalog/registry/provider). Typing surfaced a real None-narrowing gap in inject_skill_context, now fixed. mypy zero-override baseline green.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T01:42:35Z",
          "mergedAt": "2026-07-06T01:42:41Z",
          "additions": 58,
          "deletions": 31,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 558,
          "url": "https://github.com/kungfu-systems/buildchain/pull/558",
          "title": "fix(governance): harden dev check gates",
          "body": "## Summary\n- add a reusable Buildchain check wrapper that runs declared lifecycle.install and lifecycle.verify\n- make the Buildchain Verify job dogfood the declarative lifecycle check path\n- default dev auto-merge and patrol required checks to the check job, and move dogfood patrol to the v2 floating runtime/default dev line\n- document check customization and patrol v2 floating defaults\n\n## Validation\n- bash scripts/check-workflows.sh\n- node --test tests/dev-pr-auto-merge.test.mjs tests/buildchain-patrol.test.mjs tests/build-surface.test.mjs\n- node bin/buildchain.mjs validate --require-version-state --require-lifecycle-stages install,verify\n- corepack pnpm@11.7.0 run check\n\n## Branch protection\n- updated dev/v2/v2.6 protection to require strict check status and one approving review\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T01:48:58Z",
          "mergedAt": "2026-07-06T01:53:20Z",
          "additions": 218,
          "deletions": 45,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 4,
          "url": "https://github.com/kungfu-systems/kfd/pull/4",
          "title": "docs: polish KFD foundation triad",
          "body": "## Summary\n- Add a README foundation triad for KFD-1/2/3: contract, truth, and relationship paths\n- Clarify KFD-1's relationship to KFD-2 and KFD-3\n- Tighten KFD-2 and KFD-3 wording without changing numbers, kinds, statuses, registry schema, or package structure\n\n## Verification\n- node scripts/check.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:00:39Z",
          "mergedAt": "2026-07-06T02:00:57Z",
          "additions": 75,
          "deletions": 13,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 5,
          "url": "https://github.com/kungfu-systems/kfd/pull/5",
          "title": "docs: add KFD product proof path",
          "body": "## Summary\n- Add a short product proof path note under the KFD foundation triad\n- Clarify that active KFDs should be reflected in product behavior, release evidence, documentation, or conformance checks\n- Identify the main Kungfu product as the primary proof surface for product philosophy KFDs\n\n## Verification\n- node scripts/check.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:02:29Z",
          "mergedAt": "2026-07-06T02:02:41Z",
          "additions": 9,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 6,
          "url": "https://github.com/kungfu-systems/kfd/pull/6",
          "title": "docs: point KFD proof path to product entrypoints",
          "body": "## Summary\n- Refine the product proof path note so it points to verification entrypoints instead of listing concrete product functions\n- Point product philosophy verification to the main Kungfu product entrypoint\n- Point release/provenance accountability verification to Buildchain\n\n## Verification\n- node scripts/check.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:04:08Z",
          "mergedAt": "2026-07-06T02:04:54Z",
          "additions": 7,
          "deletions": 6,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 277,
          "url": "https://github.com/kungfu-systems/kungfu/pull/277",
          "title": "refactor(core): annotate the rewind cost adapters + schema/export plumbing",
          "body": "Merge feature/py-typing-rewind-cost into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:19:41Z",
          "mergedAt": "2026-07-06T02:19:46Z",
          "additions": 50,
          "deletions": 21,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 278,
          "url": "https://github.com/kungfu-systems/kungfu/pull/278",
          "title": "refactor(core): annotate the rewind capture pipeline (L0-L2)",
          "body": "Merge feature/py-typing-rewind-plumbing into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:32:34Z",
          "mergedAt": "2026-07-06T02:32:39Z",
          "additions": 60,
          "deletions": 32,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 561,
          "url": "https://github.com/kungfu-systems/buildchain/pull/561",
          "title": "chore(release): prepare v2.6 alpha version state",
          "body": "## Summary\n- align package.json version with the active dev/v2/v2.6 release line\n- unblock dev/v2/v2.6 -> alpha/v2/v2.6 release-line verification\n\n## Validation\n- node bin/buildchain.mjs validate --require-version-state --require-lifecycle-stages install,verify\n- BUILDCHAIN_HEAD_REF=dev/v2/v2.6 BUILDCHAIN_BASE_REF=alpha/v2/v2.6 node scripts/verify-release-pr.mjs\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:36:46Z",
          "mergedAt": "2026-07-06T02:39:03Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 559,
          "url": "https://github.com/kungfu-systems/buildchain/pull/559",
          "title": "chore(release): promote v2.6 alpha",
          "body": "## Summary\n- promote the protected dev/v2/v2.6 line into alpha/v2/v2.6\n- release automation will create the alpha version-state commit and publish the alpha package through Buildchain promotion\n\n## Validation\n- branch protection requires the check job before merge\n- source lineage is dev/v2/v2.6 -> alpha/v2/v2.6\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:34:08Z",
          "mergedAt": "2026-07-06T02:40:48Z",
          "additions": 1689,
          "deletions": 108,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 279,
          "url": "https://github.com/kungfu-systems/kungfu/pull/279",
          "title": "refactor(core): annotate replay + the managed-run entry",
          "body": "Merge feature/py-typing-rewind-cli into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:44:11Z",
          "mergedAt": "2026-07-06T02:44:16Z",
          "additions": 69,
          "deletions": 53,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 563,
          "url": "https://github.com/kungfu-systems/buildchain/pull/563",
          "title": "chore(release): refresh promote action bundle",
          "body": "## Summary\n- refresh the committed promote-buildchain-ref action bundle generated by the current toolchain\n- unblock v2.6 alpha promotion verification, which fails when lifecycle.verify rebuilds the bundle during promotion\n\n## Validation\n- corepack pnpm@11.7.0 run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:47:51Z",
          "mergedAt": "2026-07-06T02:49:42Z",
          "additions": 34,
          "deletions": 34,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 564,
          "url": "https://github.com/kungfu-systems/buildchain/pull/564",
          "title": "chore(release): promote v2.6 alpha bundle fix",
          "body": "## Summary\n- promote the generated action bundle refresh from dev/v2/v2.6 into alpha/v2/v2.6\n- retry the v2.6 alpha promotion with lifecycle.verify no longer changing dist files\n\n## Context\n- Previous alpha promotion reached post-merge promotion but failed because lifecycle.verify rebuilt actions/promote-buildchain-ref/dist/index.js.\n- PR #563 fixed the committed bundle on dev/v2/v2.6 and passed check plus Build Surface Fixture.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:50:12Z",
          "mergedAt": "2026-07-06T02:51:59Z",
          "additions": 34,
          "deletions": 34,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 7,
          "url": "https://github.com/kungfu-systems/kfd/pull/7",
          "title": "docs: clarify KFD foundation titles",
          "body": "## Summary\n- retitle KFD-1/2/3 so the foundation reads as contract -> fact -> cooperation\n- remove version-line anchoring from KFD-1 title and one-sentence summary\n- add config contracts as a concrete KFD-1 implementation surface alongside versioning\n\n## Validation\n- node scripts/check.mjs\n- git diff --check\n\n## Release impact\n- KFD content patch only\n- no number, slug, kind, registry schema, or package-structure change",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:51:25Z",
          "mergedAt": "2026-07-06T02:53:20Z",
          "additions": 42,
          "deletions": 24,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 567,
          "url": "https://github.com/kungfu-systems/buildchain/pull/567",
          "title": "chore(release): promote v2.6 stable",
          "body": "## Summary\n- promote Buildchain v2.6 from alpha/v2/v2.6 to release/v2/v2.6\n- publish the stable v2.6 release after alpha promotion succeeded\n\n## Validation\n- alpha promotion succeeded for v2.6.0-alpha.0\n- npm alpha dist-tag points to 2.6.0-alpha.0\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T02:56:43Z",
          "mergedAt": "2026-07-06T02:58:42Z",
          "additions": 1689,
          "deletions": 108,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 568,
          "url": "https://github.com/kungfu-systems/buildchain/pull/568",
          "title": "Release v2.6.0",
          "body": "Create the generated version-state commit for v2.6.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:00:54Z",
          "mergedAt": "2026-07-06T03:02:41Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 281,
          "url": "https://github.com/kungfu-systems/kungfu/pull/281",
          "title": "feat(terminal): honest per-session cost badge on the session tile",
          "body": "Show each managed session's rolled-up cost on its tile: a dollar total when every CostSnapshot's usd is known, else a token count (never a fake $0); amber '~' for ambiguous attribution, dotted underline for observed (non-exact-run) attribution. Also journal a managed run into the ambient runtime home so its cost facts are discoverable by the tile, and declare the rewind capability the view uses. Follows S1+S2a (PR#273).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:08:37Z",
          "mergedAt": "2026-07-06T03:08:42Z",
          "additions": 70,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 570,
          "url": "https://github.com/kungfu-systems/buildchain/pull/570",
          "title": "fix(release): pass surface impact to release passports",
          "body": "## Summary\n- expose release-passport-impact-json on the release-candidate promote wrapper\n- pass Buildchain's surface-aware release impact into self promotion\n- add contract checks so production release passports have surface impact input\n\n## Validation\n- node scripts/check-inventory.mjs\n- node --test tests/build-surface.test.mjs\n- bash scripts/check-workflows.sh\n- corepack pnpm@11.7.0 run check\n\n## Context\n- Fixes the v2.6.0 finalization failure where production release passport verification required surfaceImpacts[].\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:08:42Z",
          "mergedAt": "2026-07-06T03:11:25Z",
          "additions": 15,
          "deletions": 0,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 282,
          "url": "https://github.com/kungfu-systems/kungfu/pull/282",
          "title": "feat(config): make Kungfu config contract-first",
          "body": "## Summary\n\n- add `framework/config/kungfu-config.contract.json` as the KFD-1 source for config schema, defaults, resolution rules, contract self-schema, and schema ids\n- load the same contract from Python, Node/TypeScript, and frozen artifacts; expose `kungfu config contract/schema/defaults/show --json`\n- add managed-run agent environment pointers that keep envelopes compact and point agents to `kungfu agent context --json`\n- copy the contract during build/freeze and extend `kungfu-code verify` to check repo hash, artifact hash, and frozen runtime-reported hash\n- register `config-contract` in `docs/versioning.md` and document the config contract surface\n\n## Verification\n\n- `PYTHONPATH=src/python uv run --frozen ruff check src/python/kungfu/config.py src/python/kungfu/cli/commands/config.py src/python/kungfu/skill/context.py src/python/kungfu/skill/provider.py src/python/kungfu/rewind/managed_cli.py tests/python/test_skill.py`\n- `PYTHONPATH=src/python uv run --frozen mypy src/python/kungfu/config.py src/python/kungfu/cli/commands/config.py src/python/kungfu/skill/context.py src/python/kungfu/skill/provider.py src/python/kungfu/rewind/managed_cli.py`\n- `PYTHONPATH=src/python uv run --frozen pytest tests/python/test_skill.py`\n- `./kungfu-code --filter @kungfu-tech/skill run build`\n- `./kungfu-code --filter @kungfu-tech/skill run test:golden`\n- `./kungfu-code freeze`\n- `./kungfu-code verify`\n\n## Notes\n\n`./kungfu-code verify` now reports `kfc config contract smoke` and confirms the frozen runtime hash matches the repo contract hash.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:11:05Z",
          "mergedAt": "2026-07-06T03:12:15Z",
          "additions": 2064,
          "deletions": 44,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 571,
          "url": "https://github.com/kungfu-systems/buildchain/pull/571",
          "title": "chore(release): prepare v2.6.1 alpha version state",
          "body": "## Summary\n- prepare dev/v2/v2.6 for the next v2.6 patch alpha release\n- bump package version to 2.6.1-alpha.0 after v2.6.0 stable was published\n\n## Validation\n- corepack pnpm@11.7.0 install --frozen-lockfile\n- node bin/buildchain.mjs validate --require-version-state --require-lifecycle-stages install,verify\n- BUILDCHAIN_HEAD_REF=dev/v2/v2.6 BUILDCHAIN_BASE_REF=alpha/v2/v2.6 node scripts/verify-release-pr.mjs\n- corepack pnpm@11.7.0 run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:13:35Z",
          "mergedAt": "2026-07-06T03:15:08Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 572,
          "url": "https://github.com/kungfu-systems/buildchain/pull/572",
          "title": "chore(release): promote v2.6.1 alpha",
          "body": "## Summary\n- promote v2.6.1-alpha.0 to alpha/v2/v2.6\n- include the release passport surface impact fix in the alpha channel\n\n## Validation\n- #570 passed local full check and PR checks\n- #571 prepared package version 2.6.1-alpha.0 and passed PR checks\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:15:48Z",
          "mergedAt": "2026-07-06T03:17:35Z",
          "additions": 16,
          "deletions": 1,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 283,
          "url": "https://github.com/kungfu-systems/kungfu/pull/283",
          "title": "refactor(core): tighten strict-mode type precision (zero-risk subset)",
          "body": "Merge feature/py-strict-type-fixes into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:23:19Z",
          "mergedAt": "2026-07-06T03:23:24Z",
          "additions": 33,
          "deletions": 25,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 575,
          "url": "https://github.com/kungfu-systems/buildchain/pull/575",
          "title": "chore(release): promote v2.6.1 stable",
          "body": "## Summary\n- merge the v2.6.1 alpha branch fixes into release/v2/v2.6\n- resolve the release version state to stable 2.6.1\n- keep release-candidate-promote passport impact wiring from alpha\n\n## Validation\n- BUILDCHAIN_HEAD_REF=fix/release-line-v2-v2.6-2.6.1-stable BUILDCHAIN_BASE_REF=release/v2/v2.6 node scripts/verify-release-pr.mjs\n- corepack pnpm@11.7.0 run check\n\nThis replaces #574, which could not be cleanly merged because release/v2/v2.6 already contains v2.6.0 finalization version-state commits.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:24:27Z",
          "mergedAt": "2026-07-06T03:26:07Z",
          "additions": 16,
          "deletions": 1,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 576,
          "url": "https://github.com/kungfu-systems/buildchain/pull/576",
          "title": "Prepare v2.6.2-alpha.0",
          "body": "Create the generated version-state commit for v2.6.2-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:28:38Z",
          "mergedAt": "2026-07-06T03:30:22Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 577,
          "url": "https://github.com/kungfu-systems/buildchain/pull/577",
          "title": "Prepare v2.6.2-alpha.0",
          "body": "Create the generated version-state commit for v2.6.2-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:32:27Z",
          "mergedAt": "2026-07-06T03:34:34Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 8,
          "url": "https://github.com/kungfu-systems/kfd/pull/8",
          "title": "docs(readme): explain KFD foundation model",
          "body": "## What\n\n- Adds a README foundation model that makes the KFD-1/2/3 worldview explicit.\n- Links docs/MAP.md to the new foundation-model section.\n\n## Registry agreement\n\n- [x] `node scripts/check.mjs` passes\n- [x] Decision texts remain append-only (README/docs navigation only)\n\n## Version impact (per KFD-1)\n\n- [x] patch (content operation)",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:35:29Z",
          "mergedAt": "2026-07-06T03:35:55Z",
          "additions": 45,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 284,
          "url": "https://github.com/kungfu-systems/kungfu/pull/284",
          "title": "fix(core): drop unused PrioritizedCommandGroup import in trace command",
          "body": "Merge feature/fix-ruff-dead-import into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:39:21Z",
          "mergedAt": "2026-07-06T03:39:26Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 285,
          "url": "https://github.com/kungfu-systems/kungfu/pull/285",
          "title": "refactor(core): resolve the judgment-call strict findings (behavior-preserving)",
          "body": "Merge feature/py-strict-type-fixes-b into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:46:02Z",
          "mergedAt": "2026-07-06T03:46:08Z",
          "additions": 26,
          "deletions": 18,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 286,
          "url": "https://github.com/kungfu-systems/kungfu/pull/286",
          "title": "feat(agent): ship local onboarding pack",
          "body": "## Summary\n- ship a local Kungfu Agent Onboarding Pack with docs, command metadata, mode selection, safety boundaries, and provider skills\n- expose `kungfu agent` as the local discovery surface and package the pack into the frozen runtime\n- extend verification so pack files, package data, frozen data files, GUI/TUI pointers, and kfx sandbox fixtures stay covered\n\n## Validation\n- `./kungfu-code verify --full --with-app` -> 39/39 passed on the linear branch\n- `node scripts/no-bash-guard.mjs && git diff --check`\n- `node scripts/verify-agent-pack.mjs`\n- `uv run --frozen mypy src/python/kungfu`\n\nSupersedes #280; this branch has an identical tracked tree but a linear single-commit history for the repository rebase-only merge policy.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:54:09Z",
          "mergedAt": "2026-07-06T03:54:44Z",
          "additions": 982,
          "deletions": 26,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 287,
          "url": "https://github.com/kungfu-systems/kungfu/pull/287",
          "title": "feat(kfx): add the C++ guest capability end and prebuilt-artifact service entry",
          "body": "Merge feature/kfx-cpp-guest into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T03:56:44Z",
          "mergedAt": "2026-07-06T03:56:49Z",
          "additions": 1172,
          "deletions": 17,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 9,
          "url": "https://github.com/kungfu-systems/kfd/pull/9",
          "title": "docs(kfd-3): clarify augmentation stance",
          "body": "## What\n\n- Clarifies KFD-3 as an augmentation stance rather than a control stance.\n- Makes the shared work environment / first-class agent interface model explicit in README and KFD-3.\n\n## Registry agreement\n\n- [x] `node scripts/check.mjs` passes\n- [x] Decision texts remain append-only (editorial clarification)\n\n## Version impact (per KFD-1)\n\n- [x] patch (content operation)",
          "author": "dongkeren",
          "createdAt": "2026-07-06T04:19:19Z",
          "mergedAt": "2026-07-06T04:19:38Z",
          "additions": 16,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 578,
          "url": "https://github.com/kungfu-systems/buildchain/pull/578",
          "title": "fix(release): enforce GitHub release metadata",
          "body": "## Summary\n- add a Buildchain helper that creates or patches GitHub Releases with tag-derived metadata\n- mark exact alpha releases as prerelease and never latest\n- mark exact stable releases as latest\n- replace unmanaged `gh release create` in binary distribution with the helper\n\n## Validation\n- node --test tests/github-release-metadata.test.mjs\n- node --test tests/build-surface.test.mjs\n- node scripts/check-inventory.mjs\n- bash scripts/check-workflows.sh\n- corepack pnpm@11.7.0 run check\n\nDogfood plan: after merge to dev, promote through alpha and verify the generated alpha GitHub Release is `isPrerelease=true` and `isLatest=false`, while the stable v2.6.1 release remains latest.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T04:26:55Z",
          "mergedAt": "2026-07-06T04:28:35Z",
          "additions": 317,
          "deletions": 2,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 579,
          "url": "https://github.com/kungfu-systems/buildchain/pull/579",
          "title": "chore(release): promote v2.6.3 alpha metadata fix",
          "body": "## Summary\n- dogfood the GitHub Release metadata enforcement added in #578\n- promote the dev line into alpha so the next alpha release is created by Buildchain itself\n\n## Validation\n- dev Verify succeeded: https://github.com/kungfu-systems/buildchain/actions/runs/28767844148\n\nExpected dogfood result: the generated exact alpha GitHub Release must be prerelease=true and latest=false, and npm latest must remain the stable release.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T04:29:46Z",
          "mergedAt": "2026-07-06T04:31:36Z",
          "additions": 317,
          "deletions": 2,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 580,
          "url": "https://github.com/kungfu-systems/buildchain/pull/580",
          "title": "Prepare v2.6.2-alpha.1",
          "body": "Create the generated version-state commit for v2.6.2-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T04:33:42Z",
          "mergedAt": "2026-07-06T04:36:07Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 581,
          "url": "https://github.com/kungfu-systems/buildchain/pull/581",
          "title": "Prepare v2.6.2-alpha.1",
          "body": "Create the generated version-state commit for v2.6.2-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T04:38:08Z",
          "mergedAt": "2026-07-06T04:41:02Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 288,
          "url": "https://github.com/kungfu-systems/kungfu/pull/288",
          "title": "feat(kfx): add KFD-1 contract validation",
          "body": "## Summary\n- add `framework/kfx/kungfu-kfx.contract.json` as the machine-readable KFX contract for package manifests, first-party manifests, discovery defaults, and contract metadata\n- validate KFX manifests from Node (`@kungfu-tech/kfx`, GUI, SDK) and Python (`kungfu kfx`, skill dependency binding, first-party trust) against the same JSON Schema contract\n- freeze the KFX contract into `dist/kungfu/config`, add artifact hash verification and frozen runtime `kungfu kfx contract --json` smoke coverage\n- document the KFX contract as a KFD-1 welded surface in `docs/contracts.md`, `docs/extensions.md`, and `docs/versioning.md`\n\n## Validation\n- `./kungfu-code verify --full` -> `40/40 passed`\n- full verify rebuilt core native artifacts, froze the runtime, built C++ and Python KFX probes, checked KFX/config contract artifact hashes, and ran journal fact fixtures\n\n## Notes\n- Added `ajv` for Node JSON Schema validation rather than hand-rolling schema checks.\n- The generated LangChain fixture venv remains git-ignored; the no-bash guard skips venv-style cache directories so third-party package scripts do not fail the repo gate.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T05:05:15Z",
          "mergedAt": "2026-07-06T05:06:08Z",
          "additions": 1118,
          "deletions": 101,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 290,
          "url": "https://github.com/kungfu-systems/kungfu/pull/290",
          "title": "feat(contract): add shared KFD-1 contract registry",
          "body": "Summary:\n- Add a shared KFD-1 contract registry for config, kfx, and skill welded contract artifacts.\n- Add Python/Node runtime helpers and CLI inspection for contract verification.\n- Make build/freeze/verify copy and hash-check registry-driven contract artifacts.\n\nValidation:\n- ./kungfu-code verify --full passed 49/49.\n- Frozen CLI smokes passed: kungfu contract verify --json, kungfu skill contract --json, kungfu skill schema --name source --json, kungfu --version.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T05:49:39Z",
          "mergedAt": "2026-07-06T05:50:43Z",
          "additions": 1071,
          "deletions": 177,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 582,
          "url": "https://github.com/kungfu-systems/buildchain/pull/582",
          "title": "chore(release): promote v2.6.2",
          "body": "Promote Buildchain v2.6.2 from alpha to stable release.\\n\\nValidation focus:\\n- GitHub Release metadata helper dogfooded on alpha.\\n- Stable release should publish latest and make GitHub Release latest.\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T05:48:59Z",
          "mergedAt": "2026-07-06T05:50:46Z",
          "additions": 318,
          "deletions": 3,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 583,
          "url": "https://github.com/kungfu-systems/buildchain/pull/583",
          "title": "Release v2.6.2",
          "body": "Create the generated version-state commit for v2.6.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T05:53:06Z",
          "mergedAt": "2026-07-06T05:55:11Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 584,
          "url": "https://github.com/kungfu-systems/buildchain/pull/584",
          "title": "Prepare v2.6.3-alpha.0",
          "body": "Create the generated version-state commit for v2.6.3-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T05:57:38Z",
          "mergedAt": "2026-07-06T05:59:23Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 291,
          "url": "https://github.com/kungfu-systems/kungfu/pull/291",
          "title": "feat(rewind): add fact bridge ingestion sync",
          "body": "## Summary\n- add `kungfu report` for external, non-managed run lifecycle, cost, approval, and event facts\n- add `kungfu remote` source registry and source-scoped runtime mirror sync for `journal` / `rewind` / `work`\n- expose remote mirrored work/runs with `remote:<source-id>`, `sync_state`, `last_synced_at`, and `capture_mode` labels through CLI/API\n- wire the remote work projection into the GUI runtime handle and reference TUI summary\n- update agent onboarding pack and Rewind API projection for reported approval fields\n\n## Verification\n- `./kungfu-code verify --full` (51/51 passed on linear branch)\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T06:36:02Z",
          "mergedAt": "2026-07-06T06:36:46Z",
          "additions": 1630,
          "deletions": 24,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 585,
          "url": "https://github.com/kungfu-systems/buildchain/pull/585",
          "title": "feat(release): add release propagation graph",
          "body": "## Summary\n\n- adds a passport-driven release propagation graph core with DAG validation, default channel-preserving alpha/release mapping, exact upstream package/passport locks, and downstream lock writing\n- adds `buildchain release-propagation plan|write-lock` plus the `@kungfu-tech/buildchain/release-propagation` export\n- adds `.github/workflows/release-propagation.yml` so upstream releases can create downstream lock PRs without consumer hand-written resolver/lock YAML\n- documents the generic A -> B -> C model and includes a safe `kfd -> site-libkungfu-dev` shaped fixture\n- refreshes `dist/site` so site consumers can render the new docs/CLI/workflow facts from the package bundle\n\n## Validation\n\n- `node --test tests/release-propagation.test.mjs`\n- `pnpm run check:workflows`\n- `pnpm run test:unit` (320 tests)\n- `pnpm run check`\n- `npm pack --dry-run --json --registry=https://registry.npmjs.org/` with package contents check for new core/CLI/docs/fixture README\n\n## Notes\n\n- This PR targets the new protected `dev/v2/v2.7` line.\n- `dev/v2/v2.7` has branch protection enabled with required `check`, strict status checks, admin enforcement, one approving review, no force pushes/deletions, and conversation resolution required.\n- The reusable workflow defaults to dry-run; real downstream PR creation requires a token with downstream contents and pull request write permission.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T06:48:20Z",
          "mergedAt": "2026-07-06T06:50:14Z",
          "additions": 1090,
          "deletions": 0,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 589,
          "url": "https://github.com/kungfu-systems/buildchain/pull/589",
          "title": "chore(release): initialize v2.7 version state",
          "body": "Initialize the v2.7 development line package version as 2.7.0-alpha.0 so dev/v2/v2.7 -> alpha/v2/v2.7 release PR verification can pass.\\n\\nValidation:\\n- BUILDCHAIN_HEAD_REF=dev/v2/v2.7 BUILDCHAIN_BASE_REF=alpha/v2/v2.7 BUILDCHAIN_SOURCE_CWD=/Users/dkr/Worktrees/buildchain/feature/release-propagation-graph node scripts/verify-release-pr.mjs\\n- pnpm run check:site\\n- node --test tests/release-line-policy.test.mjs tests/cli.test.mjs --test-name-pattern 'release dry-run|version'",
          "author": "dongkeren",
          "createdAt": "2026-07-06T06:55:31Z",
          "mergedAt": "2026-07-06T06:57:31Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 10,
          "url": "https://github.com/kungfu-systems/kfd/pull/10",
          "title": "Add KFD npm trusted publishing workflow",
          "body": "## Summary\n- align published KFD package paths for site consumption\n- add npm trusted publishing workflow using GitHub Actions OIDC\n- bump package to 1.0.0-alpha.1 for trusted publishing verification\n\n## Verification\n- node scripts/check.mjs\n- actionlint .github/workflows/publish-npm.yml\n- npm pack --dry-run --json\n- npm trust list @kungfu-tech/kfd --json --registry=https://registry.npmjs.org/\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-06T06:36:15Z",
          "mergedAt": "2026-07-06T06:58:04Z",
          "additions": 568,
          "deletions": 29,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 586,
          "url": "https://github.com/kungfu-systems/buildchain/pull/586",
          "title": "release: promote v2.7 alpha",
          "body": "Promote Buildchain v2.7 development line to alpha after release propagation graph landed.\\n\\nValidation already passed on #585: `pnpm run check` and Buildchain dogfood fixture checks.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T06:52:34Z",
          "mergedAt": "2026-07-06T06:59:30Z",
          "additions": 1091,
          "deletions": 1,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 11,
          "url": "https://github.com/kungfu-systems/kfd/pull/11",
          "title": "chore(release): promote dev to alpha v1.0",
          "body": "Promote the KFD dev line to alpha after routing releases through Buildchain-managed publish transactions.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T06:59:33Z",
          "mergedAt": "2026-07-06T07:01:32Z",
          "additions": 388,
          "deletions": 11,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 591,
          "url": "https://github.com/kungfu-systems/buildchain/pull/591",
          "title": "release: promote v2.7 stable",
          "body": "Promote Buildchain v2.7 alpha to stable after alpha promotion succeeded.\\n\\nAlpha evidence:\\n- tag: v2.7.0-alpha.0\\n- npm dist-tag alpha: 2.7.0-alpha.0\\n- alpha branch: e6f1bb7143fa37e1d20d493ab175a8f263405660",
          "author": "dongkeren",
          "createdAt": "2026-07-06T07:02:15Z",
          "mergedAt": "2026-07-06T07:04:15Z",
          "additions": 1091,
          "deletions": 1,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 12,
          "url": "https://github.com/kungfu-systems/kfd/pull/12",
          "title": "ci(buildchain): pass promotion token to release workflow",
          "body": "Map the organization GitHub token to Buildchain's promotion-token secret input so KFD promotion can read protected branch governance details instead of falling back to the default GITHUB_TOKEN.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T07:03:58Z",
          "mergedAt": "2026-07-06T07:05:39Z",
          "additions": 4,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 13,
          "url": "https://github.com/kungfu-systems/kfd/pull/13",
          "title": "chore(release): promote Buildchain token mapping to alpha",
          "body": "Promote the KFD release workflow token mapping so Buildchain promotion can read protected branch governance details before npm publish.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T07:06:04Z",
          "mergedAt": "2026-07-06T07:08:10Z",
          "additions": 4,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 590,
          "url": "https://github.com/kungfu-systems/buildchain/pull/590",
          "title": "Prepare v2.7.0-alpha.0",
          "body": "Create the generated version-state commit for v2.7.0-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T07:01:36Z",
          "mergedAt": "2026-07-06T07:10:40Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 593,
          "url": "https://github.com/kungfu-systems/buildchain/pull/593",
          "title": "Release v2.7.0",
          "body": "Create the generated version-state commit for v2.7.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T07:06:27Z",
          "mergedAt": "2026-07-06T07:10:40Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 292,
          "url": "https://github.com/kungfu-systems/kungfu/pull/292",
          "title": "feat(sdk): add KFD contract evidence",
          "body": "## Summary\n\nAdd the first KFD-native SDK contract prototype for local contract adoption, explicit writes, generated fixtures, and advisory evidence output.\n\nThis PR does not change release policy, does not edit KFD text, and does not enforce a new release gate. It shapes local JSON evidence so a future Buildchain/release-passport task can consume Kungfu-owned contract facts instead of redefining them.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- Add `kungfu sdk contract adopt <surface> --source <path> --json` for existing config/kfx/skill contract sources.\n- Add `kungfu sdk contract render <surface> --check|--write --json`.\n- Add `kungfu sdk contract add <surface> --json` with registry entry and deterministic drift/probe fixture generation.\n- Add `kungfu sdk contract evidence [surface] --json` as read-only KFD-1 local evidence.\n- Document the KFD-1/2/3 SDK and future release-gate design.\n\n## Verification\n\n- `./kungfu-code --filter @kungfu-tech/sdk run build`\n- `./kungfu-code exec biome check developer/sdk/src/sdk.js developer/sdk/tests/contract-cli.test.mjs`\n- `node developer/sdk/src/sdk.js contract evidence --json`\n- `git diff --check origin/dev/v4/v4.0..HEAD`\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: this PR adds advisory local SDK evidence for KFD-1 contracts. It does not enforce release policy, publish artifacts, or change release workflows.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T07:10:47Z",
          "mergedAt": "2026-07-06T07:11:55Z",
          "additions": 1147,
          "deletions": 9,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 14,
          "url": "https://github.com/kungfu-systems/kfd/pull/14",
          "title": "ci(buildchain): ignore Buildchain runtime state",
          "body": "Ignore Buildchain runtime and release-candidate scratch files so version-state verification only sees intentional version file changes.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T07:11:40Z",
          "mergedAt": "2026-07-06T07:13:48Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 15,
          "url": "https://github.com/kungfu-systems/kfd/pull/15",
          "title": "chore(release): promote Buildchain runtime ignore to alpha",
          "body": "Promote the .buildchain ignore fix so Buildchain version-state verification can proceed without treating runtime scratch files as product source changes.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T07:14:09Z",
          "mergedAt": "2026-07-06T07:16:02Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 595,
          "url": "https://github.com/kungfu-systems/buildchain/pull/595",
          "title": "Prepare v2.7.1-alpha.0",
          "body": "Create the generated version-state commit for v2.7.1-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T07:13:29Z",
          "mergedAt": "2026-07-06T07:16:30Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 16,
          "url": "https://github.com/kungfu-systems/kfd/pull/16",
          "title": "Prepare v1.0.0-alpha.1",
          "body": "Create the generated version-state commit for v1.0.0-alpha.1.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T07:16:54Z",
          "mergedAt": "2026-07-06T07:18:37Z",
          "additions": 19,
          "deletions": 5,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 17,
          "url": "https://github.com/kungfu-systems/kfd/pull/17",
          "title": "Prepare v1.0.0-alpha.1",
          "body": "Create the generated version-state commit for v1.0.0-alpha.1.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T07:19:23Z",
          "mergedAt": "2026-07-06T07:21:17Z",
          "additions": 19,
          "deletions": 5,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 293,
          "url": "https://github.com/kungfu-systems/kungfu/pull/293",
          "title": "feat(agent): add codex goal report bootstrap",
          "body": "## Summary\n- add `kungfu codex report-goal` and `verify-goal-report` for native Codex goal receipts\n- add agent bootstrap/status/mode/unbootstrap/uninstall policy surfaces with dry-run defaults\n- update the agent onboarding pack and skills so report closeout verifies receipts and managed-run keeps report as fallback\n- add fixtures for Codex goal receipts and agent bootstrap behavior\n\n## Verification\n- `uv run --frozen python -m py_compile src/python/kungfu/cli/commands/agent.py src/python/kungfu/cli/commands/codex.py src/python/kungfu/cli/commands/__registry__.py`\n- `node scripts/verify-agent-pack.mjs`\n- `node tests/fixtures/rewind-demo-codex-goal-report/run.mjs`\n- `node tests/fixtures/agent-demo-bootstrap/run.mjs`\n- `./kungfu-code build:core`\n- `./kungfu-code freeze`\n- `./kungfu-code verify`\n- frozen CLI smoke: `kungfu codex report-goal` + `kungfu codex verify-goal-report`\n\n## Notes\n- `./kungfu-code --filter @kungfu-tech/core run package` reached binary staging but then failed in an existing package script path handling error (`ERR_INVALID_ARG_TYPE` in `framework/core/.gyp/run-build.js`).\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T07:31:12Z",
          "mergedAt": "2026-07-06T07:32:06Z",
          "additions": 913,
          "deletions": 12,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 18,
          "url": "https://github.com/kungfu-systems/kfd/pull/18",
          "title": "feat(metadata): expose KFD standards metadata",
          "body": "## Summary\n- add standards.json as the KFD-owned machine metadata surface for standard keys, document routes, schema IDs, and concept names\n- add JSON schemas for the standards metadata contract and KFD-1 contract-world/witness schema identities\n- publish the new metadata surface through package files and explicit subpath exports\n\n## Validation\n- node scripts/check.mjs\n- npm pack --dry-run --json\n- local package import smoke for @kungfu-tech/kfd/standards.json\n\n## Release impact\n- additive package structure and standards metadata surface; release-impact.json marks the Buildchain impact as minor",
          "author": "dongkeren",
          "createdAt": "2026-07-06T08:02:45Z",
          "mergedAt": "2026-07-06T08:04:42Z",
          "additions": 556,
          "deletions": 13,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 19,
          "url": "https://github.com/kungfu-systems/kfd/pull/19",
          "title": "ci(metadata): include standards metadata in artifacts",
          "body": "## Summary\n- include standards.json and schemas/ in Buildchain release candidate artifacts\n- require the standards metadata schema and KFD-1 schema identity files in artifact validation\n\n## Validation\n- node scripts/check.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T08:06:29Z",
          "mergedAt": "2026-07-06T08:08:20Z",
          "additions": 3,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 20,
          "url": "https://github.com/kungfu-systems/kfd/pull/20",
          "title": "ci(build): limit KFD verification to Linux",
          "body": "## Summary\n- switch the KFD Buildchain reusable build call to a custom single-platform matrix\n- keep only the Linux x64 GitHub-hosted runner for KFD package verification\n\n## Validation\n- node scripts/check.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T08:09:57Z",
          "mergedAt": "2026-07-06T08:11:18Z",
          "additions": 3,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 21,
          "url": "https://github.com/kungfu-systems/kfd/pull/21",
          "title": "release(alpha): promote KFD standards metadata",
          "body": "## Summary\n- promote KFD standards metadata and Linux-only KFD verification from dev to alpha\n- publish a new @kungfu-tech/kfd alpha through Buildchain ref promotion after alpha Verify succeeds\n\n## Validation before channel PR\n- PR #18: metadata package surface checks passed\n- PR #19: metadata artifact checks passed\n- PR #20: Linux-only Buildchain matrix checks passed",
          "author": "dongkeren",
          "createdAt": "2026-07-06T08:12:20Z",
          "mergedAt": "2026-07-06T08:15:12Z",
          "additions": 562,
          "deletions": 15,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 22,
          "url": "https://github.com/kungfu-systems/kfd/pull/22",
          "title": "Prepare v1.0.0-alpha.2",
          "body": "Create the generated version-state commit for v1.0.0-alpha.2.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T08:16:09Z",
          "mergedAt": "2026-07-06T08:21:36Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 23,
          "url": "https://github.com/kungfu-systems/kfd/pull/23",
          "title": "Prepare v1.0.0-alpha.2",
          "body": "Create the generated version-state commit for v1.0.0-alpha.2.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T08:22:27Z",
          "mergedAt": "2026-07-06T08:24:40Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 294,
          "url": "https://github.com/kungfu-systems/kungfu/pull/294",
          "title": "fix(terminal): scope the managed tmux socket to the runtime home",
          "body": "A tmux server freezes its env at creation; the managed backend used one fixed -L kungfu-managed socket for every runtime home, so a server started by one home could leak its stale KF_RUNTIME_DIR/launcher into a managed session created later by a different home (cost/journal facts then landed in the wrong home). Derive the socket per runtime home (kungfu-managed-<hash>): each server belongs to exactly one home, deterministic so restart reattaches, KF_TMUX_SOCKET still overrides.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T08:27:43Z",
          "mergedAt": "2026-07-06T08:27:49Z",
          "additions": 31,
          "deletions": 7,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 598,
          "url": "https://github.com/kungfu-systems/buildchain/pull/598",
          "title": "feat(release): add KFD-1 contract-world gate",
          "body": "## Summary\n- add first-class KFD-1 contract-world release gate evidence backed by @kungfu-tech/kfd metadata\n- pass KFD-1 witness inputs through release-candidate-promote and promote-buildchain-ref into release passports\n- bind managed branch protection required checks to GitHub Actions check runs\n\n## Validation\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T08:48:36Z",
          "mergedAt": "2026-07-06T08:50:46Z",
          "additions": 794,
          "deletions": 71,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 599,
          "url": "https://github.com/kungfu-systems/buildchain/pull/599",
          "title": "release: promote v2.8 alpha",
          "body": "Promote Buildchain v2.8 development line to alpha for KFD-1 contract-world release gate validation.\n\nValidation before PR:\n- dev/v2/v2.8 Verify run 28779479361 passed",
          "author": "dongkeren",
          "createdAt": "2026-07-06T08:52:02Z",
          "mergedAt": "2026-07-06T08:53:38Z",
          "additions": 794,
          "deletions": 71,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 601,
          "url": "https://github.com/kungfu-systems/buildchain/pull/601",
          "title": "release: promote v2.8 stable",
          "body": "Promote Buildchain v2.8 alpha to stable release.\n\nAlpha validation:\n- Buildchain Ref Promotion run 28779698806 passed\n- npm @kungfu-tech/buildchain@2.8.0-alpha.0 published under dist-tag alpha\n- v2.8.0-alpha.0 and v2.8-alpha tags point at alpha/v2/v2.8",
          "author": "dongkeren",
          "createdAt": "2026-07-06T08:56:49Z",
          "mergedAt": "2026-07-06T09:00:11Z",
          "additions": 794,
          "deletions": 71,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 295,
          "url": "https://github.com/kungfu-systems/kungfu/pull/295",
          "title": "feat(core): type the pykungfu native binding via build-generated stubs",
          "body": "Merge feature/pykungfu-stub-typing into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T09:03:22Z",
          "mergedAt": "2026-07-06T09:03:28Z",
          "additions": 6788,
          "deletions": 7,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 602,
          "url": "https://github.com/kungfu-systems/buildchain/pull/602",
          "title": "Release v2.8.0",
          "body": "Create the generated version-state commit for v2.8.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T09:02:27Z",
          "mergedAt": "2026-07-06T09:04:21Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 297,
          "url": "https://github.com/kungfu-systems/kungfu/pull/297",
          "title": "chore(verify): align stale kfc naming with the kungfu executable",
          "body": "Merge feature/verify-kungfu-naming into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T09:50:36Z",
          "mergedAt": "2026-07-06T09:50:41Z",
          "additions": 44,
          "deletions": 44,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 296,
          "url": "https://github.com/kungfu-systems/kungfu/pull/296",
          "title": "feat(sdk): add agent-first KFD-1 canonical policy",
          "body": "## Summary\n\n- add an agent-first KFD-1 canonical policy for Kungfu contract surfaces\n- consume `@kungfu-tech/kfd@1.0.0-alpha.2` and `@kungfu-tech/buildchain@2.8.0` instead of redefining KFD metadata or Buildchain JSON formatting locally\n- add `kungfu sdk contract policy|witness|audit --json` and wire the policy into frozen contract artifacts\n- canonicalize config/kfx/skill contract mother files through the SDK renderer\n- update docs and SDK tests for the Buildchain KFD-1 witness path\n\n## Validation\n\n- `pnpm --filter @kungfu-tech/sdk run build`\n- `pnpm exec biome check developer/sdk/src/sdk.js developer/sdk/tests/contract-cli.test.mjs scripts/contract-registry.cjs docs/contracts.md docs/kfd-native-sdk-release-gates.md types/vendor-shims.d.ts`\n- `node developer/sdk/src/sdk.js contract audit --json`\n- `node developer/sdk/src/sdk.js contract evidence --json`\n- `git diff --check`\n- `copyContractArtifacts` temp smoke confirmed the canonical policy is copied with the registry/contracts\n\n## Known residual\n\n- `pnpm run check:types` still fails on pre-existing `framework/core/.gyp` and vendor JS typing gaps after this slice's SDK typing issues were removed.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T09:49:39Z",
          "mergedAt": "2026-07-06T10:02:20Z",
          "additions": 1254,
          "deletions": 132,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 604,
          "url": "https://github.com/kungfu-systems/buildchain/pull/604",
          "title": "feat(contract): add Buildchain floating ref contract lock",
          "body": "## Summary\n\n- add a Buildchain runtime contract world manifest for stable floating refs such as `@v2`\n- add consumer-side `buildchain.contract-lock.json` validation with compatible-drift issue reporting and breaking-drift fail-fast\n- wire contract lock checks into reusable build and release-candidate promote workflows before heavy/publish work\n- document Buildchain KFD-1 support, witness boundaries, consumer usage, and value in the release passport and reusable workflow docs\n- dogfood the mechanism in Buildchain with its own contract lock and generated site bundle contract facts\n\n## Validation\n\n- `node scripts/generate-site-bundle.mjs`\n- `BUILDCHAIN_RUNTIME_REF=v2 BUILDCHAIN_RUNTIME_SHA=$(git ls-remote origin refs/tags/v2 | awk '{print $1}') BUILDCHAIN_CONTRACT_ACCEPTED_AT=2026-07-06T00:00:00.000Z node scripts/buildchain-contract-lock.mjs write-lock --output buildchain.contract-lock.json`\n- `corepack pnpm@11.7.0 run check`\n- `BUILDCHAIN_RUNTIME_ROOT=. BUILDCHAIN_RUNTIME_REF=v2 BUILDCHAIN_RUNTIME_SHA=$(git rev-parse HEAD) BUILDCHAIN_RUNTIME_CLASS=stable BUILDCHAIN_CONTRACT_LOCK_PATH=buildchain.contract-lock.json BUILDCHAIN_CONTRACT_DRIFT_ISSUE_BODY=/tmp/buildchain-contract-drift-issue.md node scripts/buildchain-contract-lock.mjs check`\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T10:08:30Z",
          "mergedAt": "2026-07-06T10:10:30Z",
          "additions": 1471,
          "deletions": 2,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 24,
          "url": "https://github.com/kungfu-systems/kfd/pull/24",
          "title": "feat(kfd): add KFD-3 collaboration interface schemas",
          "body": "## Summary\n\n- add KFD-3 collaboration-interface and witness schemas\n- expose the new KFD-3 schema IDs, paths, and concept names in standards.json\n- document the product profile boundary for participant-facing collaboration interfaces\n- update release-impact and conformance checks for the additive KFD-3 metadata surface\n\n## Verification\n\n- npm run check\n- jq empty standards.json release-impact.json schemas/kfd-3/collaboration-interface.schema.json schemas/kfd-3/witness.schema.json\n\n## Governance\n\n- KFD-3 remains participant-oriented, not agent-only\n- product-specific profiles stay in product repositories\n- package line remains v1.0; this is an additive metadata/schema surface\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T10:53:35Z",
          "mergedAt": "2026-07-06T10:54:59Z",
          "additions": 609,
          "deletions": 6,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 25,
          "url": "https://github.com/kungfu-systems/kfd/pull/25",
          "title": "release(alpha): promote KFD collaboration interface metadata",
          "body": "## What\n\nPromote the latest KFD dev line into the alpha channel so the KFD-3 collaboration-interface metadata and schemas can be published as the next @kungfu-tech/kfd alpha.\n\nIncluded dev commits:\n- Merge PR #24 with KFD-3 collaboration-interface and witness schemas.\n- Preserve the Buildchain version-state return commit from the previous alpha.\n\n## Registry agreement\n\n- [x] Latest dev Verify workflow passed on fb23afa0b66a5f09ea62f39eb08c57e66714a147.\n- [x] KFD package release remains on the v1.0 line; Buildchain should advance the prerelease alpha number.\n\n## Version impact\n\n- [x] alpha promotion for additive KFD metadata/schema surface; npm dist-tag should remain alpha.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T11:18:34Z",
          "mergedAt": "2026-07-06T11:21:12Z",
          "additions": 609,
          "deletions": 6,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 26,
          "url": "https://github.com/kungfu-systems/kfd/pull/26",
          "title": "Prepare v1.0.0-alpha.3",
          "body": "Create the generated version-state commit for v1.0.0-alpha.3.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T11:22:15Z",
          "mergedAt": "2026-07-06T11:24:07Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 27,
          "url": "https://github.com/kungfu-systems/kfd/pull/27",
          "title": "Prepare v1.0.0-alpha.3",
          "body": "Create the generated version-state commit for v1.0.0-alpha.3.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T11:24:53Z",
          "mergedAt": "2026-07-06T11:26:26Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 605,
          "url": "https://github.com/kungfu-systems/buildchain/pull/605",
          "title": "feat(release): add KFD-3 collaboration interface gate",
          "body": "## Summary\n- add KFD-3 collaboration-interface prebuild and artifact witness release passport gate\n- pass KFD-3 witness inputs through release-candidate-promote and promote-buildchain-ref\n- expose the KFD-3 gate in the v2 contract world and docs\n\n## Validation\n- node scripts/check-inventory.mjs && node --test tests/release-passport.test.mjs tests/buildchain-contract.test.mjs tests/build-surface.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T11:38:54Z",
          "mergedAt": "2026-07-06T11:40:06Z",
          "additions": 1142,
          "deletions": 80,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 606,
          "url": "https://github.com/kungfu-systems/buildchain/pull/606",
          "title": "feat(release): add KFD trust passport audits",
          "body": "## Summary\n- add KFD-1 self contract verification, KFD-2 public release trust audit, and KFD-3 self-verification trust proof into release passports\n- enforce publish-gate source-lock inputs through release-candidate-promote and fail closed on retained legacy release workflows that bypass source locks\n- update contract/docs/site bundle and tests for floating @v2 drift protection across publish models\n\n## Verification\n- node --test tests/build-surface.test.mjs tests/buildchain-contract.test.mjs tests/release-passport.test.mjs\n- node scripts/check-inventory.mjs\n- corepack pnpm run build\n- node scripts/generate-site-bundle.mjs\n- BUILDCHAIN_RUNTIME_REF=v2 BUILDCHAIN_RUNTIME_SHA=$(git ls-remote origin refs/tags/v2 | awk '{print $1}') BUILDCHAIN_CONTRACT_ACCEPTED_AT=2026-07-06T00:00:00.000Z node scripts/buildchain-contract-lock.mjs write-lock --output buildchain.contract-lock.json\n- corepack pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:14:03Z",
          "mergedAt": "2026-07-06T13:15:39Z",
          "additions": 1781,
          "deletions": 345,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 607,
          "url": "https://github.com/kungfu-systems/buildchain/pull/607",
          "title": "Promote v2.8 dev to alpha",
          "body": "## Summary\nPromote the current dev/v2/v2.8 tree to alpha/v2/v2.8 after #606.\n\nThis supersedes stale version-state PRs #600 and #603 so the release-candidate evidence and publish-gate source lock are regenerated from the current Buildchain tree.\n\n## Release intent\n- channel: alpha\n- source: dev/v2/v2.8\n- target: alpha/v2/v2.8\n- expected next prerelease: v2.8.1-alpha.0 or next available alpha patch\n",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T13:18:01Z",
          "mergedAt": "2026-07-06T13:19:55Z",
          "additions": 4271,
          "deletions": 304,
          "changedFiles": 40
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 28,
          "url": "https://github.com/kungfu-systems/kfd/pull/28",
          "title": "feat(kfd): add release trust metadata",
          "body": "## Summary\n- add KFD-2 release claims and release trust passport schemas\n- expose KFD-1/2/3 machine interface versions and decision document SHA-256 bindings in standards.json\n- add a KFD-1 release witness and wire it into the Buildchain release passport path\n- add KFD -> site-libkungfu-dev release propagation graph and workflow\n\n## Verification\n- node scripts/check.mjs\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n- buildchain release-propagation plan with a synthetic KFD alpha envelope\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:14:35Z",
          "mergedAt": "2026-07-06T13:20:53Z",
          "additions": 1201,
          "deletions": 16,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 609,
          "url": "https://github.com/kungfu-systems/buildchain/pull/609",
          "title": "fix(release): validate publish source locks generically",
          "body": "## Summary\n- make promote-buildchain-ref source-lock validation generic across semver and anchored/manual release models\n- keep release-candidate-promote source-lock enforcement enabled for floating @v2 consumers\n- retain anchored package diagnostics as a separate toolkit check instead of using it as the universal publish gate\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs tests/build-surface.test.mjs\n- corepack pnpm run build\n- corepack pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:24:41Z",
          "mergedAt": "2026-07-06T13:25:54Z",
          "additions": 146,
          "deletions": 87,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 29,
          "url": "https://github.com/kungfu-systems/kfd/pull/29",
          "title": "release(alpha): promote KFD release trust metadata",
          "body": "Promote the KFD-2 release claims and release trust passport metadata to alpha through the Buildchain channel flow.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:21:52Z",
          "mergedAt": "2026-07-06T13:26:09Z",
          "additions": 1201,
          "deletions": 16,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 610,
          "url": "https://github.com/kungfu-systems/buildchain/pull/610",
          "title": "Promote v2.8 dev to alpha",
          "body": "## Summary\nPromote the current dev/v2/v2.8 tree to alpha/v2/v2.8 after #606 and #609.\n\nThis refreshes the alpha channel so Buildchain self-promotion uses the generic publish source-lock validator.\n\n## Release intent\n- channel: alpha\n- source: dev/v2/v2.8\n- target: alpha/v2/v2.8\n- expected next prerelease: next available v2.8 alpha patch\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:26:20Z",
          "mergedAt": "2026-07-06T13:27:30Z",
          "additions": 146,
          "deletions": 87,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 30,
          "url": "https://github.com/kungfu-systems/kfd/pull/30",
          "title": "Prepare v1.0.0-alpha.4",
          "body": "Create the generated version-state commit for v1.0.0-alpha.4.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T13:27:14Z",
          "mergedAt": "2026-07-06T13:29:04Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 9,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/9",
          "title": "feat(site): render KFD package surface",
          "body": "## Summary\n- render the KFD package-owned site bundle at /kfd/ and kfd.libkungfu.dev\n- add @kungfu-tech/kfd as the upstream fact source for kfd-site.json, registry, standards, and decisions\n- make the Buildchain web-surface workflow honor KFD release propagation locks before install/build\n\n## Validation\n- node scripts/prepare-kfd-upstream.mjs && npm install --package-lock-only --ignore-scripts --registry=https://registry.npmjs.org/ && npm ci --ignore-scripts --registry=https://registry.npmjs.org/ && npm run build && npm run check && bash -n scripts/build-site.sh scripts/check-site.sh\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:38:31Z",
          "mergedAt": "2026-07-06T13:40:29Z",
          "additions": 397,
          "deletions": 7,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 32,
          "url": "https://github.com/kungfu-systems/kfd/pull/32",
          "title": "fix(release): target KFD site propagation at main",
          "body": "## Summary\n- point KFD release propagation at the actual site-libkungfu-dev main branch\n- document the downstream consumed site bundle surfaces\n- update KFD-1 welded witnesses and release impact for the propagation graph/workflow change\n\n## Validation\n- node scripts/check.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:38:31Z",
          "mergedAt": "2026-07-06T13:40:30Z",
          "additions": 22,
          "deletions": 9,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 612,
          "url": "https://github.com/kungfu-systems/buildchain/pull/612",
          "title": "feat(release): publish GitHub release evidence from promote wrapper",
          "body": "## Summary\n\n- expose declarative `github-release` inputs on `release-candidate-promote.yml`\n- create/update the exact-tag GitHub Release after a complete publish transaction and upload publish evidence plus release passport assets\n- dogfood the GitHub Release path in Buildchain semver promotion\n- tighten RC run selection so reused channel head branches cannot select stale PR-stage artifacts\n\n## Verification\n\n- `node --test tests/release-candidate.test.mjs tests/github-release-metadata.test.mjs tests/build-surface.test.mjs`\n- `node scripts/check-inventory.mjs`\n- `corepack pnpm run build`\n- `node scripts/generate-site-bundle.mjs`\n- `corepack pnpm run check`\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:41:02Z",
          "mergedAt": "2026-07-06T13:42:16Z",
          "additions": 202,
          "deletions": 10,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 613,
          "url": "https://github.com/kungfu-systems/buildchain/pull/613",
          "title": "Promote v2.8 dev to alpha",
          "body": "## Summary\n\nPromote the current v2.8 development line to alpha so Buildchain can dogfood the release-candidate promote wrapper, publish source-lock enforcement, and declarative GitHub Release evidence upload.\n\n## Verification\n\n- dev/v2/v2.8 PR checks must provide the PR-stage release candidate artifacts\n- merge to alpha/v2/v2.8 must run promote-only publication without selecting stale RC artifacts\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:43:01Z",
          "mergedAt": "2026-07-06T13:44:28Z",
          "additions": 202,
          "deletions": 10,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 31,
          "url": "https://github.com/kungfu-systems/kfd/pull/31",
          "title": "Prepare v1.0.0-alpha.4",
          "body": "Create the generated version-state commit for v1.0.0-alpha.4.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T13:30:00Z",
          "mergedAt": "2026-07-06T13:46:50Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 615,
          "url": "https://github.com/kungfu-systems/buildchain/pull/615",
          "title": "fix(release): run build surface fixture on channel PRs",
          "body": "## Summary\n- widen Build Surface Fixture pull_request branch globs so channel PRs like alpha/v2/v2.8 trigger the PR-stage RC build\n- add a regression assertion so the fixture stays aligned with release/verify workflow branch patterns\n\n## Why\n- alpha promotion run 28796226981 failed before publish because channel PR #613 had no successful Build Surface Fixture PR run to resolve release-candidate evidence from\n\n## Verification\n- bash scripts/check-workflows.sh\n- node --test tests/build-surface.test.mjs tests/release-candidate.test.mjs\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:51:03Z",
          "mergedAt": "2026-07-06T13:52:14Z",
          "additions": 7,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 617,
          "url": "https://github.com/kungfu-systems/buildchain/pull/617",
          "title": "fix(release): default fixture transfer mode on PR events",
          "body": "## Summary\n- avoid the workflow_dispatch-only inputs context in Build Surface Fixture pull_request runs\n- keep manual artifact-transfer-mode override for workflow_dispatch while defaulting PR runs to github-artifacts\n- update the regression assertion for the PR-safe expression\n\n## Why\n- Build Surface Fixture run 28796729227 started for channel PR #616 but failed at workflow startup before creating jobs\n\n## Verification\n- bash scripts/check-workflows.sh\n- node --test tests/build-surface.test.mjs tests/release-candidate.test.mjs\n- corepack pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:56:44Z",
          "mergedAt": "2026-07-06T13:58:16Z",
          "additions": 5,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 619,
          "url": "https://github.com/kungfu-systems/buildchain/pull/619",
          "title": "fix(release): grant fixture reusable workflow permissions",
          "body": "## Summary\n- grant Build Surface Fixture the issues:write permission required by the reusable .build.yml workflow\n- keep the fixture permission surface aligned with the called workflow so channel PR runs can start and produce RC artifacts\n- add a regression assertion for the caller permission\n\n## Why\n- Build Surface Fixture runs 28796729227 and 28797103513 failed at workflow startup before creating jobs after channel PR triggering was enabled\n- reusable workflows cannot elevate beyond the caller permissions\n\n## Verification\n- bash scripts/check-workflows.sh\n- node --test tests/build-surface.test.mjs tests/release-candidate.test.mjs\n- corepack pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:01:49Z",
          "mergedAt": "2026-07-06T14:04:00Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 620,
          "url": "https://github.com/kungfu-systems/buildchain/pull/620",
          "title": "Promote v2.8 dev to alpha",
          "body": "Promote Buildchain v2.8 dev to alpha after enabling semver GitHub Release publication dogfood and fixing Build Surface Fixture channel PR triggers/startup permissions.\n\nExpected dogfood:\n- PR-stage Build Surface Fixture produces release-candidate evidence.\n- Merge-stage buildchain-ref-promotion resolves that RC and promotes without rebuilding.\n- release-candidate-promote publishes GitHub Release evidence when the transaction completes.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:04:22Z",
          "mergedAt": "2026-07-06T14:06:25Z",
          "additions": 14,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 10,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/10",
          "title": "alpha: enable live preview and staging apply",
          "body": "## Summary\n- enable Buildchain preview apply and preview cleanup for same-repository PRs\n- enable protected staging apply on main pushes\n- keep production apply disabled while production remains pending\n- update deploy docs and infra-output checks to match the live preview/staging model\n\n## Validation\n- node scripts/prepare-kfd-upstream.mjs && npm install --package-lock-only --ignore-scripts --registry=https://registry.npmjs.org/ && npm ci --ignore-scripts --registry=https://registry.npmjs.org/ && npm run build && npm run check && git diff --check\n\n## Preview\nThis alpha PR is intended to trigger a Buildchain preview deployment once GitHub Actions runs with preview apply enabled.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T13:58:57Z",
          "mergedAt": "2026-07-06T14:13:07Z",
          "additions": 32,
          "deletions": 17,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 622,
          "url": "https://github.com/kungfu-systems/buildchain/pull/622",
          "title": "fix(release): include site contract in version state",
          "body": "## Summary\n- include dist/site/buildchain-contract.json#product.version in Buildchain own semver version state\n- add a regression check so generated site contract version changes are allowed in release promotion version-state commits\n\n## Why\n- alpha promotion run 28797656148 resolved the PR-stage RC and publish-gate lock successfully, but failed after semver bump because dist/site/buildchain-contract.json became stale\n\n## Verification\n- node --test tests/build-surface.test.mjs tests/promote-buildchain-ref.test.mjs\n- node scripts/check-inventory.mjs && node scripts/generate-site-bundle.mjs --check\n- corepack pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:11:14Z",
          "mergedAt": "2026-07-06T14:13:40Z",
          "additions": 19,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 623,
          "url": "https://github.com/kungfu-systems/buildchain/pull/623",
          "title": "Promote v2.8 dev to alpha",
          "body": "Promote Buildchain v2.8 dev to alpha after enabling semver GitHub Release publication dogfood and fixing Buildchain own semver version-state site contract.\n\nExpected dogfood:\n- PR-stage Build Surface Fixture produces release-candidate evidence.\n- Merge-stage buildchain-ref-promotion resolves that RC and promotes without rebuilding.\n- semver version-state includes package.json and dist/site/buildchain-contract.json.\n- release-candidate-promote publishes GitHub Release evidence when the transaction completes.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:13:59Z",
          "mergedAt": "2026-07-06T14:16:22Z",
          "additions": 19,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 33,
          "url": "https://github.com/kungfu-systems/kfd/pull/33",
          "title": "feat(kfd): add KFD-3 self collaboration witness",
          "body": "## What\n\n- Add KFD-owned KFD-3 collaboration-interface and prebuild/artifact witnesses.\n- Extend package exports, build artifacts, and release-impact metadata for the new self-verification surfaces.\n- Wire KFD release promotion to Buildchain alpha v2.8 KFD-3 release passport inputs.\n- Extend `node scripts/check.mjs` to verify KFD-3 witness hashes, closure, evidence pointers, and declared/exposed surface parity.\n\n## Verification\n\n- `npm run check`\n- `npm pack --dry-run --json`\n\n## Note\n\nThis uses `kungfu-systems/buildchain/...@alpha/v2/v2.8` for promotion because the current stable `@v2` ref does not yet expose the KFD-3 release passport inputs.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:14:47Z",
          "mergedAt": "2026-07-06T14:19:01Z",
          "additions": 1680,
          "deletions": 12,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 34,
          "url": "https://github.com/kungfu-systems/kfd/pull/34",
          "title": "release(alpha): promote KFD-3 self collaboration witness",
          "body": "## What\n\nPromote KFD dev/v1/v1.0 to alpha/v1/v1.0 after adding KFD-3 self collaboration-interface and witness verification.\n\n## Verification\n\n- PR #33 Verify passed\n- PR #33 Build passed\n- dev/v1/v1.0 push Verify passed\n\n## Release intent\n\nPublish the next @kungfu-tech/kfd alpha with KFD-3 self-verification artifacts and Buildchain KFD-3 release passport inputs.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:20:20Z",
          "mergedAt": "2026-07-06T14:22:35Z",
          "additions": 1701,
          "deletions": 20,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 299,
          "url": "https://github.com/kungfu-systems/kungfu/pull/299",
          "title": "feat(core): stop shipping the scientific stack in the frozen runtime",
          "body": "Merge feature/kfx-app-slim-depandas into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:22:38Z",
          "mergedAt": "2026-07-06T14:22:44Z",
          "additions": 64,
          "deletions": 46,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 11,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/11",
          "title": "alpha: link KFD decision pages from homepage",
          "body": "## Summary\\n- render KFD-1/2/3 cards as explicit links on the KFD homepage\\n- verify dist/kfd/1, /2, and /3 pages exist\\n- fail checks if the KFD homepage stops linking to registry decision pages\\n\\n## Validation\\n- node scripts/prepare-kfd-upstream.mjs\\n- npm install --package-lock-only --ignore-scripts --registry=https://registry.npmjs.org/\\n- npm ci --ignore-scripts --registry=https://registry.npmjs.org/\\n- npm run build\\n- npm run check\\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:25:32Z",
          "mergedAt": "2026-07-06T14:27:23Z",
          "additions": 39,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 626,
          "url": "https://github.com/kungfu-systems/buildchain/pull/626",
          "title": "fix(release): materialize version-state lifecycle outputs",
          "body": "## Summary\n- add a `version-state` lifecycle stage to Buildchain semver promotion so generated version-state files are materialized before verify/finalization\n- dogfood the stage for `dist/site/buildchain-contract.json` by regenerating the site bundle before semver release checks\n- make promote-buildchain-ref commit the verified declared version-state file contents, including generated derived files\n\n## Context\nThe semver dogfood alpha promotion reached the GitHub Release-enabled path but failed before publish finalization because `dist/site/buildchain-contract.json` was stale after the version bump. Directly listing the generated file as a version file was not enough; the promotion path also needs to run the generator before verification and commit the generated content.\n\n## Verification\n- `node --test tests/promote-buildchain-ref.test.mjs tests/build-surface.test.mjs`\n- `corepack pnpm --filter ./actions/promote-buildchain-ref build`\n- `corepack pnpm run check`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:26:09Z",
          "mergedAt": "2026-07-06T14:30:11Z",
          "additions": 255,
          "deletions": 121,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 35,
          "url": "https://github.com/kungfu-systems/kfd/pull/35",
          "title": "fix(release): anchor KFD alpha publish state",
          "body": "## Summary\n- switch KFD Buildchain release config to anchored/manual mode with an explicit kfd.release.json manifest\n- add the release anchor to package exports, build artifacts, KFD-1 witness coverage, and KFD-3 collaboration metadata\n- bump the alpha package version to 1.0.0-alpha.5\n\n## Verification\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:29:23Z",
          "mergedAt": "2026-07-06T14:31:15Z",
          "additions": 128,
          "deletions": 24,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 36,
          "url": "https://github.com/kungfu-systems/kfd/pull/36",
          "title": "release(alpha): publish KFD 1.0.0-alpha.5",
          "body": "## Summary\n- promote dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd@1.0.0-alpha.5\n- includes anchored/manual release manifest and KFD-3 collaboration-interface package witness updates\n\n## Verification\n- PR #35 Verify and Build passed before merge",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:31:28Z",
          "mergedAt": "2026-07-06T14:32:41Z",
          "additions": 128,
          "deletions": 24,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 627,
          "url": "https://github.com/kungfu-systems/buildchain/pull/627",
          "title": "Promote Buildchain v2.8 dev to alpha",
          "body": "## Summary\n- Promote the current v2.8 dev line to alpha.\n- Dogfood semver release GitHub Release evidence publication via `buildchain-ref-promotion.yml` and `release-candidate-promote.yml`.\n- Includes the version-state lifecycle fix that regenerates `dist/site/buildchain-contract.json` before publish verification.\n\n## Verification\n- Dev PR #626 checks passed before merge.\n- This PR must produce a PR-stage release-candidate artifact and merge into alpha without a second heavy build during promote-only publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:30:42Z",
          "mergedAt": "2026-07-06T14:32:55Z",
          "additions": 255,
          "deletions": 121,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 300,
          "url": "https://github.com/kungfu-systems/kungfu/pull/300",
          "title": "build(core): strip local symbols from release native artifacts",
          "body": "Merge feature/kfx-app-slim-strip into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:33:59Z",
          "mergedAt": "2026-07-06T14:34:05Z",
          "additions": 13,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 38,
          "url": "https://github.com/kungfu-systems/kfd/pull/38",
          "title": "fix(package): expose release impact metadata",
          "body": "## Summary\n- bump KFD alpha release anchor to 1.0.0-alpha.6\n- include release-impact.json in npm files and package exports\n- enforce that package surface in scripts/check.mjs and refresh KFD-3 witnesses\n\n## Verification\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:36:08Z",
          "mergedAt": "2026-07-06T14:37:42Z",
          "additions": 17,
          "deletions": 15,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 628,
          "url": "https://github.com/kungfu-systems/buildchain/pull/628",
          "title": "Prepare v2.8.1-alpha.0",
          "body": "Create the generated version-state commit for v2.8.1-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:35:57Z",
          "mergedAt": "2026-07-06T14:38:18Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 40,
          "url": "https://github.com/kungfu-systems/kfd/pull/40",
          "title": "release(alpha): publish KFD 1.0.0-alpha.6",
          "body": "## Summary\n- promote @kungfu-tech/kfd@1.0.0-alpha.6 using a dedicated alpha-based promotion branch\n- keeps the promotion head up to date with the protected alpha base\n- includes release-impact.json in npm files and exports\n\n## Verification\n- PR #38 Verify and Build passed before merge\n- promotion branch merge commit carries DCO sign-off",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:40:20Z",
          "mergedAt": "2026-07-06T14:42:24Z",
          "additions": 17,
          "deletions": 15,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 629,
          "url": "https://github.com/kungfu-systems/buildchain/pull/629",
          "title": "Prepare v2.8.1-alpha.0",
          "body": "Create the generated version-state commit for v2.8.1-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:40:26Z",
          "mergedAt": "2026-07-06T14:43:04Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 41,
          "url": "https://github.com/kungfu-systems/kfd/pull/41",
          "title": "fix(release): prepare KFD alpha.7 topology sync",
          "body": "## Summary\n- start from the current alpha branch so dev will contain the latest alpha promotion topology\n- bump the anchored/manual package release fact to 1.0.0-alpha.7\n- refresh KFD-3 package witness hashes\n\n## Why\nBuildchain ref promotion requires the final alpha commit to come from a merged same-repository PR dev/v1/v1.0 -> alpha/v1/v1.0. Dev must first contain the current alpha base to satisfy GitHub strict branch protection on that direct promotion PR.\n\n## Verification\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:44:57Z",
          "mergedAt": "2026-07-06T14:46:29Z",
          "additions": 12,
          "deletions": 12,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 37,
          "url": "https://github.com/kungfu-systems/kfd/pull/37",
          "title": "Prepare v1.0.0-alpha.5",
          "body": "Create the generated version-state commit for v1.0.0-alpha.5.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T14:33:56Z",
          "mergedAt": "2026-07-06T14:46:31Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 632,
          "url": "https://github.com/kungfu-systems/buildchain/pull/632",
          "title": "release: promote v2.8 alpha to stable via recovery merge",
          "body": "## Summary\n- Promote the current alpha/v2/v2.8 source material to release/v2/v2.8.\n- Resolve the only direct alpha-to-release conflict by preserving alpha package version state (`2.8.1-alpha.0`) before the release promotion transaction creates the stable version-state commit.\n- Keep the branch name line-scoped (`fix/release-line-v2-v2.8-*`) so Buildchain release governance can audit this as an explicit recovery merge.\n\n## Verification\n- `node -e 'JSON.parse(require(\"fs\").readFileSync(\"package.json\",\"utf8\")); console.log(\"package-json-ok\")'`\\n- `git diff --check`\\n- PR checks must pass before merge.\\n\\n## Dogfood note\\nThe alpha path successfully created GitHub Release `v2.8.1-alpha.0` with `prerelease=true`, `make_latest=false`, and release passport/evidence assets. This PR continues the stable semver GitHub Release dogfood.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T14:45:42Z",
          "mergedAt": "2026-07-06T14:48:02Z",
          "additions": 4777,
          "deletions": 397,
          "changedFiles": 47
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 42,
          "url": "https://github.com/kungfu-systems/kfd/pull/42",
          "title": "release(alpha): publish KFD 1.0.0-alpha.7",
          "body": "## Summary\n- direct promotion from dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd@1.0.0-alpha.7\n- dev now contains the current alpha base, satisfying strict branch protection\n- promotion source matches Buildchain policy: merged same-repository PR dev/v1/v1.0 -> alpha/v1/v1.0\n\n## Verification\n- PR #41 Verify and Build passed before merge\n- local npm run check\n- local npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:46:51Z",
          "mergedAt": "2026-07-06T14:48:13Z",
          "additions": 12,
          "deletions": 12,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 43,
          "url": "https://github.com/kungfu-systems/kfd/pull/43",
          "title": "Prepare v1.0.0-alpha.7",
          "body": "Create the generated version-state commit for v1.0.0-alpha.7.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T14:49:24Z",
          "mergedAt": "2026-07-06T14:51:10Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 633,
          "url": "https://github.com/kungfu-systems/buildchain/pull/633",
          "title": "Release v2.8.1",
          "body": "Create the generated version-state commit for v2.8.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:50:34Z",
          "mergedAt": "2026-07-06T14:53:05Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 634,
          "url": "https://github.com/kungfu-systems/buildchain/pull/634",
          "title": "Prepare v2.8.2-alpha.0",
          "body": "Create the generated version-state commit for v2.8.2-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T14:55:56Z",
          "mergedAt": "2026-07-06T14:58:09Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 12,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/12",
          "title": "feat(site): render KFD and Buildchain package surfaces",
          "body": "## Summary\n- switch the site build to pnpm with pinned package artifacts\n- render KFD decision pages with structured Markdown, tables, and section navigation\n- consume the latest Buildchain release package for the Buildchain surface\n- add a stewarded substrate footer with GitHub organization collaboration routing\n\n## Verification\n- pnpm run build\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:10:11Z",
          "mergedAt": "2026-07-06T15:11:49Z",
          "additions": 647,
          "deletions": 176,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 44,
          "url": "https://github.com/kungfu-systems/kfd/pull/44",
          "title": "feat(release): wire KFD passport gates",
          "body": "## Summary\n- add an explicit machine-bound KFD-2 public release trust claim\n- publish the KFD-2 claim through package files/exports and Buildchain artifacts\n- pass KFD-1, KFD-2, and KFD-3 evidence into Buildchain release passport promotion\n- update KFD-3 witnesses so minimal entrypoints are declared public surfaces\n\n## Verification\n- npm run check\n- npm pack --dry-run --json\n- npx @kungfu-tech/buildchain@2.8.1 collect github-release ... --kfd-1-witness-json ... --kfd-2-claim-json ... --kfd-3-prebuild-witness-json ... --kfd-3-artifact-witness-json ...\n- npx @kungfu-tech/buildchain@2.8.1 verify release-passport ... --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:11:57Z",
          "mergedAt": "2026-07-06T15:12:36Z",
          "additions": 507,
          "deletions": 28,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 635,
          "url": "https://github.com/kungfu-systems/buildchain/pull/635",
          "title": "fix(passport): project KFD-3 evidence into KFD-2 trust proofs",
          "body": "## Summary\n- preserve a machine-readable KFD-2 trustProof object on generated kfd-3:* public claims\n- require KFD-3-derived KFD-2 claims to carry witness hashes, declared capability verification, reverse audit boundary, residual risk, and responsibility state\n- update release passport docs, inventory guard, site contract digest, and bundled promote action\n\n## Verification\n- node --test tests/release-passport.test.mjs\n- corepack pnpm --filter ./actions/promote-buildchain-ref build\n- node scripts/check-inventory.mjs\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:10:39Z",
          "mergedAt": "2026-07-06T15:12:45Z",
          "additions": 192,
          "deletions": 66,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 45,
          "url": "https://github.com/kungfu-systems/kfd/pull/45",
          "title": "release: promote KFD alpha.8",
          "body": "## Summary\nPromote dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd@1.0.0-alpha.8.\n\nThis promotion includes:\n- KFD-1 contract-world witness coverage for package/release trust surfaces\n- explicit KFD-2 public release trust claim input\n- KFD-3 collaboration-interface closure witness fix for minimal entrypoints\n- Buildchain promotion wiring for KFD-1/2/3 release passport sections\n\n## Verification\n- PR #44 check / check passed\n- local npm run check passed\n- local Buildchain release passport verify returned trust=pass with only KFD-2 residual-risk warnings",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:13:15Z",
          "mergedAt": "2026-07-06T15:14:24Z",
          "additions": 507,
          "deletions": 28,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 636,
          "url": "https://github.com/kungfu-systems/buildchain/pull/636",
          "title": "chore(release): backfill v2.8.2 alpha state to dev",
          "body": "## Summary\n- merge the current alpha/v2/v2.8 version-state back into dev/v2/v2.8 after stable release recovery\n- preserve the KFD-3 to KFD-2 trust-proof fix already merged in #635\n- regenerate site contract facts for package version 2.8.2-alpha.0\n\n## Verification\n- corepack pnpm run check:site\n- node --test tests/release-passport.test.mjs",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:15:08Z",
          "mergedAt": "2026-07-06T15:17:14Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 638,
          "url": "https://github.com/kungfu-systems/buildchain/pull/638",
          "title": "Promote Buildchain v2.8 KFD trust proof fix to alpha",
          "body": "## Summary\n- promote the KFD-3 to KFD-2 trust proof projection from dev to alpha\n- includes the alpha version-state backfill so the release line stays monotonic\n\n## Verification\n- dev Verify run: https://github.com/kungfu-systems/buildchain/actions/runs/28802320941\n- PR #635 checks passed before merge\n- PR #636 checks passed before merge",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:19:02Z",
          "mergedAt": "2026-07-06T15:20:47Z",
          "additions": 192,
          "deletions": 66,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 46,
          "url": "https://github.com/kungfu-systems/kfd/pull/46",
          "title": "fix(release): keep KFD claim out of build artifacts",
          "body": "## Summary\n- keep the explicit KFD-2 release trust claim in the npm package and promotion inputs\n- remove the KFD-2 hidden directory from PR-stage Build artifact paths/requiredPaths to avoid Build startup failure\n- refresh KFD-1/KFD-2/KFD-3 witness hashes\n\n## Verification\n- npm run check\n- npm pack --dry-run --json\n- local buildchain collect github-release + verify release-passport: trust=pass, no errors",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:19:52Z",
          "mergedAt": "2026-07-06T15:21:11Z",
          "additions": 12,
          "deletions": 13,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 47,
          "url": "https://github.com/kungfu-systems/kfd/pull/47",
          "title": "chore(release): sync alpha.8 topology",
          "body": "## Summary\n- merge alpha/v1/v1.0 history back into dev/v1/v1.0 after the failed alpha.8 promotion attempt\n- keep dev-side follow-up content while restoring alpha-as-ancestor topology for the next promotion PR\n\n## Verification\n- merge completed without content conflicts\n- alpha/v1/v1.0 is an ancestor of this sync branch",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:22:10Z",
          "mergedAt": "2026-07-06T15:22:49Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 48,
          "url": "https://github.com/kungfu-systems/kfd/pull/48",
          "title": "release(alpha): prepare KFD 1.0.0-alpha.9",
          "body": "## Summary\n- bump KFD package/release anchor from 1.0.0-alpha.8 to 1.0.0-alpha.9\n- refresh KFD-1, KFD-2, and KFD-3 release evidence hashes\n\n## Verification\n- npm run check\n- npm pack --dry-run --json\n- local Buildchain release passport verify: trust=pass, no errors",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:23:54Z",
          "mergedAt": "2026-07-06T15:24:44Z",
          "additions": 31,
          "deletions": 31,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 49,
          "url": "https://github.com/kungfu-systems/kfd/pull/49",
          "title": "release(alpha): publish KFD 1.0.0-alpha.9",
          "body": "## Summary\nPromote dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd@1.0.0-alpha.9.\n\nThis promotion includes the KFD-1/2/3 Buildchain release passport integration and a non-workflow alpha.9 release anchor refresh after alpha.8's PR-stage Build startup failure.\n\n## Verification\n- PR #48 check / check passed\n- local npm run check passed\n- local Buildchain release passport verify returned trust=pass with no errors\n- alpha/v1/v1.0 is an ancestor of dev/v1/v1.0",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:25:09Z",
          "mergedAt": "2026-07-06T15:26:09Z",
          "additions": 36,
          "deletions": 37,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 13,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/13",
          "title": "fix(site): guard libkungfu production readiness",
          "body": "## Summary\\n- mirror kfd.libkungfu.dev into the local infra output contract\\n- verify all declared production surface URLs against buildchain.toml\\n- make production-apply follow the infra production status so pending remains fail-closed\\n\\n## Validation\\n- pnpm run build\\n- pnpm run check\\n- git diff --check\\n\\n## Production impact\\n- no production apply is enabled by this PR\\n- production remains blocked while infra/outputs.json marks production pending",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:26:03Z",
          "mergedAt": "2026-07-06T15:27:58Z",
          "additions": 17,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 50,
          "url": "https://github.com/kungfu-systems/kfd/pull/50",
          "title": "fix(release): use Verify evidence for KFD promotion",
          "body": "## Summary\n- sync alpha.9 topology back into dev\n- bump KFD package/release anchor to 1.0.0-alpha.10\n- make KFD promotion resolve PR-stage release evidence from the Verify workflow instead of the Build workflow\n- refresh KFD-1, KFD-2, and KFD-3 release evidence hashes\n\n## Verification\n- npm run check\n- npm pack --dry-run --json\n- local Buildchain release passport verify: trust=pass, no errors",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:29:10Z",
          "mergedAt": "2026-07-06T15:30:00Z",
          "additions": 37,
          "deletions": 37,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 51,
          "url": "https://github.com/kungfu-systems/kfd/pull/51",
          "title": "release(alpha): publish KFD 1.0.0-alpha.10",
          "body": "## Summary\nPromote dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd@1.0.0-alpha.10.\n\nThis promotion uses Verify PR-stage evidence for KFD's source/package release path and includes full KFD-1/2/3 release passport inputs.\n\n## Verification\n- PR #50 check / check passed\n- local npm run check passed\n- local Buildchain release passport verify returned trust=pass with no errors\n- alpha/v1/v1.0 is an ancestor of dev/v1/v1.0",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:30:21Z",
          "mergedAt": "2026-07-06T15:31:01Z",
          "additions": 37,
          "deletions": 37,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 52,
          "url": "https://github.com/kungfu-systems/kfd/pull/52",
          "title": "fix(release): pin KFD build workflow to v2.8",
          "body": "## Summary\n- sync alpha.10 topology back into dev\n- bump KFD package/release anchor to 1.0.0-alpha.11\n- pin the KFD Build workflow to buildchain alpha/v2/v2.8 because the moved v2 tag currently causes KFD Build startup_failure\n- refresh KFD-1, KFD-2, and KFD-3 release evidence hashes\n\n## Verification\n- npm run check\n- npm pack --dry-run --json\n- local Buildchain release passport verify: trust=pass, no errors",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:35:04Z",
          "mergedAt": "2026-07-06T15:37:43Z",
          "additions": 36,
          "deletions": 36,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 53,
          "url": "https://github.com/kungfu-systems/kfd/pull/53",
          "title": "fix(release): use Build evidence for KFD promotion",
          "body": "## Summary\n- switch Buildchain ref promotion back to the Build release-candidate workflow\n- add a scripted KFD-1 witness refresh step so release workflow/package/claim hash bindings do not drift\n- refresh KFD-1/2/3 release evidence for alpha.12\n\n## Verification\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json\n- git diff --check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:41:40Z",
          "mergedAt": "2026-07-06T15:43:06Z",
          "additions": 50,
          "deletions": 25,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 54,
          "url": "https://github.com/kungfu-systems/kfd/pull/54",
          "title": "release(alpha): publish KFD 1.0.0-alpha.12",
          "body": "## Summary\n- promote KFD dev/v1/v1.0 to alpha/v1/v1.0\n- publish @kungfu-tech/kfd@1.0.0-alpha.12 through Buildchain\n- generate release passport with KFD-1, KFD-2, and KFD-3 evidence\n\n## Release evidence included\n- KFD-1 contract-world witness\n- KFD-2 public release trust claim\n- KFD-3 collaboration-interface prebuild and artifact witnesses\n- Build release-candidate evidence for promotion\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:43:28Z",
          "mergedAt": "2026-07-06T15:45:00Z",
          "additions": 67,
          "deletions": 42,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 14,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/14",
          "title": "Enable libkungfu.dev production deployment",
          "body": "## Summary\n- mirror active production infra outputs\n- enable Buildchain web-surface production apply for approved manual dispatches\n\n## Verification\n- pnpm install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/ --config.minimumReleaseAge=0\n- pnpm run build && pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:43:44Z",
          "mergedAt": "2026-07-06T15:45:19Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 55,
          "url": "https://github.com/kungfu-systems/kfd/pull/55",
          "title": "Prepare v1.0.0-alpha.12",
          "body": "Create the generated version-state commit for v1.0.0-alpha.12.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T15:46:15Z",
          "mergedAt": "2026-07-06T15:49:51Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 642,
          "url": "https://github.com/kungfu-systems/buildchain/pull/642",
          "title": "Add Buildchain self KFD claim registry",
          "body": "## Summary\n- define Buildchain public KFD release claims and collaboration surfaces in a package-owned source module\n- generate Buildchain self KFD-1/2/3 witness files during self promotion and pass them into release passports\n- publish kfd-claims.json in the site bundle and document it as the source claim registry\n- move semver GitHub Release evidence publication into promote-buildchain-ref and keep the wrapper declarative\n\n## Validation\n- corepack pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:52:14Z",
          "mergedAt": "2026-07-06T15:54:22Z",
          "additions": 2565,
          "deletions": 217,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 15,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/15",
          "title": "Make kfd.libkungfu.dev root canonical",
          "body": "## Summary\n- make KFD public and agent URLs canonical at https://kfd.libkungfu.dev/\n- expose decision pages as /1/, /2/, /3/ on the KFD host\n- switch cross-surface navigation to canonical subdomain URLs\n\n## Verification\n- pnpm install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/ --config.minimumReleaseAge=0\n- pnpm run build && pnpm run check\n- generated manifest KFD pages are /, /1/, /2/, /3/\n- no generated KFD artifact references https://kfd.libkungfu.dev/kfd/ as canonical",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:55:10Z",
          "mergedAt": "2026-07-06T15:56:40Z",
          "additions": 44,
          "deletions": 35,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 643,
          "url": "https://github.com/kungfu-systems/buildchain/pull/643",
          "title": "Promote dev/v2/v2.8 to alpha",
          "body": "## Summary\nPromote current dev/v2/v2.8 to alpha/v2/v2.8 after adding Buildchain self KFD claim registry and release passport dogfood.\n\n## Included\n- PR #642 Add Buildchain self KFD claim registry\n\n## Validation\n- dev Verify run 28804713369 succeeded\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T15:55:55Z",
          "mergedAt": "2026-07-06T15:58:02Z",
          "additions": 2565,
          "deletions": 217,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 646,
          "url": "https://github.com/kungfu-systems/buildchain/pull/646",
          "title": "Fix GitHub Release CLI guard in action bundle",
          "body": "## Summary\n- prevent scripts/ensure-github-release.mjs from running its CLI main when bundled into promote-buildchain-ref\n- rebuild promote-buildchain-ref dist bundle\n\n## Validation\n- node --test tests/github-release-metadata.test.mjs tests/promote-buildchain-ref.test.mjs\n- corepack pnpm --filter ./actions/promote-buildchain-ref build\n- node scripts/check-inventory.mjs\n\n## Context\nAlpha promotion run 28805011280 proved Buildchain self KFD witness generation worked, then failed in promote-only publish because the imported ensure-github-release CLI guard fired inside the bundled action and required GH_TOKEN/GITHUB_TOKEN.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:04:14Z",
          "mergedAt": "2026-07-06T16:06:22Z",
          "additions": 25,
          "deletions": 17,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 647,
          "url": "https://github.com/kungfu-systems/buildchain/pull/647",
          "title": "Promote dev/v2/v2.8 guard fix to alpha",
          "body": "## Summary\nPromote the GitHub Release CLI guard fix into alpha/v2/v2.8 so the self-KFD alpha promotion can complete.\n\n## Included\n- PR #646 Fix GitHub Release CLI guard in action bundle\n\n## Context\nPrevious alpha promotion run 28805011280 failed after self-KFD witness generation because ensure-github-release CLI main executed inside the bundled promote action.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:06:51Z",
          "mergedAt": "2026-07-06T16:08:47Z",
          "additions": 25,
          "deletions": 17,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 649,
          "url": "https://github.com/kungfu-systems/buildchain/pull/649",
          "title": "fix(kfd): keep source claim registry version invariant",
          "body": "## Summary\n- keep Buildchain KFD source claim registry independent from semver version-state bumps\n- move exact release version / exact runtime contract digest out of dist/site/kfd-claims.json and leave those run-specific facts to generated release passport witnesses\n- add a regression test proving the source claim registry is stable across package version bumps\n\n## Validation\n- corepack pnpm run check\n- manual version-state smoke: bump package.json/dist site contract version, regenerate site bundle, and confirm no new dirty files outside declared version state",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:18:05Z",
          "mergedAt": "2026-07-06T16:21:09Z",
          "additions": 52,
          "deletions": 20,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 651,
          "url": "https://github.com/kungfu-systems/buildchain/pull/651",
          "title": "Prepare v2.8.2-alpha.1",
          "body": "## Summary\n- promote the KFD source claim registry version-invariance fix to alpha\n- prevents Buildchain self KFD claims from dirtying dist/site/kfd-claims.json during semver version-state generation\n\n## Validation\n- PR #649 checks passed\n- local corepack pnpm run check passed on the source fix\n\n## Release intent\nAlpha promotion only.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:21:50Z",
          "mergedAt": "2026-07-06T16:23:55Z",
          "additions": 52,
          "deletions": 20,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 650,
          "url": "https://github.com/kungfu-systems/buildchain/pull/650",
          "title": "feat(web-surface): add production preflight health evidence",
          "body": "## Summary\n- add web-surface production preflight evidence for canonical/indexable production channels, concrete AWS targets, CloudFront aliases, DNS, and configured surface-set coverage\n- add production health-check evidence and include preflight/health results in the web-surface release passport\n- align the site-libkungfu-dev fixture with the current KFD surface design: `https://kfd.libkungfu.dev` is a first-class product homepage\n\n## Train validation\n- Runtime train ref: `train/v2/v2.8/production-promotion`\n- Head: `2d08a4a4772ca135f16be955f06483422d9f0edb`\n\n## Verification\n- `node --test tests/web-surface.test.mjs`\n- `pnpm run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:18:35Z",
          "mergedAt": "2026-07-06T16:26:21Z",
          "additions": 803,
          "deletions": 19,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 652,
          "url": "https://github.com/kungfu-systems/buildchain/pull/652",
          "title": "Prepare v2.8.2-alpha.2",
          "body": "Create the generated version-state commit for v2.8.2-alpha.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:26:17Z",
          "mergedAt": "2026-07-06T16:28:09Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 653,
          "url": "https://github.com/kungfu-systems/buildchain/pull/653",
          "title": "Prepare v2.8.2",
          "body": "## Summary\n- promote Buildchain v2.8.2 from alpha to stable release\n- includes KFD source claim registry version-invariance fix and prior KFD-1/KFD-2/KFD-3 release passport trust proof work\n\n## Validation\n- alpha v2.8.2-alpha.2 published successfully\n- GitHub Release v2.8.2-alpha.2 created as prerelease/latest=false with passport assets\n- npm alpha dist-tag points to 2.8.2-alpha.2\n\n## Release intent\nStable release promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:31:10Z",
          "mergedAt": "2026-07-06T16:33:10Z",
          "additions": 2748,
          "deletions": 234,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 654,
          "url": "https://github.com/kungfu-systems/buildchain/pull/654",
          "title": "fix(web-surface): detect robots noindex meta in health",
          "body": "## Summary\n- make web-surface health-check fail production when an HTML page includes `<meta name=\"robots\" content=\"noindex\">`\n- preserve the existing `x-robots-tag` check and record whether noindex came from header or HTML meta\n- add regression coverage for the live KFD production failure mode\n\n## Train validation\n- Runtime train ref: `train/v2/v2.8/production-promotion`\n- Head: `0f43bf3817f9c9816e8b11fa129cd07ca7e1edf5`\n\n## Verification\n- `node --test tests/web-surface.test.mjs`\n- `pnpm run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:31:14Z",
          "mergedAt": "2026-07-06T16:33:47Z",
          "additions": 58,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 16,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/16",
          "title": "fix(site): remove production noindex metadata",
          "body": "## Summary\n- remove the hard-coded robots noindex meta tag from generated production pages\n- add checks so the hub and KFD production artifact cannot embed noindex metadata\n\n## Verification\n- `pnpm run build`\n- `pnpm run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:35:26Z",
          "mergedAt": "2026-07-06T16:37:27Z",
          "additions": 6,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 655,
          "url": "https://github.com/kungfu-systems/buildchain/pull/655",
          "title": "Release v2.8.2",
          "body": "Create the generated version-state commit for v2.8.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:35:35Z",
          "mergedAt": "2026-07-06T16:37:58Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 656,
          "url": "https://github.com/kungfu-systems/buildchain/pull/656",
          "title": "Prepare v2.8.3-alpha.0",
          "body": "Create the generated version-state commit for v2.8.3-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:40:44Z",
          "mergedAt": "2026-07-06T16:44:55Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 56,
          "url": "https://github.com/kungfu-systems/kfd/pull/56",
          "title": "feat(kfd-2): add trust taxonomy extension path",
          "body": "## Summary\n- add a KFD-2 trust taxonomy schema as the single source for residual-risk, downgrade, provability, and agent-action values\n- route release claims, release trust passports, and KFD-3 witnesses through the KFD-2 taxonomy definitions\n- add KFD-3 extension request support so agents know to open a KFD GitHub issue when a missing taxonomy value is needed\n- document the KFD npm package as the self-proof case for KFD-1/2/3 and add an agent quickstart\n- strengthen the KFD check gate and KFD-1 witness surfaces for README/docs/site/check/schema proof\n\n## Verification\n- node scripts/check.mjs\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:41:11Z",
          "mergedAt": "2026-07-06T16:45:38Z",
          "additions": 769,
          "deletions": 112,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 657,
          "url": "https://github.com/kungfu-systems/buildchain/pull/657",
          "title": "fix(web-surface): invalidate viewer paths",
          "body": "## Summary\n- invalidate CloudFront by viewer URL path instead of S3 object prefix\n- keep deployment manifest paths in the invalidation set\n- cover host-root KFD production invalidation as /*\n\n## Verification\n- node --test tests/web-surface.test.mjs\n- git diff --check\n- pnpm run check\n\n## Runtime validation\n- train/v2/v2.8/production-promotion now points at 16e4e9fca5979da4c0468be928d66a4f591ddc1e for site production validation.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T16:44:22Z",
          "mergedAt": "2026-07-06T16:46:19Z",
          "additions": 20,
          "deletions": 8,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 658,
          "url": "https://github.com/kungfu-systems/buildchain/pull/658",
          "title": "fix(release-passport): preserve KFD evidence in binary releases",
          "body": "## Summary\n- fetch the durable release-state passport before Buildchain's binary-distribution release asset upload\n- merge that authoritative passport as the base for the binary release passport so KFD-1/2/3 evidence, version impact, and release-state SHA survive the final GitHub Release asset update\n- expose collect github-release base-passport inputs and fail closed when required KFD evidence is missing\n\n## Source-first KFD reason\nThe source claim registry and durable release-state passport are the authoritative KFD truth. The binary distribution workflow was producing a later GitHub Release asset that omitted KFD evidence, so public release audit entrypoints drifted from the source-of-truth passport. This change preserves the source-defined KFD claims before any documentation-only work.\n\n## Validation\n- corepack pnpm run check\n",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T16:57:23Z",
          "mergedAt": "2026-07-06T16:59:48Z",
          "additions": 258,
          "deletions": 81,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 660,
          "url": "https://github.com/kungfu-systems/buildchain/pull/660",
          "title": "chore(release): backfill v2.8.3 alpha state to dev",
          "body": "## Summary\n- Backfill the current v2.8.3-alpha.0 version-state from alpha into dev/v2/v2.8 before the next alpha promotion.\n- This removes the channel PR conflict so the next legal dev -> alpha promotion can proceed.\n\n## Validation\n- corepack pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:03:22Z",
          "mergedAt": "2026-07-06T17:05:12Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 662,
          "url": "https://github.com/kungfu-systems/buildchain/pull/662",
          "title": "chore(release): merge v2.8.3 alpha state into dev",
          "body": "## Summary\n- Preserve alpha/v2/v2.8 as ancestry of dev/v2/v2.8 after the v2.8.3-alpha.0 state update.\n- This fixes the legal dev -> alpha channel PR merge-base, which cannot be repaired by squash-only content backfill.\n\n## Merge requirement\nPlease merge this PR with a merge commit, not squash, so dev retains alpha as an ancestor.\n\n## Validation\n- corepack pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:08:20Z",
          "mergedAt": "2026-07-06T17:10:16Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 663,
          "url": "https://github.com/kungfu-systems/buildchain/pull/663",
          "title": "Promote v2.8 KFD passport fix to alpha",
          "body": "## Summary\n- Promote the KFD release-passport source-of-truth fix from dev/v2/v2.8 to alpha/v2/v2.8.\n- Dev now preserves the current alpha version-state ancestry, so this is a normal channel promotion PR.\n\n## Validation\n- PR #658 checks passed.\n- PR #662 merge-backfill checks passed and preserved alpha ancestry.\n- dev/v2/v2.8 Verify run 28809418955 passed.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:11:40Z",
          "mergedAt": "2026-07-06T17:13:58Z",
          "additions": 1137,
          "deletions": 107,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 664,
          "url": "https://github.com/kungfu-systems/buildchain/pull/664",
          "title": "Prepare v2.8.3-alpha.1",
          "body": "Create the generated version-state commit for v2.8.3-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:16:12Z",
          "mergedAt": "2026-07-06T17:18:18Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 666,
          "url": "https://github.com/kungfu-systems/buildchain/pull/666",
          "title": "fix(release-passport): bundle publish evidence for release assets",
          "body": "## Summary\n- Copy publish evidence into the release-passport bundle as sibling `evidence.json`.\n- Make `buildchain.release.json` point to that sibling file so a downloaded GitHub Release asset bundle can pass `buildchain verify release-passport`.\n- Keep KFD source claims and durable release-state evidence as the source of truth; this fixes the public audit entrypoint path.\n\n## Validation\n- node --test tests/release-passport.test.mjs\n- corepack pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:26:03Z",
          "mergedAt": "2026-07-06T17:28:20Z",
          "additions": 110,
          "deletions": 55,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 667,
          "url": "https://github.com/kungfu-systems/buildchain/pull/667",
          "title": "chore(release): merge v2.8.3 alpha state into dev",
          "body": "Backfills the v2.8.3-alpha.1 version-state merge ancestry into dev/v2/v2.8 after the release-passport fix landed on dev.\n\nThis PR must be merged with a merge commit, not squash, so alpha/v2/v2.8 remains an ancestor of dev/v2/v2.8 and the next dev -> alpha channel PR is mergeable.\n\nValidation:\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:32:06Z",
          "mergedAt": "2026-07-06T17:34:01Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 668,
          "url": "https://github.com/kungfu-systems/buildchain/pull/668",
          "title": "Release Buildchain v2.8.3 alpha passport evidence fix",
          "body": "Promotes the release-passport evidence fix from dev/v2/v2.8 to alpha/v2/v2.8.\n\nSource-first KFD acceptance focus:\n- release passport keeps KFD-1/KFD-2/KFD-3 evidence from durable release-state\n- GitHub Release flat asset bundle can self-verify without path mutation\n- binary distribution collects release-state passport as authoritative base\n\nValidation already passed on dev PRs:\n- corepack pnpm run check\n- Build Surface Fixture",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:34:26Z",
          "mergedAt": "2026-07-06T17:36:48Z",
          "additions": 110,
          "deletions": 55,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 669,
          "url": "https://github.com/kungfu-systems/buildchain/pull/669",
          "title": "Prepare v2.8.3-alpha.2",
          "body": "Create the generated version-state commit for v2.8.3-alpha.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:39:26Z",
          "mergedAt": "2026-07-06T17:41:20Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 671,
          "url": "https://github.com/kungfu-systems/buildchain/pull/671",
          "title": "fix(release-passport): validate release-state KFD base",
          "body": "Fixes Binary Distribution tag runs after release passport finalization.\n\nThe durable release-state branch stores buildchain.release.json as the audit entry, while sibling evidence assets are not present in that branch checkout. The binary workflow should therefore validate the authoritative base passport as a KFD base, then let the final collected release-passport bundle run the full verifier once evidence assets are available.\n\nValidation:\n- node --test tests/build-surface.test.mjs\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:47:38Z",
          "mergedAt": "2026-07-06T17:49:30Z",
          "additions": 26,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 672,
          "url": "https://github.com/kungfu-systems/buildchain/pull/672",
          "title": "chore(release): merge v2.8.3-alpha.2 state into dev",
          "body": "Backfills v2.8.3-alpha.2 version-state ancestry into current dev/v2/v2.8 after the binary release-state passport fix landed.\n\nThis must be merged with a merge commit, not squash, so alpha/v2/v2.8 remains an ancestor of dev/v2/v2.8.\n\nValidation:\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:52:18Z",
          "mergedAt": "2026-07-06T17:54:25Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 673,
          "url": "https://github.com/kungfu-systems/buildchain/pull/673",
          "title": "Release Buildchain v2.8.3 alpha binary passport fix",
          "body": "Promotes the Binary Distribution release-state passport base validation fix to alpha/v2/v2.8.\n\nThis keeps durable release-state as the authoritative KFD base while deferring full release-passport verification until sibling evidence assets are present in the final GitHub Release bundle.\n\nValidation:\n- #671: node --test tests/build-surface.test.mjs\n- #671: corepack pnpm run check\n- #672: corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:54:48Z",
          "mergedAt": "2026-07-06T17:56:43Z",
          "additions": 26,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 674,
          "url": "https://github.com/kungfu-systems/buildchain/pull/674",
          "title": "Prepare v2.8.3-alpha.3",
          "body": "Create the generated version-state commit for v2.8.3-alpha.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T17:59:02Z",
          "mergedAt": "2026-07-06T18:01:03Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 675,
          "url": "https://github.com/kungfu-systems/buildchain/pull/675",
          "title": "Prepare v2.8.3-alpha.3",
          "body": "Create the generated version-state commit for v2.8.3-alpha.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:03:11Z",
          "mergedAt": "2026-07-06T18:10:24Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 677,
          "url": "https://github.com/kungfu-systems/buildchain/pull/677",
          "title": "chore(release): merge v2.8 release ancestry into dev",
          "body": "Backfills release/v2/v2.8 ancestry into dev/v2/v2.8 while keeping the current alpha.3 version-state tree.\n\nPurpose: make the next legal dev -> alpha promotion carry release ancestry, so the following alpha -> release PR can be a clean channel merge without bypassing release lineage checks.\n\nThis PR must be merged with a merge commit, not squash.\n\nValidation:\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:11:27Z",
          "mergedAt": "2026-07-06T18:13:40Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 678,
          "url": "https://github.com/kungfu-systems/buildchain/pull/678",
          "title": "Promote v2.8 release ancestry backfill to alpha",
          "body": "Promotes the release ancestry backfill from dev/v2/v2.8 to alpha/v2/v2.8 through the legal dev -> alpha channel.\n\nPurpose: make release/v2/v2.8 an ancestor of alpha/v2/v2.8 so the subsequent alpha -> release PR is a clean channel merge while preserving Buildchain release lineage governance.\n\nValidation:\n- #677: corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:14:12Z",
          "mergedAt": "2026-07-06T18:16:05Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 679,
          "url": "https://github.com/kungfu-systems/buildchain/pull/679",
          "title": "Prepare v2.8.3-alpha.4",
          "body": "Create the generated version-state commit for v2.8.3-alpha.4.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:18:35Z",
          "mergedAt": "2026-07-06T18:20:44Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 676,
          "url": "https://github.com/kungfu-systems/buildchain/pull/676",
          "title": "Release Buildchain v2.8.3",
          "body": "Promotes Buildchain v2.8.3 from alpha/v2/v2.8 to release/v2/v2.8.\n\nThis stable release includes source-first KFD passport evidence fixes and Binary Distribution release-state KFD base validation.\n\nValidated in alpha:\n- v2.8.3-alpha.3 npm alpha published\n- v2.8.3-alpha.3 GitHub Release prerelease created\n- release passport flat JSON audit bundle verifies\n- KFD-1/KFD-2/KFD-3 passed in passport\n- Binary Distribution tag run passed, including durable release-state KFD base fetch, collect, verify, artifact discovery, and GitHub Release asset upload",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:08:37Z",
          "mergedAt": "2026-07-06T18:25:11Z",
          "additions": 1218,
          "deletions": 109,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 681,
          "url": "https://github.com/kungfu-systems/buildchain/pull/681",
          "title": "Release v2.8.3",
          "body": "Create the generated version-state commit for v2.8.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:27:31Z",
          "mergedAt": "2026-07-06T18:29:39Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 682,
          "url": "https://github.com/kungfu-systems/buildchain/pull/682",
          "title": "Prepare v2.8.4-alpha.0",
          "body": "Create the generated version-state commit for v2.8.4-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:32:32Z",
          "mergedAt": "2026-07-06T18:36:13Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 683,
          "url": "https://github.com/kungfu-systems/buildchain/pull/683",
          "title": "Prepare v2.8.4-alpha.0",
          "body": "Create the generated version-state commit for v2.8.4-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:38:48Z",
          "mergedAt": "2026-07-06T18:41:23Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 684,
          "url": "https://github.com/kungfu-systems/buildchain/pull/684",
          "title": "fix(release): keep GitHub Release target aligned",
          "body": "## Summary\\n- patch existing GitHub Releases with target_commitish when a target is supplied\\n- make Binary Distribution pass the exact tag commit to ensure-github-release\\n- cover update behavior in GitHub Release metadata tests\\n\\n## Validation\\n- node --test tests/github-release-metadata.test.mjs tests/build-surface.test.mjs\\n- node scripts/generate-site-bundle.mjs --check\\n- corepack pnpm run check\\n\\n## Notes\\n- v2.8.3 GitHub Release metadata was manually repaired to target the current exact tag commit after discovering the mismatch during closeout.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:48:00Z",
          "mergedAt": "2026-07-06T18:50:16Z",
          "additions": 7,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 685,
          "url": "https://github.com/kungfu-systems/buildchain/pull/685",
          "title": "Promote Buildchain v2.8.4 alpha target metadata fix",
          "body": "## Summary\\n- promote the GitHub Release target metadata fix from dev to alpha\\n- expected alpha publish: v2.8.4-alpha.1\\n\\n## Validation\\n- dev Verify passed: https://github.com/kungfu-systems/buildchain/actions/runs/28815396566\\n- source PR #684 passed Verify and Build Surface Fixture\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:51:55Z",
          "mergedAt": "2026-07-06T18:54:10Z",
          "additions": 7,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 686,
          "url": "https://github.com/kungfu-systems/buildchain/pull/686",
          "title": "Prepare v2.8.4-alpha.1",
          "body": "Create the generated version-state commit for v2.8.4-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T18:56:42Z",
          "mergedAt": "2026-07-06T19:00:15Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 687,
          "url": "https://github.com/kungfu-systems/buildchain/pull/687",
          "title": "Prepare v2.8.4-alpha.1",
          "body": "Create the generated version-state commit for v2.8.4-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T19:02:38Z",
          "mergedAt": "2026-07-06T19:05:10Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 688,
          "url": "https://github.com/kungfu-systems/buildchain/pull/688",
          "title": "Release Buildchain v2.8.4",
          "body": "Promote Buildchain v2.8.4 from alpha to stable.\\n\\nValidation already completed on alpha v2.8.4-alpha.1, including KFD release passport collection, artifact discovery, and GitHub Release exact tag target metadata alignment.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T19:05:24Z",
          "mergedAt": "2026-07-06T19:08:00Z",
          "additions": 10,
          "deletions": 5,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 689,
          "url": "https://github.com/kungfu-systems/buildchain/pull/689",
          "title": "Release v2.8.4",
          "body": "Create the generated version-state commit for v2.8.4.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T19:10:20Z",
          "mergedAt": "2026-07-06T19:12:26Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 690,
          "url": "https://github.com/kungfu-systems/buildchain/pull/690",
          "title": "Prepare v2.8.5-alpha.0",
          "body": "Create the generated version-state commit for v2.8.5-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T19:15:17Z",
          "mergedAt": "2026-07-06T19:17:55Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 691,
          "url": "https://github.com/kungfu-systems/buildchain/pull/691",
          "title": "Sync dev with v2.8.5 alpha state",
          "body": "Backfill the alpha channel state after releasing Buildchain v2.8.4 and preparing v2.8.5-alpha.0, so dev remains a descendant of the current alpha/release line.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T19:23:35Z",
          "mergedAt": "2026-07-06T19:25:21Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 17,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/17",
          "title": "ci(web-surface): use Buildchain v2 workflow",
          "body": "## Summary\n- switch the web-surface reusable workflow shell from Buildchain @v2.4 to @v2\n- enable the Buildchain release-PR production gate on main with the buildchain-release label and release/ head prefix\n- extend infra drift checks so workflow ref, production apply, and release gate cannot silently drift\n- refresh docs and agent map for the current Buildchain/KFD pinned package versions and active production state\n\n## Verification\n- pnpm install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/\n- pnpm run build\n- pnpm run check\n- actionlint .github/workflows/buildchain-web-surface.yml\n- node /Users/dkr/Code/kungfu-systems/buildchain/scripts/web-surface.mjs --mode validate --cwd .\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:02:24Z",
          "mergedAt": "2026-07-06T23:03:59Z",
          "additions": 42,
          "deletions": 24,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 57,
          "url": "https://github.com/kungfu-systems/kfd/pull/57",
          "title": "docs(kfd): clarify foundation axiom wording",
          "body": "## Summary\n- make the public foundation triad use the stronger axiom wording: facts must not drift; trust must start from facts; cooperation must start from transparent value\n- update README, KFD-1, KFD-2, KFD-3, registry, standards metadata, and site bundle to align around the facts -> trust -> cooperation structure\n- remove the stale KFD-2 wording that framed KFD-1 only as release/version responsibility\n- refresh KFD-2 claim, KFD-3 witnesses, and KFD-1 witness hashes\n\n## Verification\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:08:04Z",
          "mergedAt": "2026-07-06T23:09:31Z",
          "additions": 136,
          "deletions": 127,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 18,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/18",
          "title": "fix(kfd): link decision eyebrow to home",
          "body": "## Summary\n- make the KFD decision detail eyebrow link back to https://kfd.libkungfu.dev/\n- keep the existing kind/status text in the title area\n- add a site check so KFD-1/2/3 keep the home breadcrumb link\n\n## Verification\n- pnpm install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/\n- pnpm run build\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:09:58Z",
          "mergedAt": "2026-07-06T23:11:28Z",
          "additions": 10,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 692,
          "url": "https://github.com/kungfu-systems/buildchain/pull/692",
          "title": "fix(kfd): enforce trust taxonomy in release passports",
          "body": "## Summary\n- discover KFD-2 trust taxonomy from @kungfu-tech/kfd standards metadata\n- fail closed on missing or unknown residualRisk/downgradeReason taxonomy values\n- validate KFD-3 prebuild/artifact residual risks and KFD-2 trust proof residual risks against the KFD-owned schema\n- refresh Buildchain site bundle digests for the updated public API surfaces\n\n## Validation\n- node --test tests/release-passport.test.mjs\n- node scripts/generate-site-bundle.mjs --check\n- corepack pnpm run check",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T23:09:32Z",
          "mergedAt": "2026-07-06T23:11:47Z",
          "additions": 476,
          "deletions": 91,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 58,
          "url": "https://github.com/kungfu-systems/kfd/pull/58",
          "title": "docs(readme): show current decision axioms",
          "body": "## Summary\n- change the README Current decisions table from long titles to the three axiom statements\n- keep registry and decision titles as the full axiom + engineering anchor form\n- refresh KFD witnesses that bind README hashes\n\n## Verification\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:13:44Z",
          "mergedAt": "2026-07-06T23:15:21Z",
          "additions": 11,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 693,
          "url": "https://github.com/kungfu-systems/buildchain/pull/693",
          "title": "Prepare v2.8.5 alpha taxonomy update",
          "body": "## Summary\n- promote dev/v2/v2.8 KFD-2 trust taxonomy enforcement into alpha\n- release passport residualRisk/downgradeReason taxonomy now uses KFD-owned standards metadata as source of truth\n\n## Validation\n- dev Verify passed for fa0bde7\n- PR #692 checks passed",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:13:49Z",
          "mergedAt": "2026-07-06T23:15:42Z",
          "additions": 476,
          "deletions": 91,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 694,
          "url": "https://github.com/kungfu-systems/buildchain/pull/694",
          "title": "Prepare v2.8.5-alpha.1",
          "body": "Create the generated version-state commit for v2.8.5-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:18:08Z",
          "mergedAt": "2026-07-06T23:19:59Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 695,
          "url": "https://github.com/kungfu-systems/buildchain/pull/695",
          "title": "Release Buildchain v2.8.5",
          "body": "## Summary\n- promote KFD-2 trust taxonomy enforcement from alpha to stable\n- publish Buildchain stable release after alpha v2.8.5-alpha.1 verification\n\n## Validation\n- PR #692 checks passed and merged to dev\n- alpha PR #693 checks passed and alpha promotion published v2.8.5-alpha.1\n- version-state PR #694 checks passed and merged\n- alpha/v2/v2.8 Verify passed at 8e91316",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:21:33Z",
          "mergedAt": "2026-07-06T23:23:31Z",
          "additions": 478,
          "deletions": 93,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 59,
          "url": "https://github.com/kungfu-systems/kfd/pull/59",
          "title": "docs(kfd): expose public fact source metadata",
          "body": "## Summary\n- add README-visible stable KFD site URL for readers entering from GitHub\n- add Decision metadata describing the GitHub-hosted KFD repository as the public fact source and kfd.libkungfu.dev as a projection surface\n- expose the same public fact-source metadata through site/kfd-site.json and the KFD-3 collaboration interface for agents\n- extend the KFD-3 collaboration interface schema and check gate for factSources and stableRenderedIndex\n\n## Verification\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:27:06Z",
          "mergedAt": "2026-07-06T23:28:26Z",
          "additions": 258,
          "deletions": 62,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 698,
          "url": "https://github.com/kungfu-systems/buildchain/pull/698",
          "title": "fix(release): select latest alpha tag for stable promotion",
          "body": "## Summary\n- fix stable release governance to use the latest alpha prerelease for the same patch\n- prevent release promotion from comparing against stale alpha.0 when alpha.1+ exists\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm --filter ./actions/promote-buildchain-ref build\n- corepack pnpm run check\n\n## Incident\n- Fixes the stable promotion failure observed in run 28830157942 / issue #697.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:28:44Z",
          "mergedAt": "2026-07-06T23:30:37Z",
          "additions": 8,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 699,
          "url": "https://github.com/kungfu-systems/buildchain/pull/699",
          "title": "Sync dev with v2.8.5-alpha.1 state",
          "body": "## Summary\n- align dev/v2/v2.8 with the published v2.8.5-alpha.1 version state\n- preserve the release alpha selection hotfix already merged to dev\n\n## Validation\n- node scripts/generate-site-bundle.mjs --check\n- node --test tests/promote-buildchain-ref.test.mjs",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:33:20Z",
          "mergedAt": "2026-07-06T23:35:15Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 60,
          "url": "https://github.com/kungfu-systems/kfd/pull/60",
          "title": "docs(kfd): clarify license and official status boundary",
          "body": "## Summary\n- add root TRADEMARKS.md to clarify Apache-2.0 scope, trademark/name-use limits, official source boundaries, fork/derivative expectations, and agent-facing authority rule\n- link README License section to the official-status boundary\n- publish TRADEMARKS.md through npm files and exports\n- expose the boundary through site/kfd-site.json and the KFD-3 collaboration interface\n- extend the self-check gate and regenerate KFD-1/2/3 evidence\n\n## Verification\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:38:28Z",
          "mergedAt": "2026-07-06T23:39:39Z",
          "additions": 248,
          "deletions": 63,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 702,
          "url": "https://github.com/kungfu-systems/buildchain/pull/702",
          "title": "chore(release): align dev with alpha v2.8 state",
          "body": "## Summary\n- merge the current alpha/v2/v2.8 state back into dev/v2/v2.8\n- resolve the generated promote-buildchain-ref bundle conflict by keeping the dev-side rebuilt bundle\n- restore a clean same-repository dev -> alpha promotion path after #700 exposed a merge conflict\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:43:41Z",
          "mergedAt": "2026-07-06T23:45:45Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 703,
          "url": "https://github.com/kungfu-systems/buildchain/pull/703",
          "title": "Promote KFD taxonomy release fix to v2.8 alpha",
          "body": "## Summary\n- promote the KFD-2 trust taxonomy implementation already merged to dev\n- include the stable-promotion fix that selects the latest same-patch alpha tag\n- carry the dev/alpha mergeability alignment from #702 so this channel PR can merge cleanly\n\n## Verification\n- dev Verify passed in #702\n- Build Surface Fixture passed in #702\n- node --test tests/release-passport.test.mjs (on the KFD taxonomy implementation)\n- corepack pnpm run check (on the KFD taxonomy implementation and release hotfix)",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:46:10Z",
          "mergedAt": "2026-07-06T23:48:27Z",
          "additions": 8,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 704,
          "url": "https://github.com/kungfu-systems/buildchain/pull/704",
          "title": "Prepare v2.8.5-alpha.3",
          "body": "Create the generated version-state commit for v2.8.5-alpha.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:51:29Z",
          "mergedAt": "2026-07-06T23:53:31Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 61,
          "url": "https://github.com/kungfu-systems/kfd/pull/61",
          "title": "chore(kfd): anchor alpha 13 release",
          "body": "## Summary\n- bump KFD anchored npm version to 1.0.0-alpha.13\n- update kfd.release.json to match package.json\n- include TRADEMARKS.md in Buildchain release artifact paths and expected artifact check\n- regenerate KFD-1/2/3 release evidence\n\n## Verification\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:53:24Z",
          "mergedAt": "2026-07-06T23:55:00Z",
          "additions": 37,
          "deletions": 36,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 705,
          "url": "https://github.com/kungfu-systems/buildchain/pull/705",
          "title": "Release Buildchain v2.8.5",
          "body": "## Summary\n- align the release/v2/v2.8 source tree with the published v2.8.5-alpha.3 alpha evidence\n- carry the KFD-2 trust taxonomy release-passport enforcement into the stable release line\n- include the stable-promotion fix that selects the latest same-patch alpha tag\n\n## Verification\n- tree matches origin/alpha/v2/v2.8 after conflict resolution\n- BUILDCHAIN_HEAD_REF=fix/release-line-v2-v2.8-alpha3-mergeability BUILDCHAIN_BASE_REF=release/v2/v2.8 node scripts/verify-release-pr.mjs\n- node --test tests/promote-buildchain-ref.test.mjs\n- alpha npm version confirmed: @kungfu-tech/buildchain@alpha = 2.8.5-alpha.3",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:54:49Z",
          "mergedAt": "2026-07-06T23:57:08Z",
          "additions": 11,
          "deletions": 8,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 706,
          "url": "https://github.com/kungfu-systems/buildchain/pull/706",
          "title": "Prepare v2.8.5-alpha.3",
          "body": "Create the generated version-state commit for v2.8.5-alpha.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:55:35Z",
          "mergedAt": "2026-07-06T23:57:46Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 62,
          "url": "https://github.com/kungfu-systems/kfd/pull/62",
          "title": "release(kfd): promote alpha 13",
          "body": "## Summary\n- promote current dev/v1/v1.0 to alpha/v1/v1.0\n- publishes @kungfu-tech/kfd@1.0.0-alpha.13 through Buildchain trusted publishing after alpha branch verification\n- includes KFD public fact-source metadata and Apache-2.0 official-status/trademark boundary surfaces\n\n## Verification already passed on dev PR #61\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:55:23Z",
          "mergedAt": "2026-07-06T23:58:11Z",
          "additions": 1272,
          "deletions": 224,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 707,
          "url": "https://github.com/kungfu-systems/buildchain/pull/707",
          "title": "Release v2.8.5",
          "body": "Create the generated version-state commit for v2.8.5.",
          "author": "dongkeren",
          "createdAt": "2026-07-06T23:59:26Z",
          "mergedAt": "2026-07-07T00:01:47Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 301,
          "url": "https://github.com/kungfu-systems/kungfu/pull/301",
          "title": "build(gui): configure Linux and Windows packaging targets",
          "body": "electron-builder.yml only declared mac targets, so gui dist on Linux/Windows fell back to defaults and failed (Linux executableName defaults to the package name @kungfu-tech/gui whose @ and / are rejected). Add explicit linux (dir+AppImage, executableName=kungfu, snap omitted) and win (dir+nsis) targets. Verified on Linux (agent-120): dev+fix produces a 232MB AppImage with executable name kungfu. Windows dist verification to follow.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:06:17Z",
          "mergedAt": "2026-07-07T00:06:23Z",
          "additions": 18,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 708,
          "url": "https://github.com/kungfu-systems/buildchain/pull/708",
          "title": "Prepare v2.8.6-alpha.0",
          "body": "Create the generated version-state commit for v2.8.6-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:04:22Z",
          "mergedAt": "2026-07-07T00:06:25Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 709,
          "url": "https://github.com/kungfu-systems/buildchain/pull/709",
          "title": "Prepare v2.8.6-alpha.0",
          "body": "## Summary\n- sync dev/v2/v2.8 to the next alpha version-state already present on alpha/v2/v2.8\n- prevent future dev-to-alpha PRs from rolling package version back to 2.8.5-alpha.3\n\n## Verification\n- node scripts/generate-site-bundle.mjs --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:11:16Z",
          "mergedAt": "2026-07-07T00:12:54Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 64,
          "url": "https://github.com/kungfu-systems/kfd/pull/64",
          "title": "chore(kfd): enable GitHub release for alpha 14",
          "body": "## Summary\n- bump @kungfu-tech/kfd to 1.0.0-alpha.14\n- enable Buildchain GitHub Release generation for KFD alpha promotion\n- align required status check with the protected check name\n- regenerate KFD-1/2/3 Buildchain evidence after the release anchor and workflow changes\n\n## Verification\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:25:36Z",
          "mergedAt": "2026-07-07T00:26:51Z",
          "additions": 37,
          "deletions": 36,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 66,
          "url": "https://github.com/kungfu-systems/kfd/pull/66",
          "title": "release(kfd): promote alpha 14",
          "body": "## Summary\n- promote @kungfu-tech/kfd 1.0.0-alpha.14 into alpha/v1/v1.0\n- use a dedicated promotion branch based on current alpha plus the dev candidate to satisfy protected-branch freshness without mutating dev\n- expected release outcome: npm alpha dist-tag and GitHub Release v1.0.0-alpha.14 with buildchain.release.json\n\n## Verification\n- PR #64 checks passed and merged to dev/v1/v1.0\n- npm run check passed on this promotion branch\n- local alpha.14 pack dry-run passed before PR #64\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:30:21Z",
          "mergedAt": "2026-07-07T00:32:37Z",
          "additions": 37,
          "deletions": 36,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 67,
          "url": "https://github.com/kungfu-systems/kfd/pull/67",
          "title": "docs(kfd): record alpha promotion provenance gate",
          "body": "## Summary\n- document the Buildchain alpha promotion provenance requirement\n- point docs/MAP.md to the release governance note\n- refresh KFD-1 and KFD-3 witness hashes for the docs map update\n\n## Verification\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json\n\n## Context\nThis records the alpha.14 release lesson: Buildchain requires alpha publishing to come from a merged same-repository PR `dev/v1/v1.0 -> alpha/v1/v1.0`; a temporary promotion branch satisfies GitHub freshness but fails Buildchain provenance.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:36:17Z",
          "mergedAt": "2026-07-07T00:37:25Z",
          "additions": 36,
          "deletions": 7,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 68,
          "url": "https://github.com/kungfu-systems/kfd/pull/68",
          "title": "chore(kfd): sync alpha history into dev",
          "body": "## Summary\n- merge current alpha/v1/v1.0 history into dev/v1/v1.0 without changing the file tree\n- restore branch ancestry so the next Buildchain-required dev -> alpha promotion can satisfy strict freshness\n\n## Verification\n- git diff --stat origin/dev/v1/v1.0..HEAD produced no file diff\n- npm run check\n\n## Context\nThe prior alpha promotion attempt through a temporary branch created alpha-only history. Buildchain requires the real release promotion to be a merged same-repository PR from dev/v1/v1.0 to alpha/v1/v1.0, so dev must first include the alpha-only merge commit.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:38:26Z",
          "mergedAt": "2026-07-07T00:39:29Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 63,
          "url": "https://github.com/kungfu-systems/kfd/pull/63",
          "title": "Prepare v1.0.0-alpha.13",
          "body": "Create the generated version-state commit for v1.0.0-alpha.13.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-06T23:59:08Z",
          "mergedAt": "2026-07-07T00:39:30Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 69,
          "url": "https://github.com/kungfu-systems/kfd/pull/69",
          "title": "release(kfd): promote alpha 14",
          "body": "## Summary\n- promote dev/v1/v1.0 into alpha/v1/v1.0 for @kungfu-tech/kfd 1.0.0-alpha.14\n- publish through Buildchain ref promotion using the required same-repository dev -> alpha provenance path\n- expected release outcome: npm alpha dist-tag and GitHub Release v1.0.0-alpha.14 with buildchain.release.json\n\n## Verification before promotion\n- PR #64 checks passed and enabled GitHub Release generation\n- PR #67 checks passed and documented release provenance gate\n- PR #68 checks passed and synced alpha history into dev without file diff\n- local npm run check passed\n- local npm pack --dry-run --json passed for 1.0.0-alpha.14\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:39:55Z",
          "mergedAt": "2026-07-07T00:41:07Z",
          "additions": 36,
          "deletions": 7,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 711,
          "url": "https://github.com/kungfu-systems/buildchain/pull/711",
          "title": "fix(release-propagation): invoke checked out runtime",
          "body": "## Summary\n- checkout the selected Buildchain runtime into `.buildchain/runtime` before the release-propagation reusable workflow calls the CLI\n- install runtime production dependencies and invoke `.buildchain/runtime/bin/buildchain.mjs` for plan/write-lock\n- document `buildchain-ref` train validation and add a workflow regression test\n\n## Verification\n- node --test tests/release-propagation.test.mjs\n- node scripts/check-inventory.mjs\n- corepack pnpm run check\n\n## Issue #710\n- inspected kungfu-systems/buildchain#710 and kfd run 28832947423\n- the direct failure there is promote governance PR lineage (`feature/kfd-alpha-14-promotion -> alpha/v1/v1.0`), not a missing `bin/buildchain.mjs` checkout; this PR fixes the reusable workflow runtime checkout issue separately\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:50:31Z",
          "mergedAt": "2026-07-07T00:52:48Z",
          "additions": 59,
          "deletions": 15,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 714,
          "url": "https://github.com/kungfu-systems/buildchain/pull/714",
          "title": "chore(release): align dev with alpha ancestry",
          "body": "## Summary\n- merge `alpha/v2/v2.8` back into dev to restore canonical dev-to-alpha promotion mergeability\n- keep the dev-side generated Buildchain contract digest that includes #711\n- this replaces failed direct/recovery alpha PRs #712 and #713\n\n## Verification\n- node scripts/generate-site-bundle.mjs --check\n- corepack pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:59:35Z",
          "mergedAt": "2026-07-07T01:01:35Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 71,
          "url": "https://github.com/kungfu-systems/kfd/pull/71",
          "title": "feat(kfd): generate homepage bundle from README",
          "body": "## Summary\n- generate site/kfd-site.json from README.md instead of maintaining homepage copy by hand\n- expose ordered homepage.sections and homepage.displayPlan so site renderers know what belongs on the first screen, primary narrative, support area, and renderer-contract area\n- make npm run check fail when the checked-in site bundle drifts from the README projection\n- publish scripts/ in the package and release artifact so the KFD self-proof path is visible to npm consumers\n- bump the anchored alpha package version to 1.0.0-alpha.15 and refresh KFD-1/2/3 Buildchain evidence\n\n## Verification\n- npm run update:site-bundle\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:00:24Z",
          "mergedAt": "2026-07-07T01:02:02Z",
          "additions": 503,
          "deletions": 66,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 72,
          "url": "https://github.com/kungfu-systems/kfd/pull/72",
          "title": "release(alpha): promote KFD alpha 15",
          "body": "## Summary\n- promote dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd 1.0.0-alpha.15\n- includes generated README-backed homepage bundle and package-visible self-proof scripts\n\n## Verification\n- dev PR #71 passed Verify and Build\n- alpha branch promotion will run protected checks before merge",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:02:56Z",
          "mergedAt": "2026-07-07T01:04:07Z",
          "additions": 503,
          "deletions": 66,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 715,
          "url": "https://github.com/kungfu-systems/buildchain/pull/715",
          "title": "release: promote Buildchain v2.8 alpha",
          "body": "## Summary\n- promote the release-propagation runtime checkout fix from dev to alpha\n- includes #711 and dev ancestry alignment #714\n\n## Verification\n- dev branch Verify passed: https://github.com/kungfu-systems/buildchain/actions/runs/28834006062\n",
          "author": "kungfu-origin",
          "createdAt": "2026-07-07T01:02:46Z",
          "mergedAt": "2026-07-07T01:05:09Z",
          "additions": 59,
          "deletions": 15,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 717,
          "url": "https://github.com/kungfu-systems/buildchain/pull/717",
          "title": "Prepare v2.8.6-alpha.1",
          "body": "Create the generated version-state commit for v2.8.6-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:07:38Z",
          "mergedAt": "2026-07-07T01:09:32Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 53,
          "url": "https://github.com/kungfu-systems/libnode/pull/53",
          "title": "Build libnode release candidates before promotion",
          "body": "## Summary\n- strip macOS/Linux release libnode binaries during dist generation\n- generate Buildchain release-candidate passports from PR-stage Build runs\n- replace publish-gate heavy rebuild publication with release-candidate promote-only publishing through Buildchain @v2\n- bump alpha version state to 22.22.3-kf.3-alpha.11\n\n## Verification\n- node --check .gyp/node-dist.js\n- actionlint .github/workflows/build.yml .github/workflows/release-new-version.yml\n- node .gyp/libnode-release-verify.js\n- node .gyp/node-platform-package.js verify-source\n- prettier --check .gyp/node-dist.js README.md docs/buildchain.md .github/workflows/build.yml .github/workflows/release-new-version.yml\n- node /Users/dkr/Code/kungfu-systems/buildchain/bin/buildchain.mjs validate --require-version-state --require-lifecycle-stages install,build,verify,publish\n\n## Release semantics\nThe Build workflow now produces the PR-stage release-candidate evidence. After merge to alpha/release, Release - New Version promotes that verified candidate without rebuilding the native matrix.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:36:53Z",
          "mergedAt": "2026-07-07T01:09:54Z",
          "additions": 156,
          "deletions": 15,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 718,
          "url": "https://github.com/kungfu-systems/buildchain/pull/718",
          "title": "release: promote Buildchain v2.8.6",
          "body": "## Summary\n- promote Buildchain v2.8.6-alpha.1 to stable release\n- includes release-propagation runtime checkout fix from #711\n\n## Verification\n- alpha branch Verify passed: https://github.com/kungfu-systems/buildchain/actions/runs/28834318838\n- alpha npm dist-tag is 2.8.6-alpha.1\n",
          "author": "kungfu-origin",
          "createdAt": "2026-07-07T01:10:57Z",
          "mergedAt": "2026-07-07T01:14:26Z",
          "additions": 61,
          "deletions": 17,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 73,
          "url": "https://github.com/kungfu-systems/kfd/pull/73",
          "title": "docs(kfd-3): clarify trusted value foundation",
          "body": "## Summary\n- change the KFD-3 foundation sentence to \"cooperation must start from trusted value\"\n- explain that value becomes trusted through transparent facts, choices, and constraints\n- keep renderer-contract text out of homepage.sections so sites that render sections do not show implementation contract text on the homepage\n- bump the anchored alpha package version to 1.0.0-alpha.16 and refresh KFD evidence\n\n## Verification\n- npm run update:site-bundle\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:17:02Z",
          "mergedAt": "2026-07-07T01:18:23Z",
          "additions": 157,
          "deletions": 135,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 720,
          "url": "https://github.com/kungfu-systems/buildchain/pull/720",
          "title": "Release v2.8.6",
          "body": "Create the generated version-state commit for v2.8.6.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:16:49Z",
          "mergedAt": "2026-07-07T01:18:59Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 719,
          "url": "https://github.com/kungfu-systems/buildchain/pull/719",
          "title": "Prepare v2.8.6-alpha.1",
          "body": "Create the generated version-state commit for v2.8.6-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:11:52Z",
          "mergedAt": "2026-07-07T01:19:30Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 74,
          "url": "https://github.com/kungfu-systems/kfd/pull/74",
          "title": "release(alpha): promote KFD alpha 16",
          "body": "## Summary\n- promote dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd 1.0.0-alpha.16\n- includes KFD-3 trusted value wording and homepage bundle fix that keeps renderer contract out of homepage.sections\n\n## Verification\n- dev PR #73 passed Verify and Build\n- alpha branch promotion will run protected checks before merge",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:18:35Z",
          "mergedAt": "2026-07-07T01:19:58Z",
          "additions": 157,
          "deletions": 135,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 302,
          "url": "https://github.com/kungfu-systems/kungfu/pull/302",
          "title": "fix(build): unblock Windows core build and cross-platform packaging",
          "body": "Two Windows-portability build fixes surfaced verifying the full package pipeline on Windows: (1) colocate pykungfu.pyd next to libnode.dll for pybind11-stubgen (MSVC multi-config emits the .pyd in build/ root and Python 3.8+ resolves an extension's DLLs from its own dir, so build:core failed with ModuleNotFoundError: pykungfu); (2) resolve --config.electronDist in a node launcher instead of a POSIX $(node -p ...) substitution that cmd.exe cannot run. Both are no-ops / behavior-preserving on macOS and Linux. Verified on Windows: build:core + freeze now pass (Nuitka produces kungfu_cli.exe) and electron-vite build runs; a further packaging-time issue (kfx contract path) is tracked separately.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:26:02Z",
          "mergedAt": "2026-07-07T01:26:09Z",
          "additions": 55,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 721,
          "url": "https://github.com/kungfu-systems/buildchain/pull/721",
          "title": "Prepare v2.8.7-alpha.0",
          "body": "Create the generated version-state commit for v2.8.7-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:21:43Z",
          "mergedAt": "2026-07-07T01:27:04Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 19,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/19",
          "title": "feat(site): improve libkungfu navigation surfaces",
          "body": "## Summary\n- update KFD content generation to @kungfu-tech/kfd@1.0.0-alpha.13\n- add clickable homepage generation-map hotspots and clearer mechanism-card actions\n- align subpage page kickers so the left side returns to the parent page and the right side shows page identity or KFD status\n\n## Verification\n- pnpm run build\n- pnpm run check\n- git diff --check\n\n## Risk\n- rendering/navigation change only; preview and deployment remain workflow-driven",
          "author": "dongkeren",
          "createdAt": "2026-07-07T00:44:08Z",
          "mergedAt": "2026-07-07T01:28:51Z",
          "additions": 614,
          "deletions": 82,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 722,
          "url": "https://github.com/kungfu-systems/buildchain/pull/722",
          "title": "fix(release): publish GitHub releases by default",
          "body": "## Summary\n- default release-candidate-promote.yml github-release to true\n- document github-release: false as the opt-out path\n- refresh site bundle digests and add regression coverage\n\n## Validation\n- node --test tests/build-surface.test.mjs\n- node scripts/check-inventory.mjs\n- node scripts/generate-site-bundle.mjs\n- git diff --check\n- corepack pnpm run check\n\n## Issue #710\nI checked #710 while working this change. It is not the same root cause as the release-propagation runtime checkout fix: #710 is a KFD promotion governance lineage failure for a non-canonical source branch, while this PR only changes the GitHub Release default for the promote wrapper.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:27:39Z",
          "mergedAt": "2026-07-07T01:31:08Z",
          "additions": 32,
          "deletions": 28,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 724,
          "url": "https://github.com/kungfu-systems/buildchain/pull/724",
          "title": "chore(release): align dev with alpha state",
          "body": "## Summary\n- merge current alpha/v2/v2.8 version state into dev/v2/v2.8\n- resolve generated site contract digest from the current source state\n- keeps the next canonical dev→alpha promotion mergeable after #722\n\n## Validation\n- node scripts/generate-site-bundle.mjs --check\n- node scripts/check-inventory.mjs",
          "author": "kungfu-origin",
          "createdAt": "2026-07-07T01:33:33Z",
          "mergedAt": "2026-07-07T01:35:36Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 20,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/20",
          "title": "fix(kfd): publish subdomain decision route aliases",
          "body": "## Summary\n- generate root-level aliases for KFD decision pages so kfd.libkungfu.dev/1/, /2/, and /3/ resolve on subdomain deployments\n- add site checks that compare the aliases with canonical dist/kfd/* pages\n\n## Verification\n- pnpm run build\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:35:01Z",
          "mergedAt": "2026-07-07T01:36:45Z",
          "additions": 19,
          "deletions": 10,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 303,
          "url": "https://github.com/kungfu-systems/kungfu/pull/303",
          "title": "fix(gui): find the kfx contract on Windows when baking the manifest",
          "body": "The electron-builder beforePack manifest bake called loadKfxContract without a cwd, so the contract resolver walked ancestors of env.PWD only; cmd.exe does not set PWD, so on Windows the committed framework/kfx/kungfu-kfx.contract.json was reported not found and dist failed. Pass cwd: process.cwd() to match POSIX behavior. With this the full Windows package pipeline completes: verified on DARKHERO producing a 162MB 'Kungfu Setup 4.0.0-alpha.0.exe' nsis installer. No change on macOS/Linux.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:38:28Z",
          "mergedAt": "2026-07-07T01:38:35Z",
          "additions": 6,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 725,
          "url": "https://github.com/kungfu-systems/buildchain/pull/725",
          "title": "release: promote Buildchain v2.8 alpha",
          "body": "## Summary\n- promote dev/v2/v2.8 to alpha/v2/v2.8\n- includes release-candidate-promote.yml defaulting github-release to true with explicit opt-out\n\n## Validation\n- #722 checks passed and merged\n- #724 aligned dev with alpha state and passed checks\n- dev Verify after #724: https://github.com/kungfu-systems/buildchain/actions/runs/28835287337",
          "author": "kungfu-origin",
          "createdAt": "2026-07-07T01:36:47Z",
          "mergedAt": "2026-07-07T01:38:43Z",
          "additions": 32,
          "deletions": 28,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 726,
          "url": "https://github.com/kungfu-systems/buildchain/pull/726",
          "title": "Prepare v2.8.7-alpha.1",
          "body": "Create the generated version-state commit for v2.8.7-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:41:16Z",
          "mergedAt": "2026-07-07T01:43:37Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 21,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/21",
          "title": "chore(site): render buildchain alpha 2.8.7",
          "body": "## Summary\n- render site content from @kungfu-tech/buildchain@2.8.7-alpha.1\n- update Buildchain drift guards in render/check scripts\n- pin the Buildchain transitive KFD dependency to the registry package via pnpm workspace override because the alpha metadata currently declares a GitHub dependency\n\n## Verification\n- pnpm run build\n- pnpm run check\n- git diff --check\n\n## Note\n@kungfu-tech/buildchain@2.8.7-alpha.1 should fix its npm metadata so @kungfu-tech/kfd resolves from the npm registry instead of github:kungfu-systems/kfd#...; the site override is a downstream compatibility guard.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:53:43Z",
          "mergedAt": "2026-07-07T01:55:23Z",
          "additions": 17,
          "deletions": 16,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 728,
          "url": "https://github.com/kungfu-systems/buildchain/pull/728",
          "title": "feat(site): publish README-derived homepage bundle",
          "body": "## Summary\n- publish a README-derived `dist/site/buildchain-site.json` homepage contract for downstream site repositories\n- document the Buildchain-owned vs site-owned rendering boundary\n- reject exotic npm dependency specifiers in package metadata, and pin `@kungfu-tech/kfd` to the audited npm package `1.0.0-alpha.16`\n\n## Verification\n- `node scripts/generate-site-bundle.mjs --check`\n- `node scripts/check-inventory.mjs`\n- `node --test tests/build-surface.test.mjs tests/buildchain-contract.test.mjs`\n- `corepack pnpm run check`\n- `npm pack --json --pack-destination /tmp/... --registry=https://registry.npmjs.org/` and inspected tarball `package/package.json` dependencies\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:51:20Z",
          "mergedAt": "2026-07-07T01:58:55Z",
          "additions": 4025,
          "deletions": 123,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 55,
          "url": "https://github.com/kungfu-systems/libnode/pull/55",
          "title": "Enable GitHub Release evidence publication",
          "body": "Enable Buildchain's github-release output for libnode release promotion so release passport/evidence assets are published to the exact-tag GitHub Release.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T01:22:40Z",
          "mergedAt": "2026-07-07T02:00:50Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 729,
          "url": "https://github.com/kungfu-systems/buildchain/pull/729",
          "title": "chore(release): align dev with alpha state",
          "body": "## Summary\\n- merge alpha v2.8 version-state back into dev after site bundle changes\\n- regenerate Buildchain site contract digest for package version 2.8.7-alpha.1\\n\\n## Verification\\n- node scripts/check-inventory.mjs\\n- node scripts/generate-site-bundle.mjs --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:00:54Z",
          "mergedAt": "2026-07-07T02:02:59Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 23,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/23",
          "title": "release(site): promote buildchain alpha staging to production",
          "body": "## Release intent\nPromote the current staging content to production.\n\n## Source\n- Staging source SHA: 944a417f6c57a38db2840e2f964321297e7a7f35\n- Release intent commit: 6cd7b32\n- Buildchain site package: @kungfu-tech/buildchain@2.8.7-alpha.1\n- KFD site package: @kungfu-tech/kfd@1.0.0-alpha.16\n\n## Staging verification\n- Staging run: https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/28835998775\n- https://buildchain.staging.libkungfu.dev/ shows 2.8.7-alpha.1\n- https://staging.libkungfu.dev/, https://core.staging.libkungfu.dev/, https://kfd.staging.libkungfu.dev/, and https://kfd.staging.libkungfu.dev/3/ returned 200\n\n## Gate\nManual release PR for this cycle. Future expected flow: Buildchain opens this PR automatically after staging apply succeeds.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-07T02:03:15Z",
          "mergedAt": "2026-07-07T02:05:21Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 732,
          "url": "https://github.com/kungfu-systems/buildchain/pull/732",
          "title": "feat(web-surface): open production release PR after staging",
          "body": "## Summary\n- add Buildchain-owned production release PR creation after successful staging apply\n- create release/<channel>-<short-sha> branches with an empty release-intent commit and buildchain-release label\n- record staging URLs, source SHA, artifact hash, and staging release-passport evidence in the PR body\n- document the staging -> release PR -> production gate flow and refresh the site bundle\n\n## Validation\n- bash scripts/check-workflows.sh\n- node --test tests/build-surface.test.mjs tests/web-surface.test.mjs\n- node scripts/check-inventory.mjs && node scripts/generate-site-bundle.mjs --check\n- node --check scripts/web-surface-production-release-pr.mjs\n- corepack pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:13:56Z",
          "mergedAt": "2026-07-07T02:15:37Z",
          "additions": 460,
          "deletions": 19,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 24,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/24",
          "title": "fix(site): use canonical production surface links",
          "body": "## Summary\n- route cross-surface header, homepage cards, and map hotspots to canonical surface hosts\n- use stable KFD decision paths (/1/, /2/, /3/) instead of path-relative decision links\n- keep checks from regressing to host-local /core/, /buildchain/, or /kfd/ links on subdomains\n\n## Verification\n- pnpm run build\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:15:25Z",
          "mergedAt": "2026-07-07T02:17:18Z",
          "additions": 38,
          "deletions": 34,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 735,
          "url": "https://github.com/kungfu-systems/buildchain/pull/735",
          "title": "chore(release): align dev with alpha state",
          "body": "## Summary\n- merge current alpha/v2/v2.8 state back into dev/v2/v2.8 so canonical dev -> alpha promotion is conflict-free\n- resolve generated site contract digests with the current dev fact source\n\n## Validation\n- node scripts/check-inventory.mjs\n- node scripts/generate-site-bundle.mjs --check\n- bash scripts/check-workflows.sh\n- node --test tests/build-surface.test.mjs tests/web-surface.test.mjs",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:22:16Z",
          "mergedAt": "2026-07-07T02:24:32Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 734,
          "url": "https://github.com/kungfu-systems/buildchain/pull/734",
          "title": "release: promote Buildchain v2.8 alpha",
          "body": "## Summary\n- promote dev/v2/v2.8 into alpha/v2/v2.8 using the canonical channel lineage\n- includes site bundle/KFD npm metadata fixes and web-surface production release PR automation\n\n## Validation\n- dev branch Verify passed: https://github.com/kungfu-systems/buildchain/actions/runs/28836751958\n- local promotion dry-run branch validated with:\n  - node scripts/check-inventory.mjs\n  - node scripts/generate-site-bundle.mjs --check\n  - bash scripts/check-workflows.sh\n  - node --test tests/build-surface.test.mjs tests/web-surface.test.mjs",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:21:10Z",
          "mergedAt": "2026-07-07T02:26:33Z",
          "additions": 4479,
          "deletions": 136,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 736,
          "url": "https://github.com/kungfu-systems/buildchain/pull/736",
          "title": "Prepare v2.8.7-alpha.2",
          "body": "Create the generated version-state commit for v2.8.7-alpha.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:29:05Z",
          "mergedAt": "2026-07-07T02:30:45Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 738,
          "url": "https://github.com/kungfu-systems/buildchain/pull/738",
          "title": "release: promote Buildchain v2.8 stable",
          "body": "Promote Buildchain v2.8 from alpha to release.\n\nValidation chain:\n- dev Verify passed: https://github.com/kungfu-systems/buildchain/actions/runs/28837067821\n- alpha promotion PR passed and merged: #734\n- alpha version-state PR passed and merged: #736\n- alpha finalization promotion passed: https://github.com/kungfu-systems/buildchain/actions/runs/28837327689\n\nThis is the canonical alpha/v2/v2.8 -> release/v2/v2.8 promotion so release-line lineage checks can validate the channel source.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:34:04Z",
          "mergedAt": "2026-07-07T02:35:42Z",
          "additions": 4511,
          "deletions": 164,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 739,
          "url": "https://github.com/kungfu-systems/buildchain/pull/739",
          "title": "Release v2.8.7",
          "body": "Create the generated version-state commit for v2.8.7.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:37:41Z",
          "mergedAt": "2026-07-07T02:39:19Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 737,
          "url": "https://github.com/kungfu-systems/buildchain/pull/737",
          "title": "Prepare v2.8.7-alpha.2",
          "body": "Create the generated version-state commit for v2.8.7-alpha.2.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:33:11Z",
          "mergedAt": "2026-07-07T02:40:31Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 740,
          "url": "https://github.com/kungfu-systems/buildchain/pull/740",
          "title": "Prepare v2.8.8-alpha.0",
          "body": "Create the generated version-state commit for v2.8.8-alpha.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:41:50Z",
          "mergedAt": "2026-07-07T02:43:43Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 76,
          "url": "https://github.com/kungfu-systems/kfd/pull/76",
          "title": "docs(kfd): add adoption boundary",
          "body": "## Summary\n- add the KFD adoption boundary to README so KFD remains an engineering discipline, not a belief test\n- expose adoption-boundary as non-first-screen homepage content in site/kfd-site.json\n- keep renderer contract outside homepage.sections\n- bump the anchored alpha package version to 1.0.0-alpha.17 and refresh KFD evidence\n\n## Verification\n- npm run update:site-bundle\n- npm run update:kfd-2-claim\n- npm run update:kfd-3-witness\n- npm run update:kfd-1-witness\n- npm run check\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:44:19Z",
          "mergedAt": "2026-07-07T02:45:46Z",
          "additions": 99,
          "deletions": 69,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 77,
          "url": "https://github.com/kungfu-systems/kfd/pull/77",
          "title": "release(alpha): promote KFD alpha 17",
          "body": "## Summary\n- promote dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd 1.0.0-alpha.17\n- includes the KFD adoption boundary as non-first-screen homepage content\n\n## Verification\n- dev PR #76 passed Verify and Build\n- alpha branch promotion will run protected checks before merge",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:46:08Z",
          "mergedAt": "2026-07-07T02:48:07Z",
          "additions": 99,
          "deletions": 69,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 57,
          "url": "https://github.com/kungfu-systems/libnode/pull/57",
          "title": "ci: promote libnode alpha candidate",
          "body": "Promote the current dev/v22/v22.22 content to alpha/v22/v22.22 using a candidate branch based on the current alpha tip.\\n\\nThis keeps the PR head up to date with the protected alpha base while preserving the dev tree exactly.\\n\\nValidation target:\\n- Build release-candidate on Linux x64, macOS ARM64, and Windows x64\\n- Publish via buildchain release-candidate promotion after merge\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T02:20:25Z",
          "mergedAt": "2026-07-07T02:58:30Z",
          "additions": 171,
          "deletions": 16,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 59,
          "url": "https://github.com/kungfu-systems/libnode/pull/59",
          "title": "ci: sync alpha promotion fixes into dev",
          "body": "Sync the current alpha promotion fixes back into dev and prepare the next alpha package version.\\n\\nThis branch is based on the current alpha tip, so merging it into dev records the alpha ancestry required for the next strict dev→alpha promotion.\\n\\nChanges:\\n- add the aggregate Build workflow status check already validated on alpha candidate #57\\n- bump npm version state from 22.22.3-kf.3-alpha.11 to 22.22.3-kf.3-alpha.12, because alpha.11 failed before npm publication\\n\\nLocal verification:\\n- pnpm verify-release\\n- pnpm verify-package-source\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T03:01:23Z",
          "mergedAt": "2026-07-07T03:15:50Z",
          "additions": 16,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 52,
          "url": "https://github.com/kungfu-systems/libnode/pull/52",
          "title": "Prepare v22.22.1-alpha.4",
          "body": "Create the generated version-state commit for v22.22.1-alpha.4.",
          "author": "dongkeren",
          "createdAt": "2026-07-05T12:47:13Z",
          "mergedAt": "2026-07-07T03:15:52Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 743,
          "url": "https://github.com/kungfu-systems/buildchain/pull/743",
          "title": "fix(release): allow promotion automation review bypass",
          "body": "## Summary\n- add declarative branch-protection bypass inputs for Buildchain-managed promotion automation\n- update release-candidate promote wrapper and Buildchain self-promotion workflow to pass bypass identities\n- recognize GitHub approving-review protected-branch rejections and fall back to version-state PRs\n- refresh Buildchain site bundle documentation facts\n\n## Validation\n- corepack pnpm@11.7.0 run check\n\n## Release intent\n- Publish a new Buildchain alpha after this lands on dev/v2/v2.8.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T03:20:54Z",
          "mergedAt": "2026-07-07T03:22:49Z",
          "additions": 282,
          "deletions": 117,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 745,
          "url": "https://github.com/kungfu-systems/buildchain/pull/745",
          "title": "chore(release): align dev with alpha state",
          "body": "## Summary\n- align dev/v2/v2.8 with the current alpha v2.8.8-alpha.0 version state\n- regenerate Buildchain site contract digest after resolving the generated bundle conflict\n\n## Validation\n- corepack pnpm@11.7.0 run check\n\n## Context\nThis repairs the dev/alpha divergence left by the protected dev branch post-release bookkeeping failure, so the pending alpha promotion PR can merge cleanly.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T03:25:47Z",
          "mergedAt": "2026-07-07T03:27:38Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 744,
          "url": "https://github.com/kungfu-systems/buildchain/pull/744",
          "title": "release: promote Buildchain v2.8 alpha",
          "body": "## Summary\n- promote current dev/v2/v2.8 into alpha/v2/v2.8\n- includes controlled promotion automation review bypass support for protected dev/alpha/release bookkeeping\n\n## Validation\n- dev PR #743 passed Verify and Build Surface Fixture checks\n- local full check passed before merge: corepack pnpm@11.7.0 run check\n\n## Release intent\n- Publish a new Buildchain alpha.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T03:23:16Z",
          "mergedAt": "2026-07-07T03:30:51Z",
          "additions": 282,
          "deletions": 117,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 61,
          "url": "https://github.com/kungfu-systems/libnode/pull/61",
          "title": "Release alpha 22.22.3-kf.3-alpha.12",
          "body": "Promote dev/v22/v22.22 to alpha/v22/v22.22 for libnode 22.22.3-kf.3-alpha.12.\\n\\nThis is the strict Buildchain promotion path: same-repository dev→alpha PR, with dev already containing the current alpha base.\\n\\nExpected after merge:\\n- Release - New Version uses the PR-stage release-candidate artifacts\\n- npm publishes via trusted publishing with dist-tag alpha\\n- GitHub Release evidence/passport is published by Buildchain\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T03:16:24Z",
          "mergedAt": "2026-07-07T03:34:04Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 746,
          "url": "https://github.com/kungfu-systems/buildchain/pull/746",
          "title": "Prepare v2.8.8-alpha.1",
          "body": "Create the generated version-state commit for v2.8.8-alpha.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T03:33:33Z",
          "mergedAt": "2026-07-07T03:36:21Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 747,
          "url": "https://github.com/kungfu-systems/buildchain/pull/747",
          "title": "fix(release): complete version-state sync without PR fallback",
          "body": "## Summary\n- auto-add the promotion token's authenticated user/app to managed branch-protection bypass allowances\n- fail fast instead of opening post-publish version-state PRs when generated channel bookkeeping cannot be applied directly\n- update release governance docs and site bundle for direct alpha/dev sync semantics\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs\n- node --test tests/build-surface.test.mjs tests/release-line-policy.test.mjs\n- corepack pnpm@11.7.0 --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:12:49Z",
          "mergedAt": "2026-07-07T04:15:59Z",
          "additions": 265,
          "deletions": 307,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 748,
          "url": "https://github.com/kungfu-systems/buildchain/pull/748",
          "title": "release: promote Buildchain v2.8 alpha",
          "body": "Promote dev/v2/v2.8 to alpha/v2/v2.8 to dogfood direct generated version-state sync without post-publish PR fallback.\n\nVerification before promotion:\n- PR #747 merged into dev/v2/v2.8\n- local check passed on #747 branch\n- required PR checks passed on #747",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:16:27Z",
          "mergedAt": "2026-07-07T04:18:15Z",
          "additions": 265,
          "deletions": 307,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 304,
          "url": "https://github.com/kungfu-systems/kungfu/pull/304",
          "title": "feat(atlas): show imported Atlas work in the GUI",
          "body": "Expose the Atlas Mission/go projection through the GUI Work Dashboard while Atlas remains the authority.\\n\\nValidation:\\n- ./kungfu-code verify --full (57/57 passed)\\n- GUI dogfood confirmed\\n- Atlas sync helper imported 5 missions / 365 goals / 882 markers",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:18:28Z",
          "mergedAt": "2026-07-07T04:20:10Z",
          "additions": 1080,
          "deletions": 80,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 750,
          "url": "https://github.com/kungfu-systems/buildchain/pull/750",
          "title": "fix(release): satisfy generated version-state checks",
          "body": "Fix protected generated version-state finalization without post-publish PR fallback.\n\nSummary:\n- create the configured required check on the exact generated version-state commit before direct protected ref updates\n- pass github.token from release-candidate-promote.yml for GitHub Actions-owned generated checks\n- grant checks:write to the reusable wrapper\n- document the generated-check direct-sync path\n\nVerification:\n- node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 run generate:site\n- git diff --check\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:26:28Z",
          "mergedAt": "2026-07-07T04:28:26Z",
          "additions": 211,
          "deletions": 93,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 752,
          "url": "https://github.com/kungfu-systems/buildchain/pull/752",
          "title": "chore(release): restore alpha dev lineage",
          "body": "Restore dev/v2/v2.8 history so it contains the alpha/v2/v2.8 merge commit from the interrupted promotion run.\n\nThis is a topology repair only: it merges alpha/v2/v2.8 into dev/v2/v2.8 without source file changes, so subsequent alpha promotion PRs are no longer behind the alpha branch.\n\nVerification:\n- merge completed without conflicts\n- no source file changes in the merge commit",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:30:00Z",
          "mergedAt": "2026-07-07T04:31:46Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 751,
          "url": "https://github.com/kungfu-systems/buildchain/pull/751",
          "title": "release: promote Buildchain v2.8 alpha",
          "body": "Promote dev/v2/v2.8 to alpha/v2/v2.8 after fixing generated version-state required checks.\n\nThis dogfoods that alpha promotion can finish generated version-state/dev synchronization directly after the channel PR merge, without opening a post-publish version-state PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:29:02Z",
          "mergedAt": "2026-07-07T04:33:39Z",
          "additions": 211,
          "deletions": 93,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 753,
          "url": "https://github.com/kungfu-systems/buildchain/pull/753",
          "title": "fix(release): grant promotion checks permission",
          "body": "Grant checks:write on the Buildchain Ref Promotion caller workflow so the reusable release-candidate-promote workflow can create generated version-state required checks.\n\nThis fixes the workflow_run startup_failure observed after adding generated-status-check-token support.\n\nVerification:\n- node --test tests/build-surface.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:36:45Z",
          "mergedAt": "2026-07-07T04:38:29Z",
          "additions": 4,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 754,
          "url": "https://github.com/kungfu-systems/buildchain/pull/754",
          "title": "chore(release): restore alpha dev lineage after startup repair",
          "body": "Restore dev/v2/v2.8 history so it contains the alpha/v2/v2.8 merge commit from #751 after the promotion workflow startup_failure.\n\nThis is a topology repair only: it merges alpha/v2/v2.8 into dev/v2/v2.8 without source file changes, so the next alpha promotion PR starts from a clean lineage.\n\nVerification:\n- merge completed without conflicts\n- no source file changes in the merge commit",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:39:52Z",
          "mergedAt": "2026-07-07T04:41:38Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 755,
          "url": "https://github.com/kungfu-systems/buildchain/pull/755",
          "title": "release: promote Buildchain v2.8 alpha",
          "body": "Promote dev/v2/v2.8 to alpha/v2/v2.8 after generated version-state check and promotion caller checks permission fixes.\n\nDogfood target:\n- promotion workflow starts successfully\n- generated version-state required check is created before protected ref update\n- alpha/dev finish synchronized directly without a post-publish version-state PR",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:42:05Z",
          "mergedAt": "2026-07-07T04:43:49Z",
          "additions": 4,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 758,
          "url": "https://github.com/kungfu-systems/buildchain/pull/758",
          "title": "fix(release): generate self KFD witnesses after version state",
          "body": "## Summary\n- move Buildchain self-KFD witness generation into promote-buildchain-ref finalization so hashes bind to the final version-state workspace\n- keep release-candidate-promote declarative by passing release-passport-buildchain-self-kfd through to the action instead of running a wrapper-side script\n- update docs, site bundle, inventory checks, and surface tests\n\n## Validation\n- node --test tests/build-surface.test.mjs\n- node --test tests/release-passport.test.mjs\n- node --check actions/promote-buildchain-ref/lib.js && node --check actions/promote-buildchain-ref/index.js\n- corepack pnpm@11.7.0 --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- corepack pnpm@11.7.0 run generate:site\n- corepack pnpm@11.7.0 run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:55:54Z",
          "mergedAt": "2026-07-07T04:58:16Z",
          "additions": 195,
          "deletions": 123,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 759,
          "url": "https://github.com/kungfu-systems/buildchain/pull/759",
          "title": "chore(release): promote dev to alpha",
          "body": "## Summary\n- promote current dev/v2/v2.8 to alpha/v2/v2.8\n- dogfood final-version self-KFD witness generation inside promote-buildchain-ref\n\n## Validation\n- Uses Buildchain Verify and Build Surface Fixture PR checks before merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T04:59:47Z",
          "mergedAt": "2026-07-07T05:01:48Z",
          "additions": 195,
          "deletions": 123,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 25,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/25",
          "title": "fix(site): render governed bundle navigation",
          "body": "## Summary\n- render Buildchain bundle pages with homepage/sidebar navigation and child-page global navigation\n- update KFD/Buildchain package pins and no-override dependency policy\n- fix KFD foundation card layout overlap and keep human site links relative\n\n## Verification\n- pnpm run build\n- pnpm run check\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:05:35Z",
          "mergedAt": "2026-07-07T05:07:31Z",
          "additions": 684,
          "deletions": 197,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 27,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/27",
          "title": "fix(ci): pin buildchain web surface workflow",
          "body": "## Summary\n- pin the reusable Buildchain web-surface workflow to v2.8.6 because current v2/v2.8.7 resolves to a startup_failure before jobs are created\n- unblock staging and production publication for the already merged site update\n\n## Evidence\n- previous successful workflow_dispatch used buildchain workflow SHA 4e865c1 (tag v2.8.6)\n- current v2 resolves to 0483e17 (tag v2.8.7) and startup-fails before jobs/logs\n\n## Verification\n- pnpm run check\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:10:13Z",
          "mergedAt": "2026-07-07T05:10:24Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 761,
          "url": "https://github.com/kungfu-systems/buildchain/pull/761",
          "title": "fix(release): skip generated version-state promotion runs",
          "body": "## Summary\n- skip Buildchain self-promotion when the completed Verify run came from generated release/version-state commits\n- keep generated commit titles covered by inventory and build-surface tests\n\n## Why\nSuccessful alpha promotion writes generated version-state commits back to alpha/dev. Those pushes should finish Verify only; they must not start a second promote job that cannot have PR-stage RC lineage.\n\nFixes #760.\n\n## Validation\n- corepack pnpm@11.7.0 run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:10:29Z",
          "mergedAt": "2026-07-07T05:12:12Z",
          "additions": 7,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 762,
          "url": "https://github.com/kungfu-systems/buildchain/pull/762",
          "title": "chore(release): promote v2.8 alpha",
          "body": "## Summary\n- promote current dev/v2/v2.8 to alpha/v2/v2.8\n- publish the next Buildchain v2.8 alpha after release workflow fixes\n\n## Validation\n- PR checks and Buildchain self-promotion workflow will validate the release candidate before merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:12:36Z",
          "mergedAt": "2026-07-07T05:14:16Z",
          "additions": 7,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 28,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/28",
          "title": "fix(site): keep cross-surface links canonical",
          "body": "## Summary\n- keep cross-surface human links canonical by default, e.g. hub -> kfd.libkungfu.dev and buildchain.libkungfu.dev\n- preserve localhost development by adding data-local-href fallbacks rewritten only on localhost/127.0.0.1\n- keep intra-surface navigation relative, such as KFD decision pages and Buildchain docs pages\n\n## Verification\n- pnpm run build\n- pnpm run check\n- browser localhost check confirms runtime fallback keeps local links local\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:17:52Z",
          "mergedAt": "2026-07-07T05:23:44Z",
          "additions": 57,
          "deletions": 27,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 763,
          "url": "https://github.com/kungfu-systems/buildchain/pull/763",
          "title": "fix(release): use release token for protected generated refs",
          "body": "## Summary\n- add a generated-ref-update-token input to promote-buildchain-ref\n- pass BUILDCHAIN_PROMOTION_TOKEN from release-candidate-promote for protected generated ref updates\n- keep generated status checks on github.token while using the release authority for protected version-state/channel bookkeeping\n\n## Fixes\n- Fixes the KFD/buildchain-friction class where finalization publishes successfully, then fails to PATCH a protected dev/* ref with `At least 1 approving review is required`.\n- Specifically addresses the open issue class represented by #741 without requiring consumer reruns or manual PR approval for Buildchain-generated bookkeeping.\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs --test-name-pattern \"generated ref update token|direct version-state sync|controlled branch-protection review bypass\"\n- node --test tests/build-surface.test.mjs --test-name-pattern \"branch-protection review bypass\"\n- node --check actions/promote-buildchain-ref/lib.js && node --check actions/promote-buildchain-ref/index.js\n- corepack pnpm@11.7.0 --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- corepack pnpm@11.7.0 run generate:site\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:30:16Z",
          "mergedAt": "2026-07-07T05:31:59Z",
          "additions": 261,
          "deletions": 108,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 764,
          "url": "https://github.com/kungfu-systems/buildchain/pull/764",
          "title": "chore(release): promote v2.8 alpha",
          "body": "## Summary\n- Promote dev/v2/v2.8 to alpha/v2/v2.8.\n- Includes protected generated ref update token support from #763.\n\n## Expected publish\n- alpha prerelease only\n- no stable/latest release movement\n- generated version-state follow-up should remain skipped\n\n## Validation before merge\n- PR-stage Buildchain checks and release-candidate artifacts",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:32:25Z",
          "mergedAt": "2026-07-07T05:34:07Z",
          "additions": 261,
          "deletions": 108,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 305,
          "url": "https://github.com/kungfu-systems/kungfu/pull/305",
          "title": "feat(sdk): add product workflows for kfx and artifacts",
          "body": "## Summary\n- add SDK-distributed `kungfu sdk product` workflows for GUI/TUI dev and build flows\n- move distributable packaging to artifact-level dist with declared first-party kfx dependencies\n- support single-kfx dev run and artifact product dist from one command\n\n## Validation\n- `./kungfu-code check:types`\n- `./kungfu-code --filter @kungfu-tech/sdk run build`\n- `./kungfu-code verify`\n- `./kungfu-code dist`\n- `hdiutil verify artifact/dist/Kungfu-4.0.0-alpha.0-arm64.dmg`\n- artifact extensions dependency check: declared 11, found 11, missing 0, extra 0\n\n## Artifacts\n- `artifact/dist/Kungfu-4.0.0-alpha.0-arm64.dmg`\n- dmg sha256: `15fea3804d305601ba06238fc080c41da0d0cd4a8221c0cd099c95932522b5c4`\n- zip sha256: `b9c99845548d6dbb6ae8f69f5b121d7d308bd4e1faa27cd4dceaf334969400aa`",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:34:19Z",
          "mergedAt": "2026-07-07T05:35:18Z",
          "additions": 1463,
          "deletions": 52,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 306,
          "url": "https://github.com/kungfu-systems/kungfu/pull/306",
          "title": "docs(agent): expose Atlas projection onboarding",
          "body": "Expose Atlas projection import/show commands through the installed Kungfu agent onboarding pack so agents can discover the workflow from Kungfu itself.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:38:58Z",
          "mergedAt": "2026-07-07T05:40:26Z",
          "additions": 104,
          "deletions": 6,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 765,
          "url": "https://github.com/kungfu-systems/buildchain/pull/765",
          "title": "feat(site): define surface manifest timestamp policy",
          "body": "## Summary\n- add a shared `@kungfu-tech/buildchain/surface-manifest` timestamp/reproducibility policy helper\n- apply the policy to Buildchain site bundle manifests, web-surface deployment manifests for every named surface, and Release Passport metadata\n- inject CI/release timestamps during Buildchain promotion version-state/publish lifecycles while keeping source checkouts deterministic with `source-date-epoch`\n- make site manifests version-state files so timestamp/version manifest changes remain part of the audited promotion entry\n\n## Validation\n- `corepack pnpm@11.7.0 run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:51:16Z",
          "mergedAt": "2026-07-07T05:55:11Z",
          "additions": 502,
          "deletions": 93,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 766,
          "url": "https://github.com/kungfu-systems/buildchain/pull/766",
          "title": "release: promote v2.8 alpha",
          "body": "## Summary\n- Promote the current Buildchain v2.8 dev line to alpha.\n- Includes the surface manifest timestamp/reproducibility policy update from PR #765.\n\n## Validation\n- PR #765 passed `check` and Build Surface Fixture.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T05:55:50Z",
          "mergedAt": "2026-07-07T05:57:39Z",
          "additions": 502,
          "deletions": 93,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 16,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/16",
          "title": "feat(site): add commercial site structure",
          "body": "## Summary\\n- add About, Services, and Legal pages so kungfu.tech is no longer a single-page product site\\n- link the commercial product axis to libkungfu.dev as the developer substrate axis\\n- keep homepage copy in coming-soon posture while preserving cost/state/proof positioning\\n- compact homepage trust copy and keep full policy detail on Trust/Legal pages\\n\\n## Verification\\n- bash scripts/build-site.sh\\n- bash scripts/check-site.sh\\n- Playwright snapshots for home, About, Services, and Legal\\n\\n## Release scope\\n- This PR is intended to update staging after merge to main.\\n- It is not a Buildchain production release PR and does not carry the buildchain-release label.\\n\\nAgent: Codex\\nGoal: 2026-07-07-kungfu-tech-production-site-structure\\nMission: kungfu-technical-stewardship",
          "author": "dongkeren",
          "createdAt": "2026-07-07T06:00:55Z",
          "mergedAt": "2026-07-07T06:02:27Z",
          "additions": 765,
          "deletions": 43,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 307,
          "url": "https://github.com/kungfu-systems/kungfu/pull/307",
          "title": "ci: route product builds through buildchain",
          "body": "## Summary\n- Add the Buildchain v2 product build workflow for alpha/release channel PRs.\n- Route product build artifacts through the S3-to-GitHub-artifacts relay on the kungfu-v4 self-hosted runner preset.\n- Replace legacy v1 release verify/publish workflows with lightweight verify plus Buildchain RC promote-only.\n- Keep npm and GitHub Release publishing disabled by using a custom publish evidence script.\n\n## Validation\n- actionlint .github/workflows/build.yml .github/workflows/release-verify.yml .github/workflows/release-new-version.yml .github/workflows/buildchain-validate.yml\n- node /Users/dkr/Code/kungfu-systems/buildchain/bin/buildchain.mjs validate config --require-version-state --require-lifecycle-stages install,build,verify,publish\n- node --check scripts/buildchain-custom-publish-evidence.mjs\n- Buildchain validatePublishEvidence smoke for the custom evidence script\n\n## Release behavior\nThe heavy product build runs once on the alpha/release PR open/ready event. The merge-side workflow uses Buildchain release-candidate promote-only and does not call the build matrix again.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T06:11:28Z",
          "mergedAt": "2026-07-07T06:12:30Z",
          "additions": 186,
          "deletions": 66,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 308,
          "url": "https://github.com/kungfu-systems/kungfu/pull/308",
          "title": "ci: align buildchain promotion check name",
          "body": "## Summary\n- Align the Buildchain promote required status check fragment with the product build job name (  • electron-builder version=20.39.0).\n\n## Validation\n- actionlint .github/workflows/release-new-version.yml",
          "author": "dongkeren",
          "createdAt": "2026-07-07T06:13:44Z",
          "mergedAt": "2026-07-07T06:14:59Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 310,
          "url": "https://github.com/kungfu-systems/kungfu/pull/310",
          "title": "ci: bootstrap buildchain alpha workflow",
          "body": "## Summary\n- Bootstrap alpha/v4/v4.0 with the Buildchain Build workflow file.\n- Replace legacy v1 release verify with a lightweight handoff check.\n- Disable release promotion on this bootstrap PR so it cannot publish or promote.\n\n## Why\nThe first dev/v4/v4.0 -> alpha/v4/v4.0 attempt created a Build workflow startup_failure because the alpha base branch did not yet contain .github/workflows/build.yml. This bootstrap PR prepares the alpha base for the actual release-candidate PR.\n\n## Validation\n- actionlint .github/workflows/build.yml .github/workflows/release-verify.yml .github/workflows/release-new-version.yml .github/workflows/buildchain-validate.yml\n- git diff --check\n\n## Release behavior\nThis PR is not a release candidate and must not be counted as the alpha product build. The actual alpha PR will be opened after this bootstrap is merged and branch protection is restored to require build.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T06:23:32Z",
          "mergedAt": "2026-07-07T06:24:18Z",
          "additions": 67,
          "deletions": 67,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 313,
          "url": "https://github.com/kungfu-systems/kungfu/pull/313",
          "title": "ci: simplify buildchain product build caller",
          "body": "## Summary\n- Simplify the Build workflow caller for Buildchain v2 reusable workflow.\n- Add secrets inheritance and remove optional workflow_dispatch/concurrency/expression inputs while keeping the product build contract unchanged.\n\n## Validation\n- actionlint .github/workflows/build.yml .github/workflows/release-verify.yml .github/workflows/release-new-version.yml .github/workflows/buildchain-validate.yml\n- git diff --check\n\n## Release behavior\nThis PR targets dev/v4/v4.0 and does not run the product build. The actual product build remains reserved for the next dev -> alpha release-candidate PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T06:33:51Z",
          "mergedAt": "2026-07-07T06:34:31Z",
          "additions": 2,
          "deletions": 14,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 315,
          "url": "https://github.com/kungfu-systems/kungfu/pull/315",
          "title": "ci: grant buildchain build issue permission",
          "body": "## Summary\n- grant the Buildchain reusable build workflow the issue permission it requests\n- unblock alpha release-candidate build startup while keeping publish/release options disabled in Buildchain config\n\n## Validation\n- actionlint .github/workflows/build.yml .github/workflows/release-verify.yml .github/workflows/release-new-version.yml .github/workflows/buildchain-validate.yml\n- git diff --check\n\n## Build policy\n- This PR targets dev/v4/v4.0, so it should only run signoff/validate and must not run the product Build workflow.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T06:41:49Z",
          "mergedAt": "2026-07-07T06:42:42Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 317,
          "url": "https://github.com/kungfu-systems/kungfu/pull/317",
          "title": "ci: make buildchain lifecycle install portable",
          "body": "## Summary\n- run Buildchain lifecycle stages through a Node shim that dispatches to kungfu-code on POSIX and kungfu-code.cmd on Windows\n- update pnpm-lock.yaml so framework/core optional platform packages match package.json under frozen lockfile checks\n\n## Evidence from failed alpha PR\n- PR #316 scheduled exactly one product Build workflow run: https://github.com/kungfu-systems/kungfu/actions/runs/28847079471\n- Windows failed because ./kungfu-code sync is not executable under cmd\n- macOS/Linux failed frozen lockfile because framework/core optionalDependencies were missing from pnpm-lock.yaml\n\n## Validation\n- node --check scripts/buildchain-run-kungfu-code.mjs\n- CI=true fnm exec --using-file -- corepack pnpm install --frozen-lockfile --lockfile-only --force\n- node scripts/buildchain-run-kungfu-code.mjs sync\n- fnm exec --using-file -- corepack pnpm exec buildchain validate --require-version-state --require-lifecycle-stages install,build,verify\n- git diff --check\n\n## Build policy\n- This PR targets dev/v4/v4.0 and should not run product Build. A fresh alpha PR will be opened after this lands.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T07:01:09Z",
          "mergedAt": "2026-07-07T07:02:01Z",
          "additions": 59,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 319,
          "url": "https://github.com/kungfu-systems/kungfu/pull/319",
          "title": "ci: fix buildchain install lifecycle",
          "body": "## Summary\n- skip optional platform packages during the Buildchain install lifecycle\n- invoke kungfu-code.cmd through cmd call on Windows runners\n\n## Validation\n- node --check scripts/buildchain-run-kungfu-code.mjs\n- pnpm exec biome check scripts/buildchain-run-kungfu-code.mjs\n- pnpm run check:types\n- node scripts/buildchain-run-kungfu-code.mjs install --frozen-lockfile --no-optional\n- pnpm exec buildchain validate --require-version-state --require-lifecycle-stages install,build,verify\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T07:25:54Z",
          "mergedAt": "2026-07-07T07:26:53Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 321,
          "url": "https://github.com/kungfu-systems/kungfu/pull/321",
          "title": "ci: provide buildchain pnpm shims",
          "body": "## Summary\n- inject a temporary pnpm/pnpm.cmd shim for Buildchain lifecycle commands\n- avoid Windows cmd quote drift by invoking fnm/corepack directly on Windows\n\n## Validation\n- node --check scripts/buildchain-run-kungfu-code.mjs\n- pnpm exec biome check scripts/buildchain-run-kungfu-code.mjs\n- pnpm run check:types\n- node scripts/buildchain-run-kungfu-code.mjs exec pnpm --version\n- node scripts/buildchain-run-kungfu-code.mjs install --frozen-lockfile --no-optional\n- pnpm exec buildchain validate --require-version-state --require-lifecycle-stages install,build,verify\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T07:47:35Z",
          "mergedAt": "2026-07-07T07:48:25Z",
          "additions": 40,
          "deletions": 14,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 323,
          "url": "https://github.com/kungfu-systems/kungfu/pull/323",
          "title": "ci: use corepack directly on windows buildchain",
          "body": "## Summary\n- avoid requiring fnm in the Windows Buildchain lifecycle wrapper\n- keep the temporary pnpm.cmd shim for nested pnpm calls inside package scripts\n\n## Validation\n- node --check scripts/buildchain-run-kungfu-code.mjs\n- pnpm exec biome check scripts/buildchain-run-kungfu-code.mjs\n- pnpm run check:types\n- node scripts/buildchain-run-kungfu-code.mjs exec pnpm --version\n- node scripts/buildchain-run-kungfu-code.mjs install --frozen-lockfile --no-optional\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:00:49Z",
          "mergedAt": "2026-07-07T08:01:36Z",
          "additions": 5,
          "deletions": 9,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 325,
          "url": "https://github.com/kungfu-systems/kungfu/pull/325",
          "title": "ci: carry no-optional through artifact dist",
          "body": "## Summary\n- pass a Buildchain-only no-optional marker through lifecycle commands\n- let artifact dist reuse --no-optional for its internal dependency sync\n- run Windows corepack.cmd through a shell so .cmd execution works\n\n## Validation\n- node --check scripts/buildchain-run-kungfu-code.mjs\n- node --check artifact/scripts/dist.mjs\n- pnpm exec biome check scripts/buildchain-run-kungfu-code.mjs artifact/scripts/dist.mjs\n- pnpm run check:types\n- node scripts/buildchain-run-kungfu-code.mjs exec node -e \"console.log(process.env.KUNGFU_BUILDCHAIN_NO_OPTIONAL)\"\n- node scripts/buildchain-run-kungfu-code.mjs install --frozen-lockfile --no-optional\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:10:26Z",
          "mergedAt": "2026-07-07T08:11:18Z",
          "additions": 11,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 768,
          "url": "https://github.com/kungfu-systems/buildchain/pull/768",
          "title": "fix(site): preserve published manifest timestamp policy",
          "body": "## Summary\n- preserve current-version `ci-injected` site manifest timestamp policy during deterministic `generate-site-bundle --check` runs\n- keep source checkouts able to force `source-date-epoch` explicitly\n- document that version-state branches use the existing published manifest policy as deterministic input\n\n## Validation\n- simulated published `ci-injected` manifest followed by `GITHUB_SHA=... pnpm run check:site`\n- `corepack pnpm@11.7.0 run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:14:05Z",
          "mergedAt": "2026-07-07T08:16:01Z",
          "additions": 51,
          "deletions": 17,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 327,
          "url": "https://github.com/kungfu-systems/kungfu/pull/327",
          "title": "feat(gui): add settings overlay and dev gates",
          "body": "## Summary\n- add a tabbed settings overlay hosted by the GUI shell\n- add bootstrap build/rebuild commands for fresh worktrees\n- add changed-scope check/fix gates and make pre-commit read-only\n\n## Verification\n- ./kungfu-code check\n- node --check scripts/build.mjs scripts/check.mjs scripts/fix.mjs scripts/precommit.mjs\n- /bin/sh -n kungfu-code && /bin/sh -n .githooks/pre-commit\n- git diff --check\n- ./kungfu-code build (completed earlier in this worktree)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:17:07Z",
          "mergedAt": "2026-07-07T08:17:59Z",
          "additions": 1247,
          "deletions": 234,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 771,
          "url": "https://github.com/kungfu-systems/buildchain/pull/771",
          "title": "fix(site): preserve published manifest timestamp policy",
          "body": "## Summary\n- preserve existing ci-injected site manifest timestamp policy on version-state branches\n- keep generated dist/site outputs check-clean for the currently published alpha version\n- document deterministic check behavior for published manifests\n\n## Validation\n- node --check scripts/generate-site-bundle.mjs\n- node scripts/check-inventory.mjs\n- GITHUB_SHA=cccccccccccccccccccccccccccccccccccccccc corepack pnpm@11.7.0 run check:site\n- corepack pnpm@11.7.0 run check\n\nThis reopens the same commit from #770 under a release-line-aware version-state head ref.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:24:45Z",
          "mergedAt": "2026-07-07T08:27:14Z",
          "additions": 51,
          "deletions": 17,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 767,
          "url": "https://github.com/kungfu-systems/buildchain/pull/767",
          "title": "release: promote v2.8 stable",
          "body": "## Summary\n- Promote Buildchain v2.8 alpha to stable release.\n- Includes `@kungfu-tech/buildchain@2.8.8-alpha.7` surface manifest timestamp/reproducibility policy and release passport timestamp policy support.\n\n## Validation\n- Alpha promotion run 28845027391 succeeded.\n- npm alpha is 2.8.8-alpha.7.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:09:21Z",
          "mergedAt": "2026-07-07T08:30:00Z",
          "additions": 1343,
          "deletions": 418,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 328,
          "url": "https://github.com/kungfu-systems/kungfu/pull/328",
          "title": "ci: prepare buildchain source build prerequisites",
          "body": "## Summary\n- keep Buildchain no-optional installs while injecting only the current libnode platform package for source rebuilds\n- mark Buildchain source builds and auto-detect a Conan default profile when missing\n- add common Windows user tool directories to PATH for lifecycle commands\n\n## Validation\n- node --check scripts/buildchain-run-kungfu-code.mjs artifact/scripts/dist.mjs framework/core/.gyp/run-conan.js\n- pnpm exec biome check scripts/buildchain-run-kungfu-code.mjs artifact/scripts/dist.mjs framework/core/.gyp/run-conan.js\n- pnpm run check:types\n- node scripts/buildchain-run-kungfu-code.mjs install --frozen-lockfile --no-optional\n- libnode NODE_PATH probe with @kungfu-tech/libnode-darwin-arm64@22.22.3-kf.1",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:34:56Z",
          "mergedAt": "2026-07-07T08:36:14Z",
          "additions": 146,
          "deletions": 11,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 774,
          "url": "https://github.com/kungfu-systems/buildchain/pull/774",
          "title": "fix(release): accept version-state PR lineage",
          "body": "## Summary\n- accept same-line buildchain/version-state/* PR heads as strict promotion lineage when they are merged, same-repository PRs targeting the channel branch\n- keep the existing dev->alpha / alpha->release rule as the primary expected source\n- add a regression test for alpha promotion from a same-line version-state PR\n\n## Validation\n- corepack pnpm@11.7.0 exec node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:43:46Z",
          "mergedAt": "2026-07-07T08:46:23Z",
          "additions": 114,
          "deletions": 43,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 330,
          "url": "https://github.com/kungfu-systems/kungfu/pull/330",
          "title": "ci: align core optional lockfile specifiers",
          "body": "## Summary\n- add the framework/core optional platform-package specifiers to the lockfile importer so Buildchain no-optional frozen installs validate on clean runners\n\n## Validation\n- CI=true pnpm install --frozen-lockfile --no-optional --lockfile-only\n- node scripts/buildchain-run-kungfu-code.mjs install --frozen-lockfile --no-optional\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:47:40Z",
          "mergedAt": "2026-07-07T08:48:17Z",
          "additions": 10,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 775,
          "url": "https://github.com/kungfu-systems/buildchain/pull/775",
          "title": "fix(release): accept version-state PR lineage",
          "body": "## Summary\n- promote the version-state PR lineage fix into alpha using the release-line-aware version-state ref form\n- allows the pending alpha promotion to recognize same-line version-state PRs as valid same-repository lineage\n\n## Validation\n- corepack pnpm@11.7.0 run check\n\nThis is the alpha-side runtime fix needed before rerunning the pending stable promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:49:44Z",
          "mergedAt": "2026-07-07T08:52:10Z",
          "additions": 114,
          "deletions": 43,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 332,
          "url": "https://github.com/kungfu-systems/kungfu/pull/332",
          "title": "ci: discover uv from windows runner users",
          "body": "## Summary\n- add Windows user tool directories from C:\\Users\\* to the Buildchain wrapper PATH so self-hosted runner jobs can find an existing uv.exe during source rebuilds\n- keep this scoped to Windows Buildchain lifecycle execution; no tool installation is performed\n\n## Validation\n- node --check scripts/buildchain-run-kungfu-code.mjs\n- pnpm exec biome check scripts/buildchain-run-kungfu-code.mjs\n- node scripts/buildchain-run-kungfu-code.mjs exec node -e \"console.log(process.env.KUNGFU_BUILDCHAIN_NO_OPTIONAL, process.env.KUNGFU_BUILDCHAIN_SOURCE_BUILD)\"\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T08:59:13Z",
          "mergedAt": "2026-07-07T09:00:03Z",
          "additions": 19,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 777,
          "url": "https://github.com/kungfu-systems/buildchain/pull/777",
          "title": "release: promote Buildchain v2.8 stable",
          "body": "Promote the current v2.8 alpha runtime into release/v2/v2.8 with conflicts resolved on a line-scoped Buildchain version-state branch.\n\nThis absorbs the alpha lineage fix and site manifest timestamp-policy release material so stable promotion can tree-match v2.8.8-alpha.8 before finalizing the stable npm/GitHub release.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:01:41Z",
          "mergedAt": "2026-07-07T09:03:51Z",
          "additions": 125,
          "deletions": 54,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 334,
          "url": "https://github.com/kungfu-systems/kungfu/pull/334",
          "title": "feat(gui): add global appearance config",
          "body": "## Summary\n- add `kungfu config set` and `kungfu config unset` for contract-validated user overrides\n- wire GUI global font family, font size, and zoom through the Kungfu config mechanism\n- add an Appearance tab with cross-platform font presets and Custom font-family input\n\n## Verification\n- `./kungfu-code check`\n- `./kungfu-code build`\n- `./kungfu-code verify`\n\n## Version impact\n- minor: adds user-facing global appearance settings",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:02:59Z",
          "mergedAt": "2026-07-07T09:04:12Z",
          "additions": 628,
          "deletions": 20,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 17,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/17",
          "title": "Release kungfu.tech commercial launch refresh",
          "body": "Production release for the refreshed kungfu.tech commercial site.\\n\\nChanged:\\n- consolidates shared header/footer styling into public/assets/site.css\\n- refines homepage/header/footer copy and mobile layout\\n- keeps public copy in coming-soon positioning\\n\\nVerified locally:\\n- bash scripts/build-site.sh\\n- bash scripts/check-site.sh\\n- mobile viewport checks at 390px and 320px\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:18:10Z",
          "mergedAt": "2026-07-07T09:19:42Z",
          "additions": 535,
          "deletions": 563,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 335,
          "url": "https://github.com/kungfu-systems/kungfu/pull/335",
          "title": "ci: instrument artifact buildchain lifecycle",
          "body": "## Summary\n- upgrade the SDK and artifact build dependency to the latest Buildchain release package, @kungfu-tech/buildchain@2.8.7\n- instrument artifact/scripts/dist.mjs with Buildchain toolkit lifecycle spans and event verification\n- keep no-optional Buildchain source builds working by installing current-platform libnode and Rollup native packages under .buildchain and exposing them through NODE_PATH\n- broaden Windows runner tool discovery for uv/uvx across WinGet package directories and Scoop shims\n\n## Validation\n- node --check artifact/scripts/dist.mjs\n- node --check scripts/buildchain-run-kungfu-code.mjs\n- ./kungfu-code exec biome check artifact/scripts/dist.mjs scripts/buildchain-run-kungfu-code.mjs artifact/package.json developer/sdk/package.json\n- ./kungfu-code run check:types\n- CI=true ./kungfu-code install --frozen-lockfile --no-optional --lockfile-only\n- Buildchain logging smoke with BUILDCHAIN_LOG_PATH\n- Rollup platform package resolution smoke\n\n## Alpha PR handling\n- Closed #333 after its single allowed Build run failed on Windows and Linux\n- Cancelled the remaining queued jobs for run 28854374922 before opening this dev fix PR",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:20:32Z",
          "mergedAt": "2026-07-07T09:21:58Z",
          "additions": 463,
          "deletions": 103,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 780,
          "url": "https://github.com/kungfu-systems/buildchain/pull/780",
          "title": "fix(release): defer protected next-alpha bookkeeping",
          "body": "Fix #778.\n\nWhen release finalization has already published the stable artifact but protected branch bookkeeping rejects a direct non-fast-forward next-alpha update, Buildchain now creates a line-scoped version-state PR and returns a pending finalization instead of failing the whole promotion run.\n\nValidation:\n- corepack pnpm@11.7.0 exec node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:27:08Z",
          "mergedAt": "2026-07-07T09:29:03Z",
          "additions": 159,
          "deletions": 70,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 337,
          "url": "https://github.com/kungfu-systems/kungfu/pull/337",
          "title": "ci: bootstrap uv for buildchain windows",
          "body": "## Summary\n- upgrade @kungfu-tech/buildchain to the current latest release package, 2.8.8\n- bootstrap uv into .buildchain/uv on Windows only when uv is not already available\n- keep the bootstrap scoped to the lifecycle wrapper instead of mutating runner-global state\n- exclude generated .buildchain runtime files from the no-bash guard used by verify\n\n## Evidence from alpha #336\n- Windows now installs libnode and Rollup platform packages but still fails because uv is unavailable on the runner\n- Linux builds the AppImage and reports Buildchain observability events, then fails verify because .buildchain/runtime/scripts/check-workflows.sh is generated by Buildchain runtime and should not be scanned as repo source\n\n## Validation\n- node --check scripts/buildchain-run-kungfu-code.mjs\n- node --check scripts/no-bash-guard.mjs\n- node scripts/no-bash-guard.mjs\n- ./kungfu-code exec biome check scripts/buildchain-run-kungfu-code.mjs scripts/no-bash-guard.mjs artifact/package.json developer/sdk/package.json\n- ./kungfu-code run check:types\n- CI=true ./kungfu-code install --frozen-lockfile --no-optional --lockfile-only",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:34:08Z",
          "mergedAt": "2026-07-07T09:34:50Z",
          "additions": 94,
          "deletions": 10,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 78,
          "url": "https://github.com/kungfu-systems/kfd/pull/78",
          "title": "ci(kfd): lock Buildchain floating contract",
          "body": "## Summary\\n- move KFD build and promotion workflows back to Buildchain v2 floating refs\\n- add a consumer-owned buildchain.contract-lock.json for Buildchain runtime contract drift checks\\n- publish the lock as a KFD package surface and bind it into KFD-2/KFD-3 witnesses\\n- bump the next alpha package version to 1.0.0-alpha.18\\n\\n## Verification\\n- node scripts/check.mjs\\n- Buildchain contract lock check: unchanged / compatible / no drift\\n- ruby YAML parse for workflows\\n- npm pack --dry-run --json\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:26:51Z",
          "mergedAt": "2026-07-07T09:42:58Z",
          "additions": 159,
          "deletions": 57,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 782,
          "url": "https://github.com/kungfu-systems/buildchain/pull/782",
          "title": "feat(web-surface): gate floating runtime contract drift",
          "body": "Add first-class Buildchain contract lock inputs to the reusable web-surface workflow so floating @v2 consumers get compatible/breaking drift handling before caller build, render, deploy planning, or publish side effects.\\n\\nIncludes contract-world/site-bundle updates and tests.\\n\\nValidation:\\n- corepack pnpm@11.7.0 run check\\n- corepack pnpm@11.7.0 run check:site\\n- corepack pnpm@11.7.0 exec node --test tests/buildchain-contract.test.mjs tests/build-surface.test.mjs",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:44:27Z",
          "mergedAt": "2026-07-07T09:46:16Z",
          "additions": 244,
          "deletions": 14,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 79,
          "url": "https://github.com/kungfu-systems/kfd/pull/79",
          "title": "release(kfd): publish alpha 18",
          "body": "## Summary\n- Promote current dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd 1.0.0-alpha.18.\n- Includes Buildchain @v2 floating reusable workflow integration with buildchain.contract-lock.json.\n- Carries KFD-1/2/3 witness metadata for the alpha package and release passport.\n\n## Verification\n- PR #78 Verify and Build passed on dev.\n- This PR should run the alpha branch gates and Buildchain promotion after merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:43:39Z",
          "mergedAt": "2026-07-07T09:46:34Z",
          "additions": 159,
          "deletions": 57,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 339,
          "url": "https://github.com/kungfu-systems/kungfu/pull/339",
          "title": "docs(readme): align public Kungfu positioning",
          "body": "## Summary\n\n- Align the README opening with the public Kungfu product and developer entrypoints.\n- Replace the older facts-before-trust slogan with KFD-oriented claim and receipt language.\n- Update the facts-before-trust document opening to match the README framing.\n\n## Checks\n\n- git diff --check\n- public wording scan for private maintenance signals\n- ./kungfu-code check (blocked during dependency install: current pnpm lockfile is missing @kungfu-tech/core optional package entries)",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:47:58Z",
          "mergedAt": "2026-07-07T09:48:54Z",
          "additions": 27,
          "deletions": 11,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 341,
          "url": "https://github.com/kungfu-systems/kungfu/pull/341",
          "title": "feat(gui): add shell status bar chrome",
          "body": "## Summary\n- add a bottom shell status bar for runtime, master, profile and KFX count signals\n- expose trusted shell APIs for status bar items and notifications\n- fix GUI root sizing so the status bar does not create an outer scrollbar\n- keep source installs from resolving unpublished core platform packages\n- sync SDK contract policy expectations with current KFD and Buildchain metadata\n\n## Validation\n- ./kungfu-code --filter @kungfu-tech/gui run build\n- ./kungfu-code product gui dev --dry-run\n- ./kungfu-code check\n- manual GUI dev run confirmed the status bar renders without an outer scrollbar",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:50:16Z",
          "mergedAt": "2026-07-07T09:51:07Z",
          "additions": 658,
          "deletions": 125,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 784,
          "url": "https://github.com/kungfu-systems/buildchain/pull/784",
          "title": "chore(action): sync promote action bundle",
          "body": "Sync the bundled promote-buildchain-ref action with source so Buildchain version-state verification does not dirty the workspace during alpha promotion.\\n\\nFixes the alpha promotion failure observed in run 28857079107 / issue #783.\\n\\nValidation:\\n- corepack pnpm@11.7.0 --filter ./actions/promote-buildchain-ref build",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:49:30Z",
          "mergedAt": "2026-07-07T09:51:17Z",
          "additions": 13,
          "deletions": 13,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 340,
          "url": "https://github.com/kungfu-systems/kungfu/pull/340",
          "title": "ci: lock conan for buildchain source builds",
          "body": "## Summary\n- add Conan 2 to the locked framework/core uv project\n- make `uv run --frozen conan ...` reproducible on self-hosted runners instead of relying on runner-global tools\n\n## Validation\n- `cd framework/core && uv lock --check`\n- `cd framework/core && uv run --frozen conan --version`\n- `tmp_conan_home=\"$(mktemp -d /tmp/kungfu-conan-home.XXXXXX)\" && cd framework/core && CONAN_HOME=\"$tmp_conan_home\" uv run --frozen conan profile detect --force`\n- `node --check scripts/buildchain-run-kungfu-code.mjs && node --check framework/core/.gyp/run-conan.js`\n- `./kungfu-code exec biome check framework/core/pyproject.toml scripts/buildchain-run-kungfu-code.mjs framework/core/.gyp/run-conan.js`\n- `./kungfu-code run check:types`\n\n## Alpha build note\nPR #338 was closed after its single allowed Build run failed on Windows before native compilation: `uv run --frozen conan profile detect --force` could not find `conan`. This PR fixes forward through dev before opening a fresh alpha PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:49:30Z",
          "mergedAt": "2026-07-07T09:52:42Z",
          "additions": 112,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 81,
          "url": "https://github.com/kungfu-systems/kfd/pull/81",
          "title": "ci(kfd): allow promotion check writes",
          "body": "## Summary\n- Grant Buildchain Ref Promotion the checks: write permission required by the Buildchain v2 reusable promotion workflow.\n- Regenerate KFD-2/KFD-3 metadata hashes for the workflow contract update.\n\n## Verification\n- node scripts/update-kfd-2-claim.mjs\n- node scripts/update-kfd-3-witness.mjs\n- node scripts/update-kfd-1-witness.mjs\n- node scripts/check.mjs\n- ruby YAML parse for buildchain-ref-promotion.yml\n- npm pack --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:51:53Z",
          "mergedAt": "2026-07-07T09:54:22Z",
          "additions": 12,
          "deletions": 11,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 82,
          "url": "https://github.com/kungfu-systems/kfd/pull/82",
          "title": "release(kfd): publish alpha 18",
          "body": "## Summary\n- Promote current dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd 1.0.0-alpha.18.\n- Includes Buildchain @v2 floating reusable workflow integration with buildchain.contract-lock.json.\n- Includes the Buildchain promotion checks: write permission required by the v2 promotion wrapper.\n\n## Verification\n- PR #78 Verify and Build passed on dev.\n- PR #81 Verify and Build passed on dev.\n- This PR should run alpha branch gates and then trigger Buildchain Ref Promotion after merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:54:45Z",
          "mergedAt": "2026-07-07T09:57:08Z",
          "additions": 12,
          "deletions": 11,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 343,
          "url": "https://github.com/kungfu-systems/kungfu/pull/343",
          "title": "docs(readme): add project status badges",
          "body": "## Summary\n\n- Add README badges for Buildchain Validate and DCO status.\n- Add compact public metadata badges for Apache-2.0 license, coming-soon product status, and supported platforms.\n\n## Checks\n\n- git diff --check\n- README public wording scan\n- badge URL HTTP checks\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:57:04Z",
          "mergedAt": "2026-07-07T09:57:48Z",
          "additions": 6,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 70,
          "url": "https://github.com/kungfu-systems/kfd/pull/70",
          "title": "Prepare v1.0.0-alpha.14",
          "body": "Create the generated version-state commit for v1.0.0-alpha.14.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-07T00:42:03Z",
          "mergedAt": "2026-07-07T09:58:20Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 75,
          "url": "https://github.com/kungfu-systems/kfd/pull/75",
          "title": "Prepare v1.0.0-alpha.16",
          "body": "Create the generated version-state commit for v1.0.0-alpha.16.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-07T01:21:21Z",
          "mergedAt": "2026-07-07T09:58:20Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 785,
          "url": "https://github.com/kungfu-systems/buildchain/pull/785",
          "title": "release: promote Buildchain v2.8.9 stable",
          "body": "Promote Buildchain v2.8.9 stable from the alpha line.\\n\\nIncludes:\\n- #780 protected next-alpha finalization fix for #778\\n- #782 first-class web-surface floating runtime contract lock gate\\n- #784 promote action bundle sync required by version-state verification\\n\\nValidation:\\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T09:56:55Z",
          "mergedAt": "2026-07-07T09:58:55Z",
          "additions": 414,
          "deletions": 95,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 787,
          "url": "https://github.com/kungfu-systems/buildchain/pull/787",
          "title": "docs(readme): add project status badges",
          "body": "## Summary\n- Add README status badges aligned with the Kungfu repository style.\n- Surface Verify, release gate, npm latest/alpha, GitHub Release, license, stability, and supported platforms.\n\n## Validation\n- git diff --check\n- Verified badge SVG endpoints return HTTP 200.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:08:12Z",
          "mergedAt": "2026-07-07T10:15:59Z",
          "additions": 18,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 344,
          "url": "https://github.com/kungfu-systems/kungfu/pull/344",
          "title": "feat(gui): add integrated window chrome",
          "body": "## Summary\n- add a shared renderer titlebar for Electron GUI shell chrome\n- use macOS hidden inset titlebar with traffic-light safe area\n- use Windows custom frame controls and keep Linux on conservative native chrome\n- add a command/search entry that opens enabled KFX views by id or title\n\n## Validation\n- ./kungfu-code --filter @kungfu-tech/gui run build\n- ./kungfu-code check\n- ./kungfu-code build\n- ./kungfu-code product gui dev (macOS visual smoke confirmed)\n\n## Notes\n- Windows and Linux behavior is implemented by platform branches but only build-validated from macOS in this pass.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:16:27Z",
          "mergedAt": "2026-07-07T10:17:01Z",
          "additions": 433,
          "deletions": 33,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 345,
          "url": "https://github.com/kungfu-systems/kungfu/pull/345",
          "title": "ci: lock ninja for buildchain windows",
          "body": "## Summary\n- add Ninja to the locked framework/core uv project\n- make `cmake-js --generator Ninja` reproducible on Windows self-hosted runners instead of relying on runner-global ninja\n\n## Validation\n- `cd framework/core && uv lock --check`\n- `cd framework/core && uv run --frozen ninja --version`\n- `cd framework/core && uv run --frozen conan --version`\n- `./kungfu-code run check:types`\n- `git diff --check`\n\n## Alpha build note\nPR #342 was closed after its single allowed Build run failed on Windows. It advanced past uv and Conan install/build setup, then failed during `cmake-js configure` because CMake could not find the Ninja build program.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:16:28Z",
          "mergedAt": "2026-07-07T10:17:52Z",
          "additions": 31,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 788,
          "url": "https://github.com/kungfu-systems/buildchain/pull/788",
          "title": "fix(release): base pending version-state PRs on channel heads",
          "body": "## Summary\n- create or reuse Buildchain-owned version-state PRs when release finalization protected refs reject direct generated bookkeeping\n- base pending next-alpha commits on the current channel head so generated PRs are clean and auditable\n- extend the same fallback to publish-gate/major release/next-alpha finalization and update docs/site bundle\n\n## Validation\n- corepack pnpm@11.7.0 exec node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 run check\n\n## Issue\n- Fixes #778\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:27:40Z",
          "mergedAt": "2026-07-07T10:29:44Z",
          "additions": 403,
          "deletions": 132,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 63,
          "url": "https://github.com/kungfu-systems/libnode/pull/63",
          "title": "feat(release): add KFD passport gates for libnode alpha",
          "body": "## Summary\n- add KFD-1 contract-world witness for libnode release facts\n- add KFD-2 public release trust claim with explicit residual risks\n- add KFD-3 collaboration-interface prebuild witness and artifact verifier\n- wire Buildchain release passport KFD inputs and bump alpha to 22.22.3-kf.3-alpha.13\n\n## Verification\n- corepack pnpm verify-release\n- corepack pnpm verify-package-source\n- git diff --check\n- local Buildchain release passport simulation with KFD-1/2/3 inputs\n\n## Notes\n- KFD-2 intentionally reports downgraded warning for upstream Node and native toolchain residual risk; KFD-1 and KFD-3 hard gates pass in simulation.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:10:14Z",
          "mergedAt": "2026-07-07T10:33:37Z",
          "additions": 820,
          "deletions": 2,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 790,
          "url": "https://github.com/kungfu-systems/buildchain/pull/790",
          "title": "chore(release): sync alpha state back to dev",
          "body": "## Summary\n- Merge current alpha/v2/v2.8 state back into dev/v2/v2.8 so dev remains a clean promotion source.\n- Preserve #788 release finalization fix while carrying forward the published alpha version-state and web-surface contract changes.\n- Regenerate site bundle and promote-buildchain-ref dist.\n\n## Validation\n- corepack pnpm@11.7.0 run check\n\n## Context\n- Unblocks dev -> alpha promotion after #788; the previous PR #789 was dirty because alpha and dev had diverged.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:34:44Z",
          "mergedAt": "2026-07-07T10:36:42Z",
          "additions": 261,
          "deletions": 31,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 347,
          "url": "https://github.com/kungfu-systems/kungfu/pull/347",
          "title": "ci: load msvc env for buildchain windows",
          "body": "## Summary\n- load MSVC Developer environment automatically for Windows Buildchain runs when `cl.exe` is not already on PATH\n- locate `vcvars64.bat` via VSINSTALLDIR, vswhere, or bounded Visual Studio directory discovery\n- keep the wrapper self-contained so Windows self-hosted runners do not need to start from a Developer Prompt\n\n## Validation\n- `node --check scripts/buildchain-run-kungfu-code.mjs`\n- `./kungfu-code exec biome check scripts/buildchain-run-kungfu-code.mjs`\n- `./kungfu-code run check:types`\n- `git diff --check`\n\n## Alpha build note\nPR #346 was closed after its single allowed Build run failed on Windows. It advanced past uv, Conan, and Ninja setup, then failed during CMake configure because `cl` was not on PATH.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:33:14Z",
          "mergedAt": "2026-07-07T10:38:14Z",
          "additions": 165,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 791,
          "url": "https://github.com/kungfu-systems/buildchain/pull/791",
          "title": "chore(release): record alpha ancestry in dev",
          "body": "## Summary\n- Record current alpha/v2/v2.8 as an ancestor of dev/v2/v2.8 without changing the dev tree.\n- This fixes GitHub merge-base conflict detection for the dev -> alpha promotion PR after #790 was squash-merged.\n\n## Validation\n- git diff --quiet origin/dev/v2/v2.8 HEAD\n\n## Merge mode\nPlease merge with a merge commit, not squash, so ancestry is preserved.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:37:53Z",
          "mergedAt": "2026-07-07T10:39:47Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 789,
          "url": "https://github.com/kungfu-systems/buildchain/pull/789",
          "title": "Promote dev/v2.8 to alpha",
          "body": "## Summary\n- Promote current dev/v2/v2.8 into alpha/v2/v2.8 after #788.\n- This should publish the next alpha using the fixed release finalization runtime.\n\n## Validation\n- dev PR #788 passed Verify and Build Surface Fixture before merge.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:30:32Z",
          "mergedAt": "2026-07-07T10:41:48Z",
          "additions": 320,
          "deletions": 131,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 794,
          "url": "https://github.com/kungfu-systems/buildchain/pull/794",
          "title": "chore(release): record release ancestry in alpha",
          "body": "Record the current release/v2/v2.8 head as an ancestor of alpha/v2/v2.8 without changing the alpha tree.\n\nThis keeps the stable promotion PR mergeable while preserving the published alpha package state.\n\nValidation:\n- tree diff vs origin/alpha/v2/v2.8 is empty\n- head ref uses the Buildchain version-state namespace accepted by release-line policy",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:51:43Z",
          "mergedAt": "2026-07-07T10:53:25Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 349,
          "url": "https://github.com/kungfu-systems/kungfu/pull/349",
          "title": "feat(gui): add collapsible sidebar",
          "body": "## Summary\n- add a persisted shell state flag for sidebar collapsed state\n- add a compact navigation rail toggle to the GUI shell\n- keep collapsed navigation accessible through view initials and tooltips\n\n## Validation\n- ./kungfu-code --filter @kungfu-tech/gui run build\n- ./kungfu-code check\n- ./kungfu-code build\n- ./kungfu-code product gui dev (macOS visual smoke confirmed)",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:54:19Z",
          "mergedAt": "2026-07-07T10:54:50Z",
          "additions": 76,
          "deletions": 25,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 65,
          "url": "https://github.com/kungfu-systems/libnode/pull/65",
          "title": "release(alpha): publish 22.22.3-kf.3-alpha.13",
          "body": "Promote dev/v22/v22.22 to alpha/v22/v22.22 for @kungfu-tech/libnode 22.22.3-kf.3-alpha.13.\n\nThis release candidate includes first-class KFD 1/2/3 release passport gates:\n- KFD-1 contract/world witness for libnode release-critical source surfaces.\n- KFD-2 public release trust claim with explicit residual risks.\n- KFD-3 collaboration interface prebuild witness and artifact reverse audit command.\n\nRelease source merge commit: 8b418cb4f9a2cd03317b0c7c815f8b4a6643d74e",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:34:23Z",
          "mergedAt": "2026-07-07T10:55:27Z",
          "additions": 820,
          "deletions": 2,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 792,
          "url": "https://github.com/kungfu-systems/buildchain/pull/792",
          "title": "Promote v2.8.10 to stable",
          "body": "## Summary\n- Promote alpha/v2/v2.8 to release/v2/v2.8 after v2.8.10-alpha.0.\n- This publishes the stable release containing #788 and the README/KFD badges.\n\n## Validation\n- Alpha promotion run 28860197348 succeeded.\n- npm alpha dist-tag is 2.8.10-alpha.0.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:45:31Z",
          "mergedAt": "2026-07-07T10:55:35Z",
          "additions": 326,
          "deletions": 131,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 350,
          "url": "https://github.com/kungfu-systems/kungfu/pull/350",
          "title": "ci: fix windows vcvars bootstrap",
          "body": "Fix the Windows Buildchain lifecycle wrapper after PR #348 proved the install lifecycle fails before the build step.\n\nChanges:\n- invoke vcvars64.bat through `cmd /d /c call \"...\" x64 >nul && set` so paths with spaces are handled correctly\n- detect MSVC availability with `where.exe cl` instead of `cl /Bv`, because `cl /Bv` can locate the compiler but still exits non-zero without source files\n\nValidation:\n- `node --check scripts/buildchain-run-kungfu-code.mjs`\n- `./kungfu-code exec biome check scripts/buildchain-run-kungfu-code.mjs`\n- `./kungfu-code run check:types`\n- `git diff --check`\n- DARKHERO read-only Windows smoke: `call vcvars64.bat ... && where cl` resolves cl.exe successfully\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:58:49Z",
          "mergedAt": "2026-07-07T10:59:48Z",
          "additions": 9,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 796,
          "url": "https://github.com/kungfu-systems/buildchain/pull/796",
          "title": "fix(release): bind stable promotion to frozen alpha evidence",
          "body": "Fixes release promotion finalization after an ancestry/version-state alpha PR creates a later same-patch alpha tag.\n\nWhen promoting alpha -> release, Buildchain now first resolves the merged promotion PR frozen head SHA and uses the same-patch alpha tag that is actually contained in that PR head. This prevents a later next-alpha bookkeeping tag from replacing the source alpha evidence for stable promotion.\n\nRegression coverage:\n- release promotion uses frozen PR alpha evidence when a later same-patch alpha exists\n\nValidation:\n- corepack pnpm@11.7.0 exec node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 run check\n\nRelated: #795",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:10:15Z",
          "mergedAt": "2026-07-07T11:12:29Z",
          "additions": 216,
          "deletions": 57,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 352,
          "url": "https://github.com/kungfu-systems/kungfu/pull/352",
          "title": "feat(agent): close KFD-3 agent interface",
          "body": "## Summary\n- add a packaged KFD-3 registry and local schema for the agent-first collaboration interface\n- anchor `kungfu agent` Click commands and the command catalog to registry API ids\n- preserve Atlas projection mode and register the `kungfu atlas` catalog commands in KFD-3 verification\n\n## Validation\n- `./kungfu-code check`\n- `./kungfu-code node scripts/verify-agent-pack.mjs`\n\n## Notes\n- Source-checkout CLI smoke needs a built native `pykungfu` binding; the changed-scope gate and agent-pack verifier passed without a full build.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:11:54Z",
          "mergedAt": "2026-07-07T11:13:22Z",
          "additions": 853,
          "deletions": 63,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 353,
          "url": "https://github.com/kungfu-systems/kungfu/pull/353",
          "title": "ci: use verbatim cmd args for vcvars",
          "body": "Fix the second Windows MSVC bootstrap issue seen in alpha PR #351.\n\nPR #350 changed the command to `call \"...vcvars64.bat\"`, but Node's Windows argument quoting still passed escaped quotes (`\\\"...\\\"`) to `cmd.exe` when using the normal args array. This PR uses the tested `cmd.exe /d /s /c \"\"<vcvars>\" x64 >nul && set\"` form with `windowsVerbatimArguments: true` so `cmd.exe` receives the batch path quotes correctly.\n\nValidation:\n- `node --check scripts/buildchain-run-kungfu-code.mjs`\n- `./kungfu-code exec biome check scripts/buildchain-run-kungfu-code.mjs`\n- `./kungfu-code run check:types`\n- `git diff --check`\n- DARKHERO Node smoke with identical `spawnSync` arguments resolves `cl.exe` successfully\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:13:53Z",
          "mergedAt": "2026-07-07T11:14:31Z",
          "additions": 2,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 66,
          "url": "https://github.com/kungfu-systems/libnode/pull/66",
          "title": "ci(release): allow promote workflow check updates",
          "body": "Fix the Release - New Version caller permissions for Buildchain v2 promotion.\n\nBuildchain's reusable release-candidate promote workflow requests checks: write. The libnode caller workflow only granted actions/contents/id-token/issues, so GitHub rejected the alpha publish run at startup before any job/log was created.\n\nThis PR only grants checks: write to the caller workflow; it does not change package payload files or the libnode version.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T10:59:15Z",
          "mergedAt": "2026-07-07T11:15:34Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 797,
          "url": "https://github.com/kungfu-systems/buildchain/pull/797",
          "title": "chore(release): sync alpha state after frozen evidence fix",
          "body": "Sync alpha/v2/v2.8 back into dev/v2/v2.8 after the frozen alpha evidence fix landed on dev.\n\nThis preserves alpha ancestry and aligns the dev version-state/site facts with the current alpha state before the next dev -> alpha promotion.\n\nValidation:\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:14:07Z",
          "mergedAt": "2026-07-07T11:16:10Z",
          "additions": 5,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 798,
          "url": "https://github.com/kungfu-systems/buildchain/pull/798",
          "title": "Promote frozen alpha evidence fix to alpha",
          "body": "Promote the stable release frozen alpha evidence fix from dev/v2/v2.8 to alpha/v2/v2.8.\n\nIncludes #796 and the alpha/dev ancestry sync #797.\n\nExpected behavior: alpha promotion should use normal Buildchain release semantics and prepare the next alpha version state without a heavy native rebuild outside the fixture checks.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:16:36Z",
          "mergedAt": "2026-07-07T11:18:52Z",
          "additions": 220,
          "deletions": 67,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 800,
          "url": "https://github.com/kungfu-systems/buildchain/pull/800",
          "title": "chore(release): record release ancestry after frozen evidence fix",
          "body": "Record release/v2/v2.8 as an ancestor of alpha/v2/v2.8 after the frozen alpha evidence fix, without changing the alpha tree.\n\nThis makes the stable promotion PR mergeable while keeping alpha package content unchanged.\n\nValidation:\n- tree diff vs origin/alpha/v2/v2.8 is empty",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:24:41Z",
          "mergedAt": "2026-07-07T11:26:52Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 799,
          "url": "https://github.com/kungfu-systems/buildchain/pull/799",
          "title": "Promote Buildchain v2.8.10 stable",
          "body": "Promote Buildchain v2.8.10 stable after the frozen alpha evidence release finalization fix.\n\nAlpha evidence currently published as @kungfu-tech/buildchain@2.8.10-alpha.2.\n\nExpected behavior: stable promotion should bind to the frozen alpha PR evidence and should not be confused by earlier same-patch alpha tags.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:23:18Z",
          "mergedAt": "2026-07-07T11:32:09Z",
          "additions": 227,
          "deletions": 68,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 355,
          "url": "https://github.com/kungfu-systems/kungfu/pull/355",
          "title": "ci: rename windows frozen cli executable",
          "body": "Fix the Windows artifact build failure seen in alpha PR #354.\n\nWindows Nuitka successfully produced `framework/core/build/kungfu-nuitka/kungfu_cli.dist/kungfu_cli.exe`, but `run-freeze.js` accidentally looked for `kungfu.exe` and renamed it to itself. The artifact build then failed because `framework/core/dist/kungfu/kungfu.exe` was never created.\n\nThis PR renames `kungfu_cli.exe` to `kungfu.exe` on Windows, matching the existing comment and the artifact/runtime expectation.\n\nValidation:\n- `node --check framework/core/.gyp/run-freeze.js`\n- `./kungfu-code exec biome check framework/core/.gyp/run-freeze.js`\n- `./kungfu-code run check:types`\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:37:35Z",
          "mergedAt": "2026-07-07T11:38:14Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 802,
          "url": "https://github.com/kungfu-systems/buildchain/pull/802",
          "title": "fix(release): merge generated next-alpha into diverged dev",
          "body": "## Summary\n- create a generated merge commit when release finalization needs to sync next-alpha state into a diverged dev branch\n- restrict that merge to verified generated version-state file differences\n- add regression coverage for the non-fast-forward dev finalization path\n\n## Verification\n- corepack pnpm@11.7.0 exec node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:40:48Z",
          "mergedAt": "2026-07-07T11:43:13Z",
          "additions": 258,
          "deletions": 60,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 803,
          "url": "https://github.com/kungfu-systems/buildchain/pull/803",
          "title": "chore(release): sync alpha state after dev finalization fix",
          "body": "## Summary\n- merge current alpha/v2/v2.8 state back into dev/v2/v2.8 after the release finalization fix\n- preserve the #802 dev fix while aligning generated version/site state to v2.8.11-alpha.0\n\n## Verification\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:45:38Z",
          "mergedAt": "2026-07-07T11:48:00Z",
          "additions": 5,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 804,
          "url": "https://github.com/kungfu-systems/buildchain/pull/804",
          "title": "Promote dev finalization fix to alpha",
          "body": "## Summary\n- promote the release finalization dev-merge fix to alpha\n- carries the synced v2.8.11-alpha.0 state forward so the promotion can publish the next alpha with the fix\n\n## Verification\n- dev/v2/v2.8 Verify is running from the merged sync head\n- PR checks must pass before merge",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:48:26Z",
          "mergedAt": "2026-07-07T11:50:53Z",
          "additions": 262,
          "deletions": 70,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 806,
          "url": "https://github.com/kungfu-systems/buildchain/pull/806",
          "title": "chore(release): record release ancestry after v2.8.11 alpha",
          "body": "## Summary\n- record release/v2/v2.8 ancestry on alpha/v2/v2.8 without changing the alpha tree\n- uses a policy-compliant generated version-state branch suffix\n\n## Verification\n- git diff origin/alpha/v2/v2.8..44e085aa731f161b9487da1bf4c7aae50cbfb9f8 is empty\n- release/v2/v2.8 is an ancestor of 44e085aa731f161b9487da1bf4c7aae50cbfb9f8",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:59:19Z",
          "mergedAt": "2026-07-07T12:01:18Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 67,
          "url": "https://github.com/kungfu-systems/libnode/pull/67",
          "title": "release(alpha): publish 22.22.3-kf.3-alpha.13",
          "body": "Promote dev/v22/v22.22 to alpha/v22/v22.22 after fixing the Release - New Version caller permissions required by Buildchain v2 promotion.\n\nThis is still @kungfu-tech/libnode 22.22.3-kf.3-alpha.13. The extra PR/build is caused by the previous alpha push failing at GitHub workflow startup because the caller workflow lacked checks: write for the Buildchain promote reusable workflow.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T11:15:57Z",
          "mergedAt": "2026-07-07T12:01:47Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 62,
          "url": "https://github.com/kungfu-systems/libnode/pull/62",
          "title": "Prepare v22.22.1-alpha.5",
          "body": "Create the generated version-state commit for v22.22.1-alpha.5.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T03:35:33Z",
          "mergedAt": "2026-07-07T12:03:33Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 807,
          "url": "https://github.com/kungfu-systems/buildchain/pull/807",
          "title": "Promote Buildchain v2.8.11 stable",
          "body": "Promote Buildchain v2.8.11 stable with release finalization recovery for diverged dev next-alpha bookkeeping.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:02:49Z",
          "mergedAt": "2026-07-07T12:06:12Z",
          "additions": 269,
          "deletions": 71,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 357,
          "url": "https://github.com/kungfu-systems/kungfu/pull/357",
          "title": "ci: run buildchain windows lifecycle on pinned node",
          "body": "## Summary\n- run Windows Buildchain lifecycle pnpm commands through `fnm exec` when available\n- keep fallback to `corepack.cmd pnpm` for environments without fnm\n\n## Why\nWindows Buildchain was invoking pnpm with the Actions runtime Node, so `scripts/verify.mjs` failed the pinned `.node-version` check even though the artifact build had completed.\n\n## Verification\n- `node --check scripts/buildchain-run-kungfu-code.mjs`\n- `./kungfu-code exec biome check scripts/buildchain-run-kungfu-code.mjs`\n- `./kungfu-code run check:types`\n- `git diff --check`\n- DARKHERO smoke: `fnm exec -- node -p process.version` -> `v22.22.3`; `fnm exec -- corepack.cmd pnpm --version` -> `11.7.0`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:15:03Z",
          "mergedAt": "2026-07-07T12:15:40Z",
          "additions": 25,
          "deletions": 6,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 810,
          "url": "https://github.com/kungfu-systems/buildchain/pull/810",
          "title": "fix(release): compare generated version-state trees",
          "body": "Fix release finalization after stable publish by validating generated version-state updates with final tree snapshots instead of PR-style compare history. This prevents already-equivalent code changes from blocking the dev next-alpha bookkeeping merge after protected branches diverge.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:14:59Z",
          "mergedAt": "2026-07-07T12:17:01Z",
          "additions": 169,
          "deletions": 81,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 811,
          "url": "https://github.com/kungfu-systems/buildchain/pull/811",
          "title": "chore(release): sync alpha state after tree-diff fix",
          "body": "Sync the generated alpha/release version-state back into dev after the v2.8.11 post-publish finalization failure, while preserving the tree-diff finalization fix already merged to dev.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:19:48Z",
          "mergedAt": "2026-07-07T12:21:49Z",
          "additions": 15,
          "deletions": 9,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 812,
          "url": "https://github.com/kungfu-systems/buildchain/pull/812",
          "title": "Promote tree-diff release finalization fix to alpha",
          "body": "Promote the release finalization tree-diff fix to alpha after syncing the v2.8.12 alpha state back into dev.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:23:30Z",
          "mergedAt": "2026-07-07T12:25:17Z",
          "additions": 169,
          "deletions": 81,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 69,
          "url": "https://github.com/kungfu-systems/libnode/pull/69",
          "title": "ci(release): refresh KFD workflow witness hash",
          "body": "Refresh the KFD-1 release-workflow surface digest after adding checks: write to Release - New Version.\n\nThe previous alpha promote reached KFD-1 finalization and failed because the release workflow byte-for-byte digest in .buildchain/kfd-1/libnode-contract-world.witness.json still pointed at the pre-permission-fix workflow content.\n\nThis PR only updates the KFD-1 witness hash; it does not change package payload files or the libnode version.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:07:19Z",
          "mergedAt": "2026-07-07T12:25:35Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 359,
          "url": "https://github.com/kungfu-systems/kungfu/pull/359",
          "title": "chore: merge applicable feature backlog",
          "body": "## Summary\n- add the KFD-2 release claims registry and generator\n- carry forward the KFD-3 collaboration-interface design docs\n- add runner smoke workflows for the three self-hosted hosts and v4 labels\n- keep boto3 out of the frozen runtime exclusion path\n\n## Notes\n- older agent onboarding, fact bridge, and kfx distribution feature branches are already covered by the current dev/v4 implementation, so their stale patches were not reapplied\n- v2.4 release-verify runner patches were not applied because dev/v4 delegates product builds to the Buildchain workflow preset\n\n## Verification\n- node scripts/kfd2-release-claims.mjs --check\n- node --check scripts/kfd2-release-claims.mjs\n- node --check scripts/verify.mjs\n- node --check scripts/no-bash-guard.mjs\n- python3 -m py_compile framework/core/src/python/kungfu/yijinjing/journal.py framework/core/src/python/kungfu_cli.py\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:29:36Z",
          "mergedAt": "2026-07-07T12:30:37Z",
          "additions": 1337,
          "deletions": 15,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 813,
          "url": "https://github.com/kungfu-systems/buildchain/pull/813",
          "title": "chore(release): record release ancestry after v2.8.12 alpha",
          "body": "Record release/v2/v2.8 ancestry on alpha/v2/v2.8 before stable promotion, without changing the alpha tree.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:29:35Z",
          "mergedAt": "2026-07-07T12:31:14Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 360,
          "url": "https://github.com/kungfu-systems/kungfu/pull/360",
          "title": "ci: tolerate windows uv mountpoint mypy probe",
          "body": "## Summary\n- keep running the mypy probe in `verify`\n- on Windows only, skip that probe when uv fails interpreter discovery with `os error 448`\n- preserve failure for all other mypy/uv errors\n\n## Why\nAfter the Windows lifecycle was moved onto the repo-pinned Node, the remaining Windows verify failure is uv interpreter discovery hitting a runner mount-point error, not a type-check failure. Linux/macOS continue to gate mypy normally.\n\n## Verification\n- `node --check scripts/verify.mjs`\n- `./kungfu-code exec biome check scripts/verify.mjs`\n- `./kungfu-code run check:types`\n- `git diff --check`\n- DARKHERO rerun evidence before this patch: pinned Node passed; only `python type check` failed with `os error 448`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:33:21Z",
          "mergedAt": "2026-07-07T12:33:59Z",
          "additions": 17,
          "deletions": 6,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 814,
          "url": "https://github.com/kungfu-systems/buildchain/pull/814",
          "title": "Promote Buildchain v2.8.12 stable",
          "body": "Promote Buildchain v2.8.12 stable with the release finalization tree-diff fix.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:32:36Z",
          "mergedAt": "2026-07-07T12:36:24Z",
          "additions": 180,
          "deletions": 92,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 71,
          "url": "https://github.com/kungfu-systems/libnode/pull/71",
          "title": "release(alpha): publish 22.22.3-kf.3-alpha.13",
          "body": "Promote dev/v22/v22.22 to alpha/v22/v22.22 after refreshing the KFD-1 release-workflow witness hash.\n\nThis is still @kungfu-tech/libnode 22.22.3-kf.3-alpha.13. The previous promote reached KFD-1 finalization and failed because the release workflow digest in the KFD-1 witness still pointed at the pre-checks-permission workflow content.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:26:01Z",
          "mergedAt": "2026-07-07T12:47:05Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 815,
          "url": "https://github.com/kungfu-systems/buildchain/pull/815",
          "title": "fix(release): preserve release ancestry in next alpha",
          "body": "Make release finalization prepare next-alpha from the finalized release commit and automatically create a generated alpha merge when protected alpha cannot fast-forward. This prevents the next stable release from needing a manual ancestry repair PR after every release.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:44:18Z",
          "mergedAt": "2026-07-07T12:47:25Z",
          "additions": 188,
          "deletions": 64,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 817,
          "url": "https://github.com/kungfu-systems/buildchain/pull/817",
          "title": "Promote next-alpha ancestry fix to alpha",
          "body": "Promote the release finalization next-alpha ancestry fix to alpha.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:48:29Z",
          "mergedAt": "2026-07-07T12:50:30Z",
          "additions": 188,
          "deletions": 64,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 819,
          "url": "https://github.com/kungfu-systems/buildchain/pull/819",
          "title": "chore(release): record release ancestry after v2.8.13 alpha",
          "body": "Record release/v2/v2.8 ancestry on alpha/v2/v2.8 before stable promotion, without changing the alpha tree.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:56:29Z",
          "mergedAt": "2026-07-07T13:00:38Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 362,
          "url": "https://github.com/kungfu-systems/kungfu/pull/362",
          "title": "ci: force windows lifecycle scripts onto pinned node",
          "body": "## Summary\\n- resolve the fnm-pinned Windows node executable before running pnpm\\n- prepend a temporary node.cmd shim so pnpm lifecycle scripts inherit Node 22\\n- export npm_node_execpath/NODE for child tooling\\n\\n## Validation\\n- node --check scripts/buildchain-run-kungfu-code.mjs\\n- ./kungfu-code exec biome check scripts/buildchain-run-kungfu-code.mjs\\n- ./kungfu-code run check:types\\n- git diff --check\\n- DARKHERO targeted smoke: node and corepack.cmd pnpm exec node both report v22.22.3\\n- DARKHERO targeted verify: corepack.cmd pnpm run verify passes 22/22 with node version pinned v22.22.3",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:01:09Z",
          "mergedAt": "2026-07-07T13:01:46Z",
          "additions": 56,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 820,
          "url": "https://github.com/kungfu-systems/buildchain/pull/820",
          "title": "Promote Buildchain v2.8.13 stable",
          "body": "Promote Buildchain v2.8.13 stable with next-alpha release ancestry preservation and custom KFD badges.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:04:19Z",
          "mergedAt": "2026-07-07T13:06:29Z",
          "additions": 199,
          "deletions": 75,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 74,
          "url": "https://github.com/kungfu-systems/libnode/pull/74",
          "title": "chore(release): bump libnode alpha to 14",
          "body": "Bump @kungfu-tech/libnode to 22.22.3-kf.3-alpha.14 after the alpha.13 promote partially published npm packages but failed before GitHub Release/passport finalization due to release transaction identity mismatch.\n\nThis updates:\n- package.json version\n- libnode.release.json npmVersion\n- KFD-3 prebuild sourceRegistry version\n- KFD-1 source surface hashes for package/release/prebuild witness\n\nLocal checks:\n- corepack pnpm verify-release\n- JSON parse for KFD declarations\n- KFD-1 source hash consistency check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T12:50:29Z",
          "mergedAt": "2026-07-07T13:09:41Z",
          "additions": 11,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 822,
          "url": "https://github.com/kungfu-systems/buildchain/pull/822",
          "title": "fix(release): skip release assets for prepare-only alpha tags",
          "body": "Allow Binary Distribution to pass for prepare-only next-alpha tags when no durable release-state exists, while keeping stable and published prerelease tags fail-closed.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:13:37Z",
          "mergedAt": "2026-07-07T13:15:41Z",
          "additions": 12,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 823,
          "url": "https://github.com/kungfu-systems/buildchain/pull/823",
          "title": "Promote prepare-only alpha binary fix to alpha",
          "body": "Promote the Binary Distribution prepare-only next-alpha release-state handling fix to alpha.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:17:08Z",
          "mergedAt": "2026-07-07T13:19:11Z",
          "additions": 12,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 364,
          "url": "https://github.com/kungfu-systems/kungfu/pull/364",
          "title": "ci: run windows pnpm with pinned node",
          "body": "## Summary\\n- run Windows pnpm through the Corepack JS owned by the fnm-pinned Node installation\\n- keep the temporary node.cmd shim so pnpm lifecycle scripts also resolve node to the pinned runtime\\n- avoid Actions setup-node 24 leaking into process.execPath for artifact packaging\\n\\n## Validation\\n- node --check scripts/buildchain-run-kungfu-code.mjs\\n- ./kungfu-code exec biome check scripts/buildchain-run-kungfu-code.mjs\\n- ./kungfu-code run check:types\\n- git diff --check\\n- DARKHERO mechanism smoke: pinned node runs Corepack JS and pnpm lifecycle script process.execPath resolves to v22.22.3",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:24:15Z",
          "mergedAt": "2026-07-07T13:25:02Z",
          "additions": 22,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 824,
          "url": "https://github.com/kungfu-systems/buildchain/pull/824",
          "title": "Promote Buildchain v2.8.14 stable",
          "body": "Promote Buildchain v2.8.14 stable with prepare-only next-alpha binary distribution handling and custom KFD badges.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:24:38Z",
          "mergedAt": "2026-07-07T13:26:42Z",
          "additions": 23,
          "deletions": 12,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 826,
          "url": "https://github.com/kungfu-systems/buildchain/pull/826",
          "title": "fix(release): skip prepare-only promotion runs",
          "body": "Skip Buildchain Ref Promotion for finalizer generated Prepare v* next-alpha commits so prepare-only dev/alpha Verify runs do not attempt to resolve PR-stage RC evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:34:04Z",
          "mergedAt": "2026-07-07T13:36:27Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 76,
          "url": "https://github.com/kungfu-systems/libnode/pull/76",
          "title": "release(alpha): publish 22.22.3-kf.3-alpha.14",
          "body": "Promote dev/v22/v22.22 to alpha/v22/v22.22 for @kungfu-tech/libnode 22.22.3-kf.3-alpha.14.\n\nThis supersedes alpha.13, which reached npm but failed before GitHub Release/passport finalization because Buildchain selected stale release material and then failed release transaction identity verification after publish.\n\nThis candidate includes refreshed KFD-1 hashes for the alpha.14 package/release/prebuild witness surfaces.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:10:06Z",
          "mergedAt": "2026-07-07T13:40:44Z",
          "additions": 11,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 827,
          "url": "https://github.com/kungfu-systems/buildchain/pull/827",
          "title": "Promote prepare-only promotion skip to alpha",
          "body": "Promote the Buildchain Ref Promotion prepare-only next-alpha skip fix to alpha.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:39:16Z",
          "mergedAt": "2026-07-07T13:41:24Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 366,
          "url": "https://github.com/kungfu-systems/kungfu/pull/366",
          "title": "ci: install windows pinned node in buildchain workspace",
          "body": "## Summary\\n- set Windows FNM_DIR to .buildchain/fnm so Buildchain lifecycle installs Node under the checkout\\n- scan .node-version-based fnm installs across the workspace and Windows users\\n- fail fast on Windows when pinned Node cannot be resolved instead of drifting to Actions Node 24\\n\\n## Validation\\n- node --check scripts/buildchain-run-kungfu-code.mjs\\n- ./kungfu-code exec biome check scripts/buildchain-run-kungfu-code.mjs\\n- ./kungfu-code run check:types\\n- git diff --check\\n- DARKHERO smoke: FNM_DIR=.buildchain/fnm fnm install resolves v22.22.3 under the checkout",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:41:55Z",
          "mergedAt": "2026-07-07T13:42:46Z",
          "additions": 91,
          "deletions": 5,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 828,
          "url": "https://github.com/kungfu-systems/buildchain/pull/828",
          "title": "Promote Buildchain v2.8.15 stable",
          "body": "Promote Buildchain v2.8.15 stable with prepare-only promotion skip and custom KFD badges.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T13:46:32Z",
          "mergedAt": "2026-07-07T13:48:40Z",
          "additions": 12,
          "deletions": 11,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 368,
          "url": "https://github.com/kungfu-systems/kungfu/pull/368",
          "title": "ci: bootstrap windows pinned node without fnm",
          "body": "## Summary\\n- fall back to downloading the .node-version Windows Node zip into .buildchain/node when fnm is unavailable\\n- keep Windows lifecycle fail-fast if pinned Node still cannot be resolved\\n- continue running pnpm through the pinned Node Corepack JS to avoid Actions Node 24 drift\\n\\n## Validation\\n- node --check scripts/buildchain-run-kungfu-code.mjs\\n- ./kungfu-code exec biome check scripts/buildchain-run-kungfu-code.mjs\\n- ./kungfu-code run check:types\\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T14:01:00Z",
          "mergedAt": "2026-07-07T14:01:36Z",
          "additions": 61,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/homebrew-tap",
          "number": 1,
          "url": "https://github.com/kungfu-systems/homebrew-tap/pull/1",
          "title": "feat(tap): track buildchain release passport",
          "body": "## Summary\n\n- Add the public Homebrew tap repository document set.\n- Add Formula/buildchain.rb for Buildchain v2.8.15, bound to upstream release-passport digests.\n- Add tap-manifest.json plus a Buildchain lifecycle verify check to detect formula/passport drift.\n\n## Checks\n\n- node scripts/check-tap.mjs\n- git diff --check\n- ruby -c Formula/buildchain.rb\n- buildchain validate --require-lifecycle-stages verify\n- buildchain lifecycle run verify --required\n\n## Governance\n\n- Does not include credentials, tokens, secrets, or private logs.\n- Touches release evidence/provenance surfaces by adding a Homebrew distribution index bound to upstream release passports.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T14:46:31Z",
          "mergedAt": "2026-07-07T14:47:11Z",
          "additions": 650,
          "deletions": 2,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 829,
          "url": "https://github.com/kungfu-systems/buildchain/pull/829",
          "title": "feat(readme): generate badge facts and blocks",
          "body": "## Summary\n- add @kungfu-tech/buildchain/readme-badges Node API for machine-readable README badge facts, deterministic Markdown rendering, drift checks, and marker-block updates\n- add buildchain badges readme --json/--check/--write CLI and dogfood Buildchain README badges from buildchain.toml plus verified release passport facts\n- document the badge contract and publish it through Buildchain KFD/site registries\n- follow GitHub latest/download redirects when reading release passport JSON\n\n## Verification\n- node bin/buildchain.mjs badges readme --cwd . --check --json\n- node --test tests/readme-badges.test.mjs tests/release-passport.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T14:43:59Z",
          "mergedAt": "2026-07-07T14:48:56Z",
          "additions": 1354,
          "deletions": 107,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 830,
          "url": "https://github.com/kungfu-systems/buildchain/pull/830",
          "title": "release: promote Buildchain v2.8 alpha",
          "body": "## Summary\nPromote dev/v2/v2.8 to alpha/v2/v2.8 after README badge facts/block support landed.\n\n## Dry run\n```\n{\n  \"schemaVersion\": 1,\n  \"dryRun\": true,\n  \"cwd\": \"/Users/dkr/Worktrees/buildchain/feature/readme-badge-block\",\n  \"targetRef\": \"alpha/v2/v2.8\",\n  \"source\": {\n    \"expectedHeadRef\": \"dev/v2/v2.8\",\n    \"sha\": \"6f0e18e70901d264af976d30664c21f687a60fbe\"\n  },\n  \"channel\": \"alpha\",\n  \"line\": \"v2.8\",\n  \"exactTags\": [\n    {\n      \"tag\": \"next v2.8.Z-alpha.N\",\n      \"kind\": \"alpha\",\n      \"action\": \"would create or reuse immutable alpha evidence tag\"\n    }\n  ],\n  \"floatingRefs\": [\n    {\n      \"ref\": \"v2.8-alpha\",\n      \"kind\": \"tag\",\n      \"action\": \"would move to alpha version-state commit\"\n    }\n  ],\n  \"branchUpdates\": [\n    {\n      \"ref\": \"alpha/v2/v2.8\",\n      \"action\": \"would move to alpha version-state commit\"\n    },\n    {\n      \"ref\": \"dev/v2/v2.8\",\n      \"action\": \"would align dev with the published alpha state\"\n    }\n  ],\n  \"versionState\": {\n    \"manager\": \"buildchain.toml\",\n    \"files\": [\n      \"package.json\",\n      \"dist/site/buildchain-contract.json\",\n      \"dist/site/buildchain-site.json\",\n      \"dist/site/site-manifest.json\"\n    ],\n    \"reason\": \"configured-version-files\",\n    \"strategy\": \"semver\",\n    \"next\": \"auto\",\n    \"anchorManifest\": \"\",\n    \"verification\": \"lifecycle.verify\",\n    \"targetVersions\": [\n      \"2.8.Z-alpha.N\"\n    ]\n  },\n  \"governanceChecks\": [\n    \"target branch protection must be readable\",\n    \"branch protection must enforce administrators\",\n    \"required pull request review must be enabled\",\n    \"strict required status check must include the check job\",\n    \"source PR must be a merged same-repository PR from dev/v2/v2.8 to alpha/v2/v2.8\"\n  ],\n  \"publishTransaction\": {\n    \"enabled\": true,\n    \"source\": \"lifecycle.publish\",\n    \"behavior\": \"would create or resume durable release transaction and require publish evidence before public refs move\"\n  },\n  \"notes\": [\n    \"Alpha promotion opens or advances the test channel; it does not move production refs.\"\n  ]\n}\n```",
          "author": "dongkeren",
          "createdAt": "2026-07-07T14:49:57Z",
          "mergedAt": "2026-07-07T14:52:10Z",
          "additions": 1354,
          "deletions": 107,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/homebrew-tap",
          "number": 2,
          "url": "https://github.com/kungfu-systems/homebrew-tap/pull/2",
          "title": "ci(tap): lock Buildchain runtime contract",
          "body": "## Summary\n- add buildchain.contract-lock.json for the accepted Buildchain @v2 runtime contract\n- run tap verification through the Buildchain reusable workflow so the contract lock is checked before lifecycle work\n- keep local tap checks aware of the contract lock\n\n## Verification\n- node scripts/check-tap.mjs\n- Buildchain contract lock check against kungfu-systems/buildchain@v2\n- buildchain validate --require-lifecycle-stages verify\n- buildchain lifecycle run verify --required\n- workflow YAML parse check\n- git diff --check\n\n## Governance\n- No secrets, credentials, provider APIs, hosted services, package names, or release evidence surfaces beyond Buildchain runtime contract lock handling.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T15:10:02Z",
          "mergedAt": "2026-07-07T15:13:33Z",
          "additions": 147,
          "deletions": 15,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 832,
          "url": "https://github.com/kungfu-systems/buildchain/pull/832",
          "title": "feat(homebrew): support distribution index taps",
          "body": "## Summary\n- add first-class Homebrew tap distribution-index support\n- expose @kungfu-tech/buildchain/homebrew Node API and `buildchain homebrew` CLI\n- generate/check Formula/buildchain.rb and tap-manifest.json from upstream release-passport evidence\n- document and include Homebrew support in site/KFD inventories\n\n## Verification\n- git diff --check\n- node --test tests/homebrew.test.mjs tests/buildchain-config.test.mjs tests/release-passport.test.mjs\n- node scripts/generate-site-bundle.mjs --check\n- corepack pnpm@11.7.0 run check\n- dogfood on a temp copy of kungfu-systems/homebrew-tap against Buildchain v2.8.15 release passport: update-formula --write + check --json passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T15:15:21Z",
          "mergedAt": "2026-07-07T15:17:30Z",
          "additions": 1362,
          "deletions": 116,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 834,
          "url": "https://github.com/kungfu-systems/buildchain/pull/834",
          "title": "fix(web-surface): smoke nested preview routes",
          "body": "## Summary\n- sync each web-surface host from its own artifact path prefix when present\n- record surface path-prefix rewrite and directory-index routing evidence in deployment manifests\n- health-check preview/staging/production roots plus nested smoke URLs so child-page 403s fail closed\n\n## Verification\n- node --check scripts/web-surface-core.mjs && node --check scripts/web-surface.mjs\n- node scripts/generate-site-bundle.mjs --check\n- node scripts/check-inventory.mjs\n- env -u GITHUB_OUTPUT node --test tests/web-surface.test.mjs tests/build-surface.test.mjs\n- corepack pnpm@11.7.0 run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T15:26:58Z",
          "mergedAt": "2026-07-07T15:29:00Z",
          "additions": 344,
          "deletions": 29,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 833,
          "url": "https://github.com/kungfu-systems/buildchain/pull/833",
          "title": "release: promote Buildchain v2.8 alpha",
          "body": "## Summary\n- promote dev/v2/v2.8 into alpha/v2/v2.8\n- includes Homebrew tap distribution-index support\n\n## Verification\n- PR #832 checks passed before dev merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T15:17:54Z",
          "mergedAt": "2026-07-07T15:31:00Z",
          "additions": 1704,
          "deletions": 143,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 371,
          "url": "https://github.com/kungfu-systems/kungfu/pull/371",
          "title": "feat(product): isolate dev instance homes for worktrees",
          "body": "## Summary\n- add product dev instance-home handling for GUI and TUI launches\n- auto-select an isolated instance root for linked git worktrees\n- seed instance config from the machine default config once without overwriting test changes\n\n## Tests\n- node --test artifact/scripts/product.test.mjs\n- ./kungfu-code product gui dev --dry-run\n- ./kungfu-code product gui dev --no-instance-home --dry-run\n- ./kungfu-code product tui dev --dry-run\n- ./kungfu-code check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T15:33:06Z",
          "mergedAt": "2026-07-07T15:34:00Z",
          "additions": 493,
          "deletions": 44,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 835,
          "url": "https://github.com/kungfu-systems/buildchain/pull/835",
          "title": "release: promote Buildchain v2.8.16 stable",
          "body": "## Summary\n- promote Buildchain v2.8.16 stable from alpha/v2/v2.8\n- includes Homebrew distribution-index support\n- includes web-surface multi-surface preview prefix routing and nested smoke checks\n\n## Verification\n- alpha promotion succeeded: v2.8.16-alpha.2\n- npm alpha dist-tag points to 2.8.16-alpha.2\n- GitHub alpha release is prerelease and latest=false\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T15:35:29Z",
          "mergedAt": "2026-07-07T15:37:47Z",
          "additions": 2988,
          "deletions": 180,
          "changedFiles": 39
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 372,
          "url": "https://github.com/kungfu-systems/kungfu/pull/372",
          "title": "ci: upload only staged release artifacts",
          "body": "## Summary\n- stage top-level electron-builder outputs from artifact/dist into artifact/release\n- upload artifact/release in the Buildchain reusable build instead of the full artifact/dist tree\n- ignore generated artifact/release locally\n\n## Verification\n- node --check artifact/scripts/dist.mjs\n- ./kungfu-code check\n\n## Risk\n- The Buildchain action scans concrete paths, not glob expressions, so this keeps a directory target while excluding unpacked app directories generated under artifact/dist.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T15:38:56Z",
          "mergedAt": "2026-07-07T15:41:26Z",
          "additions": 46,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/homebrew-tap",
          "number": 3,
          "url": "https://github.com/kungfu-systems/homebrew-tap/pull/3",
          "title": "feat(tap): add tap-local KFD claims",
          "body": "## Summary\n- add tap-local KFD-1, KFD-2, and KFD-3 claim/witness files under kfd/\n- add a witness generator and extend tap verification to reject stale hashes and undeclared control surfaces\n- include KFD artifacts in the Buildchain Tap Check artifact contract\n\n## Verification\n- node scripts/update-kfd-witnesses.mjs\n- node scripts/check-tap.mjs\n- node /Users/dkr/Code/kungfu-systems/buildchain/bin/buildchain.mjs validate --require-lifecycle-stages verify\n- node /Users/dkr/Code/kungfu-systems/buildchain/bin/buildchain.mjs lifecycle run verify --required --artifact-path tap-manifest.json --artifact-path buildchain.contract-lock.json --artifact-path Formula --artifact-path docs --artifact-path kfd --artifact-name homebrew-tap-check --expected-artifacts-json '{\"requiredPaths\":[\"tap-manifest.json\",\"buildchain.contract-lock.json\",\"Formula/buildchain.rb\",\"docs/MAP.md\",\"kfd/kfd-1.witness.json\",\"kfd/kfd-2.release-claims.json\",\"kfd/kfd-3.witness.json\"]}'\n- python3 workflow YAML parse for buildchain-validate.yml and tap-check.yml\n- git diff --check\n\n## Governance\n- No credentials, tokens, secrets, private logs, provider APIs, hosted services, package names, or branding changes.\n- Touches release evidence/provenance surfaces by adding tap-local KFD claims and Buildchain artifact expectations.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T15:40:39Z",
          "mergedAt": "2026-07-07T15:45:04Z",
          "additions": 1612,
          "deletions": 6,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 373,
          "url": "https://github.com/kungfu-systems/kungfu/pull/373",
          "title": "docs(storage): plan runtime storage service",
          "body": "## Summary\n- add a draft runtime storage service design covering fsck, import/export, GC, compact, and projection rebuild\n- link the design from the documentation map\n- document current storage-service limits in known limits\n\n## Validation\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T16:08:18Z",
          "mergedAt": "2026-07-07T16:09:08Z",
          "additions": 268,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 374,
          "url": "https://github.com/kungfu-systems/kungfu/pull/374",
          "title": "ci: remove retired GitHub workflows",
          "body": "## Summary\n- remove retired runner smoke, release handoff, and legacy bump workflows\n- update version/release design pointers to the active Buildchain workflows\n- refresh the verify version-source comment after the release workflow migration\n\n## Validation\n- actionlint .github/workflows/*.yml\n- ./kungfu-code check\n- rg retired workflow names",
          "author": "dongkeren",
          "createdAt": "2026-07-07T16:14:44Z",
          "mergedAt": "2026-07-07T16:15:38Z",
          "additions": 10,
          "deletions": 321,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 836,
          "url": "https://github.com/kungfu-systems/buildchain/pull/836",
          "title": "feat(build): add locked source checkout cache",
          "body": "## Summary\n- add a locked source checkout helper for reusable build jobs with off/auto/require cache modes\n- support trusted mirror URL templates and runner-local reference repository templates with GitHub fallback\n- verify final HEAD and source tree SHA, then record sanitized checkout cache evidence in platform diagnostics\n- dogfood the fallback path in the Build Surface Fixture workflow\n\n## Validation\n- pnpm run check\n- node --test tests/locked-source-checkout.test.mjs\n- node --test tests/build-surface.test.mjs\n- pnpm run check:workflows\n\n## Notes\n- Cache configuration stays in trusted workflow inputs or repo/org variables; it is not read from PR-controlled files.\n- The cache only changes Git object transport. The buildable source remains the resolved publish-source-sha.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T16:14:07Z",
          "mergedAt": "2026-07-07T16:22:30Z",
          "additions": 742,
          "deletions": 60,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 375,
          "url": "https://github.com/kungfu-systems/kungfu/pull/375",
          "title": "feat(atlas): add storage fsck and export",
          "body": "## Summary\n- store complete Atlas source JSON payloads as hash-addressed import payloads alongside the existing Atlas journal projection\n- add Atlas-scoped storage status/fsck/export commands plus atlas verify against the source repo\n- keep build:core dist staging self-contained by copying kungfubuildinfo.json\n\n## Validation\n- PYTHONPATH=framework/core/src/python uv run --project framework/core --frozen pytest framework/core/tests/python/test_atlas_storage.py\n- uv run --project framework/core --frozen ruff check framework/core/src/python/kungfu/atlas/importer.py framework/core/src/python/kungfu/atlas/store.py framework/core/src/python/kungfu/atlas/payloads.py framework/core/src/python/kungfu/cli/commands/atlas.py framework/core/src/python/kungfu/cli/commands/storage.py framework/core/src/python/kungfu/cli/commands/__registry__.py framework/core/tests/python/test_atlas_storage.py\n- uv run --project framework/core --frozen ruff format --check framework/core/src/python/kungfu/atlas/importer.py framework/core/src/python/kungfu/atlas/store.py framework/core/src/python/kungfu/atlas/payloads.py framework/core/src/python/kungfu/cli/commands/atlas.py framework/core/src/python/kungfu/cli/commands/storage.py framework/core/src/python/kungfu/cli/commands/__registry__.py framework/core/tests/python/test_atlas_storage.py\n- ./kungfu-code build:core\n- ./kungfu-code check\n- Atlas dataset smoke with temporary KF_HOME/KF_RUNTIME_DIR: import 5 missions, 371 goals, 895 markers, 1271 payloads; storage fsck ok; export 1271 JSONL records; atlas verify ok\n",
          "author": "dongkeren",
          "createdAt": "2026-07-07T16:34:21Z",
          "mergedAt": "2026-07-07T16:34:52Z",
          "additions": 840,
          "deletions": 29,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 837,
          "url": "https://github.com/kungfu-systems/buildchain/pull/837",
          "title": "fix(readme): derive KFD badges from KFD standards",
          "body": "## Summary\n- derive KFD README badge vocabulary from @kungfu-tech/kfd standards metadata\n- render the repository-owned Buildchain Release Passport badge for the consumer repo passport capability\n- regenerate Buildchain README and site bundle\n\n## Validation\n- node --test tests/readme-badges.test.mjs\n- node scripts/check-inventory.mjs\n- node bin/buildchain.mjs badges readme --check --json\n- pnpm run generate:site\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-07T23:39:03Z",
          "mergedAt": "2026-07-07T23:40:58Z",
          "additions": 295,
          "deletions": 32,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 376,
          "url": "https://github.com/kungfu-systems/kungfu/pull/376",
          "title": "feat(storage): add atlas source sync",
          "body": "## Summary\n- add `kungfu source` commands for registering and syncing read-only Atlas storage sources\n- preserve source id, source type, source head, source time, and range metadata in Atlas payload manifests\n- add range-aware Atlas import/verify and storage export compatibility paths\n- keep parent mission context when a ranged sync selects recent goals\n\n## Validation\n- `PYTHONPATH=/Users/dkr/Worktrees/kungfu/feature/storage-source-adapter/framework/core/src/python pnpm --filter @kungfu-tech/core exec uv run --frozen pytest tests/python/test_atlas_storage.py`\n- `./kungfu-code check`\n- `./kungfu-code build`\n- `pnpm --filter @kungfu-tech/core run freeze`\n- real Atlas smoke with `framework/core/dist/kungfu/kungfu source add/sync/fsck`, `storage fsck`, and `storage export --since 3d` against `/Users/dkr/Code/atlas`",
          "author": "dongkeren",
          "createdAt": "2026-07-07T23:48:38Z",
          "mergedAt": "2026-07-07T23:49:15Z",
          "additions": 722,
          "deletions": 17,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 838,
          "url": "https://github.com/kungfu-systems/buildchain/pull/838",
          "title": "feat(readme): add hosted Buildchain badge endpoints",
          "body": "## Summary\n- generate stable Buildchain-hosted README badge image URLs for KFD and Buildchain Release Passport badges\n- publish badge endpoint registry and Shields-compatible payloads in the Buildchain site bundle for site-libkungfu-dev to render\n- keep future logo replacement endpoint-owned so consumers do not need to rerun badge generation\n- make web-surface nested smoke URLs required only when nested HTML exists\n\n## Validation\n- node --test tests/readme-badges.test.mjs\n- node --test tests/web-surface.test.mjs\n- node scripts/check-inventory.mjs\n- node bin/buildchain.mjs badges readme --check --json\n- pnpm run generate:site\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T00:02:55Z",
          "mergedAt": "2026-07-08T00:06:15Z",
          "additions": 1335,
          "deletions": 61,
          "changedFiles": 51
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 839,
          "url": "https://github.com/kungfu-systems/buildchain/pull/839",
          "title": "chore(release): promote v2.8 alpha",
          "body": "Promote dev/v2/v2.8 to alpha/v2/v2.8 for the next Buildchain v2.8 alpha publication.\n\nThis promotion includes:\n- locked source checkout cache\n- KFD README badge derivation\n- hosted Buildchain badge endpoints\n- web-surface nested smoke behavior for surfaces without nested HTML\n\nBuildchain Ref Promotion will publish the alpha after the alpha branch Verify workflow succeeds.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T00:07:37Z",
          "mergedAt": "2026-07-08T00:09:23Z",
          "additions": 2343,
          "deletions": 124,
          "changedFiles": 61
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 841,
          "url": "https://github.com/kungfu-systems/buildchain/pull/841",
          "title": "chore(release): sync v2.8 alpha state to dev",
          "body": "Sync the generated v2.8.17-alpha.1 version-state commit back into dev/v2/v2.8.\n\nThis branch contains an explicit merge commit with:\n- first parent: dev/v2/v2.8 at a301e0b\n- second parent: alpha/v2/v2.8 at 81e6bc9\n\nThe resolved tree only changes the generated version/site manifest facts:\n- package.json\n- dist/site/buildchain-contract.json\n- dist/site/buildchain-site.json\n- dist/site/site-manifest.json\n\nValidation:\n- node scripts/check-inventory.mjs\n- pnpm run check:site",
          "author": "dongkeren",
          "createdAt": "2026-07-08T00:16:08Z",
          "mergedAt": "2026-07-08T00:18:17Z",
          "additions": 11,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 842,
          "url": "https://github.com/kungfu-systems/buildchain/pull/842",
          "title": "release: promote Buildchain v2.8.17 stable",
          "body": "Promote the tested v2.8 alpha channel to the stable v2.8 release channel.\n\nSource:\n- alpha/v2/v2.8 at v2.8.17-alpha.1\n\nExpected Buildchain promotion behavior after merge:\n- publish @kungfu-tech/buildchain@2.8.17 to npm latest\n- create/update GitHub Release v2.8.17\n- keep v2/v2.8 floating refs on the stable release\n- prepare the next alpha state for the v2.8 line",
          "author": "dongkeren",
          "createdAt": "2026-07-08T00:21:23Z",
          "mergedAt": "2026-07-08T00:23:09Z",
          "additions": 2353,
          "deletions": 134,
          "changedFiles": 62
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 380,
          "url": "https://github.com/kungfu-systems/kungfu/pull/380",
          "title": "docs(storage): describe runtime source sync model",
          "body": "Merge feature/storage-design-consensus into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-08T00:20:12Z",
          "mergedAt": "2026-07-08T00:25:56Z",
          "additions": 153,
          "deletions": 53,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 381,
          "url": "https://github.com/kungfu-systems/kungfu/pull/381",
          "title": "docs(storage): record storage architecture ADRs",
          "body": "## Summary\n- add ADR-0018 for the runtime storage service architecture\n- add ADR-0019 for Git-like source sync over location/channel\n- link the runtime storage service reference page to both ADRs\n\n## Validation\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T00:32:41Z",
          "mergedAt": "2026-07-08T00:33:33Z",
          "additions": 326,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 382,
          "url": "https://github.com/kungfu-systems/kungfu/pull/382",
          "title": "docs(rewind): record action timeline ADR",
          "body": "## Summary\n- add ADR-0020 for the agent action timeline and rewind/replay boundary\n- link event-model, Rewind docs, and the documentation map to the ADR\n\n## Validation\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T00:46:17Z",
          "mergedAt": "2026-07-08T00:47:07Z",
          "additions": 168,
          "deletions": 1,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 843,
          "url": "https://github.com/kungfu-systems/buildchain/pull/843",
          "title": "feat(badges): add trust badge bundle entrypoint",
          "body": "## Summary\n- add a first-class `@kungfu-tech/buildchain/badges` public subpath for badge bundle and README badge APIs\n- add `buildchain badges bundle` for KFD-1/KFD-2/KFD-3/Release Passport trust badge bundles with machine-readable facts\n- document bundle configuration and update generated site facts\n\n## Validation\n- `node --test tests/readme-badges.test.mjs`\n- `node bin/buildchain.mjs badges bundle --claims nope --json` fails closed on unknown claims\n- `pnpm run generate:site`\n- `pnpm run check`",
          "author": "dongkeren",
          "createdAt": "2026-07-08T00:55:23Z",
          "mergedAt": "2026-07-08T00:57:48Z",
          "additions": 453,
          "deletions": 67,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 383,
          "url": "https://github.com/kungfu-systems/kungfu/pull/383",
          "title": "docs(timeline): record observer-relative projection ADR",
          "body": "## Summary\n- add ADR-0021 for observer-relative timeline projection over causal facts\n- route multi-machine timeline questions through the docs map, event model, concepts, and ADR index\n- clarify that trust comes from reproducible facts plus projection policy, not a universal global clock\n\n## Validation\n- git diff --check\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T01:12:28Z",
          "mergedAt": "2026-07-08T01:13:10Z",
          "additions": 194,
          "deletions": 0,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 844,
          "url": "https://github.com/kungfu-systems/buildchain/pull/844",
          "title": "feat(build-facts): add module and product facts",
          "body": "## Summary\n\n- Add first-class Build Facts for Git source, version source, module output, product artifact, and legacy Kungfu buildinfo projection evidence.\n- Expose `@kungfu-tech/buildchain/build-facts`, root API exports, and `buildchain facts module|aggregate|verify`.\n- Let release passports carry build facts through `--build-facts-json`, and register the capability in docs plus the package-owned site bundle.\n- Dogfood Buildchain with declarative `[facts]` config for the core/site-bundle product facts.\n\n## Validation\n\n- `pnpm run check`\n- `node scripts/check-inventory.mjs`\n- `node --test tests/build-facts.test.mjs`\n- `pnpm run check:site`\n- `node bin/buildchain.mjs validate --cwd . --require-version-state --require-lifecycle-stages version-state,verify --json`\n- `node bin/buildchain.mjs facts module --module buildchain-core --output .buildchain/facts/buildchain-core.json --json`\n- `node bin/buildchain.mjs facts aggregate --product buildchain --module-fact .buildchain/facts/buildchain-core.json --output .buildchain/facts/buildchain.json --json`\n- `node bin/buildchain.mjs facts verify --fact .buildchain/facts/buildchain.json --json`",
          "author": "dongkeren",
          "createdAt": "2026-07-08T01:31:33Z",
          "mergedAt": "2026-07-08T01:33:26Z",
          "additions": 1482,
          "deletions": 47,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 384,
          "url": "https://github.com/kungfu-systems/kungfu/pull/384",
          "title": "feat(core): add language-neutral action recorder",
          "body": "Add a C++ action-recording surface in libkungfu, expose thin Python/Node bindings, and document the C++ ownership boundary for future polyglot runtime fact-ledger work.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T01:44:24Z",
          "mergedAt": "2026-07-08T01:46:49Z",
          "additions": 736,
          "deletions": 18,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 845,
          "url": "https://github.com/kungfu-systems/buildchain/pull/845",
          "title": "fix(web-surface): resolve surface root index routes",
          "body": "## Summary\n\n- write directory-index alias objects for web-surface S3 object prefixes during deploy apply\n- cover surface host roots and nested directory index routes such as `/` and `/docs/`\n- document the CloudFront/S3 REST-origin routing behavior and refresh the generated site bundle\n\n## Validation\n\n- `node --test tests/web-surface.test.mjs`\n- `pnpm run check:site`\n- `node scripts/check-inventory.mjs`\n- `pnpm run check:workflows`\n- `pnpm run test:unit`\n\n## Notes\n\nThis does not trigger any consumer repository deployment or heavy build.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T01:52:55Z",
          "mergedAt": "2026-07-08T01:54:49Z",
          "additions": 124,
          "deletions": 30,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 385,
          "url": "https://github.com/kungfu-systems/kungfu/pull/385",
          "title": "ci: lock buildchain contract",
          "body": "## Summary\n- add the Buildchain v2 contract lock accepted by Kungfu\n- wire the reusable build workflow to validate the lock before matrix builds\n- open drift issues for compatible and breaking contract drift\n\n## Validation\n- actionlint .github/workflows/build.yml .github/workflows/buildchain-validate.yml\n- buildchain-contract-lock.mjs check\n- git diff --check\n- jq contract-lock shape check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:02:13Z",
          "mergedAt": "2026-07-08T02:03:57Z",
          "additions": 74,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 83,
          "url": "https://github.com/kungfu-systems/kfd/pull/83",
          "title": "feat(kfd): add observer perspective guideline",
          "body": "## Summary\n- add KFD-4 as the first practice guideline: timelines must declare their observer\n- publish the KFD-4 observer-perspective schema and expose it through registry/standards metadata\n- update KFD self-proof witnesses, site bundle, release impact, and alpha.19 package anchor\n\n## Verification\n- node scripts/check.mjs\n- git diff --check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n\n## Release path\nThis does not publish locally. Alpha publishing should happen through Buildchain channel promotion after this lands on dev/v1/v1.0, then dev/v1/v1.0 -> alpha/v1/v1.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:01:45Z",
          "mergedAt": "2026-07-08T02:04:43Z",
          "additions": 790,
          "deletions": 124,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 85,
          "url": "https://github.com/kungfu-systems/kfd/pull/85",
          "title": "chore(release): promote KFD alpha.19",
          "body": "## Summary\n- promote dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd 1.0.0-alpha.19\n- includes KFD-4 observer perspective guideline and current Buildchain v2 contract lock acceptance\n\n## Release path\nThis is the required Buildchain channel promotion path for KFD alpha publishing:\n\n```text\ndev/v1/v1.0 -> alpha/v1/v1.0\n```\n\nNo local npm publish was performed.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:05:26Z",
          "mergedAt": "2026-07-08T02:06:40Z",
          "additions": 790,
          "deletions": 124,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 846,
          "url": "https://github.com/kungfu-systems/buildchain/pull/846",
          "title": "chore(release): update v2.9 impact metadata",
          "body": "## Summary\n\n- update Buildchain self-promotion release-passport impact metadata for v2.9\n- align inventory contract snippets with the v2.9 release claims\n\n## Validation\n\n- `node scripts/check-inventory.mjs`\n- `pnpm run check:workflows`",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:08:42Z",
          "mergedAt": "2026-07-08T02:13:01Z",
          "additions": 8,
          "deletions": 9,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 386,
          "url": "https://github.com/kungfu-systems/kungfu/pull/386",
          "title": "feat(atlas): record imports as action envelopes",
          "body": "## Summary\n- route Atlas import snapshot writes through the C++ action_recorder binding\n- add action envelopes to Atlas import manifests and fsck journal-frame validation\n- add C++ action_recorder readback smoke plus Atlas import/export/GUI fixture coverage\n\n## Verification\n- PYTHONPATH=src/python uv run --frozen pytest tests/python/test_atlas_storage.py -q\n- node tests/fixtures/atlas-demo-import/run.mjs\n- cmake -S . -B build -DKUNGFU_WITH_SLICES=ON && cmake --build build --config Release --target fact_ledger_action_recorder --parallel 8\n- ./framework/core/build/Release/fact_ledger_action_recorder /tmp/kf-action-recorder.A19XMO 5\n- ./kungfu-code build\n- node tests/fixtures/kfx-demo-work-dashboard-atlas-live/run.mjs\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:16:41Z",
          "mergedAt": "2026-07-08T02:17:53Z",
          "additions": 501,
          "deletions": 22,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 387,
          "url": "https://github.com/kungfu-systems/kungfu/pull/387",
          "title": "docs: manage README badges with buildchain",
          "body": "## Summary\n- replace the hand-maintained README badge set with a Buildchain-managed badge block\n- configure Buildchain badge facts for KFD, release passport, license, platform and workflow badges\n- update Kungfu to @kungfu-tech/buildchain 2.8.17 and refresh the generated SDK canonical policy\n\n## Validation\n- ./kungfu-code check\n- buildchain badges readme --cwd . --check --json\n- buildchain validate --cwd . --require-version-state --require-lifecycle-stages install,build,verify --json\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:20:40Z",
          "mergedAt": "2026-07-08T02:21:33Z",
          "additions": 29,
          "deletions": 13,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 848,
          "url": "https://github.com/kungfu-systems/buildchain/pull/848",
          "title": "chore(release): open v2.9 alpha version state",
          "body": "## Summary\n- set Buildchain version state to 2.9.0-alpha.0 for the v2.9 release line\n- refresh generated site bundle contract and manifest versions\n- keep site bundle timestamp policy ci-injected for public package metadata\n\n## Validation\n- pnpm run check:site\n- node scripts/check-inventory.mjs\n- pnpm run check:workflows\n- pnpm run test:unit\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:20:33Z",
          "mergedAt": "2026-07-08T02:22:27Z",
          "additions": 11,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 849,
          "url": "https://github.com/kungfu-systems/buildchain/pull/849",
          "title": "release: promote Buildchain v2.9 alpha",
          "body": "## Summary\nPromote the Buildchain v2.9 line from dev to alpha.\n\nThis PR carries the reviewed v2.9.0-alpha.0 version state and release-impact metadata. Promotion should publish the alpha prerelease through Buildchain Ref Promotion after Verify succeeds.\n\n## Channel\n- source: dev/v2/v2.9\n- target: alpha/v2/v2.9\n- expected version: 2.9.0-alpha.0",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:22:56Z",
          "mergedAt": "2026-07-08T02:25:04Z",
          "additions": 2049,
          "deletions": 135,
          "changedFiles": 36
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 852,
          "url": "https://github.com/kungfu-systems/buildchain/pull/852",
          "title": "chore(release): sync action bundles for v2.9 promotion",
          "body": "## Summary\n- rebuild checked-in action dist bundles so version-state verification stays limited to configured version files\n- fixes v2.9 alpha promotion failure: action dist changed during verification\n\n## Validation\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:35:43Z",
          "mergedAt": "2026-07-08T02:37:30Z",
          "additions": 122,
          "deletions": 122,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 853,
          "url": "https://github.com/kungfu-systems/buildchain/pull/853",
          "title": "release: promote Buildchain v2.9 alpha bundle fix",
          "body": "## Summary\nPromote the v2.9 action bundle synchronization into alpha so Buildchain Ref Promotion can verify generated version-state trees without action dist drift.\n\n## Channel\n- source: dev/v2/v2.9\n- target: alpha/v2/v2.9\n- includes: #852 action dist synchronization\n- expected version: 2.9.0-alpha.0",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:37:56Z",
          "mergedAt": "2026-07-08T02:40:57Z",
          "additions": 122,
          "deletions": 122,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 854,
          "url": "https://github.com/kungfu-systems/buildchain/pull/854",
          "title": "release: promote Buildchain v2.9",
          "body": "Promote Buildchain v2.9 from alpha to the stable release channel.\n\nEvidence:\n- Alpha promotion succeeded for v2.9.0-alpha.0.\n- npm alpha dist-tag points to 2.9.0-alpha.0 while latest remains 2.8.17.\n- GitHub alpha release is prerelease and includes release passport/evidence assets.\n\nThis PR should trigger the normal release-channel verify gate; after merge, Buildchain Ref Promotion should publish the stable v2.9.0 release.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:44:38Z",
          "mergedAt": "2026-07-08T02:46:19Z",
          "additions": 2171,
          "deletions": 257,
          "changedFiles": 39
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 388,
          "url": "https://github.com/kungfu-systems/kungfu/pull/388",
          "title": "feat(atlas): reset v4 msg type envelope",
          "body": "## Summary\n- reset v4 business facts onto a generic msg_type=1000 action-envelope carrier\n- move Atlas import semantics to action_type/schema_ref metadata\n- update Atlas import/export/fsck/projection tests and msg_type docs\n- make hook installation tolerate locked main-repo .git hooks during worktree builds\n\n## Validation\n- python3 -m py_compile framework/core/src/python/kungfu/atlas/__init__.py framework/core/src/python/kungfu/atlas/payloads.py framework/core/src/python/kungfu/atlas/store.py framework/core/tests/python/test_atlas_storage.py tests/fixtures/atlas-demo-import/check_import.py\n- cd framework/core && PYTHONPATH=src/python uv run --frozen pytest tests/python/test_atlas_storage.py -q\n- ./kungfu-code build\n- ./kungfu-code check\n- node tests/fixtures/atlas-demo-import/run.mjs\n- node tests/fixtures/kfx-demo-work-dashboard-atlas-live/run.mjs\n- cmake/build fact_ledger_action_recorder smoke",
          "author": "dongkeren",
          "createdAt": "2026-07-08T02:52:33Z",
          "mergedAt": "2026-07-08T02:53:55Z",
          "additions": 478,
          "deletions": 267,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 855,
          "url": "https://github.com/kungfu-systems/buildchain/pull/855",
          "title": "fix(web-surface): resolve multi-surface preview roots",
          "body": "## Summary\n- ensure CloudFront default root object is index.html for web-surface S3/CloudFront deploys\n- keep multi-surface preview host roots equivalent to explicit /index.html requests\n- add release-line bootstrap and public surface reverse-audit support for the v2.9 line\n\n## Verification\n- pnpm run check\n- node --test tests/web-surface.test.mjs\n- node --test tests/public-surface-audit.test.mjs\n- node --test tests/cli.test.mjs\n- node scripts/check-inventory.mjs\n- pnpm run check:site\n- pnpm run check:workflows\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T03:42:13Z",
          "mergedAt": "2026-07-08T03:44:41Z",
          "additions": 6647,
          "deletions": 230,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 856,
          "url": "https://github.com/kungfu-systems/buildchain/pull/856",
          "title": "chore(release): promote v2.9 alpha",
          "body": "## Summary\n- promote dev/v2/v2.9 into the alpha channel for the next v2 release\n- carries PR #855 web-surface preview root routing and v2.9 contract updates\n\n## Verification\n- channel PR checks must pass before merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T03:45:33Z",
          "mergedAt": "2026-07-08T03:47:28Z",
          "additions": 6647,
          "deletions": 230,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 389,
          "url": "https://github.com/kungfu-systems/kungfu/pull/389",
          "title": "feat(core): add frame integrity receipts and msg type gate",
          "body": "## Summary\n- add a repository gate that blocks new raw 300xx/400xx msg_type allocations outside reviewed legacy surfaces\n- add action recorder receipt integrity fields for payload and frame checksums\n- verify Atlas import fsck against persisted action frame checksums\n\n## Validation\n- ./kungfu-code verify --full\n- staged pre-commit gate during commit",
          "author": "dongkeren",
          "createdAt": "2026-07-08T03:50:09Z",
          "mergedAt": "2026-07-08T03:50:54Z",
          "additions": 592,
          "deletions": 36,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 857,
          "url": "https://github.com/kungfu-systems/buildchain/pull/857",
          "title": "chore(release): promote v2.9.1",
          "body": "## Summary\n- promote the tested v2.9.1 alpha channel into the stable v2.9 release channel\n- finalizes the v2 floating release after the multi-surface preview root fix\n\n## Verification\n- v2.9.1-alpha.1 promotion completed successfully\n- channel PR checks must pass before merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T03:50:49Z",
          "mergedAt": "2026-07-08T03:52:43Z",
          "additions": 6657,
          "deletions": 240,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 859,
          "url": "https://github.com/kungfu-systems/buildchain/pull/859",
          "title": "feat(kfd): add KFD-3 surface registration",
          "body": "## Summary\n\n- add first-class `buildchain kfd-3 detect/register/audit/witness/query` commands\n- add the public Node API export `@kungfu-tech/buildchain/kfd-3-surfaces`\n- generate KFD/site/manual/CLI/Node registry facts for the new surface and document the KFD-1/2/3 support model\n- cover npm, CLI, wheel-shaped, binary, docs, site bundle, registry, witness, query, and Buildchain self-dogfood paths\n\n## Verification\n\n- `node --test tests/kfd3-surface-register.test.mjs tests/public-surface-audit.test.mjs`\n- `node bin/buildchain.mjs kfd-3 query buildchain --json`\n- `pnpm run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T04:21:02Z",
          "mergedAt": "2026-07-08T04:22:48Z",
          "additions": 1681,
          "deletions": 41,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 390,
          "url": "https://github.com/kungfu-systems/kungfu/pull/390",
          "title": "refactor(core): replace location category with role policy",
          "body": "## Summary\n- replace trading-era yijinjing location category with neutral location_role / role across C++, Python, Node, SDK, and stubs\n- decouple journal page sizing from location role and use a uniform 16 MiB default storage policy\n- document the v4 greenfield decision in ADR-0024\n\n## Validation\n- ./kungfu-code build\n- ./kungfu-code check\n- git diff --check\n- Python enum smoke for location_role\n- kungfu journal --help exposes --role\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T04:24:51Z",
          "mergedAt": "2026-07-08T04:25:46Z",
          "additions": 710,
          "deletions": 595,
          "changedFiles": 57
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 860,
          "url": "https://github.com/kungfu-systems/buildchain/pull/860",
          "title": "fix(web-surface): keep preview apply distribution-free",
          "body": "## Summary\n- stop consumer web-surface apply from mutating shared CloudFront DefaultRootObject\n- keep multi-surface root routing on per-surface S3 directory-index alias objects\n- upload preview/staging/production apply diagnostics artifacts and print failed operation details\n\n## Verification\n- node --test tests/web-surface.test.mjs tests/build-surface.test.mjs\n- pnpm run generate:site\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T04:31:07Z",
          "mergedAt": "2026-07-08T04:33:03Z",
          "additions": 185,
          "deletions": 130,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 858,
          "url": "https://github.com/kungfu-systems/buildchain/pull/858",
          "title": "chore(release): promote v2.10 alpha",
          "body": "Buildchain release line bootstrap opened v2.10. Merge this channel PR to publish the first alpha for the new minor line.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T04:17:46Z",
          "mergedAt": "2026-07-08T04:34:46Z",
          "additions": 2121,
          "deletions": 176,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 861,
          "url": "https://github.com/kungfu-systems/buildchain/pull/861",
          "title": "chore(release): promote v2.10 release",
          "body": "## Summary\n- Promote Buildchain v2.10 release after v2.10.0-alpha.0 validation.\n- Includes KFD-3 surface registration and web-surface preview root diagnostics/routing fix.\n\n## Verification\n- v2.10.0-alpha.0 promotion succeeded\n- PR checks must pass before merge",
          "author": "dongkeren",
          "createdAt": "2026-07-08T04:38:28Z",
          "mergedAt": "2026-07-08T04:40:11Z",
          "additions": 2121,
          "deletions": 176,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 391,
          "url": "https://github.com/kungfu-systems/kungfu/pull/391",
          "title": "refactor(core): move business semantics into envelopes",
          "body": "## Summary\n- rename the low-level journal dispatch field/API from msg_type to carrier_type\n- route Atlas/Rewind/Work/KFX business semantics through kungfu.action-envelope/v1 action_type payloads\n- replace raw 300xx/400xx allocation checks with a carrier/action-envelope gate and ADR-0025\n- update SDK/TUI/journal manager surfaces to expose carrierType transport metadata\n\n## Verification\n- ./kungfu-code check\n- ./kungfu-code build (completed; log ended with [build] complete)\n- python3 -m compileall -q framework/core/src/python/kungfu tests/fixtures\n- node scripts/check-carrier-action-envelope.mjs --all\n- node tests/fixtures/atlas-demo-import/run.mjs\n- node tests/fixtures/work-demo-lifecycle/run.mjs\n- node tests/fixtures/rewind-demo-kfx-schema/run.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T05:14:54Z",
          "mergedAt": "2026-07-08T05:18:21Z",
          "additions": 1595,
          "deletions": 1088,
          "changedFiles": 113
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 392,
          "url": "https://github.com/kungfu-systems/kungfu/pull/392",
          "title": "feat(buildchain): wire Kungfu KFD release evidence",
          "body": "## Summary\n- upgrade Kungfu Buildchain dependency to 2.10.0\n- add root Buildchain KFD evidence generator for KFD-1/2/3 release passport inputs\n- wire release promotion workflow to pass KFD witnesses, claims, and artifact verify command\n- add Buildchain KFD verification to ./kungfu-code verify and document the current KFD flow\n\n## Verification\n- ./kungfu-code kfd:buildchain\n- ./kungfu-code kfd:buildchain:check\n- ./kungfu-code check\n- ./kungfu-code check:types\n- ./kungfu-code verify\n- Buildchain KFD-3 release gate smoke: status=passed, releaseStatus=enforced\n\nNote: ./kungfu-code verify --full reached 27/28 and failed only in existing capability slices build because slice sources reference longfist::enums::category::SYSTEM, which is outside this KFD wiring change.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T05:25:51Z",
          "mergedAt": "2026-07-08T05:27:29Z",
          "additions": 1343,
          "deletions": 63,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 79,
          "url": "https://github.com/kungfu-systems/libnode/pull/79",
          "title": "ci: enable locked checkout cache",
          "body": "## Summary\n- pass Buildchain locked source checkout cache inputs to Build and Release - Verify\n- document the checkout cache and Node source mirror variables\n- set repo variables for the local HTTP mirror path used by self-hosted runners\n\n## Verification\n- python YAML parse for workflow files\n- pnpm exec prettier --check README.md .github/workflows/build.yml .github/workflows/release-verify.yaml\n- git diff --check\n- git ls-remote against local HTTP mirrors for libnode and node tag\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T04:03:10Z",
          "mergedAt": "2026-07-08T05:35:34Z",
          "additions": 81,
          "deletions": 16,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 82,
          "url": "https://github.com/kungfu-systems/libnode/pull/82",
          "title": "release(alpha): publish 22.22.3-kf.3-alpha.15",
          "body": "## Summary\n- include latest dev/v22/v22.22 checkout-cache changes in the alpha channel candidate\n- bump package.json and libnode.release.json to 22.22.3-kf.3-alpha.15\n\n## Verification\n- corepack pnpm verify-release\n- corepack pnpm verify-package-source\n- pnpm pack --dry-run\n- git diff --check\n\nThis PR is the Buildchain publish-gate alpha candidate. The PR build should produce the release-candidate evidence, and the alpha branch promotion should publish through Trusted Publishing.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T05:40:20Z",
          "mergedAt": "2026-07-08T06:02:20Z",
          "additions": 83,
          "deletions": 18,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/homebrew-tap",
          "number": 5,
          "url": "https://github.com/kungfu-systems/homebrew-tap/pull/5",
          "title": "feat(tap): add managed product updater",
          "body": "## Summary\n- add a managed product updater that projects upstream release passports into Homebrew formulae, tap-manifest.json, and compatible Buildchain @v2 contract-lock updates\n- add scheduled/manual Managed Product Updates workflow to open update PRs\n- update tracked Buildchain formula and tap manifest from v2.8.15 to v2.10.0, and refresh the compatible Buildchain @v2 lock\n- classify the new updater and workflow in KFD-1/2/3 witnesses and docs\n\n## Validation\n- node --check scripts/update-managed-products.mjs\n- node --check scripts/update-kfd-witnesses.mjs\n- node --check scripts/check-tap.mjs\n- node scripts/update-managed-products.mjs --check --update-lock --json\n- node scripts/check-tap.mjs\n- actionlint .github/workflows/managed-product-updates.yml .github/workflows/tap-check.yml .github/workflows/buildchain-validate.yml\n- buildchain validate --require-lifecycle-stages verify\n- buildchain lifecycle run verify --required\n- git diff --check\n\n## Notes\n- Buildchain v2.10.0 release passport reports KFD-1/KFD-2/KFD-3 as passed.\n- The Buildchain @v2 compatibility digest is unchanged; only the resolved SHA and contract digest moved.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T05:31:40Z",
          "mergedAt": "2026-07-08T06:43:05Z",
          "additions": 741,
          "deletions": 59,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 863,
          "url": "https://github.com/kungfu-systems/buildchain/pull/863",
          "title": "fix(release): accept publish-gate lineage and rewrite surface roots",
          "body": "## Summary\n\n- accept strict same-line publish-gate/alpha and publish-gate/release PR lineage in promote-buildchain-ref governance checks\n- install a CloudFront viewer-request directory-index rewrite for web-surface deploys so multi-surface preview roots resolve to each surface index.html\n- update release passport impact facts, docs, tests, action bundle, and site bundle projections\n\n## Verification\n\n- node --test tests/promote-buildchain-ref.test.mjs tests/web-surface.test.mjs\n- pnpm run build\n- pnpm run check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/ (confirmed scripts/web-surface-cloudfront-rewrite.mjs is packaged)\n\nFixes #862\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T06:53:23Z",
          "mergedAt": "2026-07-08T06:55:22Z",
          "additions": 480,
          "deletions": 91,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 864,
          "url": "https://github.com/kungfu-systems/buildchain/pull/864",
          "title": "release: promote Buildchain v2.10 alpha",
          "body": "## Summary\n\nPromote the current v2.10 dev line to alpha after fixing publish-gate channel lineage and web-surface preview root routing.\n\n## Included fixes\n\n- #863 accepts same-line publish-gate/alpha and publish-gate/release PR lineage in promote-buildchain-ref\n- #863 installs CloudFront directory-index rewrites for multi-surface web preview roots\n\n## Verification\n\n- dev/v2/v2.10 PR #863 checks passed before merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T06:56:41Z",
          "mergedAt": "2026-07-08T06:58:31Z",
          "additions": 480,
          "deletions": 91,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 393,
          "url": "https://github.com/kungfu-systems/kungfu/pull/393",
          "title": "refactor(core): narrow yijinjing greenfield surface",
          "body": "## Summary\n- remove Python yijinjing typed AllDataTypes helper bindings and narrow stubs to raw carrier/action surfaces\n- rename trading-day restore helpers to neutral session/history window APIs\n- remove trading/market closed-set registries and legacy cache feed helper, leaving explicit legacy refresh debt\n- add ADR-0026 and a yijinjing greenfield guard wired into check/pre-commit\n\n## Validation\n- ./kungfu-code build\n- ./kungfu-code check\n- python3 -m compileall -q framework/core/src/python/kungfu tests/fixtures\n- node scripts/check-yijinjing-greenfield.mjs --all\n- node scripts/check-carrier-action-envelope.mjs --all\n- node framework/core/src/libyijinjing/check-deps.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T06:58:59Z",
          "mergedAt": "2026-07-08T06:59:57Z",
          "additions": 685,
          "deletions": 1773,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 865,
          "url": "https://github.com/kungfu-systems/buildchain/pull/865",
          "title": "release: promote Buildchain v2.10.1 stable",
          "body": "## Summary\n\nPromote Buildchain v2.10.1 from alpha to stable.\n\n## Included fixes\n\n- #862 / #863: promote-buildchain-ref accepts strict same-line publish-gate channel lineage\n- #863: web-surface deploy applies CloudFront directory-index rewrites for multi-surface preview roots\n\n## Alpha evidence\n\n- v2.10.1-alpha.1\n- npm dist-tag alpha = 2.10.1-alpha.1\n- Buildchain Ref Promotion run 28923902125 succeeded\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T07:02:24Z",
          "mergedAt": "2026-07-08T07:04:13Z",
          "additions": 490,
          "deletions": 101,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 394,
          "url": "https://github.com/kungfu-systems/kungfu/pull/394",
          "title": "refactor(core): fence python longfist public types",
          "body": "## Summary\n- add C++ CorePublic*DataTypes registries for Python longfist/types/state/profile bindings\n- stop exposing legacy trading/profile schemas through Python stubs and dispatch bench typed mode\n- document the boundary in ADR-0027 and extend the yijinjing greenfield gate\n\n## Validation\n- ./kungfu-code build\n- node scripts/check-yijinjing-greenfield.mjs --all\n- node scripts/check-carrier-action-envelope.mjs --all\n- node framework/core/src/libyijinjing/check-deps.mjs\n- python3 -m compileall -q framework/core/src/python/kungfu framework/core/tests/bench/dispatch_load.py tests/fixtures\n- git diff --check\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T07:39:12Z",
          "mergedAt": "2026-07-08T07:39:24Z",
          "additions": 245,
          "deletions": 1452,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 395,
          "url": "https://github.com/kungfu-systems/kungfu/pull/395",
          "title": "refactor(core): fence node longfist public registry",
          "body": "## Summary\n- bind Node Longfist public `types` and `carrierTypes` to `CorePublicDataTypes`\n- update the status view wording to show the core registry rather than the legacy compiled registry\n- extend the yijinjing greenfield guard to block public Node binding and CorePublic* registry regressions\n\n## Validation\n- ./kungfu-code build\n- ./kungfu-code check\n- node scripts/check-yijinjing-greenfield.mjs --all\n- node scripts/check-carrier-action-envelope.mjs --all\n- node framework/core/src/libyijinjing/check-deps.mjs\n- git diff --check\n- runtime probe: Longfist public types/carrierTypes expose 27 core entries and no legacy trading/profile entries",
          "author": "dongkeren",
          "createdAt": "2026-07-08T08:02:51Z",
          "mergedAt": "2026-07-08T08:03:05Z",
          "additions": 118,
          "deletions": 12,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 396,
          "url": "https://github.com/kungfu-systems/kungfu/pull/396",
          "title": "refactor(core): name legacy compiled longfist registry",
          "body": "## Summary\n- add explicit LegacyCompiled* registry names for internal compiled longfist compatibility decode paths\n- move journal replay, console, typed dump, rx custom-event detection, and Node Frame typed decode away from direct AllTypes/AllDataTypes names\n- extend greenfield/dependency guards so public bindings and future yijinjing code cannot reintroduce legacy registry coupling\n\n## Validation\n- ./kungfu-code build\n- ./kungfu-code check\n- node scripts/check-carrier-action-envelope.mjs --all\n- node scripts/check-yijinjing-greenfield.mjs --all\n- node framework/core/src/libyijinjing/check-deps.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T08:16:35Z",
          "mergedAt": "2026-07-08T08:16:46Z",
          "additions": 59,
          "deletions": 23,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 867,
          "url": "https://github.com/kungfu-systems/buildchain/pull/867",
          "title": "fix(web-surface): support external directory index rewrites",
          "body": "## Summary\n\n- add declarative `directory_index_rewrite = external` for web-surface deploy channels and surface overrides\n- skip Buildchain-managed CloudFront Function creation when an existing viewer-request router owns directory-index rewrites\n- keep routing evidence and root/nested health checks as the validation contract\n\n## Verification\n\n- `node --test tests/buildchain-config.test.mjs tests/web-surface.test.mjs`\n- `pnpm run check`\n\n## Release\n\nPatch release candidate for v2.10.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T08:16:14Z",
          "mergedAt": "2026-07-08T08:18:11Z",
          "additions": 323,
          "deletions": 126,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 868,
          "url": "https://github.com/kungfu-systems/buildchain/pull/868",
          "title": "chore(release): promote v2.10 dev to alpha",
          "body": "Promote dev/v2/v2.10 to alpha/v2/v2.10 for the external web-surface directory-index rewrite contract fix.\n\nIncluded dev PR:\n- #867 fix(web-surface): support external directory index rewrites",
          "author": "dongkeren",
          "createdAt": "2026-07-08T08:18:38Z",
          "mergedAt": "2026-07-08T08:20:43Z",
          "additions": 323,
          "deletions": 126,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 869,
          "url": "https://github.com/kungfu-systems/buildchain/pull/869",
          "title": "chore(release): promote v2.10.2 to release",
          "body": "Promote alpha/v2/v2.10 to release/v2/v2.10 after successful alpha publish.\n\nAlpha proof:\n- npm alpha: @kungfu-tech/buildchain@2.10.2-alpha.1\n- GitHub Release: v2.10.2-alpha.1\n\nIncluded fix:\n- #867 fix(web-surface): support external directory index rewrites",
          "author": "dongkeren",
          "createdAt": "2026-07-08T08:23:56Z",
          "mergedAt": "2026-07-08T08:25:55Z",
          "additions": 333,
          "deletions": 136,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 85,
          "url": "https://github.com/kungfu-systems/libnode/pull/85",
          "title": "fix: keep KFD witnesses in sync",
          "body": "## Summary\n- add a generated KFD witness sync/check script\n- fail verify when KFD witness JSON is stale\n- refresh KFD-1/KFD-3 witness files for the current release state\n- update the Buildchain v2 contract lock to v2.10.1\n\n## Verification\n- corepack pnpm verify-release\n- corepack pnpm verify-kfd-witnesses\n- corepack pnpm verify-package-source\n- corepack pnpm pack --dry-run\n- npm exec --yes --package @kungfu-tech/buildchain@2.10.1 -- buildchain validate --cwd . --require-version-state --require-lifecycle-stages build,verify\n- local Buildchain KFD-1 passport collect: source/artifact verification passed",
          "author": "dongkeren",
          "createdAt": "2026-07-08T08:02:22Z",
          "mergedAt": "2026-07-08T08:37:27Z",
          "additions": 180,
          "deletions": 13,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 86,
          "url": "https://github.com/kungfu-systems/libnode/pull/86",
          "title": "chore(release): publish libnode 22.22.3-kf.3-alpha.16",
          "body": "## Summary\n- bump libnode alpha version to 22.22.3-kf.3-alpha.16\n- refresh KFD-1 and KFD-3 witness files for the release commit\n\n## Verification\n- corepack pnpm verify-release\n- corepack pnpm verify-kfd-witnesses\n- GITHUB_ACTIONS=true node .gyp/libnode-kfd-witnesses.js check\n- corepack pnpm verify-package-source\n- corepack pnpm pack --dry-run\n- npm exec --yes --package @kungfu-tech/buildchain@2.10.1 -- buildchain validate --cwd . --require-version-state --require-lifecycle-stages build,verify\n- local Buildchain KFD-1 passport collect: source/artifact verification passed",
          "author": "dongkeren",
          "createdAt": "2026-07-08T08:38:58Z",
          "mergedAt": "2026-07-08T09:01:44Z",
          "additions": 182,
          "deletions": 15,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 870,
          "url": "https://github.com/kungfu-systems/buildchain/pull/870",
          "title": "docs(kfd): add capability-based site registry",
          "body": "## Summary\n\n- Add `dist/site/capability-registry.json` as the package-owned capability navigation source for Buildchain KFD-3 surfaces.\n- Add capability metadata to page, manual, CLI, Node API, workflow, and action registries.\n- Remove placeholder CLI purpose text by making command metadata required, and require Node API summaries in inventory checks.\n- Document the capability-first organization in `docs/MAP.md`, `docs/cli.md`, and `docs/site-bundle-contract.md`.\n\n## Validation\n\n- `node scripts/check-inventory.mjs`\n- `pnpm run check:site`\n- `node bin/buildchain.mjs kfd-3 query buildchain --json`\n- `pnpm run check` before reverting an unrelated local action bundle rebuild artifact; 420 unit tests passed.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T09:18:32Z",
          "mergedAt": "2026-07-08T09:20:28Z",
          "additions": 2117,
          "deletions": 187,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 29,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/29",
          "title": "feat(site): publish Buildchain badge endpoints",
          "body": "## Summary\\n- render Buildchain hosted badge endpoint SVG/JSON files from the @kungfu-tech/buildchain site bundle\\n- upgrade the site renderer to consume @kungfu-tech/buildchain 2.8.17\\n- add Buildchain-managed README badges and enforce badge drift checks\\n- refresh the accepted Buildchain v2 contract lock\\n\\n## Verification\\n- pnpm run build\\n- pnpm run check\\n- pnpm exec buildchain badges readme --check\\n\\n## Current release note\\nPreview deploy currently applies the hub surface, but the Buildchain workflow health check still reports 403 for multi-surface preview roots such as buildchain-pr-29.preview.libkungfu.dev/. Explicit /index.html routes are reachable, so this appears to be a Buildchain/CloudFront directory-index routing issue rather than a site artifact generation issue.",
          "author": "dongkeren",
          "createdAt": "2026-07-07T14:54:49Z",
          "mergedAt": "2026-07-08T09:25:18Z",
          "additions": 910,
          "deletions": 76,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 397,
          "url": "https://github.com/kungfu-systems/kungfu/pull/397",
          "title": "refactor(core): remove watcher legacy data path",
          "body": "## Summary\n- remove Watcher legacy trading-data reader/cache/sync path and old command shim exports\n- slim Watcher constructor/config/API to neutral runtime arguments\n- drop LegacyRefreshDataTypes/Tags and update ADR plus bench usage\n\n## Validation\n- ./kungfu-code check\n- ./kungfu-code build\n- git diff --check\n- node --check framework/core/lib/kungfu.js\n- node --check framework/core/tests/bench/dispatch_watcher_bench.js\n- rg residual scan for removed legacy watcher symbols/config names",
          "author": "dongkeren",
          "createdAt": "2026-07-08T09:51:16Z",
          "mergedAt": "2026-07-08T09:51:27Z",
          "additions": 34,
          "deletions": 319,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 871,
          "url": "https://github.com/kungfu-systems/buildchain/pull/871",
          "title": "fix: support managed-network web surface health",
          "body": "## Summary\n- add managed-network web-surface health strategy that validates deploy manifest and S3 object sync evidence instead of requiring public HTTP fetches\n- expose an allowed-runner override for private-network HTTP smoke checks\n- update web-surface docs and generated site bundle\n\n## Validation\n- node --test tests/web-surface.test.mjs\n- node --check scripts/web-surface-core.mjs && node --check scripts/web-surface.mjs\n- pnpm run check:site\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T09:58:24Z",
          "mergedAt": "2026-07-08T10:00:17Z",
          "additions": 182,
          "deletions": 14,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 398,
          "url": "https://github.com/kungfu-systems/kungfu/pull/398",
          "title": "feat(sdk): expose KFD capability queries",
          "body": "## Summary\n- add `kungfu sdk kfd query|check|witness` for SDK-distributed KFD-3 capability facts\n- add installed CLI bridge `kungfu kfd ...` that delegates to the SDK implementation\n- package the generated Buildchain KFD-3 registry under `developer/sdk/kfd/buildchain.kfd3.json` and declare the new surfaces\n- document installed-runtime vs repo-side KFD evidence entrypoints\n\n## Validation\n- `./kungfu-code kfd:buildchain:check`\n- `./kungfu-code check:types`\n- `./kungfu-code check`\n- `node developer/sdk/src/sdk.js kfd query --json`\n- `python3 -m py_compile framework/core/src/python/kungfu/cli/commands/kfd.py`\n- `cd framework/core && uv run --frozen ruff check src/python/kungfu/cli/commands/kfd.py src/python/kungfu/cli/commands/__registry__.py`\n- `cd framework/core && uv run --frozen ruff format --check src/python/kungfu/cli/commands/kfd.py src/python/kungfu/cli/commands/__registry__.py`\n\n## Note\n`./kungfu-code --filter @kungfu-tech/core run dev:kungfu -- kfd query --json` was attempted, but this worktree has no built `pykungfu` native binding, so the dev runtime failed before reaching the new command. The Python file was syntax-checked and ruff-checked; SDK-side KFD query/check/witness is covered by tests.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:02:52Z",
          "mergedAt": "2026-07-08T10:04:48Z",
          "additions": 935,
          "deletions": 3,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 872,
          "url": "https://github.com/kungfu-systems/buildchain/pull/872",
          "title": "fix: verify managed-network web surfaces with s3 heads",
          "body": "## Summary\n- verify managed-network live web-surface health with S3 head-object checks for each surface manifest and smoke target object\n- keep deployment-evidence fallback for dry-run/plan-only health and keep allowed-runner HTTP smoke override\n- update web-surface docs and generated site bundle\n\n## Validation\n- node --test tests/web-surface.test.mjs\n- node --check scripts/web-surface-core.mjs && node --check scripts/web-surface.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:05:11Z",
          "mergedAt": "2026-07-08T10:07:09Z",
          "additions": 144,
          "deletions": 20,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 399,
          "url": "https://github.com/kungfu-systems/kungfu/pull/399",
          "title": "refactor(core): remove trading legacy surface",
          "body": "## Summary\n- narrow longfist compiled registries to the v4 core/runtime surface and remove LegacyCompiled* aliases\n- remove Node trading-era profile store exports and watcher strategy/broker state plumbing\n- remove Python trading/profile enum public bindings and regenerate stubs\n- update greenfield guards and ADRs to block the old surface from returning\n\n## Validation\n- ./kungfu-code check\n- ./kungfu-code build\n- git diff --check\n- node --check framework/core/lib/kungfu.js\n- node --check scripts/check-yijinjing-greenfield.mjs\n- node --check framework/core/src/libyijinjing/check-deps.mjs",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:10:51Z",
          "mergedAt": "2026-07-08T10:11:03Z",
          "additions": 184,
          "deletions": 3810,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 31,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/31",
          "title": "fix(site): render KFD badge endpoints from registry",
          "body": "## Summary\\n- derive missing KFD badge endpoint entries from the pinned @kungfu-tech/kfd registry\\n- generate KFD-4 SVG/JSON badge endpoints for every supported Buildchain badge state\\n- make build and check assertions follow the KFD registry instead of a fixed KFD-1/2/3 list\\n\\n## Verification\\n- pnpm run build\\n- pnpm run check\\n- local static check: /badges/v1/kfd-4/passed.svg and .json return 200",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:08:42Z",
          "mergedAt": "2026-07-08T10:21:37Z",
          "additions": 139,
          "deletions": 7,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 873,
          "url": "https://github.com/kungfu-systems/buildchain/pull/873",
          "title": "chore: include managed-network health in release impact",
          "body": "## Summary\n- update Buildchain release impact metadata to include managed-network web-surface health verification\n\n## Validation\n- node scripts/check-inventory.mjs\n- bash scripts/check-workflows.sh",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:19:57Z",
          "mergedAt": "2026-07-08T10:21:53Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 400,
          "url": "https://github.com/kungfu-systems/kungfu/pull/400",
          "title": "refactor(core): rename libkungfu runtime sources",
          "body": "## Summary\n- move libkungfu implementation sources from src/yijinjing to src/runtime\n- update the libkungfu CMake cache glob to the new runtime path\n- update docs links that referenced the old physical source directory\n\n## Notes\n- public include paths remain <kungfu/yijinjing/...>\n- C++ namespaces remain kungfu::yijinjing\n- Python/Node public APIs are unchanged\n\n## Validation\n- ./kungfu-code check\n- ./kungfu-code build\n- git diff --check\n- rg old src/yijinjing path references",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:22:53Z",
          "mergedAt": "2026-07-08T10:23:05Z",
          "additions": 7,
          "deletions": 6,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 874,
          "url": "https://github.com/kungfu-systems/buildchain/pull/874",
          "title": "chore(release): promote v2.10 managed-network health alpha",
          "body": "Promote dev/v2/v2.10 to alpha for the managed-network web-surface health release.\n\nIncludes:\n- managed-network health without public runner HTTP access\n- live S3 head-object verification for managed-network surface manifests and smoke target objects\n- release impact metadata for the new web-surface health strategy",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:22:38Z",
          "mergedAt": "2026-07-08T10:24:36Z",
          "additions": 2418,
          "deletions": 196,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/homebrew-tap",
          "number": 6,
          "url": "https://github.com/kungfu-systems/homebrew-tap/pull/6",
          "title": "feat(tap): auto-merge managed product updates",
          "body": "## Summary\n- enable GitHub auto-merge for automation-owned managed product update PRs\n- keep auto-merge scoped to the managed updater workflow and automation branch\n- update Buildchain tracking from v2.10.0 to v2.10.2 using the managed updater\n- refresh compatible Buildchain @v2 contract lock and KFD witnesses\n\n## Validation\n- node --check scripts/update-managed-products.mjs\n- node --check scripts/update-kfd-witnesses.mjs\n- node --check scripts/check-tap.mjs\n- node scripts/update-managed-products.mjs --check --update-lock --json\n- node scripts/check-tap.mjs\n- actionlint .github/workflows/managed-product-updates.yml .github/workflows/tap-check.yml .github/workflows/buildchain-validate.yml\n- buildchain validate --require-lifecycle-stages verify\n- buildchain lifecycle run verify --required\n- git diff --check\n\n## Auto-merge boundary\nOnly the managed updater workflow enables auto-merge for its own automation branch after release-passport validation. Non-automation PRs still follow normal review.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:24:18Z",
          "mergedAt": "2026-07-08T10:25:45Z",
          "additions": 97,
          "deletions": 58,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 875,
          "url": "https://github.com/kungfu-systems/buildchain/pull/875",
          "title": "chore(release): promote v2.10.3 stable",
          "body": "Promote Buildchain v2.10.3 from tested alpha to stable release.\n\nAlpha evidence:\n- exact tag: v2.10.3-alpha.1\n- alpha branch: alpha/v2/v2.10\n- npm alpha dist-tag: 2.10.3-alpha.1\n\nRelease includes managed-network web-surface health verification and release impact metadata.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:27:54Z",
          "mergedAt": "2026-07-08T10:29:33Z",
          "additions": 2428,
          "deletions": 206,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 876,
          "url": "https://github.com/kungfu-systems/buildchain/pull/876",
          "title": "feat(badges): discover KFD badge bundle claims from standards",
          "body": "## Summary\n- discover active kfd-* badge specs from @kungfu-tech/kfd standards metadata instead of keeping the bundle fixed to KFD-1/2/3\n- add KFD-4 badge bundle support, README projection, and site badge endpoint registry payloads\n- expose createKfdBadgeSpecsFromStandards for consumers and generated site bundle reuse\n\n## Verification\n- node --test tests/readme-badges.test.mjs\n- node --check packages/core/readme-badges.js && node --check scripts/generate-site-bundle.mjs && node --check scripts/check-inventory.mjs\n- node scripts/check-inventory.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:52:19Z",
          "mergedAt": "2026-07-08T10:54:08Z",
          "additions": 486,
          "deletions": 110,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 32,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/32",
          "title": "chore(site): validate Buildchain 2.10.3 runtime",
          "body": "## Summary\n- upgrade the pinned Buildchain package artifact from 2.10.2 to 2.10.3\n- update site version assertions and docs to the new package version\n- keep existing site-side KFD badge augmentation and buildchain-host badge mirror checks\n\n## Verification\n- pnpm run build\n- pnpm run check\n- git diff --check\n- bash -n scripts/build-site.sh scripts/check-site.sh\n\n## Notes\nThis PR is intended to verify whether Buildchain 2.10.3 fixes the managed-network web-surface health check path during real preview/staging publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T10:42:34Z",
          "mergedAt": "2026-07-08T10:56:08Z",
          "additions": 32,
          "deletions": 14,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 401,
          "url": "https://github.com/kungfu-systems/kungfu/pull/401",
          "title": "feat(sdk): aggregate upstream KFD facts",
          "body": "## Summary\n- aggregate Kungfu SDK KFD facts with upstream KFD-aware dependencies: @kungfu-tech/kfd, @kungfu-tech/libnode, and @kungfu-tech/buildchain\n- upgrade @kungfu-tech/libnode to 22.22.3-kf.3-alpha.16 and @kungfu-tech/kfd to 1.0.0-alpha.17\n- expose installed SDK commands for kfd upstream and aggregate views, and document the generated upstream aggregate artifact\n\n## Validation\n- ./kungfu-code kfd:buildchain:check\n- node --test developer/sdk/tests/contract-cli.test.mjs\n- ./kungfu-code check\n- git diff --check origin/dev/v4/v4.0...HEAD",
          "author": "dongkeren",
          "createdAt": "2026-07-08T11:12:02Z",
          "mergedAt": "2026-07-08T11:13:14Z",
          "additions": 648,
          "deletions": 54,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 877,
          "url": "https://github.com/kungfu-systems/buildchain/pull/877",
          "title": "fix(release): publish anchored packages by public version tag",
          "body": "## Summary\n- use published package versions as the public GitHub Release tag for anchored/manual publish-final-version transactions\n- keep transaction exact tags and release-state refs in the release passport for recovery and audit\n- prefer public package-version GitHub Release passport discovery while keeping explicit internal exact tag fallback\n\n## Verification\n- node --test tests/release-passport.test.mjs tests/promote-buildchain-ref.test.mjs tests/build-surface.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T11:15:16Z",
          "mergedAt": "2026-07-08T11:17:21Z",
          "additions": 327,
          "deletions": 138,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 402,
          "url": "https://github.com/kungfu-systems/kungfu/pull/402",
          "title": "refactor(core): split runtime and storage public APIs",
          "body": "## Summary\n- rename libkungfu runtime-facing public APIs from yijinjing to runtime\n- keep yijinjing as the journal and storage-semantic kernel\n- add yijinjing storage contract headers for source, range, bundle, channel, acceptance, fsck, and providers\n- align the fact-ledger spec, storage service docs, ADR, and embedding smoke with the new boundary\n\n## Validation\n- ./kungfu-code fix\n- ./kungfu-code check\n- ./kungfu-code build\n- node framework/core/src/libyijinjing/check-deps.mjs\n- node framework/core/slices/embedding/run.mjs\n- git diff --check\n\n## Risk\n- pre-release v4 public API rename; no backward compatibility promise for older v4 work-in-progress names",
          "author": "dongkeren",
          "createdAt": "2026-07-08T11:56:42Z",
          "mergedAt": "2026-07-08T11:57:43Z",
          "additions": 1002,
          "deletions": 411,
          "changedFiles": 133
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 403,
          "url": "https://github.com/kungfu-systems/kungfu/pull/403",
          "title": "ci(buildchain): enable locked checkout cache",
          "body": "## Summary\n- pass Buildchain locked source checkout cache inputs to the release-candidate build workflow\n- use repo/org variables for the private local/LAN Git cache template\n- document the private config boundary and sanitized source-checkout diagnostics\n\n## Private config\n- configured kungfu-systems/kungfu repo variable BUILDCHAIN_CHECKOUT_CACHE_MIRROR_URL_TEMPLATE from the matching libnode variable\n- variable value is intentionally not written to repository files\n\n## Validation\n- ruby -e 'require \"yaml\"; YAML.load_file(\".github/workflows/build.yml\")'\n- git diff --check origin/dev/v4/v4.0...HEAD\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T11:59:25Z",
          "mergedAt": "2026-07-08T12:00:01Z",
          "additions": 20,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 878,
          "url": "https://github.com/kungfu-systems/buildchain/pull/878",
          "title": "fix(web-surface): hand off production release PR summary by artifact",
          "body": "## Summary\n- write a compact staging release PR summary JSON after staging apply\n- upload/download that summary as an artifact for the production release PR job\n- keep full staging apply results in diagnostics and stop passing operations/stdout through cross-job env/output\n\n## Verification\n- node --test tests/build-surface.test.mjs\n- bash scripts/check-workflows.sh\n- node scripts/check-inventory.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T11:58:08Z",
          "mergedAt": "2026-07-08T12:00:04Z",
          "additions": 224,
          "deletions": 7,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 879,
          "url": "https://github.com/kungfu-systems/buildchain/pull/879",
          "title": "chore(dev): merge residual feature and fix branches",
          "body": "## Summary\n- Merge all residual feature/fix branches that can be merged cleanly into dev/v2/v2.10.\n- This is a topology cleanup PR: final tree diff versus dev is empty.\n- Branches with actual conflicts are listed as explicitly not directly mergeable.\n\n## Cleanly merged branches\n- fix/binary-distribution-prepare-alpha-passport\n- fix/binary-release-state-base-passport\n- fix/rc-resolver-scan-artifact-runs\n- fix/skip-prepare-next-alpha-promotion\n\n## Conflicted branches not merged\n- feature/alpha-release-latest-alpha-selection\n- feature/kfd-3-collaboration-interface-gate\n- feature/kfd-3-passport-trust-proof\n- feature/local-git-checkout-cache\n- feature/rc-promote-default-workflow\n- feature/rc-promote-feedback\n- feature/rc-promotion-default-head-fallback\n- feature/rc-promotion-default-resolver\n- feature/rc-promotion-runtime-preserve\n- feature/v2-3-promotion-github-read-retry\n- feature/v2-3-release-passport-stable-2-3-1\n- fix/alpha-site-manifest-preserve-ci\n- fix/alpha-transaction-source-mismatch\n- fix/alpha-v2-v2.8-release-propagation-runtime\n- fix/anchored-public-github-release\n- fix/github-release-promote\n- fix/kfd-claims-version-state\n- fix/published-alpha-history-selection\n- fix/readme-badge-logo-placeholder\n- fix/release-finalization-alpha-source\n- fix/release-finalization-frozen-alpha-evidence\n- fix/release-line-v2-v2.0-finalization-source-tree\n- fix/release-next-alpha-ancestry\n- fix/release-next-alpha-dev-finalization\n- fix/release-state-retry-diagnostics\n- fix/semver-github-release\n- fix/site-manifest-preserve-ci-policy\n- fix/site-manifest-timestamp-policy\n- fix/stale-alpha-transaction-selection\n- fix/version-state-pr-fallback-title\n- fix/version-state-pr-lineage\n- fix/version-state-tree-diff\n\n## Verification\n- corepack pnpm@11.7.0 run check\n- git diff --check origin/dev/v2/v2.10..HEAD",
          "author": "dongkeren",
          "createdAt": "2026-07-08T12:05:15Z",
          "mergedAt": "2026-07-08T12:07:08Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 405,
          "url": "https://github.com/kungfu-systems/kungfu/pull/405",
          "title": "refactor(core): split yijinjing platform utilities",
          "body": "## Summary\n- move runtime-only stacktrace, terminal, signal, and Windows AppContainer APIs from libyijinjing into libkungfu runtime\n- keep yijinjing focused on hash and mmap primitives plus journal/storage contracts\n- tighten the yijinjing dependency guard and embedding docs so old util includes cannot return\n\n## Validation\n- ./kungfu-code fix\n- ./kungfu-code check\n- ./kungfu-code build\n- node framework/core/src/libyijinjing/check-deps.mjs\n- node framework/core/slices/embedding/run.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T12:15:10Z",
          "mergedAt": "2026-07-08T12:15:42Z",
          "additions": 235,
          "deletions": 248,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 404,
          "url": "https://github.com/kungfu-systems/kungfu/pull/404",
          "title": "feat(kfd): expose dev metadata in product runs",
          "body": "## Summary\n- inject local KFD registry/upstream aggregate/SDK entry env into `./kungfu-code product gui dev` and `tui dev`\n- keep explicit `KUNGFU_*` overrides authoritative\n- document dev-run KFD bridge behavior\n\n## Validation\n- `node --test artifact/scripts/product.test.mjs`\n- `KUNGFU_KFD3_REGISTRY=... KUNGFU_KFD_UPSTREAM_AGGREGATE=... node developer/sdk/src/sdk.js kfd aggregate --json`\n- `./kungfu-code kfd:buildchain:check`\n- `./kungfu-code check:types`\n- `./kungfu-code check`",
          "author": "dongkeren",
          "createdAt": "2026-07-08T12:15:00Z",
          "mergedAt": "2026-07-08T12:15:49Z",
          "additions": 87,
          "deletions": 1,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 880,
          "url": "https://github.com/kungfu-systems/buildchain/pull/880",
          "title": "chore(release): promote dev v2.10 to alpha",
          "body": "Promote the current dev/v2/v2.10 line to alpha so Buildchain can publish the next v2.10 alpha before stable promotion.\\n\\nIncluded since the previous alpha:\\n- web-surface production release PR handoff compact artifact/file based summary\\n- residual feature/fix branch closeout merged into dev where clean\\n- all active feature/fix branch residue cleaned up\\n\\nThis PR intentionally uses the protected channel PR flow; Buildchain promotion should run after Verify succeeds and the PR is merged.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-08T12:15:29Z",
          "mergedAt": "2026-07-08T12:17:47Z",
          "additions": 1030,
          "deletions": 248,
          "changedFiles": 49
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 881,
          "url": "https://github.com/kungfu-systems/buildchain/pull/881",
          "title": "chore(release): promote v2.10.4 stable",
          "body": "Promote Buildchain v2.10.4 alpha line to stable release.\\n\\nAlpha already published successfully as v2.10.4-alpha.1 from the protected dev→alpha PR flow. This PR should run the release verification checks and, after merge, Buildchain Ref Promotion should publish the stable v2.10.4 release.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T12:21:28Z",
          "mergedAt": "2026-07-08T12:24:12Z",
          "additions": 1040,
          "deletions": 258,
          "changedFiles": 49
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 34,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/34",
          "title": "chore(site): render Buildchain 2.10.4",
          "body": "## Summary\n- upgrade the pinned @kungfu-tech/buildchain package to 2.10.4\n- refresh the generated README badge block for KFD-4\n- update site rendering and validation version guards\n\n## Verification\n- pnpm run build\n- pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T12:35:32Z",
          "mergedAt": "2026-07-08T12:45:13Z",
          "additions": 20,
          "deletions": 24,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 406,
          "url": "https://github.com/kungfu-systems/kungfu/pull/406",
          "title": "feat(kfd): enforce strict buildchain registry mode",
          "body": "## Summary\n- make `buildchain.kfd3.json` the strict Buildchain-default KFD-3 registry for Kungfu\n- add per-surface declaration metadata and a strict registry audit in `scripts/buildchain-kfd-evidence.mjs`\n- expose strict registry metadata through `kungfu sdk kfd check --json` / `kungfu kfd check --json`\n- run `kfd:buildchain:check` from the normal changed-scope/staged check when KFD evidence inputs change\n\n## Validation\n- `./kungfu-code kfd:buildchain`\n- `./kungfu-code kfd:buildchain:check -- --json`\n- `node --test developer/sdk/tests/contract-cli.test.mjs`\n- `node scripts/buildchain-kfd-evidence.mjs --artifact-witness --json`\n- `./kungfu-code check:types`\n- `./kungfu-code check`",
          "author": "dongkeren",
          "createdAt": "2026-07-08T12:45:36Z",
          "mergedAt": "2026-07-08T12:46:15Z",
          "additions": 1000,
          "deletions": 132,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 407,
          "url": "https://github.com/kungfu-systems/kungfu/pull/407",
          "title": "refactor(core): retire longfist schema surface",
          "body": "## Summary\n- move the v4 runtime fact schema into `kungfu/yijinjing/schema` and remove the pre-v4 longfist public package from C++/Python/Node surfaces\n- delete trading-era FlatBuffers schema/codegen and update the C++ probe to compile against yijinjing schema instead\n- update docs and ADRs so v4 is the greenfield schema root, while v4 stable and later remain responsible for v4+ schema compatibility\n\n## Verification\n- `./kungfu-code check`\n- `./kungfu-code build`\n- `node framework/core/src/libyijinjing/check-deps.mjs`\n- `node scripts/check-runtime-greenfield.mjs`\n- `git diff --check`\n",
          "author": "kungfu-origin",
          "createdAt": "2026-07-08T12:46:16Z",
          "mergedAt": "2026-07-08T12:47:04Z",
          "additions": 1116,
          "deletions": 3177,
          "changedFiles": 169
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 882,
          "url": "https://github.com/kungfu-systems/buildchain/pull/882",
          "title": "feat(kfd): unify command namespace",
          "body": "## Summary\n- replace the standalone `buildchain kfd-3` command with the first-class `buildchain kfd` namespace\n- expose `@kungfu-tech/buildchain/kfd` as the unified Node API for KFD 1/2/3/4 schemas and KFD-3 surface helpers\n- regenerate the site bundle, CLI registry, KFD claims, and bundled promote action dist from the new public surface\n\n## Breaking change\n- `buildchain kfd-3 ...` and `@kungfu-tech/buildchain/kfd-3-surfaces` are intentionally removed; consumers should use `buildchain kfd 3 ...` and `@kungfu-tech/buildchain/kfd`\n\n## Validation\n- `corepack pnpm@11.7.0 run check`\n- `node bin/buildchain.mjs kfd schema list --json`\n- `node bin/buildchain.mjs kfd 3 query buildchain --json`\n- verified old `node bin/buildchain.mjs kfd-3 detect` fails closed as unsupported\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T12:55:27Z",
          "mergedAt": "2026-07-08T12:57:32Z",
          "additions": 735,
          "deletions": 253,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 408,
          "url": "https://github.com/kungfu-systems/kungfu/pull/408",
          "title": "feat(core): separate hash integrity surfaces",
          "body": "## Summary\n- rename C++ internal hash helpers to fast_hash_* and document MurmurHash3 as internal-only\n- expose checksum/content hash algorithm constants through C++, Python, and Node surfaces\n- add ADR-0028 plus runtime greenfield gates to prevent future hash taxonomy drift\n\n## Verification\n- ./kungfu-code check\n- ./kungfu-code build\n- node scripts/check-runtime-greenfield.mjs --all\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T13:10:13Z",
          "mergedAt": "2026-07-08T13:11:25Z",
          "additions": 252,
          "deletions": 55,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 36,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/36",
          "title": "fix(site): render channel-aware surface links",
          "body": "## Summary\n- render cross-surface links for the active deployment channel\n- wire workflow builds to production, staging, or preview channel link targets\n- extend site checks to validate production, staging, and preview link targets\n\n## Verification\n- pnpm run build && pnpm run check\n- SITE_SURFACE_CHANNEL=staging pnpm run build && SITE_SURFACE_CHANNEL=staging pnpm run check\n- SITE_SURFACE_CHANNEL=preview SITE_PREVIEW_ALIAS=pr-34 pnpm run build && SITE_SURFACE_CHANNEL=preview SITE_PREVIEW_ALIAS=pr-34 pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T13:14:44Z",
          "mergedAt": "2026-07-08T13:23:46Z",
          "additions": 72,
          "deletions": 16,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 883,
          "url": "https://github.com/kungfu-systems/buildchain/pull/883",
          "title": "feat(kfd): make KFD support first class",
          "body": "## Summary\n- add canonical .buildchain/ repository layout helpers and migrate Buildchain's own config/contract lock into .buildchain/\n- expose first-class buildchain kfd status/migrate-layout plus KFD-1 witness/gate/verify and KFD-2 taxonomy/claims commands and Node APIs\n- keep KFD-4 explicitly schema-only, and update docs plus generated site/KFD facts to reflect the adjusted support model\n\n## Validation\n- node --check bin/buildchain.mjs\n- node --check packages/core/kfd.js\n- node --check packages/core/buildchain-layout.js\n- corepack pnpm@11.7.0 exec node --test tests/buildchain-config.test.mjs tests/buildchain-contract.test.mjs tests/kfd3-surface-register.test.mjs tests/cli.test.mjs\n- corepack pnpm@11.7.0 run check\n- node bin/buildchain.mjs kfd status --json\n- node bin/buildchain.mjs kfd 1 witness --json\n- node bin/buildchain.mjs kfd 2 claims --json\n- node bin/buildchain.mjs kfd 3 query buildchain --json\n- node bin/buildchain.mjs kfd 4 claims (expected schema-only failure)",
          "author": "dongkeren",
          "createdAt": "2026-07-08T13:25:39Z",
          "mergedAt": "2026-07-08T13:28:05Z",
          "additions": 1354,
          "deletions": 297,
          "changedFiles": 45
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 37,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/37",
          "title": "fix(site): render agent surface links per channel",
          "body": "## Summary\n- render KFD alternate links, KFD agent manifest, KFD llms, hub llms, generated site manifest pages, and Buildchain badge route hosts from the active surface channel\n- extend site checks so production, staging, and preview builds verify their own expected hosts\n\n## Verification\n- pnpm run build && pnpm run check\n- SITE_SURFACE_CHANNEL=staging pnpm run build && SITE_SURFACE_CHANNEL=staging pnpm run check\n- SITE_SURFACE_CHANNEL=preview SITE_PREVIEW_ALIAS=pr-37 pnpm run build && SITE_SURFACE_CHANNEL=preview SITE_PREVIEW_ALIAS=pr-37 pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T13:34:27Z",
          "mergedAt": "2026-07-08T13:40:40Z",
          "additions": 74,
          "deletions": 47,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 884,
          "url": "https://github.com/kungfu-systems/buildchain/pull/884",
          "title": "fix(web-surface): degrade production release PR handoff",
          "body": "## Summary\n- make post-staging production release PR handoff permission-aware\n- add production-release-pr-mode, optional PR token, and fail-on-release-pr-error inputs\n- always emit handoff summary/body artifacts and manual gh pr create instructions for permission-denied cases\n\n## Validation\n- node --check scripts/web-surface-production-release-pr.mjs\n- node --test tests/build-surface.test.mjs\n- pnpm run generate:site\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T13:40:33Z",
          "mergedAt": "2026-07-08T13:42:18Z",
          "additions": 452,
          "deletions": 55,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 409,
          "url": "https://github.com/kungfu-systems/kungfu/pull/409",
          "title": "feat(core): add content hash API",
          "body": "Merge feature/content-hash-api into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-08T13:47:12Z",
          "mergedAt": "2026-07-08T13:48:12Z",
          "additions": 566,
          "deletions": 30,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 885,
          "url": "https://github.com/kungfu-systems/buildchain/pull/885",
          "title": "chore(release): promote v2.10.5 alpha",
          "body": "## Summary\n- Promote dev/v2/v2.10 through alpha after PR #884.\n- Source commit: 4814c2ecf48337eb0f9d023049459b74efa78591\n\n## Validation\n- Verify on dev/v2/v2.10 succeeded: https://github.com/kungfu-systems/buildchain/actions/runs/28947287689",
          "author": "dongkeren",
          "createdAt": "2026-07-08T13:46:10Z",
          "mergedAt": "2026-07-08T13:48:15Z",
          "additions": 2476,
          "deletions": 540,
          "changedFiles": 50
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 88,
          "url": "https://github.com/kungfu-systems/kfd/pull/88",
          "title": "feat(kfd): generalize KFD-1 impact core",
          "body": "## Summary\n- promote KFD-1 breaking/additive/none/unclassifiable into a generic compatibility-impact core\n- keep release versioning as the first projection instead of the whole KFD-1 interpretation\n- add KFD-owned `surfaceRegister` metadata in `standards.json`\n- project KFD surface classification and impact projection into the KFD-1 witness from that single fact source\n\n## Dogfood\nKFD now uses `standards.json#/standards/kfd-1/surfaceRegister` as the source of truth for its own registered surfaces. `scripts/update-kfd-1-witness.mjs` projects that register into `.buildchain/kfd-1/contract-world.witness.json`, and `scripts/check.mjs` verifies the projection.\n\n## Verification\n- node scripts/check.mjs\n- git diff --check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n\n## Release note\nThis does not publish locally. It is an additive metadata/schema extension on KFD schemaVersion 1.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T13:51:19Z",
          "mergedAt": "2026-07-08T13:52:35Z",
          "additions": 1378,
          "deletions": 105,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 887,
          "url": "https://github.com/kungfu-systems/buildchain/pull/887",
          "title": "fix(promote): ignore downloaded release candidate evidence",
          "body": "## Summary\n- ignore transient .buildchain/release-candidate evidence in promote-buildchain-ref version-state dirty guard\n- keep other untracked .buildchain files fail-closed\n- rebuild promote action dist\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- pnpm run check\n\n## Release blocker\nFixes the failed alpha promotion run 28947757711 where downloaded PR-stage RC evidence made version verification fail outside version state.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T13:53:57Z",
          "mergedAt": "2026-07-08T13:56:04Z",
          "additions": 35,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 888,
          "url": "https://github.com/kungfu-systems/buildchain/pull/888",
          "title": "chore(release): promote v2.10.5 alpha",
          "body": "## Summary\n- Promote current dev/v2/v2.10 to alpha after PR #884 and release blocker fix #887.\n- Source commit: 984d3a5cbb569da18eb591883b4fc63af4aa9531\n\n## Validation\n- Verify on dev/v2/v2.10 succeeded: https://github.com/kungfu-systems/buildchain/actions/runs/28948223764\n- Fix #887 local validation: pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T13:57:55Z",
          "mergedAt": "2026-07-08T14:00:57Z",
          "additions": 35,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 889,
          "url": "https://github.com/kungfu-systems/buildchain/pull/889",
          "title": "chore(release): promote v2.10.5 stable",
          "body": "## Summary\n- Promote alpha/v2/v2.10 to release/v2/v2.10 for Buildchain v2.10.5.\n- Alpha release completed: v2.10.5-alpha.1\n- Alpha state commit: 657d42573ea0e704ebe2770d61d1410423220605\n\n## Validation\n- Alpha Verify succeeded: https://github.com/kungfu-systems/buildchain/actions/runs/28948554400\n- Alpha Ref Promotion succeeded: https://github.com/kungfu-systems/buildchain/actions/runs/28948634819",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:04:41Z",
          "mergedAt": "2026-07-08T14:08:47Z",
          "additions": 2520,
          "deletions": 550,
          "changedFiles": 52
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 410,
          "url": "https://github.com/kungfu-systems/kungfu/pull/410",
          "title": "feat(frame): add crc32c frame checksum receipts",
          "body": "Implement versioned frame checksum receipts with integrity_version=2 and crc32c, keep v1 fnv1a64 fsck verification, update Python/Node bindings, Atlas import/fsck tests, and ADR-0029.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:12:08Z",
          "mergedAt": "2026-07-08T14:12:14Z",
          "additions": 543,
          "deletions": 55,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 891,
          "url": "https://github.com/kungfu-systems/buildchain/pull/891",
          "title": "fix(promote): ignore generated buildchain evidence",
          "body": "## Summary\n- ignore generated Buildchain KFD and release-passport evidence in promote-buildchain-ref version-state dirty guard\n- keep other untracked .buildchain files fail-closed\n- extend promote action tests and rebuild action bundle\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 run build\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:14:37Z",
          "mergedAt": "2026-07-08T14:16:24Z",
          "additions": 24,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 892,
          "url": "https://github.com/kungfu-systems/buildchain/pull/892",
          "title": "chore(release): promote v2.10.6 alpha",
          "body": "## Summary\n- promote dev/v2/v2.10 to alpha after generated Buildchain evidence dirty-guard fix\n- expected release line: v2.10.6-alpha.1\n\n## Validation\n- PR checks and alpha ref promotion will validate release candidate reuse and publish gates.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:16:45Z",
          "mergedAt": "2026-07-08T14:19:02Z",
          "additions": 24,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 89,
          "url": "https://github.com/kungfu-systems/kfd/pull/89",
          "title": "feat(kfd): generalize KFD-2 trust assessment",
          "body": "## Summary\n- add generic KFD-2 trust-claims and trust-assessment schemas\n- dogfood KFD-2 by assessing KFD-1, KFD-3, and KFD-4 package claims\n- rename authoritative decision files to decisions/KFD-N.md and usage docs to docs/KFD-N-usage.md\n- update standards metadata, witnesses, site bundle, package exports, and release impact\n\n## Verification\n- node scripts/check.mjs\n- git diff --check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:17:45Z",
          "mergedAt": "2026-07-08T14:19:04Z",
          "additions": 2459,
          "deletions": 348,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 895,
          "url": "https://github.com/kungfu-systems/buildchain/pull/895",
          "title": "chore(release): sync v2.10.5 stable ancestry to alpha",
          "body": "## Summary\n- sync release/v2/v2.10 ancestry back into alpha/v2/v2.10 after v2.10.5 finalization\n- keep alpha tree unchanged at v2.10.6-alpha.0\n- unblock v2.10.6 alpha -> release PR clean merge\n\n## Validation\n- tree(HEAD) == tree(origin/alpha/v2/v2.10)\n- origin/release/v2/v2.10 is an ancestor of HEAD\n- origin/alpha/v2/v2.10 is an ancestor of HEAD\n- node --test tests/promote-buildchain-ref.test.mjs",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:26:25Z",
          "mergedAt": "2026-07-08T14:28:14Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 38,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/38",
          "title": "fix(site): render Buildchain badges from latest release",
          "body": "## Summary\n- upgrade @kungfu-tech/buildchain from 2.10.4 to 2.10.5\n- render the Buildchain homepage badge block as markdown image badges instead of escaped README text\n- rewrite Buildchain-hosted badge image URLs to the active surface channel, including staging and preview\n- allow the frozen install step to use the same minimumReleaseAge override as the lockfile update step for fresh Buildchain releases\n\n## Verification\n- pnpm --config.minimumReleaseAge=0 run build && pnpm --config.minimumReleaseAge=0 run check\n- SITE_SURFACE_CHANNEL=staging pnpm --config.minimumReleaseAge=0 run build && SITE_SURFACE_CHANNEL=staging pnpm --config.minimumReleaseAge=0 run check\n- SITE_SURFACE_CHANNEL=preview SITE_PREVIEW_ALIAS=pr-38 pnpm --config.minimumReleaseAge=0 run build && SITE_SURFACE_CHANNEL=preview SITE_PREVIEW_ALIAS=pr-38 pnpm --config.minimumReleaseAge=0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:23:24Z",
          "mergedAt": "2026-07-08T14:29:51Z",
          "additions": 60,
          "deletions": 15,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 893,
          "url": "https://github.com/kungfu-systems/buildchain/pull/893",
          "title": "chore(release): promote v2.10.6 stable",
          "body": "## Summary\n- promote alpha/v2/v2.10 to release/v2/v2.10\n- alpha release: v2.10.6-alpha.0\n- alpha state commit: 0bbabb6688de66d467fed4637541bf01c74632d7\n\n## Evidence\n- Alpha Verify: https://github.com/kungfu-systems/buildchain/actions/runs/28949794016\n- Alpha Ref Promotion: https://github.com/kungfu-systems/buildchain/actions/runs/28949859012\n\n## Expected result\n- publish @kungfu-tech/buildchain@2.10.6\n- move v2 and v2.10 floating tags to the stable release passport commit",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:22:52Z",
          "mergedAt": "2026-07-08T14:30:04Z",
          "additions": 35,
          "deletions": 16,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 91,
          "url": "https://github.com/kungfu-systems/kfd/pull/91",
          "title": "feat(kfd): add KFD-3 trusted value evidence",
          "body": "## Summary\n- add explicit KFD-3 valueEvidence to the collaboration interface and witness schemas\n- dogfood KFD-3 value evidence in the KFD package collaboration interface and generated witnesses\n- link KFD-3 trusted value to the KFD-2 generic trust assessment while preserving the semantic residual-risk warning\n\n## Verification\n- node scripts/check.mjs\n- git diff --check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:29:45Z",
          "mergedAt": "2026-07-08T14:31:01Z",
          "additions": 557,
          "deletions": 98,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 411,
          "url": "https://github.com/kungfu-systems/kungfu/pull/411",
          "title": "feat(storage): add manifest sync root verification",
          "body": "## Summary\n- add manifest-scoped kungfu.sync-root/v1 commitments for Atlas import manifests\n- verify sync roots in storage fsck and expose roots from import/status/export metadata\n- document ADR-0030 and storage-service semantics\n\n## Verification\n- ./kungfu-code fix\n- ./kungfu-code build\n- ./kungfu-code check\n- PYTHONPATH=framework/core/build/Release:framework/core/src/python uv run --project framework/core pytest framework/core/tests/python/test_atlas_storage.py\n- temp Atlas 3d import/fsck/export smoke plus deleted-sync_root failure smoke",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:34:26Z",
          "mergedAt": "2026-07-08T14:34:32Z",
          "additions": 334,
          "deletions": 17,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 92,
          "url": "https://github.com/kungfu-systems/kfd/pull/92",
          "title": "feat(kfd): expose decision usage pages in site bundle",
          "body": "## Summary\n- add `decisionUsagePattern` and `decisionPages.usagePages` to the generated site bundle\n- map every registry decision page `/N` to its usage child page `/N/usage` backed by `docs/KFD-N-usage.md`\n- enforce the mapping in `scripts/check.mjs` and record the additive site-bundle impact\n\n## Verification\n- node scripts/check.mjs\n- git diff --check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:38:21Z",
          "mergedAt": "2026-07-08T14:40:31Z",
          "additions": 194,
          "deletions": 63,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 897,
          "url": "https://github.com/kungfu-systems/buildchain/pull/897",
          "title": "fix(promote): resume published stable finalization",
          "body": "## Summary\n- resume durable stable release transactions even after alpha/dev have advanced to the next alpha\n- keep stable finalization reruns bound to the persisted release-state version and exact tag\n- add regression coverage for published stable finalization after alpha advancement\n\n## Verification\n- node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:43:34Z",
          "mergedAt": "2026-07-08T14:46:15Z",
          "additions": 214,
          "deletions": 61,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 898,
          "url": "https://github.com/kungfu-systems/buildchain/pull/898",
          "title": "chore(release): promote dev to alpha v2.10.7",
          "body": "## Summary\n- Promote the current dev/v2/v2.10 line to alpha after stable finalization resume fix.\n- Expected Buildchain version: v2.10.7-alpha.0.\n\n## Verification\n- PR checks and Buildchain promotion gates.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:47:23Z",
          "mergedAt": "2026-07-08T14:49:10Z",
          "additions": 214,
          "deletions": 61,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 899,
          "url": "https://github.com/kungfu-systems/buildchain/pull/899",
          "title": "chore(release): sync stable ancestry to alpha",
          "body": "## Summary\n- Synchronize release/v2/v2.10 ancestry into alpha/v2/v2.10 before the next stable promotion.\n- Keep the alpha tree unchanged so v2.10.7-alpha.0 remains the candidate material.\n\n## Verification\n- Git merge uses the alpha tree with release/v2/v2.10 as ancestry only.\n- PR checks must pass before merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:53:23Z",
          "mergedAt": "2026-07-08T14:55:28Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 93,
          "url": "https://github.com/kungfu-systems/kfd/pull/93",
          "title": "chore(kfd): anchor alpha 20 version",
          "body": "## Summary\n- bump the anchored KFD npm version from 1.0.0-alpha.19 to 1.0.0-alpha.20\n- regenerate KFD release trust evidence and witnesses for the new package/release-anchor hashes\n\n## Verification\n- node scripts/check.mjs\n- git diff --check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:56:11Z",
          "mergedAt": "2026-07-08T14:58:44Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 94,
          "url": "https://github.com/kungfu-systems/kfd/pull/94",
          "title": "release(kfd): promote alpha 20",
          "body": "## Summary\n- promote dev/v1/v1.0 to alpha/v1/v1.0 for KFD alpha.20\n- publish @kungfu-tech/kfd@1.0.0-alpha.20 via Buildchain trusted publishing\n\n## Verification\n- dev PR #93 checks passed before promotion\n- KFD main workspace fast-forwarded to dev/v1/v1.0 after PR #93\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T14:59:15Z",
          "mergedAt": "2026-07-08T15:00:40Z",
          "additions": 4351,
          "deletions": 377,
          "changedFiles": 37
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 900,
          "url": "https://github.com/kungfu-systems/buildchain/pull/900",
          "title": "chore(release): promote alpha to stable v2.10.7",
          "body": "## Summary\n- Promote the v2.10.7 alpha line to stable.\n- Expected stable version: v2.10.7.\n\n## Verification\n- v2.10.7-alpha.1 published successfully.\n- PR checks and Buildchain release promotion gates.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-08T14:59:04Z",
          "mergedAt": "2026-07-08T15:02:35Z",
          "additions": 225,
          "deletions": 72,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 412,
          "url": "https://github.com/kungfu-systems/kungfu/pull/412",
          "title": "feat(core): switch fast hashing to XXH3",
          "body": "## Summary\\n- replace the runtime fast hash implementation with xxhash/0.8.3 XXH3_64 and XXH3_128\\n- remove the retired pre-v4 hash implementation from active source\\n- expose fast-hash algorithm metadata in Python and Node bindings\\n- add ADR-0031 and fast-hash tests\\n\\n## Validation\\n- ./kungfu-code fix\\n- ./kungfu-code build\\n- ./kungfu-code check\\n- PYTHONPATH=framework/core/build/Release:framework/core/src/python uv run --project framework/core pytest framework/core/tests/python/test_fast_hash.py\\n- node binding smoke for FAST_HASH_ALGORITHM, hash64, and 128-bit hex",
          "author": "dongkeren",
          "createdAt": "2026-07-08T15:02:58Z",
          "mergedAt": "2026-07-08T15:03:04Z",
          "additions": 273,
          "deletions": 487,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 96,
          "url": "https://github.com/kungfu-systems/kfd/pull/96",
          "title": "docs(kfd): clarify KFD-4 gate boundary",
          "body": "## Summary\n- clarify that KFD-4 gates perspective-bearing timeline/history/replay/sync views only\n- separate KFD package interface proof from adopter runtime timeline correctness proof\n- add a compatible optional viewSubject field to the KFD-4 observer-perspective schema\n- refresh KFD-1/2/3 generated evidence and site bundle\n\n## Verification\n- node scripts/check.mjs\n- git diff --check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T15:11:18Z",
          "mergedAt": "2026-07-08T15:12:51Z",
          "additions": 178,
          "deletions": 104,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 98,
          "url": "https://github.com/kungfu-systems/kfd/pull/98",
          "title": "chore(kfd): anchor alpha 21 version",
          "body": "## Summary\n- bump KFD npm/release anchor to 1.0.0-alpha.21\n- refresh generated release trust and witness evidence\n\n## Verification\n- node scripts/check.mjs\n- git diff --check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T15:15:25Z",
          "mergedAt": "2026-07-08T15:16:54Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 99,
          "url": "https://github.com/kungfu-systems/kfd/pull/99",
          "title": "release(kfd): promote alpha 21",
          "body": "## Summary\n- promote dev/v1/v1.0 to alpha/v1/v1.0 for KFD alpha.21\n- publish @kungfu-tech/kfd@1.0.0-alpha.21 via Buildchain trusted publishing\n\n## Verification\n- KFD-4 PR #96 checks passed and merged\n- alpha.21 version anchor PR #98 checks passed and merged\n- KFD main workspace fast-forwarded to dev/v1/v1.0 after PR #98\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T15:17:25Z",
          "mergedAt": "2026-07-08T15:18:58Z",
          "additions": 203,
          "deletions": 129,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 901,
          "url": "https://github.com/kungfu-systems/buildchain/pull/901",
          "title": "fix(web-surface): support release app handoff",
          "body": "## Summary\n- add first-class GitHub App token support for web-surface production release PR handoff\n- upgrade @kungfu-tech/kfd to 1.0.0-alpha.21 and expose foundation KFD-2 trust claims/assessment APIs and CLI commands\n- refresh Buildchain site/KFD facts and tests\n\n## Verification\n- pnpm run check\n- node bin/buildchain.mjs kfd 2 trust-claims --json\n- npm view @kungfu-tech/kfd@alpha version --registry=https://registry.npmjs.org/",
          "author": "dongkeren",
          "createdAt": "2026-07-08T15:22:08Z",
          "mergedAt": "2026-07-08T15:24:12Z",
          "additions": 380,
          "deletions": 52,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 902,
          "url": "https://github.com/kungfu-systems/buildchain/pull/902",
          "title": "release: promote v2.10.8 alpha",
          "body": "## Summary\nPromote dev/v2/v2.10 to alpha for Buildchain v2.10.8.\n\nIncludes:\n- web-surface GitHub App production release PR token support\n- @kungfu-tech/kfd@1.0.0-alpha.21 upgrade\n- first-class KFD-2 foundation trust claims and trust assessment APIs/CLI\n\n## Verification\n- PR #901 checks passed\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T15:24:42Z",
          "mergedAt": "2026-07-08T15:26:27Z",
          "additions": 380,
          "deletions": 52,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 413,
          "url": "https://github.com/kungfu-systems/kungfu/pull/413",
          "title": "feat(kfd): adopt buildchain managed layout",
          "body": "## Summary\n- upgrade @kungfu-tech/buildchain to 2.10.7 across the workspace, SDK, and artifact package\n- migrate Buildchain-owned repo files into .buildchain/ and use .buildchain/kfd/kfd-3-surfaces.json as the KFD-3 source of truth\n- switch Kungfu KFD query code to the Buildchain 2.10.7 kfd namespace and refresh SDK/product KFD projections\n\n## Validation\n- ./kungfu-code sync\n- ./kungfu-code kfd:buildchain -- --json\n- ./kungfu-code kfd:buildchain:check -- --json\n- ./kungfu-code exec buildchain kfd status --json\n- node --test developer/sdk/tests/contract-cli.test.mjs\n- node --test artifact/scripts/product.test.mjs\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T15:26:40Z",
          "mergedAt": "2026-07-08T15:27:37Z",
          "additions": 144,
          "deletions": 104,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 903,
          "url": "https://github.com/kungfu-systems/buildchain/pull/903",
          "title": "release: promote v2.10.8 stable",
          "body": "Promote Buildchain v2.10.8 from alpha to stable.\n\n- Source: alpha/v2/v2.10 at v2.10.8-alpha.1\n- Includes GitHub App production release PR token support in web-surface reusable workflow\n- Includes KFD alpha.21 upgrade with KFD-2 trust claims/assessment APIs and CLI surfaces\n\nValidation before alpha:\n- pnpm run check\n- node --test tests/build-surface.test.mjs\n- node --test tests/kfd3-surface-register.test.mjs\n- buildchain kfd 2 trust-claims --json\n- buildchain kfd 2 trust-assessment --json",
          "author": "dongkeren",
          "createdAt": "2026-07-08T15:31:41Z",
          "mergedAt": "2026-07-08T15:33:48Z",
          "additions": 390,
          "deletions": 62,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 414,
          "url": "https://github.com/kungfu-systems/kungfu/pull/414",
          "title": "feat(storage): move atlas integrity checks into core",
          "body": "## Summary\n- add a C++ yijinjing storage sync-root surface for Atlas import manifests\n- expose runtime bindings for sync-root computation, sync-root verification, and payload reference verification\n- route the Python Atlas storage adapter through the C++ core surface while keeping existing CLI behavior stable\n\n## Validation\n- ./kungfu-code fix\n- ./kungfu-code build\n- PYTHONPATH=framework/core/build/Release:framework/core/src/python uv run --project framework/core pytest framework/core/tests/python/test_atlas_storage.py framework/core/tests/python/test_content_hash.py\n- ./kungfu-code check\n- dogfood: temp KF_HOME/KF_CONFIG_HOME import Atlas last 3 days, storage status/fsck/export, atlas verify; fsck/verify ok, export 156 records\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T15:36:12Z",
          "mergedAt": "2026-07-08T15:37:01Z",
          "additions": 347,
          "deletions": 56,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 415,
          "url": "https://github.com/kungfu-systems/kungfu/pull/415",
          "title": "feat(kfd): expose standard coverage in sdk",
          "body": "## Summary\n- upgrade Buildchain consumers to 2.10.8 and align the KFD metadata package to alpha.21 for KFD-4 schemas\n- add SDK/installed CLI KFD standard entrypoints for KFD-1, KFD-2, and KFD-4 while preserving the existing KFD-3 query behavior\n- regenerate Buildchain KFD evidence and SDK aggregate facts so packaged Kungfu exposes KFD-1/2/3/4 support\n\n## Validation\n- ./kungfu-code sync\n- ./kungfu-code kfd:buildchain -- --json\n- ./kungfu-code kfd:buildchain:check -- --json\n- ./kungfu-code exec buildchain kfd status --json\n- ./kungfu-code exec buildchain kfd 4 schema --json\n- node --test developer/sdk/tests/contract-cli.test.mjs\n- node --test artifact/scripts/product.test.mjs\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T15:59:18Z",
          "mergedAt": "2026-07-08T16:00:08Z",
          "additions": 646,
          "deletions": 73,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 40,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/40",
          "title": "feat(site): render KFD usage pages",
          "body": "## Summary\n- update @kungfu-tech/kfd to 1.0.0-alpha.21 and @kungfu-tech/buildchain to 2.10.8\n- render KFD usage child pages from the KFD site bundle at /kfd/N/usage/ and /N/usage/\n- wire Buildchain production release PR GitHub App inputs into the reusable workflow\n\n## Verification\n- pnpm run build\n- pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T16:09:52Z",
          "mergedAt": "2026-07-08T16:16:37Z",
          "additions": 144,
          "deletions": 27,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 43,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/43",
          "title": "fix(site): clarify KFD usage navigation",
          "body": "## Summary\n- add usage links to KFD decision section navigation\n- only expand the Usage child item in the KFD global nav when the rendered page is a usage page\n- strengthen checks for usage navigation placement and visible Usage sections headings\n\n## Verification\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T22:25:53Z",
          "mergedAt": "2026-07-08T22:30:40Z",
          "additions": 68,
          "deletions": 17,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 416,
          "url": "https://github.com/kungfu-systems/kungfu/pull/416",
          "title": "feat(kfd): complete buildchain kfd 1 2 support",
          "body": "## Summary\n- persist Buildchain KFD-1 witness, release gate, and verify result into .buildchain and the SDK package\n- persist KFD-2 canonical release claims plus per-claim Buildchain projections into .buildchain and the SDK package\n- expose kungfu sdk kfd 1 gate/verify and make kfd 2 claims return the packaged release-claim documents\n- extend KFD evidence checks to cover the new KFD-1/2 files\n\n## Validation\n- ./kungfu-code kfd:buildchain -- --json\n- ./kungfu-code kfd:buildchain:check -- --json\n- node --test developer/sdk/tests/contract-cli.test.mjs\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T22:32:40Z",
          "mergedAt": "2026-07-08T22:33:38Z",
          "additions": 2364,
          "deletions": 19,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 417,
          "url": "https://github.com/kungfu-systems/kungfu/pull/417",
          "title": "feat(storage): add generic source service",
          "body": "## Summary\n- add a C++ generic storage source service for source records, import manifests, accepted ranges, payload/schema inventories, bundle export, and manifest fsck\n- wire Python source/storage services and CLI commands for source-scoped status/fsck/export/import while keeping Atlas compatibility\n- make Atlas sync accept generic storage manifests and mirror payloads into the generic payload store\n- document ADR-0032 and update the runtime storage service plan\n\n## Validation\n- ./kungfu-code fix\n- PYTHONPATH=framework/core/build/Release:framework/core/src/python uv run --project framework/core pytest framework/core/tests/python/test_atlas_storage.py\n- ./kungfu-code check\n- ./kungfu-code build\n- dogfood: source add/sync Atlas last 3 days, storage fsck all, source export jsonl/bundle, bundle import into a second temp runtime, fsck imported source",
          "author": "dongkeren",
          "createdAt": "2026-07-08T22:37:28Z",
          "mergedAt": "2026-07-08T22:37:59Z",
          "additions": 1331,
          "deletions": 54,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 44,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/44",
          "title": "Release production from e0b9ea8351a2",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `e0b9ea8351a2f95bcfde83fabcec61a7c696a872`\n- Artifact hash: `ac8c960f58940b09ec909dd6d948de0d4dd7c2266a4fefac68dc27df83cdec5a`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/28980260526)\n- Required label: `buildchain-release`\n- Release branch: `release/production-e0b9ea8351a2`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-08T22:35:19Z",
          "mergedAt": "2026-07-08T23:01:31Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 418,
          "url": "https://github.com/kungfu-systems/kungfu/pull/418",
          "title": "refactor(kfd): remove legacy kfd 1 2 helpers",
          "body": "## Summary\n- remove unused legacy KFD-1 support summary helper\n- remove unused legacy KFD-2 claim summary helper\n- keep Buildchain-native KFD-1 witness/gate/verify and KFD-2 packaged claims behavior unchanged\n\n## Validation\n- node --check developer/sdk/src/sdk.js\n- node developer/sdk/src/sdk.js kfd 1 witness/gate/verify --json\n- node developer/sdk/src/sdk.js kfd 2 claims --json\n- ./kungfu-code kfd:buildchain:check -- --json\n- node --test developer/sdk/tests/contract-cli.test.mjs\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T23:01:58Z",
          "mergedAt": "2026-07-08T23:02:43Z",
          "additions": 0,
          "deletions": 61,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 904,
          "url": "https://github.com/kungfu-systems/buildchain/pull/904",
          "title": "feat(kfd): aggregate upstream KFD facts",
          "body": "## Summary\n\n- add first-class KFD upstream aggregate collection/check APIs and CLI commands\n- dogfood Buildchain's upstream KFD aggregate with `@kungfu-tech/kfd` as the standard/schema provider\n- export the aggregate through the generated site bundle and KFD claim registry\n- document upstream KFD aggregation and the runtime-dependency boundary for `@kungfu-tech/kfd`\n\n## Dependency note\n\n`@kungfu-tech/kfd` stays in `dependencies`, not `devDependencies`, because Buildchain's runtime KFD surfaces resolve KFD standards/schemas/taxonomy from the package at runtime.\n\n## Verification\n\n- `node --test tests/kfd3-surface-register.test.mjs`\n- `node --test tests/readme-badges.test.mjs`\n- `node bin/buildchain.mjs kfd upstream check --json | jq '{ok,status,issues}'`\n- `corepack pnpm@11.7.0 run check`\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T23:03:03Z",
          "mergedAt": "2026-07-08T23:07:20Z",
          "additions": 888,
          "deletions": 35,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 89,
          "url": "https://github.com/kungfu-systems/libnode/pull/89",
          "title": "chore(release): publish libnode 22.22.3-kf.3-alpha.17",
          "body": "Publish libnode alpha 17 through the Buildchain v2 publish gate.\n\n- Bumps package.json and libnode.release.json to 22.22.3-kf.3-alpha.17\n- Uses the stable Buildchain @v2 workflows already declared in the repository\n- Expects the PR-stage Build workflow to produce the release-candidate artifacts before promotion\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T22:40:20Z",
          "mergedAt": "2026-07-08T23:15:49Z",
          "additions": 16,
          "deletions": 16,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 419,
          "url": "https://github.com/kungfu-systems/kungfu/pull/419",
          "title": "feat(storage): add maintenance sync ops",
          "body": "## Summary\n- add storage maintenance operations for the generic source service: status/fsck expansion, projection rebuild, dry-run gc/compact planning, and local sync verification\n- expose the maintenance surface through `kungfu storage ...` CLI commands and KFD-3 adjacent-agent command metadata\n- document the first safe maintenance/sync-readiness slice in `docs/runtime-storage-service.md`\n\n## Validation\n- `./kungfu-code check`\n- `./kungfu-code build`\n- `./kungfu-code --dir framework/core exec env PYTHONPATH=build/Release:src/python uv run --frozen pytest tests/python/test_atlas_storage.py` (`13 passed`)\n- frozen CLI smoke using `/Users/dkr/Code/atlas` as an Atlas source with `--since 3d`: sync/status/fsck/gc/compact/rebuild-index/verify-sync all passed; sync roots matched\n- `./kungfu-code kfd:buildchain` (`48 KFD-3 surface(s)`)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-08T23:18:52Z",
          "mergedAt": "2026-07-08T23:19:26Z",
          "additions": 1057,
          "deletions": 30,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 906,
          "url": "https://github.com/kungfu-systems/buildchain/pull/906",
          "title": "feat(kfd): infer upstream roles",
          "body": "## Summary\n- make KFD upstream roles Buildchain-managed and inferred from package identity/evidence\n- add `buildchain kfd upstream roles --json` and public Node API registry\n- allow auto-discovery from devDependencies so consumers do not duplicate semver or role facts\n- update KFD docs with first-use guidance for upstream aggregation, dependency placement, optional KFD state hints, and role fail-closed policy\n\n## Verification\n- `node --test tests/kfd3-surface-register.test.mjs tests/public-surface-audit.test.mjs`\n- `corepack pnpm@11.7.0 run generate:site`\n- `corepack pnpm@11.7.0 run check:site`\n- `corepack pnpm@11.7.0 run check`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-08T23:29:46Z",
          "mergedAt": "2026-07-08T23:31:25Z",
          "additions": 446,
          "deletions": 53,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 1,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/1",
          "title": "docs(paper): declare Kungfu Origin publishing identity",
          "body": "## Summary\n\n- declare Kungfu Origin Technology Limited as the paper publishing identity\n- add Keren Dong contact email to README, security, issue contact, and paper author metadata\n- keep kungfu-systems only as the GitHub organization / repository naming surface\n\n## Checks\n\n- [x] make check\n- [x] make pdf\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs.\n- [x] No unpublished reviewer correspondence or private operational data.\n- [x] Provider/API/data claims are sourced or clearly marked as future work.\n- [x] Public branding and trademark language stays factual.",
          "author": "dongkeren",
          "createdAt": "2026-07-08T23:32:17Z",
          "mergedAt": "2026-07-08T23:32:45Z",
          "additions": 25,
          "deletions": 20,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 907,
          "url": "https://github.com/kungfu-systems/buildchain/pull/907",
          "title": "fix(release): create public package release tag",
          "body": "## Summary\n- create the public package GitHub Release tag after release transaction finalization when it differs from the internal exact transaction tag\n- keep internal exact tags unchanged for Buildchain recovery/audit\n- add anchored package test coverage proving v<publishedVersion> is created\n\nFixes #905.\n\n## Verification\n- `node --test tests/promote-buildchain-ref.test.mjs`\n- `corepack pnpm@11.7.0 --filter \"./actions/promote-buildchain-ref\" build`\n- `corepack pnpm@11.7.0 run check`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-08T23:37:16Z",
          "mergedAt": "2026-07-08T23:39:17Z",
          "additions": 58,
          "deletions": 47,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 45,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/45",
          "title": "fix(site): hide KFD machine facts from homepage",
          "body": "## Summary\n- remove KFD machine facts from the human homepage\n- keep KFD source facts in machine-readable manifests\n- align KFD decision card actions so Usage notes sits apart from the read link\n\n## Verification\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-08T23:47:00Z",
          "mergedAt": "2026-07-08T23:58:57Z",
          "additions": 24,
          "deletions": 33,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 420,
          "url": "https://github.com/kungfu-systems/kungfu/pull/420",
          "title": "feat(storage): add runtime service API surface",
          "body": "## Summary\n- Add the libkungfu runtime storage service request/capabilities surface for status, fsck, export, import, rebuild, gc, compact, and sync verification operations.\n- Expose the surface through the Python runtime binding and route the existing Python storage operations through it while preserving the current backend and output schemas.\n- Document the storage layering rule and add tests proving Python storage commands enter the C++ service surface.\n\n## Validation\n- `./kungfu-code fix`\n- `./kungfu-code check`\n- `PYTHONPATH=\"$PWD/src/python:$PWD/build/Release\" DYLD_FALLBACK_LIBRARY_PATH=\"$PWD/build/Release${DYLD_FALLBACK_LIBRARY_PATH:+:$DYLD_FALLBACK_LIBRARY_PATH}\" uv run --frozen pytest tests/python/test_atlas_storage.py` from `framework/core` (`15 passed`)\n- `./kungfu-code build`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T00:01:43Z",
          "mergedAt": "2026-07-09T00:02:23Z",
          "additions": 495,
          "deletions": 1,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 908,
          "url": "https://github.com/kungfu-systems/buildchain/pull/908",
          "title": "chore(release): publish v2.10.9-alpha.1",
          "body": "## Summary\n- Promote current dev/v2/v2.10 into alpha/v2/v2.10.\n- Includes #906 KFD upstream role inference and #907 public package GitHub Release tag creation.\n\n## Release intent\n- Channel: alpha/v2/v2.10\n- Expected next alpha: v2.10.9-alpha.1\n- Stable release will follow through alpha/v2/v2.10 -> release/v2/v2.10 after alpha promotion succeeds.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-09T00:04:46Z",
          "mergedAt": "2026-07-09T00:07:19Z",
          "additions": 1339,
          "deletions": 82,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 46,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/46",
          "title": "Release production from 8652822cbc1e",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `8652822cbc1e002df44ea95ce68be413d978a8d6`\n- Artifact hash: `6200c6b19ef057503ed2f147fb60fc17fe06380b832192dc78f37efcf75f00c3`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/28984087447)\n- Required label: `buildchain-release`\n- Release branch: `release/production-8652822cbc1e`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-09T00:03:30Z",
          "mergedAt": "2026-07-09T00:08:25Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 910,
          "url": "https://github.com/kungfu-systems/buildchain/pull/910",
          "title": "fix(release): include KFD upstream aggregate in version state",
          "body": "## Summary\n- include dist/site/kfd-upstream-aggregate.json in Buildchain's declared version-state files\n- update the version-state contract test so release verification allows the generated KFD upstream aggregate version projection\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs tests/build-surface.test.mjs\n- pnpm run check\n\nFixes the alpha promotion failure in run https://github.com/kungfu-systems/buildchain/actions/runs/28984478250 where version verification rejected dist/site/kfd-upstream-aggregate.json.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T00:14:10Z",
          "mergedAt": "2026-07-09T00:16:05Z",
          "additions": 6,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 912,
          "url": "https://github.com/kungfu-systems/buildchain/pull/912",
          "title": "chore(release): publish v2.10.9-alpha.1",
          "body": "## Summary\n- promote current dev/v2/v2.10 to alpha/v2/v2.10 after fixing version-state verification for the KFD upstream aggregate site fact\n- retries the alpha release that previously failed in Buildchain Ref Promotion run https://github.com/kungfu-systems/buildchain/actions/runs/28984478250\n\n## Included since previous alpha channel head\n- #910 fix(release): include KFD upstream aggregate in version state\n\n## Expected result\n- publish next alpha for the v2.10 line via Buildchain Ref Promotion\n- keep publish-gate source lock and promote-only RC semantics intact",
          "author": "dongkeren",
          "createdAt": "2026-07-09T00:16:39Z",
          "mergedAt": "2026-07-09T00:18:27Z",
          "additions": 6,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 913,
          "url": "https://github.com/kungfu-systems/buildchain/pull/913",
          "title": "chore(release): publish v2.10.9",
          "body": "## Summary\n- promote alpha/v2/v2.10 to release/v2/v2.10 for Buildchain v2.10.9\n- alpha evidence: v2.10.9-alpha.1 published from #912 / run https://github.com/kungfu-systems/buildchain/actions/runs/28984940441\n\n## Included changes since v2.10.8\n- #901 release App handoff support\n- #904 KFD upstream aggregate facts\n- #906 managed KFD upstream role inference\n- #907 public package GitHub Release tag semantics\n- #910 version-state declaration for KFD upstream aggregate site facts\n\n## Expected result\n- publish @kungfu-tech/buildchain@2.10.9 to npm latest\n- create/update GitHub Release v2.10.9 with Buildchain release passport assets\n- prepare the next alpha state for the v2.10 line",
          "author": "dongkeren",
          "createdAt": "2026-07-09T00:22:25Z",
          "mergedAt": "2026-07-09T00:24:11Z",
          "additions": 1355,
          "deletions": 92,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 421,
          "url": "https://github.com/kungfu-systems/kungfu/pull/421",
          "title": "feat(storage): move file provider into runtime service",
          "body": "## Summary\n- move the generic content-addressed file storage provider into libkungfu runtime storage service\n- keep Python storage APIs as compatibility shims over the C++ service\n- expose direct Python bindings for runtime operations, manifest accept/load, record export, and payload writes\n- update storage tests and docs for the C++ file provider\n\n## Validation\n- ./kungfu-code fix\n- ./kungfu-code build:core\n- PYTHONPATH=\"/Users/dkr/Worktrees/kungfu/feature/storage-cpp-file-provider/src/python:/Users/dkr/Worktrees/kungfu/feature/storage-cpp-file-provider/build/Release\" DYLD_FALLBACK_LIBRARY_PATH=\"/Users/dkr/Worktrees/kungfu/feature/storage-cpp-file-provider/build/Release${DYLD_FALLBACK_LIBRARY_PATH:+:}\" uv run --frozen pytest tests/python/test_atlas_storage.py\n- ./kungfu-code check\n- ./kungfu-code build",
          "author": "dongkeren",
          "createdAt": "2026-07-09T00:33:17Z",
          "mergedAt": "2026-07-09T00:34:43Z",
          "additions": 1112,
          "deletions": 536,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 914,
          "url": "https://github.com/kungfu-systems/buildchain/pull/914",
          "title": "fix(web-surface): use app client id for release PR token",
          "body": "## Summary\n- add `production-release-app-client-id` as the first-class web-surface release PR GitHub App input\n- keep `production-release-app-id` as a deprecated input-name alias while passing the selected value through `client-id`\n- pin `actions/create-github-app-token` to v3.1.1 and refresh generated site bundle/docs/tests\n\n## Validation\n- `pnpm run check`\n\nCloses #911",
          "author": "dongkeren",
          "createdAt": "2026-07-09T00:37:25Z",
          "mergedAt": "2026-07-09T00:39:07Z",
          "additions": 41,
          "deletions": 26,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/homebrew-tap",
          "number": 7,
          "url": "https://github.com/kungfu-systems/homebrew-tap/pull/7",
          "title": "feat(tap): prepare kungfu gui cask publication",
          "body": "## Summary\n- add a planned `kungfu` cask entry without exposing an installable cask yet\n- teach the managed updater and tap checker to project and verify formula and cask entries from upstream release passports\n- document the Kungfu GUI App cask materialization path and refresh tap-local KFD witnesses\n- accept the current Buildchain `@v2` contract lock after verifying the surface set stayed closed-world and lifecycle verify passes\n\n## Validation\n- `node --check scripts/update-managed-products.mjs`\n- `node --check scripts/check-tap.mjs`\n- `node --check scripts/update-kfd-witnesses.mjs`\n- `node scripts/update-kfd-witnesses.mjs`\n- `node scripts/check-tap.mjs`\n- `git diff --check`\n- `buildchain validate --require-lifecycle-stages verify`\n- `buildchain lifecycle run verify --required`\n- dry-run materialization of `package=kungfu` from a data URL release passport\n- `node scripts/update-managed-products.mjs --json --update-lock` confirms the refreshed Buildchain lock is compatible\n\n## Notes\nThe current upstream Buildchain formula has a newer release available, but this PR intentionally does not update `Formula/buildchain.rb`; managed product propagation remains a separate automation concern.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T00:43:59Z",
          "mergedAt": "2026-07-09T00:45:33Z",
          "additions": 582,
          "deletions": 156,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 422,
          "url": "https://github.com/kungfu-systems/kungfu/pull/422",
          "title": "feat(storage): expose runtime service to node",
          "body": "## Summary\n- expose libkungfu runtime storage service operations through the Node native binding and @kungfu-tech/core\n- add Node/Python parity coverage over the same C++ storage service fixture\n- add runtime-greenfield ownership checks and docs clarifying Python/Node are storage shims\n\n## Validation\n- ./kungfu-code check\n- ./kungfu-code build:core\n- KUNGFU_REQUIRE_NATIVE=1 KUNGFU_DIR=\"/Users/dkr/Worktrees/kungfu/feature/storage-node-binding-provider-cleanup/framework/core/dist/kungfu\" pnpm --filter @kungfu-tech/core run test:storage-binding\n- node tests/fixtures/storage-demo-node-binding/run.mjs\n- ./kungfu-code build",
          "author": "dongkeren",
          "createdAt": "2026-07-09T01:00:28Z",
          "mergedAt": "2026-07-09T01:00:49Z",
          "additions": 464,
          "deletions": 2,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 915,
          "url": "https://github.com/kungfu-systems/buildchain/pull/915",
          "title": "feat(publication): add publication artifact workflow",
          "body": "## Summary\n- add first-class publication-artifact project support for paper/report repositories\n- add publication artifact CLI, Node API, reusable workflow, fixture, docs, and site bundle metadata\n- make the publication reusable workflow enforce trusted buildchain-ref override semantics and contract-lock checks before build work\n\n## Validation\n- node scripts/generate-site-bundle.mjs\n- node --test tests/publication-artifact.test.mjs tests/buildchain-config.test.mjs tests/build-surface.test.mjs tests/cli.test.mjs\n- bash scripts/check-workflows.sh\n- pnpm run check\n\n## Release note\nThis branch is based on dev/v2/v2.10 after PR #914, so the #911 fix is included in the next release promotion from this line.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T01:05:03Z",
          "mergedAt": "2026-07-09T01:07:03Z",
          "additions": 1574,
          "deletions": 159,
          "changedFiles": 40
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 916,
          "url": "https://github.com/kungfu-systems/buildchain/pull/916",
          "title": "release: promote dev v2.10 to alpha",
          "body": "## Summary\nPromote dev/v2/v2.10 to alpha/v2/v2.10.\n\nIncluded changes:\n- #914 fixes web-surface GitHub App release PR token client id handling (#911)\n- #915 adds first-class publication artifact workflow support\n\n## Validation\n- dev PR checks passed before merge\n- channel promotion checks will run on this PR",
          "author": "dongkeren",
          "createdAt": "2026-07-09T01:07:41Z",
          "mergedAt": "2026-07-09T01:09:24Z",
          "additions": 1609,
          "deletions": 179,
          "changedFiles": 42
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 917,
          "url": "https://github.com/kungfu-systems/buildchain/pull/917",
          "title": "release: promote alpha v2.10 to stable",
          "body": "## Summary\nPromote alpha/v2/v2.10 to release/v2/v2.10.\n\nIncluded changes:\n- #914 fixes web-surface GitHub App release PR token client id handling (#911)\n- #915 adds first-class publication artifact workflow support\n- alpha publication succeeded as @kungfu-tech/buildchain@2.10.10-alpha.1\n\n## Validation\n- alpha PR #916 checks passed\n- Buildchain Ref Promotion run 28986930759 succeeded\n- stable channel checks will run on this PR",
          "author": "dongkeren",
          "createdAt": "2026-07-09T01:13:09Z",
          "mergedAt": "2026-07-09T01:15:11Z",
          "additions": 1620,
          "deletions": 190,
          "changedFiles": 43
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 423,
          "url": "https://github.com/kungfu-systems/kungfu/pull/423",
          "title": "feat(product): add cli product artifacts",
          "body": "## Summary\n- rename the dogfood product assembly package from artifact/ to product/ and update workspace, docs, Buildchain artifact paths, and KFD evidence\n- keep desktop installer output under product/release/desktop and add a CLI archive product under product/release/cli\n- expose kungfu sdk product cli dist for product assembly packages and add KFD-3 surfaces for CLI product build/query\n\n## Validation\n- ./kungfu-code check\n- ./kungfu-code kfd:buildchain:check\n- ./kungfu-code kfd2:claims:check\n- ./kungfu-code check:types\n- node --test product/scripts/product.test.mjs\n- node --test developer/sdk/tests/contract-cli.test.mjs\n- ./kungfu-code dist:cli (produced product/release/cli/kungfu-cli-darwin-arm64.tar.gz, 57M)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T01:32:20Z",
          "mergedAt": "2026-07-09T01:33:23Z",
          "additions": 864,
          "deletions": 256,
          "changedFiles": 41
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 47,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/47",
          "title": "ci(site): use Buildchain release app client id",
          "body": "## Summary\n- switch the Buildchain web-surface workflow to `production-release-app-client-id`\n- add/use the `KUNGFU_RELEASE_APP_CLIENT_ID` repository variable for the release GitHub App client id\n\n## Verification\n- `pnpm run build && pnpm run check`\n\n## Notes\n- Follows Buildchain v2.10.10 fixing kungfu-systems/buildchain#911.\n- The deprecated numeric app id variable is left in place for rollback/compatibility, but the workflow no longer consumes it.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T01:44:22Z",
          "mergedAt": "2026-07-09T01:48:58Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 424,
          "url": "https://github.com/kungfu-systems/kungfu/pull/424",
          "title": "feat(storage): add rocksdb payload provider",
          "body": "## Summary\n- add a C++ storage provider abstraction with default content-addressed-file and optional RocksDB providers\n- route source registry, manifests, payload reads/writes, fsck/export/import/rebuild/gc/compact/verify through the provider surface\n- keep Node/Python as thin runtime bindings and extend parity tests across file and RocksDB providers\n- document provider-neutral storage semantics in ADR/runtime/spec docs and guard provider ownership in the runtime greenfield gate\n\n## Validation\n- ./kungfu-code fix\n- ./kungfu-code check\n- ./kungfu-code build:core\n- KUNGFU_REQUIRE_NATIVE=1 KUNGFU_DIR=\"$PWD/framework/core/dist/kungfu\" pnpm --filter @kungfu-tech/core run test:storage-binding\n- PYTHONPATH=\"$PWD/framework/core/src/python:$PWD/framework/core/dist/kungfu\" KUNGFU_DIR=\"$PWD/framework/core/dist/kungfu\" uv run --frozen --project framework/core python -m pytest framework/core/tests/python/test_atlas_storage.py\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-09T01:54:22Z",
          "mergedAt": "2026-07-09T01:55:12Z",
          "additions": 698,
          "deletions": 164,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 425,
          "url": "https://github.com/kungfu-systems/kungfu/pull/425",
          "title": "test(product): smoke CLI product install layout",
          "body": "## Summary\n- extract generated CLI archives in a temporary install layout after packaging\n- validate runtime, SDK/KFD metadata, TUI entry, first-party kfx package set, and `kungfu kfd status --json` from the extracted product\n- include the SDK runtime KFD package and module metadata in the CLI product\n\n## Validation\n- `./kungfu-code check`\n- `node --test product/scripts/archive.test.mjs product/scripts/product.test.mjs`\n- `./kungfu-code product cli dist`\n- verified `product/release/cli/kungfu-cli-darwin-arm64.tar.gz` contains runtime, SDK, KFD package, TUI, and 11 first-party kfx package manifests\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T01:59:40Z",
          "mergedAt": "2026-07-09T02:00:33Z",
          "additions": 443,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 91,
          "url": "https://github.com/kungfu-systems/libnode/pull/91",
          "title": "chore(release): publish libnode 22.22.3-kf.3-alpha.18",
          "body": "## Summary\n- bump libnode alpha to 22.22.3-kf.3-alpha.18\n- update Buildchain v2 contract lock to v2.10.10\n- refresh KFD witnesses for the new release manifest\n\n## Verification\n- node .gyp/libnode-release-verify.js\n- git diff --check\n- corepack pnpm verify-release\n- corepack pnpm verify-package-source\n- corepack pnpm verify-kfd-witnesses\n- Buildchain v2.10.10 contract lock check: unchanged\n\n## Purpose\nValidate Buildchain v2.10.10 public package release tag / GitHub Release / release passport fix after alpha.17 published to npm but failed release finalization.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T01:41:40Z",
          "mergedAt": "2026-07-09T02:15:18Z",
          "additions": 14,
          "deletions": 14,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 426,
          "url": "https://github.com/kungfu-systems/kungfu/pull/426",
          "title": "feat(storage): harden provider lifecycle",
          "body": "## Summary\n- make runtime storage provider selection report its source: explicit option, env, or default\n- keep RocksDB provider handles owned by the C++ provider instance and reuse them across key operations\n- expose provider runtime diagnostics while keeping Node/Python as thin bindings\n- document the provider lifecycle/config boundary in runtime storage docs and ADR-0018\n\n## Validation\n- ./kungfu-code fix\n- ./kungfu-code check\n- ./kungfu-code build:core\n- KUNGFU_REQUIRE_NATIVE=1 KUNGFU_DIR=\"/Users/dkr/Worktrees/kungfu/feature/storage-provider-lifecycle-hardening/framework/core/dist/kungfu\" pnpm --filter @kungfu-tech/core run test:storage-binding\n- PYTHONPATH=\"/Users/dkr/Worktrees/kungfu/feature/storage-provider-lifecycle-hardening/src/python:/Users/dkr/Worktrees/kungfu/feature/storage-provider-lifecycle-hardening/dist/kungfu\" KUNGFU_DIR=\"/Users/dkr/Worktrees/kungfu/feature/storage-provider-lifecycle-hardening/dist/kungfu\" uv run --frozen python -m pytest tests/python/test_atlas_storage.py\n\nNote: build:core still prints existing pybind11_stubgen docstring parsing warnings, but exits 0.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T02:48:35Z",
          "mergedAt": "2026-07-09T02:49:08Z",
          "additions": 148,
          "deletions": 30,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 920,
          "url": "https://github.com/kungfu-systems/buildchain/pull/920",
          "title": "fix(publication): pin workflow pnpm and declare toolchain evidence",
          "body": "## Summary\n\n- pin Buildchain-owned workflow pnpm activation to pnpm@11.7.0 so Corepack no longer resolves pnpm/latest\n- add first-class publication toolchain facts for custom-command and latex-docker profiles\n- record publication toolchain evidence and custom-command residual risk in publication manifests/passports\n- refresh Buildchain site bundle and generated action bundles\n\nFixes #919.\nFixes #918.\n\n## Validation\n\n- corepack pnpm@11.7.0 exec node --test tests/publication-artifact.test.mjs\n- corepack pnpm@11.7.0 exec node --test tests/buildchain-config.test.mjs\n- corepack pnpm@11.7.0 exec node --test tests/cli.test.mjs\n- corepack pnpm@11.7.0 exec node --test tests/build-surface.test.mjs\n- corepack pnpm@11.7.0 run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T02:44:57Z",
          "mergedAt": "2026-07-09T02:51:27Z",
          "additions": 447,
          "deletions": 117,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 921,
          "url": "https://github.com/kungfu-systems/buildchain/pull/921",
          "title": "chore(release): publish v2.10.11 alpha",
          "body": "## Summary\n\nPromote dev/v2/v2.10 to alpha/v2/v2.10 for the v2.10.11 release train.\n\nIncludes #920:\n- pinned Buildchain-owned pnpm workflow activation\n- publication-artifact toolchain evidence for custom-command and latex-docker\n\n## Validation\n\n- #920 local `corepack pnpm@11.7.0 run check` passed\n- #920 PR `check` and `libnode-shaped` CI passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T02:58:48Z",
          "mergedAt": "2026-07-09T03:02:19Z",
          "additions": 447,
          "deletions": 117,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 922,
          "url": "https://github.com/kungfu-systems/buildchain/pull/922",
          "title": "fix(release): stabilize promote dependency bootstrap",
          "body": "## Summary\n- enable Corepack pnpm shims before release-candidate promote dependency install\n- call pnpm through `corepack pnpm@11.7.0` so promotion works on Node 24 runner images\n- fall back to the checked-out source reporter if the runtime reporter path is unavailable during failure classification\n- refresh generated Buildchain contract digest\n\n## Validation\n- `node --test tests/build-surface.test.mjs`\n- `node scripts/check-inventory.mjs`\n- `pnpm run check`\n\n## Release note\nThis fixes the failed alpha promotion run 28991041859 before retrying the v2.10.11 release.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:08:41Z",
          "mergedAt": "2026-07-09T03:10:49Z",
          "additions": 16,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 427,
          "url": "https://github.com/kungfu-systems/kungfu/pull/427",
          "title": "feat(storage): add sqlite projection",
          "body": "## Summary\n- add a C++-owned storage SQLite projection at storage/projections/storage.sqlite\n- rebuild projection tables from accepted latest manifests through rebuild_index\n- report projection status/drift in status, fsck, and compact planning\n\n## Validation\n- ./kungfu-code fix\n- ./kungfu-code check\n- ./kungfu-code build:core\n- PYTHONPATH=\"/Users/dkr/Worktrees/kungfu/feature/storage-sqlite-projection-v1/src/python:/Users/dkr/Worktrees/kungfu/feature/storage-sqlite-projection-v1/dist/kungfu\" KUNGFU_DIR=\"/Users/dkr/Worktrees/kungfu/feature/storage-sqlite-projection-v1/dist/kungfu\" uv run --frozen python -m pytest tests/python/test_atlas_storage.py\n- KUNGFU_REQUIRE_NATIVE=1 KUNGFU_DIR=\"/Users/dkr/Worktrees/kungfu/feature/storage-sqlite-projection-v1/framework/core/dist/kungfu\" pnpm --filter @kungfu-tech/core run test:storage-binding",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:12:35Z",
          "mergedAt": "2026-07-09T03:13:10Z",
          "additions": 503,
          "deletions": 16,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 923,
          "url": "https://github.com/kungfu-systems/buildchain/pull/923",
          "title": "chore(release): publish v2.10.11 alpha",
          "body": "## Summary\n- Promote the latest dev/v2/v2.10 changes to alpha after fixing the release-candidate promote dependency bootstrap.\n- Includes #920 open-issue fixes and #922 release bootstrap stabilization.\n\n## Validation\n- #920 checks passed before merge.\n- #922 checks passed before merge.\n- Local validation for #922: `node --test tests/build-surface.test.mjs`, `node scripts/check-inventory.mjs`, `pnpm run check`.\n\n## Prior failed run addressed\n- Fixes the `pnpm: command not found` alpha promotion failure from run 28991041859 before retrying the alpha release.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:11:32Z",
          "mergedAt": "2026-07-09T03:13:39Z",
          "additions": 16,
          "deletions": 5,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 924,
          "url": "https://github.com/kungfu-systems/buildchain/pull/924",
          "title": "chore(release): promote v2.10.11 stable",
          "body": "## Summary\n- Promote Buildchain v2.10.11 from alpha to stable.\n- Alpha verification succeeded via v2.10.11-alpha.1.\n\n## Evidence\n- Alpha promotion run: https://github.com/kungfu-systems/buildchain/actions/runs/28991463403\n- Alpha GitHub Release: v2.10.11-alpha.1 (prerelease, latest=false)\n- npm alpha dist-tag: 2.10.11-alpha.1\n\n## Included fixes\n- #920 open issue fixes\n- #922 release-candidate promote pnpm bootstrap and friction reporter fallback fix",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:17:34Z",
          "mergedAt": "2026-07-09T03:19:37Z",
          "additions": 472,
          "deletions": 131,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 38,
          "url": "https://github.com/kungfu-systems/build-images/pull/38",
          "title": "feat(images): add latex pdf builder image",
          "body": "## Summary\n\n- add `latex-pdf-builder` as a child of `node24-pnpm`, preserving the Kungfu `base-linux` ancestry and non-root `kungfu` user\n- include `latexmk`, `biber`, practical TeX Live packages, `lmodern`, and `pnpm@11.7.0` from the parent image\n- add pnpm-driven PDF smoke coverage for `paper/main.tex -> _build/main.pdf`\n- open the v1.2 image-family line and document first-publish lock handling\n\n## Verification\n\n- `pnpm run check`\n- Ubuntu Docker smoke with apt cache: `base-linux -> node24-pnpm -> latex-pdf-builder`, then `pnpm run pdf` produced `_build/main.pdf` with sha256 `8ad775ded1553577feba233ce3895db32ad5e3ed3767b9fd9f23317b031a9b48`\n\nFixes #37.\nRelated: kungfu-systems/buildchain#918",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:38:57Z",
          "mergedAt": "2026-07-09T03:40:18Z",
          "additions": 172,
          "deletions": 8,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 39,
          "url": "https://github.com/kungfu-systems/build-images/pull/39",
          "title": "chore(release): promote v1.2 alpha",
          "body": "## Summary\n\nPromote the new v1.2 image-family line to alpha so Buildchain can publish `v1.2.0-alpha.0`, including the new `latex-pdf-builder` image.\n\n## Verification before promotion\n\n- PR #38 passed Verify and Consumer Smoke.\n- Ubuntu Docker smoke built `base-linux -> node24-pnpm -> latex-pdf-builder` and generated `_build/main.pdf` through `pnpm run pdf`.\n\nRelated: #37\nRelated: kungfu-systems/buildchain#918",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:40:43Z",
          "mergedAt": "2026-07-09T03:41:46Z",
          "additions": 172,
          "deletions": 8,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 428,
          "url": "https://github.com/kungfu-systems/kungfu/pull/428",
          "title": "feat(storage): add projection query API",
          "body": "## Summary\n- add C++-owned `query` storage service operation over the rebuildable SQLite projection\n- expose thin Python service and `kungfu storage query` CLI wrappers\n- register the new KFD-3 command surface and refresh Buildchain KFD evidence\n- extend Python and Node storage parity tests to cover query results\n\n## Validation\n- `./kungfu-code build:core`\n- `./kungfu-code check`\n- `PYTHONPATH=\"$PWD/src/python:$PWD/dist/kungfu\" KUNGFU_DIR=\"$PWD/dist/kungfu\" uv run --frozen python -m pytest tests/python/test_atlas_storage.py`\n- `KUNGFU_REQUIRE_NATIVE=1 KUNGFU_DIR=\"$PWD/framework/core/dist/kungfu\" pnpm --filter @kungfu-tech/core run test:storage-binding`\n- CLI smoke via `CliRunner`: `kungfu storage query --table entries --scope source --source cli-synth --json`\n- `git diff --check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:46:43Z",
          "mergedAt": "2026-07-09T03:47:12Z",
          "additions": 404,
          "deletions": 18,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 102,
          "url": "https://github.com/kungfu-systems/kfd/pull/102",
          "title": "feat(kfd-1): define publication URL semantics",
          "body": "## Summary\n\n- Adds `schemas/kfd-1/publication-url-semantics.schema.json` for canonical reader URLs, latest aliases, immutable version artifact URLs, artifact digests, source coordinates, lineage, site consumption, and archive policy.\n- Registers the new interface in `standards.json`, KFD-1 docs, the generated site bundle projection, release impact metadata, and KFD-1/KFD-2/KFD-3 generated evidence surfaces.\n- Extends `scripts/check.mjs` so KFD fails closed if the new schema/interface/metadata or archive-policy constants drift.\n\n## Verification\n\n- `npm run check`\n- `git diff --check`\n- `npm pack --dry-run --json --registry=https://registry.npmjs.org/`\n- `npx -y @kungfu-tech/buildchain@2.10.10 validate --cwd . --json`\n- `jq` spot checks for the new standards metadata and archive policy constants\n\n## Related\n\n- Resolves https://github.com/kungfu-systems/kfd/issues/101\n- Coordinates with https://github.com/kungfu-systems/buildchain/issues/925\n- Coordinates with https://github.com/kungfu-systems/site-libkungfu-dev/issues/50",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:47:42Z",
          "mergedAt": "2026-07-09T03:55:04Z",
          "additions": 523,
          "deletions": 106,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 40,
          "url": "https://github.com/kungfu-systems/build-images/pull/40",
          "title": "fix(ci): use app token for generated status checks",
          "body": "## Summary\n- grant the promotion workflow checks:write permission\n- pass github.token as the generated status check token for Buildchain protected ref updates\n- keep the promotion token path unchanged for the existing ref update flow\n\n## Verification\n- pnpm run check\n\nFollow-up for latex-pdf-builder v1.2.0-alpha.0 promotion after PR #38 and PR #39.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:53:03Z",
          "mergedAt": "2026-07-09T03:55:51Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 41,
          "url": "https://github.com/kungfu-systems/build-images/pull/41",
          "title": "chore(release): promote v1.2 ci fix to alpha",
          "body": "## Summary\n- promote the Buildchain generated status check token fix to alpha/v1/v1.2\n- retrigger Buildchain Ref Promotion for the v1.2.0-alpha.0 image publication path\n\n## Verification\n- PR #40 checks passed\n- no image contract changes beyond the already merged latex-pdf-builder release content",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:56:27Z",
          "mergedAt": "2026-07-09T03:57:23Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 51,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/51",
          "title": "feat(site): render publication archive routes",
          "body": "## Summary\n\n- add a Buildchain-shaped publication registry fixture for papers/archive route semantics\n- render /papers/** index/latest/version pages plus immutable PDF/source/passport artifact paths\n- expose publication archive facts in /manifest.json, /papers/manifest.json, /papers/registry.json, /papers/llms.txt\n- fail checks when declared immutable artifacts disappear, digest drift, or archive route semantics are missing\n\n## Scope\n\nRefs #50. This is the site-side preparation that can be implemented before Buildchain publishes the real publication registry from kungfu-systems/buildchain#925. It does not close #50 yet.\n\n## Validation\n\n- pnpm run build\n- pnpm run check\n\nNo alpha/release publication is requested in this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:49:44Z",
          "mergedAt": "2026-07-09T03:59:17Z",
          "additions": 637,
          "deletions": 1,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 42,
          "url": "https://github.com/kungfu-systems/build-images/pull/42",
          "title": "fix(ci): declare Buildchain promotion bypass app",
          "body": "## Summary\n- declare github-actions as the Buildchain-managed branch protection bypass app for direct promote-buildchain-ref usage\n- pass the generated ref update token explicitly while keeping github.token for generated status checks\n\n## Verification\n- pnpm run check\n\nThis follows the Buildchain direct-caller guidance for protected generated version-state bookkeeping.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:01:53Z",
          "mergedAt": "2026-07-09T04:02:47Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 43,
          "url": "https://github.com/kungfu-systems/build-images/pull/43",
          "title": "chore(release): promote Buildchain bypass app fix to alpha",
          "body": "## Summary\n- promote the direct Buildchain promotion bypass app fix to alpha/v1/v1.2\n- retrigger the v1.2.0-alpha.0 image publication path for latex-pdf-builder\n\n## Verification\n- PR #42 checks passed\n- alpha Verify will rerun after merge before Buildchain Ref Promotion",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:03:03Z",
          "mergedAt": "2026-07-09T04:04:12Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 44,
          "url": "https://github.com/kungfu-systems/build-images/pull/44",
          "title": "fix(ci): update default promotion workflow for v1.2",
          "body": "## Summary\n- update the default-branch Buildchain promotion workflow so workflow_run promotions use the v1.2 target default\n- add checks:write and generated status/ref token inputs for promote-buildchain-ref\n- declare github-actions as the Buildchain-managed bypass app for protected generated bookkeeping\n\n## Verification\n- pnpm run check\n\nReason: GitHub workflow_run executes the workflow definition from the repository default branch, which is currently dev/v1/v1.1.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:06:56Z",
          "mergedAt": "2026-07-09T04:07:59Z",
          "additions": 5,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 928,
          "url": "https://github.com/kungfu-systems/buildchain/pull/928",
          "title": "feat(publication): add immutable archive registry",
          "body": "## Summary\n- add optional [publication.archive] config for canonical/latest/immutable publication URLs\n- generate append-only publication-registry.json with same-version digest immutability checks\n- record archive routes/evidence in publication manifest/passport and upload registry from the reusable workflow\n- allow release propagation locks to carry publicationArtifact payloads without npm package facts\n\n## Validation\n- node --test tests/build-surface.test.mjs tests/publication-artifact.test.mjs tests/release-propagation.test.mjs tests/buildchain-config.test.mjs\n- pnpm run check\n\nFixes #925",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:57:35Z",
          "mergedAt": "2026-07-09T04:08:40Z",
          "additions": 784,
          "deletions": 132,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 429,
          "url": "https://github.com/kungfu-systems/kungfu/pull/429",
          "title": "feat(master): add resident service supervisor",
          "body": "## Summary\n- add `kungfu master` commands for resident master supervisor status/start/stop/restart\n- add dry-run-by-default user service plan/install/uninstall commands for macOS, Linux, and Windows\n- register the public CLI surface in Buildchain-managed KFD-3 and document the lifecycle contract\n\n## Verification\n- `./kungfu-code check`\n- `./kungfu-code check:types`\n- `./kungfu-code kfd:buildchain:check`\n- `PYTHONPATH=src/python uv run --frozen pytest tests/python/test_master_service.py`\n- `uv run --frozen mypy src/python/kungfu/master_service.py src/python/kungfu/cli/commands/master.py`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:13:20Z",
          "mergedAt": "2026-07-09T04:14:34Z",
          "additions": 1050,
          "deletions": 0,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 926,
          "url": "https://github.com/kungfu-systems/buildchain/pull/926",
          "title": "chore(release): promote v2.11 alpha",
          "body": "Buildchain release line bootstrap opened v2.11. Merge this channel PR to publish the first alpha for the new minor line.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T03:43:25Z",
          "mergedAt": "2026-07-09T04:15:14Z",
          "additions": 864,
          "deletions": 199,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 104,
          "url": "https://github.com/kungfu-systems/kfd/pull/104",
          "title": "chore(kfd): anchor alpha 22 version",
          "body": "## Summary\n- Anchor the KFD package release metadata at 1.0.0-alpha.22.\n- Regenerate KFD release witnesses that bind package.json and kfd.release.json.\n\n## Validation\n- npm run check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n- npx -y @kungfu-tech/buildchain@2 validate --cwd . --json",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:15:05Z",
          "mergedAt": "2026-07-09T04:16:29Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 45,
          "url": "https://github.com/kungfu-systems/build-images/pull/45",
          "title": "chore(release): align dev v1.2 with alpha",
          "body": "## Summary\n- align dev/v1/v1.2 with the reviewed alpha/v1/v1.2 merge commit\n- unblock Buildchain promotion finalization without weakening branch protection\n\n## Verification\n- alpha/v1/v1.2 Verify succeeded for 83966e59e212586df48ff44b5e60f3c94449ff41\n- Buildchain generated check succeeded on the same SHA, but direct protected update was rejected due a stale cancelled same-name check run",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:15:44Z",
          "mergedAt": "2026-07-09T04:17:56Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 105,
          "url": "https://github.com/kungfu-systems/kfd/pull/105",
          "title": "chore: promote KFD alpha 22",
          "body": "## Summary\nPromote dev/v1/v1.0 to alpha/v1/v1.0 for @kungfu-tech/kfd@1.0.0-alpha.22.\n\n## Included\n- KFD-1 publication URL semantics from PR #102.\n- Alpha 22 version anchor from PR #104.\n\n## Validation\n- Buildchain Verify and Build gates run on this promotion PR.\n- After merge, Buildchain workflow_run should publish the alpha npm package and release passport.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:17:10Z",
          "mergedAt": "2026-07-09T04:18:52Z",
          "additions": 548,
          "deletions": 131,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 46,
          "url": "https://github.com/kungfu-systems/build-images/pull/46",
          "title": "fix(ci): disable optional release passport for image promotion",
          "body": "## Summary\n- disable optional Buildchain release-passport generation for the image promotion workflow\n- keep publish transaction evidence for GHCR image publication intact\n\n## Verification\n- pnpm run check\n\nReason: Buildchain v2 promotion currently reaches optional release-passport generation and fails on a missing bundled @kungfu-tech/kfd dependency for this image-publishing workflow.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:20:02Z",
          "mergedAt": "2026-07-09T04:21:06Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 929,
          "url": "https://github.com/kungfu-systems/buildchain/pull/929",
          "title": "chore(release): promote v2.11 release",
          "body": "Promote Buildchain v2.11 from alpha to release after validating the immutable publication archive registry work.\\n\\nSource PRs:\\n- #928\\n- #926\\n\\nCloses #925.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:19:52Z",
          "mergedAt": "2026-07-09T04:21:43Z",
          "additions": 864,
          "deletions": 199,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 430,
          "url": "https://github.com/kungfu-systems/kungfu/pull/430",
          "title": "docs(storage): define episode object model",
          "body": "## Summary\n\n- accept Episode as the first-class causal segment object\n- add the companion Episode object model design document\n- route storage, event model, concepts, and ADR index docs to the new model\n\n## Validation\n\n- git diff --check\n- ./kungfu-code check\n\n## Governance checklist\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider API, billing, quota, or usage-attribution changes\n- [x] No hosted-service, brand, package, or release identity changes\n- [x] No release evidence or publishing surface changes\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:34:58Z",
          "mergedAt": "2026-07-09T04:40:39Z",
          "additions": 446,
          "deletions": 1,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 431,
          "url": "https://github.com/kungfu-systems/kungfu/pull/431",
          "title": "feat(gui): add master tray residency controls",
          "body": "## Summary\n- keep the Electron GUI resident in a tray/menu-bar surface when the main window is closed\n- add explicit tray controls for show/hide, master status/start/stop, Quit GUI, and Stop Master and Quit\n- register the GUI tray capability in KFD-3 and document the lifecycle semantics\n\n## Validation\n- ./kungfu-code check\n- ./kungfu-code check:types\n- ./kungfu-code kfd:buildchain:check\n- ./kungfu-code build:app\n- ./kungfu-code product gui pack --dry-run\n- ./kungfu-code product gui dist --dry-run\n- ./kungfu-code kfd:query --json | jq -r '.capabilities[] | select(.id==\"kungfu.gui.master-tray\")'\n\n## Notes\n- No service files are installed or removed by this change.\n- A live desktop tray smoke was not run in this branch.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:40:10Z",
          "mergedAt": "2026-07-09T04:41:23Z",
          "additions": 269,
          "deletions": 3,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 47,
          "url": "https://github.com/kungfu-systems/build-images/pull/47",
          "title": "chore(images): lock latex pdf builder digest",
          "body": "## Summary\n- update images.lock.json to the published v1.2.0-alpha.0 image family digests\n- add the latex-pdf-builder digest to the lock file\n- remove the temporary pending-first-publish lock state from latex-pdf-builder\n\n## Verification\n- pnpm run check\n\nRelease evidence: https://github.com/kungfu-systems/build-images/actions/runs/28993838949",
          "author": "dongkeren",
          "createdAt": "2026-07-09T04:40:47Z",
          "mergedAt": "2026-07-09T04:42:06Z",
          "additions": 18,
          "deletions": 11,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 432,
          "url": "https://github.com/kungfu-systems/kungfu/pull/432",
          "title": "docs(storage): define episode manifest journal",
          "body": "## Summary\n\n- accept the Episode manifest journal as the local authority for Episode metadata\n- define Episode manifest records as yijinjing first-class data structures\n- clarify that JSON is only an export, diagnostic, or folded view\n- update the Episode object model and storage docs to route to ADR-0034\n\n## Validation\n\n- git diff --check\n- ./kungfu-code check\n\n## Governance checklist\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider API, billing, quota, or usage-attribution changes\n- [x] No hosted-service, brand, package, or release identity changes\n- [x] No release evidence or publishing surface changes\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T05:13:22Z",
          "mergedAt": "2026-07-09T05:18:56Z",
          "additions": 216,
          "deletions": 24,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 49,
          "url": "https://github.com/kungfu-systems/build-images/pull/49",
          "title": "fix(ci): disable release passport for v1.2 promotion",
          "body": "Align the v1.2 development line with the release-channel promotion workflow so the next alpha evidence tree can be promoted through Buildchain without optional release passport collection.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T05:29:08Z",
          "mergedAt": "2026-07-09T05:30:41Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 433,
          "url": "https://github.com/kungfu-systems/kungfu/pull/433",
          "title": "docs(config): define workspace-local data home",
          "body": "## Summary\n\n- accept workspace-local `.kungfu/` as the default Episode/fact ledger home\n- hard-cut the user config default from `~/.kungfu` to `~/.kungfu-config`\n- retain `KF_HOME` as the explicit and machine-level data fallback\n- update config docs, documentation map, and ADR index\n\n## Validation\n\n- git diff --check\n- ./kungfu-code check\n\n## Governance checklist\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider API, billing, quota, or usage-attribution changes\n- [x] No hosted-service, brand, package, or release identity changes\n- [x] No release evidence or publishing surface changes\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T05:33:08Z",
          "mergedAt": "2026-07-09T05:33:40Z",
          "additions": 181,
          "deletions": 28,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 50,
          "url": "https://github.com/kungfu-systems/build-images/pull/50",
          "title": "chore(alpha): promote v1.2 dev to alpha",
          "body": "Promote the v1.2 development line through the Buildchain alpha channel after locking the published latex-pdf-builder digest and aligning release promotion workflow configuration.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T05:31:05Z",
          "mergedAt": "2026-07-09T05:34:52Z",
          "additions": 19,
          "deletions": 11,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 48,
          "url": "https://github.com/kungfu-systems/build-images/pull/48",
          "title": "chore(release): promote v1.2 to release",
          "body": "## Summary\n- promote the verified v1.2 alpha line to release/v1/v1.2 through the Buildchain channel flow\n- release source is the existing alpha exact tag path for latex-pdf-builder\n\n## Evidence\n- alpha tag: v1.2.0-alpha.0 -> 83966e59e212586df48ff44b5e60f3c94449ff41\n- alpha promotion run: https://github.com/kungfu-systems/build-images/actions/runs/28993838949\n- latex-pdf-builder digest: sha256:4d7123794fa7e3ea510dd51ab447d70be90df5df87c01675704a0a5607bf17bf\n\n## Verification\n- release branch Verify must pass before merge\n- Buildchain Ref Promotion will publish the release version after this PR merges",
          "author": "dongkeren",
          "createdAt": "2026-07-09T05:19:58Z",
          "mergedAt": "2026-07-09T05:42:32Z",
          "additions": 191,
          "deletions": 15,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 434,
          "url": "https://github.com/kungfu-systems/kungfu/pull/434",
          "title": "docs(master): define supervisor topology",
          "body": "## Summary\n- add ADR-0036 for the per-user supervisor and per-data-root workspace master topology\n- document that the supervisor routes and manages masters but does not own durable facts\n- update master service, config, ADR index, and docs map entry points\n\n## Validation\n- git diff --check\n- ./kungfu-code check\n\n## Notes\n- This is a documentation/architecture decision slice. Implementation work remains separate.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T05:50:44Z",
          "mergedAt": "2026-07-09T05:51:14Z",
          "additions": 295,
          "deletions": 16,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 435,
          "url": "https://github.com/kungfu-systems/kungfu/pull/435",
          "title": "feat(master): route data roots through supervisor",
          "body": "## Summary\n- add `kungfu master ensure` to register the current data root and start/reuse the per-user supervisor\n- move supervisor runtime state to `KF_CONFIG_HOME/runtime/supervisor` and workspace master state to `<data-root>/runtime/master`\n- teach the supervisor loop to poll a route registry and manage per-data-root master children\n- align config defaults with `~/.kungfu-config` and refresh KFD-1 canonical policy\n\n## Validation\n- PYTHONPATH=framework/core/src/python python3 direct harness for `framework/core/tests/python/test_master_service.py`\n- python3 -m py_compile framework/core/src/python/kungfu/master_service.py framework/core/src/python/kungfu/cli/commands/master.py framework/core/src/python/kungfu/cli/commands/__init__.py framework/core/tests/python/test_master_service.py\n- git diff --check\n- ./kungfu-code check\n\n## Notes\n- V1 uses a file-backed supervisor route registry. It intentionally does not make closed-data storage operations depend on a live master.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T06:06:58Z",
          "mergedAt": "2026-07-09T06:07:52Z",
          "additions": 507,
          "deletions": 138,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 932,
          "url": "https://github.com/kungfu-systems/buildchain/pull/932",
          "title": "feat(publication): use build-images latex builder for papers",
          "body": "## Summary\n- switch publication-artifact workflow latex-docker defaults to build-images latex-pdf-builder v1.2.0 pinned by digest\n- make publication-artifact init scaffold write the pinned latex-docker toolchain into .buildchain/buildchain.toml\n- update publication docs, site bundle, and tests for the new paper builder contract\n\n## Verification\n- node --test tests/cli.test.mjs tests/buildchain-config.test.mjs tests/publication-artifact.test.mjs tests/build-surface.test.mjs\n- pnpm run generate:site\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-09T06:02:56Z",
          "mergedAt": "2026-07-09T06:14:20Z",
          "additions": 67,
          "deletions": 45,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 931,
          "url": "https://github.com/kungfu-systems/buildchain/pull/931",
          "title": "fix(promote): ignore release evidence during version verification",
          "body": "Fixes #930.\\n\\nBuildchain promotion can generate publish transaction evidence and local release-state files before later generated version-state verification runs. Those Buildchain-owned untracked files should not fail the version-state dirty check.\\n\\nThis adds .buildchain/release-evidence/ and .buildchain/release-state/ to the existing ephemeral Buildchain evidence whitelist and extends the unit coverage that already covers generated evidence paths.\\n\\nValidation:\\n- node --test tests/promote-buildchain-ref.test.mjs --test-name-pattern \"version verification ignores generated buildchain evidence\"\\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-09T06:01:07Z",
          "mergedAt": "2026-07-09T07:00:17Z",
          "additions": 13,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 436,
          "url": "https://github.com/kungfu-systems/kungfu/pull/436",
          "title": "docs(adr): storage-service records are Hana-core kernel metadata",
          "body": "Merge feature/storage-adr0033-zero-copy-records into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-09T07:03:29Z",
          "mergedAt": "2026-07-09T07:03:35Z",
          "additions": 211,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 437,
          "url": "https://github.com/kungfu-systems/kungfu/pull/437",
          "title": "feat(gui): surface supervisor master status",
          "body": "Merge feature/supervisor-status-surface-integration into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-09T07:08:04Z",
          "mergedAt": "2026-07-09T07:08:10Z",
          "additions": 286,
          "deletions": 8,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 934,
          "url": "https://github.com/kungfu-systems/buildchain/pull/934",
          "title": "fix(kfd): unify generated output layout",
          "body": "## Summary\n- unify Buildchain-owned KFD outputs under `.buildchain/kfd/kfd-N/`\n- move the KFD-3 surface registry default to `.buildchain/kfd/kfd-3/surfaces.json`\n- expose canonical KFD layout constants and migrate legacy KFD paths through Buildchain layout helpers\n- update self-KFD witness generation, promotion finalization, docs, tests, and generated site/action bundles\n\nFixes #933.\n\n## Verification\n- `corepack pnpm run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T07:23:52Z",
          "mergedAt": "2026-07-09T07:28:52Z",
          "additions": 385,
          "deletions": 201,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 438,
          "url": "https://github.com/kungfu-systems/kungfu/pull/438",
          "title": "feat(master): add supervisor route lifecycle leases",
          "body": "Adds supervisor route heartbeat leases, deterministic lifecycle health states, ensure-time repair for unsafe route state, and GUI status/tray lifecycle surfacing.\\n\\nValidation:\\n- ./kungfu-code check\\n- pnpm --filter @kungfu-tech/gui run build\\n- ./kungfu-code build\\n- built CLI master status/ensure/status/stop smoke with temporary KF_HOME/KF_CONFIG_HOME",
          "author": "dongkeren",
          "createdAt": "2026-07-09T07:34:54Z",
          "mergedAt": "2026-07-09T07:35:00Z",
          "additions": 469,
          "deletions": 25,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 51,
          "url": "https://github.com/kungfu-systems/build-images/pull/51",
          "title": "feat(buildchain): wire KFD123 evidence",
          "body": "## Summary\n- migrate Buildchain config to `.buildchain/buildchain.toml` and add a `v2` contract lock\n- pin local Buildchain/KFD tooling through pnpm and run Buildchain via `pnpm exec`\n- add generated KFD-1/2/3 evidence plus a `check:kfd` gate with release-passport smoke verification\n- enable release-passport KFD inputs in the Buildchain ref promotion workflow\n\n## Verification\n- `pnpm install --frozen-lockfile`\n- `pnpm run check`\n- `pnpm exec buildchain validate --require-version-state --require-lifecycle-stages verify,publish`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T07:19:16Z",
          "mergedAt": "2026-07-09T07:35:39Z",
          "additions": 3618,
          "deletions": 8,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 52,
          "url": "https://github.com/kungfu-systems/build-images/pull/52",
          "title": "chore(alpha): promote KFD123 buildchain config",
          "body": "## Summary\n- promote build-images KFD123 Buildchain config wiring from dev/v1/v1.2 to alpha/v1/v1.2\n- includes .buildchain config layout, v2 contract lock, pinned Buildchain/KFD tooling, and release-passport KFD inputs\n\n## Verification\n- dev/v1/v1.2 Verify passed on merge commit 1d9e969\n- PR #51 checks passed before merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T07:36:51Z",
          "mergedAt": "2026-07-09T07:38:22Z",
          "additions": 3618,
          "deletions": 8,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 53,
          "url": "https://github.com/kungfu-systems/build-images/pull/53",
          "title": "fix(buildchain): keep KFD evidence stable across release bumps",
          "body": "## Summary\n- make generated KFD evidence stable when Buildchain temporarily bumps package.json during release version verification\n- pin generated evidence timestamps and remove build-machine cwd/product version drift from tracked KFD artifacts\n\n## Verification\n- `pnpm run check`\n- temp detached worktree: set package.json version to `1.2.1-alpha.0`, ran `pnpm run check:kfd`, and only package.json changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T07:48:17Z",
          "mergedAt": "2026-07-09T07:54:47Z",
          "additions": 59,
          "deletions": 33,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 55,
          "url": "https://github.com/kungfu-systems/build-images/pull/55",
          "title": "fix(alpha): keep KFD evidence stable across release bumps",
          "body": "## Summary\n- cherry-pick the KFD evidence stability fix onto alpha/v1/v1.2\n- prevents Buildchain release version verification from seeing KFD evidence drift after temporary package.json version bumps\n\n## Verification\n- PR #53 checks passed on dev\n- local temp worktree bump test only changed package.json\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T07:56:02Z",
          "mergedAt": "2026-07-09T07:57:48Z",
          "additions": 59,
          "deletions": 33,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 439,
          "url": "https://github.com/kungfu-systems/kungfu/pull/439",
          "title": "feat(storage): fsck distinguishes redacted/absent from missing payloads",
          "body": "Merge feature/storage-fsck-payload-status into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-09T08:04:20Z",
          "mergedAt": "2026-07-09T08:04:25Z",
          "additions": 94,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 56,
          "url": "https://github.com/kungfu-systems/build-images/pull/56",
          "title": "chore(alpha): retrigger KFD123 promotion gate",
          "body": "## Summary\n- retrigger Buildchain promotion through an allowed publish-gate/alpha source branch\n- keep the build-images content tree unchanged after the KFD123 + contract-lock integration already landed\n\n## Verification\n- no file changes in this PR; provenance-only gate repair\n- prior alpha head passed repository check and KFD123 verification in Buildchain Ref Promotion run 29003186390 before governance source validation",
          "author": "dongkeren",
          "createdAt": "2026-07-09T08:07:56Z",
          "mergedAt": "2026-07-09T08:09:29Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 57,
          "url": "https://github.com/kungfu-systems/build-images/pull/57",
          "title": "chore(alpha): lock KFD123 promotion source",
          "body": "## Summary\n- retrigger Buildchain alpha promotion through the strict publish-gate/alpha/v1/v1.2/1.2.1-alpha.0 source-lock branch shape\n- keep the build-images content tree unchanged; KFD123, pnpm support, and contract lock are already present on alpha\n\n## Verification\n- prior promotion run 29003832640 passed repository check and KFD123 verification before rejecting the earlier non-canonical publish-gate branch name\n- this PR is provenance-only and carries the strict Buildchain publish-gate source-ref format",
          "author": "dongkeren",
          "createdAt": "2026-07-09T08:11:07Z",
          "mergedAt": "2026-07-09T08:12:42Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 935,
          "url": "https://github.com/kungfu-systems/buildchain/pull/935",
          "title": "fix(verify): resolve npm artifact integrity",
          "body": "## Summary\n- resolve `npm:<name>@<version>` subject digests from npm registry `dist.integrity`\n- match resolved npm integrity against release passport artifacts, packageSet, and publish evidence\n- add `--npm-registry` for custom registries on verify/explain/inspect artifact commands\n- cover main and platform npm package verification with a local registry/passport fixture\n\nFixes #927.\n\n## Verification\n- `node --test tests/release-passport.test.mjs`\n- `corepack pnpm run generate:site && corepack pnpm run build`\n- `corepack pnpm run check`\n- `node bin/buildchain.mjs verify artifact npm:@kungfu-tech/libnode@22.22.3-kf.3-alpha.18 --repository kungfu-systems/libnode --tag v22.22.3-kf.3-alpha.18 --json`\n- `node bin/buildchain.mjs verify artifact npm:@kungfu-tech/libnode-darwin-arm64@22.22.3-kf.3-alpha.18 --repository kungfu-systems/libnode --tag v22.22.3-kf.3-alpha.18 --json`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T08:11:51Z",
          "mergedAt": "2026-07-09T08:19:02Z",
          "additions": 244,
          "deletions": 39,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 440,
          "url": "https://github.com/kungfu-systems/kungfu/pull/440",
          "title": "feat(storage): add episode manifest v1",
          "body": "Adds yijinjing-backed Episode manifest v1 records, runtime storage service APIs, CLI commands, fsck coverage, tests, and ADR updates.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T08:28:21Z",
          "mergedAt": "2026-07-09T08:28:30Z",
          "additions": 1880,
          "deletions": 34,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 441,
          "url": "https://github.com/kungfu-systems/kungfu/pull/441",
          "title": "feat(product): rename GUI product to Kungfu Episodes",
          "body": "## Summary\\n- Rename the GUI desktop product/display artifact from Kungfu to Kungfu Episodes.\\n- Project the new product display name into Buildchain KFD evidence and release passport inputs.\\n- Update GUI visible labels and product docs that reference the app bundle / dmg name.\\n\\n## Validation\\n- ./kungfu-code kfd:buildchain\\n- ./kungfu-code kfd:buildchain:check\\n- ./kungfu-code check:types\\n- ./kungfu-code product gui dist --dry-run\\n- ./kungfu-code check\\n- ./kungfu-code build:app\\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T08:54:22Z",
          "mergedAt": "2026-07-09T09:00:35Z",
          "additions": 81,
          "deletions": 69,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 936,
          "url": "https://github.com/kungfu-systems/buildchain/pull/936",
          "title": "chore(release): promote v2.11 alpha",
          "body": "## Summary\nPromote current `dev/v2/v2.11` into the alpha channel for the next Buildchain v2.11 patch release.\n\nIncluded since the current alpha channel:\n- `fix(kfd): unify generated output layout`\n- `fix(verify): resolve npm artifact integrity`\n- recent publication/release verification fixes already on dev\n\n## Verification\n- dev branch checks passed on merged PRs\n- channel PR checks must pass before merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T08:51:23Z",
          "mergedAt": "2026-07-09T09:02:07Z",
          "additions": 670,
          "deletions": 247,
          "changedFiles": 37
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 442,
          "url": "https://github.com/kungfu-systems/kungfu/pull/442",
          "title": "docs(readme): clarify Kungfu Episodes naming",
          "body": "Merge docs/readme-brand-episodes into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-09T09:04:13Z",
          "mergedAt": "2026-07-09T09:04:20Z",
          "additions": 11,
          "deletions": 7,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 937,
          "url": "https://github.com/kungfu-systems/buildchain/pull/937",
          "title": "chore(release): promote v2.11.1",
          "body": "Promotes the verified v2.11 alpha channel to stable release.\n\nSource alpha evidence:\n- Alpha tag: v2.11.1-alpha.1\n- Alpha promotion run: https://github.com/kungfu-systems/buildchain/actions/runs/29006978697\n- Includes #934 and #935 fixes from dev/v2/v2.11.\n\nRelease path remains channel-governed: alpha/v2/v2.11 -> release/v2/v2.11, then Buildchain Ref Promotion performs the stable release transaction.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T09:08:54Z",
          "mergedAt": "2026-07-09T09:11:51Z",
          "additions": 681,
          "deletions": 258,
          "changedFiles": 39
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 444,
          "url": "https://github.com/kungfu-systems/kungfu/pull/444",
          "title": "refactor(location): rename group to namespace",
          "body": "Renames the v4 Location middle identity segment from group to namespace across yijinjing schema, C++ runtime, Python/Node bindings, capability API, GUI extensions, docs, and stubs. Keeps path shape unchanged and preserves narrow legacy group input fallback while canonicalizing output to namespace.\\n\\nValidation:\\n- ./kungfu-code build\\n- ./kungfu-code check\\n- Python namespace binding smoke\\n- Node IODevice namespace/legacy-group smoke",
          "author": "dongkeren",
          "createdAt": "2026-07-09T09:20:43Z",
          "mergedAt": "2026-07-09T09:20:49Z",
          "additions": 334,
          "deletions": 225,
          "changedFiles": 66
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 443,
          "url": "https://github.com/kungfu-systems/kungfu/pull/443",
          "title": "fix(product): rename CLI archive for Kungfu Episodes",
          "body": "## Summary\n- rename the CLI product archive/staging basename to `kungfu-episodes-cli-<platform>`\n- add a focused product dist test for the CLI archive basename\n\n## Validation\n- `./kungfu-code sync`\n- `node --test product/scripts/dist.test.mjs`\n- `./kungfu-code check:types`\n- `./kungfu-code check`\n- `./kungfu-code kfd:buildchain:check`\n- `./kungfu-code product cli dist --dry-run`\n- `git diff --check`\n- `node --check product/scripts/dist.mjs && node --check product/scripts/dist.test.mjs`",
          "author": "dongkeren",
          "createdAt": "2026-07-09T09:19:31Z",
          "mergedAt": "2026-07-09T09:22:52Z",
          "additions": 30,
          "deletions": 9,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 939,
          "url": "https://github.com/kungfu-systems/buildchain/pull/939",
          "title": "chore(release): recover v2.11.1 stable promotion",
          "body": "Adds an empty release-intent commit through the Buildchain release-line recovery ref pattern so stable promotion can run after #937 rebase-merged an alpha prepare commit.\n\nContext:\n- #937 advanced release/v2/v2.11 to alpha evidence v2.11.1-alpha.1.\n- The resulting release branch HEAD title starts with `chore(release): prepare v`, which Buildchain Ref Promotion intentionally skips.\n- This PR uses the accepted `fix/release-line-v2-v2.11-*` recovery head ref and changes no files.\n\nExpected outcome: release/v2/v2.11 Verify succeeds from a non-prepare release-intent commit, then Buildchain Ref Promotion publishes v2.11.1 stable.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T09:23:19Z",
          "mergedAt": "2026-07-09T09:35:02Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 940,
          "url": "https://github.com/kungfu-systems/buildchain/pull/940",
          "title": "chore(release): merge-trigger v2.11.1 stable promotion",
          "body": "Adds an empty release-intent commit through the accepted Buildchain release-line recovery ref pattern.\n\nThis PR must be merged with a merge commit, not rebase, so release/v2/v2.11 gets a non-prepare HEAD and the Verify workflow_run can trigger stable Buildchain Ref Promotion.\n\nContext:\n- #937 advanced release/v2/v2.11 to v2.11.1-alpha.1 evidence, but the HEAD title was `chore(release): prepare v...`, which promotion intentionally skips.\n- #939 was rebase-merged; GitHub dropped the empty commit, so release/v2/v2.11 did not advance.\n- This PR changes no files and exists only to create the release-intent merge commit under branch protection.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T09:36:05Z",
          "mergedAt": "2026-07-09T09:37:34Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 445,
          "url": "https://github.com/kungfu-systems/kungfu/pull/445",
          "title": "feat(storage): make episodes first-class storage slices",
          "body": "Implements Episode-owned storage slice v1: generic storage scope=episode fsck/query/export surfaces backed by yijinjing Episode manifests, plus CLI/Python wiring, docs, and storage tests.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T09:47:22Z",
          "mergedAt": "2026-07-09T09:47:27Z",
          "additions": 295,
          "deletions": 21,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 942,
          "url": "https://github.com/kungfu-systems/buildchain/pull/942",
          "title": "fix(promote): accept release recovery trigger trees",
          "body": "## Summary\n- allow release-branch Verify workflow_run events to promote prepare commits\n- accept release-line recovery PR triggers when their tree is equivalent to exact alpha evidence\n- keep post-alpha release version-state changes constrained by existing allowlist checks\n\n## Validation\n- node --test tests/promote-buildchain-ref.test.mjs\n- node --test tests/build-surface.test.mjs\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-09T09:47:44Z",
          "mergedAt": "2026-07-09T09:51:38Z",
          "additions": 148,
          "deletions": 47,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 944,
          "url": "https://github.com/kungfu-systems/buildchain/pull/944",
          "title": "chore(release): sync alpha v2.11 state to dev",
          "body": "## Summary\n- Sync the current alpha/v2/v2.11 generated version state back into dev/v2/v2.11.\n- Keeps the release-promotion recovery fix already merged in dev.\n- Restores a clean dev -> alpha promotion path.\n\n## Validation\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-09T09:56:28Z",
          "mergedAt": "2026-07-09T09:58:43Z",
          "additions": 12,
          "deletions": 12,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 943,
          "url": "https://github.com/kungfu-systems/buildchain/pull/943",
          "title": "chore(release): promote Buildchain v2.11 alpha",
          "body": "## Summary\n- Promote dev/v2/v2.11 to alpha/v2/v2.11 for the next Buildchain v2.11 alpha.\n- Includes release recovery trigger governance fix from PR #942.\n\n## Release intent\n- Channel: alpha\n- Line: v2.11\n- Expected: publish alpha only before stable release promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T09:52:23Z",
          "mergedAt": "2026-07-09T10:05:43Z",
          "additions": 148,
          "deletions": 47,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 446,
          "url": "https://github.com/kungfu-systems/kungfu/pull/446",
          "title": "fix(storage): preserve Atlas range export context",
          "body": "## Summary\n- preserve Atlas range exports as context-closed slices\n- record goal-to-mission source refs in Atlas manifest entries, with fallback for older manifests\n- document Atlas JSONL range export semantics\n\n## Validation\n- ./kungfu-code build\n- PYTHONPATH=\"$PWD/framework/core/src/python:$PWD/framework/core/build/Release\" uv run --project framework/core python -m pytest framework/core/tests/python/test_atlas_storage.py -q\n- ./kungfu-code check\n- CLI smoke: import/export/verify /Users/dkr/Code/atlas from 2026-06-29T00:00:00Z, 739 records, matching sync root, verify ok",
          "author": "dongkeren",
          "createdAt": "2026-07-09T10:27:33Z",
          "mergedAt": "2026-07-09T10:27:40Z",
          "additions": 158,
          "deletions": 36,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 946,
          "url": "https://github.com/kungfu-systems/buildchain/pull/946",
          "title": "chore(release): publish-gate Buildchain v2.11.1",
          "body": "## Summary\n- Use a strict publish-gate/release source branch for the v2.11.1 stable promotion.\n- The branch is based on release/v2/v2.11 and merges the verified alpha/v2/v2.11 material, resolving the existing release recovery ancestry conflict.\n- Includes the v2.11.1-alpha.2 material and release recovery trigger fix.\n\n## Validation\n- pnpm run check\n\n## Supersedes\n- Supersedes #945, which is dirty because release/v2/v2.11 already contains a recovery merge commit.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T10:23:41Z",
          "mergedAt": "2026-07-09T10:31:48Z",
          "additions": 238,
          "deletions": 59,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 447,
          "url": "https://github.com/kungfu-systems/kungfu/pull/447",
          "title": "fix(core): run ruff lint in the changed-scope check gate",
          "body": "Merge feature/ruff-lint-gate into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-09T10:39:14Z",
          "mergedAt": "2026-07-09T10:39:21Z",
          "additions": 47,
          "deletions": 29,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 948,
          "url": "https://github.com/kungfu-systems/buildchain/pull/948",
          "title": "fix(release): accept publish-gate release verify refs",
          "body": "## Summary\n- teach release-line verify policy to accept publish-gate alpha/release PR refs\n- keep publish-gate channel and release-line matching fail-closed before promotion\n- add regression coverage for alpha/release publish-gate verify paths\n\n## Validation\n- node --test tests/release-line-policy.test.mjs\n- corepack pnpm run check\n\n## Release note\nThis fix must land through dev -> alpha before the stable v2.11.1 release promotion can satisfy tree-equivalence against the latest alpha tag.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T10:41:04Z",
          "mergedAt": "2026-07-09T10:53:37Z",
          "additions": 78,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 448,
          "url": "https://github.com/kungfu-systems/kungfu/pull/448",
          "title": "feat(config): resolve workspace data home",
          "body": "## Summary\n- Resolve workspace-local `.kungfu` data homes from existing `.kungfu` ancestors or the git workspace root.\n- Keep config under `~/.kungfu-config` / `KF_CONFIG_HOME` while exposing `workspaceDataHome` and `machineDataHome` in config path output.\n- Make product dev launchers use workspace data homes without creating isolated instance config.\n\n## Validation\n- ./kungfu-code build\n- ./kungfu-code check\n- node --test product/scripts/product.test.mjs\n- pnpm --filter @kungfu-tech/skill run build\n- PYTHONPATH=\"$PWD/framework/core/src/python:$PWD/framework/core/build/Release\" uv run --project framework/core python -m pytest framework/core/tests/python/test_skill.py -q\n- CLI smoke for workspace `.kungfu`, explicit `KF_HOME`, and machine fallback",
          "author": "dongkeren",
          "createdAt": "2026-07-09T10:58:38Z",
          "mergedAt": "2026-07-09T10:58:45Z",
          "additions": 459,
          "deletions": 34,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 949,
          "url": "https://github.com/kungfu-systems/buildchain/pull/949",
          "title": "chore(release): promote v2.11 dev to alpha",
          "body": "## Summary\n- promote dev/v2/v2.11 to alpha after publish-gate release verify policy fix\n- required before retrying stable v2.11.1 so release and alpha trees match except version-state files\n\n## Validation\n- dev PR #948 passed check and Build Surface Fixture\n- local corepack pnpm run check passed on the fix branch",
          "author": "dongkeren",
          "createdAt": "2026-07-09T10:54:14Z",
          "mergedAt": "2026-07-09T11:00:49Z",
          "additions": 78,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 951,
          "url": "https://github.com/kungfu-systems/buildchain/pull/951",
          "title": "chore(release): refresh alpha v2.11 candidate",
          "body": "## Summary\n- add a no-op release candidate refresh commit after #949 was merged before its PR-stage RC fixture completed\n- lets the next dev->alpha PR produce required PR-stage release-candidate evidence without changing source tree content\n\n## Validation\n- no source tree changes; previous fix branch passed corepack pnpm run check\n\n## Release note\nThis is a governance refresh commit only; it exists to produce a fresh auditable dev head for alpha promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T11:11:26Z",
          "mergedAt": "2026-07-09T11:17:53Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 952,
          "url": "https://github.com/kungfu-systems/buildchain/pull/952",
          "title": "chore(release): refresh alpha v2.11 candidate",
          "body": "## Summary\n- promote refreshed dev head to alpha so PR-stage release-candidate artifacts exist before alpha promotion\n- no source tree changes beyond the already merged publish-gate verify policy fix\n\n## Validation\n- PR #951 passed check and Build Surface Fixture before merging to dev\n\n## Release note\nWait for this PR's Build Surface Fixture to finish before merging; alpha promotion consumes that PR-stage RC evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T11:18:23Z",
          "mergedAt": "2026-07-09T11:20:48Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 953,
          "url": "https://github.com/kungfu-systems/buildchain/pull/953",
          "title": "chore(release): publish v2.11.1",
          "body": "## Summary\n- promote the currently tested v2.11.1-alpha.3 source into the v2.11 stable release channel\n- keep release finalization under Buildchain publish-gate governance\n\n## Validation\n- PR-stage Release - Verify must pass\n- PR-stage Build Surface Fixture must finish before merge so promote-only release can reuse the RC evidence\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T11:40:35Z",
          "mergedAt": "2026-07-09T11:42:29Z",
          "additions": 90,
          "deletions": 12,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 449,
          "url": "https://github.com/kungfu-systems/kungfu/pull/449",
          "title": "feat(storage): expose workspace episode layout",
          "body": "## Summary\n- add a C++ storage service layout operation for workspace Episode storage paths\n- expose `kungfu storage layout --json` through the Python CLI\n- document the `.kungfu/runtime` Episode layout and verify Python/Node storage bindings\n\n## Validation\n- ./kungfu-code build\n- ./kungfu-code check\n- PYTHONPATH=\"$PWD/src/python:$PWD/dist/kungfu\" DYLD_FALLBACK_LIBRARY_PATH=\"$PWD/dist/kungfu:${DYLD_FALLBACK_LIBRARY_PATH:-}\" uv run --frozen pytest tests/python/test_atlas_storage.py::test_runtime_storage_service_surface_is_bound_from_libkungfu tests/python/test_atlas_storage.py::test_python_storage_operations_enter_runtime_service_surface tests/python/test_atlas_storage.py::test_episode_manifest_v1_is_yijinjing_backed_and_fscked -q\n- KUNGFU_DIR=\"$PWD/dist/kungfu\" DYLD_FALLBACK_LIBRARY_PATH=\"$PWD/dist/kungfu:${DYLD_FALLBACK_LIBRARY_PATH:-}\" pnpm run test:storage-binding\n- frozen CLI `kungfu storage layout --json` smoke",
          "author": "dongkeren",
          "createdAt": "2026-07-09T12:01:39Z",
          "mergedAt": "2026-07-09T12:03:20Z",
          "additions": 261,
          "deletions": 0,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 450,
          "url": "https://github.com/kungfu-systems/kungfu/pull/450",
          "title": "docs(adr): unified view interface as sole FlatBuffers access point",
          "body": "Merge feature/unified-view-interface-fb-encapsulation into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-09T12:22:17Z",
          "mergedAt": "2026-07-09T12:22:23Z",
          "additions": 153,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 451,
          "url": "https://github.com/kungfu-systems/kungfu/pull/451",
          "title": "feat(storage): attach episodes to runtime lifecycles",
          "body": "## Summary\n- wrap rewind trace, managed-run, and reported run paths in runtime Episode lifecycles\n- attach action recorder frame receipts and payload refs to Episode manifests\n- validate Episode list/inspect/fsck/export through the rewind demo fixture\n\n## Validation\n- ./kungfu-code build\n- ./kungfu-code check\n- cd framework/core && DYLD_FALLBACK_LIBRARY_PATH=dist/kungfu PYTHONPATH=src/python:dist/kungfu uv run --frozen pytest tests/python/test_atlas_storage.py -q\n- node tests/fixtures/rewind-demo-happy/run.mjs",
          "author": "dongkeren",
          "createdAt": "2026-07-09T12:35:39Z",
          "mergedAt": "2026-07-09T12:35:45Z",
          "additions": 339,
          "deletions": 117,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 54,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/54",
          "title": "Upgrade Buildchain and KFD site bundles",
          "body": "## Summary\n\n- pin `@kungfu-tech/buildchain` to `2.11.1`\n- pin `@kungfu-tech/kfd` to `1.0.0-alpha.22`\n- update renderer/check constants and docs to match the consumed upstream package versions\n\n## Verification\n\n```bash\npnpm install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/ --config.minimumReleaseAge=0\npnpm run build\npnpm run check\n```\n\n## Notes\n\nBuildchain `2.11.1` still does not publish `dist/site/publication-registry.json`, so `papers.libkungfu.dev` remains fixture-backed. Tracked upstream as kungfu-systems/buildchain#954.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T12:35:25Z",
          "mergedAt": "2026-07-09T12:38:49Z",
          "additions": 27,
          "deletions": 22,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 452,
          "url": "https://github.com/kungfu-systems/kungfu/pull/452",
          "title": "feat(storage): expose episode causal graph diagnostics",
          "body": "## Summary\n- add kungfu.episode.causal-graph/v1 projection from the C++ yijinjing Episode manifest fold\n- surface dependencies/degraded status through episode inspect, storage export, and fsck\n- cover declared external triggers and degraded missing dependency/payload cases\n\n## Validation\n- ./kungfu-code build\n- DYLD_FALLBACK_LIBRARY_PATH=dist/kungfu PYTHONPATH=src/python:dist/kungfu uv run --frozen pytest tests/python/test_atlas_storage.py -q\n- node tests/fixtures/rewind-demo-happy/run.mjs\n- ./kungfu-code check",
          "author": "dongkeren",
          "createdAt": "2026-07-09T14:23:00Z",
          "mergedAt": "2026-07-09T14:23:06Z",
          "additions": 330,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 58,
          "url": "https://github.com/kungfu-systems/build-images/pull/58",
          "title": "fix(ci): publish build-images release passports",
          "body": "## Summary\n- enable Buildchain release-passport generation on the default-branch promotion workflow\n- enable GitHub Release upload for publish evidence and release passport assets\n- pass build-images KFD-1/2/3 evidence paths into the passport generator\n\n## Verification\n- ruby YAML parse for .github/workflows/buildchain-ref-promotion.yml",
          "author": "dongkeren",
          "createdAt": "2026-07-09T14:22:57Z",
          "mergedAt": "2026-07-09T14:23:56Z",
          "additions": 9,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 59,
          "url": "https://github.com/kungfu-systems/build-images/pull/59",
          "title": "fix(ci): expose workspace node modules to buildchain action",
          "body": "## Summary\n- expose the checked-out workspace node_modules to the Buildchain action via NODE_PATH\n- unblock release-passport KFD evidence generation in the default-branch promotion workflow\n\n## Verification\n- ruby YAML parse for .github/workflows/buildchain-ref-promotion.yml\n- prior promotion run 29025253898 proved the new release-passport/github-release configuration is active and failed only on @kungfu-tech/kfd module resolution",
          "author": "dongkeren",
          "createdAt": "2026-07-09T14:26:25Z",
          "mergedAt": "2026-07-09T14:27:13Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 453,
          "url": "https://github.com/kungfu-systems/kungfu/pull/453",
          "title": "chore(buildchain): adopt v2 kfd contract management",
          "body": "## Summary\n- upgrade Buildchain to 2.11.1 and refresh the v2 contract lock\n- migrate repository-owned KFD evidence into the Buildchain-managed .buildchain/kfd layout\n- wire build and release workflows to the Buildchain v2 contract-lock path\n\n## Verification\n- ./kungfu-code kfd:buildchain:check\n- ./kungfu-code check\n- git diff --check\n- buildchain doctor --cwd . --require-publish-source-lock --json\n\n## Risk\n- KFD evidence paths moved from legacy roots to .buildchain/kfd/kfd-1|kfd-2|kfd-3. Scripts and release workflow references were updated together.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T14:30:16Z",
          "mergedAt": "2026-07-09T14:31:16Z",
          "additions": 4681,
          "deletions": 157,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 955,
          "url": "https://github.com/kungfu-systems/buildchain/pull/955",
          "title": "fix(site): publish publication registry bundle",
          "body": "## Summary\n- add dist/site/publication-registry.json as the package-owned publication archive registry for downstream papers surfaces\n- export @kungfu-tech/buildchain/site/publication-registry.json and include it in site/KFD claim registries\n- document the publication registry consumption contract and regenerate the site bundle\n\n## Validation\n- corepack pnpm@11.7.0 run check\n- node --input-type=module import @kungfu-tech/buildchain/site/publication-registry.json\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/ confirms dist/site/publication-registry.json is packaged\n- publication-registry fixture digest smoke\n\nFixes #954",
          "author": "dongkeren",
          "createdAt": "2026-07-09T14:41:34Z",
          "mergedAt": "2026-07-09T14:44:02Z",
          "additions": 293,
          "deletions": 33,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 454,
          "url": "https://github.com/kungfu-systems/kungfu/pull/454",
          "title": "feat(view): encapsulate FlatBuffers access behind kungfu::view (ADR-0039 slice 1)",
          "body": "Confine all open-layer FlatBuffers/reflection access to one runtime-independent chokepoint (kungfu::view) so the .bfbs dangling-view bug is structurally unrepresentable (ADR-0039, accepted). schema_handle co-owns its .bfbs bytes and never hands out a bare reflection view; pod.h keeps the hot path zero-cost; a CI boundary guard fails the build on raw flatbuffers::/reflection:: outside the module; a capability slice proves the projection roundtrip. Full core build green; projection roundtrip equivalent to the pre-migration path. schema_compiler migration is the next slice.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T14:52:55Z",
          "mergedAt": "2026-07-09T14:53:01Z",
          "additions": 823,
          "deletions": 198,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 455,
          "url": "https://github.com/kungfu-systems/kungfu/pull/455",
          "title": "feat(storage): add episode repair plans",
          "body": "## Summary\n- add C++ storage repair_plan operation for degraded Episode/source diagnostics\n- expose read-only kungfu storage repair --plan --dry-run CLI\n- validate Episode bundle import evidence without mutating the manifest journal\n\n## Validation\n- ./kungfu-code build\n- ./kungfu-code check\n- DYLD_FALLBACK_LIBRARY_PATH=dist/kungfu PYTHONPATH=src/python:dist/kungfu uv run --frozen pytest tests/python/test_atlas_storage.py -q\n- KUNGFU_DIR=$PWD/dist/kungfu node --test tests/storage-node-binding.test.js\n- CLI smoke: kungfu storage repair --scope episode --episode-id 7 --plan --dry-run --json",
          "author": "dongkeren",
          "createdAt": "2026-07-09T14:53:00Z",
          "mergedAt": "2026-07-09T14:53:05Z",
          "additions": 492,
          "deletions": 42,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 57,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/57",
          "title": "Adopt Buildchain dotdir layout",
          "body": "## Summary\n- move Buildchain config and contract lock into the canonical .buildchain/ directory\n- update the web-surface workflow, checks, and docs to use .buildchain/contract-lock.json and .buildchain/buildchain.toml\n- keep KFD upstream propagation compatible with the canonical .buildchain/upstreams path while retaining a legacy fallback for existing Buildchain output\n\n## Verification\n- pnpm install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/ --config.minimumReleaseAge=0\n- pnpm run build\n- pnpm run check\n- pnpm exec buildchain kfd status --json\n- pnpm exec buildchain validate --cwd . --require-lifecycle-stages build,verify\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-09T14:46:58Z",
          "mergedAt": "2026-07-09T14:53:58Z",
          "additions": 46,
          "deletions": 17,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 957,
          "url": "https://github.com/kungfu-systems/buildchain/pull/957",
          "title": "fix(kfd): bundle release gate metadata",
          "body": "## Summary\n- statically import KFD package metadata, standards, and trust taxonomy in the release gate module\n- rebuild promote-buildchain-ref so release-passport KFD gates do not require consumer NODE_PATH\n- add a regression test that prevents kfd-gate from reintroducing runtime require.resolve metadata lookup\n\n## Validation\n- corepack pnpm@11.7.0 exec node --test tests/release-passport.test.mjs\n- corepack pnpm@11.7.0 --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- promote action bundle smoke: no @kungfu-tech/kfd runtime package resolution remains\n- corepack pnpm@11.7.0 run check\n\nFixes #956",
          "author": "dongkeren",
          "createdAt": "2026-07-09T14:55:14Z",
          "mergedAt": "2026-07-09T14:57:39Z",
          "additions": 117,
          "deletions": 90,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 58,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/58",
          "title": "Release production from b3f23543ee49",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `b3f23543ee49bd6e054faa2212ab7e5b68673bb4`\n- Artifact hash: `67582e5fbbb74f1167853bea7fa1af584342f47f54720a0475c5c7a6d0eb341d`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29027270137)\n- Required label: `buildchain-release`\n- Release branch: `release/production-b3f23543ee49`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-09T15:00:13Z",
          "mergedAt": "2026-07-09T15:06:07Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 456,
          "url": "https://github.com/kungfu-systems/kungfu/pull/456",
          "title": "fix(slices): retarget capability slices to the yijinjing journal core",
          "body": "The schema-registry and fact-ledger capability slices link only the yijinjing\nstatic library, but four sources still opened with `using namespace\nkungfu::runtime;` left over from the runtime/storage public-API split (only the\nembedding slice was verified there). Those runtime data/journal/time aliases\ncome from <kungfu/runtime/common.h>, which the slices do not include, so the\nnames stopped resolving against their <kungfu/yijinjing/*> includes and\n`cmake --build … -DKUNGFU_WITH_SLICES=ON` failed.\n\nThis retargets producer.cpp, decoder.cpp, host.cpp and export.cpp to\nkungfu::yijinjing (matching their includes, link library, and the embedding\nslice), and follows the frame `msg_type` -> `carrier_type` rename on the read\npath. The emitted `msg_type` bundle field is unchanged.\n\nVerified (KUNGFU_WITH_SLICES=ON): built all four targets; `node\nslices/schema-registry/run.mjs build` passes; `fact_ledger_host` +\n`fact_ledger_export` verified end-to-end (segment checksum + causal chain).",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:08:31Z",
          "mergedAt": "2026-07-09T15:08:36Z",
          "additions": 8,
          "deletions": 8,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 958,
          "url": "https://github.com/kungfu-systems/buildchain/pull/958",
          "title": "chore(release): promote v2.11.2 alpha",
          "body": "## Summary\n- promote current dev/v2/v2.11 fixes to alpha/v2/v2.11\n- includes publication registry site bundle and bundled KFD release gate metadata fixes\n\n## Validation\n- dev branch PR checks passed before merge\n- release promotion workflow will run after protected channel merge\n\nRelease path: dev/v2/v2.11 -> alpha/v2/v2.11",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:20:31Z",
          "mergedAt": "2026-07-09T15:23:25Z",
          "additions": 407,
          "deletions": 120,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 457,
          "url": "https://github.com/kungfu-systems/kungfu/pull/457",
          "title": "feat(storage): apply local episode repairs",
          "body": "## Summary\n- add C++ storage-service repair_apply for local Episode/source repair material\n- expose kungfu storage repair --apply --from with dry-run default and --execute mutation\n- document repair-apply safety boundaries and refresh KFD evidence\n\n## Validation\n- ./kungfu-code build\n- ./kungfu-code check\n- DYLD_FALLBACK_LIBRARY_PATH=dist/kungfu PYTHONPATH=src/python:dist/kungfu uv run --frozen pytest tests/python/test_atlas_storage.py -q\n- KUNGFU_DIR=\"$PWD/dist/kungfu\" node --test tests/storage-node-binding.test.js\n- CLI smoke: episode fsck degraded -> repair apply dry-run -> execute -> fsck ok",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:25:23Z",
          "mergedAt": "2026-07-09T15:25:29Z",
          "additions": 762,
          "deletions": 66,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 960,
          "url": "https://github.com/kungfu-systems/buildchain/pull/960",
          "title": "fix(release): allow publication registry version state",
          "body": "Fixes #959.\n\n## Summary\n- include dist/site/publication-registry.json in Buildchain semver version-state files\n- verify publication-registry package.version matches package.json\n- update version-state contract test expectation\n\n## Verification\n- node scripts/check-inventory.mjs\n- node --test tests/build-surface.test.mjs\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:32:09Z",
          "mergedAt": "2026-07-09T15:34:23Z",
          "additions": 10,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 458,
          "url": "https://github.com/kungfu-systems/kungfu/pull/458",
          "title": "feat(view): route .fbs compile through kungfu::view; flip FB gate strict (ADR-0039 slice 2)",
          "body": "Complete ADR-0039: no flatbuffers::/reflection:: symbol appears outside kungfu::view. Adds view::compile_schema (the sole .fbs->.bfbs compile entry), makes schema_compiler delegate to it (keeping only trust-tier policy), and removes the schema_compiler allowlist so the boundary gate is strict. Full core build green; view-encapsulation probe (now exercising compile_schema) passes under the strict gate; py-runtime unchanged (marshals compiled bytes, holds no reflection view). Validated C++ (standalone harness) and Python (pykungfu.runtime.compile_schema).",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:34:45Z",
          "mergedAt": "2026-07-09T15:34:51Z",
          "additions": 67,
          "deletions": 33,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 961,
          "url": "https://github.com/kungfu-systems/buildchain/pull/961",
          "title": "chore(release): promote v2.11.2 alpha",
          "body": "## Summary\n- promote dev/v2/v2.11 to alpha/v2/v2.11 after fixing publication registry version-state gating\n\n## Notes\n- retries alpha promotion after #959 was resolved in #960",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:35:00Z",
          "mergedAt": "2026-07-09T15:38:00Z",
          "additions": 10,
          "deletions": 0,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 1,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/1",
          "title": "feat: package product-readable white paper",
          "body": "## Summary\n- Replace private project-specific dogfood names with public-safe real-work dogfood wording.\n- Strengthen the KFD-3 product stance: human-agent cooperation should start from trusted value, not hidden pressure.\n- Make the PDF read more like a commercial white paper: cover page, executive summary, reader guide, callout box, clearer visual hierarchy, and less academic-paper framing.\n- Add an npm package contract for the white paper with generated site bundles:\n  - `site/brand-site.json` for `kungfu.tech`\n  - `site/evidence-site.json` for `papers.libkungfu.dev`\n  - `site/site-bundles.json` as the bundle index\n- Add generator/check scripts so the bundles are derived from paper source and cannot silently drift.\n- Declare canonical routes for the brand and evidence sites.\n\n## Canonical URLs\n- Brand: https://kungfu.tech/whitepaper/kungfu-real-world-agent-work\n- Brand index: https://kungfu.tech/whitepaper\n- Brand PDF: https://kungfu.tech/whitepaper/kungfu-real-world-agent-work.pdf\n- Evidence: https://papers.libkungfu.dev/kungfu-product-white-paper\n\n## Validation\n- npm run check\n- make check\n- make pdf\n- npx -y @kungfu-tech/buildchain@2.10.10 validate --cwd . --json\n- npm pack --dry-run --json\n- git diff --check\n- Rendered PDF pages 1-2 for visual QA\n\n## Risk\n- Downstream site renderers still need to consume the new bundle contracts.\n- The white paper remains a draft and needs product-positioning review before public launch use.\n- Tectonic reports a non-blocking underfull hbox warning on the cover layout.",
          "author": "kungfu-origin",
          "createdAt": "2026-07-09T02:40:57Z",
          "mergedAt": "2026-07-09T15:46:46Z",
          "additions": 1913,
          "deletions": 143,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 459,
          "url": "https://github.com/kungfu-systems/kungfu/pull/459",
          "title": "feat(storage): source-registry records as Hana-core kernel journal (ADR-0037)",
          "body": "Move the ADR-0018 storage-service source-registry record family to Hana-core kernel metadata (ADR-0037): fixed-layout POD records written to an append-only yijinjing journal and folded into a current view, with JSON as an edge projection only. Exposed through the runtime storage service; end-to-end tests cover register/update-head/accepted-range round-trip, fsck, and dangling-head detection (22/22 storage tests pass). Accepts ADR-0037, validated by this slice.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:51:37Z",
          "mergedAt": "2026-07-09T15:51:43Z",
          "additions": 842,
          "deletions": 7,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 3,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/3",
          "title": "chore(release): trigger white paper alpha promotion",
          "body": "## Summary\n\n- create a same-repository release-channel PR into `alpha/v0/v0.1`\n- satisfy Buildchain release governance for alpha promotion\n- no content changes; the alpha branch already contains the white paper release candidate\n\n## Checks\n\n- release-channel PR checks will run on GitHub\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:49:34Z",
          "mergedAt": "2026-07-09T15:52:22Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 460,
          "url": "https://github.com/kungfu-systems/kungfu/pull/460",
          "title": "feat(storage): fetch local episode repair material",
          "body": "## Summary\n- Add C++ storage_service repair_fetch operation that consumes repair_plan output and collects local repair material from the runtime plus registered remote mirrors.\n- Expose repair fetch through Python and CLI as storage repair --fetch --out, and include it in agent/KFD discovery surfaces.\n- Extend remote mirror sync to include storage evidence and cover source/Episode repair-fetch-to-apply flows in tests.\n\n## Validation\n- ./kungfu-code build\n- ./kungfu-code check\n- PYTHONPATH=src/python:build/Release DYLD_FALLBACK_LIBRARY_PATH=build/Release uv run --frozen pytest tests/python/test_atlas_storage.py -q\n- KUNGFU_DIR=/Users/dkr/Worktrees/kungfu/feature/episode-repair-fetch-v1/framework/core/dist/kungfu pnpm --filter @kungfu-tech/core run test:storage-binding\n- CLI smoke: plan -> fetch --out -> apply --dry-run -> apply --execute -> fsck ok on /tmp/kungfu-repair-fetch.f7bB5X",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:52:57Z",
          "mergedAt": "2026-07-09T15:54:06Z",
          "additions": 601,
          "deletions": 53,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 965,
          "url": "https://github.com/kungfu-systems/buildchain/pull/965",
          "title": "feat(publication): add paper release preset",
          "body": "## Summary\n\n- add Buildchain-managed `paper-release.yml@v2` reusable workflow for publication-artifact npm publishing\n- add `buildchain publication-artifact npm-package` CLI and `@kungfu-tech/buildchain/publication-package` Node API\n- document the declarative paper release contract, Trusted Publishing setup, source lock, GitHub Release default, and site bundle surfaces\n\nFixes #962\n\n## Validation\n\n- `corepack pnpm@11.7.0 run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:59:31Z",
          "mergedAt": "2026-07-09T16:02:23Z",
          "additions": 1419,
          "deletions": 107,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 4,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/4",
          "title": "ci(buildchain): ignore runtime checkout",
          "body": "## Summary\\n- Ignore Buildchain's runtime checkout directory so promote-only version verification does not see it as an out-of-state file.\\n\\n## Verification\\n- npm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:59:52Z",
          "mergedAt": "2026-07-09T16:04:06Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 966,
          "url": "https://github.com/kungfu-systems/buildchain/pull/966",
          "title": "chore(release): promote v2.11.2 alpha",
          "body": "Promote the Buildchain v2.11.2 paper release preset work through alpha.\n\nIncludes #962 via PR #965.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T16:03:06Z",
          "mergedAt": "2026-07-09T16:05:07Z",
          "additions": 1419,
          "deletions": 107,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 5,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/5",
          "title": "release: promote white paper alpha runtime-ignore fix",
          "body": "## Summary\\n- Promote the Buildchain runtime ignore fix into the alpha channel.\\n\\n## Release\\n- Target channel: alpha/v0/v0.1\\n- Package: @kungfu-tech/paper-kungfu-product-white-paper@0.1.0-alpha.0\\n\\n## Verification\\n- Main PR #4 passed check and Buildchain publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T16:04:41Z",
          "mergedAt": "2026-07-09T16:07:01Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 968,
          "url": "https://github.com/kungfu-systems/buildchain/pull/968",
          "title": "chore(release): release v2.11.2",
          "body": "Promote Buildchain v2.11.2 from alpha to stable release.\n\nIncludes the paper release preset for #962 after alpha validation.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T16:09:18Z",
          "mergedAt": "2026-07-09T16:11:29Z",
          "additions": 1801,
          "deletions": 192,
          "changedFiles": 39
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 6,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/6",
          "title": "release: trigger white paper alpha publish from dev channel",
          "body": "## Summary\\n- Trigger the alpha package publication through the Buildchain-approved dev/v0/v0.1 -> alpha/v0/v0.1 channel path.\\n\\n## Release\\n- Target channel: alpha/v0/v0.1\\n- Package: @kungfu-tech/paper-kungfu-product-white-paper@0.1.0-alpha.0\\n\\n## Verification\\n- Alpha already contains PR #5 with the runtime ignore fix.\\n- This PR is an empty release trigger to satisfy Buildchain channel lineage.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T16:09:50Z",
          "mergedAt": "2026-07-09T16:11:59Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 461,
          "url": "https://github.com/kungfu-systems/kungfu/pull/461",
          "title": "feat(storage): rebuildable SQLite projection for source-registry (ADR-0037 slice 2)",
          "body": "Slice 2 of ADR-0037: project the source-registry kernel journal to a rebuildable SQLite cache via the compile-time Hana closed-set to SQLite path (make_storage_ptr over SourceRegistryDataTypes). Adds source_registry_rebuild; source_registry_fsck now verifies journal + projection, treating drift as degraded. Content-addressed payload bodies stay deferred to the payload/import slice. 24/24 storage tests pass.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T16:29:36Z",
          "mergedAt": "2026-07-09T16:29:42Z",
          "additions": 427,
          "deletions": 9,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 462,
          "url": "https://github.com/kungfu-systems/kungfu/pull/462",
          "title": "feat(view): verify open-layer frames at the access boundary (spatial safety)",
          "body": "Second hardening step under ADR-0039 (view-hardening parent). bind_frame now runs flatbuffers::Verify against the schema before any field access, so a malformed/truncated open-layer frame is skipped (returns std::optional nullopt), never dereferenced into an out-of-bounds reflection read. No unchecked variant: the open-layer projection is a cold async/batched path (per-frame verify is negligible next to the SQLite write) and the lock-free hot path (POD frame reads) carries no FlatBuffers and is untouched. project_frame returns bool; flush counts + warns skipped frames. Full core build green, view slice asserts truncated/garbage frames skip.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T20:29:53Z",
          "mergedAt": "2026-07-09T20:29:59Z",
          "additions": 66,
          "deletions": 21,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 463,
          "url": "https://github.com/kungfu-systems/kungfu/pull/463",
          "title": "feat(storage): payload bodies are opaque content-addressed bytes (ADR-0037)",
          "body": "Store payload bodies as opaque content-addressed bytes (storage/payloads/<hash-prefix>/<sha256>, no format-implying extension); the manifest entry commits to the body by hash, length, and content_type metadata. Aligns C++ runtime service and Python importer on the content-addressed path. Decouples and precedes the import-manifest migration. 25/25 storage tests pass.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T20:34:15Z",
          "mergedAt": "2026-07-09T20:34:21Z",
          "additions": 77,
          "deletions": 11,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 970,
          "url": "https://github.com/kungfu-systems/buildchain/pull/970",
          "title": "fix(web-surface): wait for CloudFront invalidations before health",
          "body": "## Summary\n- wait for applied CloudFront invalidations before web-surface health checks fetch public smoke URLs\n- add unit coverage for extracting invalidation wait targets from apply results\n- document the health-check ordering to avoid stale CloudFront 403 failures after successful deploy apply\n\n## Verification\n- `node --check scripts/web-surface.mjs && node --test tests/web-surface.test.mjs`\n- `pnpm run check`\n\n## Context\n`site-kungfu-tech` PR preview apply succeeds, but the health job can fetch CloudFront before the new invalidation reaches `Completed`, producing transient 403 failures even though the preview URL becomes healthy after invalidation propagation.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T20:42:30Z",
          "mergedAt": "2026-07-09T20:44:32Z",
          "additions": 168,
          "deletions": 13,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 971,
          "url": "https://github.com/kungfu-systems/buildchain/pull/971",
          "title": "chore(release): promote v2.11 web-surface health fix to alpha",
          "body": "## Summary\n- promote the web-surface health fix from dev/v2/v2.11 into the alpha channel\n- includes waiting for CloudFront invalidations before public smoke checks\n\n## Verification\n- source PR #970 passed Verify and Build Surface Fixture\n- local `pnpm run check` passed before merge\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T20:45:25Z",
          "mergedAt": "2026-07-09T20:47:36Z",
          "additions": 168,
          "deletions": 13,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 972,
          "url": "https://github.com/kungfu-systems/buildchain/pull/972",
          "title": "chore(release): promote v2.11.3 to stable",
          "body": "## Summary\n- promote Buildchain v2.11.3 alpha to the stable release line\n- carries the web-surface health fix that waits for CloudFront invalidations before public smoke checks\n\n## Evidence\n- alpha promotion published `2.11.3-alpha.1`\n- source fix PR #970 passed Verify and Build Surface Fixture\n- alpha channel PR #971 passed checks and promotion\n\n## Expected impact\n- moves stable `v2` / `v2.11` and npm `latest` to the patch release after promotion\n- lets web-surface consumers using `@v2` avoid transient stale CloudFront 403 health failures\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T20:51:13Z",
          "mergedAt": "2026-07-09T20:53:09Z",
          "additions": 183,
          "deletions": 28,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 973,
          "url": "https://github.com/kungfu-systems/buildchain/pull/973",
          "title": "fix(web-surface): retry transient health smoke failures",
          "body": "## Summary\n- retry transient HTTP 403/404/5xx responses during web-surface health smoke checks\n- record the number of HTTP attempts in health check output\n- document that health checks wait for CloudFront invalidations and then absorb short edge propagation windows\n\n## Verification\n- `node --test tests/web-surface.test.mjs`\n- `pnpm run generate:site && pnpm run check`\n\n## Context\n`site-kungfu-tech` preview apply now waits for CloudFront invalidation completion, but GitHub-hosted runner HTTP smoke can still observe a short stale 403 window immediately after the waiter returns. Manual checks succeed seconds later. The health check should stay strict while retrying these transient edge states.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T21:11:44Z",
          "mergedAt": "2026-07-09T21:13:43Z",
          "additions": 104,
          "deletions": 13,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 974,
          "url": "https://github.com/kungfu-systems/buildchain/pull/974",
          "title": "chore(release): promote web-surface health retry to alpha",
          "body": "## Summary\n- promote web-surface health retry fix to alpha\n- carries the retry for transient 403/404/5xx public smoke failures after CloudFront invalidation wait\n\n## Evidence\n- source PR #973 passed Verify and Build Surface Fixture\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T21:13:58Z",
          "mergedAt": "2026-07-09T21:16:10Z",
          "additions": 104,
          "deletions": 13,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 975,
          "url": "https://github.com/kungfu-systems/buildchain/pull/975",
          "title": "chore(release): promote v2.11.4 to stable",
          "body": "Promote Buildchain v2.11.4 to stable.\n\nThis release includes the web-surface health smoke retry fix after CloudFront invalidation waits. It keeps the generated site workflow from failing on short-lived 403/404/5xx responses immediately after the invalidation has completed.\n\nValidation already completed on alpha:\n- alpha promotion published `@kungfu-tech/buildchain@2.11.4-alpha.1`\n- Buildchain Ref Promotion run completed successfully\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T21:20:04Z",
          "mergedAt": "2026-07-09T21:22:36Z",
          "additions": 119,
          "deletions": 28,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 976,
          "url": "https://github.com/kungfu-systems/buildchain/pull/976",
          "title": "fix(web-surface): extend health retry window",
          "body": "Extend the default web-surface HTTP health retry window after CloudFront invalidation waits.\n\nWhy:\n- site-kungfu-tech preview apply still observed transient 403 responses after the invalidation waiter completed.\n- The previous default retry window was only about 20 seconds after invalidation completion, which was too short for the observed CloudFront propagation behavior.\n\nChange:\n- Default HTTP smoke retries are now 12 attempts at 10 second intervals.\n- Consumers can still override with BUILDCHAIN_WEB_SURFACE_HEALTH_HTTP_RETRY_ATTEMPTS and BUILDCHAIN_WEB_SURFACE_HEALTH_HTTP_RETRY_INTERVAL_MS.\n- Added a regression test that the default window absorbs extended transient 403s without requiring slow sleeps.\n\nValidation:\n- node --test tests/web-surface.test.mjs\n- pnpm run generate:site && pnpm run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T21:34:07Z",
          "mergedAt": "2026-07-09T21:36:04Z",
          "additions": 64,
          "deletions": 15,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 977,
          "url": "https://github.com/kungfu-systems/buildchain/pull/977",
          "title": "chore(release): promote web-surface health retry window to alpha",
          "body": "Promote the web-surface health retry-window fix to alpha.\n\nThis carries the Buildchain web-surface default health retry window change:\n- 12 HTTP smoke attempts\n- 10 second retry interval\n- transient 403/404/5xx retry after CloudFront invalidation waits\n\nValidation on dev:\n- Verify run passed after merging the fix to dev/v2/v2.11\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T21:37:31Z",
          "mergedAt": "2026-07-09T21:39:59Z",
          "additions": 64,
          "deletions": 15,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 978,
          "url": "https://github.com/kungfu-systems/buildchain/pull/978",
          "title": "chore(release): promote v2.11.5 to stable",
          "body": "Promote Buildchain v2.11.5 to stable.\n\nThis release extends the web-surface HTTP health retry window after CloudFront invalidation waits:\n- default 12 attempts\n- default 10 second interval\n- retryable transient 403/404/5xx\n\nReason:\n- site-kungfu-tech preview apply observed 403 responses after invalidation completion even with the shorter 2.11.4 retry window.\n\nValidation:\n- alpha published as @kungfu-tech/buildchain@2.11.5-alpha.1\n- Buildchain Ref Promotion completed successfully for alpha\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T21:43:44Z",
          "mergedAt": "2026-07-09T21:49:18Z",
          "additions": 79,
          "deletions": 30,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 979,
          "url": "https://github.com/kungfu-systems/buildchain/pull/979",
          "title": "fix(web-surface): support explicit S3 health strategy",
          "body": "## Summary\n\n- adds `deploy.<channel>.health_strategy = \"s3-object\"` for web-surface channels and per-surface overrides\n- lets public preview channels verify uploaded deployment manifests and S3 objects without waiting on public edge HTTP convergence\n- documents the contract and adds regression coverage for preview S3 health without public fetches\n\n## Validation\n\n- `node --test tests/buildchain-config.test.mjs tests/web-surface.test.mjs`\n- `pnpm run generate:site && pnpm run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T22:08:05Z",
          "mergedAt": "2026-07-09T22:09:46Z",
          "additions": 230,
          "deletions": 100,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 980,
          "url": "https://github.com/kungfu-systems/buildchain/pull/980",
          "title": "chore(release): promote explicit S3 health strategy to alpha",
          "body": "## Summary\n\n- promotes explicit `s3-object` web-surface health strategy to alpha\n- includes contract, documentation, bundle, and regression tests from dev\n\n## Validation\n\n- dev `Verify` passed on `daf621da5f2b62e9d43a2b2c987f440fc7429b39`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T22:11:04Z",
          "mergedAt": "2026-07-09T22:12:59Z",
          "additions": 230,
          "deletions": 100,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 981,
          "url": "https://github.com/kungfu-systems/buildchain/pull/981",
          "title": "chore(release): promote v2.11.6 to stable",
          "body": "## Summary\n\n- promotes Buildchain v2.11.6 to stable\n- includes explicit S3 object health strategy for public web-surface preview channels\n- carries the alpha-tested release material from `v2.11.6-alpha.1`\n\n## Validation\n\n- alpha `Verify` passed on `abdd57778ad614737aa9078f97ca412bd8445e14`\n- `v2.11.6-alpha.1` Binary Distribution passed\n- npm alpha dist-tag points to `2.11.6-alpha.1`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T22:18:02Z",
          "mergedAt": "2026-07-09T22:20:01Z",
          "additions": 245,
          "deletions": 115,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 19,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/19",
          "title": "ci(site): adopt Buildchain v2 contract lock",
          "body": "## Summary\n- move Buildchain config to `.buildchain/buildchain.toml`\n- add `.buildchain/contract-lock.json` for floating `@v2` anti-drift validation\n- switch the web-surface workflow from `@v2.4` to `@v2`\n- keep staging on ordinary main pushes and production behind Buildchain release PR/manual approval gates\n- update local checks and docs to reject the legacy root Buildchain layout\n\n## Validation\n- `ruby -e 'require \"yaml\"; YAML.load_file(\".github/workflows/buildchain-web-surface.yml\"); puts \"workflow yaml ok\"'`\\n- `bash scripts/build-site.sh && bash scripts/check-site.sh`\\n- `npm exec --yes --package @kungfu-tech/buildchain@latest -- buildchain kfd status --cwd . --json`\\n- `npm exec --yes --package @kungfu-tech/buildchain@latest -- buildchain validate --cwd . --require-lifecycle-stages build,verify`\\n- Buildchain web-surface validate + staging/production deploy-plan generation with `@kungfu-tech/buildchain@2.11.2`\\n- Buildchain contract lock check against `v2` / `085efbc375abc53352c2e01ff58164d441b5fc90`\\n\\n## Live deploy\\nThis PR should publish preview only. Merging to main will run the normal Buildchain v2 staging flow and should no longer start staging apply without a staging plan.",
          "author": "dongkeren",
          "createdAt": "2026-07-09T16:30:28Z",
          "mergedAt": "2026-07-09T22:35:05Z",
          "additions": 167,
          "deletions": 15,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 982,
          "url": "https://github.com/kungfu-systems/buildchain/pull/982",
          "title": "fix(web-surface): accept bucket-root S3 health evidence",
          "body": "## Summary\n\n- treats an explicit empty `objectPrefix` as valid bucket-root deployment evidence\n- keeps managed-network staging health on S3 manifest/object checks for bucket-root sites\n- adds regression coverage for root and nested object keys at bucket root\n\n## Validation\n\n- `node --test tests/web-surface.test.mjs`\n- `pnpm run generate:site && pnpm run check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T22:40:23Z",
          "mergedAt": "2026-07-09T22:42:17Z",
          "additions": 49,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 983,
          "url": "https://github.com/kungfu-systems/buildchain/pull/983",
          "title": "chore(release): promote bucket-root health fix to alpha",
          "body": "## Summary\n\n- promotes bucket-root managed-network S3 health evidence fix to alpha\n- keeps bucket-root staging deployments from being misclassified as missing objectPrefix\n\n## Validation\n\n- dev `Verify` passed on `c0c30b8cc35e9e653e06de53b240a0608ab5fdfd`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T22:43:47Z",
          "mergedAt": "2026-07-09T22:45:38Z",
          "additions": 49,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 984,
          "url": "https://github.com/kungfu-systems/buildchain/pull/984",
          "title": "chore(release): promote v2.11.7 to stable",
          "body": "## Summary\n\n- promotes Buildchain v2.11.7 to stable\n- includes the bucket-root managed-network S3 health evidence fix\n- carries alpha-tested release material from `v2.11.7-alpha.1`\n\n## Validation\n\n- alpha `Verify` passed\n- `v2.11.7-alpha.1` Binary Distribution passed\n- npm alpha dist-tag points to `2.11.7-alpha.1`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T22:50:51Z",
          "mergedAt": "2026-07-09T22:53:09Z",
          "additions": 65,
          "deletions": 17,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 20,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/20",
          "title": "ci(site): accept Buildchain v2.11.7 runtime",
          "body": "## Summary\n\n- Accept the floating `v2` Buildchain runtime at `v2.11.7`.\n- Keep the existing `v2` contract-lock pattern while moving the resolved SHA past the bucket-root S3 health fix.\n\n## Verification\n\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `npm exec --yes --package @kungfu-tech/buildchain@latest -- buildchain validate --cwd . --require-lifecycle-stages build,verify`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T23:00:33Z",
          "mergedAt": "2026-07-09T23:02:44Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 21,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/21",
          "title": "Release production from c8b82cbed2e8",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `c8b82cbed2e8672b87becb98b0966bb450408031`\n- Artifact hash: `57f94c5d5ce4180bf92a3af14e9f0a91a24f300360f2d66f1d112260edf689e7`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29056280362)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-c8b82cbed2e8`\n\nThis PR intentionally contains one empty release-intent commit.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-09T23:06:46Z",
          "mergedAt": "2026-07-09T23:08:39Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 60,
          "url": "https://github.com/kungfu-systems/build-images/pull/60",
          "title": "fix(ci): drop buildchain KFD NODE_PATH workaround",
          "body": "## Summary\n- remove the consumer-side NODE_PATH workaround from the default Buildchain promotion workflow\n- rely on Buildchain v2.11.7+ bundling KFD release gate metadata (kungfu-systems/buildchain#956 / PR #957)\n\n## Verification\n- ruby YAML parse for .github/workflows/buildchain-ref-promotion.yml",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:03:00Z",
          "mergedAt": "2026-07-10T00:04:09Z",
          "additions": 0,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 987,
          "url": "https://github.com/kungfu-systems/buildchain/pull/987",
          "title": "fix(web-surface): report unavailable release app token",
          "body": "## Summary\n- resolve production release PR token config before opening the PR\n- report `app-token-unavailable` when GitHub App config is incomplete or token creation fails\n- include token source/app token status in handoff outputs and docs\n\nFixes #985.\n\n## Verification\n- `node --check scripts/web-surface-production-release-pr.mjs && node --test tests/build-surface.test.mjs`\n- `bash scripts/check-workflows.sh`\n- `corepack pnpm@11.7.0 run check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:03:01Z",
          "mergedAt": "2026-07-10T00:06:48Z",
          "additions": 223,
          "deletions": 40,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 61,
          "url": "https://github.com/kungfu-systems/build-images/pull/61",
          "title": "fix(buildchain): update v1.2 contract lock to 2.11.7",
          "body": "## Summary\n- update @kungfu-tech/buildchain from 2.11.0 to 2.11.7\n- refresh .buildchain/contract-lock.json to the v2.11.7 tag commit\n- migrate KFD evidence to the current .buildchain/kfd/kfd-{1,2,3} layout\n- update release-passport evidence paths and keep GitHub Release upload enabled\n\n## Verification\n- pnpm install --frozen-lockfile\n- pnpm run check\n- pnpm exec buildchain validate --require-version-state --require-lifecycle-stages verify,publish\n- collectKfdStatus layout=current",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:07:56Z",
          "mergedAt": "2026-07-10T00:09:20Z",
          "additions": 101,
          "deletions": 98,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 988,
          "url": "https://github.com/kungfu-systems/buildchain/pull/988",
          "title": "chore(release): promote v2.11.8 alpha",
          "body": "Promote the latest Buildchain v2.11 web-surface fixes through alpha.\n\nIncludes #985 via PR #987.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:07:32Z",
          "mergedAt": "2026-07-10T00:09:21Z",
          "additions": 223,
          "deletions": 40,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 62,
          "url": "https://github.com/kungfu-systems/build-images/pull/62",
          "title": "chore(alpha): promote Buildchain 2.11.7 contract lock",
          "body": "## Summary\n- promote the v1.2 Buildchain 2.11.7 contract-lock update through the strict alpha source-lock path\n- verify the latest Buildchain v2 action no longer needs the build-images NODE_PATH workaround for KFD metadata\n\n## Verification\n- pnpm install --frozen-lockfile\n- pnpm run check\n- ruby YAML parse for buildchain-ref-promotion workflow",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:10:46Z",
          "mergedAt": "2026-07-10T00:11:54Z",
          "additions": 101,
          "deletions": 98,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 990,
          "url": "https://github.com/kungfu-systems/buildchain/pull/990",
          "title": "fix(release): make durable state writes ref-safe",
          "body": "## Summary\n- make durable release-state writes retry-safe without force-updating refs\n- treat retried createRef/updateRef success as idempotent when GitHub returns reference-exists or non-fast-forward after a transient response failure\n- cover create visibility races and update retry races in promote-buildchain-ref tests\n\nFixes #989.\n\n## Verification\n- corepack pnpm@11.7.0 exec node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:20:35Z",
          "mergedAt": "2026-07-10T00:22:16Z",
          "additions": 180,
          "deletions": 83,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 63,
          "url": "https://github.com/kungfu-systems/build-images/pull/63",
          "title": "fix(ci): pass KFD passport inputs as JSON arrays",
          "body": "## Summary\n\n- pass Buildchain release-passport KFD inputs as JSON arrays to avoid v2 action JSON.parse failures\n- keep v1.1 legacy KFD paths while routing v1.2+ targets to the canonical .buildchain/kfd layout\n\n## Validation\n\n- ruby -e 'require \"yaml\"; YAML.load_file(\".github/workflows/buildchain-ref-promotion.yml\"); puts \"yaml-ok\"'\n\nRelated upstream Buildchain issue: kungfu-systems/buildchain#991",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:25:38Z",
          "mergedAt": "2026-07-10T00:26:31Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 992,
          "url": "https://github.com/kungfu-systems/buildchain/pull/992",
          "title": "fix(paper): reduce release path friction",
          "body": "## Summary\n- ignore the checked-out Buildchain runtime when verifying version-state local changes\n- report all missing protected-channel settings in one governance failure\n- keep the existing first-class paper release workflow covered by the done-check\n\nFixes #986.\nCloses #963.\nCloses #964.\nCloses #967.\nCloses #969.\n\n## Verification\n- corepack pnpm@11.7.0 install --frozen-lockfile\n- corepack pnpm@11.7.0 exec node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- corepack pnpm@11.7.0 run check",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:26:23Z",
          "mergedAt": "2026-07-10T00:28:04Z",
          "additions": 102,
          "deletions": 47,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 64,
          "url": "https://github.com/kungfu-systems/build-images/pull/64",
          "title": "fix(ci): keep KFD passport inputs as documented paths",
          "body": "## Summary\n\n- undo the JSON-array workaround that Buildchain v2 does not accept for KFD witnesses\n- keep target-ref-based path selection so v1.1 uses legacy KFD paths and v1.2+ uses the canonical .buildchain/kfd layout\n\n## Validation\n\n- ruby -e 'require \"yaml\"; YAML.load_file(\".github/workflows/buildchain-ref-promotion.yml\"); puts \"yaml-ok\"'\n\nUpstream blocker: kungfu-systems/buildchain#991",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:29:52Z",
          "mergedAt": "2026-07-10T00:30:58Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 464,
          "url": "https://github.com/kungfu-systems/kungfu/pull/464",
          "title": "feat(view): add fuzz + sanitizer targets for the FlatBuffers access module (PoC)",
          "body": "Land the kungfu::view fuzz/sanitizer targets (ADR-0039 residual risk, view-hardening child B). Three libFuzzer targets over the untrusted-input entries (compile_schema / from_bytes / bind_frame), each linking only the view module + FlatBuffers + SQLite, plus seed corpus and a validated build recipe (README). PoC validated on mac arm64: from_bytes 698k / compile_schema 211k / bind_frame 2.7M execs no crash; a planted skip-verify makes the fuzzer catch an out-of-bounds ReadScalar in seconds. NOTE: these sources carry no CMakeLists yet (not wired into any build/CI) — the CMake option + verify.mjs sanitizer stage + alpha-build fuzz gate are the next stage; until then they are inert assets and can bit-rot.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:32:16Z",
          "mergedAt": "2026-07-10T00:32:21Z",
          "additions": 170,
          "deletions": 0,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 993,
          "url": "https://github.com/kungfu-systems/buildchain/pull/993",
          "title": "fix(passport): accept cwd-relative KFD inputs",
          "body": "## Summary\n- resolve release passport JSON input paths relative to the caller cwd before parsing inline JSON\n- preserve KFD witness/claim path-list inputs documented by promote-buildchain-ref\n- add regression coverage for .buildchain/kfd/... relative witness paths\n\n## Validation\n- corepack pnpm@11.7.0 exec node --test tests/release-passport.test.mjs\n- corepack pnpm@11.7.0 --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- corepack pnpm@11.7.0 run check\n\nFixes #991",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:34:02Z",
          "mergedAt": "2026-07-10T00:36:05Z",
          "additions": 138,
          "deletions": 79,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 994,
          "url": "https://github.com/kungfu-systems/buildchain/pull/994",
          "title": "chore(release): promote v2.11 fixes to alpha",
          "body": "## Summary\nPromote the accumulated v2.11 fixes from dev to alpha.\n\nIncluded fixes:\n- release-state durable non-fast-forward finalization recovery (#990)\n- paper release friction fixes (#992)\n- cwd-relative KFD passport path inputs (#993)\n\n## Validation\n- covered by merged PR checks on #990, #992, and #993\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:37:19Z",
          "mergedAt": "2026-07-10T00:39:07Z",
          "additions": 347,
          "deletions": 136,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 995,
          "url": "https://github.com/kungfu-systems/buildchain/pull/995",
          "title": "chore(release): promote v2.11.8 to stable",
          "body": "## Summary\nPromote Buildchain v2.11.8 alpha fixes to the stable v2 release line.\n\nIncluded fixes:\n- durable release-state non-fast-forward finalization recovery\n- paper release path friction reductions\n- cwd-relative KFD passport path-list inputs\n\n## Alpha validation\n- v2.11.8-alpha.2 published successfully\n- npm dist-tag alpha points to 2.11.8-alpha.2\n- Buildchain Ref Promotion run 29060539597 completed successfully\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:43:22Z",
          "mergedAt": "2026-07-10T00:45:00Z",
          "additions": 584,
          "deletions": 190,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 465,
          "url": "https://github.com/kungfu-systems/kungfu/pull/465",
          "title": "docs(adr): ADR-0040 — first-class content-addressed KV as a runtime fact-ledger primitive",
          "body": "Records the runtime fact ledger's first-class content-addressed KV primitive: one uniform contract features build on; content-addressing as the concurrency/dedup/tiering enabler; backend-neutral with a one-way dependency direction (yijinjing owns the interface, must not depend on any concrete engine; RocksDB isolated/injected/replaceable behind a boundary gate); per-agent journals for linear write scaling; scale target single-node TB-to-tens-of-TB, sharded to hundreds of TB, tiered toward PB. Status: proposed.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:45:03Z",
          "mergedAt": "2026-07-10T00:45:09Z",
          "additions": 294,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 997,
          "url": "https://github.com/kungfu-systems/buildchain/pull/997",
          "title": "fix(release): tolerate stale release-state ref reads",
          "body": "## Summary\n- retry durable release-state non-fast-forward recovery when GitHub getRef briefly returns the stale parent SHA\n- rebuild the release-state commit on the refreshed head before retrying updateRef\n- add regression coverage for stale ref reads after non-fast-forward\n\n## Validation\n- corepack pnpm@11.7.0 exec node --test tests/promote-buildchain-ref.test.mjs\n- corepack pnpm@11.7.0 --filter @kungfu-systems/buildchain-promote-buildchain-ref build\n- corepack pnpm@11.7.0 run check\n\nFixes #996",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:51:16Z",
          "mergedAt": "2026-07-10T00:52:51Z",
          "additions": 110,
          "deletions": 65,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 998,
          "url": "https://github.com/kungfu-systems/buildchain/pull/998",
          "title": "chore(release): promote release-state retry fix to alpha",
          "body": "## Summary\nPromote the durable release-state stale-ref retry fix to alpha after stable v2.11.8 finalization exposed a GitHub ref visibility race.\n\nIncluded fix:\n- tolerate stale getRef reads after non-fast-forward release-state update conflicts (#997)\n\n## Validation\n- PR #997 checks passed\n- corepack pnpm@11.7.0 run check\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:53:56Z",
          "mergedAt": "2026-07-10T00:55:32Z",
          "additions": 110,
          "deletions": 65,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 999,
          "url": "https://github.com/kungfu-systems/buildchain/pull/999",
          "title": "chore(release): promote v2.11.9 to stable",
          "body": "## Summary\nPromote Buildchain v2.11.9 to stable after validating the durable release-state stale-ref retry fix in alpha.\n\nIncluded fix:\n- durable release-state non-fast-forward recovery now waits out stale getRef reads (#997)\n\n## Alpha validation\n- v2.11.9-alpha.0 published successfully\n- npm dist-tag alpha points to 2.11.9-alpha.0\n- Buildchain Ref Promotion run 29061209271 completed successfully\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T00:59:36Z",
          "mergedAt": "2026-07-10T01:01:25Z",
          "additions": 126,
          "deletions": 81,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 466,
          "url": "https://github.com/kungfu-systems/kungfu/pull/466",
          "title": "docs(adr): ADR-0041 — the Episode manifest is the object's trust boundary, a POD-native journal structure",
          "body": "Makes the Episode manifest (the Episode's trust boundary per ADR-0033) a first-class POD-native yijinjing journal structure and tightens the four operations around it (POD-native fold JSON-edge-only, tight open/seal writer contract, runtime over typed structure, fsck verifying trust-boundary claims + causal closure + frame integrity, query over folded view + rebuildable SQLite projection; content-addressed refs via the ADR-0040 KV). Deliberately scoped to the manifest; the complete Episode object model is a forthcoming ADR. Status: proposed.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T01:07:20Z",
          "mergedAt": "2026-07-10T01:07:26Z",
          "additions": 217,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 22,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/22",
          "title": "ci(site): accept Buildchain v2.11.9 runtime",
          "body": "## Summary\n\n- Accept the floating `v2` Buildchain runtime at `v2.11.9`.\n- Keep the existing major-compatible contract lock while consuming the release-app-token handling fix from Buildchain.\n\n## Verification\n\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `npm exec --yes --package @kungfu-tech/buildchain@latest -- buildchain validate --cwd . --require-lifecycle-stages build,verify`\n\n## Follow-up validation\n\nAfter merge, this should verify that staging can automatically open the production release PR through the configured Buildchain release GitHub App path.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T01:10:57Z",
          "mergedAt": "2026-07-10T01:13:29Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 65,
          "url": "https://github.com/kungfu-systems/build-images/pull/65",
          "title": "fix(buildchain): update v1.2 contract lock to 2.11.9",
          "body": "## Summary\n\n- update local Buildchain dependency from 2.11.7 to 2.11.9\n- refresh Buildchain contract lock to v2.11.9 / ac5142e51969e71d7c2351175ebfeeed3da8a80b\n- refresh KFD aggregate/claim hashes after the lock update\n\n## Validation\n\n- pnpm install --frozen-lockfile\n- pnpm exec buildchain validate --require-version-state --require-lifecycle-stages verify,publish\n- pnpm run check\n\nRelated upstream fix: kungfu-systems/buildchain#991 / PR #993",
          "author": "dongkeren",
          "createdAt": "2026-07-10T01:15:12Z",
          "mergedAt": "2026-07-10T01:16:19Z",
          "additions": 21,
          "deletions": 21,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 66,
          "url": "https://github.com/kungfu-systems/build-images/pull/66",
          "title": "fix(buildchain): promote v1.2 contract lock to 2.11.9",
          "body": "## Summary\n\n- promote the Buildchain 2.11.9 contract-lock update from dev/v1/v1.2 into alpha/v1/v1.2\n- use strict publish-gate source-lock branch shape for Buildchain alpha promotion\n\n## Validation\n\n- pnpm install --frozen-lockfile\n- pnpm run check\n\nRelated upstream fix: kungfu-systems/buildchain#991 / PR #993",
          "author": "dongkeren",
          "createdAt": "2026-07-10T01:17:06Z",
          "mergedAt": "2026-07-10T01:18:11Z",
          "additions": 21,
          "deletions": 21,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 7,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/7",
          "title": "ci(buildchain): validate v2.11.9 alpha publication",
          "body": "## Summary\\n- Bump the white paper package to 0.1.0-alpha.1 for a real alpha publication validation.\\n- Update the Buildchain npm dev dependency and contract lock to v2.11.9.\\n- Refresh site bundle packageVersion metadata.\\n\\n## Verification\\n- npm run check\\n- Local Docker/PDF build was attempted but the local GHCR image pull stalled; GitHub Actions Build will provide the Docker publication build proof.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T01:21:15Z",
          "mergedAt": "2026-07-10T01:23:02Z",
          "additions": 15,
          "deletions": 15,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 8,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/8",
          "title": "chore(release): stage alpha.1 on dev channel",
          "body": "## Summary\\n- Stage 0.1.0-alpha.1 and Buildchain v2.11.9 on the protected dev channel.\\n\\n## Verification\\n- npm run check\\n- PR #7 passed Buildchain publication on main.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T01:26:00Z",
          "mergedAt": "2026-07-10T01:28:03Z",
          "additions": 15,
          "deletions": 15,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 9,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/9",
          "title": "release: publish white paper alpha.1 with Buildchain v2.11.9",
          "body": "## Summary\\n- Promote 0.1.0-alpha.1 into the alpha channel.\\n- Validate Buildchain v2.11.9 after the paper release friction fixes.\\n\\n## Release\\n- Target channel: alpha/v0/v0.1\\n- Package: @kungfu-tech/paper-kungfu-product-white-paper@0.1.0-alpha.1\\n- Buildchain: v2.11.9 / ac5142e51969e71d7c2351175ebfeeed3da8a80b\\n\\n## Verification\\n- PR #7 passed check and Buildchain publication on main.\\n- PR #8 passed check and Buildchain publication into protected dev.\\n- This PR uses the canonical dev/v0/v0.1 -> alpha/v0/v0.1 channel path.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T01:28:41Z",
          "mergedAt": "2026-07-10T01:30:37Z",
          "additions": 15,
          "deletions": 15,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 467,
          "url": "https://github.com/kungfu-systems/kungfu/pull/467",
          "title": "fix(view): reject rootless .bfbs at the load boundary; wire the fuzz + sanitizer gate",
          "body": "Memory-safety coverage for kungfu::view (ADR-0039 residual risk).\n\nTwo tiers over the three FlatBuffers access entries (compile_schema / from_bytes /\nbind_frame), sharing one set of libFuzzer entry functions:\n- KUNGFU_WITH_SANITIZERS: ASan/UBSan corpus replay via a libFuzzer-less driver\n  (any build compiler; MSVC /fsanitize=address on Windows) — the every-build tier.\n- KUNGFU_WITH_FUZZ: real libFuzzer long-run (needs a libFuzzer-capable clang).\n\nfuzz/CMakeLists.txt is a standalone project (the fuzz tier needs a different\ncompiler than the conan/cmake-js core toolchain); scripts/verify.mjs stage 7 drives\nboth against the conan tree build:core seeds, without mutating the checked-in\ncorpus; the alpha/release build runs verify --fuzz so a new crash blocks the alpha.\n\nFixes a spatial-safety hole the new gate found: a valid .bfbs with no root_type\npasses VerifySchemaBuffer but leaves root_table() null, which plan_columns /\nbind_frame / verify_table then dereference. from_bytes now rejects a rootless\nschema at the sole load boundary.\n\nValidated on mac arm64: after the fix all three targets run crash-free\n(compile_schema 842k / from_bytes 2.2M / bind_frame 12M execs, 30s each).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T02:02:08Z",
          "mergedAt": "2026-07-10T02:02:14Z",
          "additions": 494,
          "deletions": 43,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 468,
          "url": "https://github.com/kungfu-systems/kungfu/pull/468",
          "title": "docs(storage): clarify content and episode manifest contracts",
          "body": "## Summary\n\nClarify the two proposed storage ADRs before implementation begins.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- narrow ADR-0040 to an immutable content-store contract and keep mutable KV as a separate capability\n- define backend capability, durability, visibility, ownership, and scale evidence boundaries\n- distinguish POD manifest records from the typed Episode current view in ADR-0041\n- add writer ownership, cross-journal crash recovery, schema-mapping, and staged dependency gates\n- update the ADR index titles\n\n## Verification\n\n- `git diff --check`\n- `./kungfu-code check`\n- public-surface scan for private paths or maintenance-authorship signals\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T02:08:32Z",
          "mergedAt": "2026-07-10T02:17:24Z",
          "additions": 200,
          "deletions": 144,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 1,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/1",
          "title": "ci(buildchain): enable managed paper releases",
          "body": "## Summary\n\n- declare the paper as a Buildchain publication artifact\n- build the PDF with the digest-pinned LaTeX Docker toolchain\n- validate the floating Buildchain v2 contract through the consumer lock\n- synthesize and publish the npm paper package through the managed paper release preset\n- generate publication manifests, passports, archive registry, source bundle, and GitHub Releases\n\n## Trusted Publishing handoff\n\n- npm package already bootstrapped\n- trusted publisher repository: this repository\n- workflow: `.github/workflows/paper-release.yml`\n\n## Checks\n\n- `make check`\n- `actionlint .github/workflows/*.yml`\n- Buildchain Verify workflow\n- Buildchain publication artifact workflow with a real PDF build",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:23:20Z",
          "mergedAt": "2026-07-10T02:28:24Z",
          "additions": 268,
          "deletions": 2,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 2,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/2",
          "title": "ci(buildchain): enable managed paper releases",
          "body": "## Summary\n\n- declare the paper as a Buildchain publication artifact\n- build the PDF with the digest-pinned LaTeX Docker toolchain\n- validate the floating Buildchain v2 contract through the consumer lock\n- synthesize and publish the npm paper package through the managed paper release preset\n- generate publication manifests, passports, archive registry, source bundle, and GitHub Releases\n\n## Trusted Publishing handoff\n\n- npm package already bootstrapped\n- trusted publisher repository: this repository\n- workflow: `.github/workflows/paper-release.yml`\n\n## Checks\n\n- `make check`\n- `actionlint .github/workflows/*.yml`\n- Buildchain Verify workflow\n- Buildchain publication artifact workflow with a real PDF build",
          "author": "dongkeren",
          "createdAt": "2026-07-09T15:20:44Z",
          "mergedAt": "2026-07-10T02:28:35Z",
          "additions": 268,
          "deletions": 2,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1000,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1000",
          "title": "docs: record Buildchain consolidation retrospective",
          "body": "## Summary\n\n- record the 2026-07-10 consolidation evidence and priorities\n- define P0 acceptance criteria for release impact truth and promotion serialization\n- add a durable maintainer handoff pointer to AGENTS.md and CONTRIBUTING.md\n- correct the active action inventory to include report-buildchain-issue\n\n## Validation\n\n- node scripts/check-inventory.mjs\n- bash scripts/check-workflows.sh\n- git diff --check\n- public-boundary scan for private workspace and maintenance-attribution terms\n\n## Scope\n\nDocumentation only. This PR does not change release behavior, refs, tags, or published artifacts.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T02:19:12Z",
          "mergedAt": "2026-07-10T02:28:48Z",
          "additions": 243,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 24,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/24",
          "title": "Render the Kungfu product white paper",
          "body": "## Summary\n\n- consume @kungfu-tech/paper-kungfu-product-white-paper@0.1.0-alpha.1 from an exact pnpm lock\n- render the product-facing white paper index, reader, and responsive section navigation from the upstream brand bundle\n- publish the package PDF only after validating its Buildchain publication digest\n- emit /whitepaper/manifest.json and /whitepaper/llms.txt for agent consumption\n- keep same-site navigation on preview/staging while preserving canonical cross-site evidence links\n\n## Verification\n\n- corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/\n- pnpm run build\n- pnpm run check\n- shell syntax and ShellCheck\n- desktop 1440x1000 browser check: no overflow, PDF rendered, no console errors\n- mobile 390x844 browser check: no overflow, section navigation and structured tables/cards rendered correctly\n\n## Boundary\n\nThis repository renders the upstream site bundle. It does not copy or redefine white paper product facts. The papers.libkungfu.dev evidence destination is released separately and is not created by this pull request.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T02:37:17Z",
          "mergedAt": "2026-07-10T02:51:15Z",
          "additions": 1211,
          "deletions": 123,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 2,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/2",
          "title": "chore(release): bootstrap v0.1 development line",
          "body": "## Summary\n\n- bootstrap the protected `dev/v0/v0.1` paper release line\n- carry the reviewed Buildchain publication contract from `main`\n- keep npm publication disabled until the separate dev-to-alpha promotion\n\n## Validation\n\n- Buildchain Verify workflow\n- Buildchain publication artifact workflow\n- no npm publish side effect on the dev channel",
          "author": "dongkeren",
          "createdAt": "2026-07-10T02:53:13Z",
          "mergedAt": "2026-07-10T02:54:41Z",
          "additions": 268,
          "deletions": 2,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 3,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/3",
          "title": "chore(release): bootstrap v0.1 development line",
          "body": "## Summary\n\n- bootstrap the protected `dev/v0/v0.1` paper release line\n- carry the reviewed Buildchain publication contract from `main`\n- keep npm publication disabled until the separate dev-to-alpha promotion\n\n## Validation\n\n- Buildchain Verify workflow\n- Buildchain publication artifact workflow\n- no npm publish side effect on the dev channel",
          "author": "dongkeren",
          "createdAt": "2026-07-10T02:53:15Z",
          "mergedAt": "2026-07-10T02:54:46Z",
          "additions": 268,
          "deletions": 2,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 3,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/3",
          "title": "chore(release): publish v0.1 alpha",
          "body": "## Summary\n\n- promote the reviewed `dev/v0/v0.1` publication contract to the protected alpha channel\n- publish `0.1.0-alpha.0` through Buildchain paper release and npm Trusted Publishing\n- generate the exact-version GitHub prerelease and Buildchain Release Passport\n\n## Immutable effects after merge\n\n- public npm alpha version\n- exact Git tag and GitHub prerelease\n- Buildchain durable release state and evidence\n\n## Required validation\n\n- protected `check / check` succeeds\n- publication artifact build succeeds\n- post-merge paper release transaction succeeds",
          "author": "dongkeren",
          "createdAt": "2026-07-10T02:56:11Z",
          "mergedAt": "2026-07-10T02:57:35Z",
          "additions": 268,
          "deletions": 2,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1001,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1001",
          "title": "fix(release): bind self impact to version state",
          "body": "## Summary\n\n- replace the static self-release impact payload with `.buildchain/release-impact.json`\n- bind the impact version to Buildchain version-state updates\n- reject stale cross-minor or incomplete version-bound impact evidence\n\n## Validation\n\n- `corepack pnpm@11.7.0 run check`\n- 467 tests passed\n\n## Version impact\n\nPatch: release evidence becomes version-bound and fails closed on stale release metadata.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T02:59:31Z",
          "mergedAt": "2026-07-10T03:01:49Z",
          "additions": 231,
          "deletions": 76,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1003,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1003",
          "title": "chore(release): promote version-bound impact evidence to alpha",
          "body": "## Summary\n\nPromote the version-bound Buildchain self-release impact evidence to the v2.11 alpha channel.\n\nIncluded change:\n- source self-release impact from version-state-managed `.buildchain/release-impact.json`\n- reject stale cross-minor or incomplete version-bound impact evidence\n\n## Validation\n\n- PR #1001 checks passed\n- `corepack pnpm@11.7.0 run check` (467 tests)\n\n## Expected public evidence\n\nThe alpha GitHub Release must publish `impact.json` with release version `2.11.10-alpha.0`, line `v2.11`, and surface impact `release-impact-version-binding`.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:03:00Z",
          "mergedAt": "2026-07-10T03:05:05Z",
          "additions": 474,
          "deletions": 77,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1004,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1004",
          "title": "fix(paper): align release package directory contract",
          "body": "## Summary\n\n- consume the publication package helper outputDir contract in the paper release workflow\n- lock the workflow-to-helper field mapping in the build surface test\n\n## Verification\n\n- node --test tests/build-surface.test.mjs tests/publication-artifact.test.mjs\n- pnpm run check\n\nCloses #1002",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:03:16Z",
          "mergedAt": "2026-07-10T03:05:55Z",
          "additions": 4,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1006,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1006",
          "title": "chore(release): reconcile generated alpha state into dev",
          "body": "## Summary\n\nMerge the generated v2.11.10-alpha.1 version state back into the protected development channel after dev advanced during alpha finalization.\n\nThis preserves both the generated alpha evidence and the already-reviewed paper release contract fix without bypassing branch protection.\n\nFollow-up: #1005",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:11:31Z",
          "mergedAt": "2026-07-10T03:13:34Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1005,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1005",
          "title": "chore(release): promote paper release contract fix to alpha",
          "body": "## Summary\n\nPromote the reviewed paper release package-directory contract fix from the protected development channel to the alpha channel.\n\n## Validation target\n\nAfter alpha promotion completes, promote the same tested tree to stable so paper consumers pinned to Buildchain v2 can resume trusted publication.\n\nRelated: #1002\nSource fix: #1004",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:08:47Z",
          "mergedAt": "2026-07-10T03:15:14Z",
          "additions": 4,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1008,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1008",
          "title": "chore(release): promote v2.11.10 to stable",
          "body": "## Summary\n\nPromote the tested v2.11.10 alpha tree to the stable v2 line.\n\nThis release includes the paper release package-directory contract fix required by standard publication-artifact consumers.\n\nValidated alpha: v2.11.10-alpha.2\nSource fix: #1004\nAlpha promotion: #1005",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:18:41Z",
          "mergedAt": "2026-07-10T03:20:28Z",
          "additions": 493,
          "deletions": 94,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 469,
          "url": "https://github.com/kungfu-systems/kungfu/pull/469",
          "title": "storage: typed episode manifest fold and trust-boundary contract",
          "body": "Merge feature/episode-manifest-journal-v2 into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:11:41Z",
          "mergedAt": "2026-07-10T03:21:41Z",
          "additions": 606,
          "deletions": 196,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1007,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1007",
          "title": "fix(release): preserve version-bound impact asset",
          "body": "## Summary\n\n- resolve file-backed release impact through the configured version-state updater before passport collection\n- keep version-bound impact metadata authoritative over release-candidate defaults\n- add regression coverage for the public `impact.json` asset\n\n## Production evidence\n\nThe first Stage 1 alpha exposed that `buildchain.release.json` carried the expected surface impact while the sibling `impact.json` fell back to unbound defaults. This patch closes that published-asset gap.\n\n## Validation\n\n- `corepack pnpm@11.7.0 run check`\n- 469 tests passed\n\n## Version impact\n\nPatch: public release evidence now preserves the configured version, line, classification, summary, and surface impacts.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:17:26Z",
          "mergedAt": "2026-07-10T03:23:04Z",
          "additions": 191,
          "deletions": 59,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1010,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1010",
          "title": "chore(release): promote bound impact asset fix to alpha",
          "body": "## Summary\n\nPromote the public release evidence fix after alpha `v2.11.10-alpha.1` proved that the sibling `impact.json` asset could fall back to unbound defaults.\n\nIncluded fix:\n- resolve file-backed impact through the configured version-state updater\n- preserve version-bound classification and summary over release-candidate defaults\n- verify the public asset shape with regression tests\n\n## Validation\n\n- PR #1007 checks passed\n- `corepack pnpm@11.7.0 run check` (469 tests)\n\n## Acceptance\n\nThe resulting public alpha `impact.json` must contain its exact published version, line `v2.11`, classification `patch`, the configured summary, and surface impact `release-impact-version-binding`.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:24:01Z",
          "mergedAt": "2026-07-10T03:25:59Z",
          "additions": 191,
          "deletions": 59,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 470,
          "url": "https://github.com/kungfu-systems/kungfu/pull/470",
          "title": "docs(episode): define atomic safety qualification",
          "body": "Define Episode atomic safety, graceful degradation, evidence-preserving recovery, fault containment, and qualification under load. Add the living qualification plan with semantic oracle, fault matrix, scale tiers, metrics, and Episode Trust Report.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:25:45Z",
          "mergedAt": "2026-07-10T03:26:36Z",
          "additions": 699,
          "deletions": 28,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 4,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/4",
          "title": "fix(release): pass protected channel authority",
          "body": "## Summary\n\nMap the organization release-authority secret into the Buildchain paper release workflow so strict protected-channel governance can read and verify branch protection.\n\nThis does not weaken governance or expose secret values.\n\n## Verification\n\n- make check\n- git diff --check\n\nRelated upstream: kungfu-systems/buildchain#1012",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:30:41Z",
          "mergedAt": "2026-07-10T03:32:10Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 5,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/5",
          "title": "fix(release): pass protected channel authority",
          "body": "## Summary\n\nMap the organization release-authority secret into the Buildchain paper release workflow so strict protected-channel governance can read and verify branch protection.\n\nThis does not weaken governance or expose secret values.\n\n## Verification\n\n- make check\n- git diff --check\n\nRelated upstream: kungfu-systems/buildchain#1012",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:30:41Z",
          "mergedAt": "2026-07-10T03:32:15Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1013,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1013",
          "title": "test(release): avoid fixed version-state target",
          "body": "## Summary\n\n- derive a distinct next patch version from the current self-impact version in the version-state regression\n- keep the test valid when promotion verification has already applied the target version locally\n\n## Production evidence\n\nBuildchain Ref Promotion run `29066879997` safely failed before ref/tag writes because the test attempted to update an already-current hard-coded version and then dereferenced an empty changed-file result.\n\n## Validation\n\n- targeted version-state test passed\n- `corepack pnpm@11.7.0 run check`\n- 469 tests passed\n\n## Version impact\n\nPatch: test-only correction for promotion-time version-state validation.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:30:28Z",
          "mergedAt": "2026-07-10T03:32:35Z",
          "additions": 7,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 6,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/6",
          "title": "chore(release): publish v0.1 alpha",
          "body": "## Summary\n\nPromote the fully configured publication workflow to the alpha channel and publish the first non-bootstrap paper package through Buildchain trusted publishing.\n\nExpected outputs:\n\n- npm alpha package\n- exact alpha tag\n- GitHub prerelease with PDF and Release Passport assets\n\nRelated upstream fixes: kungfu-systems/buildchain#1002 and kungfu-systems/buildchain#1012",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:33:05Z",
          "mergedAt": "2026-07-10T03:34:21Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 4,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/4",
          "title": "chore(release): publish v0.1 alpha",
          "body": "## Summary\n\n- promote the reviewed `dev/v0/v0.1` publication contract to the protected alpha channel\n- publish `0.1.0-alpha.0` through Buildchain paper release and npm Trusted Publishing\n- generate the exact-version GitHub prerelease and Buildchain Release Passport\n\n## Immutable effects after merge\n\n- public npm alpha version\n- exact Git tag and GitHub prerelease\n- Buildchain durable release state and evidence\n\n## Required validation\n\n- protected `check / check` succeeds\n- publication artifact build succeeds\n- post-merge paper release transaction succeeds",
          "author": "dongkeren",
          "createdAt": "2026-07-10T02:56:14Z",
          "mergedAt": "2026-07-10T03:34:26Z",
          "additions": 270,
          "deletions": 2,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1014,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1014",
          "title": "chore(release): retry bound impact alpha after test fix",
          "body": "## Summary\n\nRetry the bound impact alpha promotion after correcting the version-state regression to remain valid when promotion has already applied the target version locally.\n\nIncluded change:\n- derive a distinct next patch target from the current release impact version\n\n## Validation\n\n- PR #1013 checks passed\n- `corepack pnpm@11.7.0 run check` (469 tests)\n- failed run `29066879997` wrote no release ref or tag\n\n## Acceptance\n\nThe resulting public alpha `impact.json` must carry its exact published version, line `v2.11`, classification `patch`, configured summary, and surface impact `release-impact-version-binding`.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:33:10Z",
          "mergedAt": "2026-07-10T03:35:12Z",
          "additions": 7,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 7,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/7",
          "title": "fix(release): ignore Buildchain workflow evidence",
          "body": "## Summary\n\nIgnore Buildchain-owned pre-publication evidence files so strict source-change verification does not classify workflow output as undeclared source drift.\n\n## Verification\n\n- make check\n- git diff --check\n- git check-ignore for both generated paths\n\nRelated upstream: kungfu-systems/buildchain#1015",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:38:26Z",
          "mergedAt": "2026-07-10T03:39:39Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 7,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/7",
          "title": "fix(release): ignore Buildchain workflow evidence",
          "body": "## Summary\n\nIgnore Buildchain-owned pre-publication evidence files so strict source-change verification does not classify workflow output as undeclared source drift.\n\n## Verification\n\n- make check\n- git diff --check\n- git check-ignore for both generated paths\n\nRelated upstream: kungfu-systems/buildchain#1015",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:38:26Z",
          "mergedAt": "2026-07-10T03:39:45Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 8,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/8",
          "title": "chore(release): retry v0.1 alpha with clean evidence boundary",
          "body": "## Summary\n\nPromote the verified Buildchain evidence-ignore contract to alpha and retry the first trusted paper publication.\n\nThe previous run stopped before npm publication because workflow-generated evidence was visible as untracked source state.\n\nRelated upstream: kungfu-systems/buildchain#1015",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:40:05Z",
          "mergedAt": "2026-07-10T03:41:26Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 8,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/8",
          "title": "chore(release): retry v0.1 alpha with clean evidence boundary",
          "body": "## Summary\n\nPromote the verified Buildchain evidence-ignore contract to alpha and retry the first trusted paper publication.\n\nThe previous run stopped before npm publication because workflow-generated evidence was visible as untracked source state.\n\nRelated upstream: kungfu-systems/buildchain#1015",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:40:05Z",
          "mergedAt": "2026-07-10T03:41:31Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 471,
          "url": "https://github.com/kungfu-systems/kungfu/pull/471",
          "title": "storage: episode manifest writer guard and crash recovery",
          "body": "Merge feature/episode-manifest-writer-guard into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:46:31Z",
          "mergedAt": "2026-07-10T03:46:36Z",
          "additions": 459,
          "deletions": 12,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1018,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1018",
          "title": "fix(paper): preserve npm repository provenance",
          "body": "## Summary\n\n- preserve authoritative source repository metadata in synthesized publication npm packages\n- fail before npm when trusted publishing lacks repository metadata\n- update the publication fixture and regression coverage\n- refresh generated public contract digests\n\n## Verification\n\n- node --test tests/publication-artifact.test.mjs\n- pnpm run check (470 tests passed)\n\nCloses #1016",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:47:33Z",
          "mergedAt": "2026-07-10T03:49:05Z",
          "additions": 71,
          "deletions": 4,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1019,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1019",
          "title": "chore(release): promote paper provenance fix to alpha",
          "body": "## Summary\n\nPromote the reviewed publication repository-provenance contract to the alpha channel.\n\nDownstream validation will retry two Buildchain-managed paper packages through npm Trusted Publishing and verify Sigstore provenance, exact tags, GitHub prereleases, and Release Passports.\n\nSource fix: #1018\nIssue: #1016",
          "author": "kungfu-origin",
          "createdAt": "2026-07-10T03:49:41Z",
          "mergedAt": "2026-07-10T03:52:19Z",
          "additions": 71,
          "deletions": 4,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1017,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1017",
          "title": "fix(release): preserve impact in binary assets",
          "body": "## Summary\n\n- fetch the authoritative sibling `impact.json` from the durable release-state ref\n- validate that its version matches the durable passport\n- pass it into binary release passport collection so Binary Distribution cannot downgrade the public asset\n\n## Production evidence\n\nAfter Buildchain Ref Promotion published a version-bound `impact.json` for `v2.11.11-alpha.0`, Binary Distribution replaced it with default unbound metadata. The durable release-state ref already contains the correct sibling asset; this patch makes it the binary collection input.\n\n## Validation\n\n- binary distribution workflow regression passed\n- `corepack pnpm@11.7.0 run check`\n- 469 tests passed\n\n## Version impact\n\nPatch: all release writers preserve the authoritative version-bound impact asset.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:47:30Z",
          "mergedAt": "2026-07-10T03:53:00Z",
          "additions": 16,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1022,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1022",
          "title": "chore(release): reconcile alpha impact state into dev",
          "body": "## Summary\n\n- reconcile the latest generated alpha version state into `dev/v2/v2.11`\n- preserve protected branch topology before promoting the binary impact preservation fix\n- keep the change limited to generated version-bound release state\n\n## Validation\n\n- `corepack pnpm@11.7.0 run check` (470 tests passed)\n\nThis unblocks the existing protected `dev/v2/v2.11` to `alpha/v2/v2.11` promotion PR after alpha advanced independently.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:58:46Z",
          "mergedAt": "2026-07-10T04:01:19Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1020,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1020",
          "title": "chore(release): promote binary impact preservation to alpha",
          "body": "## Summary\n\nPromote the final release evidence consolidation fix so Binary Distribution consumes the authoritative durable-state `impact.json` instead of regenerating default metadata.\n\nIncluded change:\n- fetch and validate the durable release-state impact sibling\n- pass it into binary release passport collection\n- prevent later release writers from downgrading the public impact asset\n\n## Validation\n\n- PR #1017 checks passed\n- `corepack pnpm@11.7.0 run check` (470 tests after latest dev sync)\n\n## Acceptance\n\nAfter both Ref Promotion and Binary Distribution finish, the public alpha `impact.json` must still carry its exact version, line `v2.11`, classification `patch`, configured summary, and `release-impact-version-binding` surface.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T03:53:40Z",
          "mergedAt": "2026-07-10T04:03:17Z",
          "additions": 16,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1023,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1023",
          "title": "chore(release): recover v2.11.11 stable promotion",
          "body": "## Summary\n\nRecover the `v2.11.11` stable promotion after the direct alpha-to-release PR became unmergeable because prior generated release-state commits diverged.\n\nThe recovery merge has the exact same Git tree as `v2.11.11-alpha.1`; it introduces no post-alpha source changes. That alpha includes the paper publication repository/provenance fix from #1018.\n\nReplaces #1021.\n\n## Verification\n\n- `node --test tests/publication-artifact.test.mjs tests/promote-buildchain-ref.test.mjs` (98 passed)\n- `pnpm run check` (470 passed; all action bundles rebuilt)\n- recovery tree SHA equals `origin/alpha/v2/v2.11^{tree}`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:01:57Z",
          "mergedAt": "2026-07-10T04:04:10Z",
          "additions": 283,
          "deletions": 79,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 472,
          "url": "https://github.com/kungfu-systems/kungfu/pull/472",
          "title": "storage: structural episode fsck over the typed fold",
          "body": "Merge feature/episode-manifest-structural-fsck into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:12:39Z",
          "mergedAt": "2026-07-10T04:12:45Z",
          "additions": 547,
          "deletions": 13,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 9,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/9",
          "title": "chore(release): advance paper alpha version",
          "body": "## Summary\n\nAdvance the publication version to `0.1.0-alpha.1`.\n\nThe earlier `alpha.0` durable transaction froze publication material synthesized before Buildchain preserved npm repository provenance. Buildchain correctly rejects replacing that material under the same immutable version, so this creates a new alpha transaction.\n\n## Verification\n\n- `make check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:14:41Z",
          "mergedAt": "2026-07-10T04:15:59Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 9,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/9",
          "title": "chore(release): advance paper alpha version",
          "body": "## Summary\n\nAdvance the publication version to `0.1.0-alpha.1`.\n\nThe earlier `alpha.0` durable transaction froze publication material synthesized before Buildchain preserved npm repository provenance. Buildchain correctly rejects replacing that material under the same immutable version, so this creates a new alpha transaction.\n\n## Verification\n\n- `make check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:14:51Z",
          "mergedAt": "2026-07-10T04:16:15Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 11,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/11",
          "title": "chore(release): promote alpha.1 publication",
          "body": "## Summary\n\nPromote the reviewed `0.1.0-alpha.1` publication version to the alpha channel.\n\nThis starts a new immutable release transaction after the superseded `alpha.0` material was correctly rejected from in-place replacement.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:16:35Z",
          "mergedAt": "2026-07-10T04:17:55Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 11,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/11",
          "title": "chore(release): promote alpha.1 publication",
          "body": "## Summary\n\nPromote the reviewed `0.1.0-alpha.1` publication version to the alpha channel.\n\nThis starts a new immutable release transaction after the superseded `alpha.0` material was correctly rejected from in-place replacement.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:16:46Z",
          "mergedAt": "2026-07-10T04:18:11Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1025,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1025",
          "title": "fix(paper): grant generated check permission",
          "body": "## Summary\n\nGrant `checks: write` to the Buildchain paper release reusable workflow and document the same required caller permission.\n\nThe promotion authority remains split by responsibility: `BUILDCHAIN_PROMOTION_TOKEN` reads and updates protected refs, while `github.token` creates the generated version-state audit check.\n\nCloses the finalization-permission gap documented in #1012.\n\n## Verification\n\n- `node --test tests/build-surface.test.mjs` (64 passed)\n- `pnpm run check` (470 passed; all action bundles rebuilt)\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:26:09Z",
          "mergedAt": "2026-07-10T04:28:19Z",
          "additions": 15,
          "deletions": 7,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 12,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/12",
          "title": "fix(release): grant generated check permission",
          "body": "## Summary\n\nGrant `checks: write` to the Buildchain paper release caller so `github.token` can publish the generated version-state audit check during protected alpha finalization.\n\nThe separate `BUILDCHAIN_PROMOTION_TOKEN` remains responsible for protected ref reads and updates.\n\n## Verification\n\n- `make check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:27:47Z",
          "mergedAt": "2026-07-10T04:29:41Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 473,
          "url": "https://github.com/kungfu-systems/kungfu/pull/473",
          "title": "storage: rebuildable episode manifest SQLite projection",
          "body": "Merge feature/episode-manifest-projection into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:29:44Z",
          "mergedAt": "2026-07-10T04:29:49Z",
          "additions": 471,
          "deletions": 3,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 12,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/12",
          "title": "fix(release): grant generated check permission",
          "body": "## Summary\n\nGrant `checks: write` to the Buildchain paper release caller so `github.token` can publish the generated version-state audit check during protected alpha finalization.\n\nThe separate `BUILDCHAIN_PROMOTION_TOKEN` remains responsible for protected ref reads and updates.\n\n## Verification\n\n- `make check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:27:59Z",
          "mergedAt": "2026-07-10T04:29:54Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1026,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1026",
          "title": "chore(release): promote paper check permission to alpha",
          "body": "## Summary\n\nPromote the reviewed paper release generated-check permission contract to the v2.11 alpha channel.\n\nThis unblocks finalization of already-published paper alpha transactions while preserving separate protected-ref and status-check authorities.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:28:43Z",
          "mergedAt": "2026-07-10T04:30:51Z",
          "additions": 15,
          "deletions": 7,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 474,
          "url": "https://github.com/kungfu-systems/kungfu/pull/474",
          "title": "fix(view): bounds-check bind_frame field_index; generalize the fuzz harness",
          "body": "Unsafe-region audit of the sole FlatBuffers access module (kungfu::view, ADR-0039 parent closeout) found a spatial-safety-by-discipline residue plus two minor items, and generalizes the fuzz harness for future untrusted-input surfaces.\n\n- bind_frame now bounds-checks the col_plan field_index before fields->Get, so a stale plan (e.g. one cached against a larger schema, then bound against a smaller one after evolve()) skips the frame instead of an out-of-range reflection read. Regression-tested in the view-encapsulation probe (teeth-checked against the unpatched module).\n- verify_table drops an unused Verifier; alter_add_missing null-guards sqlite3_column_text.\n- fuzz/CMakeLists.txt exposes kungfu_add_fuzz(name, sources) and verify.mjs discovers targets from fuzz_<name>.cpp, so a new fuzz surface (e.g. episode import) is one CMake row + an entry cpp + a corpus dir.\n\nValidated mac arm64: both fuzz tiers build via the generalized harness; view fuzz clean; probe passes under ASan+UBSan.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:31:55Z",
          "mergedAt": "2026-07-10T04:32:00Z",
          "additions": 79,
          "deletions": 23,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1028,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1028",
          "title": "chore(release): recover v2.11.12 stable promotion",
          "body": "## Summary\n\nRecover the `v2.11.12` stable promotion after the direct alpha-to-release PR became unmergeable because generated release-state ancestry diverged.\n\nThe recovery commit has the exact same Git tree as `v2.11.12-alpha.0`; it introduces no post-alpha source changes.\n\nReplaces #1027.\n\n## Verification\n\n- `pnpm run check` (470 passed; all action bundles rebuilt)\n- recovery tree SHA equals `origin/alpha/v2/v2.11^{tree}`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:36:36Z",
          "mergedAt": "2026-07-10T04:38:44Z",
          "additions": 48,
          "deletions": 25,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 16,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/16",
          "title": "chore(release): reconcile alpha ancestry",
          "body": "## Summary\n\nReconcile the protected alpha merge ancestry into dev through a work branch that already contains the current dev permission change.\n\nThe resulting tree is identical to current dev; this PR changes ancestry only and unblocks the reviewed dev-to-alpha permission promotion.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:48:34Z",
          "mergedAt": "2026-07-10T04:50:09Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 475,
          "url": "https://github.com/kungfu-systems/kungfu/pull/475",
          "title": "feat(episode): add qualification harness",
          "body": "## Summary\n\n- add a versioned Episode Qualification Harness with accumulation and 1/2/5/10-worker contention modes\n- validate reports against a Trust Report schema and fail on correctness violations\n- document the first clean smoke, 100k accumulation, and 10k contention baselines with explicit claim boundaries\n\n## Validation\n\n- ./kungfu-code check\n- ./kungfu-code build:core\n- pytest -q framework/core/tests/python/test_episode_manifest_recovery.py\n- pytest -q framework/core/tests/python/test_atlas_storage.py -k episode\n- ./kungfu-code episode:qualify -- --profile mvp-smoke-v1\n- one-seed mvp-baseline-v1 accumulation and contention runs\n\n## Version impact\n\nPatch-level tooling and documentation addition; no runtime API or Episode semantic change.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:50:29Z",
          "mergedAt": "2026-07-10T04:50:35Z",
          "additions": 1920,
          "deletions": 0,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 16,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/16",
          "title": "chore(release): reconcile alpha ancestry",
          "body": "## Summary\n\nReconcile the protected alpha merge ancestry into dev through a work branch that already contains the current dev permission change.\n\nThe resulting tree is identical to current dev; this PR changes ancestry only and unblocks the reviewed dev-to-alpha permission promotion.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:48:46Z",
          "mergedAt": "2026-07-10T04:50:44Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 13,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/13",
          "title": "fix(release): promote generated check permission",
          "body": "## Summary\n\nPromote the reviewed `checks: write` caller permission to the alpha channel.\n\nWith Buildchain `v2.11.12`, this allows the existing `0.1.0-alpha.1` durable transaction to resume finalization without republishing its npm artifact.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:43:50Z",
          "mergedAt": "2026-07-10T04:55:45Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 13,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/13",
          "title": "fix(release): promote generated check permission",
          "body": "## Summary\n\nPromote the reviewed `checks: write` caller permission to the alpha channel.\n\nWith Buildchain `v2.11.12`, this allows the existing `0.1.0-alpha.1` durable transaction to resume finalization without republishing its npm artifact.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:43:33Z",
          "mergedAt": "2026-07-10T04:56:08Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 17,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/17",
          "title": "chore(release): advance paper alpha to alpha.2",
          "body": "## Summary\n\nAdvance the paper publication to `0.1.0-alpha.2` from a branch that already contains current dev and alpha ancestry.\n\n`alpha.1` remains an immutable partial transaction: npm publishing succeeded, but finalization could not be replayed after the caller-permission source change. `alpha.2` starts a clean transaction with the corrected Buildchain and branch-protection contracts in place.\n\n## Verification\n\n- `make check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:59:41Z",
          "mergedAt": "2026-07-10T05:01:11Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 17,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/17",
          "title": "chore(release): advance paper alpha to alpha.2",
          "body": "## Summary\n\nAdvance the paper publication to `0.1.0-alpha.2` from a branch that already contains current dev and alpha ancestry.\n\n`alpha.1` remains an immutable partial transaction: npm publishing succeeded, but finalization could not be replayed after the caller-permission source change. `alpha.2` starts a clean transaction with the corrected Buildchain and branch-protection contracts in place.\n\n## Verification\n\n- `make check`\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:59:52Z",
          "mergedAt": "2026-07-10T05:01:28Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 18,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/18",
          "title": "chore(release): promote alpha.2 publication",
          "body": "## Summary\n\nPromote the reviewed `0.1.0-alpha.2` publication to the protected alpha channel.\n\nThe branch already contains current alpha ancestry, and the Buildchain caller, reusable workflow, and required status-check context are aligned before this transaction begins.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T05:01:42Z",
          "mergedAt": "2026-07-10T05:03:12Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 18,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/18",
          "title": "chore(release): promote alpha.2 publication",
          "body": "## Summary\n\nPromote the reviewed `0.1.0-alpha.2` publication to the protected alpha channel.\n\nThe branch already contains current alpha ancestry, and the Buildchain caller, reusable workflow, and required status-check context are aligned before this transaction begins.\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T05:01:54Z",
          "mergedAt": "2026-07-10T05:03:30Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 476,
          "url": "https://github.com/kungfu-systems/kungfu/pull/476",
          "title": "feat(storage): add first-class content store contract with file backend",
          "body": "ADR-0040 first delivery, kernel side: immutable content_store contract in libyijinjing (put-if-absent / get / has / verify, error taxonomy, size-limit semantics, capability discovery) with a dependency-free file backend (atomic tmp+rename publish, ADR-0037 payload layout), extended dependency guard (engine symbols, CMake links, seeded --self-test) wired into verify stage 5, and a content-store capability slice proving the four obligations plus single-node concurrent dedup across threads and processes.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T05:35:11Z",
          "mergedAt": "2026-07-10T05:35:17Z",
          "additions": 1111,
          "deletions": 26,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 59,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/59",
          "title": "feat(papers): render publication packages",
          "body": "## Summary\n\n- pin the three published Kungfu paper packages and aggregate their package-local publication registries\n- render a human-first papers index, per-paper pages, latest routes, and immutable PDF/manifest/passport/source archives\n- expose exact package, lock integrity, route, and digest facts through papers manifests, registry, and llms.txt\n\n## Verification\n\n- `corepack pnpm@11.9.0 run build`\n- `corepack pnpm@11.9.0 run check`\n- `bash -n scripts/build-site.sh scripts/check-site.sh`\n- `shellcheck scripts/build-site.sh scripts/check-site.sh`\n- desktop and mobile Playwright checks for the papers index and paper detail pages\n- HTTP verification of all 22 rendered papers routes and artifact content types\n\n## Boundaries\n\n- paper packages remain the source of publication facts and immutable artifact bytes\n- this repository owns package-set membership, aggregation, rendering, and environment-aware navigation\n- no production deployment or infrastructure change is included",
          "author": "dongkeren",
          "createdAt": "2026-07-10T04:50:16Z",
          "mergedAt": "2026-07-10T05:46:34Z",
          "additions": 644,
          "deletions": 146,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1030,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1030",
          "title": "fix(release): serialize promotion transactions",
          "body": "## Summary\n\n- serialize protected promotion transactions without cancellation\n- revalidate target ancestry before checkout, dependency install, RC resolution, or ref mutation\n- turn compatible superseded events into auditable zero-mutation no-ops while keeping incompatible movement fail-closed\n\n## Validation\n\n- `pnpm run check` (473 tests, workflow checks, site bundle checks, and four action bundles)\n- focused promotion and build-surface tests (158 tests)\n- `git diff --check`\n\n## Governance\n\n- patch release impact; no public input or artifact schema change\n- no credentials, private logs, hosted-service configuration, branding, package identity, or domain changes\n- release evidence updated for `2.11.13-alpha.0`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T05:47:04Z",
          "mergedAt": "2026-07-10T05:48:54Z",
          "additions": 375,
          "deletions": 94,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1031,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1031",
          "title": "chore(release): promote v2.11.13 alpha",
          "body": "Promote the reviewed `dev/v2/v2.11` release intent into the protected alpha channel.\n\nEvidence target: `v2.11.13-alpha.0` with serialized promotion preflight, version-bound release impact, and no stable publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T05:50:03Z",
          "mergedAt": "2026-07-10T05:52:04Z",
          "additions": 375,
          "deletions": 94,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 477,
          "url": "https://github.com/kungfu-systems/kungfu/pull/477",
          "title": "test(episode): gate verify with qualification smoke",
          "body": "## Summary\n\n- run the versioned `mvp-smoke-v1` Episode qualification from `verify` by default\n- retain failed Trust Reports, enforce clean-source qualification in CI, and expose an explicit local diagnostic skip\n- keep the 100k accumulation and 10k contention baseline outside the per-build path\n\n## Validation\n\n- `./kungfu-code check`\n- `./kungfu-code build:core`\n- `./kungfu-code freeze`\n- clean-source `CI=1 ./kungfu-code verify`: Episode qualification 5/5, `qualified=true`\n- dirty-source CI negative test: Episode stage blocks as designed\n- checked-in Buildchain/workflow commands contain no Episode skip\n\n## Known baseline\n\nThe full verify summary remains red on five pre-existing mypy errors in `master_service.py` and `sources/store.py`; the new Episode stage itself passes.\n\n## Version impact\n\nPatch-level verification and documentation change; no Episode runtime contract change.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T05:56:50Z",
          "mergedAt": "2026-07-10T05:56:57Z",
          "additions": 121,
          "deletions": 3,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 10,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/10",
          "title": "fix(paper): use title-derived PDF filename",
          "body": "## Summary\n\n- publish the white paper under a filename derived from its full title\n- align both site bundles, npm `./pdf` export, Buildchain contract, workflow artifact paths, and local build output\n- verify the site-bundle generator rejects a primary artifact that drifts from the title-derived filename\n\n## Validation\n\n- `npm run check`\n- `npx -y @kungfu-tech/buildchain@2.11.12 validate --cwd . --json`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T06:10:13Z",
          "mergedAt": "2026-07-10T06:13:52Z",
          "additions": 41,
          "deletions": 20,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 19,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/19",
          "title": "fix(paper): use title-derived PDF filename",
          "body": "## Summary\n\n- publish the PDF under a filename derived from the full paper title\n- keep `paper/main.tex` as the internal LaTeX entrypoint\n- align the Buildchain artifact contract, workflow upload path, local build, and documentation\n\n## Validation\n\n- `make check`\n- `npx -y @kungfu-tech/buildchain@2.11.12 validate --cwd . --json`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T06:10:13Z",
          "mergedAt": "2026-07-10T06:15:08Z",
          "additions": 10,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 19,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/19",
          "title": "fix(paper): use title-derived PDF filename",
          "body": "## Summary\n\n- publish the PDF under a filename derived from the paper title\n- keep `paper/main.tex` as the internal LaTeX entrypoint\n- align the Buildchain artifact contract, workflow upload path, local build, and documentation\n\n## Validation\n\n- `make check`\n- `npx -y @kungfu-tech/buildchain@2.11.12 validate --cwd . --json`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T06:10:13Z",
          "mergedAt": "2026-07-10T06:15:13Z",
          "additions": 10,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 478,
          "url": "https://github.com/kungfu-systems/kungfu/pull/478",
          "title": "feat(episode): resolve payload refs through the content store",
          "body": "ADR-0041 stage 4: Episode payload refs resolve through the ADR-0040 immutable content_store by content identity (ref_hash); ref_id stays an edge label. Verified reads map the store's error taxonomy onto manifest diagnostics (missing / hash-mismatch / unaddressable / io); an unverified payload ref fails a sealed Episode and degrades an open one; repair planning also scans fsck errors so sealed payload issues remain fetchable. Producers publish bytes before claiming them, and the file provider's payload write now publishes via content-store put-if-absent. Validation: full core build; episode suites 28/28 incl. 7 new stage-4 fixtures; full python 108 passed with only the 2 pre-existing first-party-baked baseline failures (reproduced on clean dev); node binding consistent with baseline.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T06:20:58Z",
          "mergedAt": "2026-07-10T06:21:04Z",
          "additions": 275,
          "deletions": 41,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 20,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/20",
          "title": "fix(paper): shorten public PDF filename",
          "body": "## Summary\n\n- shorten the public PDF filename to `kfd-foundation-model.pdf`\n- keep the Buildchain contract, workflow artifact, local build, and documentation aligned\n- retain `paper/main.tex` only as the internal LaTeX entrypoint\n\n## Validation\n\n- `make check`\n- `npx -y @kungfu-tech/buildchain@2.11.12 validate --cwd . --json`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T06:55:55Z",
          "mergedAt": "2026-07-10T07:00:51Z",
          "additions": 6,
          "deletions": 7,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 12,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/12",
          "title": "fix(paper): shorten public PDF filename",
          "body": "## Summary\n\n- shorten the public PDF filename to `kungfu-real-world-agent-work.pdf`\n- derive both site-bundle URLs from the declared primary artifact basename\n- align npm exports, Buildchain contract, workflow artifacts, local build, and generated bundles\n\n## Validation\n\n- `npm run check`\n- `npx -y @kungfu-tech/buildchain@2.11.12 validate --cwd . --json`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T06:55:55Z",
          "mergedAt": "2026-07-10T07:00:51Z",
          "additions": 28,
          "deletions": 32,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 20,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/20",
          "title": "fix(paper): shorten public PDF filename",
          "body": "## Summary\n\n- shorten the public PDF filename to `observer-declared-timelines.pdf`\n- keep the Buildchain contract, workflow artifact, local build, and documentation aligned\n- retain `paper/main.tex` only as the internal LaTeX entrypoint\n\n## Validation\n\n- `make check`\n- `npx -y @kungfu-tech/buildchain@2.11.12 validate --cwd . --json`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T06:55:56Z",
          "mergedAt": "2026-07-10T07:00:51Z",
          "additions": 6,
          "deletions": 7,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 479,
          "url": "https://github.com/kungfu-systems/kungfu/pull/479",
          "title": "fix(core): restore mypy baseline",
          "body": "Merge fix/mypy-baseline-recovery into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:03:58Z",
          "mergedAt": "2026-07-10T07:04:05Z",
          "additions": 7,
          "deletions": 7,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 21,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/21",
          "title": "chore(release): advance short filename alpha",
          "body": "## Summary\n\nAdvance the paper version to 0.1.0-alpha.3 so the next Buildchain alpha publishes the short kfd-foundation-model.pdf artifact.\n\n## Validation\n\n- repository checks\n- Buildchain paper profile validation\n- clean diff validation",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:02:45Z",
          "mergedAt": "2026-07-10T07:04:34Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 13,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/13",
          "title": "chore(release): advance short filename alpha",
          "body": "## Summary\n\nAdvance the white paper version to 0.1.0-alpha.2 and refresh versioned site bundles so the next Buildchain alpha publishes kungfu-real-world-agent-work.pdf.\n\n## Validation\n\n- repository checks\n- Buildchain paper profile validation\n- clean diff validation",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:02:45Z",
          "mergedAt": "2026-07-10T07:04:34Z",
          "additions": 7,
          "deletions": 7,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 21,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/21",
          "title": "chore(release): advance short filename alpha",
          "body": "## Summary\n\nAdvance the paper version to 0.1.0-alpha.3 so the next Buildchain alpha publishes the short observer-declared-timelines.pdf artifact.\n\n## Validation\n\n- repository checks\n- Buildchain paper profile validation\n- clean diff validation",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:02:45Z",
          "mergedAt": "2026-07-10T07:04:34Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 14,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/14",
          "title": "chore(release): promote short filename alpha",
          "body": "## Summary\n\nPromote the validated development line to the alpha channel for 0.1.0-alpha.2.\n\nThe public paper artifact is declared as `kungfu-real-world-agent-work.pdf` and will be published through the Buildchain paper release transaction with npm Trusted Publishing.\n\n## Release validation\n\n- verify the exact npm alpha version and dist-tag\n- verify the npm tarball PDF basename\n- verify site/publication bundle download URLs\n- verify the GitHub prerelease and Release Passport",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:04:51Z",
          "mergedAt": "2026-07-10T07:07:02Z",
          "additions": 41,
          "deletions": 24,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 22,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/22",
          "title": "chore(release): promote short filename alpha",
          "body": "## Summary\n\nPromote the validated development line to the alpha channel for 0.1.0-alpha.3.\n\nThe public paper artifact is declared as `kfd-foundation-model.pdf` and will be published through the Buildchain paper release transaction with npm Trusted Publishing.\n\n## Release validation\n\n- verify the exact npm alpha version and dist-tag\n- verify the npm tarball PDF basename\n- verify site/publication bundle download URLs\n- verify the GitHub prerelease and Release Passport",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:04:51Z",
          "mergedAt": "2026-07-10T07:08:05Z",
          "additions": 10,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 22,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/22",
          "title": "chore(release): promote short filename alpha",
          "body": "## Summary\n\nPromote the validated development line to the alpha channel for 0.1.0-alpha.3.\n\nThe public paper artifact is declared as `observer-declared-timelines.pdf` and will be published through the Buildchain paper release transaction with npm Trusted Publishing.\n\n## Release validation\n\n- verify the exact npm alpha version and dist-tag\n- verify the npm tarball PDF basename\n- verify site/publication bundle download URLs\n- verify the GitHub prerelease and Release Passport",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:04:51Z",
          "mergedAt": "2026-07-10T07:08:08Z",
          "additions": 10,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1033,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1033",
          "title": "fix(release): preserve TOML version state formatting",
          "body": "## Summary\n\n- treat already-matching configured JSON/TOML versions as semantic no-ops\n- update real TOML versions through a parser-verified lossless edit\n- prevent formatter-only paper release preparation commits without weakening transaction source identity\n\n## Validation\n\n- `node --test tests/buildchain-config.test.mjs tests/promote-buildchain-ref.test.mjs`\n- `pnpm run check` (476 tests)\n- `git diff --check`\n\nCloses #1029",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:08:28Z",
          "mergedAt": "2026-07-10T07:11:06Z",
          "additions": 327,
          "deletions": 117,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1034,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1034",
          "title": "chore(release): promote TOML version state fix to v2.11 alpha",
          "body": "## Release intent\n\nPromote the v2.11 development line after #1033. This alpha verifies that configured TOML version updates preserve repository formatting and semantic version-state no-ops do not produce formatter-only preparation commits.\n\n## Evidence\n\n- source PR: #1033\n- source commit: `6a13bca61f2f5ae2703543607a64daaf0faf9e83`\n- full Buildchain check: 476 tests passed\n- issue closed by source PR: #1029\n\nStable publication is not requested.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:12:03Z",
          "mergedAt": "2026-07-10T07:13:48Z",
          "additions": 327,
          "deletions": 117,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 16,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/16",
          "title": "chore(buildchain): accept current v2 contract",
          "body": "## Summary\n\nAccept the current stable Buildchain v2 contract after reviewing its compatible additive drift.\n\nThe compatibility digest and all registered breaking surface digests are unchanged. Updating the accepted SHA and contract digest prevents compatible-drift issue material from entering the release version verification worktree.\n\n## Validation\n\n- current v2 contract lock status: unchanged\n- contract drift: false\n- npm repository checks\n- Buildchain paper profile validation",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:19:20Z",
          "mergedAt": "2026-07-10T07:21:19Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 17,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/17",
          "title": "chore(release): retry alpha with accepted v2 contract",
          "body": "## Summary\n\nPromote the accepted current Buildchain v2 contract lock into the alpha channel and retry the still-unpublished 0.1.0-alpha.2 transaction.\n\nThe previous promotion stopped before npm publish because compatible contract drift generated an untracked issue body during version verification. The accepted lock now matches the current v2 SHA and contract digest while preserving the same compatibility and breaking-surface digests.\n\n## Release validation\n\n- verify npm 0.1.0-alpha.2 and alpha dist-tag\n- verify kungfu-real-world-agent-work.pdf in the npm tarball\n- verify both site-bundle download URLs\n- verify GitHub prerelease and Release Passport",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:21:34Z",
          "mergedAt": "2026-07-10T07:23:21Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 480,
          "url": "https://github.com/kungfu-systems/kungfu/pull/480",
          "title": "feat(storage): rocksdb content store with symmetric facades",
          "body": "Completes the ADR-0040 first delivery. RocksDB-backed content_store in the runtime layer over the provider's single long-lived engine handle (keys <namespace>/<digest>, WAL-atomic publication, verified reads); provider payload ops route through it and the rocksdb payload key prefix aligns to the payloads namespace. Kernel fsck/inspect accept an injected content store and every graph-building service path passes the provider's store, closing the stage-4 injection seam: payload-ref resolution reads the same backend that published the bytes under either provider. Python/Node gain symmetric thin facades (put-if-absent / get / has / verify / capabilities); episode_lifecycle publishes through the facade. Validation: full core build; dual-provider facade suite 16/16 incl. proof that fsck under rocksdb resolves refs without touching the file payload tree; full python 124 passed (only the 2 pre-existing first-party-baked baseline failures); node facade roundtrip green under both providers via KUNGFU_DIR=build/Release; mypy baseline clean; dependency guard + self-test green.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:27:52Z",
          "mergedAt": "2026-07-10T07:28:00Z",
          "additions": 823,
          "deletions": 56,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 481,
          "url": "https://github.com/kungfu-systems/kungfu/pull/481",
          "title": "feat(code): native kungfu-code launcher with Rust adoption paradigm",
          "body": "Establish Rust as a first-class option with the kungfu-code launcher as the first exercised case.\n\n- code/ cargo workspace; kungfu-code as a std-only, dependency-free single binary (~364KB)\n- bootstraps pinned prebuilt fnm / uv into the user-global cache when missing: a fresh clone needs nothing beyond curl\n- sh / cmd entrypoints become thin shims (cached binary -> prebuilt download -> cargo build -> legacy fallback); machines with fnm+uv installed see zero behavior change\n- absorbs the Windows special-casing (pinned node, corepack.cmd, MSVC vcvars) natively\n- kungfu-code CI (fmt / clippy -D warnings / tests / release build, 3 platforms) + release workflow publishing prebuilt binaries on kungfu-code-v<version> tags\n- docs/rust-adoption.md: adoption paradigm with hard boundaries and the selective-exercise discipline; KFD-1 register entry for the launcher welded surface",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:36:30Z",
          "mergedAt": "2026-07-10T07:36:38Z",
          "additions": 1549,
          "deletions": 18,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 62,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/62",
          "title": "fix(papers): consume renamed PDF artifacts",
          "body": "## Summary\n\n- update the three pinned paper packages to their renamed-PDF releases\n- preserve upstream publication registry filenames without site-side rewriting\n- refresh pnpm integrity and minimum-release-age policy entries\n\n## Verification\n\n- corepack pnpm install --frozen-lockfile\n- corepack pnpm run build\n- corepack pnpm run check\n- verified current/latest reader pages contain no main.pdf links\n- verified all three rendered PDF digests match the publication manifest\n\n## Governance\n\n- [x] No change to canonical domains or release identity\n- [x] No site-owned publication facts introduced\n- [x] Production remains separately gated",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:43:57Z",
          "mergedAt": "2026-07-10T07:51:35Z",
          "additions": 24,
          "deletions": 24,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 482,
          "url": "https://github.com/kungfu-systems/kungfu/pull/482",
          "title": "test(episode): add semantic qualification evidence",
          "body": "## Summary\n\n- add a Kungfu-independent Episode Semantic v1 oracle with 48 bounded histories\n- replace Trust Report v1 semantic zero placeholders with v2 passed/failed/not_exercised evidence dimensions\n- gate recurring smoke on 8 required production comparisons while keeping capability_soundness honestly not_exercised\n- cover recovery, useful degradation, monotonic repair, dependency containment, projection rebuild, content integrity, and portable identity\n\n## Validation\n\n- 34 focused Episode tests passed\n- ./kungfu-code check\n- ./kungfu-code build:core\n- ./kungfu-code freeze\n- CI=1 ./kungfu-code verify (25/25; 5/5 scale, 8/8 required semantic, qualified=true)",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:57:36Z",
          "mergedAt": "2026-07-10T07:58:51Z",
          "additions": 1224,
          "deletions": 44,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 483,
          "url": "https://github.com/kungfu-systems/kungfu/pull/483",
          "title": "refactor(crates): rename the Rust workspace directory code/ to crates/",
          "body": "Pure rename plus reference updates (shims, workflows, docs, versioning register); no behavior change. crates/ is the de-facto standard cargo workspace container name in Rust monorepos. Published kungfu-code-v0.1.0 binaries are unaffected (asset URLs carry no directory path; the launcher discovers the repo root by marker).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T08:01:51Z",
          "mergedAt": "2026-07-10T08:01:57Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 18,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/18",
          "title": "ci: pass Buildchain train to promotion dry-run",
          "body": "## Summary\n\n- expose the existing Buildchain runtime override on the manual promotion dry-run\n- keep manual non-dry-run promotion rejected\n- lock the pass-through in the repository check\n\n## Validation\n\n- `make check`\n- `actionlint -color=false .github/workflows/*.yml`\n- `git diff --check`\n\nThis enables non-mutating validation of the Buildchain fix for kungfu-systems/buildchain#1032.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T08:00:48Z",
          "mergedAt": "2026-07-10T08:03:11Z",
          "additions": 18,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1035,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1035",
          "title": "fix(paper): validate publication evidence contract",
          "body": "## Summary\n\n- allow only enumerated untracked Buildchain contract-drift and publication-result evidence during strict version verification\n- preflight protected publication authority before expensive paper build work\n- document caller-chosen release-authority secret mapping and preserve strict rejection for undeclared paths\n\n## Validation\n\n- failure-first regression: targeted suite failed on both missing contracts before the implementation\n- targeted Buildchain promotion/build-surface suite: 159 passed\n- `pnpm run check`: 476 passed, workflow/site/inventory checks and four action builds passed\n- `git diff --check`\n\n## Issue evidence\n\nAddresses #1012, #1015, and #1032. The issues will be closed after protected and consumer runtime evidence is attached.\n\n## Version impact\n\nPatch: release governance and paper publication preflight behavior are corrected without changing public input or artifact schemas.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T07:58:32Z",
          "mergedAt": "2026-07-10T08:08:11Z",
          "additions": 118,
          "deletions": 30,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 484,
          "url": "https://github.com/kungfu-systems/kungfu/pull/484",
          "title": "refactor(shifu): rename the launcher product kungfu-code to shifu",
          "body": "Rename the launcher product to shifu — the master that bootstraps the toolchain and walks you into the repo. One word, globally recognizable, native to the kungfu brand's semantic field (the martial-arts mentor-tool lineage that ninja established for build tools).\n\nFull product rename, same contract shape: entrypoints ./shifu / shifu.cmd (L2 shifu.mjs), crate crates/shifu, release tags shifu-v<version>, assets shifu-<platform>, env keys SHIFU_*. All in-repo callers, docs, KFD-3 surfaces, and the versioning register follow; historical decision-log rows keep the old name verbatim. Pre-release, no external consumers; kungfu-code-v0.1.0 will be retired and reissued as shifu-v0.1.0.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T08:18:00Z",
          "mergedAt": "2026-07-10T08:18:06Z",
          "additions": 318,
          "deletions": 322,
          "changedFiles": 64
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1037,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1037",
          "title": "fix(web-surface): preserve immutable publication archives",
          "body": "Closes #1036.\n\n## Summary\n- detect the existing publication archive policy in each surface manifest\n- exclude immutable archive roots from owning and parent `sync --delete` operations\n- verify existing objects before and after `--no-overwrite` SHA-256 uploads\n- expose preservation coverage in apply summaries and health evidence\n\n## Validation\n- failure-first tests for parent-surface deletion coverage, global preflight ordering, CLI evidence, and digest mismatch\n- `pnpm run check` (481 tests; all action bundles built)\n- no live AWS mutations were executed",
          "author": "dongkeren",
          "createdAt": "2026-07-10T08:23:55Z",
          "mergedAt": "2026-07-10T08:26:20Z",
          "additions": 766,
          "deletions": 50,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 485,
          "url": "https://github.com/kungfu-systems/kungfu/pull/485",
          "title": "feat(storage): process-level provider cache retires per-call lifecycle",
          "body": "Close ADR-0040 decision 6: one process-cached provider per (provider, canonical runtime dir); thread-safe shared rocksdb handle; GIL released around the content-store facade; concurrency dedup fixtures for both providers; cache observability in status/layout; lifecycle doc.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T08:28:43Z",
          "mergedAt": "2026-07-10T08:28:49Z",
          "additions": 321,
          "deletions": 52,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1038,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1038",
          "title": "release: promote v2.11 alpha",
          "body": "Promotes the current protected v2.11 development line to alpha.\n\nIncluded fixes:\n- exact paper publication evidence allowlist and early protected-authority preflight (#1035)\n- immutable publication archive preservation across parent and owning web-surface syncs (#1037)\n\nValidation:\n- Buildchain PR checks green\n- full local `pnpm run check` (481 tests)\n- current site-libkungfu-dev artifact consumed the train in deploy-plan-only mode; no AWS apply was executed\n\nStable publication is out of scope.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T08:27:03Z",
          "mergedAt": "2026-07-10T08:28:59Z",
          "additions": 870,
          "deletions": 66,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 486,
          "url": "https://github.com/kungfu-systems/kungfu/pull/486",
          "title": "feat(shifu): lock the launcher version to lerna and make shifu the build opener",
          "body": "Version: crates/shifu/Cargo.toml is kept in lockstep with lerna.json by scripts/sync-shifu-version.mjs (rewritten during the lerna version lifecycle; drift-gated by shifu check). The launcher ships with the release train, so it carries the train's version: shifu-v0.1.0 is reissued as shifu-v4.0.0-alpha.0.\n\nDocs: onboarding opens with ./shifu everywhere (README quick start, AGENTS.md, CONTRIBUTING) — nothing to preinstall beyond curl; fnm / uv are bootstrapped details, not prerequisites.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T08:31:12Z",
          "mergedAt": "2026-07-10T08:31:19Z",
          "additions": 115,
          "deletions": 28,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 487,
          "url": "https://github.com/kungfu-systems/kungfu/pull/487",
          "title": "feat(storage): add Episode Qualification Capability Contract v1",
          "body": "## Summary\n- add C++-owned kungfu.episode.qualification/v1 with evidence, issues, safe capabilities, contractions, and repair prerequisites\n- project the same result through scoped fsck/inspect and Python/Node/CLI edges\n- make capability_soundness a required, executable Semantic v1 dimension\n\n## Validation\n- ./kungfu-code check\n- ./kungfu-code build:core\n- ./kungfu-code freeze\n- focused Episode Python: 41 passed plus final fsck 22 passed\n- native Node binding: 5 passed, 0 skipped\n- CI=1 ./kungfu-code verify: 25/25, scale 5/5, semantic 9/9, qualified=true",
          "author": "dongkeren",
          "createdAt": "2026-07-10T08:38:40Z",
          "mergedAt": "2026-07-10T08:38:45Z",
          "additions": 957,
          "deletions": 75,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1039,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1039",
          "title": "docs(retrospective): record consolidation closure",
          "body": "Records the completed Stage 1–3 evidence, open-issue audit, #1036 archive preservation fix, v2.11.13-alpha.3 evidence, and remaining out-of-scope work.\n\nValidation: `git diff --check`; documentation-only change.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T08:39:23Z",
          "mergedAt": "2026-07-10T08:41:50Z",
          "additions": 69,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 23,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/23",
          "title": "docs(paper): add Episode implementation evidence",
          "body": "## Summary\n\n- model observer-declared timelines over accepted, causally closed Episodes\n- separate journal authority, typed derivation, rebuildable projection, and observer-facing views\n- map current Kungfu evidence and remaining work to the KFD-4 contract\n- replace the evaluation-plan-only framing with bounded semantic, scale, contention, recovery, and projection evidence\n- state explicitly that first-class multi-machine observer projection remains future work\n\n## Verification\n\n- `make check`\n- `make pdf`\n- rendered and inspected all 12 PDF pages\n- cross-checked numeric claims against the public Episode qualification source\n- verified all fixed evidence links return HTTP 200\n\n## Boundaries\n\n- metadata-only development measurements are not capacity promises\n- capability soundness remains `not_exercised`\n- accepted-range sync, observer policy, exported observer declarations, and projection-level causal fsck are not claimed as implemented\n\n## Governance\n\n- [x] No credentials, tokens, secrets, private logs, or provider payloads\n- [x] No hosted-service or package publication change\n- [x] No branding, release identity, or domain change\n- [x] Public evidence and provenance links are explicit\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T08:42:06Z",
          "mergedAt": "2026-07-10T08:43:27Z",
          "additions": 340,
          "deletions": 57,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 488,
          "url": "https://github.com/kungfu-systems/kungfu/pull/488",
          "title": "feat(shifu): repo-pinned fnm/uv bootstrap versions + native CI lifecycle entrypoint",
          "body": "Two moves that finish making shifu the single build opener:\n\n1. fnm/uv bootstrap versions move from Rust constants to repo data files (.fnm-version / .uv-version, .node-version-shaped). Precedence: env override > pin file > compiled fallback. Bumping a pin is a one-line data change with no launcher re-release.\n2. Buildchain lifecycle stages and the build workflow verify-command run ./shifu directly under bash on every platform (the shim now resolves the native windows-x64 binary under MINGW/MSYS). scripts/buildchain-run-shifu.mjs (~660 lines of Windows special-casing) is retired. Promoted versions auto-tag shifu-v<version> launcher releases. build.yml gains workflow_dispatch for on-demand full-matrix validation.\n\nThe explicit verify-command is wrapped in bash -c with inlined env because a workflow-input command runs under the platform default shell and inherits neither the stage shell nor [lifecycle.env] — this also fixes the old env-prefix form that could not have worked under cmd.exe.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T09:11:44Z",
          "mergedAt": "2026-07-10T09:11:51Z",
          "additions": 170,
          "deletions": 704,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1041,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1041",
          "title": "chore(release): promote v2.11.13",
          "body": "## Summary\n\n- promote the tested v2.11.13 alpha lineage to the protected release channel\n- publish @kungfu-tech/buildchain@2.11.13 with release evidence\n- advance the stable v2.11 and v2 refs after transaction finalization\n\n## Included fixes\n\n- preserve immutable publication archive prefixes (#1037)\n- validate paper publication evidence and authority preflight (#1035)\n- serialize and canonicalize protected promotion triggers (#1030, #1033)\n\n## Validation\n\n- v2.11.13-alpha.3 is published from the current alpha channel\n- alpha/v2/v2.11 is a strict descendant of release/v2/v2.11\n- stable promotion remains guarded by Release - Verify and protected review\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T09:15:03Z",
          "mergedAt": "2026-07-10T09:17:14Z",
          "additions": 1536,
          "deletions": 241,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 24,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/24",
          "title": "chore(release): prepare observer paper alpha.4",
          "body": "## Summary\n\n- bring the second substantive observer-timeline paper revision onto the v0.1 development line\n- advance the publication version to `0.1.0-alpha.4`\n- update publication metadata to describe the implemented Episode substrate and bounded evidence\n- preserve the established short public PDF filename and Buildchain paper release configuration\n\n## Verification\n\n- `make check`\n- `make pdf`\n- confirmed `_build/observer-declared-timelines.pdf`\n- inspected PDF metadata: 12 pages, letter size\n\n## Release boundary\n\nThis PR prepares the development line only. Publishing occurs after a separate reviewed promotion from `dev/v0/v0.1` to `alpha/v0/v0.1`.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T09:30:35Z",
          "mergedAt": "2026-07-10T09:33:52Z",
          "additions": 342,
          "deletions": 59,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 26,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/26",
          "title": "chore(release): promote observer paper alpha.4",
          "body": "## Promotion\n\nPromote the reviewed v0.1 development line to `0.1.0-alpha.4`.\n\n## Included change\n\n- second substantive observer-declared timelines paper revision\n- Episode causal-object model and authority/projection separation\n- KFD-4 implementation map\n- bounded semantic, scale, contention, recovery, and projection evidence\n- explicit remaining multi-machine observer-projection boundary\n- preserved `observer-declared-timelines.pdf` public filename\n\n## Evidence\n\n- development PR #24 approved and merged\n- Build publication artifact: passed\n- Verify: passed\n- local `make check` and `make pdf`: passed\n\nMerging this PR intentionally triggers the Buildchain paper alpha release transaction.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T09:34:15Z",
          "mergedAt": "2026-07-10T09:35:28Z",
          "additions": 342,
          "deletions": 59,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 64,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/64",
          "title": "fix(buildchain): preserve publication archives",
          "body": "## Summary\n\n- upgrade the pinned Buildchain package from 2.11.1 to 2.11.13\n- accept the current floating v2 runtime contract\n- consume the immutable publication preservation fix from buildchain#1036\n- update rendered Buildchain version assertions and documentation\n\n## Verification\n\n- corepack pnpm install --frozen-lockfile\n- corepack pnpm run build\n- corepack pnpm run check\n- generated a staging deploy plan with the Buildchain 2.11.13 runtime\n- verified Papers declares archive as a preserved root\n- verified the hub mutable sync excludes papers/archive/*\n- verified the Papers mutable sync excludes archive/*\n- verified pre-upload, no-overwrite sync, and post-upload immutable operations are planned\n\n## Governance\n\n- [x] Buildchain workflow consumption remains on floating v2\n- [x] Contract lock resolves v2 to 618512fd874cc0125cc8a3daa07ef4d1b195777e\n- [x] Production remains separately gated\n- [x] No publication facts are rewritten by the site",
          "author": "dongkeren",
          "createdAt": "2026-07-10T09:31:17Z",
          "mergedAt": "2026-07-10T09:39:51Z",
          "additions": 18,
          "deletions": 18,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 490,
          "url": "https://github.com/kungfu-systems/kungfu/pull/490",
          "title": "feat(shifu): launcher usage/version flags and installed-binary delegation",
          "body": "Bare shifu / -h / --help print the launcher's own usage; --version / -v / -V print build identity (crate version + git sha baked by build.rs + installed/repo role); an installed shifu delegates to the checkout's ./shifu entrypoint whenever it runs inside one (SHIFU_FROM_SHIM guards recursion), so the repo-pinned launcher always wins. Shims gain matching in-script fallbacks. pnpm's own help stays reachable via shifu help.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T09:59:19Z",
          "mergedAt": "2026-07-10T09:59:25Z",
          "additions": 214,
          "deletions": 12,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 66,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/66",
          "title": "fix(papers): update observer timelines alpha.4",
          "body": "## Summary\n\n- update the pinned observer-declared-timelines package to 0.1.0-alpha.4\n- consume the new publication PDF and evidence directly from the upstream registry\n- keep Buildchain immutable preservation scoped to the complete archive root\n\n## Verification\n\n- corepack pnpm install --frozen-lockfile\n- corepack pnpm run build\n- corepack pnpm run check\n- verified the rendered alpha.4 PDF SHA-256 is 6a3f0a4583f0dacb8bc36aa2331c49ac906ed0ca8438cd3c3cc84175a8d09fa8\n- verified the staging plan protects archive/* and the hub plan protects papers/archive/*\n\n## Staging acceptance\n\n- alpha.4 observer PDF and evidence routes return HTTP 200\n- alpha.3 observer PDF and evidence routes remain HTTP 200 after deployment\n- staging __immutable__ health remains pass\n- production remains separately gated",
          "author": "dongkeren",
          "createdAt": "2026-07-10T09:56:07Z",
          "mergedAt": "2026-07-10T10:03:28Z",
          "additions": 8,
          "deletions": 8,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 491,
          "url": "https://github.com/kungfu-systems/kungfu/pull/491",
          "title": "feat(storage): sealed Episode content root commits identity (ADR-0043)",
          "body": "ADR-0043: Episode identity is two layers — episode_id stays the local lifecycle coordinate; a sealed Episode's content identity is a hash root chained over its owned claim sequence, committed as EpisodeRootCommitted (carrier 10806, additive) by the seal path and verified by fsck. Covers determinism/sensitivity/crash-shape/cross-store-invariance fixtures, projection support, bundle-apply compatibility, and the qualification reference model update.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:04:59Z",
          "mergedAt": "2026-07-10T10:05:05Z",
          "additions": 856,
          "deletions": 29,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1045,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1045",
          "title": "feat(kfd): add product claims registry",
          "body": "## Summary\n- add a generic product-owned KFD-2 claims registry contract under the canonical `.buildchain/kfd/kfd-2` layout\n- expose deterministic render, write, and read-only drift checks through Node API and CLI\n- register the public surface and generated site facts\n\n## Downstream validation\n- exact train: `train/v2/v2.11/kfd2-product-claims-registry` at `6da888728a99141ecc962774edf5d08095386c18`\n- Kungfu migrated its registry and generated release/SDK projections through this API\n- Kungfu core build, freeze, KFD evidence checks, mypy, Episode qualification, and end-to-end verify passed 25/25\n\n## Validation\n- `pnpm run check` (486 tests passed)\n- `node --test tests/kfd2-product-claims-registry.test.mjs tests/kfd3-surface-register.test.mjs` (13 passed)\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:03:46Z",
          "mergedAt": "2026-07-10T10:05:46Z",
          "additions": 887,
          "deletions": 52,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1047,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1047",
          "title": "chore(release): reconcile v2.11 alpha state",
          "body": "## Summary\n- merge the generated `v2.11.14-alpha.0` release bookkeeping from `alpha/v2/v2.11` back into `dev/v2/v2.11`\n- preserve the KFD-2 product claims registry merged in #1045\n- restore a clean, reviewable `dev -> alpha` promotion path for #1046\n\nThis is the documented recovery path after the prior release transaction skipped a non-fast-forward dev sync.\n\n## Validation\n- `pnpm run generate:site`\n- `pnpm run check` (486 passed)\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:08:50Z",
          "mergedAt": "2026-07-10T10:10:40Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1046,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1046",
          "title": "release: promote KFD-2 product claims registry",
          "body": "## Release intent\nPromote the reviewed Buildchain KFD-2 product claims registry capability from `dev/v2/v2.11` to the alpha channel.\n\n## Included change\n- PR #1045 (`ec716b4`)\n- downstream validation against exact train `6da8887`\n- Buildchain cross-platform checks passed\n- Kungfu build, freeze, KFD evidence, and verify passed 25/25\n\nThis uses the normal Buildchain alpha promotion transaction and npm trusted publishing path.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:06:18Z",
          "mergedAt": "2026-07-10T10:12:46Z",
          "additions": 956,
          "deletions": 52,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 492,
          "url": "https://github.com/kungfu-systems/kungfu/pull/492",
          "title": "feat(shifu): clone and doctor verbs; repo version line reports the branch",
          "body": "shifu clone [path] fetches the repository (default ., SHIFU_CLONE_URL override) — with delegation this completes the bootstrap-core loop: install once, clone anywhere, every evolvable behavior comes from the repo-pinned launcher. shifu doctor is an environment preflight that reports and never installs (required tools with versions/install pointers, shifu-managed tools with repo pins, optional rustc; exit 1 on missing required). The repo role of --version now appends the checkout's current branch.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:16:07Z",
          "mergedAt": "2026-07-10T10:16:12Z",
          "additions": 334,
          "deletions": 22,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 493,
          "url": "https://github.com/kungfu-systems/kungfu/pull/493",
          "title": "refactor(kfd): adopt Buildchain product claims",
          "body": "## Summary\n- move the product-owned KFD-2 claims registry to canonical `.buildchain/kfd/kfd-2/registry.json`\n- replace Kungfu's custom 501-line generator with Buildchain `product-claims` render/write/check APIs\n- upgrade all Buildchain consumers to published `2.11.14-alpha.0` and refresh release/SDK evidence\n- remove `framework/release` and all legacy references while preserving release-passport claim inputs and public package projections\n\n## Upstream\n- Buildchain #1045 merged\n- alpha promotion #1046 merged\n- npm `@kungfu-tech/buildchain@2.11.14-alpha.0` published and verified\n\n## Validation\n- frozen install passed\n- staged gate passed\n- `pnpm run check:types` passed\n- `pnpm run kfd2:claims:check` passed\n- `pnpm run kfd:buildchain:check` passed\n- core build + freeze passed\n- `pnpm verify` passed 25/25, including Episode Qualification\n- legacy path/reference scan passed\n\n## Known baseline\n`pnpm run check:all` still reports the existing repository-wide Biome baseline (945 diagnostics in unrelated files); all touched files pass the staged/targeted Biome gates.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:19:36Z",
          "mergedAt": "2026-07-10T10:20:31Z",
          "additions": 151,
          "deletions": 686,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 494,
          "url": "https://github.com/kungfu-systems/kungfu/pull/494",
          "title": "feat(shifu): styled launcher output and bootstrap-core docs",
          "body": "Styled launcher-owned output (usage / doctor / clone): ANSI color + semantic emoji, TTY-gated (NO_COLOR and TERM=dumb respected; piped output stays plain, doctor's exit code remains the script interface). std-only ~50-line style module.\n\nDocs: README getting-started gains the installed-shifu bootstrap-core path (cargo install once, shifu clone anywhere, stay current by pulling code) and a doctor step; CONTRIBUTING and AGENTS.md point at doctor.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:23:51Z",
          "mergedAt": "2026-07-10T10:23:57Z",
          "additions": 165,
          "deletions": 37,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 495,
          "url": "https://github.com/kungfu-systems/kungfu/pull/495",
          "title": "fix(shifu): weld the delegation protocol to the entrypoints alone",
          "body": "Installed binaries bake in the delegation protocol forever, so anchor it on nothing that can evolve: repo-root recognition = shifu + shifu.cmd both present (the welded entrypoint pair; previously the L2 marker and the node pin file — a future without node must not break old binaries); the entrypoint is spawned directly, implementation-form agnostic; SHIFU_DELEGATED=1 joins SHIFU_FROM_SHIM=1 as a second anti-loop fuse. Protocol registered as part of the shifu-launcher welded surface. Shipped before any delegating binary reaches a release.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:36:53Z",
          "mergedAt": "2026-07-10T10:36:58Z",
          "additions": 38,
          "deletions": 9,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 67,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/67",
          "title": "Release production from 5a413ac31513",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `5a413ac3151320a756a357aa8b6c0a99bf5d1f65`\n- Artifact hash: `188958976a0fe0d5bc66b29d34bf527a90aead0a304465b314d16102506e171c`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29085094503)\n- Required label: `buildchain-release`\n- Release branch: `release/production-5a413ac31513`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-10T10:11:33Z",
          "mergedAt": "2026-07-10T10:42:31Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 68,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/68",
          "title": "feat(release): add no-apply Buildchain canary",
          "body": "## Summary\n- add a dedicated `Buildchain Stable Canary` manual workflow\n- require an exact Buildchain alpha ref\n- fix preview, staging, production, and production-release apply paths to `false`\n- leave the existing deployment workflow unchanged\n\n## Validation\n- `actionlint .github/workflows/buildchain-web-surface.yml .github/workflows/buildchain-stable-canary.yml`\n- repository web-surface checks\n\nThe new canary workflow does not perform AWS apply or deployment.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:28:50Z",
          "mergedAt": "2026-07-10T10:42:54Z",
          "additions": 49,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 496,
          "url": "https://github.com/kungfu-systems/kungfu/pull/496",
          "title": "docs(shifu): ADR-0044 records the delegation protocol; entrypoints carry the warning",
          "body": "ADR-0044 states the four protocol clauses installed binaries bake in (root recognition = shifu + shifu.cmd pair, direct spawn, the two anti-loop env fuses, release asset layout), the consequences (never rename/move/remove the entrypoints; implementation form free), and rejected alternatives. Both entrypoint files carry a protocol-warning header — the file an agent opens to edit is the file that warns them. KFD-1 register row, rust-adoption.md, MAP.md, and source comments point at the ADR.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:43:11Z",
          "mergedAt": "2026-07-10T10:43:17Z",
          "additions": 111,
          "deletions": 3,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 69,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/69",
          "title": "fix(release): grant reusable canary permissions",
          "body": "## Summary\n- match the permission contract declared by `.web-surface.yml@v2`\n- keep all preview, staging, production, and production-release apply inputs fixed to `false`\n\n## Evidence\n- train canary run 29087244764 stopped at `startup_failure` with zero jobs\n- `actionlint .github/workflows/buildchain-stable-canary.yml`\n\nNo AWS apply or deployment ran in the failed attempt.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:45:11Z",
          "mergedAt": "2026-07-10T10:45:23Z",
          "additions": 2,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 70,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/70",
          "title": "fix(release): match canary contents permission",
          "body": "## Summary\n- grant the maximum `contents: write` permission declared by the called `.web-surface.yml@v2` workflow\n- keep every canary apply and production-release input fixed to `false`\n\n## Evidence\n- train canary runs 29087244764 and 29087343327 both stopped at `startup_failure` with zero jobs while caller permissions were lower than the reusable workflow contract\n- `actionlint .github/workflows/buildchain-stable-canary.yml`\n\nNeither failed attempt started a job or performed AWS apply.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:46:48Z",
          "mergedAt": "2026-07-10T10:47:02Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1049,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1049",
          "title": "feat(release): gate stable promotion with canaries",
          "body": "## Summary\n- add a versioned Buildchain stable-release policy: 24-hour stable cooldown, named internal and consumer canaries, one-hour soak, version-bound impact, and non-empty product/contract diff\n- evaluate the stable gate after RC resolution and before publish-gate, npm, tag, or ref mutation; alpha and train iteration remain unthrottled\n- preserve concurrent dev changes when overlaying generated next-alpha version state\n- report post-complete next-alpha failures as deferred bookkeeping instead of reversing an already complete stable release\n- record the Stage 4 decision and #1042 reproduction in release governance and the consolidation retrospective\n\n## Train and canary\n- train ref: `train/v2/v2.3/stable-release-throttling-canary-gate`\n- train SHA: `a5f486b1f9a9df3225c407f9473ddf7f6feb5958`\n- consumer canary workflow PR: kungfu-systems/site-libkungfu-dev#68\n\n## Validation\n- 9 stable-gate unit/integration tests pass\n- promotion/build-surface/gate targeted suite passes\n- full unit suite passes except four local KFD package-discovery cases unavailable without this new worktree dependency install; protected PR CI is the authoritative full dependency run\n- `node scripts/check-inventory.mjs`\n- generated site bundle check\n- action bundle rebuilt and syntax checked\n- `actionlint` for promotion workflows\n- `git diff --check`\n\nNo stable release, npm publication, AWS apply, branch-protection bypass, or channel-ref mutation was used as validation.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:38:58Z",
          "mergedAt": "2026-07-10T10:49:03Z",
          "additions": 1402,
          "deletions": 186,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1050,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1050",
          "title": "chore(release): promote v2.11 stable gate alpha",
          "body": "## Release intent\nPromote the merged Stage 4 stable-release gate from `dev/v2/v2.11` to the alpha channel.\n\n## Evidence\n- implementation PR: #1049\n- no-apply consumer train canary: https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29087415700\n- train runtime SHA: `1525f7bc7453cd35421bce80159081f05a7ad92b`\n- consumer build/check passed; all apply and production-release jobs were skipped\n\nThis PR requests alpha evidence only. It does not request stable publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:49:32Z",
          "mergedAt": "2026-07-10T10:51:08Z",
          "additions": 1402,
          "deletions": 186,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1053,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1053",
          "title": "fix(release): rebuild stable gate action bundle",
          "body": "## Summary\n- rebuild `actions/promote-buildchain-ref/dist/index.js` with the repository-standard `tsup` command and complete workspace dependency graph\n- no source behavior change\n\n## Evidence\n- alpha promotion run 29087654249 failed before publication because version verification rebuilt this bundle and detected drift\n- canonical bundle size matches CI output: 865.85 KB\n- targeted promotion regressions: 3 passed\n- stable gate tests: 9 passed\n- `node --check actions/promote-buildchain-ref/dist/index.js`\n- `git diff --check`\n\nCloses #1052 after a successful alpha retry.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:56:08Z",
          "mergedAt": "2026-07-10T10:58:05Z",
          "additions": 59,
          "deletions": 59,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1054,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1054",
          "title": "chore(release): retry v2.11 stable gate alpha",
          "body": "## Release intent\nRetry the Stage 4 alpha after canonical action bundle rebuild PR #1053.\n\n## Evidence\n- first promotion run 29087654249 stopped before publication on generated bundle drift\n- source fix PR: #1053\n- no-apply consumer train canary: https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29087415700\n\nThis remains alpha-only release intent; no stable publication is requested.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T10:58:17Z",
          "mergedAt": "2026-07-10T11:00:16Z",
          "additions": 59,
          "deletions": 59,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 25,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/25",
          "title": "Release production from a515dd2ba587",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `a515dd2ba587a6ce293f72b98fbc230bb5d426e8`\n- Artifact hash: `3c42347d5aafcc404f4c1d701a27519f1518915cfa2d1457a5be0861780c3476`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29065556069)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-a515dd2ba587`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-10T02:53:17Z",
          "mergedAt": "2026-07-10T11:17:58Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 497,
          "url": "https://github.com/kungfu-systems/kungfu/pull/497",
          "title": "feat(shifu): enforce the repository build entrypoint",
          "body": "## Summary\n\n- route Claude and Copilot repository guidance through the existing `AGENTS.md` Shifu contract\n- add a deterministic entry-contract gate for participant-facing docs, workflows, Buildchain lifecycle commands, runtime markers, and root package tasks\n- mark Shifu child execution and reject accidental direct package-manager entry with a copyable `./shifu <task>` correction\n- run the gate from both source checks and Buildchain lifecycle verification while preserving explicit launcher/bootstrap exceptions\n- restore the Rust format and Clippy baseline exposed by the three-platform launcher gate\n\n## Validation\n\n- `./shifu check:staged`\n- `./shifu check:entry-contract`\n- `./shifu exec node --test scripts/check-shifu-entry-contract.test.mjs` (7/7)\n- `SHIFU_NATIVE=0 ./shifu check:entry-contract`\n- native debug launcher `check:entry-contract`\n- `cargo fmt --all --manifest-path crates/Cargo.toml -- --check`\n- `cargo clippy --manifest-path crates/Cargo.toml --workspace --all-targets -- -D warnings`\n- `cargo test --manifest-path crates/Cargo.toml -p shifu` (4/4)\n- `sh -n shifu`\n- `shellcheck -e SC1007 shifu`\n- PR CI: macOS, Linux, and Windows launcher format/Clippy/test/release-build/smoke gates passed\n- Buildchain validate and DCO passed\n\n## Existing baseline\n\nThe repository-wide `./shifu check` reaches and passes the new gate and tests, then reports the pre-existing SDK canonical-policy source/render mismatch (25/26 SDK tests). This PR does not touch that policy or projection.\n\n## Version impact\n\nPatch: this enforces the already documented Shifu entrypoint and does not change the registered delegation protocol or open a new compatibility line.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T11:16:13Z",
          "mergedAt": "2026-07-10T11:22:13Z",
          "additions": 461,
          "deletions": 59,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 498,
          "url": "https://github.com/kungfu-systems/kungfu/pull/498",
          "title": "docs(kfx): propose native and wasm execution profiles",
          "body": "## Summary\n\n- document the historical and current native KFX evidence\n- propose four orthogonal execution profiles: native, WebAssembly, managed, and subprocess\n- recommend Rust as the native authoring default only behind a versioned C ABI and explicit safety gates\n- select Wasmtime provisionally for a future component-model spike, with Wasmer retained as a measured fallback\n- define performance, footprint, provenance, and decision gates without changing the current KFX contract\n\n## Validation\n\n- git diff --check\n- local Markdown link validation\n- staged repository gate passed during commit\n- ./shifu check: 25/26 SDK tests passed; the remaining failure is a pre-existing canonical-policy hash mismatch in an unchanged contract file\n\n## Scope\n\nResearch and proposed ADR only. No runtime, contract, dependency, or build-pipeline implementation is included.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T11:32:18Z",
          "mergedAt": "2026-07-10T11:34:01Z",
          "additions": 286,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 499,
          "url": "https://github.com/kungfu-systems/kungfu/pull/499",
          "title": "fix(sdk): refresh canonical policy baseline",
          "body": "## Summary\n- refresh the frozen canonical-policy Buildchain package version to match the SDK dependency\n- restore byte-for-byte equality between the canonical source and SDK renderer\n\n## Validation\n- `./shifu check`\n- `./shifu exec node developer/sdk/src/sdk.js contract policy --check --json`\n- `./shifu exec node developer/sdk/src/sdk.js contract audit --json`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-10T11:39:18Z",
          "mergedAt": "2026-07-10T11:40:18Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 28,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/28",
          "title": "Upgrade white paper site bundle to alpha.2",
          "body": "## Summary\n\n- upgrade `@kungfu-tech/paper-kungfu-product-white-paper` to `0.1.0-alpha.2`\n- consume the brand bundle, publication manifest, and PDF through package exports\n- match the PDF artifact using its exported package-relative path instead of the former `_build/main.pdf` filename\n- keep pnpm minimum-release-age protection while allowing this explicitly verified alpha.2 package\n\n## Verification\n\n- `corepack pnpm@11.7.0 run build`\n- `corepack pnpm@11.7.0 run check`\n- generated PDF SHA256: `646998d209f045389ef4f3af4cadd48e18750a1e57b0ae144c9e2466a3c3f087`\n- generated machine manifest identifies `@kungfu-tech/paper-kungfu-product-white-paper@0.1.0-alpha.2`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T11:43:26Z",
          "mergedAt": "2026-07-10T11:46:27Z",
          "additions": 14,
          "deletions": 18,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 29,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/29",
          "title": "Release production from 7f62cf45b9a0",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `7f62cf45b9a05657caa2bba5644ace36501af862`\n- Artifact hash: `4fc8e5dd5b6d72b811d6fc2b3614bfbb1bf2f2b7bf55e8805b91f62c499995a2`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29090467241)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-7f62cf45b9a0`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-10T11:48:24Z",
          "mergedAt": "2026-07-10T11:50:55Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 500,
          "url": "https://github.com/kungfu-systems/kungfu/pull/500",
          "title": "docs(positioning): define the runtime fact infrastructure layer",
          "body": "## Summary\n\n- position Kungfu through the SQLite shape, Git-for-runs semantics, and flight-recorder-plus-qualification mission\n- distinguish the runtime fact ledger from observability and blockchain\n- explain why agent work creates a missing first-class runtime-fact layer\n- route the positioning question and keywords from the documentation map\n\n## Validation\n\n- `git diff --check`\n- public-surface leakage scan\n- `./shifu check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T11:59:08Z",
          "mergedAt": "2026-07-10T11:59:57Z",
          "additions": 113,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 501,
          "url": "https://github.com/kungfu-systems/kungfu/pull/501",
          "title": "feat(crates): probe the rust host shell, measure the real cost of freezing",
          "body": "Merge feature/rust-host-spike into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T12:07:57Z",
          "mergedAt": "2026-07-10T12:08:08Z",
          "additions": 634,
          "deletions": 0,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 502,
          "url": "https://github.com/kungfu-systems/kungfu/pull/502",
          "title": "feat(storage): migrate import manifest, export bundle, and channel cursor to kernel journal records",
          "body": "Merge feature/import-manifest-migration into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T12:40:03Z",
          "mergedAt": "2026-07-10T12:40:09Z",
          "additions": 2304,
          "deletions": 2215,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1055,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1055",
          "title": "fix: close open build and release contract gaps",
          "body": "## Summary\n\n- inherit lifecycle/stage env and an explicitly declared stage shell for workflow command overrides\n- retry transient GitHub source fallback fetches with a bounded, evidenced attempt budget\n- preserve the emitted `check / check` context and other consumer-required checks during release governance updates\n- hydrate cumulative paper publication registries from npm-integrity-verified historical packages\n- resolve web-surface channel/preview alias before caller build and reject cross-channel manifest hosts before apply\n\n## Verification\n\n- `pnpm run check`\n- 506 unit tests passed\n- workflow syntax/static checks passed\n- generated action bundles and `dist/site` registries rebuilt\n\n## Validation boundary\n\nThe exact runtime is published at `train/v2/v2.3/open-issue-remediation` for consumer checks. No stable ref or release is used as a test shortcut.\n\nFixes #1040\nFixes #1043\nFixes #1044\nFixes #1048\nFixes #1051",
          "author": "dongkeren",
          "createdAt": "2026-07-10T12:32:23Z",
          "mergedAt": "2026-07-10T12:43:15Z",
          "additions": 872,
          "deletions": 214,
          "changedFiles": 42
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1056,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1056",
          "title": "alpha: release open issue remediation",
          "body": "## Release intent\n\nPromote the reviewed Buildchain open-issue remediation from `dev/v2/v2.11` to the protected alpha channel.\n\nEvidence:\n- implementation PR #1055 merged with dual-identity review\n- full local check: 506 tests passed\n- Build Surface fixture passed on Linux, macOS, and Windows\n- exact-train site canary run 29093239858 passed with all deploy applies disabled\n- live npm registry hydration reconstructed alpha.1 through alpha.4 and appended alpha.5 deterministically\n\nThis PR requests a new alpha only; it does not request stable promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T12:44:42Z",
          "mergedAt": "2026-07-10T12:47:04Z",
          "additions": 872,
          "deletions": 214,
          "changedFiles": 42
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1058,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1058",
          "title": "fix(governance): preserve Buildchain self check context",
          "body": "## Summary\n\n- keep the public reusable-workflow default at the exact consumer context `check / check`\n- make Buildchain self-promotion, release-line bootstrap, and dogfood patrol use the repository-local `check` context\n- add regressions that fail if self and consumer contexts are collapsed again\n- refresh generated public-site contract evidence\n\n## Why\n\nThe issue-remediation alpha promotion failed closed because Buildchain's own protected branches emit `check`, while the reusable workflow context exposed to consumers is `check / check`. This patch preserves both exact contexts at their respective boundaries without mutating branch protection.\n\n## Validation\n\n- `node --test tests/build-surface.test.mjs tests/cli.test.mjs` (118 passed)\n- `pnpm run check` (506 tests passed; workflow checks, generated site, and four action builds passed)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T12:57:09Z",
          "mergedAt": "2026-07-10T12:59:41Z",
          "additions": 44,
          "deletions": 23,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1059,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1059",
          "title": "chore(release): promote v2.11 issue remediation to alpha",
          "body": "## Promotion intent\n\nPromote the completed open-issue remediation and the Buildchain self-check context correction from `dev/v2/v2.11` to `alpha/v2/v2.11`.\n\nThis creates a fresh protected Verify event so Buildchain Ref Promotion evaluates the repository-local required context `check` and publishes the next alpha. It does not request a stable release.\n\n## Included evidence\n\n- issue remediation PR #1055 (issues #1040, #1043, #1044, #1048, #1051)\n- self/consumer check-context correction PR #1058\n- full repository check: 506 tests, workflow validation, generated site consistency, and four action builds\n- Build Surface Fixture: Linux, macOS, and Windows passed on #1058\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T13:00:04Z",
          "mergedAt": "2026-07-10T13:02:06Z",
          "additions": 44,
          "deletions": 23,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1060,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1060",
          "title": "fix(release): bind stable canaries to exact runtime",
          "body": "## Summary\n\n- accept stable-canary runtime input only when it is the exact alpha tag or the 40-character SHA resolved from that tag\n- downgrade a successful commit status to `mismatched` when its workflow, repository, or runtime ref does not match the candidate\n- cover exact tag, exact candidate SHA, and wrong SHA behavior with a failure-first collector regression\n- refresh the `2.11.14` release impact so the eventual stable passport covers the full issue-remediation surface\n\n## Live finding\n\nThe no-apply site canary run 29096562817 rejected `v2.11.14-alpha.2` because the trusted runtime override contract accepts train refs or exact SHAs. Stage 4's prior accepted canary also used an exact SHA, but the stable gate collector only compared the run input with the tag and, separately, could retain `success` after a metadata mismatch.\n\nNo site deployment, npm publication, tag, or channel ref mutation occurred.\n\n## Validation\n\n- failure-first wrong-SHA collector assertion reproduced the false-success path\n- `node --test tests/stable-release-gate-cli.test.mjs tests/stable-release-gate.test.mjs` (9 passed)\n- `pnpm run check` (506 tests; workflow checks, generated site, and four action builds passed)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T13:39:34Z",
          "mergedAt": "2026-07-10T13:41:24Z",
          "additions": 106,
          "deletions": 40,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1061,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1061",
          "title": "alpha: verify stable canary runtime binding",
          "body": "## Promotion intent\n\nPromote the stable-canary exact runtime binding and consolidated `2.11.14` release impact to the alpha channel.\n\nThis is required before the next stable release can obtain a valid exact-SHA site canary. It does not request or bypass stable publication; the 24-hour stable interval and 1-hour canary soak remain authoritative.\n\n## Included evidence\n\n- fix PR #1060\n- failure-first tag/SHA/wrong-SHA collector regression\n- full repository check: 506 tests, workflow validation, generated site consistency, and four action builds\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T13:41:52Z",
          "mergedAt": "2026-07-10T13:43:44Z",
          "additions": 106,
          "deletions": 40,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 503,
          "url": "https://github.com/kungfu-systems/kungfu/pull/503",
          "title": "feat(storage): honest producer contract for redacted, absent, and missing payloads",
          "body": "Merge feature/storage-payload-redaction-producer into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T13:50:44Z",
          "mergedAt": "2026-07-10T13:50:51Z",
          "additions": 344,
          "deletions": 45,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1062,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1062",
          "title": "fix(release): read stable canary run metadata",
          "body": "## Summary\n\n- resolve the authoritative workflow name from the Actions run `workflow_id`\n- recover the exact runtime ref from the workflow-owned run-name when the REST run payload omits dispatch inputs\n- keep explicit API inputs authoritative when a provider exposes them\n- record runtime-ref source and workflow ID in stable gate evidence\n\n## Live finding\n\nExact-SHA no-apply canary run 29097422065 succeeded with all apply jobs skipped. Its real GitHub REST object has no `inputs`, and its `name`/`display_title` is `Buildchain Stable Canary / <SHA>` rather than the base workflow name. The previous unit fixture did not model either provider behavior.\n\nNo attestation, stable PR merge, npm stable publication, tag, ref, or deployment mutation was performed from this incomplete evidence shape.\n\n## Validation\n\n- failure-first live-shape collector regression reproduced the blocked gate\n- `node --test tests/stable-release-gate-cli.test.mjs tests/stable-release-gate.test.mjs` (9 passed)\n- `pnpm run check` (506 tests; workflow checks, generated site, and four action builds passed)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T13:52:39Z",
          "mergedAt": "2026-07-10T13:54:41Z",
          "additions": 61,
          "deletions": 23,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1063,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1063",
          "title": "alpha: verify stable canary run metadata",
          "body": "## Promotion intent\n\nPromote the live GitHub Actions run-metadata collector correction to alpha so the stable gate can consume an exact-SHA no-apply canary without synthetic API fields.\n\nStable cooldown and final canary soak remain unchanged and are not bypassed.\n\n## Included evidence\n\n- fix PR #1062\n- exact live REST shape from canary run 29097422065\n- failure-first workflow_id/run-name regression\n- full repository check: 506 tests, workflow validation, generated site consistency, and four action builds\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T13:55:23Z",
          "mergedAt": "2026-07-10T13:57:11Z",
          "additions": 61,
          "deletions": 23,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 504,
          "url": "https://github.com/kungfu-systems/kungfu/pull/504",
          "title": "docs(adr): ADR-0046 — rust host trunk, layered CLI, assembled runtime",
          "body": "Merge feature/adr-rust-host-endstate into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:17:39Z",
          "mergedAt": "2026-07-10T14:17:46Z",
          "additions": 262,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 506,
          "url": "https://github.com/kungfu-systems/kungfu/pull/506",
          "title": "docs(storage): record the payload backend and source registry decisions as settled",
          "body": "Merge fix/storage-open-decisions into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:28:25Z",
          "mergedAt": "2026-07-10T14:28:33Z",
          "additions": 15,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 507,
          "url": "https://github.com/kungfu-systems/kungfu/pull/507",
          "title": "docs(adr): ADR-0046 — lazy-by-default toolchain delivery via the launcher lineage",
          "body": "Merge feature/adr0046-lazy-toolchain into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:41:17Z",
          "mergedAt": "2026-07-10T14:41:25Z",
          "additions": 41,
          "deletions": 13,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 505,
          "url": "https://github.com/kungfu-systems/kungfu/pull/505",
          "title": "ci(build): expose trusted Buildchain train override",
          "body": "## Summary\n\n- expose the documented trusted `workflow_dispatch` `buildchain-ref` pass-through while keeping the committed reusable workflow pinned to `@v2`\n- preserve normal build behavior when the input is empty\n- refresh the already-stale KFD-1/KFD-3 projections required by the repository commit gate\n\n## Validation\n\n- `./shifu check`\n- `actionlint .github/workflows/build.yml`\n- DCO and repository pre-commit gate\n- exact train run: https://github.com/kungfu-systems/kungfu/actions/runs/29099884183\n\nThis provides the consumer evidence path for Buildchain issue #1043 without committing a temporary Buildchain train ref.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:27:43Z",
          "mergedAt": "2026-07-10T14:46:49Z",
          "additions": 14,
          "deletions": 8,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 19,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/19",
          "title": "chore(buildchain): accept current v2 contract",
          "body": "## Summary\n\n- accept Buildchain v2 at immutable commit 618512fd874cc0125cc8a3daa07ef4d1b195777e\n- record the authoritative published contract digest\n- preserve the unchanged major-compatible surface digest\n\n## Validation\n\n- make check\n- git diff --check\n- verified the lock digest against Buildchain v2 dist/site/buildchain-contract.json\n\n## Governance\n\nThis is a compatible floating-ref acceptance update. It changes only .buildchain/contract-lock.json.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:49:33Z",
          "mergedAt": "2026-07-10T14:51:39Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 508,
          "url": "https://github.com/kungfu-systems/kungfu/pull/508",
          "title": "docs(kfx): ratify ADR-0045 execution profiles",
          "body": "## Summary\n\n- ratify ADR-0045 after all five maintainer decisions were accepted\n- record the native-first spike order and shared host capability membrane\n- keep implementation, contract changes, and spike gate claims explicitly pending\n\n## Validation\n\n- `./shifu check`\n- `git diff --check`\n- public-surface leak scan\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider API, billing, quota, or usage-attribution changes\n- [x] No hosted-service, branding, package, release, or deployment changes\n- [x] No contract or runtime implementation changes",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:50:54Z",
          "mergedAt": "2026-07-10T14:51:44Z",
          "additions": 23,
          "deletions": 17,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 23,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/23",
          "title": "chore(buildchain): accept current v2 contract",
          "body": "## Summary\n\n- accept Buildchain v2 at immutable commit 618512fd874cc0125cc8a3daa07ef4d1b195777e\n- record the authoritative published contract digest\n- preserve the unchanged major-compatible surface digest\n\n## Validation\n\n- make check\n- git diff --check\n- verified the lock digest against Buildchain v2 dist/site/buildchain-contract.json\n\n## Governance\n\nThis is a compatible floating-ref acceptance update. It changes only .buildchain/contract-lock.json.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:49:37Z",
          "mergedAt": "2026-07-10T14:51:44Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 27,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/27",
          "title": "chore(buildchain): accept current v2 contract",
          "body": "## Summary\n\n- accept Buildchain v2 at immutable commit 618512fd874cc0125cc8a3daa07ef4d1b195777e\n- record the authoritative published contract digest\n- preserve the unchanged major-compatible surface digest\n\n## Validation\n\n- make check\n- git diff --check\n- verified the lock digest against Buildchain v2 dist/site/buildchain-contract.json\n\n## Governance\n\nThis is a compatible floating-ref acceptance update. It changes only .buildchain/contract-lock.json.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:49:40Z",
          "mergedAt": "2026-07-10T14:51:49Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 20,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/20",
          "title": "chore(buildchain): accept current v2 contract on development line",
          "body": "## Summary\n\n- accept the current Buildchain v2 contract on the active v0.1 development line\n- preserve the development line's paper and release history\n- resolve the outstanding compatible-drift review debt\n\n## Validation\n\n- make check\n- git diff --check\n- verified the accepted digest against Buildchain v2 dist/site/buildchain-contract.json\n\n## Scope\n\nThis PR changes only .buildchain/contract-lock.json. It does not publish or modify an existing alpha release.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:53:46Z",
          "mergedAt": "2026-07-10T14:55:55Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 24,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/24",
          "title": "chore(buildchain): accept current v2 contract on development line",
          "body": "## Summary\n\n- accept the current Buildchain v2 contract on the active v0.1 development line\n- preserve the development line's paper and release history\n- resolve the outstanding compatible-drift review debt\n\n## Validation\n\n- make check\n- git diff --check\n- verified the accepted digest against Buildchain v2 dist/site/buildchain-contract.json\n\n## Scope\n\nThis PR changes only .buildchain/contract-lock.json. It does not publish or modify an existing alpha release.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:53:49Z",
          "mergedAt": "2026-07-10T14:56:00Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 28,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/28",
          "title": "chore(buildchain): accept current v2 contract on development line",
          "body": "## Summary\n\n- accept the current Buildchain v2 contract on the active v0.1 development line\n- preserve the development line's paper and release history\n- resolve the outstanding compatible-drift review debt\n\n## Validation\n\n- make check\n- git diff --check\n- verified the accepted digest against Buildchain v2 dist/site/buildchain-contract.json\n\n## Scope\n\nThis PR changes only .buildchain/contract-lock.json. It does not publish or modify an existing alpha release.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:53:51Z",
          "mergedAt": "2026-07-10T14:56:08Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 509,
          "url": "https://github.com/kungfu-systems/kungfu/pull/509",
          "title": "docs(shifu): state the role — when your kungfu fails you, you turn to shifu",
          "body": "Merge feature/shifu-motto into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T15:08:08Z",
          "mergedAt": "2026-07-10T15:08:14Z",
          "additions": 34,
          "deletions": 1,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1065,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1065",
          "title": "fix(checkout): seed fallback from advertised source ref",
          "body": "## Summary\n\n- fetch the advertised source ref before trying a raw SHA so a current mirror satisfies checkout and a stale mirror seeds reusable objects\n- return retryable ref timeouts directly to the bounded retry loop instead of spending the same timeout again on an unadvertised SHA\n- separate the trusted-cache timeout from a 600-second default GitHub fallback timeout, sized from the real three-platform 5 Mbps contention window\n- preserve exact source commit/tree verification and record both timeout budgets\n- correct the Buildchain retrospective after the earlier premature closure\n\n## Validation\n\n- failure-first source-fetch order and timeout regressions\n- `node --test tests/locked-source-checkout.test.mjs tests/build-surface.test.mjs` (74/74)\n- `pnpm run check` (508/508, workflow and site checks, four action builds)\n- `git diff --check`\n- exact train: `train/v2/v2.3/issue-1043-source-fetch@48bf6148`\n- Kungfu dev consumer run: https://github.com/kungfu-systems/kungfu/actions/runs/29101288426\n\n## Release plan\n\nThis invalidates the current `v2.11.14-alpha.4` candidate and its canaries. After merge, regenerate alpha, rerun Binary Distribution and exact-SHA site/Build Surface canaries, then replace the existing stable release PR before the Stage 4 time gate.\n\nFixes #1043",
          "author": "dongkeren",
          "createdAt": "2026-07-10T14:24:16Z",
          "mergedAt": "2026-07-10T15:12:02Z",
          "additions": 174,
          "deletions": 45,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1067,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1067",
          "title": "alpha: include issue 1043 source checkout fix",
          "body": "## Promotion scope\n\n- include #1065 / #1043 constrained-source checkout correction\n- promote dev/v2/v2.11 at ea28e2bcaee6c23751271a6a5eb56e248c7ad143\n- invalidate v2.11.14-alpha.4 as the final stable candidate\n\n## Evidence\n\n- Buildchain Verify + Build Surface Fixture on #1065: green\n- authoritative Kungfu train run: https://github.com/kungfu-systems/kungfu/actions/runs/29101288426\n- locked-source checkout succeeded on Linux, macOS, and Windows; later lifecycle failures are downstream and outside #1043\n\nAfter merge, publish the next v2.11.14 alpha and run a fresh exact-SHA no-apply site canary before opening the replacement stable PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T15:12:46Z",
          "mergedAt": "2026-07-10T15:14:34Z",
          "additions": 174,
          "deletions": 45,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 510,
          "url": "https://github.com/kungfu-systems/kungfu/pull/510",
          "title": "docs(adr): converge ADR-0045/0046 on one libkungfu embedding membrane",
          "body": "Merge feature/adr-0045-0046-reconcile into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T15:29:03Z",
          "mergedAt": "2026-07-10T15:29:10Z",
          "additions": 28,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 511,
          "url": "https://github.com/kungfu-systems/kungfu/pull/511",
          "title": "docs(architecture): establish dual schema authority",
          "body": "## Summary\n\n- establish ADR-0047: every persisted structured fact has exactly one schema owner, either Hana POD or FlatBuffers\n- supersede ADR-0002 in schema scope and amend ADR-0025 so the action envelope migrates from transitional JSON/base64 to `ActionEnvelope.fbs`\n- align public architecture, event, storage, carrier, and versioning docs; correct ADR-0037 so typed storage service work is no longer reported as complete\n\n## Validation\n\n- `./shifu check`\n- `git diff --check`\n\n## Version impact\n\n- breaking-pre-release decision for the action-envelope encoding; no stable v4 compatibility promise is affected",
          "author": "dongkeren",
          "createdAt": "2026-07-10T15:57:35Z",
          "mergedAt": "2026-07-10T15:58:38Z",
          "additions": 395,
          "deletions": 78,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 512,
          "url": "https://github.com/kungfu-systems/kungfu/pull/512",
          "title": "shifu: extract the role framework (shifu-core: bootstrap + probe)",
          "body": "Split the launcher into a thin binary plus shifu-core, the unpublished workspace library carrying the shifu role: the pinned-fetch bootstrap engine with named self-diagnosing errors, and the declarative probe contract (reports, never repairs; exact repair commands named). The dev doctor consumes the probe framework and mounts the first seed probes (cache health, mirror reachability, pin bite); an integration test drives the bootstrap the way the product trunk will (ADR-0046 stage 1). Launcher behavior, release pipeline, and version pin surface unchanged.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T15:58:55Z",
          "mergedAt": "2026-07-10T15:59:01Z",
          "additions": 1426,
          "deletions": 647,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1069,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1069",
          "title": "feat(release): add major alpha floating channels",
          "body": "## Summary\n\n- add a generic `vN-alpha` channel for every Buildchain major\n- move it only from the highest minor in that major with a published alpha\n- fail closed to an auditable skip when an older minor promotes later\n- expose the contract in dry-run output, docs, generated site facts, and bundled action code\n\n## Validation\n\n- `node --test tests/promote-buildchain-ref.test.mjs tests/build-surface.test.mjs` (167 passed)\n- `pnpm run check` (512 passed; generated site and action bundles verified)\n- `git diff --check`\n\n## Release impact\n\nThis intentionally supersedes the current v2.11.14 stable candidate. After merge, Buildchain will publish a fresh alpha and rebuild exact-SHA canary evidence before opening a replacement stable PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T16:15:08Z",
          "mergedAt": "2026-07-10T16:17:31Z",
          "additions": 403,
          "deletions": 142,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1071,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1071",
          "title": "chore(release): reconcile v2.11 alpha version state",
          "body": "## Summary\n\nReconcile the protected dev line with the already-published `v2.11.14-alpha.5` generated version state. The prior promotion recorded `skipped-non-fast-forward` for dev, which made the next dev-to-alpha PR conflict.\n\nThis changes only the seven declared version-state files and retains the generic `vN-alpha` implementation already merged in #1069.\n\n## Validation\n\n- `pnpm run check` (512 passed)\n- generated site timestamp/source policy preserved from the alpha.5 evidence commit\n- `git diff --check`\n\nAfter this lands, PR #1070 can merge without rewriting protected branch history.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T16:22:57Z",
          "mergedAt": "2026-07-10T16:25:13Z",
          "additions": 23,
          "deletions": 14,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1072,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1072",
          "title": "chore(release): reconcile v2.11 alpha ancestry",
          "body": "## Summary\n\nRestore the already-published alpha.5 commit as an ancestor of the protected dev line after the prior promotion recorded `skipped-non-fast-forward`.\n\nThis merge commit is intentionally tree-identical to current dev: it changes no files and only closes the branch ancestry graph so the existing dev-to-alpha PR #1070 can merge without a force push or conflict rewrite.\n\n## Proof\n\n- first parent tree: `35e9e839cedd0f5971c99fc7ad904b0be88b6c91`\n- merge tree: `35e9e839cedd0f5971c99fc7ad904b0be88b6c91`\n- second parent: `v2.11.14-alpha.5` / `46c3fe1e`\n- `git diff-tree --exit-code HEAD^1 HEAD`\n- alpha commit is an ancestor of the proposed head",
          "author": "dongkeren",
          "createdAt": "2026-07-10T16:27:06Z",
          "mergedAt": "2026-07-10T16:29:01Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 516,
          "url": "https://github.com/kungfu-systems/kungfu/pull/516",
          "title": "build(core): split runtime deps from the toolchain, ship the wheel in dist",
          "body": "Merge feature/assembly-dist-s1 into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T16:29:16Z",
          "mergedAt": "2026-07-10T16:29:23Z",
          "additions": 72,
          "deletions": 33,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1070,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1070",
          "title": "alpha: publish generic major alpha channel",
          "body": "## Summary\n\nPromote the merged generic `vN-alpha` contract into the v2.11 alpha channel.\n\n## Expected promotion result\n\n- publish a fresh exact v2.11 alpha tag\n- move `v2.11-alpha` to the generated alpha commit\n- create and move `v2-alpha` to the same commit\n- align `alpha/v2/v2.11` and `dev/v2/v2.11` with that generated version state\n\nThis supersedes the candidate from closed PR #1068. Stable promotion requires fresh exact-SHA canary evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T16:19:09Z",
          "mergedAt": "2026-07-10T16:31:22Z",
          "additions": 397,
          "deletions": 127,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1074,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1074",
          "title": "fix(release): consume complete matching-ref responses",
          "body": "## Summary\n\nFix #1073 by consuming GitHub's complete matching-refs response exactly once. The endpoint returns all matching refs (340 for `tags/v2.` in this repository) and ignores page parameters; treating a 100+ result as another page repeated the same response until the safety cap failed.\n\nThe highest-minor `vN-alpha` ownership scan remains complete and cached, while the regression test now covers a single response containing more than 100 refs and a newer minor at the end.\n\n## Validation\n\n- live read-only API: page 1 and page 2 each returned the same complete 340-ref response\n- `node --test tests/promote-buildchain-ref.test.mjs` (100 passed)\n- `pnpm run check` (512 passed)\n- action bundle rebuilt\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-10T16:35:29Z",
          "mergedAt": "2026-07-10T16:37:34Z",
          "additions": 77,
          "deletions": 87,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1075,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1075",
          "title": "alpha: retry generic major alpha channel publication",
          "body": "## Summary\n\nRetry the generic `vN-alpha` alpha promotion after #1074 fixed issue #1073.\n\nThe first promotion failed before publication because GitHub matching-refs returns one complete 340-ref response and ignores page parameters. This PR carries the single-response scan fix; no new alpha tag or floating ref was moved by the failed run.\n\nExpected result: a fresh exact v2.11 alpha plus `v2.11-alpha` and the new `v2-alpha` pointing at the same generated commit.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T16:38:00Z",
          "mergedAt": "2026-07-10T16:39:47Z",
          "additions": 77,
          "deletions": 87,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 517,
          "url": "https://github.com/kungfu-systems/kungfu/pull/517",
          "title": "feat(core): kungfu-trunk with the kungfu-owned env surface",
          "body": "Merge feature/assembly-dist-s1 into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T17:04:34Z",
          "mergedAt": "2026-07-10T17:04:40Z",
          "additions": 832,
          "deletions": 6,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 518,
          "url": "https://github.com/kungfu-systems/kungfu/pull/518",
          "title": "feat(core): wrong-runtime guard at the binding seam",
          "body": "Merge feature/assembly-dist-s1 into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T17:11:16Z",
          "mergedAt": "2026-07-10T17:11:21Z",
          "additions": 177,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 519,
          "url": "https://github.com/kungfu-systems/kungfu/pull/519",
          "title": "docs: user guide for kungfu env and the one-runtime contract",
          "body": "Merge feature/assembly-dist-s1 into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T17:20:57Z",
          "mergedAt": "2026-07-10T17:21:02Z",
          "additions": 83,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 520,
          "url": "https://github.com/kungfu-systems/kungfu/pull/520",
          "title": "check: Rust format + clippy join the staged/changed/all gates",
          "body": "crates/ edits could reach a PR without meeting rustfmt or clippy locally — the pre-commit gate covered C++/Python/JS but not Rust. Wire a Rust leg into check.mjs at all three scopes running the exact two commands shifu CI runs (cargo fmt --all --check, cargo clippy --workspace --all-targets -D warnings) so the local gate cannot drift from CI; fix.mjs gets the matching repair leg (shifu fix:staged runs cargo fmt and re-stages). Missing cargo warns and skips — rustc stays outside shifu's bootstrap scope and CI backstops.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T21:00:55Z",
          "mergedAt": "2026-07-10T21:01:01Z",
          "additions": 53,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 521,
          "url": "https://github.com/kungfu-systems/kungfu/pull/521",
          "title": "feat(product): honor KF_DEV_HOME as the pinned dev workspace data home",
          "body": "Merge feature/kf-dev-home into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T21:07:02Z",
          "mergedAt": "2026-07-10T21:07:09Z",
          "additions": 127,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 523,
          "url": "https://github.com/kungfu-systems/kungfu/pull/523",
          "title": "shifu: source-fresh dev cache + self-update",
          "body": "The shim cache was keyed by the release pin, which only moves at release time — dev machines structurally ran a stale launcher (new doctor probes could never reach the user). Content-address the cache slot by the last commit touching launcher source when cargo+git are present (dirty trees rebuild every call, out-of-repo target dir so locked checkouts build); machines without cargo keep the existing path byte for byte. Add shifu self-update to refresh an installed binary in place: in-checkout source rebuild (or pinned release without cargo), explicit --version outside; downloads verified against SHA256SUMS through shifu-core's fetch engine (which learns raw non-archive assets); rename-dance swap restores the old binary on failure; shim-cache slots refuse the verb. Verified end to end incl. file:// mirror fixture.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T23:08:42Z",
          "mergedAt": "2026-07-10T23:08:48Z",
          "additions": 437,
          "deletions": 14,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 524,
          "url": "https://github.com/kungfu-systems/kungfu/pull/524",
          "title": "ci: consume buildchain through the v2-alpha floating channel",
          "body": "Switch the three buildchain references from @v2 to @v2-alpha to pick up the lifecycle override inheritance and bounded checkout fallback fixes (buildchain#1040, #1043) ahead of the stable channel — unblocking the native shifu lifecycle validation on the self-hosted matrix.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T23:30:51Z",
          "mergedAt": "2026-07-10T23:30:56Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 527,
          "url": "https://github.com/kungfu-systems/kungfu/pull/527",
          "title": "shifu: promote — the freshest built dev kungfu, one command away",
          "body": "Builds happen in temporary worktrees; using a fresh dev build meant locating the worktree, digging out the dmg, and installing by hand — and a cleaned worktree took its build with it. Desktop builds now register themselves into a user-global stash (directory-as-registry under ~/.cache/kungfu/product, meta.env in build-local.env shape, KUNGFU_PRODUCT_BUILDS_KEEP retention; advisory — cannot fail a successful build). The launcher grows the consuming verbs: shifu builds lists the stash, shifu promote [--launch] installs the newest entry (mac stage-then-swap .app replace with running-app guard; win silent nsis; linux AppImage), both answering outside a checkout. The user-global build-local.env layer now loads unconditionally so rootless verbs read configuration; knobs documented in build-local.env.example.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T23:46:05Z",
          "mergedAt": "2026-07-10T23:46:10Z",
          "additions": 590,
          "deletions": 7,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 526,
          "url": "https://github.com/kungfu-systems/kungfu/pull/526",
          "title": "Assembled runtime host: neutral seam, assemble packaging leg, trunk entry (ADR-0046 stage 2)",
          "body": "## What\n\nThree steps toward the assembled runtime distribution (ADR-0046 stage 2 — assembly replaces freezing), all behind the existing `freezer` config; defaults are untouched on every platform.\n\n1. **Host-neutral seam** (`kungfu.host`): the python tree stops deriving \"where is the product root\" and \"how does a child re-enter kungfu\" from `sys.executable`. Three host forms (frozen / assembled / source); the assembled form is declared by a `kungfu-host.json` marker at the tree prefix. The product-root family (contract discovery, baked first-party manifest, agent pack, trunk lookup, variants dist detection) and the self-re-entry family route through the seam; the wrong-runtime guard learns the assembled host is blessed by construction. Also fixes two latent entry_command defects (interpreter-shaped argv0 like `python3.13` slipping the exclusion set; `python -m` handing children an unexecutable `__main__.py` path) and the baked first-party test fixtures that had gone stale against the tightened sha256 schema.\n\n2. **Assemble packaging leg** (`freezer=assemble`): stages the pinned python-build-standalone prefix under `dist/kungfu/python` (same arch-qualified key and cache the trunk uses, from the same runtime-pins manifest), resolves the runtime dependency closure from the committed lock into the tree's site-packages, and wires the flat dist root through a site-packages `.pth` — never via `PYTHON*` env vars, which would leak into satellite envs. The tree keeps python-build-standalone's `EXTERNALLY-MANAGED` marker as an install-surface guard; the build stages deps through the one explicit bypass. The stdlib prune policy is a declarative manifest (`product/stdlib-prune.json`): a fixed family-level subtraction from a complete stdlib that new dependencies never interact with, whose stale entries fail the build instead of failing in the field — deliberately unlike the nofollow-import surface this stage retires. Windows is refused by name until its layout lands.\n\n3. **Trunk entry**: the trunk binary installs under the product name `kungfu` next to the tree. Invoked as `kungfu` it keeps the subtrees it implements (env, prewarm) and execs the assembled interpreter on `-m kungfu` for everything else, verbatim — argv-transparent per the layering law. The kungfu package ships in the tree's site-packages (its standard home, freeing the dist root for the entry). First prune fill: tcl/tk family, pip/ensurepip (uv is the only install engine), headers, bin auxiliaries — tree 68M full → 56M pruned.\n\n## Validation (macOS arm64)\n\n- `ruff` / `mypy` / `biome` / `cargo fmt+clippy` clean; trunk tests pass.\n- Seam tests (8 new) + wrong-runtime guard (8) + baked first-party (2, fixture fixed) all pass; full python suite delta vs baseline is exactly the fixture fix (remaining baseline failures are binding drift against a borrowed sibling build, not touched here).\n- Assembled dist smoke through the product entry: `kungfu --version`, `kungfu kfd status --json` (libnode round trip), `kungfu env list` (native), contract registry discovery, `import tkinter` refused, `python -m pip` absent, form/product-root detection correct.\n\n## Not in this PR\n\nmacOS default flip + `verify --full` gate migration (next slice, with the full-gate evidence); Linux/Windows assembly; Nuitka disposition ledger.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T23:36:42Z",
          "mergedAt": "2026-07-10T23:48:24Z",
          "additions": 670,
          "deletions": 50,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1079,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1079",
          "title": "ci(dogfood): verify floating alpha consumer refs",
          "body": "Merge feature/vn-alpha-self-dogfood-canary into dev/v2/v2.11 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T23:50:13Z",
          "mergedAt": "2026-07-10T23:52:37Z",
          "additions": 395,
          "deletions": 33,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1081,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1081",
          "title": "fix(dogfood): bootstrap stable runtime lane",
          "body": "Merge fix/vn-alpha-self-dogfood-bootstrap into dev/v2/v2.11 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-10T23:59:05Z",
          "mergedAt": "2026-07-11T00:01:04Z",
          "additions": 99,
          "deletions": 39,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1080,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1080",
          "title": "fix(runtime): allow official floating channel selection",
          "body": "## Summary\\n- treat official floating refs such as v2 and v2-alpha as channel selections on pull requests and pushes\\n- keep train refs and exact SHAs behind the trusted workflow_dispatch permission gate\\n- apply the resolver contract across build, release verification, web surface, paper release, and publication artifact workflows\\n- document the explicit workflow-shell/runtime binding required for alpha consumers\\n\\n## Verification\\n- pnpm run check\\n- 513 unit tests passed\\n- actionlint passed for all runtime-aware reusable workflows\\n- site-libkungfu-dev PR-event canary Plan passed: https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29131439215\\n\\nFixes #1077",
          "author": "dongkeren",
          "createdAt": "2026-07-10T23:57:04Z",
          "mergedAt": "2026-07-11T00:04:02Z",
          "additions": 214,
          "deletions": 60,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1082,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1082",
          "title": "chore(release): promote v2.11 alpha",
          "body": "Promote the reviewed v2.11 development line to the alpha channel.\\n\\nThis publishes the official `v2-alpha` runtime-selection fix and self-dogfood coverage required by site and infrastructure consumers.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T00:04:53Z",
          "mergedAt": "2026-07-11T00:06:49Z",
          "additions": 663,
          "deletions": 87,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 528,
          "url": "https://github.com/kungfu-systems/kungfu/pull/528",
          "title": "shifu: fix cmd source fingerprint (rev-list instead of log --format)",
          "body": "First real-machine Windows run caught the cmd shim's source-fresh path never activating: a percent format inside a for /f backquote command is percent-processed again by the child cmd, so git received a literal %h and the empty fingerprint silently fell through to the release-pinned path. rev-list needs no format string.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T00:12:34Z",
          "mergedAt": "2026-07-11T00:12:39Z",
          "additions": 4,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1083,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1083",
          "title": "fix(dogfood): accept reviewed alpha contract",
          "body": "Merge fix/alpha-self-dogfood-contract-lock into dev/v2/v2.11 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T00:18:16Z",
          "mergedAt": "2026-07-11T00:20:40Z",
          "additions": 145,
          "deletions": 13,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 30,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/30",
          "title": "ci: adopt Buildchain v2-alpha runtime",
          "body": "## Summary\\n- move the web-surface workflow shell to the floating Buildchain v2-alpha channel\\n- accept the current v2-alpha runtime contract\\n- enforce the workflow and lock ref in repository checks and documentation\\n\\n## Verification\\n- pnpm 11.7.0 install --frozen-lockfile --ignore-scripts\\n- bash scripts/build-site.sh\\n- bash scripts/check-site.sh\\n- actionlint\\n- shellcheck\\n- Buildchain contract lock check against v2-alpha",
          "author": "dongkeren",
          "createdAt": "2026-07-10T23:45:37Z",
          "mergedAt": "2026-07-11T00:21:33Z",
          "additions": 26,
          "deletions": 14,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 74,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/74",
          "title": "ci: adopt Buildchain v2-alpha runtime",
          "body": "## Summary\\n- move the web-surface workflow shell and runtime canary to the floating Buildchain v2-alpha channel\\n- accept the current v2-alpha runtime contract in .buildchain/contract-lock.json\\n- enforce and document the alpha floating ref without changing deterministic site-bundle package pins\\n\\n## Verification\\n- pnpm 11.9.0 install --frozen-lockfile --ignore-scripts\\n- pnpm run build\\n- pnpm run check\\n- actionlint\\n- shellcheck\\n- Buildchain contract lock check against v2-alpha",
          "author": "dongkeren",
          "createdAt": "2026-07-10T23:45:34Z",
          "mergedAt": "2026-07-11T00:21:39Z",
          "additions": 26,
          "deletions": 32,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 514,
          "url": "https://github.com/kungfu-systems/kungfu/pull/514",
          "title": "feat(core): spike shared embedding membrane",
          "body": "## Summary\n\n- add one core-owned, versioned C ABI function table for context/reader/batched journal views\n- prove the same lifecycle through a dynamically loaded native KFX C++ wrapper and the existing Rust host-spike safe wrapper\n- retain mmap pages until explicit batch release; no per-frame callback and zero payload copies\n- keep KFX manifest/contract, WASM, product loader, and ADR-0046 Stage 3 out of scope\n\n## Final cross-platform evidence\n\n| Platform | control p50/p99 | 4 KiB batch p50/p99 | zero-copy / 1 MiB / idle |\n| --- | ---: | ---: | --- |\n| macOS ARM64 | 41 / 42 ns | 2.375 / 3.458 us | 0 copied / 1048576 B / 96 B |\n| Linux x64 | 18 / 19 ns | 1.002 / 2.898 us | 0 copied / 1048576 B / 96 B |\n| Windows x64 | 0 / 100 ns | 2.500 / 3.500 us | 0 copied / 1048576 B / 96 B |\n\n- final head: `faf0f266271e247c71194c3f933a69f5d2c17a6a`\n- workflow: https://github.com/kungfu-systems/kungfu/actions/runs/29132033903\n- 10 warmups, 1000 measured 16-frame / 4 KiB batches, 3 trials; median trial gates p99 <= 5 us\n- native KFX module dependency inspection: system runtime only on all three platforms\n- version/size/unknown-tail negotiation and null/busy/stale-token/close-before-release paths: pass\n- Rust host-spike: 5/5 pass\n- C11 header syntax, Rust fmt, focused Biome, actionlint, DCO, Buildchain Validate, and shifu CI: pass\n\n## Validation notes\n\n- macOS performance uses the official GitHub-hosted ARM64 runner; the self-hosted service inherits Darwin background QoS and remains useful for functional/zero-copy evidence, not latency gating.\n- hosted registry rebinding preserves the locked package name/version, non-registry source, and every sdist/wheel hash; only the registry transport URL changes from the LAN mirror to public PyPI.\n- full `./shifu lint` remains red on the existing repository baseline of 945 unrelated Biome diagnostics; focused task checks are green.",
          "author": "dongkeren",
          "createdAt": "2026-07-10T16:12:55Z",
          "mergedAt": "2026-07-11T00:26:27Z",
          "additions": 1798,
          "deletions": 111,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 530,
          "url": "https://github.com/kungfu-systems/kungfu/pull/530",
          "title": "docs(query): define runtime fact query contract",
          "body": "Merge feature/runtime-query-service-adr0048 into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T00:28:19Z",
          "mergedAt": "2026-07-11T00:28:24Z",
          "additions": 430,
          "deletions": 1,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 529,
          "url": "https://github.com/kungfu-systems/kungfu/pull/529",
          "title": "feat(episode): retain release qualification evidence",
          "body": "## Summary\n- add a Shifu-only `kungfu.episode.release-evidence/v1` generator/verifier and retained Buildchain workflow artifact\n- bind Trust Report v2 to exact source, profile, platform, toolchain, runtime artifacts, and 14 explicit hard gates\n- preserve cross-page Episode manifest history and separate the no-progress safety gate from the outer runner watchdog\n\n## Verification\n- `./shifu check`\n- `./shifu build`\n- `./shifu episode:qualify:release -- --output product/release/qualification/episode-release-evidence.json`\n  - 21/21 scenarios, 14/14 gates, correctness failures 0, semantic oracle 48 histories\n  - evidence digest `sha256:c007eb30b699f7261e06334a88d56ccf867260d42533a8affaa1282f5ac6ac74`\n- independent `verify --check-runtime --json`: schema, internal contract, and runtime hashes all pass\n\n## Boundaries\nPerformance remains trend-only; this does not claim fleet/distributed capacity or a public throughput SLO. The heavy 100k baseline is release/manual only, not a per-PR gate.\n\n## Merge note\nPlease use a merge commit so the exact qualified head `e74e9b11f88b152e6964bd6e2c7c85b173f52045` remains a parent of the integrated result.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T00:23:13Z",
          "mergedAt": "2026-07-11T00:31:10Z",
          "additions": 1364,
          "deletions": 14,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 531,
          "url": "https://github.com/kungfu-systems/kungfu/pull/531",
          "title": "docs(architecture): define layer-complete products",
          "body": "Merge feature/layer-complete-domain-horizons into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T01:11:22Z",
          "mergedAt": "2026-07-11T01:11:28Z",
          "additions": 548,
          "deletions": 9,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1087,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1087",
          "title": "feat(workflow): add automatic channel router",
          "body": "## Summary\n\n- add a generated public `build.yml` router that selects `vN-alpha` for development/prerelease intent and `vN` for stable release intent\n- preserve `.build.yml` as the advanced surface and support explicit channel or trusted runtime overrides\n- self-dogfood both automatic alpha and explicit stable lanes with separate contract locks\n- record the v2.12 minor decision and Stage 6 canary evidence\n\n## Validation\n\n- `pnpm run check` (520 tests passed)\n- train self-dogfood run 29134325376 passed both alpha and stable lanes\n- stable contract lock refreshed to reviewed `v2@618512fd874cc0125cc8a3daa07ef4d1b195777e` after run 29134106772 correctly failed closed\n\n## Release plan\n\nMerge into `dev/v2/v2.12`, then promote the existing dev-to-alpha PR to publish `2.12.0-alpha.0` and move `v2-alpha` / `v2.12-alpha` without changing stable `v2`.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T01:21:25Z",
          "mergedAt": "2026-07-11T01:23:32Z",
          "additions": 1502,
          "deletions": 172,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1084,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1084",
          "title": "chore(release): promote v2.12 alpha",
          "body": "Buildchain release line bootstrap opened v2.12. Merge this channel PR to publish the first alpha for the new minor line.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T00:43:53Z",
          "mergedAt": "2026-07-11T01:25:16Z",
          "additions": 1579,
          "deletions": 242,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1089,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1089",
          "title": "fix(action): refresh promotion bundle",
          "body": "## Summary\n\n- commit the current deterministic `promote-buildchain-ref` action bundle\n- prevent release verification from detecting a generated-file drift outside version state\n\n## Evidence\n\n- two consecutive action builds produced SHA256 `7fca06fb001b5bcb575c4dc7053551a18e086556e6ecb2ab3700ca183431c122`\n- `pnpm run check` passed with 520 tests and left only this intended generated bundle diff\n- promotion run 29134620285 reached publish source locking, then failed closed on the stale bundle\n\nFixes #1088\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T01:29:38Z",
          "mergedAt": "2026-07-11T01:31:10Z",
          "additions": 42,
          "deletions": 42,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1090,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1090",
          "title": "chore(release): retry v2.12 alpha",
          "body": "## Summary\n\nRetry the `v2.12` alpha promotion after refreshing the deterministic `promote-buildchain-ref` bundle in #1089.\n\n## Evidence\n\n- initial promotion run 29134620285 failed closed before version-state or npm publication\n- #1089 fixes the only detected out-of-version-state generated diff\n- full verification passed with 520 tests and a clean regenerated bundle\n\n## Expected release\n\nPublish `2.12.0-alpha.0`, move `v2.12-alpha` and generic `v2-alpha`, and leave stable `v2` unchanged.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T01:31:49Z",
          "mergedAt": "2026-07-11T01:33:38Z",
          "additions": 42,
          "deletions": 42,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 532,
          "url": "https://github.com/kungfu-systems/kungfu/pull/532",
          "title": "docs: add choose-your-kungfu adoption guide",
          "body": "Merge feature/choose-your-kungfu-guide into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T01:46:28Z",
          "mergedAt": "2026-07-11T01:46:34Z",
          "additions": 151,
          "deletions": 1,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 533,
          "url": "https://github.com/kungfu-systems/kungfu/pull/533",
          "title": "feat(qualification): add ADR-0049 layer harness",
          "body": "## Summary\n- add the machine-readable ADR-0049 artifact matrix and five-state schema\n- add source-bound dependency and onboarding budget baselines\n- prove the CLI/TUI workspace closure survives GUI removal\n- wire the harness and positive/negative tests into the Shifu check gate\n\n## Validation\n- ./shifu layers:qualify -- --report /tmp/kungfu-layer-qualification-final.json\n- ./shifu check:staged\n- ./shifu check reaches the pre-existing run-freeze.js platform/arch type baseline after all new gates pass",
          "author": "dongkeren",
          "createdAt": "2026-07-11T01:53:03Z",
          "mergedAt": "2026-07-11T01:53:07Z",
          "additions": 786,
          "deletions": 0,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 534,
          "url": "https://github.com/kungfu-systems/kungfu/pull/534",
          "title": "feat(atlas): seal each import batch as one Episode",
          "body": "## Summary\n\nOne `kungfu atlas import` batch now becomes one sealed Episode: `episode_begin` wraps ImportBegin, every snapshot frame receipt is attached through `episode_attach_frame`, payload identities are claimed with content-addressed refs after the mirror publishes the bytes, and ImportEnd seals the Episode. Failures abort the Episode with the error summary. This brings the atlas import batch into the Episode boundary, so `storage fsck --scope episode --verify-frames` covers atlas frames and the qualification contract (replay/depend_on) applies automatically.\n\n- The import manifest, import result, and `storage status` name the sealing `episode_id`; the Episode source field carries `atlas:<import_id>` for the reverse index.\n- `storage fsck` grows an explicit `--verify-frames` flag (episode scope only).\n- No heartbeats: an import batch is a short-lived single-writer burst (~3s against a real control-plane repo); begin/attach/end already carry its progress evidence.\n- The atlas-demo-import fixture asserts one sealed Episode per batch, full frame/ref coverage, a green verify_frames fsck, and — destructively, last — that deleting the import event journal fails the sealed Episode with `episode_attached_frame_missing` instead of passing silently.\n\n## Verify-gate repairs\n\n`verify --full` had not run since the schema-surface retirement and exposed three latent regressions, fixed here so the gate passes end to end:\n\n- `fix(examples)`: the cpp probe could no longer compile against the public schema headers (missing fmt/nlohmann/spdlog/hana wiring, C++17 pin).\n- `fix(slices)`: the fact-ledger recorder probe still compared the retired `msg_type` field and hardcoded integrity version 1.\n- `fix(tests)`: the stub-only rewind fixtures died on the new native content-hash dispatch; their stub now answers the sha256 default only.\n\n## Validation\n\n- `./shifu verify --full`: 71/71 passed.\n- Real control-plane repo smoke: import 3.1s, one sealed Episode, 1568 frames attached, 1566 payload refs, `fsck --verify-frames` green in 0.15s, qualification reports all capabilities safe.\n- Fixture negative case proves the fsck blind spot is closed (manifest present + journal page lost -> failed, `episode_attached_frame_missing`).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T01:53:28Z",
          "mergedAt": "2026-07-11T01:54:24Z",
          "additions": 331,
          "deletions": 75,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 535,
          "url": "https://github.com/kungfu-systems/kungfu/pull/535",
          "title": "shifu: self-update provenance, generations, and checkout-free upgrade",
          "body": "Once a binary was replaced you could not tell what you were running, could not get back, and going forward required a source checkout. Now: build.rs bakes a build channel (release CI assets vs local source builds) that --version prints; every replacement archives the outgoing binary into a generations ledger (--list to inspect, --rollback to restore reversibly, KUNGFU_SHIFU_GENERATIONS_KEEP deep); and outside a checkout self-update takes the newest local build slot the shim produced — the binary that drove the last build, surviving its worktree — announcing its identity before the swap. Verified end to end with two distinguishable binaries: slot upgrade, ledger, double rollback, retention.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T01:56:47Z",
          "mergedAt": "2026-07-11T01:56:55Z",
          "additions": 364,
          "deletions": 39,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 537,
          "url": "https://github.com/kungfu-systems/kungfu/pull/537",
          "title": "feat(query): add proof-carrying episode authority scan",
          "body": "## Summary\n- add typed ADR-0048 Q0 query basis, cut, result schema, and lineage contracts\n- implement deterministic Episode authority scans for head and exact historical manifest cuts\n- expose thin Python and Node service probes with reproducibility and missing-cut coverage\n\n## Validation\n- ./shifu build:core\n- Python storage suite: 28 passed\n- ./shifu foreach test:storage-binding: 5 passed\n- staged quality gate passed\n\n## Known baseline\n- ./shifu check reaches the unchanged run-freeze.js TypeScript platform-key baseline and exits 1",
          "author": "dongkeren",
          "createdAt": "2026-07-11T01:58:12Z",
          "mergedAt": "2026-07-11T01:58:18Z",
          "additions": 629,
          "deletions": 0,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 538,
          "url": "https://github.com/kungfu-systems/kungfu/pull/538",
          "title": "docs: reorder adoption guides for new users",
          "body": "Merge feature/human-first-doc-order into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T02:01:00Z",
          "mergedAt": "2026-07-11T02:01:08Z",
          "additions": 178,
          "deletions": 141,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 539,
          "url": "https://github.com/kungfu-systems/kungfu/pull/539",
          "title": "docs: normalize README link labels",
          "body": "Merge feature/readme-link-labels into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T02:10:09Z",
          "mergedAt": "2026-07-11T02:10:16Z",
          "additions": 27,
          "deletions": 27,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 536,
          "url": "https://github.com/kungfu-systems/kungfu/pull/536",
          "title": "feat(core): assembled runtime becomes the macOS product form (ADR-0046 stage 2)",
          "body": "ADR-0046 stage 2, macOS leg — the freezer config default is now platform-conditional (assemble on macOS, nuitka elsewhere), the conan chain stops threading the retired freezer option, and both product gates (dist.mjs, verify) assert the assembled tree is well-formed.\n\nEvidence on macOS arm64:\n- verify --full passes 71/71 on the assembled form (probes, slices, fixtures, episode qualification, ASan/UBSan replay).\n- Product chain green end to end: CLI archive (interpreter tree + wheels inside, installed-layout smoke) and desktop app (assembled tree with symlinks intact under Resources, single-runtime audit, zip+dmg).\n- Startup parity: assembled kungfu --version 0.17-0.19s vs frozen 0.19s baseline; native env subtree at ms-class.\n- Tree ships 56M pruned (68M full); total dist 209M, net flat against the frozen form.\n\nAlso lands, each in its own commit:\n- ADR-0048: the stdlib pruning policy record stage 2 calls for, plus the freeze retirement ledger in docs/buildchain.md.\n- Drift fixes the full gate surfaced: the cpp probe closes over the core's public header surface (fmt/spdlog/nlohmann/hana, C++23), the fact-ledger slice follows carrier_type/integrity-v2, the binding-less rewind fixtures stub kungfu.content_hash.\n- The product chain builds the pykungfu wheel on every build and hard-fails a wheel-less dist (the first assembled product build shipped without the install surface and only warned).\n\nLinux/Windows keep the frozen path until their platform legs land.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T01:57:50Z",
          "mergedAt": "2026-07-11T02:12:19Z",
          "additions": 232,
          "deletions": 16,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 77,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/77",
          "title": "fix(release): restore stable canary identity",
          "body": "## Summary\n\n- restore the stable canary workflow identity required by Buildchain release policy\n- keep the canary workflow shell on `v2-alpha` and require an exact alpha tag or SHA\n- align the repository agent entrypoint with the stable-release purpose\n\n## Validation\n\n- `npm run build`\n- `npm run check`\n- exact Buildchain candidate `e2d11404d4d5421db37b2c3e110462a2fea38861` completed no-apply canary run 29135808431 before the identity correction\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T02:12:24Z",
          "mergedAt": "2026-07-11T02:20:31Z",
          "additions": 5,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 541,
          "url": "https://github.com/kungfu-systems/kungfu/pull/541",
          "title": "feat(core): qualify native storage closure",
          "body": "## Summary\n\n- add a versioned, single-thread-affine native storage C ABI restricted to the five ADR-0049 closure operations\n- delegate all semantics to the existing libkungfu runtime storage service\n- add a native-only .kungfu lifecycle fixture covering Episode seal, reopen, head/historical query, fsck, and export\n- promote the libkungfu qualification row to passing and run the proof in the existing three-platform native workflow\n\n## Validation\n\n- `cmake --build framework/core/build --config Release --parallel 4 --target native_storage_closure_host`\n- `node framework/core/slices/native-storage-closure/run.mjs framework/core/build`\n- `./shifu layers:qualify`\n- C11 header syntax check\n- `actionlint .github/workflows/embedding-membrane-spike.yml`\n- staged repository gate passed during commit\n\n## Boundary\n\nThe ABI transports UTF-8 JSON edge projections only. It does not duplicate storage, query, fsck, or export semantics and explicitly rejects every storage operation outside the demonstrated v1 closure.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T02:29:54Z",
          "mergedAt": "2026-07-11T02:40:24Z",
          "additions": 609,
          "deletions": 4,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 542,
          "url": "https://github.com/kungfu-systems/kungfu/pull/542",
          "title": "docs(architecture): connect KFD facts to runtime admission",
          "body": "## Summary\n\n- add ADR-0051 for KFD contract-world declarations, replayable fact admission, historical interpretation, and KFD-2 trust assessment\n- document how domain facts enter Kungfu without equating durable capture with external truth\n- extend the runtime-query and KFD SDK designs with declaration-root and admission semantics\n\n## Validation\n\n- ./shifu check\n- ./shifu check:staged\n- Markdown local-link scan (214 links checked)",
          "author": "dongkeren",
          "createdAt": "2026-07-11T02:41:15Z",
          "mergedAt": "2026-07-11T02:41:21Z",
          "additions": 363,
          "deletions": 8,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 543,
          "url": "https://github.com/kungfu-systems/kungfu/pull/543",
          "title": "feat(query): add canonical planner and agent CLI",
          "body": "Merge feature/adr0048-q1-planner-cli into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T02:49:19Z",
          "mergedAt": "2026-07-11T02:49:25Z",
          "additions": 1789,
          "deletions": 42,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1092,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1092",
          "title": "fix(runtime): harden consumer checkout integrity",
          "body": "## Summary\n\n- preserve and validate authoritative published contract digests before writing consumer locks\n- bootstrap self-hosted Buildchain runtime checkouts through the existing mirror/cache and bounded GitHub fallback path\n- upload exact-SHA runtime checkout diagnostics independently from lifecycle results\n\n## Validation\n\n- targeted contract, checkout, and workflow tests: 88 passed\n- pnpm run check: 523 passed\n- workflow lint, generated site bundle, action bundles, and git diff checks passed\n- downstream constrained-network canary will use train/v2/v2.3/release-blockers-alpha1 before merge\n\nCloses #1066\nCloses #1078",
          "author": "dongkeren",
          "createdAt": "2026-07-11T02:58:31Z",
          "mergedAt": "2026-07-11T03:10:28Z",
          "additions": 231,
          "deletions": 41,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 545,
          "url": "https://github.com/kungfu-systems/kungfu/pull/545",
          "title": "docs(architecture): define KFD-2 assessment execution",
          "body": "## Summary\n\n- add ADR-0052 for claim-triggered KFD-2 assessment jobs and workspace-master coordination\n- define Assessment Episodes, single-writer assessor journals, and durable retry/idempotency\n- keep one semantic contract across Desktop process and embedded thread executors\n- document progressive disclosure from status and TrustReport to proof and replay\n\n## Validation\n\n- ./shifu check:staged\n- 233 Markdown links checked with none missing\n- ./shifu check reached the unchanged run-freeze.js platform-key TypeScript baseline failure",
          "author": "dongkeren",
          "createdAt": "2026-07-11T03:11:48Z",
          "mergedAt": "2026-07-11T03:11:53Z",
          "additions": 428,
          "deletions": 1,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1093,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1093",
          "title": "chore(release): promote v2.12.0-alpha.1",
          "body": "## Summary\n\nPromote the verified `dev/v2/v2.12` candidate containing fixes for #1066 and #1078 to the alpha channel.\n\n## Evidence\n\n- Buildchain full check: 523/523\n- PR #1092 protected checks: green\n- Live Kungfu consumer canary: exact runtime checkout succeeded on macOS ARM64, Linux x64, and Windows x64\n- Runtime checkout diagnostics matched source commit `74b383e44987d2f11422514ec9d32ed6e62136b8` on all three platforms\n\n## Release intent\n\nPublish and verify `v2.12.0-alpha.1`; do not promote stable `v2.12.0` in this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T03:11:31Z",
          "mergedAt": "2026-07-11T03:13:21Z",
          "additions": 231,
          "deletions": 41,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 544,
          "url": "https://github.com/kungfu-systems/kungfu/pull/544",
          "title": "feat(shifu): register builds from KFD-declared artifacts",
          "body": "Merge feature/shifu-kfd-registrar into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T03:07:26Z",
          "mergedAt": "2026-07-11T03:17:53Z",
          "additions": 1187,
          "deletions": 214,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 546,
          "url": "https://github.com/kungfu-systems/kungfu/pull/546",
          "title": "feat(core): qualify ecosystem storage SDKs",
          "body": "## Summary\n\n- add thin Python, Node, and Rust storage SDK artifacts over the versioned libkungfu contract\n- drive all three clean-environment installations through one seven-step semantic fixture\n- bind package provenance to the native header and fixture hashes, with artifact budgets and sibling-runtime deletion checks\n\n## Validation\n\n- `./shifu build:core`\n- `./shifu pack:sdk`\n- `./shifu layers:qualify:sdk -- --report /tmp/kungfu-sdk-qualification.json`\n- `./shifu layers:qualify -- --report /tmp/kungfu-layers-q2.json`\n- staged Python, JS/JSON, Rust formatting/lint and Cargo Clippy\n\n## Boundaries\n\nPackage publication, Linux/Windows exact-artifact evidence, and cross-platform peak-RSS remain staged and are not claimed by this PR. The repository-wide `./shifu check` still reaches the pre-existing `framework/core/.gyp/run-freeze.js` platform/architecture index typing baseline after all changed-scope gates pass.\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider billing, quota, or usage-attribution change\n- [x] No hosted-service deployment\n- [x] Adds staged package identities without publishing them\n- [x] Release evidence is exact-artifact and source-commit bound",
          "author": "dongkeren",
          "createdAt": "2026-07-11T03:29:35Z",
          "mergedAt": "2026-07-11T03:30:44Z",
          "additions": 1643,
          "deletions": 14,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1095,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1095",
          "title": "fix(runtime): decouple checkout bootstrap from channel",
          "body": "## Summary\n\n- resolve and pin the reusable workflow shell commit independently from the selected runtime\n- carry the workflow shell checkout bootstrap into native/container jobs\n- use that bootstrap for both runtime and consumer source checkout\n- preserve compatibility when `@vN-alpha` routes a stable release to an older `vN` runtime\n\n## Regression\n\n- full `pnpm run check` passes\n- workflow surface test proves no source checkout invokes the selected runtime copy\n- live train canary will run the new workflow shell with `buildchain-ref: v2` to exercise the older stable runtime\n\nCloses #1094",
          "author": "dongkeren",
          "createdAt": "2026-07-11T03:25:32Z",
          "mergedAt": "2026-07-11T03:31:27Z",
          "additions": 53,
          "deletions": 25,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 547,
          "url": "https://github.com/kungfu-systems/kungfu/pull/547",
          "title": "feat(query): bind declaration admission proof",
          "body": "ADR-0048 Q1 S2: bind explicit KFD-1 declaration coordinates and typed admission outcomes into QueryDefinition, LogicalPlan, and proof lineage; fail closed on unregistered, incompatible, ambiguous, or unverifiable declarations.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T03:31:26Z",
          "mergedAt": "2026-07-11T03:31:32Z",
          "additions": 424,
          "deletions": 65,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1096,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1096",
          "title": "chore(release): promote v2.12.0-alpha.2",
          "body": "## Summary\n\nPromote the corrected v2.12 candidate after `v2.12.0-alpha.1` self-dogfood exposed and #1094 fixed the stable-route bootstrap compatibility gap.\n\n## Evidence\n\n- full Buildchain check: 523/523\n- protected PR #1095 checks: macOS, Windows, Linux container, Verify all green\n- live train alpha/stable self-dogfood: https://github.com/kungfu-systems/buildchain/actions/runs/29138083017\n- stable route used current `v2` runtime and completed runtime checkout, locked source checkout, install, build, verify, and floating-ref SHA verification\n\n## Release intent\n\nPublish and verify `v2.12.0-alpha.2`; keep stable `v2.12.0` pending the new candidate canary and soak.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T03:32:02Z",
          "mergedAt": "2026-07-11T03:33:52Z",
          "additions": 53,
          "deletions": 25,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1098,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1098",
          "title": "fix(release): retry visible-parent state updates",
          "body": "## Summary\n\n- retry a durable release-state `updateRef` when GitHub returns non-fast-forward while still reporting the expected parent\n- keep retries bounded and non-forced\n- cover the exact ref-propagation signal seen during the alpha.2 promotion attempt\n- rebuild the promoted action bundle\n\n## Evidence\n\n- targeted durable-state race tests pass\n- full `pnpm run check` passes\n- failure evidence: https://github.com/kungfu-systems/buildchain/actions/runs/29138244936\n\nCloses #1097",
          "author": "dongkeren",
          "createdAt": "2026-07-11T03:46:44Z",
          "mergedAt": "2026-07-11T03:48:38Z",
          "additions": 85,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1099,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1099",
          "title": "chore(release): retry v2.12 alpha after state fix",
          "body": "## Summary\n\nRetry the v2.12 alpha promotion with the bounded durable release-state ref propagation fix from #1098.\n\nThe prior alpha.2 attempt created no tag, release, npm version, or floating-ref movement; it stopped while persisting the transaction state. The publisher must preserve that failed immutable transaction and choose the next safe alpha identity if required.\n\n## Evidence\n\n- exact online failure signal is covered by regression\n- full Buildchain check passes\n- protected PR #1098 checks pass\n- alpha/stable checkout compatibility dogfood remains green: https://github.com/kungfu-systems/buildchain/actions/runs/29138083017",
          "author": "dongkeren",
          "createdAt": "2026-07-11T03:48:58Z",
          "mergedAt": "2026-07-11T03:51:04Z",
          "additions": 85,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 548,
          "url": "https://github.com/kungfu-systems/kungfu/pull/548",
          "title": "feat(product): qualify headless and GUI layer closures",
          "body": "Summary: expose the existing storage service through public API, KFX, and GUI capability surfaces; qualify CLI and GUI against one semantic fixture; bind both distributions to an exact compatibility manifest and clean source commit; prove GUI deletion leaves lower data byte-identical and healthy. Validation: shifu build, dist --dir, exact surface qualifier, generic layer qualifier, SDK fixture, and 7 product tests pass. Full shifu check passes the new gates and stops only on the pre-existing framework/core/.gyp/run-freeze.js platform and architecture TypeScript errors. Boundary: exact local macOS arm64 artifacts pass; installer-specific uninstall, publication, other platforms, and resident-memory budgets remain separate release claims.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T04:03:44Z",
          "mergedAt": "2026-07-11T04:05:08Z",
          "additions": 953,
          "deletions": 6,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 549,
          "url": "https://github.com/kungfu-systems/kungfu/pull/549",
          "title": "refactor(storage): establish typed service boundary",
          "body": "## Summary\n\n- establish Hana-owned POD storage records and typed C++ service requests/results\n- keep FlatBuffers ownership for KFX/business payloads, including the ActionEnvelope vertical slice\n- expose Python and Node projections through recursive Hana bindings; confine JSON to explicit edge adapters\n- reuse typed journal folds and sqlite_orm projections for Source, Manifest, Entry, Episode, repair, fsck, export/import, and layout operations\n- enforce single schema ownership, no JSON core service semantics, and exclusive projection routing\n\nThis is the linear-history replacement for #522; its tree is byte-for-byte identical to the Mac-verified head of that PR.\n\n## Mac verification\n\n- `./shifu build:core`\n- targeted Python storage/action/query tests: 57/57\n- native Node storage/action tests: 7/7\n- `./shifu check:types`\n- `./shifu check`\n- schema authority negative fixtures: 5/5\n\nCI is currently unavailable; merge approval is based on the completed Mac build and test evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T04:17:33Z",
          "mergedAt": "2026-07-11T04:17:52Z",
          "additions": 12357,
          "deletions": 2890,
          "changedFiles": 84
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1100,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1100",
          "title": "fix(release): preflight candidate evidence before promotion",
          "body": "## Summary\n\n- add a metadata-only PR-stage release-candidate evidence job after serialized intent revalidation\n- block the full promotion job before candidate dependency installation when channel PR, workflow run, passport pair, or payload metadata is missing or stale\n- retain the complete evidence download and validation in the publication job at the existing trust boundary\n- keep expected manual dry-run failures visible without creating automated workflow-friction issues\n- document the early-failure contract and publish it through the generated site facts\n\n## Validation\n\n- `pnpm run check` (525/525 unit tests, workflow lint, site bundle check, all action bundles)\n- `npm pack --dry-run --json --registry=https://registry.npmjs.org/`\n- live metadata-only resolver smoke: valid alpha promotion SHA passed without an output directory\n- historical #1085/#1086 SHA failed before payload download or candidate dependency installation\n- real GitHub workflow dry-run proved the new preflight job completes before the full promotion job\n- `git diff --check`\n\nCloses #1085\nCloses #1086\nCloses #1101",
          "author": "dongkeren",
          "createdAt": "2026-07-11T04:40:49Z",
          "mergedAt": "2026-07-11T04:46:30Z",
          "additions": 99,
          "deletions": 20,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 551,
          "url": "https://github.com/kungfu-systems/kungfu/pull/551",
          "title": "feat(query): add SQLite SQL conformance",
          "body": "Linear replacement for #550 after the repository rejected merge commits during rebase-only integration. Same validated tree as #550.\\n\\nValidation:\\n- ./shifu build\\n- 95 Python tests passed\\n- staged gates passed\\n\\nNode binding suite discovered 7 tests but skipped all because the expected dist binding path was unavailable.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T04:52:37Z",
          "mergedAt": "2026-07-11T04:53:12Z",
          "additions": 831,
          "deletions": 87,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 553,
          "url": "https://github.com/kungfu-systems/kungfu/pull/553",
          "title": "fix(core): qualify action envelope schema type",
          "body": "## Summary\n- fully qualify the `schema_ref` type used by `action::envelope`\n- preserve the existing public member name and serialized contract\n\n## Evidence\n- fixes the GCC error: declaration of `envelope::schema_ref` changes meaning of `schema_ref`\n- Apple Clang C++23 syntax probe passes\n- one-line source change with DCO sign-off",
          "author": "dongkeren",
          "createdAt": "2026-07-11T05:03:25Z",
          "mergedAt": "2026-07-11T05:04:40Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 556,
          "url": "https://github.com/kungfu-systems/kungfu/pull/556",
          "title": "fix(core): pin native closure query basis",
          "body": "## Summary\n- make the native storage C consumer send explicit contract-world and fact-surface declaration references\n- intentionally pin the current built-in roots so declaration drift fails closed\n\n## Evidence\n- reproduces the latest planner requirement for explicit declarations\n- `native_storage_closure_host` builds and its complete lifecycle/query/fsck/export harness passes locally\n- no C ABI or storage implementation change",
          "author": "dongkeren",
          "createdAt": "2026-07-11T05:28:32Z",
          "mergedAt": "2026-07-11T05:38:55Z",
          "additions": 10,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 557,
          "url": "https://github.com/kungfu-systems/kungfu/pull/557",
          "title": "feat(storage): episode bundles carry owned bytes and import materializes them",
          "body": "Merge feature/episode-bundle-self-contained into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T05:40:49Z",
          "mergedAt": "2026-07-11T05:40:55Z",
          "additions": 1286,
          "deletions": 44,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1102,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1102",
          "title": "chore(release): promote v2.12.0-alpha.4",
          "body": "## Summary\n\n- promote the current v2.12 development head after PR #1100\n- publish the next immutable v2.12 alpha candidate\n- advance v2.12-alpha and v2-alpha after the release transaction completes\n- start fresh exact-candidate stable canary and soak evidence\n\n## Candidate\n\n- source: `dev/v2/v2.12`\n- source SHA: `87055553ae85ac7facc683c62de3945a831828c5`\n- expected version: `v2.12.0-alpha.4`\n- included fixes: #1085, #1086, #1101 via #1100\n\n## Validation\n\n- PR #1100 protected checks passed on macOS, Windows, and Linux\n- Buildchain full check passed: 525/525 plus workflow lint, generated site, and action bundles\n- repository currently has no open issues",
          "author": "dongkeren",
          "createdAt": "2026-07-11T05:40:16Z",
          "mergedAt": "2026-07-11T05:43:10Z",
          "additions": 99,
          "deletions": 20,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 558,
          "url": "https://github.com/kungfu-systems/kungfu/pull/558",
          "title": "feat(core): assembled runtime becomes the Linux product default (ADR-0046 stage 2)",
          "body": "ADR-0046 stage 2, Linux leg — the platform default flips (only Windows keeps nuitka now) and the prune manifest gains its linux section, grounded on the real cpython-3.13.14-linux-x86_64-gnu prefix. share/terminfo deliberately stays (curses/readline may consult it at runtime; ADR-0050 semantic-disjoint bar).\n\nGrounding caught a real key bug: both pbs-key sites (run-freeze pbsKey, the trunk's python_request) hardcoded the -none libc segment, which only exists for macOS/Windows — on Linux the request must end in -gnu or uv refuses it by name. Both mappings now derive the libc field per platform.\n\nEvidence on linux-x64 (agent-120):\n- verify --full 73/73 green on the assembled form (probes, slices, fixtures, episode qualification, ASan/UBSan replay) at the pre-drift base; post-rebase revalidation on the touched surfaces (mypy repo-green, closure slice green).\n- Product chain green: CLI archive kungfu-episodes-cli-linux-x64.tar.gz with interpreter tree + wheel inside, installed-layout smoke passed.\n- Startup 0.11-0.12s; tree 93M pruned (104M full); import tkinter and python -m pip both refused in the shipped tree.\n\nAlso lands, each in its own commit: the query CLI mypy gate fix (typed runtime_dir access + NoReturn on _fail, extended over the new engine call site), the action-envelope encoding lookup type narrowing, and the closure slice declaring the explicit basis ADR-0048 now requires (pinned built-in declarations — drift without a version bump fails the slice by design).\n\nNote: dev-tip verify --full currently carries 5 unrelated failures on linux from the storage/qualification lines (deterministic, reproduce with the dev-tip python tree, untouched by this diff); recorded for their owning lines.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T05:42:05Z",
          "mergedAt": "2026-07-11T05:44:07Z",
          "additions": 46,
          "deletions": 11,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 561,
          "url": "https://github.com/kungfu-systems/kungfu/pull/561",
          "title": "feat(core): add libwasm shared embedding membrane spike",
          "body": "## Summary\n\n- add a bounded Rust-host libwasm spike behind the existing versioned `kf_embedding_api_v1` capability membrane\n- run one shared core-Wasm guest through Wasmtime 46.0.1 and measured Wasmer 7.2.0 fallback adapters, each isolated behind two C ABI symbols\n- prove batch journal access, explicit release, trap/panic containment, copy accounting, latency/throughput/idle budgets, and no per-frame FFI\n- extend the hosted macOS ARM64 / Linux x64 / Windows x64 membrane matrix without changing KFX manifest/contract or advancing ADR-0046 Stage 3\n\n## Validation\n\n- `./shifu check`\n- `actionlint .github/workflows/embedding-membrane-spike.yml`\n- CMake Release build of shared embedding, native storage closure, and libwasm targets\n- all three local harnesses PASS on macOS ARM64\n- prior three-platform evidence run: 29138796710\n\n## Delivery note\n\nSupersedes #540 for merge delivery only. GitHub correctly refused rebase merge of #540 because its branch accumulated merge commits while tracking a moving dev branch. This PR replays the same 13 task commits onto current `dev/v4/v4.0` with no merge commits, preserving #540 as the full implementation and CI audit trail.\n\n## Open production gates\n\nWasmer CPU metering, WIT/Component ABI decisions, admission/receipts, and production compatibility remain explicitly out of scope.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T05:52:34Z",
          "mergedAt": "2026-07-11T05:52:59Z",
          "additions": 4646,
          "deletions": 18,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 560,
          "url": "https://github.com/kungfu-systems/kungfu/pull/560",
          "title": "fix(storage): harden Hana SQLite projections",
          "body": "## Summary\n\n- preserve enum, fixed-array, and vector BLOB roundtrips through sqlite_orm\n- rebuild Source, Manifest, and Episode projections atomically on one SQLite connection\n- derive primary-key normalization and canonical content digests from Hana schema metadata\n- keep verification read-only and detect same-row-count corruption, including append-only export subset integrity\n- batch replay through sqlite_orm replace_range\n\n## Mac validation\n\n- `./shifu check`\n- `./shifu verify --full` — 69/74; remaining failures are existing Episode contention / Atlas demo / rewind capture baselines\n- targeted storage regression suite — 51 passed\n- `storage-demo-node-binding` fixture passed\n- Hana SQLite capability slice passed\n- ASan/UBSan view replay passed\n\nCI is not used as the merge gate for this change.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T05:52:27Z",
          "mergedAt": "2026-07-11T05:54:52Z",
          "additions": 873,
          "deletions": 299,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 559,
          "url": "https://github.com/kungfu-systems/kungfu/pull/559",
          "title": "feat(core): admit domain facts",
          "body": "## Summary\n- add ADR-0051 domain-fact authority with effective-time declaration history\n- implement five admission outcomes plus correction, retraction, and conflict handling\n- expose the shared C++ contract through Python, Node, Rust, CLI, and KFD evidence\n- retain the current ActionEnvelope, typed-storage, SQLite query, native closure, and self-contained Episode bundle mainline\n\n## Verification\n- Conan Node + Python core build\n- 66 Python tests (storage, query, action envelope, Episode bundle)\n- 8 Node binding tests\n- native storage closure harness\n- kungfu-sdk Rust tests\n- `./shifu check`\n\n## Known boundary\n- source validation is complete; frozen product artifact qualification remains the release pipeline responsibility.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T05:51:48Z",
          "mergedAt": "2026-07-11T06:11:25Z",
          "additions": 2450,
          "deletions": 50,
          "changedFiles": 39
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 562,
          "url": "https://github.com/kungfu-systems/kungfu/pull/562",
          "title": "feat(query): add resumable changelog views",
          "body": "## Summary\\n- add a native typed kungfu.query.changelog/v1 stream with integrity-checked resume tokens and reproducible authority cuts\\n- expose changelog paging through storage, Python CLI, TypeScript/KFX contracts, and saved-view JSON\\n- add System Status table, timeline, diff, and causal-graph reference views with visible evidence and Gap handling\\n- document the Q3 contract and extend native, Python, CLI, and TypeScript coverage\\n\\n## Correctness properties\\n- resume tokens pin the query definition, logical plan, authority frontiers, result hashes, batch, and next message index\\n- opaque frame UIDs locate exact cuts; authority record counts establish monotonic advancement\\n- replay is deterministic and idempotent, with bounded paging and explicit Gap on unreproducible state\\n- GUI state is reconstructed from the native changelog; saved views persist only QueryDefinition and ViewSpec\\n\\n## Validation\\n- ./shifu check\\n- ./shifu --filter @kungfu-tech/core compile\\n- targeted native/Python storage tests\\n- query CLI tests\\n- TypeScript query tests\\n- API and KFX tsc --noEmit\\n- System Status KFX bundle build\\n\\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-11T06:12:38Z",
          "mergedAt": "2026-07-11T06:17:45Z",
          "additions": 1887,
          "deletions": 34,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 563,
          "url": "https://github.com/kungfu-systems/kungfu/pull/563",
          "title": "test(core): stabilize libwasm copy evidence",
          "body": "## Summary\n\n- average eight consecutive 1 MiB guest copies inside each throughput observation\n- keep the existing 1 GiB/s gate and outer three-trial median unchanged\n- account for every measured host-to-guest byte and document the sampling boundary\n\n## Why\n\nPR #561 merged the libwasm spike before its late-attached embedding matrix completed. The macOS job then exposed that one isolated 1 MiB timing sample could be dominated by runner scheduling: Wasmer measured 1.63 GB/s once and about 0.70 GB/s twice. This patch measures sustained copy throughput instead of a single scheduling interval; it does not lower any acceptance budget.\n\n## Validation\n\n- `./shifu check`\n- incremental Release adapter/host build\n- local macOS ARM64 libwasm harness PASS with exact byte accounting\n\nFollow-up to #561; supersedes the unmerged fix commit on its now-closed delivery branch.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T06:20:27Z",
          "mergedAt": "2026-07-11T06:48:39Z",
          "additions": 22,
          "deletions": 7,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1091,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1091",
          "title": "chore(release): promote v2.12.0",
          "body": "## Summary\n\n- promote the tested v2.12.0-alpha.4 lineage to the protected stable channel\n- publish @kungfu-tech/buildchain@2.12.0\n- advance the stable v2.12 and v2 floating refs after transaction finalization\n\n## Included changes\n\n- add the automatic alpha/stable consumer channel router\n- add generic vN-alpha floating tags and self-dogfood coverage\n- consolidate release evidence and harden promotion serialization/canonicalization\n- restore the authoritative site-libkungfu-dev stable canary identity\n- include the completed issue fixes through #1100\n\n## Validation\n\n- candidate v2.12.0-alpha.4 is published from f8b67b1728f6719b4873d9c6e954e5d8c3ece2c3\n- npm alpha and the v2-alpha / v2.12-alpha floating refs resolve to the exact candidate\n- Build Surface Fixture and Binary Distribution succeeded on the candidate\n- Buildchain self-dogfood succeeded on rerun; the first stable-lane summary attempt hit a transient Node 22 undici assertion during pnpm network I/O\n- exact-SHA site-libkungfu-dev stable canary succeeded with all apply jobs skipped: https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29141861127\n- authorized canary status was attested by kungfu-origin at 2026-07-11T05:52:09Z\n- earliest stable promotion time after the mandatory one-hour soak: 2026-07-11T06:52:09Z (2026-07-11 14:52:09 Asia/Shanghai)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T02:17:40Z",
          "mergedAt": "2026-07-11T07:02:00Z",
          "additions": 2038,
          "deletions": 321,
          "changedFiles": 45
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1104,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1104",
          "title": "fix(release): separate stable candidate version",
          "body": "## Summary\n\n- keep the release-candidate passport artifact version for payload validation and publication\n- resolve the Buildchain release-line alpha independently from the checked-out channel manifest\n- feed the exact Buildchain alpha version into the stable canary/soak gate\n- fail before publication when the checked-out release line does not declare an exact alpha\n\n## Root cause\n\nThe stable gate consumed `release-candidate-version`, which is the libnode-shaped payload version (`22.22.3-kf.0`) for Buildchain's fixture. The gate instead requires the Buildchain release-line candidate (`2.12.0-alpha.4`). Reusing one field for both meanings caused the stable promotion to fail closed after PR #1091 merged.\n\n## Validation\n\n- `node --test tests/build-surface.test.mjs`\n- `pnpm run check`\n\nFixes #1103\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T07:08:46Z",
          "mergedAt": "2026-07-11T07:10:31Z",
          "additions": 27,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1106,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1106",
          "title": "fix(release): compare new minor to stable major",
          "body": "## Summary\n\n- keep the 24-hour stable cooldown scoped to preceding patches on the same minor\n- independently select the latest prior stable in the same major as the product-diff baseline\n- allow a first stable on a new minor only when that cross-minor comparison contains declared product or contract paths\n- cover the v2.11.13 to v2.12.0-alpha.0 transition in the collector test\n\n## Root cause\n\nFor `v2.12.0-alpha.4`, there is intentionally no previous stable on minor `2.12`. The collector reused that same-minor cooldown lookup for product-diff comparison, producing an empty path set even though the candidate differs materially from current stable `v2.11.13`.\n\n## Validation\n\n- `node --test tests/stable-release-gate.test.mjs tests/stable-release-gate-cli.test.mjs`\n- live read-only gate evaluation for `v2.12.0-alpha.4`: `allow`, 90 compared paths, required canaries and soak passed\n- `pnpm run check`\n\nFixes #1103\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T07:17:30Z",
          "mergedAt": "2026-07-11T07:19:22Z",
          "additions": 33,
          "deletions": 10,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1107,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1107",
          "title": "fix(release): carry stable gate fixes into v2.12",
          "body": "## Summary\n- carry the exact Buildchain alpha candidate resolver into the v2.12 release line\n- compare a first stable on a new minor against the preceding stable in the same major\n- preserve same-minor stable cooldown semantics\n\n## Validation\n- `pnpm run check`\n- live stable-gate evaluation for `v2.12.0-alpha.4`\n\nCloses #1105",
          "author": "dongkeren",
          "createdAt": "2026-07-11T07:24:08Z",
          "mergedAt": "2026-07-11T07:26:25Z",
          "additions": 60,
          "deletions": 14,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1109,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1109",
          "title": "fix(release): bind soak to exact alpha evidence",
          "body": "## Summary\n- reject PR-stage release-candidate runs whose head SHA differs from the exact alpha candidate\n- recover the successful Build Surface run bound to the candidate SHA\n- keep soak time anchored to immutable alpha evidence\n\n## Validation\n- `pnpm run check` (525 tests)\n- live gate evaluation with supplemental PR run `29144431364` resolves exact-alpha run `29141753378` and returns `allow`\n\nCloses #1105\nCloses #1108",
          "author": "dongkeren",
          "createdAt": "2026-07-11T07:31:39Z",
          "mergedAt": "2026-07-11T07:33:31Z",
          "additions": 40,
          "deletions": 8,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1110,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1110",
          "title": "fix(release): carry exact-alpha soak evidence into v2.12",
          "body": "## Summary\n- carry the exact-alpha release-candidate evidence binding into the v2.12 release transaction\n- prevent supplemental PR builds from resetting an already satisfied alpha soak\n\n## Validation\n- `pnpm run check` (525 tests)\n- live stable gate returns `allow` and resolves run `29141753378`\n\nRelease follow-up for #1109.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T07:33:43Z",
          "mergedAt": "2026-07-11T07:35:39Z",
          "additions": 40,
          "deletions": 8,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1112,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1112",
          "title": "chore(release): promote v2.12.0-alpha.5",
          "body": "## Summary\n- promote the three stable-gate fixes through the alpha channel\n- create an alpha candidate whose tree can be promoted to stable without bypassing source equality\n\n## Validation\n- `pnpm run check` (525 tests)\n- exact-alpha evidence lookup live gate evaluation\n\nCloses #1111",
          "author": "dongkeren",
          "createdAt": "2026-07-11T07:39:30Z",
          "mergedAt": "2026-07-11T07:41:18Z",
          "additions": 100,
          "deletions": 22,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 566,
          "url": "https://github.com/kungfu-systems/kungfu/pull/566",
          "title": "refactor(runtime): retire journal Session architecture",
          "body": "## Summary\n- remove the legacy journal Session record, markers, SQLite index, C++ finder/builder, Node SessionStore, Python bindings/module, and session-oriented journal CLI tools\n- replace Master session liveness with registry liveness and derive SDK replay anchors from typed Episode manifests\n- split the mixed runtime/cache bucket into runtime/state_cache and runtime/projection, with an ADR and blocking anti-regression gate\n\n## Mac validation\n- ./shifu build\n- ./shifu check\n- pnpm --filter @kungfu-tech/api run test:query\n\nCI is currently unavailable; per maintainer direction this PR is qualified by the Mac build and tests above.\n\nBreaking pre-release cleanup; no stable-v4 Session compatibility shim is retained.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T07:44:43Z",
          "mergedAt": "2026-07-11T07:46:08Z",
          "additions": 778,
          "deletions": 1497,
          "changedFiles": 65
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 568,
          "url": "https://github.com/kungfu-systems/kungfu/pull/568",
          "title": "feat(trust): implement ADR-0052 assessment runtime",
          "body": "## Summary\n- add the typed durable KFD-2 assessment lifecycle and dependent Assessment Episodes\n- schedule isolated assessor processes from workspace master with timeout cancellation and retry\n- expose equivalent thread execution plus CLI, GUI, SDK, and native storage edges\n\n## Validation\n- ./shifu check\n- Python storage: 54 passed\n- master service: 11 passed\n- host seam: 9 passed\n- Node native storage binding: 9 passed, 0 skipped\n- GUI production build\n- native storage closure: PASS\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-11T08:03:06Z",
          "mergedAt": "2026-07-11T08:06:25Z",
          "additions": 1998,
          "deletions": 14,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 569,
          "url": "https://github.com/kungfu-systems/kungfu/pull/569",
          "title": "feat(libwasm): ship governed production runtime",
          "body": "Promotes the validated libwasm membrane into the default build, frozen runtime, KFX capability contract, dual-engine qualification, KFD evidence, and release artifact checks. Wasmtime remains primary; Wasmer is metered fallback behind the same C ABI.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T08:15:21Z",
          "mergedAt": "2026-07-11T08:15:27Z",
          "additions": 5307,
          "deletions": 45,
          "changedFiles": 40
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 570,
          "url": "https://github.com/kungfu-systems/kungfu/pull/570",
          "title": "feat(query): add bounded temporal attention patterns",
          "body": "## Summary\n- add one fail-closed temporal pattern family to QueryDefinition and LogicalPlan\n- compile the same algebra from constrained MATCH_RECOGNIZE SQL and expose it through Python CLI, TypeScript/KFX, and an attention reference view\n- prove Buildchain and non-Buildchain fixtures, authority/SQLite conformance, and late terminal RowRetract behavior\n\n## Boundaries\n- ordered two-step subsequence only, repeated 1..16 times within 1ns..30d\n- explicit as_of_time closes optional absence\n- attribution is recorded evidence; no causal relationship is inferred\n- alternation, nesting, unbounded waits, and general CEP remain unsupported\n\n## Validation\n- ./shifu --filter @kungfu-tech/core compile\n- 60 Python core/CLI tests passed\n- @kungfu-tech/api tests and typecheck passed\n- System Status KFX build passed\n- ./shifu check passed",
          "author": "dongkeren",
          "createdAt": "2026-07-11T08:20:41Z",
          "mergedAt": "2026-07-11T08:21:25Z",
          "additions": 1065,
          "deletions": 103,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1114,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1114",
          "title": "fix(release): honor immediate stable authority",
          "body": "## Summary\n- treat an exact `BUILDCHAIN_STABLE_RELEASE_NOW` repository authority as the final human release instruction\n- record the immediate-release reason in workflow evidence\n- keep the default canary/soak gate when no exact authority is present\n\n## Validation\n- `pnpm run check` (525 tests)\n\nThis restores the invariant that soak is a default quality mechanism, not a veto over an explicit stable release instruction.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T08:20:26Z",
          "mergedAt": "2026-07-11T08:22:44Z",
          "additions": 37,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1113,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1113",
          "title": "chore(release): promote v2.12.0",
          "body": "## Summary\n- promote the fully validated `v2.12.0-alpha.5` tree to stable\n- retain exact-alpha Build Surface, binary, dogfood, site canary, and soak evidence\n\n## Candidate\n- tag: `v2.12.0-alpha.5`\n- SHA: `349a81e6ad8f96c18edc9ba9304ef9f3e1c324c8`\n- alpha promotion: `29144940344`\n- binary distribution: `29145005487`\n- self-dogfood: `29145013962`\n\nThe PR will remain unmerged until the exact-SHA site canary and 3600-second soak pass.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T07:46:58Z",
          "mergedAt": "2026-07-11T08:23:00Z",
          "additions": 17,
          "deletions": 17,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 571,
          "url": "https://github.com/kungfu-systems/kungfu/pull/571",
          "title": "fix(trust): execute embedded assessments on a real thread",
          "body": "## Summary\n\n- dispatch embedded `thread` assessments on a dedicated joined C++ thread\n- persist placement evidence without changing semantic report identity\n- prove inline/thread report equivalence in the native Node binding suite\n- update ADR-0051/0052 implementation status\n\n## Validation\n\n- `./shifu check`\n- native storage binding suite: 10 passed, 0 failed\n- staged commit gates\n- core compilation reached modified trust objects and bindings; full build is currently blocked in unrelated libwasm Cargo dependency fetches by the office proxy returning 404 for addr2line\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-11T08:36:39Z",
          "mergedAt": "2026-07-11T08:37:23Z",
          "additions": 184,
          "deletions": 70,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 572,
          "url": "https://github.com/kungfu-systems/kungfu/pull/572",
          "title": "refactor(storage): retire legacy journal lifecycle tools",
          "body": "## Summary\n\n- retire the loose-file `kungfu journal` lifecycle command group and its KFA archive/prune helpers\n- remove the non-authoritative Storage `archive_dir` surface and stale runtime path parsers\n- align the journal manager with typed Episode replay anchors and add TypeScript checking\n- correct the duplicate ADR identity (`0054` remains libwasm; Session retirement becomes `0055`) and record lifecycle retirement as `0056`\n- add executable gates for ADR identity uniqueness and the Storage/Episode journal authority boundary\n\n## Validation\n\n- `./shifu fix`\n- `./shifu check`\n- `KF_LIBWASM_CARGO_REGISTRY=sparse+https://rsproxy.cn/index/ ./shifu build`\n- `./shifu --filter @kungfu-tech/core run kungfu --help` (no `journal` command; `storage` and `query` remain)\n- `git diff --check`\n\nCI is currently unavailable; this change is being merged against the completed macOS build and test evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T08:58:23Z",
          "mergedAt": "2026-07-11T08:58:44Z",
          "additions": 243,
          "deletions": 453,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1115,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1115",
          "title": "feat(release): add qualified alpha stable patrol",
          "body": "Merge feature/qualified-alpha-stable-patrol into dev/v2/v2.12 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T09:13:26Z",
          "mergedAt": "2026-07-11T09:15:19Z",
          "additions": 1979,
          "deletions": 122,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1116,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1116",
          "title": "chore(release): promote qualified alpha stable patrol",
          "body": "Promote the merged qualified-alpha candidate ledger and Stable Candidate Patrol to the public v2 alpha channel.\\n\\nEvidence:\\n- PR #1115 merged to dev/v2/v2.12\\n- pnpm run check: 538 tests passed\\n- train dogfood run 29147440568 succeeded\\n- live dry-run reconstructed v2.12.0 history and left v2.12.1-alpha.0 fail-closed without required evidence",
          "author": "dongkeren",
          "createdAt": "2026-07-11T09:16:51Z",
          "mergedAt": "2026-07-11T09:18:40Z",
          "additions": 2014,
          "deletions": 124,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1118,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1118",
          "title": "fix(dogfood): accept current stable contract",
          "body": "## Summary\n\n- refresh the Buildchain self-consumer stable contract lock to the current `v2` runtime\n- keep alpha and stable self-dogfood locks channel-specific\n- restore stable-consumer dogfood without weakening contract compatibility checks\n\n## Validation\n\n- `corepack pnpm@11.7.0 run check`\n- direct contract-lock evaluation against `refs/tags/v2` reports `unchanged`\n\n## Evidence\n\nThe previous self-dogfood run failed only in the stable consumer because the committed stable lock still referenced a pre-v2.12 contract. The alpha consumer succeeded.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T09:31:42Z",
          "mergedAt": "2026-07-11T09:33:52Z",
          "additions": 13,
          "deletions": 8,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1120,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1120",
          "title": "chore(release): promote v2.12 stable dogfood lock",
          "body": "## Release intent\n\nPromote the reviewed stable self-dogfood contract lock fix into the next v2.12 alpha.\n\n## Included\n\n- qualified-alpha stable candidate patrol mechanism from #1115\n- stable contract lock refresh from #1118\n\n## Validation\n\n- full `pnpm run check` passes (538 tests)\n- current `v2` contract-lock evaluation is `unchanged`\n- PR #1118 checks passed and was approved by `kungfu-origin`",
          "author": "dongkeren",
          "createdAt": "2026-07-11T09:34:15Z",
          "mergedAt": "2026-07-11T09:36:11Z",
          "additions": 13,
          "deletions": 8,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 574,
          "url": "https://github.com/kungfu-systems/kungfu/pull/574",
          "title": "feat(query): add workspace saved query catalog",
          "body": "## Summary\n- journal versioned saved-query create, update, delete facts as FlatBuffers ActionEnvelope events sealed into Episodes under the workspace runtime home\n- expose shared catalog lifecycle through native storage, Python CLI, TypeScript/KFX capability, System Status GUI, and agent discovery\n- bind saved query id, revision, and content hash to query runs while keeping portable saved-view JSON as the import/export edge\n\n## Validation\n- ./shifu check\n- Python query CLI: 8 passed\n- native Node storage binding: 11 passed, 0 skipped\n- API typecheck and query tests: 4 passed\n- KFX and Status KFX builds\n- kungfu agent verify: ok, no missing/stale/hidden APIs\n- libkungfu, Python, and Node native targets compile and link\n\n## Environment note\nThe full all-target build remains locally blocked by sequential 404s from the configured LAN Cargo proxy. Exact locked crate checksums were verified; this is tracked separately as dogfood friction and is not a source/query failure.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T09:44:28Z",
          "mergedAt": "2026-07-11T09:46:54Z",
          "additions": 1253,
          "deletions": 53,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 575,
          "url": "https://github.com/kungfu-systems/kungfu/pull/575",
          "title": "ci: accept the v2-alpha buildchain contract in the consumer lock",
          "body": "The v2-alpha switch updated workflow references but left the consumer contract lock pinned to the v2 contract world — the trust gate correctly rejected runs as breaking drift. Regenerate the lock against the current v2-alpha runtime (4cba0848) so accepted surfaces match the consumed channel.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T09:52:37Z",
          "mergedAt": "2026-07-11T09:52:42Z",
          "additions": 14,
          "deletions": 9,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 576,
          "url": "https://github.com/kungfu-systems/kungfu/pull/576",
          "title": "feat(facts): add durable fact library manager",
          "body": "## Summary\n- add a built-in Fact Manager GUI over the shared Storage capability\n- add stable agent CLI/API operations for versioned fact types and materials\n- persist schemas and payloads in the selected Kungfu data root\n- add verified full/thin Fact Library export and append-only import\n- include assessment Episodes and Trust Report material in library transfer\n\n## Validation\n- `./shifu check`\n- 72 Python storage/Episode tests passed\n- targeted libkungfu, Python binding, and Node binding build passed\n- Fact Manager KFX build passed\n- full Electron/Vite GUI production build passed\n- isolated product dry-run passed\n- temporary-home CLI full/thin export, verify, execute import, and payload readback passed\n\n## Known infrastructure issue\nThe repository-wide ALL target still reaches the currently broken LAN Cargo mirror for libwasm crates. This PR does not wait on that CI/infrastructure path; the directly changed runtime and product targets were built and tested locally.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:09:00Z",
          "mergedAt": "2026-07-11T10:14:25Z",
          "additions": 2639,
          "deletions": 56,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/homebrew-tap",
          "number": 8,
          "url": "https://github.com/kungfu-systems/homebrew-tap/pull/8",
          "title": "fix(ci): adopt Buildchain dual-channel routing",
          "body": "## Summary\n\n- adopt the current Buildchain v2 dual-channel model\n- route development/alpha validation through `v2-alpha` and release consumption through `v2`\n- add and verify channel-specific consumer contract locks\n- update repository checks and machine-readable evidence where applicable\n\n## Validation\n\n- `actionlint` on changed GitHub workflows\n- stable and alpha contract locks regenerated and revalidated against exact v2.12 contract worlds\n- repository-local lightweight checks passed where available\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:20:27Z",
          "mergedAt": "2026-07-11T10:25:05Z",
          "additions": 135,
          "deletions": 31,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 107,
          "url": "https://github.com/kungfu-systems/kfd/pull/107",
          "title": "fix(ci): adopt Buildchain dual-channel routing",
          "body": "## Summary\n\n- adopt the current Buildchain v2 dual-channel model\n- route development/alpha validation through `v2-alpha` and release consumption through `v2`\n- add and verify channel-specific consumer contract locks\n- update repository checks and machine-readable evidence where applicable\n\n## Validation\n\n- `actionlint` on changed GitHub workflows\n- stable and alpha contract locks regenerated and revalidated against exact v2.12 contract worlds\n- repository-local lightweight checks passed where available\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:20:32Z",
          "mergedAt": "2026-07-11T10:25:13Z",
          "additions": 149,
          "deletions": 31,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 578,
          "url": "https://github.com/kungfu-systems/kungfu/pull/578",
          "title": "refactor(runtime): adopt domain-neutral live terminology",
          "body": "## Summary\n\n- replace internal practice/hero/apprentice/master terminology with live/reactor/peer/coordinator\n- expose peer/coordinator consistently across C++, Python, Node, CLI, GUI/TUI, KFD and current docs\n- preserve historic wire-v1 location identity through explicit compatibility adapters\n- add ADR-0057 and a terminology architecture gate\n\n## Validation\n\n- ./shifu check\n- ./shifu build (Mac, full build)\n- Python runtime/event-loop tests: 20 passed\n- Node storage binding tests: 11 passed\n- assessment process/thread parity: 1 passed\n- pybind and Node binding smoke tests\n- built CLI runtime status/help smoke tests\n\n## Known verifier issue\n\n./shifu verify reaches 29/30; Episode qualification still fails because its probe readback omits safe_capabilities, warnings, status and episode_projection even though journal writing/fsck completes. This is outside the runtime terminology change. Per current project direction, CI is unavailable and this PR is accepted on the Mac build/test evidence above.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:23:37Z",
          "mergedAt": "2026-07-11T10:25:39Z",
          "additions": 1876,
          "deletions": 1495,
          "changedFiles": 93
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 577,
          "url": "https://github.com/kungfu-systems/kungfu/pull/577",
          "title": "fix(ci): adopt Buildchain dual-channel routing",
          "body": "## Summary\n\n- adopt the current Buildchain v2 dual-channel model\n- route development/alpha validation through `v2-alpha` and release consumption through `v2`\n- add and verify channel-specific consumer contract locks\n- update repository checks and machine-readable evidence where applicable\n\n## Validation\n\n- `actionlint` on changed GitHub workflows\n- stable and alpha contract locks regenerated and revalidated against exact v2.12 contract worlds\n- repository-local lightweight checks passed where available\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:20:36Z",
          "mergedAt": "2026-07-11T10:25:52Z",
          "additions": 104,
          "deletions": 9,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 27,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/27",
          "title": "fix(ci): adopt Buildchain dual-channel routing",
          "body": "## Summary\n\n- adopt the current Buildchain v2 dual-channel model\n- route development/alpha validation through `v2-alpha` and release consumption through `v2`\n- add and verify channel-specific consumer contract locks\n- update repository checks and machine-readable evidence where applicable\n\n## Validation\n\n- `actionlint` on changed GitHub workflows\n- stable and alpha contract locks regenerated and revalidated against exact v2.12 contract worlds\n- repository-local lightweight checks passed where available\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:20:45Z",
          "mergedAt": "2026-07-11T10:25:55Z",
          "additions": 108,
          "deletions": 12,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 31,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/31",
          "title": "fix(ci): adopt Buildchain dual-channel routing",
          "body": "## Summary\n\n- adopt the current Buildchain v2 dual-channel model\n- route development/alpha validation through `v2-alpha` and release consumption through `v2`\n- add and verify channel-specific consumer contract locks\n- update repository checks and machine-readable evidence where applicable\n\n## Validation\n\n- `actionlint` on changed GitHub workflows\n- stable and alpha contract locks regenerated and revalidated against exact v2.12 contract worlds\n- repository-local lightweight checks passed where available\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:20:48Z",
          "mergedAt": "2026-07-11T10:25:59Z",
          "additions": 108,
          "deletions": 12,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 33,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/33",
          "title": "fix(ci): adopt Buildchain dual-channel routing",
          "body": "## Summary\n\n- adopt the current Buildchain v2 dual-channel model\n- route development/alpha validation through `v2-alpha` and release consumption through `v2`\n- add and verify channel-specific consumer contract locks\n- update repository checks and machine-readable evidence where applicable\n\n## Validation\n\n- `actionlint` on changed GitHub workflows\n- stable and alpha contract locks regenerated and revalidated against exact v2.12 contract worlds\n- repository-local lightweight checks passed where available\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:20:53Z",
          "mergedAt": "2026-07-11T10:26:03Z",
          "additions": 127,
          "deletions": 26,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 23,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/23",
          "title": "fix(ci): adopt Buildchain dual-channel routing",
          "body": "## Summary\n\n- adopt the current Buildchain v2 dual-channel model\n- route development/alpha validation through `v2-alpha` and release consumption through `v2`\n- add and verify channel-specific consumer contract locks\n- update repository checks and machine-readable evidence where applicable\n\n## Validation\n\n- `actionlint` on changed GitHub workflows\n- stable and alpha contract locks regenerated and revalidated against exact v2.12 contract worlds\n- repository-local lightweight checks passed where available\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:20:42Z",
          "mergedAt": "2026-07-11T10:26:30Z",
          "additions": 122,
          "deletions": 14,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 80,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/80",
          "title": "fix(ci): adopt Buildchain dual-channel routing",
          "body": "## Summary\n\n- adopt the current Buildchain v2 dual-channel model\n- route development/alpha validation through `v2-alpha` and release consumption through `v2`\n- add and verify channel-specific consumer contract locks\n- update repository checks and machine-readable evidence where applicable\n\n## Validation\n\n- `actionlint` on changed GitHub workflows\n- stable and alpha contract locks regenerated and revalidated against exact v2.12 contract worlds\n- repository-local lightweight checks passed where available\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:20:56Z",
          "mergedAt": "2026-07-11T10:30:20Z",
          "additions": 149,
          "deletions": 26,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/libnode",
          "number": 92,
          "url": "https://github.com/kungfu-systems/libnode/pull/92",
          "title": "fix(ci): adopt Buildchain dual-channel routing",
          "body": "## Summary\n\n- adopt the current Buildchain v2 dual-channel model\n- route development/alpha validation through `v2-alpha` and release consumption through `v2`\n- add and verify channel-specific consumer contract locks\n- update repository checks and machine-readable evidence where applicable\n\n## Validation\n\n- `actionlint` on changed GitHub workflows\n- stable and alpha contract locks regenerated and revalidated against exact v2.12 contract worlds\n- repository-local lightweight checks passed where available\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T10:20:40Z",
          "mergedAt": "2026-07-11T11:32:03Z",
          "additions": 114,
          "deletions": 15,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 580,
          "url": "https://github.com/kungfu-systems/kungfu/pull/580",
          "title": "feat(freeze): assemble the Windows runtime tree + retire the freeze chain",
          "body": "ADR-0046 stage 2 completes: Windows joins macOS and Linux on the assembled\nCPython runtime, and the Nuitka/PyInstaller freeze distribution chain retires.\n\n## Windows assemble leg\n- `run-freeze.js`: fork the assemble tree for the python-build-standalone\n  Windows prefix (python.exe at the root, Lib/site-packages, a three-level .pth)\n  vs the POSIX bin/python3 + lib/pythonX.Y layout; stage the Windows binding\n  through the MSVC-aware helper; `freezer()` now defaults every platform to\n  assemble.\n- `stdlib-prune.json`: restructure so the shared stdlib families live in each\n  platform section (common was POSIX-shaped); add a `win32` section grounded\n  against the real cpython-3.13.14-windows-x86_64 tree.\n- `verify.mjs` / `dist.mjs`: assert the assembled-tree interpreter per platform.\n- Cross-platform fix: parse `runtime-pins.env` line-ending agnostically (a\n  `core.autocrlf` checkout renders it CRLF, which defeated the value regex).\n\nValidated on a Windows build host: `rebuild:core` + `freeze` (assembled form),\nthe assembled `kungfu.exe` runs `-m kungfu`, and `dist:cli` builds the CLI\nproduct package and passes the installed-layout smoke.\n\n## Freeze chain retirement\nWindows was the last frozen platform, so the freeze distribution machinery\nretires as one: the nuitka/pyinstaller legs, the nuitka entry shim, the\nPyInstaller spec and hooks, the dead conanfile freeze path, and the pyinstaller\ndev pin. The `engage nuitka` bridge (py-AOT kfx build, ADR-0045) stays, so the\nnuitka pin is kept. The retirement ledger in `docs/buildchain.md` records it.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T11:02:01Z",
          "mergedAt": "2026-07-11T12:10:29Z",
          "additions": 122,
          "deletions": 708,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 581,
          "url": "https://github.com/kungfu-systems/kungfu/pull/581",
          "title": "fix(journal): harden mmap ownership and page publication",
          "body": "## What changed\n\n- introduce move-only `mapped_region` ownership for POSIX and Windows mappings\n- separate existing-only mappings from explicit create/grow authority\n- make `page_header::last_frame_position` the release/acquire page publication token\n- validate page/header/frame sizes and offsets before payload access\n- keep journal wire-v1 and the public three-argument Python `get_page_path` API unchanged\n- extend ADR-0001 and add native mmap correctness tests wired through Shifu and CTest\n\n## Why\n\nReader mappings could create or stretch files, raw mapping ownership leaked resources on error paths, and page initialization relied on ordinary cross-process field polling. The new boundary makes ownership and mutation authority explicit while preserving the existing single-writer, zero-copy journal contract.\n\n## Validation\n\n- `./shifu build:core` — passed on Mac arm64 after rebasing onto current `dev/v4/v4.0`; includes Node, Electron, Python, Wasmer and Wasmtime targets\n- `./shifu test:mmap` — passed\n- `ctest --test-dir framework/core/build -R '^yijinjing_mmap_tests$' --output-on-failure` — passed\n- `./shifu check` — passed\n- commit pre-checks including clang-format 20.1.8 — passed\n\nCI is currently unavailable and is not used as the merge gate for this change; the requested gate is the Mac build and tests above.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T12:37:25Z",
          "mergedAt": "2026-07-11T12:38:25Z",
          "additions": 741,
          "deletions": 119,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 582,
          "url": "https://github.com/kungfu-systems/kungfu/pull/582",
          "title": "test(journal): cover mmap resource failure paths",
          "body": "## What changed\n\nFollow-up fault qualification for PR #581:\n\n- repeat truncated existing-only mappings and assert process fd/handle count does not grow\n- force an already-unmapped view and assert flush failure is surfaced while RAII ownership is cleared\n- use POSIX `RLIMIT_FSIZE` to force resize/file-budget failure and verify the page is not grown past the limit\n\n## Why\n\nThe implementation fixes in #581 were complete, but closeout review found that resource-error and resize-budget acceptance criteria lacked direct deterministic tests. This PR closes that evidence gap without changing production code.\n\n## Validation\n\n- `./shifu test:mmap` — 9/9 passed on Mac arm64\n- CTest `yijinjing_mmap_tests` — passed\n- `./shifu check` — passed\n- clang-format 20.1.8 / pre-commit staged gates — passed\n\nThe production implementation was already validated by the complete Mac `./shifu build:core` in #581. CI is not required as a merge gate per operator instruction.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-11T12:44:10Z",
          "mergedAt": "2026-07-11T12:44:43Z",
          "additions": 84,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 583,
          "url": "https://github.com/kungfu-systems/kungfu/pull/583",
          "title": "docs(adr): close ADR-0045 implementation record",
          "body": "Merge docs/adr0045-closeout into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T13:27:58Z",
          "mergedAt": "2026-07-11T13:28:04Z",
          "additions": 56,
          "deletions": 32,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 584,
          "url": "https://github.com/kungfu-systems/kungfu/pull/584",
          "title": "refactor(journal): separate mmap mapping policies",
          "body": "## Summary\n\n- replace implicit mmap booleans with explicit access, creation, residency, and durability policies\n- make page and reader/coordinator intents explicit while preserving wire-v1, POD layout, zero-copy, and compatibility adapters\n- document the qualified policy matrix in ADR-0058 and add illegal-combination coverage\n\n## Validation\n\n- ./shifu build:core\n- ./shifu test:mmap (11/11)\n- ./shifu check",
          "author": "dongkeren",
          "createdAt": "2026-07-11T13:41:54Z",
          "mergedAt": "2026-07-11T13:42:36Z",
          "additions": 646,
          "deletions": 165,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1122,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1122",
          "title": "feat(kfd): expose Shifu artifact discovery contract",
          "body": "## Summary\n\n- add a versioned `buildchain layout --json` contract so Shifu can discover the active KFD-3 registry without copying Buildchain paths\n- validate explicit KFD-3 distribution declarations with registrar, tasks, artifact kind, platform, path glob, and optional digest\n- self-describe Buildchain standalone archives as a Shifu-managed distribution surface and expose the `binary:build` task\n- publish the new CLI, Node API, docs, KFD claims, and generated site facts\n\n## Validation\n\n- `pnpm run check` (541 tests, workflow checks, generated site checks, action bundles)\n- `node --test tests/kfd3-surface-register.test.mjs`\n- standalone macOS arm64 SEA/archive smoke via `pnpm binary:build`\n\n## Runtime train\n\n- `train/v2/v2.12/kfd-artifact-onboarding` at `a9565ea819affc6964dd4be71d376dd35ec3c142`",
          "author": "dongkeren",
          "createdAt": "2026-07-11T13:42:22Z",
          "mergedAt": "2026-07-11T13:44:25Z",
          "additions": 603,
          "deletions": 153,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1123,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1123",
          "title": "feat(release): promote KFD artifact onboarding alpha",
          "body": "## Summary\n\nPromote the reviewed KFD artifact onboarding contract from `dev/v2/v2.12` to the alpha channel.\n\nThe candidate adds Buildchain-owned layout discovery, explicit Shifu jurisdiction declarations, and three-platform standalone artifact metadata.\n\n## Evidence\n\n- implementation PR: #1122\n- implementation merge: `906680ed66a3e49c0a21c29ebede17939c96b163`\n- full Buildchain check: 541 tests passed\n- standalone macOS arm64 archive smoke passed",
          "author": "dongkeren",
          "createdAt": "2026-07-11T13:45:44Z",
          "mergedAt": "2026-07-11T13:47:23Z",
          "additions": 603,
          "deletions": 153,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 586,
          "url": "https://github.com/kungfu-systems/kungfu/pull/586",
          "title": "fix(gui): run first-party manifest with tsx",
          "body": "## Summary\n\n- execute first-party manifest generation through the project TypeScript runtime\n- keep the package script and electron-builder beforePack hook on the same execution path\n- preserve the pinned first-party extension manifest in desktop artifacts\n\n## Validation\n\n- `./shifu check`\n- `./shifu --filter @kungfu-tech/gui run gen:first-party-manifest`\n- full `./shifu product gui dist` completed with ZIP and DMG outputs\n- packaged Status extension hash matches the pinned first-party manifest",
          "author": "dongkeren",
          "createdAt": "2026-07-11T13:48:18Z",
          "mergedAt": "2026-07-11T13:48:23Z",
          "additions": 10,
          "deletions": 6,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 585,
          "url": "https://github.com/kungfu-systems/kungfu/pull/585",
          "title": "feat(mission-control): make Mission evidence portable",
          "body": "Merge feature/mission-control into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T13:46:53Z",
          "mergedAt": "2026-07-11T13:53:03Z",
          "additions": 6000,
          "deletions": 215,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1125,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1125",
          "title": "fix(release): refresh promotion action bundle",
          "body": "## Summary\n\nRegenerate `actions/promote-buildchain-ref/dist/index.js` after the final KFD distribution digest validation change.\n\nThe first alpha promotion correctly failed closed because lifecycle verification rebuilt the action and detected this tracked bundle drift. The source was already correct; the bundled action still contained the pre-final condition.\n\n## Validation\n\n- `node --test tests/build-surface.test.mjs` (70 passed)\n- rebuilt the promotion action twice; the resulting digest is stable\n- bundle word diff is limited to the intended `sha256` presence validation",
          "author": "dongkeren",
          "createdAt": "2026-07-11T13:53:48Z",
          "mergedAt": "2026-07-11T13:55:40Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1126,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1126",
          "title": "fix(release): repromote KFD artifact onboarding alpha",
          "body": "## Summary\n\nRe-promote the KFD artifact onboarding candidate after refreshing the generated promotion action bundle.\n\n## Evidence\n\n- implementation PR: #1122\n- fail-closed friction: #1124\n- generated bundle fix: #1125\n- bundle regeneration is stable and all PR checks passed",
          "author": "dongkeren",
          "createdAt": "2026-07-11T13:55:53Z",
          "mergedAt": "2026-07-11T13:57:55Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1128,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1128",
          "title": "fix(binary): isolate standalone CLI entrypoint",
          "body": "## Summary\n\n- mark the SEA bundle as the single embedded entrypoint so imported script CLIs do not self-execute\n- bundle `@kungfu-tech/kfd` JSON exports into the standalone executable\n- add a regression test that builds the real SEA and executes `version` and `layout --json`\n- extend the inventory gate to require the embedded entrypoint definition\n\n## Validation\n\n- `pnpm run check` (542 tests passed)\n- standalone SEA execution regression passed locally\n\nCloses #1127",
          "author": "dongkeren",
          "createdAt": "2026-07-11T14:30:11Z",
          "mergedAt": "2026-07-11T14:32:55Z",
          "additions": 33,
          "deletions": 7,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1129,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1129",
          "title": "release: promote v2.12 alpha after standalone CLI fix",
          "body": "Promote the latest v2.12 development train after fixing standalone binary entrypoint isolation.\n\nIncludes #1128 and closes the standalone release artifact regression before consumer onboarding.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T14:33:08Z",
          "mergedAt": "2026-07-11T14:34:46Z",
          "additions": 33,
          "deletions": 7,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 587,
          "url": "https://github.com/kungfu-systems/kungfu/pull/587",
          "title": "ci(dev): give the development mainline a standing verify signal",
          "body": "Merge ci/dev-verify-signal into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T14:37:36Z",
          "mergedAt": "2026-07-11T14:37:43Z",
          "additions": 200,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 591,
          "url": "https://github.com/kungfu-systems/kungfu/pull/591",
          "title": "feat(shifu): onboard pinned Buildchain artifacts",
          "body": "## Summary\n- make Buildchain a pin-first Shifu-managed tool via `.buildchain-version`\n- bootstrap standalone Buildchain release archives on demand and inject the cached binary into task PATH\n- expose mirror/version/checksum controls plus doctor pin/cache evidence\n- document `buildchain layout --json` as the stable KFD registry discovery contract\n\n## Evidence\n- `./shifu sync`\n- `./shifu fix`\n- `./shifu check`\n- `cargo test --manifest-path crates/Cargo.toml -p shifu-core -p shifu`\n- fresh `./shifu kfd2:claims:check` downloaded `v2.12.1-alpha.4` standalone archive\n- cached standalone `buildchain version` and `buildchain layout --cwd . --json` passed\n\nBuildchain source PRs: kungfu-systems/buildchain#1122, #1125, #1128.\nBuildchain release: `v2.12.1-alpha.4`.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T14:47:21Z",
          "mergedAt": "2026-07-11T14:48:38Z",
          "additions": 204,
          "deletions": 44,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1130,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1130",
          "title": "feat(build): provision mirrored Rust and Cargo toolchains",
          "body": "Summary: provision optional pinned Rust toolchains for native lifecycle jobs on Linux, macOS, and Windows; support optional rustup distribution mirrors; add an optional cargo-registry-index input passed as CARGO_REGISTRIES_CRATES_IO_INDEX; preserve locked source bytes across runner-global line-ending settings; document repository-variable usage without exposing private network topology; regenerate public workflow and contract artifacts. Validation: pnpm run check on the latest dev/v2/v2.12 merge (542 tests passed); Buildchain fixture matrix passed; downstream Kungfu run 29153055191 completed Rust setup and build lifecycle on Linux, macOS, and Windows; isolated Cargo fetch downloaded the complete wasmer dependency graph through the selected registry. Supersedes #1117, whose branch became conflicting after dev advanced.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T14:44:34Z",
          "mergedAt": "2026-07-11T14:57:50Z",
          "additions": 244,
          "deletions": 33,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1117,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1117",
          "title": "feat(build): provision optional native Rust toolchains",
          "body": "## Summary\n- add opt-in `setup-rust` and `rust-toolchain` inputs to the reusable native build matrix\n- bootstrap Windows Rust through `cmd` + `curl.exe`, without bash, PowerShell policy changes, or host PATH mutation\n- support optional rustup distribution/update mirrors while keeping official defaults\n- isolate Windows Cargo, rustup, and installer state by workflow run/attempt\n- force locked source checkouts to preserve Git bytes across runner-global CRLF settings\n- regenerate the channel router and public contract/site artifacts\n\n## Validation\n- `pnpm run check` (538 tests passed)\n- downstream train: `train/v2/v2.12/setup-rust-toolchain` at `7369fca49d97a50138a551647df4c6d4a71b9921`\n- downstream Kungfu ADR-0049 run: https://github.com/kungfu-systems/kungfu/actions/runs/29153055191\n  - exact Kungfu source: `f5abbc35bd9c4b1c9e484935422a64c63a654092`\n  - full Linux/macOS/Windows qualification is in progress\n\n## Downstream evidence required before merge\n- successful complete Kungfu ADR-0049 self-hosted Linux/macOS/Windows matrix with Rust 1.96.0",
          "author": "dongkeren",
          "createdAt": "2026-07-11T09:27:07Z",
          "mergedAt": "2026-07-11T14:57:52Z",
          "additions": 211,
          "deletions": 33,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 597,
          "url": "https://github.com/kungfu-systems/kungfu/pull/597",
          "title": "fix(core): suppress Windows minmax macros in mmap",
          "body": "Fixes #596.\n\nThe Windows product gate includes `windows.h` before using `std::numeric_limits<LONGLONG>::max()`. Defining `NOMINMAX` at the include boundary prevents Win32 macro expansion and follows the existing repository convention.\n\nEvidence:\n- exact MSVC failure reproduced by run 29156716599\n- `./shifu check` passed\n- staged pre-commit gate passed\n\nThe follow-up self-hosted Windows product build will run together with the Rust/Cargo provisioning candidate.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T15:04:53Z",
          "mergedAt": "2026-07-11T15:05:29Z",
          "additions": 3,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 590,
          "url": "https://github.com/kungfu-systems/kungfu/pull/590",
          "title": "fix(ci): provision mirrored Rust and Cargo",
          "body": "Summary: provision Rust 1.96.0 on the self-hosted native matrix; use mirrored rustup distribution endpoints; pass the Cargo registry index through a repository variable so private LAN topology stays out of public workflow YAML. Validation: ./shifu check passed; full self-hosted workflow run 29156651239 is in progress. Depends on Buildchain #1117 and the stacked Cargo registry input PR. Fixes #579.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T14:44:35Z",
          "mergedAt": "2026-07-11T15:07:12Z",
          "additions": 7,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 599,
          "url": "https://github.com/kungfu-systems/kungfu/pull/599",
          "title": "perf(yijinjing): qualify and optimize mmap page lookup",
          "body": "## Summary\n\n- add a reproducible native mmap qualification harness and retain macOS/Linux evidence\n- replace reverse-linear page-header lookup with a tail fast path plus ordered binary probes\n- record independent accept/reject/defer decisions for sizing, advice, residency, flush range, and release polling\n\n## Evidence\n\n- Mac three-round A/B at 128 pages: early seek p50 3.131-3.505 ms -> 0.298-0.517 ms; middle 1.825-1.953 ms -> 0.293-0.454 ms; late unchanged\n- Linux three-round A/B: early 0.750-0.782 ms -> 0.153-0.155 ms; middle 0.431-0.454 ms -> 0.152-0.154 ms; late unchanged\n- `./shifu rebuild` passed on macOS arm64 and agent-120 Linux x86_64\n- `./shifu test:mmap` passed on both hosts\n- `./shifu check` passed on macOS\n\n## Compatibility\n\nNo wire bytes, Hana POD layout, public API, mapping authority, or durability semantics change. Rollback is a normal revert of the two lookup commits.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T15:10:53Z",
          "mergedAt": "2026-07-11T15:11:37Z",
          "additions": 2795,
          "deletions": 7,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 600,
          "url": "https://github.com/kungfu-systems/kungfu/pull/600",
          "title": "fix(ci): honor the libwasm Rust pin",
          "body": "Summary: align the self-hosted CI bootstrap with the authoritative Rust 1.95.0 pins in `crates/libwasm/rust-toolchain.toml` and `crates/libwasm-spike/rust-toolchain.toml`, so the native build does not attempt a second rustup install inside the build lifecycle. This is the follow-up to #590 discovered by real matrix validation. Validation: `actionlint .github/workflows/build.yml` and `./shifu check` pass. The final self-hosted proof run is 29157505924. Related to #579.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T15:31:30Z",
          "mergedAt": "2026-07-11T15:33:55Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 595,
          "url": "https://github.com/kungfu-systems/kungfu/pull/595",
          "title": "docs(mission-control): design workspace product flow",
          "body": "## Summary\n- define Desktop Open Workspace, recents, cold-start restore, and lazy `.kungfu` initialization\n- separate workspace facts, global config/session state, machine fallback, and explicit personal workspace semantics\n- redesign Work Dashboard as a five-question Mission Home with compact authoring actions\n- confirm Saved Query Catalog remains workspace-scoped and define Atlas dogfood behavior\n- add ADR-0060 plus eight implementation slices and falsifiable product gates\n\n## Validation\n- `git diff --check`\n- `./shifu check`\n- ADR identity/index gate passed\n\n## Scope\nDesign and architecture only. This PR does not claim that Open Workspace or the redesigned Mission Home is implemented.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T14:59:16Z",
          "mergedAt": "2026-07-11T15:46:26Z",
          "additions": 1122,
          "deletions": 11,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 602,
          "url": "https://github.com/kungfu-systems/kungfu/pull/602",
          "title": "fix(ci): dev verify patrol treats only failure as a red signal",
          "body": "Merge fix/dev-verify-report-result-guard into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-11T15:47:04Z",
          "mergedAt": "2026-07-11T15:47:10Z",
          "additions": 9,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 603,
          "url": "https://github.com/kungfu-systems/kungfu/pull/603",
          "title": "docs(adr): add ADR-0060 journal container epoch and page-sizing design note",
          "body": "Adds ADR-0060 (journal container epoch derived from the page/frame header layout; hard refusal on the hot path; deferred offline cross-epoch conversion) and the journal-page-sizing-and-episode-reclamation design note, wired into the ADR index, data-axis theme, related documents, episode-object-model, and ADR-0033/0034. Documentation only.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T15:47:41Z",
          "mergedAt": "2026-07-11T15:55:32Z",
          "additions": 365,
          "deletions": 3,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 607,
          "url": "https://github.com/kungfu-systems/kungfu/pull/607",
          "title": "fix(windows): unblock mmap build and RAII qualification",
          "body": "## Summary\n\n- replace non-standard `_WINDOWS` guards with compiler-standard `_WIN32` and enforce the boundary in `shifu check`\n- load the MSVC environment before Shifu L2 build dispatch, with Rust unit coverage\n- enable global MSVC `/EHsc` so exception paths unwind mmap RAII handles\n- close Windows build/freeze/SDK path and canonical-text gaps exposed by the clean build\n\n## Validation\n\n- DARKHERO Windows: default `shifu.cmd build` passed without manual vcvars or compile flags\n- DARKHERO Windows: `shifu.cmd test:mmap` passed, including repeated failing-map handle regression (previously +8 handles)\n- DARKHERO Windows: clean baseline qualification bound to `a3ba855105f61aa46471b1b2d8e2921a8b85567e`, MSVC 19.51, `git_dirty=false`\n- macOS arm64: full `./shifu build`, `./shifu check`, and `./shifu test:mmap` passed\n- agent-120 Linux: `./shifu sync`, full `./shifu build`, `./shifu test:mmap`, and `./shifu check` passed\n\nCI is currently unavailable; this PR is qualified by the explicit three-host local matrix above.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T16:42:47Z",
          "mergedAt": "2026-07-11T16:43:38Z",
          "additions": 159,
          "deletions": 73,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 605,
          "url": "https://github.com/kungfu-systems/kungfu/pull/605",
          "title": "fix(ci): align libwasm Rust toolchain pins",
          "body": "Fixes #604.\n\nAlign both libwasm toolchain pins with the Rust 1.96.0 version provisioned by the self-hosted Buildchain runner contract. This prevents parallel Wasmer/Wasmtime targets from racing two implicit rustup installs of the old 1.95.0 toolchain.\n\nEvidence:\n- exact race captured in alpha r2 Linux run 29157376683\n- `./shifu check` passed\n- staged pre-commit gate passed\n\nA replacement alpha candidate will rerun all three product legs after merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T15:57:36Z",
          "mergedAt": "2026-07-11T17:16:17Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 609,
          "url": "https://github.com/kungfu-systems/kungfu/pull/609",
          "title": "fix(ci): align product Rust toolchain pin",
          "body": "## Summary\n\n- align the alpha/release product workflow with the Rust 1.96 pins established by #605\n- avoid cross-toolchain rustup installation during the native matrix\n\n## Validation\n\n- `./shifu check`\n- staged repository gates\n\nFixes #608.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T17:19:22Z",
          "mergedAt": "2026-07-11T17:20:03Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 611,
          "url": "https://github.com/kungfu-systems/kungfu/pull/611",
          "title": "feat(workspace): ship Home and Project Mission Control",
          "body": "## Summary\n- add lazy Home/Project Workspace identity, selection, persistence, and Desktop Mission Home\n- expose shared inspect/advice/preview/authorization/action/receipt/verify contracts to GUI and agents\n- add bounded project-gravity and portable-contract guidance without implicit Git/network effects\n- qualify real Atlas scale (5 Missions, 533 Go, 1151 markers) with source-bound TrustReports and bounded CLI output\n\n## Local validation\n- workspace/guidance Python tests: 16 passed\n- Desktop workspace selection: 3 passed\n- API tests: 5 passed\n- ./shifu check: passed\n- ./shifu product gui build: passed; bundle-core audit passed\n- direct GUI dogfood: first-install Home, Mission Home, guidance receipt verification, and Atlas five-question TrustReport passed\n\nKnown unrelated CI problems are not used as a completion gate for this change, per current project direction.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T18:00:52Z",
          "mergedAt": "2026-07-11T18:01:49Z",
          "additions": 4696,
          "deletions": 375,
          "changedFiles": 42
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 606,
          "url": "https://github.com/kungfu-systems/kungfu/pull/606",
          "title": "feat(trunk): ADR-0046 Stage 3 — embedding membrane, native node variant, unified help",
          "body": "ADR-0046 Stage 3: the Rust trunk grows into the process host. Ratified RFC\n`framework/core/docs/embedding-contract-face.md` plus its four implementation\nsteps.\n\n- **RFC (embedding contract face)**: the libkungfu embedding surface is exactly\n  the one versioned C ABI membrane (`kungfu_embedding_get_api` + `kf_embedding_api_v1`),\n  converged with the ADR-0045 gate-1 ABI — one membrane, two consumers (native\n  KFX + the trunk).\n- **kungfu-embedding crate (D7)**: the one shared Rust borrowing layer over the\n  membrane; host-spike drops its private copy and depends on it. Pure rlib with\n  compile-time ABI layout guards; no libkungfu link, so it stays in the workspace\n  gate.\n- **trunk doctor (D5/D6)**: read-only physical inspection through the membrane,\n  behind the `embedding` cargo feature (off by default, so coreless builds stay\n  green); build.rs links libkungfu when the feature is on.\n- **native node variant**: `KUNGFU_AS_VARIANT=node` runs `node::Start` through a\n  standalone `kungfu_node_host` library dlopen'd at the front door, without\n  booting CPython; falls back to the Python variant when the library is absent\n  (zero behavior change). The python variant stays Python-side (it is pervasively\n  kungfu-bridged).\n- **unified --help**: `kungfu --help` renders the command surface from a\n  declarative manifest generated by introspecting the live click tree (single\n  source of truth), shipped in dist/kungfu; falls back to the Python CLI help\n  when absent.\n\nRust workspace: cargo test/clippy/fmt green. The native launcher, the embedding\nfeature link, and the assemble-time help-manifest generation are exercised by CI.",
          "author": "dongkeren",
          "createdAt": "2026-07-11T16:40:06Z",
          "mergedAt": "2026-07-11T20:27:49Z",
          "additions": 1667,
          "deletions": 273,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 615,
          "url": "https://github.com/kungfu-systems/kungfu/pull/615",
          "title": "feat(yijinjing): derive journal container epoch from header layout (ADR-0062)",
          "body": "Replaces the hand-maintained __JOURNAL_VERSION__ integer with journal_format_epoch, a compile-time value derived from the page_header/frame_header layout (Boost.Hana fold over field names + type tokens + sizeof/alignof). Any layout change -- including size-preserving reorder/retype/rename the *_length checks miss -- changes the epoch, so an unversioned layout change cannot ship and old-epoch pages are refused automatically. page::load semantics and the *_length checks are unchanged. Implements ADR-0062 (removing the now-unreachable assemble cross-epoch branch is a separate follow-up).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T06:10:35Z",
          "mergedAt": "2026-07-12T06:10:41Z",
          "additions": 92,
          "deletions": 12,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 616,
          "url": "https://github.com/kungfu-systems/kungfu/pull/616",
          "title": "refactor(yijinjing): remove unreachable cross-epoch branch in assemble (ADR-0062)",
          "body": "Every assignment to a reader's current page goes through page::load, which throws on an epoch mismatch, so a version-mismatched page can never reach assemble::read_bytes -- its skip-and-warn branch and the per-frame epoch check were dead code. Removes them (cross-epoch replay is offline conversion, ADR-0062) and adds a 'version' case to test_corrupt_page_header_facts_are_rejected to lock the load-level guarantee the removal rests on.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T06:39:21Z",
          "mergedAt": "2026-07-12T06:39:26Z",
          "additions": 7,
          "deletions": 9,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 617,
          "url": "https://github.com/kungfu-systems/kungfu/pull/617",
          "title": "docs(adr): mark ADR-0062 implemented",
          "body": "The derived journal container epoch (PR #615) and the removal of the unreachable cross-epoch assemble branch (PR #616) have landed. Flip ADR-0062 status to implemented and record how each verification item was discharged.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T06:46:44Z",
          "mergedAt": "2026-07-12T06:46:49Z",
          "additions": 26,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1132,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1132",
          "title": "fix(release): automate stable candidate qualification",
          "body": "## Summary\n\n- produce Build Surface Fixture and no-apply site canary evidence after exact-alpha self-dogfood\n- separate cross-repository dispatch authority from repository-local attestation\n- keep Patrol selection, source-lock PR, stable gate, and publish transaction unchanged\n\n## Validation\n\n- targeted qualification, Patrol, and stable gate tests passed\n- pnpm run check passed with 548 tests\n- workflow checks and git diff checks passed\n\n## Runtime validation\n\nTrain: train/v2/v2.12/patrol-qualification-evidence\n\nThe first post-merge exact alpha will prove the workflow-run trigger, exact-tag Build Surface dispatch, no-apply site canary, Actions attestation, and subsequent Patrol qualification.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T06:50:39Z",
          "mergedAt": "2026-07-12T06:53:20Z",
          "additions": 448,
          "deletions": 14,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 618,
          "url": "https://github.com/kungfu-systems/kungfu/pull/618",
          "title": "docs(adr): define yijinjing concurrency and error ownership",
          "body": "Merge docs/yijinjing-concurrency-contracts into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T06:54:30Z",
          "mergedAt": "2026-07-12T06:54:37Z",
          "additions": 382,
          "deletions": 1,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1133,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1133",
          "title": "chore(release): promote Patrol qualification evidence",
          "body": "Promote the merged stable-candidate qualification producer for exact-alpha runtime validation.\n\nExpected post-promotion evidence:\n- new exact alpha release and SHA\n- successful Buildchain Alpha Self-Dogfood\n- automatic Build Surface Fixture dispatch on the exact tag\n- automatic site-libkungfu-dev no-apply canary on the exact SHA\n- github-actions bot commit-status attestation accepted by the stable policy",
          "author": "dongkeren",
          "createdAt": "2026-07-12T06:54:07Z",
          "mergedAt": "2026-07-12T06:55:59Z",
          "additions": 688,
          "deletions": 43,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 614,
          "url": "https://github.com/kungfu-systems/kungfu/pull/614",
          "title": "fix(product): stabilize cross-platform release gates",
          "body": "## Summary\n\n- scope product observability verification to `kungfu-product` events so unrelated Buildchain lifecycle errors do not poison a successful product assembly\n- launch the first-party manifest ESM entrypoint through a `file://` URL on Windows\n- normalize unknown help-manifest generation errors introduced on current dev\n- add regression coverage for observability isolation and the ESM entrypoint specifier\n\n## Validation\n\n- `./shifu fix`\n- `./shifu check`\n- product/tooling tests: 10 passed, including both new regressions\n\nFixes #613.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T05:58:58Z",
          "mergedAt": "2026-07-12T07:06:31Z",
          "additions": 84,
          "deletions": 13,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1134,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1134",
          "title": "fix(release): match cross-repository canary runs",
          "body": "Fix Stable Candidate Qualification matching for cross-repository site canary runs. The candidate SHA is bound through the exact run display title because the site workflow run head SHA belongs to the site repository. Same-repository Build Surface matching remains pinned to the candidate SHA. Adds a regression test. Validation: pnpm run check (549 tests).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T07:07:33Z",
          "mergedAt": "2026-07-12T07:12:12Z",
          "additions": 37,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1135,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1135",
          "title": "chore(release): promote qualification matcher fix to alpha",
          "body": "Promote the cross-repository canary matching fix so Stable Candidate Qualification executes the corrected script from the exact candidate SHA.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T07:12:49Z",
          "mergedAt": "2026-07-12T07:14:53Z",
          "additions": 37,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 625,
          "url": "https://github.com/kungfu-systems/kungfu/pull/625",
          "title": "fix(python): restore public lockfile sources",
          "body": "## Summary\n\n- restore the committed Python lockfile to public PyPI sources\n- preserve locked package versions and SHA-256 hashes\n- keep local mirror selection out of repository truth\n- narrow mission evidence containers so the full public-runner mypy baseline remains valid once dependency sync can execute\n\n## Evidence\n\n- no `192.168.100.222:3141` references remain in `framework/core/uv.lock`\n- `UV_DEFAULT_INDEX=https://pypi.org/simple uv lock --check --directory framework/core`\n- `UV_DEFAULT_INDEX=https://pypi.org/simple uv run --frozen mypy src/python/kungfu`\n- `./shifu check`\n- reproduces the pre-test dependency failure in Dev Check run 29184081297; the first #625 run then reached mypy and exposed the pre-existing container inference gap\n\nCloses #624",
          "author": "dongkeren",
          "createdAt": "2026-07-12T07:23:30Z",
          "mergedAt": "2026-07-12T07:25:59Z",
          "additions": 607,
          "deletions": 607,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 626,
          "url": "https://github.com/kungfu-systems/kungfu/pull/626",
          "title": "docs(adr): add ADR-0065 schema registry consolidation",
          "body": "One authoritative type set with trait-derived subsets replaces the hand-maintained overlapping maps in schema/registry.h, retires the rot-prone numeric tag comments, and makes tag sets compile-time. Finishes msg_type -> carrier_type at internal sites while keeping the frozen v1 embedding ABI. Dispatch micro-optimization is a non-goal without measurement.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T07:32:39Z",
          "mergedAt": "2026-07-12T07:32:45Z",
          "additions": 129,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 627,
          "url": "https://github.com/kungfu-systems/kungfu/pull/627",
          "title": "feat(build): modernize the native C++ toolchain contract",
          "body": "## Summary\n\n- define one machine-readable C++23 toolchain contract and enforce it through Shifu, CMake, Conan, Ninja, and Buildchain\n- replace global native flags with target-scoped contracts, add portable content-hash spans, and qualify C++ modules behind a hold gate\n- make GCC 14, AppleClang, and MSVC builds reproducible with a pinned RxCpp portability recipe and canonical LF sources\n- document the compiler policy and accepted Modules hold in ADR-0066\n\n## Validation\n\n- macOS AppleClang 21: `./shifu build:core`, `./shifu test:mmap`, `./shifu check`\n- agent-120 GCC 14.2: full core/Node/Electron/Python/wheel build, mmap/content-hash tests, `./shifu check`\n- DARKHERO MSVC 19.51 + Rust 1.96: full core/Node/Electron/Python/wheel build, mmap/content-hash tests, `./shifu check`\n- C++ Modules qualification executed on all three platforms; promotion remains held by ADR-0066\n\nCI is currently unavailable; the platform-local qualification above is the merge evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T07:38:11Z",
          "mergedAt": "2026-07-12T07:38:58Z",
          "additions": 1315,
          "deletions": 138,
          "changedFiles": 40
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 628,
          "url": "https://github.com/kungfu-systems/kungfu/pull/628",
          "title": "refactor(yijinjing): derive pure-category type subsets from a membership table (ADR-0065)",
          "body": "Replaces the hand-listed State/Profile/SourceRegistry/ManifestCatalog/EpisodeManifest maps in schema/registry.h with one authoritative membership table + hana::filter. Derived maps are identical in type to the old ones (same type_name -> type_c shape), so consumers are unaffected; per-subset count static_asserts guard membership. Set-equality vs the old maps verified. schema/core.h stays neutral; AllTypes/has_data/CorePublic* structural subsets are a follow-up (ADR-0065).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T07:51:43Z",
          "mergedAt": "2026-07-12T07:51:51Z",
          "additions": 61,
          "deletions": 28,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 619,
          "url": "https://github.com/kungfu-systems/kungfu/pull/619",
          "title": "feat(freeze): build product trunk with --features embedding on POSIX (ADR-0046 S3)",
          "body": "ADR-0046 stage 3 productionization (Phase A, POSIX). The frozen/assembled product trunk now links libkungfu and ships the real embedding-backed `doctor` on macOS/Linux.\n\nBoth trunk build points pass `--features embedding` with an explicit `KF_TRUNK_NATIVE_DIR` / `KF_TRUNK_BUILD_TYPE` (`framework/core/build/<bt>`, populated before assemble) so build.rs never guesses a relative path that could fail canonicalize under CI:\n- `framework/core/.gyp/run-freeze.js` `stageEntry`\n- `product/scripts/dist.mjs` `stageTrunk`\n\nWindows stays featureless until the static-core link follow-up lands; the trunk's doctor/help/variant paths all fall back gracefully when the core is absent, so this is zero-regression.\n\nLocal verification (macOS): product cargo invocation builds a real embedding trunk (links `@rpath/libkungfu.dylib`, `@loader_path` rpath); in a co-located dist layout `doctor` negotiates ABI v1 + reports real capabilities, `KUNGFU_AS_VARIANT=node` dlopens the node host and runs `node::Start`, and `--help` renders from the co-located manifest (falls through when absent).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T06:59:59Z",
          "mergedAt": "2026-07-12T07:59:05Z",
          "additions": 51,
          "deletions": 16,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 630,
          "url": "https://github.com/kungfu-systems/kungfu/pull/630",
          "title": "feat(yijinjing): implement ADR-0063 concurrency ownership",
          "body": "## Summary\n\n- add a move-only RAII frame transaction and migrate in-tree writer, recorder, replay, and webserver paths while retaining deprecated compatibility adapters\n- define Reader cursor thread affinity and protect journal/runtime-writer management with stable snapshots\n- remove recursive locking and microsecond shared_ptr polling; page release now drops collector ownership without waiting for external leases\n- add failure injection, concurrent management, page-lifetime tests, and a paired qualification gate for transaction overhead\n\n## Validation\n\n- `./shifu build`\n- `./shifu test:mmap`\n- `./shifu check`\n- independent Release TSAN mmap build/run with `halt_on_error=1`\n- `./shifu qualify:mmap --profile baseline`: clean head `bbf8c890b`, 11 paired alternating trials, median transaction overhead `-5.68%` versus the deprecated split adapter (threshold `5%`), zero transaction heap allocations and zero published-read refcount operations\n\n## Evidence boundary\n\nLocal runtime/TSAN/qualification evidence is macOS arm64. This PR preserves the ADR-0001 publication token and journal layout, but ADR-0063 remains `proposed` until current Windows/Linux last-owner destruction and x86 publication stress evidence is recorded. ADR-0064 retains ownership of library-level signal/error propagation such as `raise(SIGINT)`.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:03:34Z",
          "mergedAt": "2026-07-12T08:04:33Z",
          "additions": 805,
          "deletions": 136,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 631,
          "url": "https://github.com/kungfu-systems/kungfu/pull/631",
          "title": "refactor(yijinjing): derive AllDataTypes from the has_data trait (ADR-0065)",
          "body": "Derives AllDataTypes by filtering the AllTypes roster on the has_data struct trait instead of hand-listing it (mark types drop out automatically); identical map type, count static_assert guard, consumers unaffected. The CorePublic* public surfaces stay explicit make_map as the runtime-greenfield public-binding audit requires (ADR-0027) -- they are out of scope for derivation.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:07:25Z",
          "mergedAt": "2026-07-12T08:07:31Z",
          "additions": 12,
          "deletions": 38,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 633,
          "url": "https://github.com/kungfu-systems/kungfu/pull/633",
          "title": "refactor(yijinjing): make schema tag sets compile-time (ADR-0065)",
          "body": "Replaces the runtime const std::set globals (AllTypesTags/StaticDataTags) with constexpr sorted std::array built by build_tag_set + a constexpr contains_tag binary search -- no static-init cost, cache-friendly per-event membership (reactor is_custom_event). Drops the dead ProfileDataTags. StaticDataTypes/StatisticDataTypes stay (empty but consumed by state-cache restore). Consumers switch to contains_tag.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:23:09Z",
          "mergedAt": "2026-07-12T08:23:17Z",
          "additions": 24,
          "deletions": 13,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 632,
          "url": "https://github.com/kungfu-systems/kungfu/pull/632",
          "title": "fix(product): select ESM entrypoint specifiers by platform",
          "body": "## Summary\n\n- keep absolute filesystem paths for POSIX first-party manifest generation\n- use a `file://` URL only on Windows, where drive-letter paths require it\n- cover Linux, macOS, and Windows specifier selection\n\n## Validation\n\n- `./shifu install`\n- `node --test product/scripts/dist.test.mjs`\n\nFixes the Linux product failure in #629.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:21:27Z",
          "mergedAt": "2026-07-12T08:26:03Z",
          "additions": 13,
          "deletions": 9,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1136,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1136",
          "title": "fix(checkout): accept regenerated pull merge trees",
          "body": "## Summary\n- keep commit identity strict for branches and ordinary refs\n- allow a regenerated GitHub pull-request merge commit only when its tree exactly matches the locked source tree\n- record the expected head and tree-equivalent identity mode in checkout evidence\n\n## Context\nKungfu PR #629 locked a synthetic pull merge SHA that GitHub later regenerated. The advertised pull ref still resolved to the same tree, but the original synthetic commit was no longer fetchable.\n\n## Validation\n- `node --test tests/locked-source-checkout.test.mjs`\n- `pnpm run build`\n- `pnpm run check` (551 tests passed)\n- `git diff --check`\n\nTrain ref: `train/v2/v2.12/locked-source-ref-fetch`",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:25:32Z",
          "mergedAt": "2026-07-12T08:29:08Z",
          "additions": 112,
          "deletions": 9,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1137,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1137",
          "title": "fix(release): promote locked-source checkout recovery",
          "body": "## Summary\n- promote the reviewed locked-source checkout recovery into the v2.12 alpha channel\n- preserve strict commit identity except for regenerated GitHub pull merge commits with the exact locked tree\n- unblock Kungfu alpha candidates when GitHub rotates a synthetic merge commit\n\n## Evidence\n- implementation PR #1136\n- Buildchain Verify and Build Surface Fixture passed\n- Kungfu direct r6 product matrix uses the train ref before this promotion",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:29:49Z",
          "mergedAt": "2026-07-12T08:31:43Z",
          "additions": 112,
          "deletions": 9,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 638,
          "url": "https://github.com/kungfu-systems/kungfu/pull/638",
          "title": "refactor(slices): rename internal msg_type to carrier_type (ADR-0065)",
          "body": "Renames the pre-ADR-0025 msg_type term to carrier_type in the fact-ledger and schema-registry probe slices (internal function/param names, comments, log text, JSON output keys; the value was already frame->carrier_type()). Out of scope: the frozen kf_embedding_frame_v1 ABI field and its readers/writers, Rust FFI mirrors, node/TS msgType binding API, and the carrier-action gate. Slice READMEs + docs/msg-type-ranges.md are a separate doc pass.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:35:25Z",
          "mergedAt": "2026-07-12T08:35:30Z",
          "additions": 11,
          "deletions": 11,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 642,
          "url": "https://github.com/kungfu-systems/kungfu/pull/642",
          "title": "fix(runtime): make error stop ownership local",
          "body": "Implements ADR-0064 error/stop ownership boundaries.\n\n- replaces replay-time raise(SIGINT) with typed replay_exhausted\n- scopes first-error-wins stop state to each reactor without process-global callbacks\n- preserves native error identity across Python and Node hosts\n- pins Node Watcher lifetime across uv work and removes invalid CallbackInfo reuse\n- adds focused native/Python qualification tests\n\nValidation:\n- ./shifu test:runtime-errors (pass)\n- ./shifu test:mmap (pass)\n- ./shifu check reaches pre-existing framework/core/.gyp/run-freeze.js TS2339 baseline failure\n- full build passed before rebase; post-rebase dependency preparation is blocked by a missing RocksDB archive in local Conan cache before compilation\n- dispatch benchmark is unavailable because its existing quote default is incompatible with dispatch_load.py integer parsing\n\nGoal: 2026-07-12-kungfu-adr0064-error-stop-ownership\nMission: kungfu-technical-stewardship\nAgent: codex",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:55:14Z",
          "mergedAt": "2026-07-12T08:55:19Z",
          "additions": 483,
          "deletions": 60,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 643,
          "url": "https://github.com/kungfu-systems/kungfu/pull/643",
          "title": "perf(libwasm): share stable per-engine Cargo caches",
          "body": "## What changed\n\n- move production Wasmtime and Wasmer Cargo target directories out of each\n  CMake build tree into stable per-engine user-cache slots;\n- key each slot by source checkout, actual Cargo/rustc identity and target,\n  profile, engine, and lockfile;\n- stage each adapter back into its consuming CMake tree so build artifacts do\n  not depend on an external-cache path;\n- serialize the two heavy Cargo builds inside one CMake graph while retaining\n  Cargo's per-target lock as the cross-graph boundary;\n- apply the same contract to the shared-membrane qualification slice;\n- add a deterministic CMake contract test and\n  `./shifu qualify:libwasm-cache` for cold/warm cross-platform evidence.\n\n## Why\n\nThe two engine workspaces intentionally remain separate because their Cranelift\ndependency lines are incompatible. The previous integration also placed both\ntarget directories under `CMAKE_CURRENT_BINARY_DIR`, so every distinct CMake\ntree paid another full Rust dependency build. This change preserves the strict\nengine/workspace boundary while making target reuse stable and explicit.\n\n## Impact\n\nSeparate CMake trees from one checkout now reuse compiled Rust dependencies.\nDifferent worktrees, engines, toolchains, targets, profiles, or lockfiles cannot\ncollide. `CARGO_HOME` still owns shared registry downloads; the optional Cargo\nmirror remains a transport-only override.\n\n## Validation\n\n- macOS arm64:\n  - qualification (Cargo 1.95): Wasmtime `319 ms -> 89 ms`, Wasmer\n    `327 ms -> 132 ms` on the corrected warm run;\n  - full `./shifu build:core` passed in `117.50 s`; production CMake adapter\n    steps reused the cache in `0.45 s` and `0.66 s`.\n- agent-120 Linux x64 (Cargo 1.96): Wasmtime `80.2 s -> 78 ms`, Wasmer\n  `76.7 s -> 91 ms`.\n- DARKHERO Windows x64 (Cargo 1.96): Wasmtime `159.3 s -> 112 ms`, Wasmer\n  `164.7 s -> 202 ms`.\n- Commit hooks: staged source/format/contract gates passed on both commits.\n- `./shifu check`: all changed-file and cache-contract gates passed; the shared\n  tooling phase remains blocked by the pre-existing unchanged\n  `framework/core/.gyp/run-freeze.js:600` TypeScript inference error.\n- CI was not used for this change; the three requested native hosts supplied\n  the build evidence.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:58:38Z",
          "mergedAt": "2026-07-12T08:59:02Z",
          "additions": 542,
          "deletions": 22,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 644,
          "url": "https://github.com/kungfu-systems/kungfu/pull/644",
          "title": "feat(shifu): define cache profile contract",
          "body": "## Summary\n\n- establish an independent Shifu ADR registry and cache ownership decision\n- add versioned profile and redacted resolution JSON Schemas with fixtures and conformance checks\n- expose exact checked-in contracts through `shifu cache contract/schema` on macOS, Linux, and Windows entrypoints\n- fix the existing freeze options type inference regression so the repository gate remains green\n\n## Validation\n\n- `./shifu check`\n- `./shifu cache contract`\n- `./shifu cache schema profile`\n- `./shifu cache schema resolution`\n\n## Version impact\n\nAdditive update to the pre-release `shifu-launcher` welded surface; no line opening.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T09:08:14Z",
          "mergedAt": "2026-07-12T09:08:23Z",
          "additions": 1596,
          "deletions": 14,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 620,
          "url": "https://github.com/kungfu-systems/kungfu/pull/620",
          "title": "ci(core): gate membrane latency on the noise-free p50, not the flaky p99",
          "body": "The shared-embedding-membrane latency gate failed intermittently on shared CI\nrunners. Quantified from recent runs: the 4 KiB batch **p99 rides its\nprovisional 5us budget** and jitters above it (3.4-4.7us on macOS ARM64,\n4.6-6.2us on Linux x64) while the **code-path p50 stays flat** at 1.4-2.4us.\nThat tail is scheduler preemption on a shared runner, not a code regression. On\na loaded runner every trial can exceed 5us at once, so per-trial aggregation\nalone cannot rescue it.\n\n**Fix:** gate the noise-free p50 code-path budgets (control 500ns, 4 KiB batch\n3.5us); take five trials and report the p99 min/median as advisory triage\nnumbers rather than gating them. A genuine latency regression raises p50 and\nstill fails the gate; only the shared-runner tail jitter is de-gated.\n\nScope is the perf gate only. The separate Dev Check PyPI-index issue (uv.lock\npins the internal mirror) is being handled in its own change.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T07:02:20Z",
          "mergedAt": "2026-07-12T09:09:06Z",
          "additions": 42,
          "deletions": 15,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 640,
          "url": "https://github.com/kungfu-systems/kungfu/pull/640",
          "title": "fix(gui): default desktop packaging to no publish",
          "body": "## Summary\n- default the cross-platform electron-builder launcher to `--publish=never`\n- preserve an explicit caller-provided publish mode\n- make the launcher import-safe and cover both argument paths with focused tests\n\n## Context\nKungfu r6 generated the Linux AppImage successfully, then electron-builder inferred CI publishing and failed because candidate builds intentionally do not receive a GitHub publishing token. Release publication remains owned by Buildchain.\n\n## Validation\n- `node --test framework/gui/scripts/run-electron-builder.test.mjs product/scripts/dist.test.mjs` (5 passed)\n- staged repository gate passed\n- `git diff --check`\n- failing product evidence: run 29186140338",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:50:11Z",
          "mergedAt": "2026-07-12T09:09:37Z",
          "additions": 44,
          "deletions": 8,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 639,
          "url": "https://github.com/kungfu-systems/kungfu/pull/639",
          "title": "feat(trunk): run the node variant natively on Windows (ADR-0046 S3 Phase B1)",
          "body": "ADR-0046 stage 3 productionization, Phase B1 (Windows node variant). `KUNGFU_AS_VARIANT=node` now runs natively on Windows without booting CPython, matching macOS/Linux.\n\n- `crates/trunk/src/variant.rs`: Windows arm using `LoadLibraryW`/`GetProcAddress` to load `kungfu_node_host.dll` next to the exe and call `kungfu_node_run` (node::Start). argv build + invocation factored into a shared `invoke_node` (unix keeps raw-byte argv; Windows uses lossy UTF-8).\n- `framework/core/src/bindings/node/CMakeLists.txt`: widen the node-host gate to `(UNIX OR WIN32)`. The host is an embedder, so on Windows it links the real libnode import lib (`libnode.lib`, which ships in LIBNODE_LIB_DIR next to libnode.dll) — not a delay-loaded node.exe like the napi addons. Body is already portable (`__declspec(dllexport)`-ready entry, unix-guarded strip, MSVC-ignored visibility preset).\n- `framework/core/.gyp/run-freeze.js`: `copyPyBindingWin` stages `kungfu_node_host.dll` (+PDB) into dist/kungfu.\n\nZero-regression: absent DLL → `variant.rs` returns None and the Python variant path still runs node.\n\nValidated on real Windows (DARKHERO, MSVC + cargo 1.96): standalone `cl` build links `libnode.lib` and exports `kungfu_node_run`; the real Windows trunk build (variant.rs Windows arm) loads the host and runs node end-to-end — `KUNGFU_AS_VARIANT=node kungfu-trunk.exe --version` → `v22.22.3`, `-e \"console.log(2+3)\"` → `5`.\n\nWindows `doctor`/embedding stays stub (deferred: needs a new single-export embedding DLL; separate evaluation).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T08:44:06Z",
          "mergedAt": "2026-07-12T09:25:35Z",
          "additions": 113,
          "deletions": 21,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 649,
          "url": "https://github.com/kungfu-systems/kungfu/pull/649",
          "title": "docs(adr): add ADR-0067 schema-registry compile-time contract welds",
          "body": "Welds two schema-contract invariants at compile time (reusing ADR-0062 fingerprint + ADR-0065 subsets): carrier_type tag uniqueness static_assert, and a paired static_assert binding each of the 13 versioned manifest POD records' layout fingerprint to its schema_version. schema_version stays explicit (option B); option i now, option ii ledger at stable release. Version-less control types out of scope.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T09:33:01Z",
          "mergedAt": "2026-07-12T09:33:06Z",
          "additions": 154,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 650,
          "url": "https://github.com/kungfu-systems/kungfu/pull/650",
          "title": "ci(core): rebind Dev Check lock to public PyPI before frozen sync",
          "body": "The committed `framework/core/uv.lock` pins every artifact URL to the office\ndevpi mirror (`192.168.100.222:3141`), a LAN pull-through PyPI cache that gives\noffice / self-hosted builds a fast path over the restricted cross-border link.\nGitHub-hosted runners cannot reach that private address, so Dev Check's raw\n`uv sync --frozen` fails intermittently with a `tcp connect error` whenever a\nwheel is not already cached (4 of the last 6 Dev Check failures were this).\n\n**Fix (option A, matches the embedding-membrane spike workflow):** re-resolve\nthe same packages against public PyPI and assert the lock fingerprint (names,\nversions, hashes) is unchanged before the frozen sync. Only this GitHub-hosted\nCI job rebinds — the committed lock and the office LAN fast path are untouched,\nand a genuinely missing package still fails.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T09:33:19Z",
          "mergedAt": "2026-07-12T09:34:51Z",
          "additions": 24,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 651,
          "url": "https://github.com/kungfu-systems/kungfu/pull/651",
          "title": "fix(cli): propagate backtest runtime context",
          "body": "## Summary\n- propagate `backtest_dir` through nested Kungfu CLI contexts\n- cover the installed `storage layout --json` path with a regression test\n\n## Validation\n- `./shifu check`\n- `./shifu check:staged`\n\nThe direct product gate exposed this after successfully producing the Linux AppImage: the installed CLI smoke failed because the nested `storage` context lacked `backtest_dir`.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T09:36:15Z",
          "mergedAt": "2026-07-12T09:37:31Z",
          "additions": 21,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 653,
          "url": "https://github.com/kungfu-systems/kungfu/pull/653",
          "title": "Merge remote-tracking branch 'origin/dev/v4/v4.0' into feature/strong-durability-docs",
          "body": "Merge feature/strong-durability-docs into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T09:46:04Z",
          "mergedAt": "2026-07-12T09:46:10Z",
          "additions": 801,
          "deletions": 0,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 654,
          "url": "https://github.com/kungfu-systems/kungfu/pull/654",
          "title": "feat(query): drive Mission Control from saved profiles",
          "body": "## Summary\n- project the five Mission Control answers from versioned Saved Query profiles\n- drive Work Dashboard refresh from proof-bearing fact changelog state\n- preserve workspace selection and live refresh compatibility\n- repair electron beforePack ESM entrypoint and dashboard storage capability declaration\n\n## Validation\n- targeted Python query, changelog, Atlas and Saved Query tests\n- API TypeScript build and query tests\n- Status and Work Dashboard KFX builds\n- product unit tests\n- full native/Python/Node rebuild and freeze\n- unpacked macOS product build, Shifu registration/promote, and real Atlas GUI dogfood\n\n## Known limits\n- CI is currently known broken; this PR does not wait for CI\n- existing headless Atlas fixture has independent sync_root_mismatch debt\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-12T09:48:01Z",
          "mergedAt": "2026-07-12T09:54:41Z",
          "additions": 858,
          "deletions": 91,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1138,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1138",
          "title": "fix(checkout): preserve fetch diagnostics for retries",
          "body": "## Summary\n- preserve Git fetch stderr in locked-source checkout\n- allow the existing transient-network classifier to recognize RPC/HTTP transport failures and use the configured bounded retries\n- cover the fetch stdio contract with a regression test\n\n## Validation\n- `pnpm run check` (552 tests passed; action bundles rebuilt)\n\nThis was exposed by Kungfu r8 direct qualification: a transient GitHub shallow-fetch failure lost its RPC diagnostics and exited after attempt 1 despite `fetchAttempts=3`.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T09:59:57Z",
          "mergedAt": "2026-07-12T10:01:53Z",
          "additions": 21,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1140,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1140",
          "title": "fix(release): promote checkout retry diagnostics",
          "body": "## Summary\n- promote the reviewed locked-source fetch diagnostics fix into the v2.12 alpha channel\n- preserve Git stderr so bounded retries recognize transient RPC/HTTP failures\n- unblock Kungfu r8 direct product qualification without weakening source identity checks\n\n## Evidence\n- implementation PR #1138\n- Buildchain check and three-platform libnode-shaped workflow passed\n- Kungfu r8 attempt 2 exposed a first-attempt GitHub shallow-fetch failure that lost retry classification",
          "author": "dongkeren",
          "createdAt": "2026-07-12T10:02:20Z",
          "mergedAt": "2026-07-12T10:04:14Z",
          "additions": 21,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 657,
          "url": "https://github.com/kungfu-systems/kungfu/pull/657",
          "title": "feat(schema): weld carrier_type tag uniqueness at compile time (ADR-0067)",
          "body": "Weld the carrier_type tag-uniqueness invariant at compile time per ADR-0067. A constexpr adjacent-distinct scan over the sorted AllTypesTags plus a static_assert turns a silent duplicate tag into a build failure. Tags stay explicit and hand-allocated. Verified: positive case compiles, a deliberate duplicate tag fails the assert.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T10:24:07Z",
          "mergedAt": "2026-07-12T10:24:12Z",
          "additions": 19,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 660,
          "url": "https://github.com/kungfu-systems/kungfu/pull/660",
          "title": "feat(schema): weld manifest payload layout to schema_version at compile time (ADR-0067)",
          "body": "Weld each versioned manifest POD record's payload layout to its schema_version per ADR-0067 (option i / option B). Binds layout_fingerprint<T>() (ADR-0062) to a checked-in expected value for all 13 records across the three ADR-0065 subsets; a size-preserving layout change fails the paired static_assert, and a coverage guard prevents a new versioned record from shipping unwelded. schema_version stays an explicit hand-chosen integer. Verified: matching layouts compile, an equal-width retype fails its assert.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T10:29:37Z",
          "mergedAt": "2026-07-12T10:29:42Z",
          "additions": 69,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 661,
          "url": "https://github.com/kungfu-systems/kungfu/pull/661",
          "title": "fix(api): use NodeNext query specifier",
          "body": "Closes #658.\n\nUse an explicit `.js` specifier for the type-only `query` import so the API package remains valid under NodeNext module resolution.\n\nValidation:\n- `./shifu check:types`\n- `./shifu check`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-12T10:30:12Z",
          "mergedAt": "2026-07-12T10:30:43Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 666,
          "url": "https://github.com/kungfu-systems/kungfu/pull/666",
          "title": "fix(shifu): skip cache-contract schema checks when ajv is absent",
          "body": "Merge fix/shifu-cache-gate-ajv-optional into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T11:22:54Z",
          "mergedAt": "2026-07-12T11:22:59Z",
          "additions": 66,
          "deletions": 35,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 668,
          "url": "https://github.com/kungfu-systems/kungfu/pull/668",
          "title": "feat(runtime): add durability position and receipt contract",
          "body": "Merge feature/durability-position-receipts into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T11:41:39Z",
          "mergedAt": "2026-07-12T11:41:48Z",
          "additions": 730,
          "deletions": 3,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 671,
          "url": "https://github.com/kungfu-systems/kungfu/pull/671",
          "title": "docs: add single-host institutional trust profile",
          "body": "## Summary\n- add an institution-facing adoption contract for Kungfu as a single-host local runtime ledger\n- state the current evaluation/shadow-only decision and exact non-claims\n- define the deployment envelope, guarantee and failure matrices, evidence requirements, operator responsibilities, and adoption gates\n- link the profile from README, the documentation map, known limits, and the durability overview\n\n## Validation\n- ./shifu check\n- local Markdown link validation across all touched documents\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-12T11:51:38Z",
          "mergedAt": "2026-07-12T11:51:45Z",
          "additions": 219,
          "deletions": 0,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 672,
          "url": "https://github.com/kungfu-systems/kungfu/pull/672",
          "title": "docs: define single-host performance release gate",
          "body": "## Summary\\n- define the post-correctness Single-Host End-to-End Performance Qualification release gate\\n- make Kungfu absolute thresholds, regression ceilings, and retained evidence authoritative\\n- constrain Aeron IPC and Aeron Archive to declared, same-semantics informative comparisons\\n- connect the gate to institutional trust, durability stages, known limits, README, and the documentation map\\n\\n## Validation\\n- ./shifu check\\n- local Markdown link validation across touched documents\\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-12T12:11:24Z",
          "mergedAt": "2026-07-12T12:11:32Z",
          "additions": 262,
          "deletions": 3,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 673,
          "url": "https://github.com/kungfu-systems/kungfu/pull/673",
          "title": "feat(runtime): fence state service and stream writers",
          "body": "Implements the ADR-0068 state-service separation slice for the Single-Host Institutional Profile: an in-process state-service boundary, independent projection lifecycle, data-root and physical-journal writer fencing with generation evidence, restartable shadow comparison, and cross-process crash/reopen tests. This does not claim durable ingest, durable receipts, HA, or power-loss qualification.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T12:15:15Z",
          "mergedAt": "2026-07-12T12:15:20Z",
          "additions": 1152,
          "deletions": 32,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 675,
          "url": "https://github.com/kungfu-systems/kungfu/pull/675",
          "title": "fix(gui): keep Mission Control refresh nonblocking",
          "body": "## Summary\n\n- execute Mission Control dashboard and assessment CLI reads asynchronously in the Electron main process\n- apply one cut-bound dashboard snapshot atomically with cached stale-while-refresh behavior, single-flight coalescing, and stale result rejection\n- yield between query changelog pages and remove synchronous native runtime-health polling from the renderer\n\n## Validation\n\n- `./shifu check`\n- API query tests, GUI Atlas transport tests, dashboard refresh coordinator tests\n- focused Python Mission Control snapshot test\n- full core build and `./shifu dist --product desktop --dir`\n- real `/Users/dkr/Code/atlas` 10-second continuous resize with 12 concurrent refreshes: RAF p95 17.6 ms, max 17.8 ms, zero long tasks, no degraded snapshot\n\nCI is currently known to be unreliable; this change is being assessed from the local evidence above.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T12:20:43Z",
          "mergedAt": "2026-07-12T12:24:48Z",
          "additions": 623,
          "deletions": 92,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 676,
          "url": "https://github.com/kungfu-systems/kungfu/pull/676",
          "title": "docs: lead performance gate with semantic purpose",
          "body": "## Summary\\n- lead the performance qualification contract with the distinction between observability telemetry and load-bearing agent ledger facts\\n- make visibility, durability, recovery, and meaning explicit obligations under load\\n- surface the same positioning in the README documentation entry\\n\\n## Validation\\n- ./shifu check\\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-12T12:26:35Z",
          "mergedAt": "2026-07-12T12:26:41Z",
          "additions": 35,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 669,
          "url": "https://github.com/kungfu-systems/kungfu/pull/669",
          "title": "feat(core): single-export embedding DLL — doctor works on Windows (ADR-0046 S3 Phase B2)",
          "body": "ADR-0046 stage 3, Phase B2. Makes `doctor`/the embedding membrane real on Windows.\n\nOn Windows the core is built STATIC and does not export `kungfu_embedding_get_api` (a SHARED core blows the COFF 65535-export limit, LNK1189), so the trunk had nothing to link. Add a **Windows-only** SHARED target `kungfu_embedding` (in its own `src/libembedding/`, so it doesn't inherit libkungfu's `enable_windows_export_all_symbols()`) that exports exactly `kungfu_embedding_get_api` and internally static-links the whole core closure (`kungfu` + `kungfu_compile_contract` + `CONAN_LIBS` — pykungfu's line minus libnode). One dllexport dodges LNK1189. POSIX is untouched (the SHARED libkungfu still exports the entry).\n\n- `framework/core/src/libembedding/CMakeLists.txt` (new) + core CMakeLists `if(WIN32 AND TARGET kungfu)` wiring.\n- `crates/trunk/build.rs`: drop the Windows panic; on Windows emit `rustc-link-lib=dylib=kungfu_embedding` from the build root (no rpath). POSIX unchanged.\n- `run-freeze.js` / `dist.mjs`: extend `--features embedding` to Windows (build-root native dir); `copyPyBindingWin` stages `kungfu_embedding.dll`.\n\nValidated end-to-end on real Windows (DARKHERO, MSVC + cargo 1.96):\n- `kungfu_embedding.dll` links the full core closure cleanly (`[26/26] Linking`, exit 0); `dumpbin /exports` shows **exactly one** symbol, `kungfu_embedding_get_api` (LNK1189 avoided); the DLL is self-contained (only system/MSVC-runtime deps).\n- The trunk built `--features embedding` links `kungfu_embedding.lib`; `doctor` → real embedding membrane, ABI v1, real capabilities `(0x3)` (not the stub).\n- POSIX `--features embedding` verified regression-free (still links `@rpath/libkungfu`).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T11:42:45Z",
          "mergedAt": "2026-07-12T12:31:31Z",
          "additions": 157,
          "deletions": 59,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 677,
          "url": "https://github.com/kungfu-systems/kungfu/pull/677",
          "title": "chore(gui): remove unused skill-context builder duplicates",
          "body": "`buildGuiSkillContext` and `buildGuiSkillManagerView` (in `framework/gui/src/main/skill-context.ts`) have **no importer anywhere in the repo**. They are in-memory duplicates of `writeGuiSkillContextFile` / `writeGuiSkillManagerViewFile` — the file-writing variants that `index.ts` actually uses; the GUI only ever writes the files. Removed the two dead functions and their now-unused `@kungfu-tech/skill` imports (28 lines).\n\nNo behavior change. From a dead-code survey. The survey's other gui candidates were kept after closer reading: `sandbox-view.ts:createSandboxedView` is a deliberate anti-drift reference (per its own header comment), and `installCli.ts:isKungfuCliInstalled` reads as reserved API — both deferred to owner review rather than removed here.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T12:33:04Z",
          "mergedAt": "2026-07-12T12:35:04Z",
          "additions": 0,
          "deletions": 28,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1139,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1139",
          "title": "feat(build): pass opaque Shifu cache profile inputs",
          "body": "## Summary\n\n- add opaque Shifu cache profile reference and digest inputs\n- pass the pair to lifecycle execution without fetching or interpreting profile fields\n- document and test the Buildchain/Shifu ownership boundary\n\n## Validation\n\n- `pnpm run check`\n- downstream validation ref: `train/v2/v2.3/shifu-cache-profile-passthrough`\n\n## Boundary\n\nBuildchain only transports the profile reference and digest. Shifu owns profile resolution, validation, application, and redacted receipts.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T10:02:16Z",
          "mergedAt": "2026-07-12T12:45:09Z",
          "additions": 121,
          "deletions": 21,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1141,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1141",
          "title": "feat(release): promote Shifu cache profile passthrough to alpha",
          "body": "## Summary\n- promote the reviewed opaque Shifu cache profile ref/digest passthrough into the v2.12 alpha channel\n- preserve the boundary that Buildchain transports values but does not parse Shifu profile fields\n\n## Evidence\n- implementation PR #1139 merged into dev/v2/v2.12\n- local Buildchain check: 552 tests passed after rebase\n- Buildchain PR check and three-platform libnode-shaped workflow passed\n- Kungfu train dogfood resolved rebased runtime 2ed3a0ad and accepted the exact Atlas runner profile digest; install passed before an unrelated existing product smoke failure",
          "author": "dongkeren",
          "createdAt": "2026-07-12T12:45:45Z",
          "mergedAt": "2026-07-12T12:48:28Z",
          "additions": 121,
          "deletions": 21,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 678,
          "url": "https://github.com/kungfu-systems/kungfu/pull/678",
          "title": "fix(build): patch rxcpp maybe<T> off deprecated std::aligned_storage",
          "body": "std::aligned_storage is deprecated in C++23 (P1413R3); rxcpp 4.1.1 uses it in maybe<T>, so under -std=gnu++23 every kungfu rx consumer instantiating maybe<T> emits a deprecation warning -isystem cannot suppress. Conan recipe patch replaces it with an equivalent alignas byte buffer; placement-new access unchanged. Verified: patched package header contains zero std::aligned_storage occurrences.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T12:54:42Z",
          "mergedAt": "2026-07-12T12:54:47Z",
          "additions": 15,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 680,
          "url": "https://github.com/kungfu-systems/kungfu/pull/680",
          "title": "docs(vocabulary): center public language on Episode",
          "body": "## Summary\n\n- establish Episode as the flagship object for real-world execution\n- publish a layered narrative around Facts, Receipts, Cuts, Watermarks, Claims, Proof, and Decisions\n- add a canonical vocabulary reference that separates Kungfu Core terms from domain profile vocabulary\n- route README, Concepts, and the documentation map to the new public entrypoints\n\n## Validation\n\n- `./shifu check`\n- `./shifu check:staged`\n- `git diff --check`\n\n## Boundaries\n\n- documentation only; no runtime, schema, CLI, or release-contract behavior changes\n- Mission and Go remain Agent Work profile terms whose naming may evolve\n- maturity and platform guarantees continue to defer to Contracts, Known Limits, and qualification evidence",
          "author": "dongkeren",
          "createdAt": "2026-07-12T13:07:50Z",
          "mergedAt": "2026-07-12T13:08:28Z",
          "additions": 604,
          "deletions": 2,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 655,
          "url": "https://github.com/kungfu-systems/kungfu/pull/655",
          "title": "feat(shifu): apply projected cache profiles",
          "body": "## Summary\n\n- implement Shifu-owned cache profile validation, resolution, binding application, and redacted receipts\n- wrap lifecycle and verification execution through `shifu cache apply`\n- pass only an opaque profile reference and digest through Buildchain\n- document the KFD-1 profile runtime and ownership boundary\n\n## Validation\n\n- `./shifu check`\n- cache runtime and contract tests: 13 passed\n- consumer currently pinned to `train/v2/v2.3/shifu-cache-profile-passthrough` for downstream validation\n\n## Dependency\n\n- kungfu-systems/buildchain#1139 must merge and publish a final ref before this PR replaces the temporary train reference and merges.\n\n## Safety\n\nProfiles and receipts reject URL credentials, query strings, fragments, secret-like environment keys, unsupported bindings, scope drift, and digest drift.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T10:09:15Z",
          "mergedAt": "2026-07-12T13:10:39Z",
          "additions": 1034,
          "deletions": 25,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 682,
          "url": "https://github.com/kungfu-systems/kungfu/pull/682",
          "title": "feat(runtime): add shadow durable ingest barriers",
          "body": "## Summary\n- add the versioned KFDL append-only segment and dual-slot checkpoint backend\n- enforce fenced owner/writer admission, exact restart deduplication, typed timeout/unavailable outcomes, and fail-stop unknown append handling\n- verify complete covered segment chains, preserve unknown tails, and compare a published mmap frame with decoded durable data\n- keep production durability profiles fail-closed behind qualification\n\n## Validation\n- ./shifu build:core\n- ./shifu test:durable-ingest\n- ./shifu test:state-service\n- ./shifu test:durability-contract\n- ./shifu test:runtime-errors\n- ./shifu test:mmap\n- ./shifu check",
          "author": "dongkeren",
          "createdAt": "2026-07-12T13:19:04Z",
          "mergedAt": "2026-07-12T13:19:10Z",
          "additions": 2404,
          "deletions": 8,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 683,
          "url": "https://github.com/kungfu-systems/kungfu/pull/683",
          "title": "fix(runtime): fail fast on unsupported nanomsg protocol; clarify intentional reactor warnings",
          "body": "Verdict-before-fix triage of 3 Tier-1 compiler warnings. BUG1 (nanomsg uninitialized rc on unsupported protocol) was a real UB and is fixed to fail deterministically. BUG2 (bitwise | in add_location) and BUG3 (discarded nodiscard probe in ensure_coordinator_rocksdb) were intentional; rewritten to preserve behavior while silencing the warnings. Verified via sibling compile_commands.json -fsyntax-only: all three target warnings gone, no new warnings.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T13:20:54Z",
          "mergedAt": "2026-07-12T13:20:59Z",
          "additions": 11,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 684,
          "url": "https://github.com/kungfu-systems/kungfu/pull/684",
          "title": "fix(gui): add Mission Control situation view",
          "body": "## Summary\n- replace the default five-question/table presentation with a visual Mission situation view\n- group parent and child Gos into progressive-disclosure cluster cards\n- expose purpose-bound KFD-2 glyphs, evidence freshness, next actor, and a detail drawer\n- preserve the five-question query output in explicit audit mode\n- project the Atlas hierarchy and Mission context fields needed by the visual model\n\n## Verification\n- ./shifu check\n- ./shifu foreach:extensions test (6/6)\n- ./shifu foreach test:query (7/7)\n- focused Atlas projection pytest (2/2)\n- ./shifu build\n- ./shifu dist --product desktop --dir\n- real Atlas workspace dogfood: visual spec present, five questions hidden by default, audit questions preserved, drawer tabs work, parent/child cluster detected, 760px viewport has no body overflow\n\n## Product\n- promoted Shifu build 20260712T133420Z-be00e1336\n- CI is currently not treated as a merge gate per operator instruction",
          "author": "dongkeren",
          "createdAt": "2026-07-12T13:37:04Z",
          "mergedAt": "2026-07-12T13:37:28Z",
          "additions": 1731,
          "deletions": 128,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 685,
          "url": "https://github.com/kungfu-systems/kungfu/pull/685",
          "title": "docs: center public guidance on Episodes",
          "body": "Merge docs/docs-information-architecture into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T13:45:12Z",
          "mergedAt": "2026-07-12T13:45:17Z",
          "additions": 423,
          "deletions": 417,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 686,
          "url": "https://github.com/kungfu-systems/kungfu/pull/686",
          "title": "docs: retire stale spec guidance",
          "body": "Merge docs/docs-stale-surface-cleanup into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T13:50:57Z",
          "mergedAt": "2026-07-12T13:51:03Z",
          "additions": 165,
          "deletions": 212,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 687,
          "url": "https://github.com/kungfu-systems/kungfu/pull/687",
          "title": "feat(runtime): add shadow projection bootstrap",
          "body": "## Summary\n\n- add a state-service-owned binary snapshot-through-T and replay-after-T substrate over checkpoint-covered KFDL records\n- bind snapshots to logical cut, projection schema, source qualification profile, and SHA-256 integrity\n- provide typed required/optional/none bootstrap outcomes, deterministic rebuild, lag/watermark status, and fail-closed corruption handling\n- keep the production coordinator compatibility restore unchanged; this PR is shadow evidence, not a public durability claim\n\n## Validation\n\n- ./shifu build:core\n- ./shifu test:projection-bootstrap\n- ./shifu test:durable-ingest\n- ./shifu test:state-service\n- ./shifu test:durability-contract\n- ./shifu test:runtime-errors\n- ./shifu test:mmap\n- ./shifu check\n\n## Remaining boundary\n\nProduction state-schema projection, shadow equality/cutover, coordinator business-join removal, real power-loss qualification, and public durable profiles remain disabled.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T13:51:25Z",
          "mergedAt": "2026-07-12T13:51:30Z",
          "additions": 1136,
          "deletions": 4,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 667,
          "url": "https://github.com/kungfu-systems/kungfu/pull/667",
          "title": "fix(ci): qualify membranes on current toolchains",
          "body": "Closes #646.\nCloses #664.\n\nFinal linear replacement for the embedding-membrane qualification. It preserves all reviewed fixes while avoiding the merge commits introduced into the earlier shared branches.\n\nChanges:\n- repo-owned RocksDB 6.29.5 Conan recipe with narrowly scoped current-compiler fixes\n- Ubuntu 24.04 / GCC 14 qualification and explicit Ninja selection\n- one Shifu-owned three-platform qualification task with MSVC bootstrap\n- calibrated Windows p50 gate from five-trial evidence while retaining the tighter POSIX budget\n- explicit MSVC empty-base optimization for generated journal records so persisted POD layouts match macOS/Linux\n\nValidation:\n- `./shifu install --frozen-lockfile`\n- `./shifu check`\n- `git diff --check` excluding patch payload whitespace\n- run 29189269994: macOS/Linux passed; Windows exposed #664\n- this PR must obtain fresh three-platform qualification on its current head before merge\n\nSupersedes #647, #659, and #662. No force-push or history rewrite was used.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T11:22:55Z",
          "mergedAt": "2026-07-12T13:53:04Z",
          "additions": 508,
          "deletions": 65,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 689,
          "url": "https://github.com/kungfu-systems/kungfu/pull/689",
          "title": "style(schema): format manifest layout weld",
          "body": "Format the ADR-0067 manifest layout weld macro with the repository-pinned clang-format.\n\nThis was exposed by the alpha candidate staged gate, which correctly checks the entire dev projection against the older alpha base. No behavior changes.\n\nValidation:\n- `uvx clang-format@20.1.8 -style=file --dry-run -Werror framework/core/src/libyijinjing/include/kungfu/yijinjing/schema/registry.h`\n- `./shifu check`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-12T13:56:49Z",
          "mergedAt": "2026-07-12T13:57:34Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 691,
          "url": "https://github.com/kungfu-systems/kungfu/pull/691",
          "title": "feat(runtime): persist durable frame context",
          "body": "## Summary\n- supersede the internal test-only KFDL v1 container with v2 records carrying the complete journal frame context\n- expose the context through durable records and the state-service shadow append boundary\n- verify restart reconstruction against an actually published mmap frame without changing journal wire-v1 or the mmap hot path\n\n## Why\nThe projection bootstrap shadow could prove payload identity, but existing `state<DataType>` routing also requires source, destination, generation time, data type, and trigger lineage. Persisting those facts in the independent durable record is required before a real typed-state projector can be qualified.\n\n## Validation\n- `./shifu build:core`\n- `./shifu test:durable-ingest`\n- `./shifu test:projection-bootstrap`\n- `./shifu test:state-service`\n- `./shifu test:durability-contract`\n- `./shifu test:runtime-errors`\n- `./shifu test:mmap`\n- `./shifu check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-12T14:10:38Z",
          "mergedAt": "2026-07-12T14:11:03Z",
          "additions": 119,
          "deletions": 28,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 693,
          "url": "https://github.com/kungfu-systems/kungfu/pull/693",
          "title": "feat(runtime): project typed state from durable records",
          "body": "## Summary\n- add a typed-state projector driven directly by the authoritative Hana `StateDataTypes` roster\n- derive the same type/uid/source/destination/update-time/data image from durable KFDL v2 records and the compatibility state bank\n- prove all current state types, same-cut equality, uid replacement semantics, fail-closed malformed records, and rollback snapshot retention\n\n## Boundary\nThis remains a test-only shadow/cutover gate. Production coordinator restore remains active; journal wire-v1, mmap hot path, Hana POD, FlatBuffers owners, and public durability claims are unchanged.\n\n## Validation\n- `./shifu build:core`\n- `./shifu test:projection-bootstrap`\n- `./shifu test:durable-ingest`\n- `./shifu test:state-service`\n- `./shifu test:durability-contract`\n- `./shifu test:runtime-errors`\n- `./shifu test:mmap`\n- `./shifu check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-12T14:27:27Z",
          "mergedAt": "2026-07-12T14:28:00Z",
          "additions": 255,
          "deletions": 8,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 694,
          "url": "https://github.com/kungfu-systems/kungfu/pull/694",
          "title": "ci(docs): add layered Markdown validation gates",
          "body": "## Summary\n\nAdd a deterministic documentation gate for Markdown structure, the full local-link and cross-file anchor graph, canonical documentation entrypoints, and explicitly retired product wording. Keep external URL health in a separate pinned Lychee workflow so network availability cannot make pull-request results nondeterministic.\n\n## Changes\n\n- add `./shifu docs:check` and integrate it into changed/staged quality gates\n- add a conservative zero-debt Markdownlint baseline plus a repository-owned link/anchor/contract checker\n- add eight negative fixtures, including case mismatch and repository escape coverage\n- add a documentation-only PR workflow and a daily/manual external-link workflow\n- repair two stale KFD-1 links found by the first external scan\n- document the deterministic versus network-dependent maintenance boundary\n\n## Verification\n\n- `./shifu docs:check` (180 Markdown files; 8/8 negative fixtures)\n- `./shifu docs:check:external` (942 links; 231 unique; 0 errors; one exact staged release-passport URL excluded)\n- `./shifu check:types`\n- `./shifu check`\n- `./shifu check:staged`\n- `actionlint .github/workflows/docs-check.yml .github/workflows/docs-external-links.yml`\n- clean detached-worktree simulation of the Docs Check install command and gate\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-12T14:28:57Z",
          "mergedAt": "2026-07-12T14:30:07Z",
          "additions": 1441,
          "deletions": 2,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 696,
          "url": "https://github.com/kungfu-systems/kungfu/pull/696",
          "title": "feat(shifu): manage Cargo and Conan cache bindings",
          "body": "## What changed\n\n- add KFD-1 cache profile bindings for Cargo crates.io source replacement and ConanCenter remotes\n- apply Cargo through a temporary wrapper with highest-priority config and Conan through a disposable CONAN_HOME\n- emit redacted application and cleanup evidence in cache receipts\n- initialize Conan default profiles for Shifu-managed source builds\n\n## Why\n\nKungfu builds need the Atlas-managed central Cargo and Conan caches without depending on or overwriting persistent host configuration. Buildchain remains limited to opaque profile reference and digest transport.\n\n## Validation\n\n- ./shifu check\n- 16 Shifu cache contract/runtime tests\n- Mac, Ubuntu, agent-120, and DARKHERO digest-bound dry-run and live Cargo/Conan cache smoke\n- persistent Cargo/Conan config hashes unchanged on all four hosts\n",
          "author": "dongkeren",
          "createdAt": "2026-07-12T14:31:55Z",
          "mergedAt": "2026-07-12T14:33:24Z",
          "additions": 592,
          "deletions": 28,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 697,
          "url": "https://github.com/kungfu-systems/kungfu/pull/697",
          "title": "feat(runtime): hydrate typed state across restart",
          "body": "## Summary\n- decode verified typed-state images into a staging `state_cache::bank` and atomically replace the target only after full validation\n- preserve the target bank on truncated, unknown-type, uid-mismatched, or malformed image data\n- add a two-process fixture: creator writes a qualified test KFDL cut and snapshot; verifier reopens both, bootstraps, and hydrates typed peer state\n\n## Boundary\nThis completes the process-independent hydration primitive, not the production coordinator cutover. The compatibility restore remains active until a verified production profile and authority wiring are available; journal wire-v1 and the mmap hot path are unchanged.\n\n## Validation\n- `./shifu build:core`\n- `./shifu test:projection-bootstrap`\n- `./shifu test:durable-ingest`\n- `./shifu test:state-service`\n- `./shifu test:durability-contract`\n- `./shifu test:runtime-errors`\n- `./shifu test:mmap`\n- `./shifu check`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-12T14:43:08Z",
          "mergedAt": "2026-07-12T14:43:54Z",
          "additions": 207,
          "deletions": 2,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 698,
          "url": "https://github.com/kungfu-systems/kungfu/pull/698",
          "title": "fix(runtime): make peer register-handshake timeout deterministic and thread-free",
          "body": "Register handshake timeout was rx::timeout + observe_on_new_thread (background thread, wall-clock, outside the single-threaded replayable model). Replaced with a wall-clock deadline checked from peer::on_active on the observer recv_timeout heartbeat - the one path alive when the coordinator is silent. Same 60s bound and signal_stop, no extra thread; the peer is not live during the handshake so the coordinator's journal time service cannot serve it. peer::timeout() documented as a post-live business timeout only. Verified via sibling compile_commands -fsyntax-only (compiles, no new warnings, clang-format clean) plus a standalone harness covering on_active's four branches.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T14:51:41Z",
          "mergedAt": "2026-07-12T14:51:47Z",
          "additions": 36,
          "deletions": 15,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 699,
          "url": "https://github.com/kungfu-systems/kungfu/pull/699",
          "title": "build(freeze): fail product builds missing the native host (ADR-0046 S3 follow-up)",
          "body": "Closes the ADR-0046 S3 productization gap where a product build could silently ship without the native host and fall back to the slow Python node path / the doctor stub (found in S3 Phase C).\n\nThe product core is always built for the node runtime, so the host must ship; a missing one is now a hard error in the **product** freeze, not a warning:\n- `product/scripts/dist.mjs` sets `KF_REQUIRE_NATIVE_HOST=1` on the product freeze call.\n- `run-freeze.js` `copyRuntimeNative` (POSIX): fatal if that flag is set and no `libkungfu_node_host.*` was staged.\n- `run-freeze.js` `copyPyBindingWin` (Windows): the `kungfu_node_host.dll` / `kungfu_embedding.dll` warnings become fatal under the flag (listing which is missing and why).\n\nDev (bare `pnpm run freeze`) leaves the flag unset and keeps warn-only — a dev assemble without a built host stays legitimate.\n\nVerified: gating logic (regex matches only host natives; fatal fires only for product-without-host, dev unchanged); recent assembled dists confirmed to contain `libkungfu_node_host.dylib`, so the guard does not break current node-runtime product builds.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T14:52:07Z",
          "mergedAt": "2026-07-12T14:52:42Z",
          "additions": 46,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 700,
          "url": "https://github.com/kungfu-systems/kungfu/pull/700",
          "title": "feat(gui): add Mission Control card query controls",
          "body": "## Summary\n- add query-driven sorting, filtering, hierarchy handling, and stable per-Mission saved views to Go cards\n- validate the versioned ViewSpec in TypeScript, native storage, and CLI import/update paths\n- make GUI refresh absorb Agent CLI saved-view revisions without restart\n\n## Validation\n- `./shifu check`\n- API tests: 9/9\n- work-dashboard tests: 9/9\n- static Atlas GUI fixture\n- `./shifu build`\n- `./shifu package` -> `20260712T145236Z-de66fa5b4`\n- real Atlas workspace dogfood: GUI filter/sort/reset/save; CLI revision 2 -> GUI auto-refresh; restore revision 3\n\n## Known baseline/environment failures\n- `./shifu verify`: 28/30; existing `mission_control.py` mypy error and Episode contention busy qualification failure\n- legacy live fixture reports `sync_root_mismatch`; the current static Atlas fixture passes\n\nCI is not a merge gate for this task per operator direction.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T14:58:27Z",
          "mergedAt": "2026-07-12T15:00:14Z",
          "additions": 1158,
          "deletions": 40,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 701,
          "url": "https://github.com/kungfu-systems/kungfu/pull/701",
          "title": "feat(runtime): inspect crash recovery evidence",
          "body": "## Summary\n- add explicit read-only KFDL recovery inspection and typed tail integrity\n- add deterministic DISCOVER -> VERIFY -> SELECT -> CLASSIFY -> REPORT outcomes\n- retain the checkpoint frontier and never mutate, repair, or promote unknown tail bytes\n\n## Validation\n- `./shifu check`\n- `./shifu test:crash-recovery`\n- `./shifu test:durable-ingest`\n- `./shifu test:projection-bootstrap`\n- `./shifu test:state-service`\n- `./shifu test:durability-contract`\n- `./shifu test:runtime-errors`\n- `./shifu test:mmap`\n\n## Scope\nThis is the first crash-recovery engine slice. Repair/quarantine, Episode folding, consistent export/restore, production qualification, and public recovery commands remain pending.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T15:02:00Z",
          "mergedAt": "2026-07-12T15:03:48Z",
          "additions": 546,
          "deletions": 3,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 703,
          "url": "https://github.com/kungfu-systems/kungfu/pull/703",
          "title": "ci(docs): enforce vocabulary prose contracts",
          "body": "Summary: make the machine-readable vocabulary registry authoritative for executable prose policy; narrow docs.contract.json to topology; generate Vale 3.14.2 styles; add required and advisory gates, negative fixtures, and documentation. Validation: shifu check, docs check, both Vale levels, and pinned Docker fallback passed locally. Goal: 2026-07-12-kungfu-vale-vocabulary-contract.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T15:10:17Z",
          "mergedAt": "2026-07-12T15:10:54Z",
          "additions": 808,
          "deletions": 74,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 704,
          "url": "https://github.com/kungfu-systems/kungfu/pull/704",
          "title": "refactor(runtime): extract shared journal-timer helpers in peer",
          "body": "Refactor only, behavior unchanged. peer's timer/time_interval/timeout each open-coded the same TimeRequest emission (5 copies), enable+arm+checkpoint prologue (3 copies), and Time-event due check. Extracted send_time_request/arm_timer/disarm_timer/timer_due so each operator reads as its own control flow. timer_due uses find instead of operator[] on timer_checkpoints_ (defensive: a real-rxcpp harness confirmed take_until terminates the interval stream before a disabled event reaches the due filter, so the old operator[] re-insert was not reachable; find hardens against future chain changes). Verified: sibling compile_commands -fsyntax-only compiles timer/time_interval + all helpers with no new warnings; clang-format clean.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T15:14:09Z",
          "mergedAt": "2026-07-12T15:14:14Z",
          "additions": 49,
          "deletions": 56,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 706,
          "url": "https://github.com/kungfu-systems/kungfu/pull/706",
          "title": "ci(docs): make publication contracts executable",
          "body": "Implements executable documentation examples, public reachability, Vale annotations and metrics, rule promotion evidence, a physically read-only lock-keyed docs toolchain, and immutable documentation supply-chain pins. Local evidence: 15 contract tests pass, 59-file Vale baseline is clean, and a cold run succeeded from a recursively read-only checkout.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T15:55:03Z",
          "mergedAt": "2026-07-12T15:55:08Z",
          "additions": 787,
          "deletions": 107,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 707,
          "url": "https://github.com/kungfu-systems/kungfu/pull/707",
          "title": "ci(docs): make publication contracts executable",
          "body": "Implements executable documentation and publication operations with local Mac validation.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T15:55:35Z",
          "mergedAt": "2026-07-12T15:55:40Z",
          "additions": 787,
          "deletions": 107,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 708,
          "url": "https://github.com/kungfu-systems/kungfu/pull/708",
          "title": "fix(docs): keep executable example source-only",
          "body": "The executable Shifu version example now forces the source-only script path. This removes native launcher compilation from the bounded docs example and fixes the GitHub-hosted docs gate timeout observed after the publication-operations merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T15:57:38Z",
          "mergedAt": "2026-07-12T15:57:49Z",
          "additions": 6,
          "deletions": 6,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 709,
          "url": "https://github.com/kungfu-systems/kungfu/pull/709",
          "title": "feat(kfx): define Profile Suite semantic contract",
          "body": "Implements the S0 decision gate for ADR-0069.\n\n- adds kungfu.profile-suite/v1 to the existing KFX contract authority\n- binds Suite packages to content-hashed Profile semantic closures\n- exposes shared Python and Node validation plus CLI schema discovery\n- retains Week/Day positive and negative fixtures in the Shifu shared gate\n- documents that lifecycle roots, activation, Mission Control migration, and release qualification remain staged\n\nValidation:\n- ./shifu test:kfx-profile-suite\n- ./shifu check\n\nGoal: 2026-07-12-kungfu-agent-first-profile-suite-runtime",
          "author": "dongkeren",
          "createdAt": "2026-07-12T16:20:19Z",
          "mergedAt": "2026-07-12T16:22:06Z",
          "additions": 968,
          "deletions": 11,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 710,
          "url": "https://github.com/kungfu-systems/kungfu/pull/710",
          "title": "docs(metadata): enforce typed document frontmatter",
          "body": "## Summary\n- define versioned path-based document metadata profiles\n- migrate public documentation and all Core/Shifu ADRs\n- make ADR body and registry status checked projections\n- preserve issue-template and Skill frontmatter as independent schemas\n\n## Validation\n- ./shifu check\n- ./shifu docs:check\n- ./shifu docs:prose:required\n- ./shifu check:types",
          "author": "dongkeren",
          "createdAt": "2026-07-12T16:46:33Z",
          "mergedAt": "2026-07-12T16:46:38Z",
          "additions": 2002,
          "deletions": 208,
          "changedFiles": 147
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 711,
          "url": "https://github.com/kungfu-systems/kungfu/pull/711",
          "title": "feat(kfx): add Profile lifecycle runtime",
          "body": "## Summary\n- compute a canonical Profile Suite root from the exact KFX contract, verified facet bytes, and explicit member roots\n- record typed Installed, Qualified, Activated, Superseded, RolledBack, and Removed facts through ActionEnvelope + Episode\n- expose stale-safe inspect/plan/apply/receipt/history behavior through shared C++, Python, Node, capability, and CLI surfaces\n- document the S1 boundary: Core closure/runtime qualification only; Agent SDK, GUI, portability, and Mission migration remain staged\n\n## Validation\n- `./shifu test:profile-lifecycle`\n- `./shifu check`\n- `./shifu build:core`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-12T17:03:32Z",
          "mergedAt": "2026-07-12T17:04:23Z",
          "additions": 2136,
          "deletions": 19,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 712,
          "url": "https://github.com/kungfu-systems/kungfu/pull/712",
          "title": "feat(kfx): add Agent Profile SDK",
          "body": "## Summary\n\n- ship an installed, self-describing Agent Profile SDK and `kungfu profile` CLI over the Core-owned Profile lifecycle\n- add deterministic scaffold, exact package-closure resolution, decision cards, semantic diff, and declarative action plan/invoke receipts\n- expose the versioned SDK contract through the Agent pack and prove custom KFX member builds do not rebuild Kungfu\n\n## Authority boundaries\n\n- Profile lifecycle remains owned by the S1 Core service\n- KFX schema and package bytes remain the source authority\n- identity, permission, evidence, authority, and destructive migration choices require external explicit decisions\n- S2 does not claim GUI Profile Manager, Mission Control migration, generic domain bindings, or Week/Day qualification\n\n## Validation\n\n- `./shifu build`\n- `./shifu kfd:buildchain`\n- `./shifu test:agent-profile-sdk` — 11 passed\n- `./shifu test:kfx-profile-suite` — Node 8 passed; Python 8 passed\n- `./shifu check`\n- frozen `kungfu profile capabilities --json`\n- frozen `kungfu agent verify --json` — no missing/hidden API surfaces\n\n`./shifu verify` passed 28/30 checks. The two failures are outside this diff: existing mypy errors in `work/store.py` and `atlas/mission_control.py`, plus the Episode qualification smoke reporting all scenarios busy. The built/frozen artifact, hashes, Agent pack, runtime smoke, and new Profile interfaces passed. CI is currently not used as a wait gate for this change.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T17:49:54Z",
          "mergedAt": "2026-07-12T17:50:14Z",
          "additions": 3390,
          "deletions": 63,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 713,
          "url": "https://github.com/kungfu-systems/kungfu/pull/713",
          "title": "feat(profile): add generic composition manager",
          "body": "## Summary\n- compose exact-root Profile fact surfaces, claims, assessment policies, and generic views through the existing ADR-0048/ADR-0052 authorities\n- add the public TypeScript Profile capability plus table/timeline/diff/causal-graph/attention renderer\n- turn the system KFX manager into an asynchronous Profile Manager with lifecycle health, roots, permissions, qualification, diagnostics, views, and exact decision/apply preview\n- publish Agent discovery and regenerated KFD-3 evidence for the same CLI/API/GUI path\n\n## Authority boundaries\n- no new fact, query, assessment, lifecycle, journal, trust, or GUI registry authority\n- Profile activation remains distinct from GUI focus\n- lifecycle mutation re-plans against the reviewed plan id and fails closed on drift\n- removal does not delete facts\n\n## Validation\n- `./shifu test:agent-profile-sdk` (22 passed)\n- API capability tests (12 passed)\n- `./shifu check`\n- `./shifu product gui build`\n- frozen app CLI `profile capabilities --json` and `profile manager --json` smoke\n- frozen first-party KFX pin and Profile Manager bundle inspection\n\nCI is currently known-broken; this PR is qualified from local gates and should not wait on CI.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T18:39:58Z",
          "mergedAt": "2026-07-12T18:40:28Z",
          "additions": 2752,
          "deletions": 68,
          "changedFiles": 37
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 705,
          "url": "https://github.com/kungfu-systems/kungfu/pull/705",
          "title": "feat(runtime): retain degraded recovery evidence",
          "body": "## Summary\n- add deterministic degraded-tail quarantine previews bound to exact stream evidence\n- publish byte-verified retained-evidence packages and typed idempotent maintenance receipts\n- reject stale previews and active ownership without changing source KFDL bytes\n- move the ownership lease default constructor out of line to fix the existing GCC 14 incomplete-pimpl build failure\n\n## Validation\n- `./shifu build:core`\n- `./shifu test:crash-recovery`\n- `./shifu test:durable-ingest`\n- `./shifu test:projection-bootstrap`\n- `./shifu test:state-service`\n- `./shifu check`\n\n## Scope\nThe quarantine package is test-only and is not a qualified power-loss receipt. This slice does not truncate or replace the authoritative stream; destructive repair, Episode folding, export/restore, and qualification remain pending.\n\n## CI follow-up\nPR #701 and the immediately preceding PR #699 both exposed the same Linux GCC 14 failure in `ownership::lease` while compiling `assemble.cpp`. This PR includes the minimal out-of-line pimpl constructor fix and relies on the Linux matrix to verify it.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T15:29:05Z",
          "mergedAt": "2026-07-12T19:12:17Z",
          "additions": 402,
          "deletions": 4,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 714,
          "url": "https://github.com/kungfu-systems/kungfu/pull/714",
          "title": "feat(profile): migrate Mission Control to public suite runtime",
          "body": "## Summary\n- close public Profile gaps for resolved query families, dynamic claim instances, explicit contract materialization, and verified independent Episodes\n- migrate Mission Control query/assessment/dashboard paths to exact Suite/catalog/member roots and public receipts\n- add Mission bundle v2 semantic closure with no implicit activation or permission grants\n\n## Validation\n- ./shifu test:agent-profile-sdk (29 passed)\n- Mission-focused Atlas tests (7 passed)\n- ./shifu check\n- Work Dashboard tests (9 passed)\n- ./shifu product gui build\n- frozen app CLI Profile discovery smoke\n\nCI is currently known-broken; local Shifu evidence is the acceptance basis for this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T20:01:42Z",
          "mergedAt": "2026-07-12T20:02:38Z",
          "additions": 2569,
          "deletions": 249,
          "changedFiles": 41
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 715,
          "url": "https://github.com/kungfu-systems/kungfu/pull/715",
          "title": "feat(profile): qualify installed profile authoring",
          "body": "## Summary\n- package the Agent Profile SDK and native esbuild runtime in the desktop product\n- add exact-root full/thin Profile source export/import without lifecycle mutation\n- expose independent observation evidence to Profile assessment planning\n- harden installed source discovery against unreadable unrelated siblings\n\n## Verification\n- `./shifu test:agent-profile-sdk` (31 passed)\n- `./shifu check`\n- `./shifu product gui build`\n- frozen product CLI built and qualified an external Week/Day/Action Suite, proved Mission coexistence, lifecycle rollback/removal/reinstall, KFD-1 query, KFD-2 assessment, and full/thin portability",
          "author": "dongkeren",
          "createdAt": "2026-07-12T20:51:47Z",
          "mergedAt": "2026-07-12T20:52:01Z",
          "additions": 550,
          "deletions": 4,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 716,
          "url": "https://github.com/kungfu-systems/kungfu/pull/716",
          "title": "docs(profile): publish agent-first profile guidance",
          "body": "## Summary\n- publish the installed agent-first Profile authoring workflow\n- document Profile composition, portability, and Mission Control coexistence\n- state the qualified macOS ARM64 pre-release boundary and remaining limits\n\n## Validation\n- ./shifu check\n- git diff --check\n\nCI is currently known-broken and is not a merge gate for this authorized release closeout.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T21:05:56Z",
          "mergedAt": "2026-07-12T21:06:24Z",
          "additions": 149,
          "deletions": 26,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 717,
          "url": "https://github.com/kungfu-systems/kungfu/pull/717",
          "title": "docs(adr): ADR-0070 layer peer communication primitives, propose renaming Band to Outlet",
          "body": "ADR-0070 (proposed). Records that the live communication primitives (channel, band, read/write requests, timer) answer a general 'how do peers communicate' question - they are the communication skeleton carried into v4, not trading logic; ADR-0057 made the terminology domain-neutral but the structure is still trading-shaped. Phase 1 (proposed now, docs-first): rename Band to Outlet, band_writers_ to off_thread_writers_, document the four layers. Phase 2/3 (decouple named-output from off-thread writing; unify establish-channel) are deferred and trigger-gated on the first post-trading peer consumer to avoid speculative abstraction. Docs gate passes locally.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T22:15:15Z",
          "mergedAt": "2026-07-12T22:15:20Z",
          "additions": 178,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 721,
          "url": "https://github.com/kungfu-systems/kungfu/pull/721",
          "title": "fix(profile): add Mission Control setup flow",
          "body": "## Summary\n- expose installed Profile source discovery through the public TypeScript capability\n- turn the Work Dashboard missing-Profile dead end into explicit install, qualify, and activate decision gates\n- show exact plan, authority, question, and effects before each authorized lifecycle mutation\n\n## Validation\n- ./shifu check\n- @kungfu-tech/api tests: 12 passed\n- work-dashboard tests: 12 passed\n- disposable runtime: install -> qualify -> activate -> active\n- ./shifu product gui build\n\nThe current known CI issue is not treated as a merge gate for this dogfood repair.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T22:56:09Z",
          "mergedAt": "2026-07-12T22:56:23Z",
          "additions": 269,
          "deletions": 9,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 723,
          "url": "https://github.com/kungfu-systems/kungfu/pull/723",
          "title": "refactor(runtime): rename Band to Outlet, band_writers_ to off_thread_writers_ (ADR-0070 phase 1)",
          "body": "ADR-0070 phase 1. Rename the Band communication primitive to Outlet (a peer's named output stream, not trading-specific) across schema type (id unchanged), registry, reactor/peer/coordinator, node binding, python stub, GUI keywords. Rename band_writers_/band_mtx_/get_band_writer to off_thread_writers_/off_thread_mtx_/get_off_thread_writer to name the pool by thread-affinity role. Document the outlet layer in concepts.md. No behavior change (type ids, wire layout, control flow unchanged); verified: reactor/peer/coordinator -fsyntax-only compile clean, docs gate + clang-format pass. ADR-0070 marked accepted; phases 2/3 deferred.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T22:59:43Z",
          "mergedAt": "2026-07-12T22:59:48Z",
          "additions": 139,
          "deletions": 136,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 725,
          "url": "https://github.com/kungfu-systems/kungfu/pull/725",
          "title": "docs(metadata): separate public metadata and bind ADR evidence",
          "body": "## Summary\\n\\n- move public entry and guide metadata to a checked sidecar registry\\n- enforce one metadata authority and flat allowlisted fields\\n- bind high-confidence ADR implementation history to commits, pull requests, closure, and qualification evidence\\n\\n## Validation\\n\\n- ./shifu docs:check\\n- ./shifu docs:prose:required\\n- ./shifu check:types\\n- ./shifu check",
          "author": "dongkeren",
          "createdAt": "2026-07-12T23:11:54Z",
          "mergedAt": "2026-07-12T23:11:59Z",
          "additions": 1282,
          "deletions": 726,
          "changedFiles": 93
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 726,
          "url": "https://github.com/kungfu-systems/kungfu/pull/726",
          "title": "docs(adr): bind ADR-0070 phase-one evidence",
          "body": "## Summary\\n\\n- bind ADR-0070 phase-one implementation to commit c42600c3d and PR 723\\n- link the live-runtime terminology gate as qualification evidence\\n- satisfy the merged ADR evidence contract without claiming full ADR closure\\n\\n## Validation\\n\\n- ./shifu docs:check\\n- ./shifu docs:prose:required",
          "author": "dongkeren",
          "createdAt": "2026-07-12T23:15:49Z",
          "mergedAt": "2026-07-12T23:15:55Z",
          "additions": 3,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 727,
          "url": "https://github.com/kungfu-systems/kungfu/pull/727",
          "title": "feat(shifu): auto-apply projected cache profiles",
          "body": "## Summary\n\n- auto-apply projected Shifu cache profiles for ordinary native and script-fallback tasks\n- fail closed on partial projection and prevent recursive application with `SHIFU_CACHE_ACTIVE`\n- preserve public-clone and explicit Buildchain cache lifecycle behavior\n\n## Validation\n\n- `./shifu check`\n- real projected-profile dogfood on macOS (single native build, cache contract passed)\n- POSIX fallback tests plus Rust launcher unit tests",
          "author": "dongkeren",
          "createdAt": "2026-07-12T23:16:17Z",
          "mergedAt": "2026-07-12T23:18:20Z",
          "additions": 366,
          "deletions": 5,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 724,
          "url": "https://github.com/kungfu-systems/kungfu/pull/724",
          "title": "docs(adr): ADR-0071 CLI language split and membrane diagnostic surface",
          "body": "Records the decision on which kungfu CLI commands fit the Rust trunk vs Python, from functional/technical fit rather than clap-vs-click.\n\n**Deciding axis**: where the work already lives and what the embedding membrane reaches.\n- **Bucket A (Rust fit)** — substrate diagnostics/maintenance (`storage fsck/verify/gc/compact`, `schema compile`): the C++ logic exists but is only reachable via the fat pybind binding today. **Grow the membrane's read-only diagnostic C ABI**, then thin Rust CLIs — extends the `doctor` pattern, no domain-logic rewrite, gains the must-work-when-broken property.\n- **Bucket B (measure first)** — `rewind verify` / `work` folds run a CPython per-frame decode; the membrane already hands raw frames to Rust. Migrate only if measurement shows the loop is felt.\n- **Bucket C (stays Python)** — product/UI/extension/orchestration/provider surfaces + tiny high-churn config/contract/workspace.\n\nStrategic lever: the membrane is the ceiling; the high-value move is growing its narrow, versioned read-only surface, not per-command rewrites. Implementation is tracked as a follow-up (Atlas go card).\n\nDocs gate: run-docs-check passed (0 errors, metadata contract + links/anchors). `decision_status: accepted`, `review_state: self-reviewed` (open to maintainer revision).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T23:09:56Z",
          "mergedAt": "2026-07-12T23:23:49Z",
          "additions": 171,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 718,
          "url": "https://github.com/kungfu-systems/kungfu/pull/718",
          "title": "ci(core): harden durable toolchain qualification",
          "body": "## Summary\n\n- run the hosted GCC 14 / Apple Clang / MSVC membrane matrix when the durable-ingest interface or implementation changes\n- retain the existing ownership PImpl coverage on the current paths\n- give Cargo registry traffic a 120-second HTTP timeout and five retries so transient rsproxy timeouts do not mask compiler results\n\n## Validation\n\n- `./shifu check`\n- prior runs #29196153424 and #29197363539 identified the exact GCC 14 / MSVC regressions now present in current dev, plus repeated 30-second Cargo registry timeouts on Windows\n",
          "author": "dongkeren",
          "createdAt": "2026-07-12T22:46:19Z",
          "mergedAt": "2026-07-12T23:26:25Z",
          "additions": 4,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 728,
          "url": "https://github.com/kungfu-systems/kungfu/pull/728",
          "title": "fix(gui): clarify Mission Control setup status",
          "body": "Merge fix/mission-control-setup-status-ux into dev/v4/v4.0 (kungfu-systems zone dual-account PR flow).",
          "author": "dongkeren",
          "createdAt": "2026-07-12T23:27:31Z",
          "mergedAt": "2026-07-12T23:27:37Z",
          "additions": 262,
          "deletions": 23,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 730,
          "url": "https://github.com/kungfu-systems/kungfu/pull/730",
          "title": "docs(adr): ADR-0072 layer frame identity - journal-local frame_uid, ledger-global stream_position",
          "body": "ADR-0072 (proposed). Frame identity is layered: frame_uid stays journal-local (in-journal lookup, causal links, checksum) and does not become a permanent global id; permanent ledger-global uniqueness is the Episode content root plus the structural, monotonic stream_position (stream_id, container_epoch, sequence, already enforced contiguous by the durable tier). The container stays a short-lived substrate (ADR-0062 unchanged); permanence moves up to the Episode/ledger layer. Phase 1 (pre-stable window): restructure frame_uid to fix the deterministic page-8-bit wrap (full page_id + frame_nb, drop probabilistic salt and redundant source-xor-dest). Phase 2: authoritative stream_position sequence assignment. Rejects widening frame_uid to a global id (still probabilistic, duplicates Episode root). Relates ADR-0062/0053/0043/0068. Docs gate passes.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T23:55:05Z",
          "mergedAt": "2026-07-12T23:55:10Z",
          "additions": 175,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 731,
          "url": "https://github.com/kungfu-systems/kungfu/pull/731",
          "title": "feat(release): enforce ADR promotion admissibility",
          "body": "## Summary\n\nMake ADR implementation truth a release-bearing Buildchain contract instead of a documentation-only claim.\n\n## Changes\n\n- add a pure-Node ADR release contract and fixture-driven gate;\n- require feature PRs to declare `stage-ready` or `implemented` intent while retaining an explicit ADR-neutral path for non-feature changes;\n- settle ADR progress after alpha Buildchain qualification;\n- block stable promotion on every unaccounted accepted ADR, with exact-release admin waivers as the only exception;\n- retain the machine report with release qualification evidence;\n- document the management intent in ADR-0072, the release design, contributor guidance, and metadata contract.\n\n## Verification\n\n- `./shifu check`\n- `./shifu docs:check`\n- `actionlint -config-file .github/actionlint.yaml .github/workflows/adr-release-gate.yml .github/workflows/build.yml .github/workflows/docs-check.yml`\n- real dev-event fixture: `implemented`, zero findings\n- real current-repository stable fixture: fails closed with every unaccounted accepted ADR listed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0073\"],\n  \"summary\": \"Implement the three-stage ADR release admissibility contract\",\n  \"verification\": [\"./shifu check\", \"./shifu docs:check\", \"actionlint\"]\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] none of the above\n\nThe change strengthens release admission. It does not alter package publishing credentials or create a bypass. Stable waivers require an exact release, exact blocking conditions, an allowlisted administrator, the current release PR, expiry, and dedicated CODEOWNER review.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-12T23:59:35Z",
          "mergedAt": "2026-07-13T00:07:26Z",
          "additions": 1406,
          "deletions": 12,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 732,
          "url": "https://github.com/kungfu-systems/kungfu/pull/732",
          "title": "fix(adr): support PR-stable closure evidence",
          "body": "## Summary\n\nMake ADR closure evidence stable under Kungfu's rebase/squash-only PR merge policy.\n\n## Changes\n\n- allow implemented ADRs to use either reachable `closure_commit` or canonical `closure_pr` evidence;\n- validate `closure_pr` against the canonical kungfu-systems repository URL shape;\n- add positive and negative metadata fixtures;\n- rebind ADR-0073 to merged PR #731 so dev metadata is valid after GitHub rewrites its commits.\n\n## Verification\n\n- `./shifu check`\n- `./shifu docs:check`\n- 43 documentation/metadata fixtures pass, including canonical and foreign closure PR cases\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0073\"],\n  \"summary\": \"Close the rebase-merge evidence loop with stable PR authority\",\n  \"verification\": [\"./shifu check\", \"./shifu docs:check\"]\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis tightens evidence compatibility with repository merge policy. It does not accept arbitrary URLs or weaken semantic closure review.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T00:10:49Z",
          "mergedAt": "2026-07-13T00:11:37Z",
          "additions": 68,
          "deletions": 15,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 737,
          "url": "https://github.com/kungfu-systems/kungfu/pull/737",
          "title": "feat(release): add promotion contract rehearsal",
          "body": "## Summary\n\nAdd a side-effect-free alpha/stable promotion rehearsal and make the Buildchain promotion job depend on its actual-event preflight.\n\n## Changes\n\n- validate alpha/stable admission fixtures and current stable readiness\n- verify immutable Buildchain locks, release evidence inputs, channel routing, and workflow dependencies\n- run the rehearsal after Buildchain config validation on GitHub-hosted runners\n- block the future reusable promotion job until the same rehearsal accepts the merged promotion event\n\n## Verification\n\n- `./shifu release:promotion:rehearse -- --report /tmp/kungfu-release-promotion-rehearsal.json`\n- `node --test scripts/adr-release-gate.test.mjs scripts/release-promotion-rehearsal.test.mjs`\n- `./shifu docs:check:readonly`\n- `./shifu check`\n- `actionlint` on the four affected workflow contracts\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0073\"],\n  \"summary\": \"Complete side-effect-free alpha/stable promotion rehearsal and Buildchain consumer wiring\",\n  \"verification\": [\"release promotion rehearsal fixtures\", \"actual alpha/stable event tests\", \"full Shifu check\", \"workflow lint\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe preflight has read-only contents permission, receives no promotion secrets, and performs no version, tag, push, publish, or release mutation.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T00:39:36Z",
          "mergedAt": "2026-07-13T00:43:03Z",
          "additions": 986,
          "deletions": 2,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 739,
          "url": "https://github.com/kungfu-systems/kungfu/pull/739",
          "title": "feat(shifu): add cache diagnostics and local profiles",
          "body": "## Summary\n\nAdd schema-governed developer operations for Shifu cache profiles while preserving Atlas as the inventory controller and Buildchain as the process owner. Diagnostics separate configured, resolved, reachable, effective, and cache-hit evidence; resolution never claims a provider hit.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add local-only `shifu cache status` and bounded `shifu cache doctor [--probe]`\n- add dry-run-first `shifu cache use/unset`, limited to a Shifu-owned delimited block with backup/rollback evidence\n- refuse local overwrite of Atlas controller-managed projections\n- add redacted diagnostic/config-plan schemas and contract discovery\n- keep native `shifu doctor --json` compiler cache compatibility and add a separate profile-cache summary\n- document the Atlas/Shifu/Buildchain ownership boundary\n\n## Verification\n\n- `./shifu check` on current `origin/dev/v4/v4.0` (changed-scope gate passed)\n- Shifu cache/runtime suite: 27 passed\n- Rust workspace format, clippy with `-D warnings`, and tests passed\n- Markdown lint, local-link, schema-authority, and tooling type checks passed\n- Mac dogfood: controller projection resolved as `workhub.development`; six selected endpoints reachable with bounded HEAD probes; hit evidence remained `unproven`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Additive developer operations implement the accepted independent SHIFU-ADR-0001 ownership boundary without changing a Core architecture decision or release channel\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\nNo credentials, private inventory, hosted-service identity, package publishing, release evidence, or deployment surface is added. Public fixtures remain private-address free.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T00:53:59Z",
          "mergedAt": "2026-07-13T01:06:53Z",
          "additions": 1018,
          "deletions": 10,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 740,
          "url": "https://github.com/kungfu-systems/kungfu/pull/740",
          "title": "fix(journal): restructure frame_uid to journal-local deterministic id (ADR-0072 P1)",
          "body": "## Summary\n\nADR-0072 Phase 1 — restructure `writer::current_frame_uid()` to a structural,\ncollision-free encoding within one journal: `(page_id << 32) | (in-page frame_nb)`.\nBoth components are persistently monotonic on disk, so a frame's id is\ndeterministically unique within a journal.\n\n## Changes\n\n- Encode `current_frame_uid` as `(page_id << 32) | (frame_nb & 0xFFFFFFFF)`; drop\n  the probabilistic `nano_hashed(writer_start)` salt and the redundant\n  `(source xor dest)` high bits (those fields are already explicit in the header).\n- Rename the `frame_header` field `frame_uid` -> `journal_frame_uid` to version the\n  wire semantics (ADR-0062 rule 4). This advances `journal_format_epoch`\n  (0x869f7bb1 -> 0xe3b24c8d), so old-epoch pages are refused by `page::load`. The\n  `frame_uid()` / `set_frame_uid()` accessor methods are unchanged.\n- The frame checksum and Episode content root read the new value verbatim.\n- `frame_uid` stays journal-local; cross-journal permanent identity remains the\n  Episode content root + `stream_position` layer (ADR-0072 layer 2).\n\n## Verification\n\n- Full `core` build green; 9/9 native ctests pass (mmap, content-hash, durability\n  contract, durable-ingest, crash-recovery, ...).\n- Counterexample harness: the old encoding produced 352 collisions over 300 pages\n  (page 1 collided with page 257 — the 4 GB / 256-page wrap); the new encoding is\n  collision-free (2400/2400 distinct).\n- `journal_format_epoch` confirmed to advance (old-epoch pages refused).\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0072\"],\n  \"summary\": \"ADR-0072 Phase 1: frame_uid becomes deterministically journal-local ((page_id<<32)|frame_nb); journal_format_epoch advances via the frame_header field rename. Phase 2 (ledger-global identity) remains pending.\",\n  \"verification\": [\"Full core build green + 9/9 native ctests pass (mmap/content-hash/durability/durable-ingest/crash-recovery)\", \"Counterexample harness: old encoding 352 collisions over 300 pages, new encoding collision-free\", \"journal_format_epoch advance confirmed\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-13T01:39:52Z",
          "mergedAt": "2026-07-13T02:01:52Z",
          "additions": 50,
          "deletions": 30,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 735,
          "url": "https://github.com/kungfu-systems/kungfu/pull/735",
          "title": "feat(core): grow embedding membrane v2 with read-only storage fsck",
          "body": "## Summary\n\nGrow the embedding membrane to a versioned ABI v2 that appends a read-only\nsubstrate-diagnostic surface after a byte-identical v1 prefix, and ship a Rust\n`kungfu fsck` over it — `doctor`'s sibling. The first diagnostic entry,\n`storage_fsck`, bridges to the native C++ `storage_service::fsck` and returns\nthe report as a JSON blob plus an `ok`/`degraded` verdict; `report_release`\nfrees the owned buffer. No domain logic is rewritten and CPython is never\nbooted, so the diagnostic survives a broken Python runtime. This delivers the\nADR-0071 Bucket A lever (grow the membrane, don't rewrite commands).\n\n## Changes\n\n- `embedding.h` / `embedding.cpp`: `kf_embedding_api_v2` table (v1 prefix +\n  `storage_fsck` + `report_release`), `KF_EMBEDDING_CAP_STORAGE_DIAGNOSTICS`,\n  request/report structs; `kungfu_embedding_get_api` dispatches v1/v2 by\n  `requested_version`, so v1 callers are unchanged. Windows single-export DLL is\n  untouched — the new functions stay anonymous-namespace statics in the table.\n- `crates/kungfu-embedding`: mirrors the v2 table, negotiates v2-first with a v1\n  fallback, adds an RAII `FsckReport`; compile-time layout guards pin the new\n  struct sizes.\n- `crates/trunk`: a top-level `fsck` command behind the `embedding` feature with\n  a graceful coreless fallback.\n- `slices/shared-embedding-membrane/host.cpp`: the consumer spike now treats\n  v2 as supported (unsupported-version probe uses `ABI_V2 + 1`) and additionally\n  asserts v2 negotiation + the storage-diagnostics capability.\n- `ADR-0071`: `implementation_status` → `partial`; Follow-up records the Bucket A\n  stage delivered and what remains.\n\n## Verification\n\n- `check (macos-14, ubuntu-22.04, windows-2022)`: core build + tests on all three\n  platforms.\n- `Embedding membrane spikes`: exercise v1 and v2 negotiation across POSIX and\n  Windows.\n- `cargo test` / `cargo clippy` for `kungfu-embedding` and `kungfu-trunk` (default\n  and `--features embedding`).\n- Manual macOS `kungfu fsck` run: healthy store `ok=true`/exit 0; degraded store\n  (corrupt projections) warn/exit 0; `--source <missing>` `ok=false`/exit 1;\n  coreless build degrades gracefully.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0071\"],\n  \"summary\": \"Grow the embedding membrane to ABI v2 with a read-only storage fsck diagnostic surface and ship a Rust kungfu fsck consumer over it (ADR-0071 Bucket A lever).\",\n  \"verification\": [\"check (macos-14, ubuntu-22.04, windows-2022) build and tests\", \"Embedding membrane spikes exercise v1 and v2 negotiation across POSIX and Windows\", \"cargo test and clippy for kungfu-embedding and kungfu-trunk in both feature configs\", \"manual macOS fsck run: healthy=ok/exit0, degraded=warn/exit0, source-missing=exit1, coreless=graceful\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T00:30:58Z",
          "mergedAt": "2026-07-13T02:04:49Z",
          "additions": 769,
          "deletions": 22,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 741,
          "url": "https://github.com/kungfu-systems/kungfu/pull/741",
          "title": "docs(adr): unify architecture decision authority",
          "body": "Unify Core and Shifu ADRs under one canonical `docs/adr/` authority while retaining independent namespaces, typed legacy redirects, and equal machine gates. Add deterministic lifecycle, supersession, evidence-debt, and stable-readiness auditing, recorded by ADR-0074.\n\nValidation:\n- `./shifu check`\n- `./shifu docs:check`\n- `./shifu docs:prose:required`\n- `./shifu adr:audit -- --release stable` fails closed with the current 50 blockers\n- `./shifu adr:audit -- --strict` fails closed with the current explicit governance debt\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"implemented\",\"adrs\":[\"ADR-0073\",\"ADR-0074\"],\"summary\":\"Unify all architecture decisions under one release-bearing authority and add complete deterministic auditing.\",\"verification\":[\"./shifu check\",\"./shifu docs:check\",\"./shifu docs:prose:required\"]}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-13T01:51:04Z",
          "mergedAt": "2026-07-13T02:07:22Z",
          "additions": 15081,
          "deletions": 12984,
          "changedFiles": 212
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 742,
          "url": "https://github.com/kungfu-systems/kungfu/pull/742",
          "title": "chore(node): drop dead MakeInstructionUID helper",
          "body": "## Summary\n\nRemove the dead `MakeInstructionUID` helper (and its `ID_TRANC` / `PAGE_ID_MASK`\nconstants) from the node watcher binding.\n\n## Changes\n\n- `MakeInstructionUID` had no callers anywhere in the repo. It was a trading-era\n  helper that packed a `frame_uid`'s low 32 bits into an instruction id.\n- After the ADR-0072 Phase 1 `frame_uid` restructure, those low bits no longer\n  carry the page id, so the helper was both unused and semantically stale.\n- `ID_TRANC` and `PAGE_ID_MASK` fed only this helper and are removed with it.\n  `TRANSFER_STATIC_DATA_LIMIT` is unrelated and kept.\n\n## Verification\n\n- Full `core` build green (node binding compiles without the removed symbols).\n- Repo-wide grep confirms zero remaining references to `MakeInstructionUID`,\n  `ID_TRANC`, or `PAGE_ID_MASK`.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Removes dead, unreferenced trading-era code (MakeInstructionUID + two constants); no architecture contract change and no ADR file touched.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-13T02:38:49Z",
          "mergedAt": "2026-07-13T02:40:03Z",
          "additions": 0,
          "deletions": 8,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 743,
          "url": "https://github.com/kungfu-systems/kungfu/pull/743",
          "title": "feat(shifu): make local promotion ancestry-aware",
          "body": "## Summary\n\nUnify Shifu binary self-update and Kungfu product builds/promote around one provenance-aware local artifact contract.\n\nDefault promotion now follows Git history instead of filesystem recency: same or one unique descendant is automatic, while ancestor, divergent, unknown, ambiguous, rollback-only, and invalid artifacts fail closed or require explicit review.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add SHIFU-ADR-0002 plus catalog and redacted promotion-receipt schemas\n- add compact, --no-truncate, --verbose, and --json inventories\n- preserve identifiable feature branch names with middle truncation\n- record branch, canonical repository, worktree, build path, digest, relation, and lifecycle state\n- retire only proven ancestor build slots after successful descendant promotion\n- retain bounded rollback-only Shifu generations outside the candidate pool\n- expose the exact contract through shifu artifacts contract/schema/receipt-schema\n- make Git fixture tests independent of caller hook and repository environment\n\n## Verification\n\n- ./shifu check\n- ./shifu docs:check\n- cargo test --workspace\n- AJV 2020 validation of self-update and builds JSON output\n- isolated XDG fixture: 8c9001c90 is ancestor and 5d3613fc0 is diverged; default promote exits 1\n- isolated linear fixture: unique descendant promotes, writes receipt, and retires only its ancestor\n- isolated self-update fixture: update and rollback both write receipts and preserve rollback-only generations\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0002\"],\n  \"summary\": \"Deliver the shared local artifact catalog and fail-closed ancestry-aware promotion substrate.\",\n  \"verification\": [\"./shifu check\", \"./shifu docs:check\", \"cargo test --workspace\", \"isolated promotion and rollback fixtures\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects only local development artifact provenance and promotion. Receipts omit local paths; full paths remain local diagnostic output.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T02:50:13Z",
          "mergedAt": "2026-07-13T02:53:12Z",
          "additions": 1585,
          "deletions": 111,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 744,
          "url": "https://github.com/kungfu-systems/kungfu/pull/744",
          "title": "feat(profile): qualify user-defined KFD-3 collaboration",
          "body": "## Summary\n\nCompletes the Profile-level KFD-3 qualification path across Agent CLI and typed Human API. A conforming user-defined Profile can now earn, export, import, and independently verify a content-bound qualification receipt and witness. The same shared intent protocol drives inspect, advise, preview, authorize, execute, receipt, and verify. Unsupported custom execution surfaces fail closed.\n\nAlso proves an independent Week/Day Profile through both clients, verifies upgrade and rollback invalidation, and repairs Shifu directory-build registration so the exact Product can be promoted without a DMG.\n\n## Verification\n\n- ./shifu test:kfx-profile-suite\n- ./shifu --filter @kungfu-tech/api run test:query\n- ./shifu test:profile-kfd3-qualification\n- ./shifu docs:check\n- ./shifu kfd:buildchain:check\n- cargo test --workspace\n- staged repository gate\n- ./shifu dist:dir\n- shifu build registration and promote of clean 746bfafb0\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0075\"],\n  \"summary\": \"Qualify conforming user-defined Profiles for shared Human and Agent KFD-3 collaboration\",\n  \"verification\": [\"independent Week Day dual-client proof\", \"portable receipt and witness verification\", \"upgrade and rollback invalidation\", \"exact Product directory build and promote\"]\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n\nNo public release channel is promoted by this PR. The exact local Product directory build was promoted for dogfood.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T02:56:25Z",
          "mergedAt": "2026-07-13T03:06:06Z",
          "additions": 3092,
          "deletions": 113,
          "changedFiles": 45
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 745,
          "url": "https://github.com/kungfu-systems/kungfu/pull/745",
          "title": "docs: establish canonical directory hierarchy",
          "body": "## Summary\n\nEstablish a canonical public documentation hierarchy organized by maintenance authority, while preserving the former flat paths as typed compatibility redirects.\n\n## Changes\n\n- move 46 canonical documents into seven responsibility directories\n- add section indexes and update every repository, metadata, KFD, and publication reference\n- add executable hierarchy and redirect contracts with negative fixtures\n- record ADR-0076 as accepted and implemented\n\n## Verification\n\n- ./shifu docs:check\n- ./shifu docs:prose:required\n- ./shifu check\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0076\"],\n  \"summary\": \"Canonical hierarchy, compatibility facade, and deterministic placement gates are implemented\",\n  \"verification\": [\"./shifu docs:check\", \"./shifu docs:prose:required\", \"./shifu check\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T03:03:03Z",
          "mergedAt": "2026-07-13T04:04:31Z",
          "additions": 12559,
          "deletions": 11236,
          "changedFiles": 178
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1144,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1144",
          "title": "feat(check): add source lifecycle mode",
          "body": "## Summary\n\n- add an opt-in `mode: source` to the reusable check workflow\n- run only `lifecycle.install` and `lifecycle.check` on GitHub-hosted Linux\n- preserve the default `install + verify` behavior and stable `check` job name\n- add a fixture regression proving build and verify are not executed\n\nCloses #1143\n\n## Validation\n\n- workflow structure check\n- inventory check\n- source-check fixture smoke\n- `git diff --check`\n\nFull repository checks run in protected PR CI.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T04:10:04Z",
          "mergedAt": "2026-07-13T04:18:46Z",
          "additions": 127,
          "deletions": 31,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1145,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1145",
          "title": "chore(release): promote source-check lifecycle alpha",
          "body": "## Release intent\n\nPromote the reviewed #1143 source-check lifecycle capability from `dev/v2/v2.12` to the v2.12 alpha channel.\n\n## Included capability\n\n- opt-in reusable check `mode: source`\n- GitHub-hosted `install + check` execution without build or verify\n- backward-compatible default verify mode\n- fixture regression and generated public surface updates\n\n## Validation\n\n- implementation PR #1144 merged with protected checks passing\n- alpha promotion dry-run confirms only alpha refs and prerelease publication move\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T04:19:19Z",
          "mergedAt": "2026-07-13T04:21:54Z",
          "additions": 127,
          "deletions": 31,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 746,
          "url": "https://github.com/kungfu-systems/kungfu/pull/746",
          "title": "docs: remove pre-release compatibility paths",
          "body": "## Summary\n\nMake the responsibility-based documentation hierarchy the only repository path surface before the first alpha release.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- remove all 46 flat `docs/*.md` compatibility files\n- remove the ordinary-document redirect metadata profile and validator branches\n- make `docs/README.md` and `docs/MAP.md` the only root Markdown entries\n- revise ADR-0076 to record the pre-release clean-path decision\n- retain and strengthen negative gates that reject canonical ADRs under `framework/core/docs/adr/` and `docs/shifu/adr/`\n\n## Verification\n\n- `./shifu docs:check` (277 Markdown files; 62 tests passed)\n- `./shifu docs:prose:required` (148 files; 0 findings)\n- `./shifu check` (changed-scope gate passed)\n- conservation audit: 46 redirects removed, 0 missing canonical targets\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0076\"],\n  \"summary\": \"Remove speculative pre-release compatibility paths and make the documentation root contract absolute\",\n  \"verification\": [\"./shifu docs:check\", \"./shifu docs:prose:required\", \"./shifu check\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T04:32:49Z",
          "mergedAt": "2026-07-13T04:36:18Z",
          "additions": 106,
          "deletions": 937,
          "changedFiles": 56
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 747,
          "url": "https://github.com/kungfu-systems/kungfu/pull/747",
          "title": "docs(adr): confirm ADR-0072 Phase 2 sequence assignment authority",
          "body": "Confirm ADR-0072 Phase 2 — authoritative ledger-global identity. Phase 2 is a\nspecification milestone (no new runtime code): the durable tier's persisted\nwatermark already is the crash-safe, monotonic authority for\nstream_position.sequence. This PR names that authority, states the contract any\nfuture live producer must follow, confirms ledger consumers key on the Episode\ncontent root + stream_position (not frame_uid), and pins the crash-safe\nmonotonic assignment guarantee with a durable_ingest regression test.\n\n<!-- kungfu-adr-release:v1 {\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"ADR-0072\"],\"summary\":\"Confirm and document ADR-0072 Phase 2: the durable-tier persisted watermark is the crash-safe monotonic authority for stream_position.sequence; stream_id/container_epoch are container identity fixed at stream open; ledger consumers key on Episode content root + stream_position, not frame_uid.\",\"verification\":[\"durable_ingest_tests.cpp new test 'sequence assignment authority is crash-safe and monotonic (ADR-0072 Phase 2)': built + ran all 28 durable_ingest tests, exit 0\",\"scripts/run-docs-check.mjs: deterministic documentation gate passed (markdownlint, links/anchors, adr-audit, release contract)\",\"scripts/document-metadata-contract.mjs on ADR-0072: exit 0\"]} -->",
          "author": "dongkeren",
          "createdAt": "2026-07-13T04:36:45Z",
          "mergedAt": "2026-07-13T04:41:55Z",
          "additions": 118,
          "deletions": 9,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 750,
          "url": "https://github.com/kungfu-systems/kungfu/pull/750",
          "title": "docs: retire framework core documentation root",
          "body": "## Summary\n\nMake `docs/` the single repository authority for public design, qualification, development, and ADR documentation before the first alpha release.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- move seven surviving Core documents into the canonical `docs/` taxonomy\n- move four mmap evidence records into `docs/qualification/evidence/mmap/` without changing their bytes\n- remove 75 Core/Shifu ADR compatibility Markdown files and the redirect metadata profile\n- reject any Markdown reintroduced under `framework/core/docs/` or `docs/shifu/adr/`\n- update section indexes, metadata authorities, ADRs, source comments, and all canonical links\n\n## Verification\n\n- `./shifu docs:check` (202 governed Markdown files; 59 tests passed)\n- `./shifu docs:prose:required` (153 files; 0 errors, warnings, or suggestions)\n- `./shifu check` (changed-scope gate passed, including Rust workspace tests, Python KFX contract tests, Node/TypeScript tests, and documentation contracts)\n- `git diff --check`\n- conservation audit: seven Markdown renames detected; four JSON evidence files are byte-identical; retired roots contain zero files\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0074\", \"ADR-0076\"],\n  \"summary\": \"Retire secondary documentation roots, conserve real content under the canonical taxonomy, and fail closed on path reintroduction\",\n  \"verification\": [\"./shifu docs:check\", \"./shifu docs:prose:required\", \"./shifu check\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T04:53:50Z",
          "mergedAt": "2026-07-13T04:55:35Z",
          "additions": 170,
          "deletions": 1389,
          "changedFiles": 113
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 670,
          "url": "https://github.com/kungfu-systems/kungfu/pull/670",
          "title": "chore(ci): drop dead source-mode mirror config and orphan checks.json",
          "body": "<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Dead-config cleanup: removes an unreachable CI source-mode mirror branch and an orphan root config file; no architecture contract or runtime behavior change.\"\n}\n-->\n\nDead-config cleanup (zero behavior change), from a dead-code survey.\n\n- **`embedding-membrane-spike.yml`**: the matrix only ever sets\n  `source_mode: github`, so the `if [ \"$SOURCE_MODE\" = \"mirror\" ]` reconstruct\n  branch never runs and its `MIRROR_REF` / `MIRROR_URL` env are unreachable —\n  removed. The live github reconstruct path and `MIRROR_BASE_SHA` (still used)\n  are unchanged; the full native matrix on this PR revalidates the step.\n- **`checks.json`** (repo root, `{\"enabled\":true,\"categories\":{}}`, dated 2023):\n  no reference anywhere in the repo — removed.\n\nScope is intentionally minimal: the vestigial always-true `source_mode == 'github'`\nguards are left in place (a larger simplification is tracked separately), and\nall code-level dead-code candidates are deferred to a review card.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T11:45:22Z",
          "mergedAt": "2026-07-13T05:05:40Z",
          "additions": 0,
          "deletions": 8,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1146,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1146",
          "title": "fix(check): expose source mode to lifecycle stages",
          "body": "## Summary\n\n- expose the selected check mode to consumer install and check lifecycle stages\n- fetch complete consumer history for source-mode merge-base checks\n- document and test the source-mode lifecycle contract\n\n## Validation\n\n- `node --test tests/build-surface.test.mjs`\n- `corepack pnpm@11.7.0 run check` (553 tests passed)\n- `git diff --check`\n\n## Safety boundary\n\nThe source mode still executes only `lifecycle.install` and `lifecycle.check`; verify-mode behavior remains unchanged.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T04:49:30Z",
          "mergedAt": "2026-07-13T05:08:38Z",
          "additions": 67,
          "deletions": 36,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1147,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1147",
          "title": "chore(release): promote source acceptance gate alpha",
          "body": "## Release intent\n\nPromote the reviewed source-acceptance lifecycle fixes from `dev/v2/v2.12` to the supported v2 alpha channel after consumer black-box qualification.\n\n## Included capability\n\n- propagate `BUILDCHAIN_CHECK_MODE` to consumer install and check stages\n- fetch complete consumer history in source mode for exact merge-base checks\n- preserve verify-mode behavior and the existing promotion lifecycle\n\n## Qualification\n\n- implementation PR #1146 merged with all protected checks passing\n- Kungfu consumer PR #751 passed `Source acceptance / check` on GitHub-hosted Ubuntu 24.04\n- consumer run used `fetch-depth: 0`, resolved the exact PR revision, and completed only install + check\n- local Buildchain suite passed 553 tests",
          "author": "dongkeren",
          "createdAt": "2026-07-13T05:09:30Z",
          "mergedAt": "2026-07-13T05:11:50Z",
          "additions": 67,
          "deletions": 36,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 751,
          "url": "https://github.com/kungfu-systems/kungfu/pull/751",
          "title": "feat(ci): require build-free source acceptance",
          "body": "## Summary\n\nRequire every development pull request to pass a GitHub-hosted, build-free source acceptance gate before merge.\n\n## Related issue\n\n- kungfu-systems/buildchain#1143\n- kungfu-systems/buildchain#1146\n\n## Changes\n\n- add a Buildchain reusable-workflow caller in `mode: source` for every dev PR\n- add a source-only lifecycle install that provisions Node dependencies and pinned wheel-based static analyzers without compiler or build tooling\n- add exact-revision source checks for formatting, lint, type, schema, documentation, and repository contracts\n- fail closed off GitHub-hosted Linux and test that source plans cannot enter build, compiler, artifact, verify, publish, or release lifecycles\n- retire the narrower Python-only Dev Check while preserving promotion install/build/verify behavior\n\n## Verification\n\n- `./shifu check:source`\n- `node --test scripts/buildchain-install.test.mjs scripts/source-acceptance.test.mjs`\n- Buildchain config validation requiring `install,check,build,verify`\n- `actionlint .github/workflows/source-acceptance.yml .github/workflows/buildchain-validate.yml`\n- `bash -n shifu`\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This CI admission fix closes an implementation gap without altering an accepted architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects pull-request admission and Buildchain lifecycle routing only. It introduces no credentials, publication action, or product artifact.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T04:58:24Z",
          "mergedAt": "2026-07-13T06:05:01Z",
          "additions": 529,
          "deletions": 103,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 752,
          "url": "https://github.com/kungfu-systems/kungfu/pull/752",
          "title": "docs(brand): explain Kungfu recursive meaning",
          "body": "## Summary\n\nAdd a progressively disclosed explanation of the Kungfu name and its recursive technical meaning without increasing first-contact product complexity.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add `Never Guess. Facts Unfold.` as the concise README brand principle\n- add a short README route to the deeper brand explanation\n- add `docs/concepts/why-kungfu.md` for the historical origin, recursive definition, semantic boundaries, and architecture mapping\n- register the document in the Concepts guide, documentation guide, map, and metadata registry\n\n## Verification\n\n- `./shifu docs:check`\n- `./shifu docs:prose:required`\n- pre-commit staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This documentation change explains the existing product philosophy and architecture without changing an architecture contract, release claim, or product identity.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBranding boundary: `UNGFU` is explicitly described as a recursive definition, not a new product, runtime, package, or registration claim. The original Chinese origin remains explicit.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T05:50:48Z",
          "mergedAt": "2026-07-13T06:10:08Z",
          "additions": 163,
          "deletions": 3,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 674,
          "url": "https://github.com/kungfu-systems/kungfu/pull/674",
          "title": "chore(core): remove unreferenced Python dead code",
          "body": "<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Removes three unreferenced Python modules (dead code); no architecture contract or runtime behavior change.\"\n}\n-->\n\nThree Python modules with **no importer anywhere in the repo** (whole-repo grep;\nthe package uses no star-imports, so the import graph is reliable):\n\n- `cli/utils.py` (`safe_import`)\n- `runtime/sinks/csv.py` (`CsvSink` / `open_csv_sink`) — the sinks layer is\n  retired; the sibling `archive.py` is already gone and is guarded out by the\n  ADR-0055/0056 journal-authority boundary. `csv.py` is not itself on that\n  guard's forbidden list, so removing it is clean.\n- `runtime/data/adapter.py` (`Adapter`) — a legacy data-export remnant.\n\n156 deletions, no behavior change. Dev Check (mypy + ruff) validates the package\nstill type-checks. From a dead-code survey; higher-risk C++/TS candidates are\ntracked separately under a review card.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T12:17:05Z",
          "mergedAt": "2026-07-13T06:15:58Z",
          "additions": 0,
          "deletions": 156,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 753,
          "url": "https://github.com/kungfu-systems/kungfu/pull/753",
          "title": "fix(ci): keep native membrane builds out of dev PRs",
          "body": "## Summary\n\nKeep native three-platform membrane builds on alpha/release promotion PRs instead of ordinary dev PRs.\n\n## Changes\n\n- move the `Embedding membrane spikes` matrix from `dev/v*/v*` to `alpha/v*/v*` and `release/v*/v*`\n- add a source-acceptance regression test that rejects restoring the native matrix as a dev PR gate\n\n## Verification\n\n- `./shifu check:source`\n- pre-commit staged gate\n- `node --test scripts/source-acceptance.test.mjs`\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This CI routing fix enforces the existing development source-acceptance contract without changing product architecture.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change only narrows pull-request workflow routing. It does not build or publish an artifact.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation and regression coverage updated\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T06:23:15Z",
          "mergedAt": "2026-07-13T06:27:40Z",
          "additions": 13,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1148,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1148",
          "title": "fix(release): fail closed on GraphQL promotion errors",
          "body": "## Summary\n- fail closed when GitHub returns GraphQL errors in an HTTP 200 promotion response\n- document the repository approval and auto-merge capabilities required by Stable Candidate Patrol\n- refresh the generated public site contract\n\n## Why\nThe latest Patrol run opened the exact-source stable PR, but the repository had auto-merge disabled. GitHub returned the refusal in a GraphQL `errors` payload while the HTTP request itself returned 200, so the client incorrectly continued to the later approval step.\n\n## Validation\n- `node --test tests/stable-candidate-patrol.test.mjs`\n- `pnpm run check` (554 tests passed)\n- `git diff --check`\n\nThis change does not weaken branch protection or publish a release.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T06:32:07Z",
          "mergedAt": "2026-07-13T06:33:45Z",
          "additions": 47,
          "deletions": 7,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 35,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/35",
          "title": "feat(homepage): add recursive Kungfu brand principle",
          "body": "## Summary\n\n- keep the consumer-facing Cost / State / Proof promise dominant on the homepage\n- add `Never Guess. Facts Unfold.` as a secondary Kungfu brand principle\n- add a dedicated `Why Kungfu?` page with the honest Chinese origin, recursive definition, and project obligation\n- extend site checks to protect the new route and semantic boundaries\n\n## Validation\n\n- `corepack pnpm@11.7.0 install --frozen-lockfile --ignore-scripts --registry=https://registry.npmjs.org/`\n- `bash -n scripts/build-site.sh`\n- `bash -n scripts/check-site.sh`\n- `bash scripts/build-site.sh`\n- `bash scripts/check-site.sh`\n- `git diff --check`\n- Playwright desktop 1440x900 and mobile 390x844; 0 console errors and 0 warnings\n\n## Release boundary\n\nThis PR updates the normal site mainline and staging path. It does not approve or trigger the separately gated production release.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T06:33:01Z",
          "mergedAt": "2026-07-13T06:37:03Z",
          "additions": 296,
          "deletions": 3,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/site-kungfu-tech",
          "number": 37,
          "url": "https://github.com/kungfu-systems/site-kungfu-tech/pull/37",
          "title": "Release production from 118357b6c055",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- default: https://staging.kungfu.tech\n\n### Release Evidence\n\n- Source SHA: `118357b6c055b7481f02baf1da8ef66447bc254b`\n- Artifact hash: `b0f0cde6538b7a705748dd2d5ee2d36ee3f8b04b87e1f5e3fbef810f0aa7f90a`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-kungfu-tech/actions/runs/29229523725)\n- Required label: `buildchain-release`\n- Release branch: `feature/release-production-118357b6c055`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-13T06:39:06Z",
          "mergedAt": "2026-07-13T06:42:00Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 754,
          "url": "https://github.com/kungfu-systems/kungfu/pull/754",
          "title": "feat(runtime): fold interrupted Episodes into recovery",
          "body": "## Summary\n- compose the existing typed Storage/Episode qualification result into crash-recovery reports\n- classify retained open Episodes as DEGRADED and invalid/unknown Episode evidence as BLOCKED\n- preserve read-only inspection, full report repeatability, and closed-Episode isolation\n- supersede #720 with an equivalent single-parent commit because the repository only permits rebase merge\n\n## Verification\n- `./shifu check:source`\n- direct `kungfu_crash_recovery_tests` execution: 10 passed\n- direct `kungfu_durable_ingest_tests` execution: 25 passed\n- direct `kungfu_projection_bootstrap_tests` execution: 13 passed\n- `git diff --check`\n- `build:core` compiled and linked all three target binaries; the aggregate build then stopped on the unrelated dev-baseline `view_encapsulation_probe` SQLite link defect\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Fold interrupted Episode qualification into deterministic read-only crash recovery\",\n  \"verification\": [\"crash-recovery contracts\", \"durable-ingest contracts\", \"projection-bootstrap contracts\", \"build-free source acceptance\"]\n}\n-->\n\n## Boundaries\n- no automatic Episode abort/resume or other mutation\n- no second lifecycle/capability vocabulary and no JSON service currency\n- no workflow, Buildchain, artifact, or release-path changes\n- export/empty-root restore and projection rebuild equality remain later recovery stages\n\n## Governance risk check\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR updates ADR delivery evidence only; it does not modify workflows, publish artifacts, or deploy anything.\n\n## Checklist\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T06:45:45Z",
          "mergedAt": "2026-07-13T06:46:56Z",
          "additions": 216,
          "deletions": 16,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 755,
          "url": "https://github.com/kungfu-systems/kungfu/pull/755",
          "title": "feat(shifu): enforce uv cache with disposable effective locks",
          "body": "## Summary\n\nMake strict Shifu cache profiles enforce the selected Python index without rewriting tracked uv.lock files or exposing private network topology in public source.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- create process-private effective uv lock and environment overlays for cache-managed execution\n- preserve dependency semantics and fail closed when strict rebinding cannot be proven\n- require every tracked uv.lock URL to use official PyPI hosts\n- preserve explicit Buildchain and runner cache projections across shell, Windows, and native config loading\n- emit redacted digest-only tool evidence and cleanup state\n\n## Verification\n\n- `node scripts/source-acceptance.mjs`\n- `cargo clippy --workspace --all-targets -- -D warnings`\n- `cargo test --workspace`\n- strict self-hosted profile dry-run on Ubuntu and agent-120\n- full `shifu sync && shifu check:source` on agent-120 with canonical lock SHA and Git status unchanged\n- development profile execution on macOS with canonical lock SHA and Git status unchanged\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-0003\"],\n  \"summary\": \"Implement disposable uv effective locks, official-PyPI canonical lock policy, and strict cache enforcement\",\n  \"verification\": [\"source acceptance\", \"Rust workspace tests\", \"macOS development profile\", \"Ubuntu and agent-120 strict profile\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe ADR and receipt define public evidence boundaries; receipts contain digests and counts, while repository locks remain restricted to official PyPI hosts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:02:26Z",
          "mergedAt": "2026-07-13T07:07:37Z",
          "additions": 1545,
          "deletions": 50,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1149,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1149",
          "title": "fix(release): support independent Patrol approvals",
          "body": "Patrol currently depends on the caller GITHUB_TOKEN for protected-branch approval. Organization policy can block that capability even when the workflow requests pull-request write permission.\\n\\nThis change adds an optional independent approval token to the reusable workflow, maps Buildchain dogfood to a dedicated repository secret, keeps the caller token fallback for repositories whose policy permits it, and documents both supported approval paths.\\n\\nValidation:\\n- pnpm run check\\n- 554 tests passed\\n- workflow validation passed\\n- generated site drift check passed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:11:19Z",
          "mergedAt": "2026-07-13T07:13:21Z",
          "additions": 30,
          "deletions": 16,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 756,
          "url": "https://github.com/kungfu-systems/kungfu/pull/756",
          "title": "chore(core): remove the unreferenced nanomsg webserver module",
          "body": "<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Removes the unreferenced kungfu::webserver module (dead code compiled into libkungfu only via GLOB); no architecture contract or runtime behavior change.\"\n}\n-->\n\n`kungfu::webserver` — `runtime/nanomsg/webserver.h` (331) + `runtime/util/webserver.cpp` (537), ~868 lines: `web_agent`, `stream`, `session`, `websocket_client`, `websocket_server`, `http_server` and helpers — has **no reference anywhere in the repo** (verified by whole-repo grep of every symbol and the include path). It is compiled into libkungfu only because it sits under a `file(GLOB_RECURSE)` source list, and **no ADR keeps it as a planned surface**; it was left disconnected when the master/coordinator transport was reworked.\n\nRemoved both files. No behavior change — nothing links against these symbols. From a dead-code survey (owner-confirmed removal).",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:04:28Z",
          "mergedAt": "2026-07-13T07:14:16Z",
          "additions": 0,
          "deletions": 868,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1150,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1150",
          "title": "fix(release): bind Patrol approval authority",
          "body": "Bind Buildchain's Patrol dogfood caller to the dedicated approval secret when configured and otherwise reuse the existing organization release authority secret. The reusable workflow still keeps the caller GITHUB_TOKEN fallback for external consumers.\n\nValidation:\n- node --test tests/build-surface.test.mjs (71 passed)\n- pnpm run check:workflows",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:16:55Z",
          "mergedAt": "2026-07-13T07:18:59Z",
          "additions": 5,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1142,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1142",
          "title": "Release v2.12.1 from qualified v2.12.1-alpha.9",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.12.1-alpha.9`\n- Candidate SHA: `41dc500ec951422c0da87d36a9e6f03dafcd181c`\n- Selection: `latest-qualified`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.12`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-12T20:04:42Z",
          "mergedAt": "2026-07-13T07:20:48Z",
          "additions": 3543,
          "deletions": 270,
          "changedFiles": 62
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 759,
          "url": "https://github.com/kungfu-systems/kungfu/pull/759",
          "title": "fix(shifu): remove private cache address from fixture",
          "body": "## Summary\n\nRemove an office-private cache address from a public Shifu test fixture and replace it with reserved `.local` fixture hosts. The test continues to cover rejection of private and non-PyPI transports without disclosing real topology.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- replace the real private cache coordinate with `package-cache.local`\n- keep private registry and artifact rejection assertions unchanged\n\n## Verification\n\n- `node --test scripts/shifu-uv-cache-adapter.test.mjs`\n- `node scripts/check-shifu-cache-contract.mjs`\n- pre-commit documentation, contract, and Biome gates\n- public fixture scan confirms the office address is absent\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This privacy fix changes only test fixture coordinates and does not alter the accepted cache enforcement architecture\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:21:22Z",
          "mergedAt": "2026-07-13T07:23:03Z",
          "additions": 2,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 761,
          "url": "https://github.com/kungfu-systems/kungfu/pull/761",
          "title": "feat(runtime): add verified backup restore round trip",
          "body": "## Summary\n- export only an exclusively owned, twice-verified READY recovery cut with explicit frontier and RPO evidence\n- bind authoritative file bytes, sealed Episode content roots, and verified payload hashes while excluding ownership, quarantine, receipts, and derived projections\n- restore into an empty or byte-identical partial data root, publish the receipt last, and require projection rebuild to the same typed state, cut, and integrity hash\n- supersede #758 and #760 with the same stable patch on the latest dev parent because branch protection requires an up-to-date, rebaseable head\n\n## Verification\n- `./shifu check:source`\n- direct `kungfu_crash_recovery_tests` execution: 13 passed\n- direct `kungfu_durable_ingest_tests` execution: 28 passed\n- direct `kungfu_projection_bootstrap_tests` execution: 13 passed\n- focused CMake build of all three test targets with the pinned C++23 toolchain\n- stable patch id matches #758 exactly: `bbd948d26fea83c87dfa2c5a0ebf08a7e0d689b5`\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Add consistent backup, empty-root verified restore, and projection rebuild equality\",\n  \"verification\": [\"crash-recovery contracts\", \"durable-ingest contracts\", \"projection-bootstrap contracts\", \"build-free source acceptance\"]\n}\n-->\n\n## Boundaries\n- no workflow, Buildchain, artifact, release, or self-hosted runner changes\n- no production durability or sudden-power-loss claim; the API remains test-only and in-process\n- no external archive format, operator backup command, remote replication, or automatic failover\n- production bootstrap cutover and named platform/filesystem qualification remain later stages\n\n## Governance risk check\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR updates ADR delivery evidence only; it does not modify workflows, publish artifacts, or deploy anything.\n\n## Checklist\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:25:54Z",
          "mergedAt": "2026-07-13T07:27:27Z",
          "additions": 857,
          "deletions": 21,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 762,
          "url": "https://github.com/kungfu-systems/kungfu/pull/762",
          "title": "feat(shifu): add gate control plane contract",
          "body": "## Summary\n\nAdd the project-neutral Shifu Gate v1 contract and a read-only control surface for validating, explaining, comparing, and planning project gates.\n\n## Related issue\n\nSHIFU-ADR-0004\n\n## Changes\n\n- define strict registry and deterministic plan schemas for light and heavy gates\n- add `shifu gate validate|list|show|explain|matrix|plan`\n- route Gate commands through native, POSIX, and Windows launchers without changing task aliases\n- document the Shifu/project/Buildchain authority boundary and register the additive KFD-1 surface update\n- add valid/invalid fixtures, semantic checks, JSON Schema conformance, and source acceptance coverage\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu check`\n- native `./shifu gate validate` and `./shifu gate plan` smoke\n- `bash -n shifu`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Complete the Gate v1 contract, read-only CLI, validation, deterministic planning, documentation, and source gates without execution or CI migration\",\n  \"verification\": [\"./shifu check:source\", \"./shifu check\", \"native shifu gate smoke\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change defines future gate evidence metadata but does not execute gates, publish artifacts, modify branch protection, or perform a release.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:38:49Z",
          "mergedAt": "2026-07-13T07:41:47Z",
          "additions": 2045,
          "deletions": 9,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 67,
          "url": "https://github.com/kungfu-systems/build-images/pull/67",
          "title": "fix(release): adopt Buildchain v2.12 dual-channel contract",
          "body": "## Summary\n\n- migrate verification to the standard Buildchain `build.yml@v2` channel router\n- route development and alpha work through `v2-alpha`, while release work stays on stable `v2`\n- lock both channels independently and bind both locks into KFD123 evidence\n- upgrade the consumer package to Buildchain 2.12.1\n- install CM-Super scalable Type1 fonts so microtype expansion works with the default T1 LaTeX setup\n\n## Validation\n\n- `pnpm run check`\n- `actionlint .github/workflows/*.yml`\n- `shellcheck scripts/*.sh images/*/tests/*.sh`\n- alpha and stable router selection checks\n- exact alpha and stable contract-lock checks\n- local amd64 LaTeX image build and microtype PDF smoke test\n\n## Release impact\n\nPatch release. The existing image families and consumer-facing tag policy remain unchanged.\n\n## Follow-up\n\nBuildchain cannot yet fail closed on post-publish OCI family completeness because image digests are only known inside the consumer publish lifecycle. The capability request is tracked in kungfu-systems/buildchain#1151; this release keeps the currently validated publish evidence and Release Passport path.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:42:48Z",
          "mergedAt": "2026-07-13T07:50:07Z",
          "additions": 338,
          "deletions": 159,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 764,
          "url": "https://github.com/kungfu-systems/kungfu/pull/764",
          "title": "feat(runtime): complete crash recovery restart contract",
          "body": "## Summary\n- report sealed non-ok Episode findings without misnaming them as interrupted or contaminating independent Episodes\n- enforce supervisor -> state service -> projection -> required peers through a typed fail-closed restart authorization gate\n- resume only exact interrupted quarantine packages and reject extra retained evidence before mutation\n- verify durable facts, sealed Episode identity, projection cut, and peer authorization by reopening the whole data root in a fresh process\n\n## Verification\n- `./shifu check:source`\n- `./shifu test:crash-recovery`: 15 focused cases plus fresh-process whole-data-root reopen passed\n- `./shifu test:durable-ingest`: 28 focused cases plus cross-process writer attestation passed\n- `./shifu test:projection-bootstrap`: 10 focused cases plus cross-process projection restart passed\n- independent Episode semantic oracle: 48 bounded histories passed\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Complete the deterministic single-host crash-recovery restart contract\",\n  \"verification\": [\"crash-recovery contracts\", \"whole-data-root process restart\", \"Episode semantic oracle\", \"build-free source acceptance\"]\n}\n-->\n\n## Boundaries\n- no workflow, Buildchain, artifact, release, or self-hosted runner changes\n- no production durability or sudden-power-loss claim; these contracts remain test-only\n- no destructive authoritative repair, remote replication, or automatic failover\n- named platform/filesystem qualification remains the next independent child goal\n\n## Governance risk check\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR updates ADR delivery evidence only; it does not modify workflows, publish artifacts, or deploy anything.\n\n## Checklist\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:49:20Z",
          "mergedAt": "2026-07-13T07:50:57Z",
          "additions": 360,
          "deletions": 18,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 69,
          "url": "https://github.com/kungfu-systems/build-images/pull/69",
          "title": "chore(alpha): reconcile v1.2 channel history",
          "body": "## Summary\n\nRecord the current alpha head as an ancestor of the v1.2 development line while preserving the verified development tree exactly.\n\nThis removes historical release-state divergence before the next protected `dev/v1/v1.2` to `alpha/v1/v1.2` promotion. The merge uses the current dev tree and contains no product-content changes.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:51:55Z",
          "mergedAt": "2026-07-13T07:53:41Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 68,
          "url": "https://github.com/kungfu-systems/build-images/pull/68",
          "title": "chore(alpha): promote Buildchain v2.12 dual-channel release",
          "body": "## Summary\n\nPromote the verified v1.2 development line to alpha with:\n\n- the standard Buildchain v2.12 dual-channel workflow\n- independent `v2-alpha` and stable `v2` contract locks\n- pnpm lifecycle execution through Corepack\n- CM-Super scalable fonts for default microtype expansion\n- KFD123 evidence and Release Passport publication enabled\n\n## Promotion plan\n\nAfter the first alpha image family is published, its exact public digests will be reviewed into `images.lock.json` before stable promotion.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:50:54Z",
          "mergedAt": "2026-07-13T07:55:32Z",
          "additions": 339,
          "deletions": 160,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 70,
          "url": "https://github.com/kungfu-systems/build-images/pull/70",
          "title": "chore(images): lock v1.2.1-alpha.3 digests",
          "body": "## Summary\n\n- accept the exact public digests published by Buildchain run 29233734962\n- bind `images.lock.json` to source `031a9c9` and tag `v1.2.1-alpha.3`\n- add an explicit `sfrm1000.pfb` probe to the LaTeX manifest and consumer smoke contract\n- refresh deterministic KFD123 evidence\n\nAll five alpha images were anonymously pulled and smoked by the publish transaction. The locked LaTeX digest contains CM-Super and successfully compiled the microtype expansion smoke document.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T08:04:43Z",
          "mergedAt": "2026-07-13T08:06:28Z",
          "additions": 32,
          "deletions": 30,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 71,
          "url": "https://github.com/kungfu-systems/build-images/pull/71",
          "title": "chore(alpha): promote locked v1.2.1 candidate",
          "body": "## Summary\n\nPromote the reviewed v1.2.1 alpha image lock and explicit scalable-font probe to the alpha channel.\n\nThe accepted `v1.2.1-alpha.3` digests passed anonymous consumer smoke, including `kpsewhich sfrm1000.pfb` and the microtype PDF build. This promotion produces the final alpha candidate before stable release.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T08:06:44Z",
          "mergedAt": "2026-07-13T08:09:19Z",
          "additions": 32,
          "deletions": 30,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 73,
          "url": "https://github.com/kungfu-systems/build-images/pull/73",
          "title": "chore(release): reconcile v1.2 channel history",
          "body": "## Summary\n\nRecord the current stable v1.2 release head as an ancestor of the verified alpha line while preserving the alpha tree exactly.\n\nThis is a zero-content channel-history reconciliation required before the protected `alpha/v1/v1.2` to `release/v1/v1.2` promotion can merge cleanly. It does not change the accepted image lock or product files.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T08:19:30Z",
          "mergedAt": "2026-07-13T08:21:27Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 74,
          "url": "https://github.com/kungfu-systems/build-images/pull/74",
          "title": "chore(release): sync v1.2 channel ancestry to dev",
          "body": "## Summary\n\nSync the release-channel ancestry reconciliation from alpha back into the v1.2 development line without changing the product tree.\n\nThe next alpha publication must originate from a protected `dev/v1/v1.2` to `alpha/v1/v1.2` PR. This sync makes that forward promotion possible while preserving the accepted image lock and candidate content exactly.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T08:24:27Z",
          "mergedAt": "2026-07-13T08:26:56Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 76,
          "url": "https://github.com/kungfu-systems/build-images/pull/76",
          "title": "chore(alpha): publish reconciled v1.2.1 candidate",
          "body": "Promote the reconciled v1.2 development channel through the standard Buildchain v2.12 alpha lane.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T08:29:20Z",
          "mergedAt": "2026-07-13T08:31:05Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 765,
          "url": "https://github.com/kungfu-systems/kungfu/pull/765",
          "title": "feat(shifu): execute gates with source-bound receipts",
          "body": "## Summary\n\nAdd the Shifu Gate execution and receipt layer so registered gates can be run individually or by profile, with source-bound evidence that downstream policy can validate and reuse.\n\n## Related issue\n\nSHIFU-ADR-0004\n\n## Changes\n\n- add `shifu gate run` for explicit diagnostic selections and full profile execution\n- execute dependency-closed gates through native Shifu tasks, argv actions, or named handlers\n- emit strict Gate receipt v1 evidence with source, definition, action, artifact, coverage, and integrity bindings\n- add `shifu gate receipt validate` with fail-closed freshness and qualification checks\n- preserve advisory visibility while blocking required failures, skips, unsupported capabilities, timeouts, stale source, and incomplete evidence\n- redact paths, URLs, secrets, child output, and inherited environment values from receipts\n- cover POSIX and Windows launcher construction plus real existing-task dogfood\n\n## Verification\n\n- `./shifu check`\n- `./shifu check:source`\n- `./shifu gate run --profile task-dogfood --registry docs/shifu/examples/gates/execution.gate-registry.json --receipt build/gate-receipts/task-dogfood-clean.json --overwrite`\n- `./shifu gate receipt validate build/gate-receipts/task-dogfood-clean.json --registry docs/shifu/examples/gates/execution.gate-registry.json --json` returned valid/current/qualifying true\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Complete the Gate v1 execution and source-bound receipt stage without migrating Kungfu gate catalogs or release workflows\",\n  \"verification\": [\"./shifu check\", \"./shifu check:source\", \"clean-source qualifying Gate receipt dogfood\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis stage defines and validates reusable gate evidence. It does not migrate release workflows, publish artifacts, modify branch protection, or perform a release. Receipt tests explicitly prove that secret-like values, inherited environment values, child output, URLs, and absolute paths are not retained.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T08:28:06Z",
          "mergedAt": "2026-07-13T08:31:29Z",
          "additions": 2041,
          "deletions": 24,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 766,
          "url": "https://github.com/kungfu-systems/kungfu/pull/766",
          "title": "feat(profile): productize KFD-3 qualification badges",
          "body": "## Summary\n\nLinear replacement for #749. The repository permits rebase merges only, while #749 contains a dev merge commit that GitHub cannot rebase. This branch is a single signed-off commit whose tree is byte-for-byte identical to the fully Mac-verified #749 head.\n\nProductize KFD-3 qualification as one content-bound status shared by human and agent clients. Shipped system Profiles receive release-owned qualification evidence and the same visible badge semantics that a user Profile earns through an explicit plan and authorization flow.\n\n## Related issue\n\n- Supersedes #749 for merge topology only\n- Atlas goal: 2026-07-13-kungfu-profile-kfd3-badge-and-agent-status\n\n## Changes\n\n- add an append-only KFD-3 qualification lifecycle fact bound to the exact Profile Suite root\n- expose status, plan, authorize, and verify operations through the Profile SDK, CLI, TypeScript API, and Agent catalog\n- remove implicit qualification probes from Profile application projection\n- bake release-owned Mission Control qualification evidence into Product artifacts\n- bind Mission Control qualification to the shared GUI and Agent APIs\n- render one emoji badge vocabulary and detailed tooltip in Profile Manager\n\n## Verification\n\n- ./shifu check\n- ./shifu test:kfx-profile-suite\n- ./shifu test:profile-lifecycle\n- ./shifu test:agent-profile-sdk: 47 passed\n- ./shifu test:profile-kfd3-qualification: Agent CLI and typed Human API matched at one lifecycle cut\n- Mac arm64 Core build: Apple Clang 21, C++23, 113 native targets plus Node/Electron/Python bindings and dual libwasm engines\n- ./shifu freeze\n- ./shifu --filter @kungfu-tech/kfx-view-work-dashboard run build\n- Mission Control factory manifest: release-qualified, 4/4 shared GUI/Agent probes matched, built-view-bundle\n- Linear branch tree equals the tested #749 head\n- Linux/Conan central-cache repair is tracked independently and is not part of this Mac product closeout\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0069\"],\n  \"summary\": \"Deliver exact-root KFD-3 qualification receipts, system and user badge parity, and one machine-readable Agent status contract.\",\n  \"verification\": [\"Shifu changed-scope gate\", \"Profile lifecycle and SDK tests\", \"Profile Suite and API tests\", \"factory manifest qualification\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe Product build now emits a content-rooted system Profile qualification manifest. Bundle audit and local qualification tests verify the manifest boundary; it contains no credentials or private runtime data.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T08:32:49Z",
          "mergedAt": "2026-07-13T08:42:24Z",
          "additions": 1311,
          "deletions": 203,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 72,
          "url": "https://github.com/kungfu-systems/build-images/pull/72",
          "title": "chore(release): promote v1.2.1",
          "body": "## Summary\n\nPromote the verified v1.2.1 alpha candidate to the stable release channel.\n\nEvidence before promotion:\n\n- `v1.2.1-alpha.3` exact digests are reviewed in `images.lock.json`\n- `v1.2.1-alpha.4` was published from the locked candidate\n- anonymous consumer smoke passed for all five image families\n- the LaTeX image passed the CM-Super probe and microtype expansion PDF build\n- KFD123 and the Buildchain alpha contract lock passed\n\nThe release branch resolves through stable Buildchain `v2` and `.buildchain/contract-lock.json` before the stable publish transaction runs.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T08:18:44Z",
          "mergedAt": "2026-07-13T08:44:20Z",
          "additions": 3866,
          "deletions": 46,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 77,
          "url": "https://github.com/kungfu-systems/build-images/pull/77",
          "title": "fix(release): supply production passport impact",
          "body": "## Summary\n- supply the v2.12 production release passport impact ledger\n- version-bind the ledger with the Buildchain version state\n- exercise production surface-impact requirements in the KFD smoke check\n\n## Verification\n- `pnpm run check`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-13T08:59:01Z",
          "mergedAt": "2026-07-13T09:00:50Z",
          "additions": 70,
          "deletions": 5,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 78,
          "url": "https://github.com/kungfu-systems/build-images/pull/78",
          "title": "chore(alpha): publish release passport fix candidate",
          "body": "Promote the production release-passport impact fix through the standard Buildchain v2.12 alpha lane.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T09:01:10Z",
          "mergedAt": "2026-07-13T09:03:21Z",
          "additions": 70,
          "deletions": 5,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 79,
          "url": "https://github.com/kungfu-systems/build-images/pull/79",
          "title": "fix(release): pass v1.2 passport impact from default wrapper",
          "body": "## Summary\n- pass the v1.2 impact ledger from the default-branch workflow_run wrapper\n- keep the v1.1 lane unchanged\n\n## Verification\n- `actionlint -color=false .github/workflows/buildchain-ref-promotion.yml`\n- `pnpm run check:workflows`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-13T09:13:42Z",
          "mergedAt": "2026-07-13T09:14:47Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 767,
          "url": "https://github.com/kungfu-systems/kungfu/pull/767",
          "title": "feat(shifu): catalog Kungfu gate policy",
          "body": "## Summary\n\nProject Kungfu real light and heavy gate surfaces into the generic Shifu Gate control plane, with explicit dev/alpha/release policy matrices, per-gate documentation, current workflow bindings, and a fail-closed consistency gate.\n\n## Related issue\n\nSHIFU-ADR-0004\n\n## Changes\n\n- add the project-owned `shifu.gates.json` registry with 34 gates and five explicit profiles\n- include light source/governance checks, self-hosted product builds, Episodes, membrane, native qualification, and release admission in one matrix\n- document every gate problem, action, dependencies, platforms, evidence, diagnosis, cost, current source, and retirement rule\n- add a deterministic generated policy matrix for `dev-pr`, `dev-patrol`, `alpha-pr`, `release-pr`, and `release-promotion`\n- bind selected policy decisions to current GitHub workflow reality while migration remains incomplete\n- add `./shifu check:gate-catalog` and wire it into source acceptance, repository check, and product verification\n- fail closed on registry, action, document, anchor, matrix, profile coverage, off-policy binding, or workflow-snippet drift\n\n## Verification\n\n- `./shifu check:gate-catalog`\n- `node --test scripts/check-kungfu-gate-catalog.test.mjs`\n- `./shifu docs:check`\n- `./shifu docs:prose:required`\n- `./shifu check:source`\n- `./shifu check`\n- `./shifu gate plan alpha-pr --platform linux --json` returned `ok=true`, `qualifying=true`, and no unsupported gates\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Complete the Kungfu Gate catalog, detailed documentation, policy matrix, workflow binding, and consistency meta-gate stage without migrating workflow execution\",\n  \"verification\": [\"./shifu check:gate-catalog\", \"./shifu docs:check\", \"./shifu docs:prose:required\", \"./shifu check:source\", \"./shifu check\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis stage describes and validates release gate policy. It does not publish artifacts, change branch protection, weaken existing required checks, or migrate workflow execution. Named remote handlers remain fail-closed until the orchestration stage registers their controllers.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T09:12:02Z",
          "mergedAt": "2026-07-13T09:15:34Z",
          "additions": 3304,
          "deletions": 1,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 81,
          "url": "https://github.com/kungfu-systems/build-images/pull/81",
          "title": "chore(release): reconcile v1.2.1 ancestry",
          "body": "Record the failed v1.2.1 stable transaction as an ancestor of the v1.2.2 development line without changing the development tree.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T09:16:16Z",
          "mergedAt": "2026-07-13T09:18:04Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 82,
          "url": "https://github.com/kungfu-systems/build-images/pull/82",
          "title": "chore(alpha): publish reconciled v1.2.2 candidate",
          "body": "Promote the v1.2.1 ancestry reconciliation through the standard Buildchain v2.12 alpha lane without changing the candidate tree.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T09:18:15Z",
          "mergedAt": "2026-07-13T09:20:03Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 768,
          "url": "https://github.com/kungfu-systems/kungfu/pull/768",
          "title": "docs(readme): sharpen first-contact product story",
          "body": "## Summary\n\nMake the repository README explain Kungfu in concrete user language before introducing the Episode model and technical evidence.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- describe Kungfu as a local-first runtime that records real-world agent work and verifies what actually got done\n- clarify that Kungfu works alongside existing agents and execution surfaces\n- move the Episode mechanism behind the first-contact promise\n- keep every image badge inside the Buildchain-managed block and render the current KFD-4 declaration\n- replace the manually maintained Coming soon badge with plain status text\n- tighten capability and qualification wording without changing product contracts\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu docs:check`\n- `./shifu docs:prose` (0 errors; no README findings)\n- pinned Buildchain `badges readme --check` (current, no drift)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This documentation-only change clarifies first-contact positioning and regenerates the declared badge projection without altering an architecture contract\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe README positioning is the intended branding change. Product names, package names, domains, release identity, and evidence semantics remain unchanged.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T09:30:24Z",
          "mergedAt": "2026-07-13T09:32:03Z",
          "additions": 26,
          "deletions": 20,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 80,
          "url": "https://github.com/kungfu-systems/build-images/pull/80",
          "title": "chore(release): publish build-images v1.2.2",
          "body": "Promote the verified `v1.2.2-alpha.0` candidate through the standard Buildchain v2.12 stable lane.\n\nThe production release passport impact ledger is version-bound and supplied by the default workflow_run wrapper.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T09:15:09Z",
          "mergedAt": "2026-07-13T09:34:02Z",
          "additions": 71,
          "deletions": 6,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 769,
          "url": "https://github.com/kungfu-systems/kungfu/pull/769",
          "title": "feat(shifu): migrate gate workflow entrypoints",
          "body": "## Summary\n\nMigrate task-backed Kungfu workflow gates onto the generic Shifu Gate executor while preserving controller-owned and supply-chain-pinned boundaries.\n\n## Related issue\n\nSHIFU-ADR-0004\n\n## Changes\n\n- route ADR delivery, promotion rehearsal, documentation closure, dev full verification, membrane qualification, and Shifu workspace CI through `shifu gate run`\n- replace the Shifu workspace remote handler with an independently executable cross-platform Gate task\n- mark every workflow binding as `gate` or `controller`, and fail closed when a Gate-owned binding lacks a real `gate run` entrypoint\n- make the catalog meta gate verify exact documented action, dependency, platform, cost, and current workflow source facts\n- align dev patrol with its real aggregate `product.verify-full` action so it does not duplicate distribution or Episode smoke work\n- retain the immutable lychee action and Buildchain-owned workflows as controllers for their existing trust/orchestration boundaries\n\n## Verification\n\n- `./shifu gate run shifu.workspace --capability rust --json`\n- `./shifu gate run governance.promotion-rehearsal --json`\n- `./shifu gate run governance.adr-delivery --json`\n- `./shifu gate plan dev-patrol --json`\n- `./shifu gate plan alpha-pr --json`\n- `./shifu check:gate-catalog`\n- `./shifu docs:check:readonly`\n- `./shifu check:source`\n- `./shifu check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Migrate task-backed Kungfu workflow gates onto Shifu Gate while preserving controller and immutable toolchain boundaries\",\n  \"verification\": [\"./shifu gate run shifu.workspace --capability rust --json\", \"./shifu check:gate-catalog\", \"./shifu docs:check:readonly\", \"./shifu check:source\", \"./shifu check\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis stage changes Gate entrypoints and validation only. It does not publish, alter branch protection, or bypass controller-owned release admission.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T09:46:22Z",
          "mergedAt": "2026-07-13T09:55:30Z",
          "additions": 287,
          "deletions": 91,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 770,
          "url": "https://github.com/kungfu-systems/kungfu/pull/770",
          "title": "test(runtime): add local durability qualification harness",
          "body": "## Summary\n\nAdd a versioned, fail-closed local Shifu qualification harness for the ADR-0068 process-crash durability stage. The harness produces separate durable_group and durable_sync reports for named macOS/APFS, Linux/ext4, and Windows/NTFS profiles without claiming power-loss or production-profile qualification.\n\n## Related issue\n\nAtlas goal 2026-07-12-kungfu-durability-qualification.\n\n## Changes\n\n- add schema-validated platform profiles and immutable JSON/raw-log evidence\n- execute only local Shifu commands, with dry-run as the default\n- exercise native durability, crash recovery, Episode qualification, and the semantic oracle\n- align typed Episode evidence and use cross-platform correctness ceilings without reducing the workload\n- document the partial implementation stage and explicit non-claims\n\n## Verification\n\n- `PATH=\"$PWD/framework/core/.venv/bin:$PATH\" ./shifu check:source` at `af0f7acbfc03462cb921589070e4c7fae5cdbc02`\n- macOS/APFS Apple Clang 21 arm64 C++23: no-controller-cache `./shifu build:core`, durable_group passed, durable_sync passed at `eeff8615e01c401aa656dbec2d05dd053d192568`\n- Linux/ext4 GCC 14 x64 C++23: no-controller-cache `./shifu build:core`, durable_group passed, durable_sync passed at `eeff8615e01c401aa656dbec2d05dd053d192568`\n- Windows/NTFS MSVC 19.51 C++23: Shifu doctor and sync passed; the default Conan cache has no exact binary and the Shifu source build could not complete after the upstream RocksDB fetch stalled. Windows remains unqualified.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Add the versioned local process-crash qualification harness and retain honest platform qualification boundaries\",\n  \"verification\": [\"Build-free Shifu source gate passed at af0f7acb\", \"Mac and Linux local Shifu qualification passed at eeff8615\", \"Windows remains explicitly unqualified\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe new evidence surface is local-only, schema-bound, revision-bound, and immutable. It does not publish artifacts or trigger remote builds.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T10:01:38Z",
          "mergedAt": "2026-07-13T10:10:27Z",
          "additions": 1251,
          "deletions": 84,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 84,
          "url": "https://github.com/kungfu-systems/build-images/pull/84",
          "title": "ci(images): add registry-backed build cache",
          "body": "## Summary\n\n- build the full image family with Buildx and a per-image, per-contract, per-platform GHCR cache\n- keep cache writes limited to the protected Buildchain lifecycle publisher while verification remains read-only\n- preserve image smoke, exact tags, digest evidence, public pulls, and Release Passport gates\n- document cache trust and fallback boundaries\n\n## Verification\n\n- `pnpm run check`\n- `shellcheck scripts/build-image-family.sh scripts/publish-image-family.sh scripts/check-workflows.sh scripts/test-build-image-family-cache.sh`\n- Buildx cache-miss probe continued with a cold build\n- Buildx unavailable-export probe completed with `ignore-error=true`\n\n## Version impact\n\nKFD-1: patch. No registered image, tag, or digest-summary surface changes.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T10:33:05Z",
          "mergedAt": "2026-07-13T10:34:56Z",
          "additions": 293,
          "deletions": 85,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 771,
          "url": "https://github.com/kungfu-systems/kungfu/pull/771",
          "title": "feat(coordination): ADR-0077 first slice — same-host named locks",
          "body": "## Same-host agent coordination — ADR-0077 first slice\n\nAdds a same-host named lock so concurrent agents serialize on a shared resource (e.g. git mainline integration) without the agent's model spinning a retry loop, and records each lock run as a replayable Episode.\n\n- `kungfu lock run NAME -- <command>` — hold NAME for a wrapped command; blocking acquire, crash-safe release.\n- `kungfu lock status` — current locks and holder liveness.\n- `kungfu.coordination.locks` — stdlib, cross-process tested; `coordination/audit.py` records Episodes.\n\nThe journal-native arbiter (coloop grant frame, instruct-injection) is a deferred follow-up.\n\n<!-- kungfu-adr-release:v1 {\"schema\": \"kungfu.adr-release-pr/v1\", \"kind\": \"dev-delivery\", \"intent\": \"stage-ready\", \"adrs\": [\"ADR-0077\"], \"summary\": \"Deliver the ADR-0077 first slice: a same-host named lock (kungfu lock run NAME -- <command>) with crash-safe auto-release and Episode audit of each run's wait/acquire/release. The journal-native arbiter (coloop grant, instruct-injection) is deferred to a follow-up.\", \"verification\": [\"4/4 cross-process lock tests: mutual exclusion, wait-then-proceed, dead-holder reclaim, with_lock release\", \"end-to-end on a local core build: two concurrent 'kungfu lock run' serialize; lock status is empty before and after\", \"Episode audit read back from the journal as coordination.lock.wait/acquire/release\", \"ruff format+lint clean; adr-audit structural pass; check-docs pass\"]} -->",
          "author": "dongkeren",
          "createdAt": "2026-07-13T10:08:27Z",
          "mergedAt": "2026-07-13T10:36:24Z",
          "additions": 688,
          "deletions": 0,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 85,
          "url": "https://github.com/kungfu-systems/build-images/pull/85",
          "title": "chore(release): promote v1.2 cache alpha",
          "body": "## Summary\n\nPromote the registry-backed BuildKit cache implementation through the protected v1.2 alpha channel.\n\n## Canary expectations\n\n- all five cache refs are initially absent\n- the image family completes a cold build and all existing smoke checks\n- protected promotion writes one isolated cache ref per image\n- exact image digest evidence and Release Passport remain authoritative\n\n## Version impact\n\nKFD-1: patch.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T10:35:35Z",
          "mergedAt": "2026-07-13T10:37:31Z",
          "additions": 293,
          "deletions": 85,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 86,
          "url": "https://github.com/kungfu-systems/build-images/pull/86",
          "title": "chore(images): accept v1.2.3-alpha.0 digests",
          "body": "## Summary\n\n- record the five public image digests published by the first registry-cache alpha canary\n- bind the lock to promotion run 29243481799 and its source merge\n- refresh KFD-1 and KFD-2 evidence hashes\n\n## Verification\n\n- `python3 scripts/verify-image-lock.py`\n- `pnpm run check`\n\n## Version impact\n\nKFD-1: patch. This refreshes reviewed consumer inputs without changing an image contract.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T10:49:32Z",
          "mergedAt": "2026-07-13T10:51:36Z",
          "additions": 30,
          "deletions": 30,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 87,
          "url": "https://github.com/kungfu-systems/build-images/pull/87",
          "title": "chore(release): promote v1.2 cache warm alpha",
          "body": "## Summary\n\nPromote the accepted v1.2.3-alpha.0 digest lock through the protected v1.2 alpha channel to measure registry-cache reuse on a fresh runner.\n\n## Canary expectations\n\n- publish a new exact candidate rather than reuse alpha.0\n- import all five per-image cache manifests\n- preserve parent-image resolution and all image smoke checks\n- retain complete digest evidence and Release Passport assets\n\n## Version impact\n\nKFD-1: patch.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T10:51:55Z",
          "mergedAt": "2026-07-13T10:53:46Z",
          "additions": 30,
          "deletions": 30,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 774,
          "url": "https://github.com/kungfu-systems/kungfu/pull/774",
          "title": "feat(shifu): manage Conan source and binary caches",
          "body": "## Summary\n\nExtend the Shifu cache profile contract so Conan source acquisition and binary reuse are execution-scoped, reproducible, and independent of persistent user Conan configuration.\n\n## Changes\n\n- add child-scoped Conan remote policy with profile-owned persistent package/download storage and runner partition locking\n- pin RocksDB 6.29.5 to an immutable commit archive with SHA256 verification and an explicit public fallback boundary\n- add a three-platform Conan publisher that validates the detected toolchain, uploads exact package revisions, and fails closed on exact remote readback\n- keep receipts path-redacted and keep Buildchain limited to the opaque profile reference and digest\n- document the schema/runtime boundary and extend source acceptance coverage\n\n## Verification\n\n- `uv run --with ruff==0.15.20 --with mypy==1.20.2 --with clang-format==20.1.8 ./shifu check:source`\n- 60 source-acceptance contract tests passed\n- macOS arm64, Linux GCC 14 x64, and Windows MSVC x64 packages completed exact hosted upload/readback and warm reuse without recompilation\n- persistent user Conan remote configuration remained byte-identical across the rollout\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0001\"],\n  \"summary\": \"Extend the Shifu cache profile contract with isolated Conan policy, persistent host-local binary storage, immutable RocksDB source acquisition, and exact three-platform binary publication/readback\",\n  \"verification\": [\"fixed-tool ./shifu check:source passed\", \"60 source-acceptance contract tests passed\", \"Mac arm64 Linux GCC14 x64 and Windows MSVC x64 exact package revisions uploaded and warm-reused\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe repository contains only the public Shifu contract, immutable public source identity, runtime logic, and secret-free publisher boundary. Private cache endpoints and credentials remain inventory-controller concerns outside this repository.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T10:51:49Z",
          "mergedAt": "2026-07-13T10:58:04Z",
          "additions": 795,
          "deletions": 51,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 88,
          "url": "https://github.com/kungfu-systems/build-images/pull/88",
          "title": "fix(images): disable registry cache after canary",
          "body": "## Summary\n\n- restore the established cold `docker build` image-family path\n- remove registry-cache-only checks, test harness, and documentation\n- regenerate KFD123 witnesses without changing the stable contract lock\n\n## Evidence\n\nTwo consecutive fresh-runner alpha candidates preserved smoke, public digest verification, publish evidence, and Release Passport contracts, but the warm run did not reduce build cost:\n\n- cold cache-seeding alpha.0 `image.family`: ~6m42s\n- warm alpha.1 `image.family`: ~6m48s\n- warm promotion job: 8m12s versus 7m43s cold\n\nRelease-specific parent image digests invalidated the expensive child layers in `node24-pnpm`, `latex-pdf-builder`, and `native-linux-x64`; registry import/export then added overhead. Keeping this optimization would make the release path slower.\n\nEvidence runs:\n- https://github.com/kungfu-systems/build-images/actions/runs/29243481799\n- https://github.com/kungfu-systems/build-images/actions/runs/29244430693\n\n## Validation\n\n- `pnpm run check`\n- KFD123 passed\n- stable Buildchain contract lock unchanged\n- DCO signed off",
          "author": "dongkeren",
          "createdAt": "2026-07-13T11:07:40Z",
          "mergedAt": "2026-07-13T11:09:39Z",
          "additions": 85,
          "deletions": 293,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 89,
          "url": "https://github.com/kungfu-systems/build-images/pull/89",
          "title": "promote: dev/v1/v1.2 to alpha/v1/v1.2",
          "body": "Promote the canary rollback from `dev/v1/v1.2` to `alpha/v1/v1.2`.\n\nThis restores the established cold image-family build path after two registry-cache alpha candidates failed the cost threshold. The promotion must still run the full image family, smoke, public digest verification, publish evidence, GitHub release, and Release Passport gates.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T11:10:05Z",
          "mergedAt": "2026-07-13T11:11:50Z",
          "additions": 85,
          "deletions": 293,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 772,
          "url": "https://github.com/kungfu-systems/kungfu/pull/772",
          "title": "feat(core): expose generic frame decode + checksum on all membranes (ADR-0078, partial)",
          "body": "## Expose the generic self-describing primitives on all membranes (ADR-0078, partial)\n\nGrow the embedding surface to ABI v3 so any consumer — Python, Rust, cross-process,\nor a `libkungfu`-only C++ user — can **decode** a `.kungfu` frame (schema-driven,\nvia the ADR-0039 reflection seam) and **verify** its whole-frame checksum, without\nre-implementing FlatBuffers reflection or the checksum in an outer ring.\n\nThis lands ADR-0078 **Decision 1** (the line: libkungfu owns the minimal generic\nmaintenance/self-describing closure; domains stay in outer rings) and **Decision 2**\n(expose the two primitives), on three membranes:\n\n- **pybind**: `decode_flatbuffer_payload_json(schema_bfbs, payload)` + `checksum_frame(header, payload, algo)`.\n- **embedding membrane C ABI v3**: `decode_frame_json` + `frame_checksum`, behind a\n  new `KF_EMBEDDING_CAP_GENERIC_CODEC`, appended after a byte-identical v2 prefix\n  (v1/v2 callers unchanged; continues the ADR-0071 grow-the-membrane pattern).\n- **`kungfu-embedding` Rust wrapper**: mirrors the v3 table (`ApiV3`, negotiate\n  v3→v2→v1, `Context::decode_frame_json` / `frame_checksum`).\n\n**Decision 3 (outer-ring de-duplication) is deferred** to a follow-up go card, so\n`implementation_status` moves `not-started → partial`.\n\n### Validation (local, three hosts)\n\n- **Mac (arm64)**: membrane v3 spike host exit 0 (v3 negotiation + capability + non-null\n  pointers); pybind smoke PASSED — `decode_flatbuffer_payload_json` decodes a real\n  ActionEnvelope frame to structured JSON, `checksum_frame` executes, corrupt frame rejected.\n- **Linux (x86_64, agent-120)**: same — host exit 0 + pybind smoke PASSED; checksum\n  values byte-identical to Mac.\n- **Rust**: `cargo test` 10 passed on arm64 / Linux x86_64 / Windows x86_64; the\n  compile-time `ApiV3 == 104` layout guard confirms the C ABI table layout on all three.\n- Windows (DARKHERO) full-build spike/pybind is tracked with the follow-up (its core\n  build is blocked by the RocksDB source build needing GitHub, unreachable from that host).\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"ADR-0078\"],\"summary\":\"Expose the two generic self-describing primitives (schema-driven frame decode + whole-frame checksum) on pybind, the embedding membrane C ABI v3, and the kungfu-embedding Rust wrapper (ADR-0078 Decision 2). Decision 3 (outer-ring de-dup) is deferred to a follow-up go card.\",\"verification\":[\"Mac (arm64): membrane v3 spike host exit 0 — v3 negotiation + CAP_GENERIC_CODEC + non-null decode/checksum pointers; pybind generic-primitive smoke PASSED (decode_flatbuffer_payload_json decodes a real ActionEnvelope frame to structured JSON; checksum_frame executes; corrupt frame rejected).\",\"agent-120 (Linux x86_64): same — membrane v3 host exit 0 + pybind smoke PASSED; checksum values byte-identical to Mac (cross-platform determinism).\",\"Rust kungfu-embedding: cargo test 10 passed on arm64 / Linux x86_64 / Windows x86_64; compile-time ApiV3 == 104 layout guard confirms the C ABI table layout on all three targets.\",\"document-metadata-contract.mjs exit 0.\"]}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-13T10:28:52Z",
          "mergedAt": "2026-07-13T11:14:03Z",
          "additions": 621,
          "deletions": 23,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 775,
          "url": "https://github.com/kungfu-systems/kungfu/pull/775",
          "title": "feat(gui): make profile home drive product navigation",
          "body": "## Summary\n\nMake the focused Profile Suite drive the product home and primary navigation, with Mission Control as the built-in first-screen profile.\n\n## Changes\n\n- Add experience.homeView to the Profile Suite contract and loader projections.\n- Render only Profile Home, Agent Console, Profiles, and Skills in the primary activity rail.\n- Move Facts to Tools and Config, Journal, Rewind, and Runtime Status to Developer surfaces.\n- Preserve command-palette/deep-link access and keep focus independent from activation.\n- Add contract, navigation, Python parity, and documentation coverage.\n\n## Verification\n\n- ./shifu test:kfx-profile-suite\n- ./shifu docs:check\n- ./shifu build:app\n- ./shifu exec tsc -p framework/kfx/tsconfig.json --noEmit\n- isolated macOS Electron runtime smoke\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0069\"],\n  \"summary\": \"Profile Suite metadata now selects the product home while the shell projects a bounded four-entry primary navigation and preserves lower-frequency routes.\",\n  \"verification\": [\"KFX Profile Suite contract tests\", \"GUI navigation projection tests\", \"Python contract parity tests\", \"documentation contracts\", \"macOS Electron build and isolated runtime smoke\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated because behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T11:37:58Z",
          "mergedAt": "2026-07-13T11:43:36Z",
          "additions": 619,
          "deletions": 137,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 90,
          "url": "https://github.com/kungfu-systems/build-images/pull/90",
          "title": "feat(images): add selective publish planner",
          "body": "## Summary\n\n- extend the image DAG resolver with fail-closed changed-path selection\n- select direct image changes plus the downstream dependency closure\n- conservatively rebuild the full family for manifests, release tooling, Buildchain metadata, workflows, empty baselines, and unknown paths\n- add CLI-level fixtures for the required image selection matrix and refresh KFD witnesses\n\n## Publish boundary\n\nThe planner is intentionally not connected to lifecycle.publish. Cross-version OCI reuse remains blocked on buildchain#1151 and buildchain#1153 so the release transaction and Release Passport can prove post-publish family completeness and per-artifact reuse provenance. Full-family publication remains unchanged.\n\n## Verification\n\n- pnpm run check\n- python3 scripts/test-selective-publish-plan.py\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-13T12:06:31Z",
          "mergedAt": "2026-07-13T12:08:13Z",
          "additions": 386,
          "deletions": 65,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1152,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1152",
          "title": "feat(gates): orchestrate Shifu profiles",
          "body": "## Summary\n- add a project-neutral reusable Shifu Gate profile workflow with capability-aware runner planning\n- validate and aggregate source-bound Shifu receipts without owning consumer gate ids or policy\n- bind qualifying Gate aggregate evidence into release-candidate and final Release Passport provenance\n- publish the workflow/manual in Buildchain generated contract and site facts\n\n## Validation\n- `pnpm run check` (561 tests)\n- real Shifu execution fixture: Buildchain plan digest matched the qualifying Shifu receipt digest\n- `actionlint` via `pnpm run check:workflows`\n\n## Canary boundary\nThe outer reusable-workflow topology still requires a trusted downstream workflow-dispatch canary; that follows this PR branch before merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T10:30:15Z",
          "mergedAt": "2026-07-13T12:19:32Z",
          "additions": 2047,
          "deletions": 74,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 778,
          "url": "https://github.com/kungfu-systems/kungfu/pull/778",
          "title": "fix(core): support fmt on AppleClang 21 C++23",
          "body": "## Summary\n\nRestore macOS Product builds under the current C++23 toolchain and keep the generated Python runtime surface aligned with the native bindings.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- disable fmt 10.2.1's broken consteval parser only for AppleClang 21 C++ targets\n- apply the compatibility flag to production and native test targets\n- refresh the generated runtime stub for the current frame checksum and FlatBuffers decode bindings\n\n## Verification\n\n- `./shifu rebuild:core`\n- `./shifu check:source`\n- `./shifu test:mmap`\n- `./shifu test:runtime-errors` with `UV_PROJECT_ENVIRONMENT` pointing to the pinned Python 3.13 environment\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This compatibility fix preserves the existing C++23 and runtime API contracts.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T12:26:56Z",
          "mergedAt": "2026-07-13T12:28:23Z",
          "additions": 14,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 773,
          "url": "https://github.com/kungfu-systems/kungfu/pull/773",
          "title": "ci(gates): publish profile-controlled dev patrol",
          "body": "## Summary\n- move Kungfu's standing dev patrol onto the generic Buildchain Shifu Gate profile workflow\n- keep the concrete Gate inventory and dev policy in Kungfu's `shifu.gates.json`\n- expand `dev-patrol` across the three `kungfu-v4-self-hosted` runner capabilities\n- pin the reusable workflow to immutable Buildchain dev commit `29a3daaf5417b138683f99a031268afd6efa9afd`\n- remove the temporary PR canary after publishing the standing patrol binding\n\n## Canary evidence\nBuildchain #1152 merged first after its repository checks and independent approval. Consumer canary run `29245122385` did **not** qualify and remains failure evidence:\n\n- Gate plan: passed\n- Linux x64: Gate execution completed and uploaded a receipt, then the qualification enforcement step failed\n- macOS ARM64: failed\n- Windows x64: the self-hosted runner was restored, but the assigned job hit an Actions acquire-job TLS/session failure and remained a zero-step assignment; cancellation was requested\n\nThe operator's explicit release policy for this goal was to publish immediately after the Windows attempt ended, regardless of success or failure. This PR therefore publishes the control-plane wiring without representing the canary as green. The standing patrol remains fail-closed and will preserve future receipts/results as the diagnostic surface.\n\n## Validation\n- full repository pre-commit gate\n- `actionlint .github/workflows/buildchain-validate.yml .github/workflows/dev-verify-patrol.yml`\n- `node scripts/check-kungfu-gate-catalog.mjs`\n- `node --test scripts/check-kungfu-gate-catalog.test.mjs`\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Publish Buildchain-owned Shifu Gate profile orchestration as Kungfu's standing dev patrol\",\n  \"verification\": [\"actionlint .github/workflows/buildchain-validate.yml .github/workflows/dev-verify-patrol.yml\", \"node scripts/check-kungfu-gate-catalog.mjs\", \"node --test scripts/check-kungfu-gate-catalog.test.mjs\"]\n}\n-->\n\n## Governance risk check\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis stage publishes Gate orchestration and qualification evidence wiring. It does not change branch protection or bypass release admission.\n\n## Checklist\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\nSigned-off-by: Keren Dong <[email-redacted]>\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T10:38:25Z",
          "mergedAt": "2026-07-13T12:31:16Z",
          "additions": 66,
          "deletions": 54,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1154,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1154",
          "title": "feat(release): promote Shifu Gate control plane to alpha",
          "body": "## Release intent\n\nPromote the reviewed generic Shifu Gate profile orchestration from `dev/v2/v2.12` to the supported v2 alpha channel, together with the already-reviewed release Patrol hardening currently on dev.\n\n## Included capability\n\n- consume a project-owned `shifu gate plan` without hard-coding consumer Gate IDs\n- derive deterministic cross-platform runner matrices from declared capabilities\n- execute fail-closed required/advisory Gate plans and upload source-bound receipts\n- aggregate per-platform evidence into stable profile outputs for release admission\n- separate lightweight planning argv from project execution wrappers\n- preserve existing Buildchain workflows as the rollback path\n\n## Qualification and disclosed failure evidence\n\n- implementation PR #1152 merged with all protected Buildchain checks passing\n- fixture tests cover deterministic planning, unsupported/skip semantics, receipt binding, and aggregate failure propagation\n- Kungfu consumer PR #773 merged the standing `dev-patrol` binding pinned to immutable Buildchain dev commit `29a3daaf5417b138683f99a031268afd6efa9afd`\n- consumer canary run `29245122385` proved planning, but did **not** qualify: Linux/macOS failed and Windows hit an Actions acquire-job TLS/session failure after the managed runner was restored\n- publication proceeds under the operator's explicit publish-after-Windows policy; no canary failure is represented as a pass\n\n## Validation\n\n- Buildchain PR #1152 protected checks: pass\n- Kungfu PR #773 protected checks: pass\n- Buildchain repository test suite: pass\n- reusable workflow and fixture actionlint/schema checks: pass\n\nSigned-off-by: Keren Dong <[email-redacted]>\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T12:32:45Z",
          "mergedAt": "2026-07-13T12:34:46Z",
          "additions": 2111,
          "deletions": 81,
          "changedFiles": 35
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 779,
          "url": "https://github.com/kungfu-systems/kungfu/pull/779",
          "title": "fix(shifu): harden cache doctor probes",
          "body": "## Summary\n\nEliminate transient Python index false negatives in `shifu cache doctor --probe` while preserving fail-closed diagnostics for persistent failures.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add optional same-origin per-service probe policy to the Shifu cache profile schema;\n- probe devpi Python indexes through the lightweight `+api` root, with a five-second floor and bounded retry;\n- record redacted target class, timeout, attempts, status, and duration in diagnostic evidence;\n- validate the policy in the dependency-free runtime and document the compatible KFD-1 addition.\n\n## Verification\n\n- `SHIFU_CACHE_ACTIVE=1 ./shifu check:source` on macOS: pass, including 98 source-acceptance tests;\n- `SHIFU_CACHE_ACTIVE=1 ./shifu check:source` on Ubuntu: pass, including 98 source-acceptance tests;\n- DARKHERO read-only live validation: three healthy runs, Python probe `provider-health`, HTTP 200 in 5 ms, projected config hash and Git status unchanged;\n- Atlas profile projection dry-run and cross-repository inventory test: pass for development and self-hosted-runner revision 4.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0001\"],\n  \"summary\": \"Deliver policy-aware bounded cache diagnostics without changing profile authority or Buildchain boundaries\",\n  \"verification\": [\"macOS and Ubuntu source gates\", \"DARKHERO read-only doctor validation\", \"Atlas projection dry-run\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T12:29:57Z",
          "mergedAt": "2026-07-13T12:40:08Z",
          "additions": 405,
          "deletions": 41,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1156,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1156",
          "title": "Release v2.12.2 from qualified v2.12.2-alpha.1",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.12.2-alpha.1`\n- Candidate SHA: `632cd3ab363910c83a906ac2f7427452a76cd646`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.12`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T12:40:18Z",
          "mergedAt": "2026-07-13T12:41:34Z",
          "additions": 2271,
          "deletions": 114,
          "changedFiles": 45
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1155,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1155",
          "title": "feat(publish): preserve OCI family provenance",
          "body": "## Summary\n\n- bind OCI artifact refs and digests after the exact publish version is selected\n- preserve built/reused content provenance separately from current release coordinates\n- carry artifact provenance through Release Passport and additive contract-lock surfaces\n- fail closed into repair_required on digest or provenance conflicts\n\nCloses #1151\nCloses #1153\n\n## Validation\n\n- `pnpm run check` (566 tests passed)\n- `git diff --check HEAD^ HEAD`\n\n## Governance\n\n- [x] no secret or provider-policy bypass\n- [x] generated site and Action bundles are committed\n- [x] release evidence surface change is additive",
          "author": "dongkeren",
          "createdAt": "2026-07-13T12:38:01Z",
          "mergedAt": "2026-07-13T12:44:00Z",
          "additions": 971,
          "deletions": 138,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 780,
          "url": "https://github.com/kungfu-systems/kungfu/pull/780",
          "title": "fix(profile): bind declared home view",
          "body": "## Summary\n\n- accept the KFX `experience.homeView` field in the libkungfu Profile authority\n- require the declared home view to resolve to a Suite member\n- preserve the field in the normalized, content-bound Profile root\n\n## Verification\n\n- `./shifu rebuild:core`\n- native Profile lifecycle tests (Node and Python build variants)\n- `./shifu freeze && node framework/gui/scripts/gen-system-profile-kfd3.mjs`\n- `./shifu check:source`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix aligns the C++ Profile authority with the existing shared KFX experience contract without changing that contract.\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T12:41:31Z",
          "mergedAt": "2026-07-13T12:46:45Z",
          "additions": 25,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 781,
          "url": "https://github.com/kungfu-systems/kungfu/pull/781",
          "title": "ci(gates): pin patrol to stable Buildchain release",
          "body": "## Summary\n\n- pin the standing `dev-patrol` reusable workflow to immutable Buildchain stable release commit `0d5487b64cc4df52519e4b30492876f3819b9137` (`v2.12.2`)\n- correct the policy documentation from the retired single-Linux patrol to the current three-platform self-hosted matrix\n- record the rollout evidence and preserve the non-qualifying canary boundary\n- make explicit that unbound heavy Gates stay `off` until runner evidence and rollback are added\n- keep `local-changed` as non-qualifying local diagnosis, not a sixth remote publication profile\n\n## Release evidence\n\n- Buildchain PR #1152 merged the generic controller\n- Buildchain PR #1154 promoted it to alpha; `v2.12.2-alpha.1` published successfully\n- Buildchain Stable Candidate Patrol run `29250692558` froze and approved the exact candidate\n- Buildchain PR #1156 passed protected checks and merged to release\n- Buildchain promotion run `29250889040` published stable `v2.12.2`; floating `v2.12` and `v2` resolve to the same stable commit\n- Kungfu canary run `29245122385` remains explicitly non-qualifying; publication followed the operator's release-after-Windows decision and does not rewrite failures as passes\n\n## Validation\n\n- `node scripts/check-kungfu-gate-catalog.mjs`\n- `node --test scripts/check-kungfu-gate-catalog.test.mjs`\n- `actionlint .github/workflows/dev-verify-patrol.yml`\n- `KUNGFU_DOCS_MODULES=... node scripts/run-docs-check.mjs`\n- direct Biome check and `git diff --check`\n\nThe isolated worktree's commit hook reached its final `pnpm exec biome` step but `pnpm` attempted a direct install that the repository correctly rejects in favor of Shifu. The same local Biome binary passed, and PR CI is the authoritative clean-environment repetition.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-0004\"],\n  \"summary\": \"Complete the Gate control-plane rollout by pinning Kungfu to the stable Buildchain controller release\",\n  \"verification\": [\"node scripts/check-kungfu-gate-catalog.mjs\", \"node --test scripts/check-kungfu-gate-catalog.test.mjs\", \"actionlint .github/workflows/dev-verify-patrol.yml\"]\n}\n-->\n\n## Governance risk check\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\nSigned-off-by: Keren Dong <[email-redacted]>\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T12:51:23Z",
          "mergedAt": "2026-07-13T12:56:11Z",
          "additions": 52,
          "deletions": 10,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1159,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1159",
          "title": "fix(release): regenerate divergent reconciliation state",
          "body": "## Summary\n\n- regenerate version-state projections from the exact current dev checkout when stable release bookkeeping cannot fast-forward\n- preserve concurrent feature capabilities in the two-parent reconciliation commit\n- fail closed if the reconciliation checkout SHA no longer matches the live dev ref\n- refresh the stale site bundle currently blocking alpha promotion PR #1157\n\nCloses #1158\n\n## Validation\n\n- `pnpm run check` (566 tests passed)\n- divergent reconciliation fixture retains `oci-family-provenance` and prepares the correct next-alpha version\n- stale reconciliation checkout fixture defers post-release bookkeeping without moving dev\n- generated Action and site bundles are committed\n\n## Governance\n\n- [x] protected channel updates remain PR- and check-gated\n- [x] no admin or branch-protection bypass was added\n- [x] reconciliation dependency install is scoped to stable release runs",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:01:27Z",
          "mergedAt": "2026-07-13T13:03:20Z",
          "additions": 397,
          "deletions": 115,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 783,
          "url": "https://github.com/kungfu-systems/kungfu/pull/783",
          "title": "fix(qualification): make native verification Windows-safe",
          "body": "## Summary\n\nMake the native Core verification and durability qualification paths honor Kungfu's existing compile contract and Windows process environment semantics. This closes the Windows evidence gap without changing the Shifu protocol, global cache configuration, or the declared durability envelope.\n\nThis PR supersedes #782 by replaying the same reviewed patch set directly on the latest protected dev head after dev advanced. It avoids bypassing the local baseline gate or force-pushing the reviewed branch.\n\n## Related issue\n\nAtlas goal 2026-07-12-kungfu-durability-qualification.\n\n## Changes\n\n- apply `kungfu_compile_contract` to native Core test and qualification targets so MSVC receives the repository UTF-8 contract\n- invoke `.cmd` Shifu entrypoints through `cmd.exe` on Windows\n- preserve Windows' case-insensitive `Path` environment key for Episode workers\n- add focused Node tests for the Windows invocation and environment behavior\n- update ADR-0068's implementation projection while retaining its explicit non-claims\n\n## Verification\n\n- no-controller-cache `./shifu check:source` passed at `1176734844f83288f1e2e43ffe2187f74cf8ea56` on `dev/v4/v4.0@2cc2975db41c3ffe8b3eeb4562e0ed763d03057c`\n- macOS/APFS Apple Clang 21 arm64 C++23: no-controller-cache `./shifu build:core`, `durable_group` passed, `durable_sync` passed at the original candidate `c71d67db`\n- Linux/ext4 GCC 14 x64 C++23: no-controller-cache `./shifu build:core`, `durable_group` passed, `durable_sync` passed at the original candidate `c71d67db`\n- Windows/NTFS MSVC 19.51 x64 C++23: no-controller-cache `./shifu.cmd build:core`, `durable_group` passed, `durable_sync` passed at the original candidate `c71d67db`\n- all six retained reports qualify only the process envelope; `power_loss_qualified=false` and `production_profile_eligible=false`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Close the Windows process-crash qualification gap and retain honest power-loss and production non-claims\",\n  \"verification\": [\"Build-free Shifu source gate passed at 11767348\", \"Mac, Linux, and Windows local Shifu builds passed at c71d67db\", \"Six local durable_group and durable_sync reports passed at c71d67db\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe evidence remains local-only and revision-bound. This PR does not modify GitHub workflows, Buildchain configuration, Shifu protocol, global cache configuration, or release artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:02:30Z",
          "mergedAt": "2026-07-13T13:04:40Z",
          "additions": 106,
          "deletions": 26,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1157,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1157",
          "title": "feat(release): promote OCI family provenance to alpha",
          "body": "## Summary\n\n- promote post-publish OCI family requirements to the v2.12 alpha channel\n- preserve built/reused content provenance in publish evidence, contract lock, and Release Passport\n- fail closed before ref movement when artifact verification conflicts\n\n## Verification\n\n- `pnpm run check`\n- 566 unit tests passed\n- feature PR #1155 checks passed\n\nRefs #1151\nRefs #1153",
          "author": "dongkeren",
          "createdAt": "2026-07-13T12:46:04Z",
          "mergedAt": "2026-07-13T13:05:21Z",
          "additions": 1238,
          "deletions": 172,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 787,
          "url": "https://github.com/kungfu-systems/kungfu/pull/787",
          "title": "fix(gates): invoke Shifu profile directly",
          "body": "## Summary\n\n- invoke the Shifu Gate profile with the project launcher directly on Linux, macOS, and Windows\n- rely on the Buildchain-projected cache profile environment instead of nesting `cache apply -- ./shifu`\n- make the workflow-binding meta gate require the structured direct argv\n\n## Failure evidence\n\nDev patrol run `29251773895` proved the nested argv was deterministically invalid after checkout succeeded:\n\n- Linux/macOS: `ERR_PNPM_RECURSIVE_EXEC_FIRST_FAIL Command \"gate\" not found`\n- Windows: `'.' is not recognized as an internal or external command`\n- all three execution artifacts recorded `runStatus=1`, `validationStatus=1`, and `receipt=null`\n\n## Verification\n\n- `node scripts/check-kungfu-gate-catalog.mjs`\n- `node --test scripts/check-kungfu-gate-catalog.test.mjs`\n- `actionlint .github/workflows/dev-verify-patrol.yml`\n- `KUNGFU_DOCS_MODULES=/Users/dkr/Worktrees/kungfu/feature/shifu-gate-catalog-docs/node_modules ./shifu docs:check` (59 tests)\n- commit hook passed all scoped Gate/docs checks; final unrelated baseline KFD witness check reported existing stale `.buildchain/kfd/kfd-1/contract-world.witness.json`, so the already-validated commits used `--no-verify`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bugfix corrects the consumer command composition for the already-implemented Shifu Gate control-plane contract without changing that contract.\"\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:31:03Z",
          "mergedAt": "2026-07-13T13:34:16Z",
          "additions": 4,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1161,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1161",
          "title": "feat(publish): support exact artifact ref templates",
          "body": "Closes #1160\n\n## Summary\n- expand a constrained `ref_template` after Buildchain selects the exact release version\n- export and validate the resolved exact ref through publish evidence, transaction state, and Release Passport\n- reject ambiguous, unsupported, and unexpanded templates before `lifecycle.publish`\n- publish the additive capability in the Buildchain contract world and generated site bundle\n\n## Verification\n- `pnpm run check` (569/569 tests)\n- alpha occupied-version selection resolves `v1.0.0-alpha.1`\n- stable selection resolves `v1.0.0`\n- invalid templates do not execute lifecycle publish",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:24:33Z",
          "mergedAt": "2026-07-13T13:34:22Z",
          "additions": 229,
          "deletions": 64,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1162,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1162",
          "title": "feat(release): promote exact artifact ref templates to alpha",
          "body": "## Summary\n\n- promote exact post-selection artifact ref templates to the v2.12 alpha channel\n- preserve resolved prefixed refs in publish evidence, transaction state, Release Passport, and the contract world\n- reject ambiguous or unexpanded templates before lifecycle publish\n\n## Verification\n\n- `pnpm run check`\n- 569 unit tests passed\n- feature PR #1161 checks passed across Linux, macOS, and Windows\n\nRefs #1160",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:34:58Z",
          "mergedAt": "2026-07-13T13:38:04Z",
          "additions": 229,
          "deletions": 64,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 788,
          "url": "https://github.com/kungfu-systems/kungfu/pull/788",
          "title": "fix(core): preserve RocksDB source archive type",
          "body": "## Summary\n\nGive the RocksDB Conan source download an explicit `.tar.gz` filename. The codeload URL ends in a commit hash, so Conan otherwise saves the valid gzip archive without an extension and attempts ZIP extraction, producing the same `BadZipFile` failure on macOS, Linux, and Windows.\n\nThis PR supersedes #784 by replaying the same validated patch and ADR projection directly on the latest protected dev head. It avoids bypassing the stale KFD witness exposed when attempting a local merge of the newly advanced dev baseline.\n\n## Changes\n\n- retain the existing source URL, SHA-256 verification, and `strip_root` behavior\n- name the temporary source object `rocksdb-source.tar.gz`\n- add a build-free regression assertion to the source acceptance suite\n- retain ADR-0068's explicit process-only evidence boundary\n\n## Verification\n\n- no-controller-cache `./shifu check:source` passed with 101 source-contract tests at `2fdb3c4c0bb6d982ffd2777ae2934371f99b996d`\n- pre-fix local Shifu `build:core` reproduced `BadZipFile: File is not a zip file` on macOS, Linux, and Windows\n- post-fix local no-controller-cache Shifu `build:core` passed at the identical code patch `1140d28d9f5e2ff17a22596d0fb71a8f1398c7bf` on:\n  - macOS arm64 / Apple Clang 21 / C++23\n  - Linux x86_64 / GCC 14 / C++23\n  - Windows x86_64 / MSVC 19.51 / C++23\n- all three builds used the existing host Conan cache through the normal Shifu command; no global cache configuration was changed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Repair the cross-platform Core source acquisition path required by durability qualification without expanding its evidence claims\",\n  \"verification\": [\"Build-free Shifu source gate passed with 101 tests at 2fdb3c4c\", \"Mac, Linux, and Windows local no-controller-cache Shifu Core builds passed for the identical source patch at 1140d28d\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe evidence remains local-only and revision-bound. This bugfix does not change workflows, Buildchain configuration, Shifu protocol, cache ownership, source URL, source digest, release artifacts, or the declared durability envelope.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:38:14Z",
          "mergedAt": "2026-07-13T13:40:57Z",
          "additions": 16,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 91,
          "url": "https://github.com/kungfu-systems/build-images/pull/91",
          "title": "feat(images): publish changed DAG closures with digest reuse",
          "body": "## Summary\n\n- build only directly changed images and their downstream DAG closure\n- reuse unchanged immutable digests with public manifest, platform, parent, label, and smoke verification\n- preserve a complete five-image Buildchain publish transaction and Release Passport with built/reused content provenance\n- accept reviewed images.lock.json updates directly from the durable GitHub Release evidence.json asset\n- lock Buildchain stable v2.12.2 and alpha v2.12.3-alpha.1 contract worlds\n\n## Validation\n\n- pnpm run check\n- 10 selective planner fixtures\n- 7 publish provenance fixtures, including Buildchain 2.12.3-alpha.1 contract round-trip\n- shellcheck scripts/build-image-family.sh scripts/publish-image-family.sh scripts/check-workflows.sh\n- anonymous GHCR manifest verification against the accepted v1.2.3-alpha.0 digest\n- Buildx carbon-copy dry-run proving --prefer-index=false preserves a single image manifest\n\n## Release boundary\n\nThis PR is safe to merge into dev/v1/v1.2, but release promotion remains intentionally fail-closed until [buildchain#1160](https://github.com/kungfu-systems/buildchain/issues/1160) publishes post-version-selection support for ref_template: v{version}. The first alpha after that upgrade must rebuild the complete family because publisher and provenance surfaces are global invalidators.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:31:19Z",
          "mergedAt": "2026-07-13T13:41:42Z",
          "additions": 2012,
          "deletions": 305,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 786,
          "url": "https://github.com/kungfu-systems/kungfu/pull/786",
          "title": "fix(shifu): reuse cache context across nested gates",
          "body": "## Summary\n\nFix nested Shifu task execution so one projected cache profile and one managed Conan lock are owned by the outer `gate run` boundary instead of being reacquired by task-backed gates.\n\n## Related issue\n\nAtlas dogfood: nested Shifu cache re-entry colliding with managed Conan storage.\n\n## Changes\n\n- make `gate run` auto-apply a projected cache profile once while keeping Gate inspection direct\n- distinguish inherited active cache state from the build-free source-acceptance bypass on POSIX, Windows, and native launchers\n- prevent profiles from injecting the internal bypass context and clear bypass when an explicit apply creates an active child\n- add deterministic outer-apply -> Gate task -> nested Shifu lock-lifecycle coverage while preserving independent concurrency fail-closed behavior\n- document the execution invariant in the Shifu cache and Gate ADR surfaces\n\n## Verification\n\n- `./shifu check:source` (101 source contract tests, TypeScript, Biome, docs)\n- pre-commit staged gate: Rust format, clippy workspace, and workspace unit tests\n- Ubuntu 192.168.100.222 isolated worktree: `./shifu gate run shifu.workspace --capability rust ...` (`pass`, including release build and smoke)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0001\", \"SHIFU-ADR-0004\"],\n  \"summary\": \"Close the nested cache re-entry stage by making Gate execution own one outer cache context while source acceptance remains explicitly cache-independent\",\n  \"verification\": [\"Mac source acceptance and Rust workspace gates\", \"Ubuntu shifu.workspace Gate release build\", \"GitHub macOS Ubuntu Windows Shifu CI\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:27:18Z",
          "mergedAt": "2026-07-13T13:43:51Z",
          "additions": 317,
          "deletions": 10,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 93,
          "url": "https://github.com/kungfu-systems/build-images/pull/93",
          "title": "chore(buildchain): adopt v2.12.3-alpha.2",
          "body": "## Summary\n\n- pin Buildchain v2.12.3-alpha.2 and its exact alpha contract world\n- refresh KFD-2/KFD123 evidence against the new contract digest\n- prove the Buildchain runtime resolves all OCI artifact refs from `v{version}` to an exact v-prefixed release tag\n\n## Validation\n\n- `pnpm install --frozen-lockfile`\n- `pnpm run check`\n- 10 selective planner fixtures\n- 8 publish provenance fixtures\n- KFD123 passed\n- Release Passport smoke passed\n\n## Release boundary\n\nAfter this PR merges, the first alpha canary must rebuild the complete five-image family because publisher/provenance changes are global invalidators. A second LaTeX-only canary will then prove one built image and four digest reuses.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:46:39Z",
          "mergedAt": "2026-07-13T13:48:52Z",
          "additions": 47,
          "deletions": 22,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1164,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1164",
          "title": "fix(runtime): resolve pull request merge refs",
          "body": "Closes #1163\n\n## Summary\n\n- resolve the current same-repository `refs/pull/N/merge` workflow shell ref to GitHub's authenticated current workflow SHA\n- keep explicit runtime override trust gates unchanged\n- reject malformed, unrelated, and cross-repository pull refs\n- align build, gate profile, release verify, web surface, paper release, and publication artifact runtime resolvers\n\n## Verification\n\n- `pnpm run check` (570/570 tests)\n- `bash scripts/check-workflows.sh`\n- static cross-workflow parity test\n- reproducer: Release - Verify run 29254330151 on #1162",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:44:24Z",
          "mergedAt": "2026-07-13T13:50:19Z",
          "additions": 84,
          "deletions": 9,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1165,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1165",
          "title": "chore(release): promote v2.12.3 alpha with runtime ref fix",
          "body": "## Summary\n\nPromote the current v2.12 development line to alpha after closing #1160 and #1163.\n\n## Included fixes\n\n- version-aware artifact `ref_template` resolution and exact Passport refs (#1160)\n- same-repository pull request merge-ref runtime resolution (#1163)\n\n## Validation\n\n- local `pnpm run check`: 570/570\n- protected Linux, macOS, and Windows build-surface checks passed on #1164\n\nThis PR intentionally uses the protected alpha promotion flow.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:50:47Z",
          "mergedAt": "2026-07-13T13:51:53Z",
          "additions": 84,
          "deletions": 9,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 94,
          "url": "https://github.com/kungfu-systems/build-images/pull/94",
          "title": "chore(release): promote selective publish canary to alpha",
          "body": "## Summary\n\nPromote the reviewed dev/v1/v1.2 state to alpha for the first selective-publisher canary.\n\nThis promotion includes:\n\n- changed-path plus image-DAG build planning\n- immutable digest reuse with complete provenance and public verification\n- Buildchain v2.12.3-alpha.2 exact artifact ref templates\n- KFD123 and alpha/stable contract locks\n- Release Passport plus GitHub Release evidence\n\n## Canary expectation\n\nThis first run must build all five images because publisher, workflow, and provenance surfaces are global invalidators. No digest reuse is accepted for this run. A later LaTeX-only promotion will prove one built image and four reused digests.\n\n## Validation\n\n- implementation PR #91 merged with dual-channel checks green\n- Buildchain alpha.2 adoption PR #93 merged with dual-channel checks green\n- exact `v{version}` resolution verified through Buildchain runtime\n- `pnpm run check` passed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:50:02Z",
          "mergedAt": "2026-07-13T13:52:04Z",
          "additions": 2354,
          "deletions": 301,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1166,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1166",
          "title": "fix(gates): resolve Windows batch entrypoints",
          "body": "## Summary\n- resolve explicit relative `.cmd`/`.bat` Gate commands against the source working directory before invoking `cmd.exe`\n- preserve PATH-resolved batch command behavior\n- add a platform-independent regression test for Windows command construction\n\n## Evidence\n- Kungfu dev patrol run 29254292905 reached the generic Gate adapter with `./shifu.cmd`, then Windows `cmd.exe` parsed the forward-slash relative path as `.`\n- `node --test tests/gate-profile.test.mjs`\n- `pnpm run check` (570 tests)\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:50:56Z",
          "mergedAt": "2026-07-13T13:57:55Z",
          "additions": 40,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1167,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1167",
          "title": "chore(release): promote Windows gate fix to v2.12.3 alpha",
          "body": "## Summary\n\nPromote the Windows batch-entrypoint Gate fix from #1166 into the v2.12 alpha channel.\n\n## Validation\n\n- `pnpm run check`: 570 tests\n- protected Linux, macOS, and Windows build-surface checks passed after updating onto the latest development head\n- Windows command construction regression coverage added\n\nThis PR uses the protected alpha promotion flow.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:58:53Z",
          "mergedAt": "2026-07-13T13:59:54Z",
          "additions": 40,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 97,
          "url": "https://github.com/kungfu-systems/build-images/pull/97",
          "title": "fix(release): backport dual-channel promotion router",
          "body": "## Summary\n\nBackport only the cross-line promotion workflow to the repository default branch, which is the authority GitHub loads for workflow_run events.\n\n- alpha targets use promote-buildchain-ref@v2-alpha\n- release and major-gate targets continue using @v2\n- v1.2 targets resolve the exact five-image requirement and fetch complete history\n- v1.1 targets retain their existing KFD paths and empty image requirement\n\n## Evidence\n\nPromotion run 29255626895 verified target alpha/v1/v1.2@ac4338e5, but loaded the default branch previous workflow and failed closed before registry mutation because the stable action exported the wrong artifact refs.\n\n## Validation\n\n- resulting promotion workflow is byte-identical to the reviewed v1.2 workflow in PR #95\n- pnpm install --frozen-lockfile\n- pnpm run check\n- git diff --check\n\nNo v1.1 image, package, lock, or release state is changed.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:59:58Z",
          "mergedAt": "2026-07-13T14:01:22Z",
          "additions": 39,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 95,
          "url": "https://github.com/kungfu-systems/build-images/pull/95",
          "title": "fix(release): route promotion by Buildchain channel",
          "body": "## Summary\n\n- use the Buildchain v2-alpha promotion action for alpha targets\n- retain the stable v2 action for release and major-gate targets\n- keep the workflow compatible with both v1.1 and v1.2 release lines\n- weld the dual-channel route and v1.2 artifact requirement into workflow checks\n\n## Canary finding\n\nPromotion run 29255626895 correctly failed closed before GHCR mutation because GitHub workflow_run loaded the default-branch workflow, whose stable v2 action could not export v-prefixed artifact refs. The verified target was alpha/v1/v1.2@ac4338e5.\n\n## Validation\n\n- pnpm run check\n- shellcheck scripts/check-workflows.sh\n- KFD123 passed\n- Release Passport smoke passed\n\nA matching workflow-only backport will be proposed to the repository default branch so workflow_run executes this routing logic.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T13:58:01Z",
          "mergedAt": "2026-07-13T14:01:59Z",
          "additions": 54,
          "deletions": 10,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 98,
          "url": "https://github.com/kungfu-systems/build-images/pull/98",
          "title": "chore(release): retry selective publisher alpha canary",
          "body": "## Summary\n\nPromote the reviewed dual-channel routing fix into alpha and retry the first full-family selective-publisher canary.\n\n## Previous attempt\n\nRun 29255626895 failed closed before registry mutation because workflow_run loaded the old default-branch stable action. PR #97 has now updated the default-branch workflow authority; PR #95 carries the same byte-identical workflow on v1.2.\n\n## Expected transaction\n\n- Buildchain promotion action resolves from v2-alpha\n- exact artifact refs are v-prefixed after version selection\n- all five images are built because workflow/publisher surfaces are global invalidators\n- Release Passport and GitHub Release evidence are emitted before refs move",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:02:37Z",
          "mergedAt": "2026-07-13T14:04:43Z",
          "additions": 54,
          "deletions": 10,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 789,
          "url": "https://github.com/kungfu-systems/kungfu/pull/789",
          "title": "docs(shifu): close cache ADR evidence debt",
          "body": "## Summary\n\nClose the stale documentation debt for the implemented Shifu cache contract and its Gate execution boundary by binding the accepted ADRs to their merged delivery and qualification evidence.\n\n## Related issue\n\nDocumentation closeout for the completed Shifu cache profile rollout.\n\n## Changes\n\n- mark SHIFU-ADR-0001 implemented and bind PRs 644 through 786 plus focused qualification tests\n- add the nested cache re-entry fix and runtime qualification to SHIFU-ADR-0004\n- self-review both current ADR projections and remove the obsolete SHIFU-ADR-0001 legacy evidence exemption\n\n## Verification\n\n- `node --test` focused metadata, ADR, cache runtime, uv, and Conan suites: 69 passed\n- `./shifu docs:check`: passed, including 59 documentation contract tests\n- `./shifu check:source`: passed, including 104 source acceptance tests, TypeScript, and Biome\n- ADR audit: structural findings 0; SHIFU-ADR-0001 and SHIFU-ADR-0004 have no remaining debt and are stable-admitted\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-0001\", \"SHIFU-ADR-0004\"],\n  \"summary\": \"Close the implemented Shifu cache and Gate cache-boundary ADRs with immutable delivery and qualification evidence\",\n  \"verification\": [\"focused cache and metadata tests\", \"deterministic documentation gate\", \"build-free source acceptance\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes only public ADR evidence metadata; it does not alter runtime behavior or release credentials.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:14:34Z",
          "mergedAt": "2026-07-13T14:17:24Z",
          "additions": 9,
          "deletions": 7,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1168,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1168",
          "title": "Release v2.12.3 from qualified v2.12.3-alpha.4",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.12.3-alpha.4`\n- Candidate SHA: `487fa51e64081e7417350d825d2cf2b31000d1ea`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.12`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:17:06Z",
          "mergedAt": "2026-07-13T14:18:43Z",
          "additions": 1564,
          "deletions": 220,
          "changedFiles": 39
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 100,
          "url": "https://github.com/kungfu-systems/build-images/pull/100",
          "title": "chore(buildchain): accept alpha baseline and adopt v2.12.3-alpha.4",
          "body": "## Summary\n\n- accept the reviewed `v1.2.3-alpha.4` five-image publish evidence as the new `images.lock.json` baseline\n- keep the image acceptance commit limited to `images.lock.json` and KFD-derived evidence so the selective planner can trust it\n- upgrade the alpha Buildchain package and contract lock to `v2.12.3-alpha.4` / `487fa51e64081e7417350d825d2cf2b31000d1ea`\n- refresh KFD123 evidence for the accepted image family and the new alpha contract\n\n## Verification\n\n- `pnpm install --frozen-lockfile`\n- `pnpm run check`\n- planner baseline: `eligible=true`, acceptance `d20213f12360f437e11ef3c1c1e71b55068b275a`\n- planner selection after Buildchain upgrade: full five-image rebuild\n- anonymous GHCR manifest checks matched all five `v1.2.3-alpha.4` evidence digests\n- Release Passport check report: `trust=pass`, transaction `complete`\n\nGoal: `2026-07-13-build-images-selective-publish`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:22:37Z",
          "mergedAt": "2026-07-13T14:24:38Z",
          "additions": 139,
          "deletions": 59,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1169,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1169",
          "title": "fix(gate): clear stale execution receipts",
          "body": "## Summary\n\n- clear the managed receipt, validation, and execution JSON files before every platform gate run\n- preserve unrelated diagnostics in the output directory\n- prevent a failed invocation from reusing a prior successful or stale receipt\n\n## Validation\n\n- `node --test tests/gate-profile.test.mjs` (7 passed)\n- `pnpm run check` (572 passed; action bundles built)\n- `git diff --check`\n\n## Runtime evidence\n\nKungfu patrol run 29255492750 rejected a stale macOS receipt from an earlier source SHA. This patch moves that invariant into the generic Buildchain gate-profile adapter so all consumers fail closed with a null current-run receipt instead of carrying stale evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:21:44Z",
          "mergedAt": "2026-07-13T14:25:18Z",
          "additions": 28,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1170,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1170",
          "title": "chore(release): promote gate receipt isolation to v2.12.4 alpha",
          "body": "## Summary\n\nPromote the current protected `dev/v2/v2.12` train to alpha after merging PR #1169. This train includes per-run managed gate receipt cleanup, preventing stale gate evidence from crossing executions.\n\n## Evidence\n\n- PR #1169 independently approved and merged after Verify plus Linux/macOS/Windows build-surface checks\n- local `pnpm run check`: 572 passed; action bundles built\n- v2.12.3 was already published immediately after the Windows adapter fix; this follow-up alpha starts the receipt-isolation patch release.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:26:14Z",
          "mergedAt": "2026-07-13T14:27:32Z",
          "additions": 28,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 102,
          "url": "https://github.com/kungfu-systems/build-images/pull/102",
          "title": "chore(release): canary Buildchain v2.12.3-alpha.4",
          "body": "## Summary\n\nPromote the reviewed image baseline and Buildchain `v2.12.3-alpha.4` contract lock to the alpha channel.\n\nThis canary is intentionally expected to rebuild the full five-image family because the Buildchain package and alpha contract lock are global publish inputs. Its Release Passport will become the clean baseline for the subsequent LaTeX-only `1 built + 4 reused` canary.\n\n## Evidence before promotion\n\n- image baseline: `v1.2.3-alpha.4`, publish run `29256526944`\n- baseline acceptance commit: `d20213f12360f437e11ef3c1c1e71b55068b275a`\n- Buildchain alpha release SHA: `487fa51e64081e7417350d825d2cf2b31000d1ea`\n- alpha contract digest: `sha256:0bbe1ae0f47f8aefd8c57b395a315655f479cfec16c31f7690824c6e2923c41d`\n- `pnpm run check`: pass\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:25:14Z",
          "mergedAt": "2026-07-13T14:27:57Z",
          "additions": 139,
          "deletions": 59,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1171,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1171",
          "title": "fix(release): reconcile human stable promotion",
          "body": "## Summary\n\n- preserve explicit human release authority while reconciling a stable release that already exists\n- accept the persisted `promotionRequest.authority=human` even when a later qualification refresh changes the transient decision reason\n- keep policy-driven candidates fail-closed unless qualification remains valid\n- regenerate the public Buildchain contract bundle\n\n## Runtime evidence\n\nStable patrol run 29258699636 failed while reconciling the already-published v2.12.3 from its human-authorized alpha candidate. The stable release was a real fact, but a later soak refresh had overwritten the transient decision reason.\n\n## Validation\n\n- stable candidate ledger/patrol tests: 13 passed\n- `pnpm run check`: 573 passed; action bundles built\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:41:00Z",
          "mergedAt": "2026-07-13T14:42:16Z",
          "additions": 29,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 104,
          "url": "https://github.com/kungfu-systems/build-images/pull/104",
          "title": "test(images): make repository-head fixture selective-aware",
          "body": "## Summary\n\n- accept the reviewed `v1.2.3-alpha.5` image family as an isolated baseline commit\n- remove the obsolete test assumption that every real repository HEAD must select a full rebuild\n- assert that each planned artifact action matches `selected_images`, while retaining the stronger all-selected invariant for full rebuilds\n\nThis does not weaken planner trust. `scripts/test-publish-provenance.py` remains a global invalidator, so this change intentionally requires one final full-family alpha canary before the LaTeX-only selective canary.\n\n## Verification\n\n- `pnpm install --frozen-lockfile`\n- `pnpm run check`\n- baseline `eligible=true`, acceptance `8a281830bc7e70221608cf2b78cfaab290085b4d`\n- current plan is intentionally full-family because the provenance test changed\n\nGoal: `2026-07-13-build-images-selective-publish`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:41:10Z",
          "mergedAt": "2026-07-13T14:43:08Z",
          "additions": 81,
          "deletions": 76,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1172,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1172",
          "title": "chore(release): promote stable reconciliation fix to v2.12.4 alpha",
          "body": "## Summary\n\nPromote protected dev after PR #1171. This train includes the final gate receipt isolation and stable-candidate human-authority reconciliation required to complete v2.12.4 without bypassing the control plane.\n\n## Evidence\n\n- PR #1171 independently approved and cross-platform checks green\n- local `pnpm run check`: 573 passed; generated contract current; action bundles built\n- failed patrol 29258699636 remains the fail-closed regression evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:43:04Z",
          "mergedAt": "2026-07-13T14:44:19Z",
          "additions": 29,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 105,
          "url": "https://github.com/kungfu-systems/build-images/pull/105",
          "title": "chore(release): canary selective-head fixture fix",
          "body": "Promote the alpha.5 lock acceptance and selective-aware repository-head fixture. This is intentionally a full-family canary because the provenance test remains a global invalidator. After its evidence is accepted, the next promotion is the pure LaTeX-only selective canary.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:43:20Z",
          "mergedAt": "2026-07-13T14:45:28Z",
          "additions": 81,
          "deletions": 76,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1173,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1173",
          "title": "Release v2.12.4 from qualified v2.12.4-alpha.2",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.12.4-alpha.2`\n- Candidate SHA: `bc90d39f5203d410ad38f4fafdc7079f3bf65fd6`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.12`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:54:02Z",
          "mergedAt": "2026-07-13T14:55:03Z",
          "additions": 73,
          "deletions": 21,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 790,
          "url": "https://github.com/kungfu-systems/kungfu/pull/790",
          "title": "feat(agent): connect native work console loop",
          "body": "## Summary\n\nConnect Mission Control work cards, installed Agent Runtime Profiles, Agent Console sessions, Episode-backed console identity, KFD-3 entrypoints, and public Profile actions into one product loop.\n\n## Related issue\n\nAtlas Goal: 2026-07-13-kungfu-native-work-agent-console-loop\n\n## Changes\n\n- add versioned WorkRef, Work Console Registry, Agent Console Envelope, and Agent Runtime Profile contracts\n- discover and configure Codex or Claude launch methods through Settings and CLI\n- launch bound work consoles from Go cards with recoverable tmux or explicit direct attempts\n- add tabs and two/three-pane presentation while preserving stable console identity\n- route system Mission Control mutations through public Profile intent plan, approve, and apply\n- expose equivalent KFD-3 agent entrypoints and regenerate Buildchain evidence\n\n## Verification\n\n- ./shifu check\n- ./shifu build\n- ./shifu test:agent-profile-sdk: 48 passed\n- ./shifu test:agent-console-contract: 7 passed\n- ./shifu docs:check\n- ./shifu product gui pack\n- installed CLI smoke for runtime discovery, preview/apply, defaults, and content-bound console envelopes\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0079\"],\n  \"summary\": \"Delivers the bounded Mac product loop joining Mission Control work, Agent Runtime Profiles, recoverable consoles, public Profile actions, and KFD-3 entrypoints.\",\n  \"verification\": [\"./shifu check\", \"./shifu build\", \"./shifu test:agent-profile-sdk\", \"./shifu test:agent-console-contract\", \"./shifu docs:check\", \"./shifu product gui pack\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nProvider discovery is limited to PATH and known executable locations with a bounded version probe. It does not read auth state, sessions, keychains, billing, quota, or private logs. Console transcripts and process exit are observations, never completion proof.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:50:18Z",
          "mergedAt": "2026-07-13T14:56:14Z",
          "additions": 4890,
          "deletions": 214,
          "changedFiles": 54
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 107,
          "url": "https://github.com/kungfu-systems/build-images/pull/107",
          "title": "test(latex): canary selective microtype image publish",
          "body": "## Summary\n\n- accept the reviewed `v1.2.3-alpha.6` full-family evidence as an isolated baseline\n- explicitly exercise scalable T1 microtype expansion in the LaTeX image smoke document\n- preserve the existing image contract and smoke command policy\n\n## Selective plan\n\n- baseline: `eligible=true`, acceptance `f75c37cfae7024cd8323db9a96534d8fa1a27b25`\n- changed path: `images/latex-pdf-builder/tests/smoke/paper/main.tex`\n- built: `latex-pdf-builder`\n- reused: `base-linux`, `kungfu-verify`, `node24-pnpm`, `native-linux-x64`\n\n## Verification\n\n- `pnpm install --frozen-lockfile`\n- `pnpm run check`\n- planner: `full_rebuild=false`, exactly one selected image\n\nGoal: `2026-07-13-build-images-selective-publish`\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:57:46Z",
          "mergedAt": "2026-07-13T14:59:56Z",
          "additions": 77,
          "deletions": 75,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 109,
          "url": "https://github.com/kungfu-systems/build-images/pull/109",
          "title": "chore(release): canary selective LaTeX publish",
          "body": "Promote the verified selective LaTeX fixture change to the alpha channel.\n\nExpected publish transaction: latex-pdf-builder built; base-linux, kungfu-verify, node24-pnpm, and native-pdm reused from the accepted v1.2.3-alpha.6 baseline.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T15:00:31Z",
          "mergedAt": "2026-07-13T15:02:37Z",
          "additions": 77,
          "deletions": 75,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 791,
          "url": "https://github.com/kungfu-systems/kungfu/pull/791",
          "title": "docs(adr): bind native console delivery PR",
          "body": "## Summary\n\nReplace the pre-rebase implementation commit anchor in ADR-0079 with the canonical merged delivery PR.\n\n## Changes\n\n- bind ADR-0079 staged implementation evidence to merged PR #790\n- avoid evidence drift when GitHub rebase merge rewrites commit SHAs\n\n## Verification\n\n- ./shifu docs:check\n- pre-commit staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0079\"],\n  \"summary\": \"Repairs the staged evidence anchor after the canonical rebase merge of PR #790.\",\n  \"verification\": [\"./shifu docs:check\", \"pre-commit staged gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T14:58:19Z",
          "mergedAt": "2026-07-13T15:06:24Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 110,
          "url": "https://github.com/kungfu-systems/build-images/pull/110",
          "title": "chore(images): accept v1.2.3-alpha.7 selective digests",
          "body": "Accept the reviewed v1.2.3-alpha.7 Release Passport into images.lock.json and refresh only the derived KFD evidence.\n\nEvidence: https://github.com/kungfu-systems/build-images/actions/runs/29260662451\n\nVerified transaction: one built image (latex-pdf-builder), four reused images, five public manifests and smoke checks passed, trust=pass, transaction=complete.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T15:12:33Z",
          "mergedAt": "2026-07-13T15:14:34Z",
          "additions": 50,
          "deletions": 50,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 792,
          "url": "https://github.com/kungfu-systems/kungfu/pull/792",
          "title": "chore(shifu): pin final stable gate runtime",
          "body": "## Summary\n\n- pin Kungfu dev heavy-gate patrol and gate workflow bindings to Buildchain v2.12.4 stable runtime\n- document the Windows batch adapter, per-run managed receipt cleanup, and human-authority stable-patrol reconciliation\n- regenerate KFD evidence projections against the final contract\n\n## Verification\n\n- `./shifu gate validate` (34 gates, 5 profiles)\n- `./shifu gate run gate.catalog`\n- `node --test scripts/check-kungfu-gate-catalog.test.mjs` (4 passed)\n- `./shifu kfd:buildchain:check`\n- staged commit hook: gate catalog/docs (59 tests), ADR evidence, and KFD evidence passed\n\nBuildchain stable runtime: `a6145efc210a961da0e5c63d7024d42061550f60` (v2.12.4).\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Pins an immutable stable gate runtime and refreshes generated KFD projections without changing an architecture decision.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR pins an immutable published Buildchain commit and updates only repository-controlled gate/release evidence.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-13T15:03:00Z",
          "mergedAt": "2026-07-13T15:16:27Z",
          "additions": 12,
          "deletions": 9,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 111,
          "url": "https://github.com/kungfu-systems/build-images/pull/111",
          "title": "chore(buildchain): adopt v2.12.4 alpha and stable contracts",
          "body": "Upgrade the consumer package to released @kungfu-tech/buildchain 2.12.4-alpha.2, accept its exact alpha contract lock, and accept the released v2.12.4 stable contract lock.\n\nThe current floating v2-alpha ref has already moved to an unreleased v2.12.5-alpha.0 preparation commit; this PR deliberately locks the last published alpha release and lets the workflow report subsequent compatible drift.\n\nKFD123 and the full repository check pass. The planner correctly selects a full five-image stable build because Buildchain package and contract metadata are global invalidators.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T15:20:56Z",
          "mergedAt": "2026-07-13T15:22:51Z",
          "additions": 25,
          "deletions": 25,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 113,
          "url": "https://github.com/kungfu-systems/build-images/pull/113",
          "title": "chore(release): canary Buildchain v2.12.4 contracts",
          "body": "Promote the accepted v1.2.3-alpha.7 selective evidence and the released Buildchain v2.12.4 alpha/stable contract locks through the standard alpha channel.\n\nExpected transaction: full five-image build, because Buildchain package and contract metadata are global provenance invalidators. This canary is the final prerequisite before alpha/v1/v1.2 -> release/v1/v1.2 stable promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T15:25:52Z",
          "mergedAt": "2026-07-13T15:27:40Z",
          "additions": 73,
          "deletions": 73,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 793,
          "url": "https://github.com/kungfu-systems/kungfu/pull/793",
          "title": "fix(gui): resolve active Profile root for Agent launch",
          "body": "## Summary\n\nResolve the active exact Mission Control Profile root through Profile Manager when launching an Agent Console from a Go card. Mission assessment remains a trust surface and is no longer an execution prerequisite.\n\n## Verification\n\n- ./shifu --filter @kungfu-tech/kfx-view-work-dashboard test\n- ./shifu check\n- ./shifu check:source\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix restores the existing Profile Manager authority boundary and does not alter an architecture contract\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)",
          "author": "dongkeren",
          "createdAt": "2026-07-13T15:36:42Z",
          "mergedAt": "2026-07-13T15:40:37Z",
          "additions": 147,
          "deletions": 23,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 115,
          "url": "https://github.com/kungfu-systems/build-images/pull/115",
          "title": "chore(release): reconcile v1.2 release history into alpha",
          "body": "Merge the existing v1.2.2 release history back into alpha before stable promotion.\n\nThe only conflicts were package.json and .buildchain/release-impact.json version fields; both deliberately retain the current alpha value 1.2.3-alpha.8. Full repository checks pass. No image, workflow, contract, or release surface is otherwise changed.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T15:40:40Z",
          "mergedAt": "2026-07-13T15:44:29Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 114,
          "url": "https://github.com/kungfu-systems/build-images/pull/114",
          "title": "chore(release): publish build-images v1.2.3",
          "body": "Promote the fully verified alpha/v1/v1.2 channel to stable.\n\nCanary evidence: v1.2.3-alpha.8, workflow run 29262435845, five built images, five public manifest and smoke checks passed, trust=pass, transaction=complete.\n\nThe stable transaction is expected to rebuild and verify all five images under the released Buildchain v2.12.4 stable runtime and accepted stable contract lock, then publish the primary Release Passport and GitHub Release.",
          "author": "dongkeren",
          "createdAt": "2026-07-13T15:38:42Z",
          "mergedAt": "2026-07-13T15:46:34Z",
          "additions": 2526,
          "deletions": 342,
          "changedFiles": 37
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 794,
          "url": "https://github.com/kungfu-systems/kungfu/pull/794",
          "title": "test(durability): retain institutional qualification evidence",
          "body": "## Summary\n\nComplete the retained qualification slice for ADR-0068 without expanding it into a production durability claim. The change retains the final three-platform process-crash reports, adds a disposable Linux/ext4 QEMU power-cut matrix, proves real ENOSPC fail-closed behavior, and records repeated whole-guest reopen plus offline backup/empty-device restore evidence.\n\n## Changes\n\n- retain six process-crash reports for macOS/APFS, Linux/ext4, and Windows/NTFS across `durable_group` and `durable_sync`\n- add a sentinel-protected power-cut fixture and a bounded 20-trial QEMU matrix covering every record/data-sync/checkpoint/directory-sync/receipt boundary\n- add a separate institutional QEMU harness for real filesystem ENOSPC, clean unmount and repeated whole-guest reopen, read-only fsck, and offline backup/restore\n- retain a machine-readable `Single-Host Institutional Profile v1` aggregate with source and raw-evidence SHA-256 bindings\n- enforce explicit non-claims for physical host restart, physical power loss, macOS/Windows device power cut, off-host backup, production eligibility, and absolute performance SLOs\n\n## Verification\n\n- `./shifu check:source` passed after the latest dev baseline merge: 115/115 source-contract tests, build-free\n- native `./shifu test:durable-ingest`, `./shifu test:crash-recovery`, and `./shifu test:projection-bootstrap` passed on agent-120 at `c7c0c680e`\n- `mvp-smoke-v1` Episode qualification passed 5/5 scenarios at `c7c0c680e`; all seven correctness violation counters are zero\n- disposable QEMU power-cut matrix passed 20/20 trials for `durable_group` and `durable_sync`\n- real ext4 ENOSPC produced `unknown/io_error` with no durable watermark; fresh reopen reported durable sequence 0 and classified the complete unacknowledged tail\n- three repeated whole-guest reopens recovered the exact sequence-1 frontier\n- offline backup and restored empty data device had identical SHA-256; read-only fsck passed before backup and after restore; fresh restore boot recovered sequence 1 with observed RPO 0 at the quiesced cut\n\nNo GitHub self-hosted workflow was dispatched for qualification. All device-tier evidence was produced through local Shifu on a sentinel-protected disposable QEMU workspace.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Retain process-crash and disposable Linux/ext4 device-tier evidence for ADR-0068 while preserving explicit physical-host, off-host-backup, production, and performance non-claims\",\n  \"verification\": [\"Build-free Shifu source gate passed with 115 tests at 7ddb217f\", \"Disposable QEMU power-cut matrix passed 20/20 trials\", \"Real ENOSPC, repeated whole-guest reopen, offline backup/restore, and Episode smoke evidence passed at c7c0c680e\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe retained aggregate is qualification evidence for one named disposable envelope. It does not activate a production profile or change release/publishing workflows.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T16:23:27Z",
          "mergedAt": "2026-07-13T16:33:57Z",
          "additions": 4324,
          "deletions": 17,
          "changedFiles": 58
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 795,
          "url": "https://github.com/kungfu-systems/kungfu/pull/795",
          "title": "feat(durability): expose evidence-bound product capability",
          "body": "## Summary\n\nExpose the retained ADR-0068 qualification result as one evidence-bound product capability without activating a production durability profile. C++ owns the semantic report; Python, Node, and `kungfu agent capabilities --json` are thin projections of that authority.\n\n## Changes\n\n- add `kungfu.durability.capability/v1` with per-profile availability, exact evidence digests, restore scope, trust assumptions, and explicit non-claims\n- report `durable_group` and `durable_sync` as test-fixture-only and fail closed with `production_eligible: false`\n- project the same C++ authority through Python, Node, and the agent capability CLI\n- bind the product report to retained three-platform process-crash and disposable Linux/ext4 QEMU evidence\n- update public qualification and known-limits documents to name the passed test envelope without implying physical-host, off-host-backup, or production qualification\n\n## Verification\n\n- `./shifu check:source` passed: 117/117 source-contract tests plus docs, TypeScript, Python, C++ format, lint, and type checks\n- local `./shifu build:core` passed with Apple Clang 21 / arm64 / C++23 using the existing host Conan cache through Shifu\n- `./shifu test:durability-contract` passed the C++ contract and Python/Node/agent-CLI projection checks\n- native Node binding suite passed 12/12 with `KUNGFU_REQUIRE_NATIVE=1`\n\nNo GitHub self-hosted workflow was dispatched for build or qualification. Heavy validation was performed locally through Shifu.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Expose retained ADR-0068 qualification as a fail-closed C++-owned capability projected consistently through Python, Node, and the agent CLI\",\n  \"verification\": [\"Build-free Shifu source gate passed with 117 tests\", \"Local Shifu Core build and C++/Python/Node durability contract passed\", \"Native Node binding suite passed 12/12\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe capability report is qualification metadata for a named test/disposable envelope. It does not change publishing, activate a production profile, or claim physical-host power-loss or off-host restore qualification.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T17:02:24Z",
          "mergedAt": "2026-07-13T17:05:17Z",
          "additions": 434,
          "deletions": 39,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 797,
          "url": "https://github.com/kungfu-systems/kungfu/pull/797",
          "title": "feat: complete ADR-0049 layer qualification",
          "body": "## Summary\n\n- complete the ADR-0049 seven-layer implementation and evidence-derived qualification harness\n- preserve exact format, native SDK, npm/PyPI/Cargo SDK, CLI/TUI, GUI, and assembled-product boundaries\n- keep public-registry-dependent rows honestly unpublished and perform no package or alpha release\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add fail-closed clean-install, compatibility, budget, and cross-platform qualification evidence\n- complete the Windows narrow storage ABI, SDK linkage, and cross-platform coordination lock backend\n- qualify display-less Linux AppImage startup without changing the shipped launch path\n- integrate the current `dev/v4/v4.0` durability, agent-console, cache, documentation, and ADR admission contracts\n- correct the merged KFX export boundary so agent-console helpers come from the capability entrypoint\n\n## Verification\n\n- exact three-host artifact candidate: `c7cda021377c4f08d3f8ba50cb65bf2d2f10a0da`\n- post-mainline merged tree: `3a46939d03dce93c65320fea9490f4bff5487dc4`\n- final linear candidate: `e6cbbffaed9a6cb95bce330e825916a5102f76a7` (implementation commit `409537aa42752388311705305a61a323f06ffa22`)\n- at `c7cda0213`, `./shifu check` passed: ADR-0049 harness 39/39, ADR-0068 7/7, SDK contracts 27/27\n- at `c7cda0213`, macOS ARM64 local `dist + release qualification` passed, exit 0\n- at `c7cda0213`, Windows x64 local `dist + release qualification` passed, exit 0\n- at `c7cda0213`, Linux x64 local `dist + release qualification` passed, exit 0; Episode 21/21 scenarios and 14/14 gates\n- at `3a46939d0`, post-mainline-merge build-free source gate passed: 118 source-acceptance tests, 61 documentation contract tests, TypeScript, Biome, Ruff, mypy over 129 source files, and C/C++ format\n- at `409537aa4`, the linear implementation commit's staged `./shifu check` passed, including Rust clippy and workspace tests plus KFD evidence validation\n- at `e6cbbffae`, the final linear build-free source gate passed: 118 source-acceptance tests, 61 documentation contract tests, TypeScript, Biome, Ruff, and mypy over 129 source files\n- `e6cbbffae` differs from the verified `3a46939d0` tree only by the ADR-0049 implementation commit pointer required for linear-history reachability\n- no GitHub heavy build was used for the final candidate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0049\"],\n  \"summary\": \"Complete all seven ADR-0049 product layers and their fail-closed qualification harness without publishing artifacts\",\n  \"verification\": [\"Full Shifu check and local macOS ARM64, Linux x64, and Windows x64 release qualification at c7cda0213\", \"Post-mainline-merge source and staged gates at 3a46939d0\", \"Linearized staged and source gates at 409537aa4 and e6cbbffae\"]\n}\n-->\n\n## Explicit non-release boundary\n\nThis PR merges implementation and qualification into `dev/v4/v4.0`. It does not publish npm, PyPI, or crates.io packages; it does not create a GitHub Release or alpha tag; and no publication workflow is invoked. Public-registry-dependent rows remain honestly unpublished.\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR changes release evidence and package surfaces but intentionally performs no publication or deployment side effect.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\nSigned-off-by: Keren Dong <[email-redacted]>\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T19:33:39Z",
          "mergedAt": "2026-07-13T19:35:16Z",
          "additions": 3821,
          "deletions": 256,
          "changedFiles": 91
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 798,
          "url": "https://github.com/kungfu-systems/kungfu/pull/798",
          "title": "fix(adr): point ADR-0049 evidence at the on-dev qualification commit",
          "body": "Correct ADR-0049's qualification evidence pointer.\n\nThe ADR-0049 layer-qualification work landed on `dev/v4/v4.0` as `360c1dfca` via a\nrebase merge, which rewrote the feature-branch hash. ADR-0049\n`implementation_commits` still referenced the pre-rebase hash `409537aa` — present\nonly on `feature/adr0049-seven-staged-release-linear-v2` and unreachable from the\nmainline — so the docs `adr-evidence-commit` gate rejects every new `dev/*` PR.\nThis points the evidence at the reachable on-dev commit (identical patch-id, no\ncontent change).\n\n<!-- kungfu-adr-release:v1 {\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"ADR-0049\"],\"summary\":\"Correct ADR-0049 qualification evidence to the reachable on-dev commit 360c1dfca; the pre-rebase feature hash 409537aa is unreachable from mainline and breaks the adr-evidence-commit docs gate for all new dev PRs.\",\"verification\":[\"git merge-base --is-ancestor 360c1dfca origin/dev/v4/v4.0 confirms the evidence commit is reachable from mainline\",\"360c1dfca has an identical patch-id to the unreachable 409537aa (same change, rebased hash)\",\"implementation_status unchanged (staged); one-line front-matter correction only\"]} -->",
          "author": "dongkeren",
          "createdAt": "2026-07-13T23:39:41Z",
          "mergedAt": "2026-07-13T23:43:39Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 799,
          "url": "https://github.com/kungfu-systems/kungfu/pull/799",
          "title": "feat(runtime): ADR-0077 live-runtime plumbing — peer react hook + coordinator page-precreate",
          "body": "ADR-0077 increment: the live-runtime plumbing the journal-native arbiter is\nbuilt on. No arbiter yet — this lands the two primitives and keeps the arbiter\nitself deferred to a follow-up.\n\n**What lands**\n\n- `feat(runtime)`: a Python-overridable peer react hook — `on_react` / `on_start`\n  trampolines plus `observe(carrier_type, callback)` and the `request_read_from`\n  / `request_read_from_public` / `request_write_to` / `get_public_writer`\n  bindings — so a live consumer written outside C++ can react to journal frames\n  without a bespoke C++ reactor subclass. No schema change.\n- `fix(journal)`: a coordinator-side correctness fix. `register_peer` read-joins\n  a freshly-registered peer's PUBLIC / SYNC / command journals before that peer\n  has opened its own writers, so the pages may not exist yet; the read-only page\n  load then failed with ENOENT and tore down the coordinator event loop. The\n  coordinator reader now creates the missing page (`coordinator_precreate`)\n  instead of failing — the \"create sync journal\" intent already at the register\n  site. Guarded so only the coordinator reader and only a genuinely missing page\n  take this path; normal readers and existing pages are unaffected. This path\n  had no exercised consumer since v4 removed the last live peer.\n\n**Validation (local core build)**\n\n- Nine native journal / durability / crash-recovery ctests pass.\n- A three-process live round-trip (coordinator + a writer peer + a reader peer)\n  delivers an action-envelope frame through the react hook — reader `observe`\n  callback fires with the decoded payload — with the coordinator surviving both\n  peers' registration purely on the page-precreate fix (no peer-side workaround).\n\n**Scope**\n\nThe arbiter peer that consumes the react hook (the in-memory lock table that\nreplaces the lock waiter's poll with a grant frame) and the instruct path are\ndeferred; they build directly on this plumbing. ADR-0077 stays `partial`.\n\n<!-- kungfu-adr-release:v1 {\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"ADR-0077\"],\"summary\":\"ADR-0077 live-runtime plumbing increment: a Python-overridable peer react hook (observe/on_react/on_start plus read/write bindings) and a coordinator page-precreate fix so a freshly-registered peer no longer crashes the coordinator when its PUBLIC/SYNC/command journals do not yet exist. The journal-native arbiter that consumes these is deferred to a follow-up.\",\"verification\":[\"nine native journal/durability/crash-recovery ctests pass on a local core build\",\"three-process live peer round-trip (coordinator + writer + reader) delivers a frame through the react hook with the coordinator surviving registration on the page-precreate fix alone, no peer-side workaround\",\"clang-format / ADR / docs commit gates pass; ADR-0077 implementation_status stays partial\"]} -->",
          "author": "dongkeren",
          "createdAt": "2026-07-13T23:47:21Z",
          "mergedAt": "2026-07-13T23:49:21Z",
          "additions": 61,
          "deletions": 6,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 800,
          "url": "https://github.com/kungfu-systems/kungfu/pull/800",
          "title": "fix(gui): recover profile and agent console setup",
          "body": "## Summary\n\n- expose the exact upgrade gate when a promoted factory Profile root supersedes the active workspace root\n- distinguish Agent detection loading, failure, and empty states in Agent Console\n- let the first explicit launch of a detected Agent remember it as the default runtime profile\n\n## Validation\n\n- 22 targeted Work Dashboard and Agent Runtime tests passed\n- ./shifu check:types passed\n- ./shifu dist:dir produced a verified macOS Product candidate\n- ./shifu check and check:source reach the pre-existing ADR-0049 evidence reachability failure on the current base; changed-file checks pass\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Restores existing Profile lifecycle and Agent Console behavior without changing an architectural decision.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-13T23:54:40Z",
          "mergedAt": "2026-07-13T23:58:01Z",
          "additions": 243,
          "deletions": 30,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 801,
          "url": "https://github.com/kungfu-systems/kungfu/pull/801",
          "title": "fix(core): sync generated peer runtime stubs",
          "body": "## Summary\n\n- sync the committed Python runtime stub with the five peer methods already exposed by the native binding\n- restore clean Product provenance after deterministic core rebuilds\n\n## Validation\n\n- generated diff reproduced identically across two full macOS Product builds\n- staged repository gates passed\n- prior exact merged-head Product build completed with verified KFD-3 receipt\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Synchronizes a generated projection with already-implemented runtime bindings without changing an architectural decision.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T00:08:58Z",
          "mergedAt": "2026-07-14T00:11:10Z",
          "additions": 10,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 116,
          "url": "https://github.com/kungfu-systems/build-images/pull/116",
          "title": "feat(pilots): add comparator Docker environments",
          "body": "## Summary\n\n- add immutable-input Aeron 1.52.2, ClickHouse 26.3.10.60 LTS, and PostgreSQL 18.4 disposable Compose profiles\n- add a shared neutral runner, explicit plan/execute boundary, scoped cleanup, and unscored evidence manifests\n- keep the Kungfu profile fail-closed until a formal product artifact, exact SHA-256, release evidence, and installer contract exist\n- run hosted normal, forced-restart, recovery, and export/restore entry smokes without changing the maintained image release family\n\n## Claim boundary\n\nThese Docker pilots provide functional and recovery-path qualification only. They are not performance evidence and do not replace designated native-host measurements or user installation-cost testing.\n\n## Validation\n\n- pnpm run check\n- shellcheck pilots/comparator/scripts/pilot.sh\n- bash pilots/comparator/scripts/pilot.sh plan aeron\n- bash pilots/comparator/scripts/pilot.sh plan clickhouse\n- bash pilots/comparator/scripts/pilot.sh plan postgres\n- verified the Kungfu plan fails closed with exit code 3\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider API, billing, quota, or usage-attribution changes\n- [x] No official hosted or managed service changes\n- [x] No official branding, package-name, release-identity, or domain changes\n- [x] Release evidence is only consumed as an immutable-input gate; no package publication or deployment",
          "author": "dongkeren",
          "createdAt": "2026-07-13T23:56:59Z",
          "mergedAt": "2026-07-14T00:21:54Z",
          "additions": 728,
          "deletions": 59,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 802,
          "url": "https://github.com/kungfu-systems/kungfu/pull/802",
          "title": "feat(core): call generic frame checksum + decode primitives from outer rings (ADR-0078)",
          "body": "## Summary\n\nADR-0078 Decision 3 (outer-ring de-duplication): `rewind` `BundleDecoder` decodes\nthrough the exposed `decode_flatbuffer_payload_json` primitive and `atlas` store\nchecksums call `checksum_frame` / `checksum_payload`, instead of re-implementing\nFlatBuffers reflection, crc32c/fnv1a, and the `frame_header` layout in Python.\nDomain folds stay in the outer rings.\n\n- `frame_header` opts into a read-only zero-copy Python buffer protocol.\n- `decode_json` gains `enum_as_int` (integer enums matching the three reflection\n  decoders) and `object_name` (decode a specific table, not just the root).\n- `implementation_status` stays `partial`: the cross-membrane enum-int symmetry\n  (C-ABI / Rust `decode_frame_json`) is a recorded follow-up.\n\n## Validation (three hosts, local — no CI reliance for heavy build)\n\n- Mac (arm64) + agent-120 (Linux x86_64) + DARKHERO (Windows x86_64): full build +\n  14 equivalence tests each, all green.\n- old-vs-native checksum parity (crc32c + fnv1a64); rewind field-by-field parity\n  vs the generated-accessor oracle; enum-as-int + absent-string-None contract.\n- Mac full python suite: 331 passed; the 11 failures are verified pre-existing on\n  base (dev/v4/v4.0), i.e. zero regression from this change.\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"ADR-0078\"],\"summary\":\"ADR-0078 Decision 3: rewind decode and atlas checksum de-duplicate onto the exposed generic primitives; domain folds stay in the outer rings.\",\"verification\":[\"Mac arm64 + agent-120 Linux x86_64 + DARKHERO Windows x86_64: full build + 14 equivalence tests each\",\"old-vs-native checksum parity (crc32c + fnv1a64); rewind field-by-field parity vs generated-accessor oracle; enum-as-int + absent-string-None contract\",\"Mac full python suite 331 passed; 11 failures verified pre-existing on base (zero regression)\"]}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T00:19:21Z",
          "mergedAt": "2026-07-14T00:23:00Z",
          "additions": 353,
          "deletions": 144,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 803,
          "url": "https://github.com/kungfu-systems/kungfu/pull/803",
          "title": "feat(qualification): close ADR-0049 Shifu gates",
          "body": "## Summary\n\nClose ADR-0049 as an implemented, first-class Shifu Gate qualification chain without performing any publication or dispatching the modified CI workflows.\n\n## Related issue\n\nADR-0049\n\n## Changes\n\n- register exact format, SDK, product-surface, and seven-row publication Gates in the alpha, release, and promotion profiles\n- emit digest-bound task evidence and unified source-bound Gate receipts\n- replace ad-hoc release aggregation wiring with evidence-root discovery and a fail-closed Gate action\n- bind the existing Buildchain and publication workflow code to the Gate catalog\n- add an independent public qualification contract and update ADR/product maturity navigation\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu docs:check`\n- `./shifu check:gate-catalog`\n- `./shifu gate validate --json`\n- local Gate plan inspection for `alpha-pr` and `release-promotion`\n- 18 focused Node tests for Gate evidence, artifact dispatch, release aggregation, and Buildchain install planning\n- changed-file Biome check\n\nThe modified GitHub workflows were not dispatched or treated as validation evidence. No alpha, npm, PyPI, crates.io, GitHub Release, tag, signing, or other publication action was performed.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0049\"],\n  \"summary\": \"Complete the Shifu Gate registry, profile, receipt, workflow-binding, documentation, and fail-closed aggregation closure for all seven layer products.\",\n  \"verification\": [\"Local build-free source acceptance passed\", \"Gate registry, catalog, plans, docs, and focused tests passed\", \"No CI workflow dispatch or publication was performed\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change modifies release-evidence and publication-workflow code but deliberately does not execute it. Publication remains separately authorized and guarded by the existing manual `execute` input and production environment.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T00:31:16Z",
          "mergedAt": "2026-07-14T00:33:39Z",
          "additions": 965,
          "deletions": 76,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 804,
          "url": "https://github.com/kungfu-systems/kungfu/pull/804",
          "title": "feat(gui): present workspace runtime as one foreground state",
          "body": "## Summary\n\nPresent the ordinary desktop runtime as one workspace-level foreground state instead of exposing supervisor and coordinator processes as separate user concerns.\n\nProcess health alone now reports Workspace online. The GUI reports Workspace ready only when explicit continuity evidence is available, preventing process presence from being mistaken for recovered live sessions.\n\n## Related issue\n\nADR-0077\n\n## Changes\n\n- add one shared workspace runtime presentation model for Electron main and renderer\n- collapse the tray and status bar process indicators into one Workspace status\n- retain raw supervisor and coordinator diagnostics in the advanced System Status view\n- accept an optional continuity state for ready, reconnecting, recovering, degraded, and needs-attention projections\n- add seven regression cases and include them in the KFX Profile Suite\n\n## Verification\n\n- ./shifu check:source\n- ./shifu check\n- ./shifu test:kfx-profile-suite\n- ./shifu build:app\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0077\"],\n  \"summary\": \"Project live-runtime and future agent continuity evidence into one workspace foreground status without exposing process topology in the ordinary GUI\",\n  \"verification\": [\"./shifu check:source\", \"./shifu check\", \"./shifu test:kfx-profile-suite\", \"./shifu build:app\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [ ] Documentation updated if behavior changed\n\nNo public documentation was changed because the advanced System Status diagnostics remain available and this PR only changes the ordinary shell projection.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T00:49:36Z",
          "mergedAt": "2026-07-14T00:54:24Z",
          "additions": 364,
          "deletions": 170,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 806,
          "url": "https://github.com/kungfu-systems/kungfu/pull/806",
          "title": "fix(gates): close direct workflow invocation drift",
          "body": "## Summary\n\nClose the first reverse-scan stage of the Kungfu Gate catalog. Direct Shifu Gate commands and the Buildchain Gate-profile workflow are now parsed from YAML into normalized execution facts and reconciled bidirectionally with registry policy and workflow bindings.\n\nKFD-1 version impact: patch. This strengthens an internal validation contract without changing a public runtime or artifact interface.\n\n## Related issue\n\nAtlas goal `2026-07-14-kungfu-gate-direct-reverse-scan`.\n\n## Changes\n\n- add a declared `yaml` parser and scan every managed workflow structurally\n- recognize POSIX, Windows, multiline, `cd &&`, and reusable Gate-profile forms\n- fail closed on rogue, missing, duplicate, mismatched, dynamic, unknown, or policy-drifting invocations\n- upgrade workflow bindings to v2 and document static versus runtime evidence boundaries\n\n## Verification\n\n- `./shifu check:gate-catalog`\n- `./shifu check:source` — 120 tests passed\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This patch strengthens Gate catalog validation without changing an accepted architecture contract\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T00:53:12Z",
          "mergedAt": "2026-07-14T00:58:01Z",
          "additions": 462,
          "deletions": 49,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 809,
          "url": "https://github.com/kungfu-systems/kungfu/pull/809",
          "title": "feat(runtime): add live durability candidate receipts",
          "body": "## Summary\n\nAdd a default-off live durability candidate seam owned by the per-data-root state service. Exact requests can be retried and reconciled after restart without inventing success or failure. Production eligibility remains false. This supersedes PR #807 with a clean linear branch for the repository rebase-only merge policy.\n\n## Related issue\n\nAtlas goal 2026-07-14-kungfu-live-durable-receipts.\n\n## Changes\n\n- add explicit candidate activation, typed request conflict handling, and checkpoint receipt reconciliation\n- expose candidate status and metrics without changing the visible hot path\n- project native reconciliation through Python, Node, and the storage CLI\n- update ADR-0068, design, and public qualification boundaries\n- make the Buildchain source-install argv assertion inspect tokens instead of absolute path substrings\n\n## Verification\n\n- local Shifu build:core\n- local Shifu test:durable-ingest\n- local Shifu test:state-service\n- local Shifu test:durability-contract\n- local Shifu check:source\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Complete the default-off live durability receipt and restart reconciliation candidate seam\",\n  \"verification\": [\"local Shifu Core build and durability contract suites\", \"build-free source acceptance\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T01:00:34Z",
          "mergedAt": "2026-07-14T01:02:50Z",
          "additions": 696,
          "deletions": 51,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 805,
          "url": "https://github.com/kungfu-systems/kungfu/pull/805",
          "title": "feat(coordination): journal-native lock arbiter body (ADR-0077)",
          "body": "Journal-native lock arbiter body — the ADR-0077 next increment over the\nfile-backed lock prototype (PR #771) and the runtime plumbing (PR #799).\n\n**What lands**\n- `coordination/arbiter.py` — pure `LockTable` (FIFO request/release/forget) +\n  action-envelope payload helpers; stdlib-only, unit-tested off the native\n  runtime (14 cases in `test_coordination_arbiter.py`).\n- `coordination/arbiter_peer.py` — resident `Arbiter(peer)`: `serve()` manual\n  loop, observes `coordination.lock.request`/`release`, is the single writer of a\n  `coordination.lock.grant` stream, and records the whole stream as one\n  replayable coordination Episode (native audit that subsumes the first slice's\n  per-run `audit.py`). Auto-release on both paths: clean holder sends a release\n  frame; a hard-killed holder is reclaimed by a same-host pid-liveness reaper.\n- `coordination/arbiter_client.py` — `LockClient` (manual-driven acquire /\n  await-grant / release with zero table poll) + `send_instruct` one-shot.\n\nCustom `coordination.*` action types ride the action envelope with no C++ schema\nchange. First live Python peer and first `coloop`-style grant-await consumer in\nthe tree.\n\n**Verification (local core build)** — race: two workers serialize with zero\npoll; kill: a SIGKILLed holder's lock is reclaimed and granted onward; instruct:\ndelivered to a lock-holding worker; audit: coordination stream replays as a\nclosed Episode (6 frames). `LockTable` unit suite green. `shifu build` green.\n\n**Deferred** — switching the `kungfu lock` CLI onto the arbiter backend as a\nmanaged resident service (library + mechanism are in place; CLI still drives the\nfile lock). ADR-0077 stays `partial`.\n\n<!-- kungfu-adr-release:v1 {\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"stage-ready\",\"adrs\":[\"ADR-0077\"],\"summary\":\"Journal-native lock arbiter body: resident Arbiter peer + pure LockTable + LockClient + replayable Episode audit; the ADR-0077 next increment over the file-backed lock, status stays partial (kungfu lock CLI backend switch deferred).\",\"verification\":[\"LockTable unit suite (14 cases) green off the native runtime\",\"cross-process harness on a local core build: race two-workers-serialize zero-poll, kill SIGKILL-holder-reclaimed-and-granted, instruct delivered-to-lock-holding-worker\",\"coordination stream replays as a closed audit Episode via episode_list (6 frames)\",\"shifu build green SHIFU_BUILD_RC=0\"]} -->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T00:50:36Z",
          "mergedAt": "2026-07-14T01:12:13Z",
          "additions": 856,
          "deletions": 9,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 808,
          "url": "https://github.com/kungfu-systems/kungfu/pull/808",
          "title": "fix(gui): inject complete KFX shared-module contract",
          "body": "## Summary\n\nInject the complete published KFX shared-module contract into every GUI renderer boundary and fail Product assembly when a bundled KFX external cannot be landed.\n\n## Verification\n\n- `./shifu test:kfx-profile-suite`\n- `./shifu check:source`\n- `./shifu exec node --test product/scripts/dist.test.mjs`\n- `./shifu --filter @kungfu-tech/sdk run build`\n- `./shifu build:app`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fix packaged KFX shared-module injection and qualification without changing an architecture contract\"\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe Product assembly gate now verifies the shipped KFX external contract before build registration.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T00:55:18Z",
          "mergedAt": "2026-07-14T01:16:08Z",
          "additions": 189,
          "deletions": 40,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 810,
          "url": "https://github.com/kungfu-systems/kungfu/pull/810",
          "title": "fix(gates): close controller workflow drift",
          "body": "## Summary\n\nClose Kungfu workflow-to-Gate policy drift in both directions for direct Gate calls, Buildchain Gate profiles, and the six remaining controller classes.\n\n## Related issue\n\nAtlas goal 2026-07-14-kungfu-gate-controller-reverse-scan.\n\n## Changes\n\n- replace legacy requiredSnippets witnesses with finite structured controller adapters\n- reverse-discover registered controller identities across workflow YAML\n- bind direct Gate arguments and profile refs/inputs to declared invocation contracts\n- fail closed on missing, duplicate, rogue, or input-drifted workflow facts\n- document the adapter boundary and extension/retirement rule\n\n## Verification\n\n- ./shifu fix\n- ./shifu check:gate-catalog\n- ./shifu check:source (124 tests)\n- ./shifu check\n\n## KFD-1 version impact\n\nPatch. This strengthens a Kungfu repository checker without changing a registered public contract or opening a version line.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This patch strengthens repository-local Gate workflow drift enforcement without changing an architecture contract\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: workflow admission semantics only; validation is source-static and does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T01:18:32Z",
          "mergedAt": "2026-07-14T01:21:16Z",
          "additions": 740,
          "deletions": 106,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 811,
          "url": "https://github.com/kungfu-systems/kungfu/pull/811",
          "title": "docs(layers): link release Gate policy path",
          "body": "## Summary\n\nLink Product Layers directly to the seven-row qualification contract, Gate catalog, generated policy matrix, and machine source of truth.\n\n## Verification\n\n- `./shifu docs:check`\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Documentation-only navigation change; it does not alter an architecture contract or Gate policy.\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T01:34:14Z",
          "mergedAt": "2026-07-14T01:39:21Z",
          "additions": 7,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1174,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1174",
          "title": "feat: add controller evidence contracts",
          "body": "## Summary\n- add a generic versioned controller plan/receipt contract bound to exact consumer and runtime identities\n- aggregate controller outcomes with fail-closed missing-receipt semantics and a Shifu-only gate envelope\n- carry compact controller receipt references through Release Candidate and Release Passport\n- publish generated controller registry, public workflow metadata, documentation, and fixtures\n\n## Validation\n- `pnpm run check` (585 tests)\n- `git diff --check`\n- generated workflow, site, contract, registry, and action bundle checks\n\n## Delivery\n- train ref: `train/v2/v2.3/gate-controller-evidence-contract`\n- downstream source/runtime binding evidence will be attached before merge/promotion\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-14T01:24:31Z",
          "mergedAt": "2026-07-14T01:42:06Z",
          "additions": 7694,
          "deletions": 364,
          "changedFiles": 49
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1175,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1175",
          "title": "chore(release): promote controller evidence contract to alpha",
          "body": "## Summary\n\nPromote the controller evidence contract after Buildchain PR #1174 and qualifying downstream Kungfu validation.\n\n## Evidence\n\n- Buildchain PR #1174 independently approved and merged as `946157b5577bf89a81121036dc5216bf585ecc85`\n- `pnpm run check`: 586 passed; generated contract current; action bundles built\n- Buildchain PR fixture: source check, Linux, macOS, Windows, plan, and final controller receipt all green\n- Kungfu downstream run 29299105492: consumer `8604c22e49852d19e2c303804f9f2ffed53216d1`, runtime `839ab985bcf182cc8d497f95fc0fcd3b578c5296`, qualifying receipt `sha256:886c503156d38c5670b2ed049f7f9b622c2d7be7d5bfdfee66af1b9d661fccfd`\n\nNo consumer Gate IDs or policy decisions enter Buildchain.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T01:44:43Z",
          "mergedAt": "2026-07-14T01:47:00Z",
          "additions": 7694,
          "deletions": 364,
          "changedFiles": 49
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 812,
          "url": "https://github.com/kungfu-systems/kungfu/pull/812",
          "title": "fix(gui): preserve node-pty spawn helper mode",
          "body": "## Summary\n\nRestore executable permissions on packaged node-pty Darwin spawn helpers so Agent Console PTYs can launch.\n\n## Related issue\n\nDogfood report: packaged Agent Console fails with `posix_spawnp failed`.\n\n## Changes\n\n- repair Darwin spawn-helper modes during Electron afterPack\n- fail the packaged-app audit when the helper is missing or non-executable\n- add a regression fixture to the changed-scope qualification suite\n\n## Verification\n\n- `./shifu check`\n- fixture proves mode 0644 fails audit and repaired mode passes\n- packaged macOS app launches `codex --version` through its bundled Electron and node-pty (exit 0)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Packaging bug fix restores the existing Agent Console PTY contract without changing architecture.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not needed; existing behavior restored)",
          "author": "dongkeren",
          "createdAt": "2026-07-14T01:45:24Z",
          "mergedAt": "2026-07-14T01:47:20Z",
          "additions": 112,
          "deletions": 2,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 813,
          "url": "https://github.com/kungfu-systems/kungfu/pull/813",
          "title": "feat(runtime): add projection authority candidate",
          "body": "## Summary\n\nAdd an explicit, default-off projection authority candidate for live peer startup while retaining the coordinator compatibility bridge as the default rollback path. The candidate remains production-ineligible.\n\n## Related issue\n\nN/A\n\n## Changes\n\n- carry required, optional, or none projection requirements as an additive Register JSON extension\n- validate a qualified snapshot-through-T plus replay-after-T image before required peer registration and emit it before RequestStart\n- skip coordinator-owned business PUBLIC/SYNC joins and compatibility restore only for explicitly declared candidate peers\n- keep undeclared peers on the existing compatibility path\n- expose one libkungfu status through Python, Node, peer bindings, and the storage CLI\n- retain same-cut parity, atomic hydration, rollback, corruption, rebuild, and process-restart evidence\n- update ADR-0068, design, qualification, known-limits, and public metadata\n\n## Verification\n\n- `./shifu build:core`\n- `./shifu test:projection-bootstrap`\n- `./shifu test:state-service`\n- `./shifu test:durable-ingest`\n- `./shifu test:durability-contract`\n- `./shifu test:runtime-errors`\n- `./shifu check`\n- `./shifu check:source`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Add the default-off live projection authority candidate with explicit startup requirements, rollback, status, and restart evidence while retaining the default compatibility bridge\",\n  \"verification\": [\"Local Core build\", \"projection and durability contract suites\", \"changed-scope check\", \"build-free source acceptance\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T01:52:42Z",
          "mergedAt": "2026-07-14T01:55:30Z",
          "additions": 1056,
          "deletions": 64,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1177,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1177",
          "title": "fix: preserve tree-equivalent controller evidence",
          "body": "## Summary\n\n- preserve the exact controller receipt source SHA from the release-candidate build\n- allow that historical source only when the promotion channel SHA equals the final Passport source and the Release Candidate proves the two Git trees are equivalent\n- keep non-equivalent and unproven source substitutions fail-closed\n\n## Failure reproduced\n\n- failed alpha promotion run: 29299474874\n- release-candidate source: 3388c38692a618447283a15a6412fcb928da5107\n- alpha promotion source: e80475ac79f2673396c1fb006f381d83d20d688d\n- failure: controller receipt reference source SHA mismatch\n\n## Validation\n\n- targeted controller, release-candidate, release-passport, and promotion tests: 184/184\n- pnpm run generate:site\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-14T01:57:53Z",
          "mergedAt": "2026-07-14T02:02:16Z",
          "additions": 102,
          "deletions": 50,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1178,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1178",
          "title": "chore(release): repair controller evidence alpha promotion",
          "body": "## Summary\n\nPromote the tree-equivalent controller evidence repair and resume the durable alpha transaction.\n\n## Evidence\n\n- fix PR #1177 independently approved and merged as 8c24e90ccc881d6d194ec79b9cdf7761daf3b4af\n- failed promotion run 29299474874 reproduced the source-SHA mismatch after the release-candidate tree-equivalence gate had passed\n- the fix preserves the exact receipt source and accepts it only under explicit tree-equivalence proof\n- local pnpm run check passed after synchronizing the current dev release state\n- dev Verify run 29300064959 passed\n- downstream Kungfu qualifying receipt remains sha256:886c503156d38c5670b2ed049f7f9b622c2d7be7d5bfdfee66af1b9d661fccfd",
          "author": "dongkeren",
          "createdAt": "2026-07-14T02:03:49Z",
          "mergedAt": "2026-07-14T02:06:01Z",
          "additions": 102,
          "deletions": 50,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 117,
          "url": "https://github.com/kungfu-systems/build-images/pull/117",
          "title": "feat(pilots): consume prebuilt Kungfu CLI package",
          "body": "## Summary\n\n- consume a prebuilt `kungfu-episodes-cli-linux-x64.tar.gz` package instead of compiling Kungfu in Docker\n- verify the package SHA-256 and `kungfu.product.cli/v1` metadata before installing its declared CLI\n- add a reusable package-smoke workflow that downloads an artifact produced earlier in the caller's workflow run\n- exercise Episode write/query/export, SIGKILL restart, fsck and isolated restore\n- keep all Docker evidence explicitly unscored and non-authoritative for performance\n\n## Package boundary\n\nPackage production happens before this comparator starts. The caller supplies the artifact name, package version, exact package SHA-256, exact source commit and workflow evidence URL. The ordinary pull-request smoke continues to cover the three self-contained comparator profiles; Kungfu runs only when a real prebuilt package is supplied.\n\nNo Kungfu source checkout, dependency installation or product compilation occurs inside the Dockerfile.\n\n## Validation\n\n- `pnpm run check`\n- `shellcheck pilots/comparator/scripts/pilot.sh`\n- `bash pilots/comparator/scripts/pilot.sh plan kungfu`\n- package-input manifest resolution fixture\n- `git diff --check`\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] No provider billing, quota, or usage-attribution change\n- [x] No product or package publication\n- [x] No package name, release identity, or domain change\n- [x] Evidence remains disposable and marked unscored/non-authoritative\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T01:36:28Z",
          "mergedAt": "2026-07-14T02:07:50Z",
          "additions": 331,
          "deletions": 50,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1179,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1179",
          "title": "fix: decouple router controller runtime",
          "body": "## Summary\n\n- execute build-channel-router controller plans and receipts from the reusable workflow shell that defines the controller\n- keep the selected alpha or stable ref as the controlled build runtime only\n- bind controller evidence to the workflow-shell repository, ref, SHA, and contract digest\n\n## Failure reproduced\n\nAlpha self-dogfood run 29300407886 passed the alpha consumer but failed the stable consumer because v2 does not yet contain scripts/controller-evidence.mjs. The v2-alpha workflow shell was incorrectly trying to execute its new controller through the selected legacy stable runtime.\n\n## Validation\n\n- generated channel workflow is current\n- controller/build-surface tests passed\n- pnpm run generate:site\n- pnpm run check",
          "author": "dongkeren",
          "createdAt": "2026-07-14T02:17:56Z",
          "mergedAt": "2026-07-14T02:20:07Z",
          "additions": 47,
          "deletions": 29,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 814,
          "url": "https://github.com/kungfu-systems/kungfu/pull/814",
          "title": "fix(terminal): add resizable console layouts",
          "body": "## Summary\n\nFix the Agent Console layout so it opens as one full-size pane and offers explicit resizable two-column, two-row, three-column, and three-row arrangements.\n\n## Changes\n\n- Replace the wrapping auto-fill grid with explicit row and column layouts.\n- Add draggable and keyboard-accessible separators with minimum pane sizes.\n- Keep restart behavior deterministic by returning to one pane.\n- Add focused layout and resize invariant tests.\n\n## Verification\n\n- `./shifu check`\n- `./shifu exec node --test extensions/terminal/tests/*.test.ts`\n- Focused TypeScript no-emit check for the terminal view and layout module\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix corrects the existing Agent Console presentation and resizing behavior without changing an architecture contract\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed or not required for this focused UI fix",
          "author": "dongkeren",
          "createdAt": "2026-07-14T02:14:42Z",
          "mergedAt": "2026-07-14T02:23:17Z",
          "additions": 329,
          "deletions": 30,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1180,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1180",
          "title": "chore(release): promote router controller compatibility fix",
          "body": "## Summary\n\nPromote the router-controller workflow-shell fix so alpha self-dogfood can verify both the new alpha controller and the legacy stable build runtime.\n\n## Evidence\n\n- fix PR #1179 independently approved and merged as 4173720b0bb53673adb939a71d84a7a1f1d1e5b8\n- alpha self-dogfood run 29300407886 proved the alpha path and reproduced the legacy stable bootstrap failure\n- controller evidence now binds the v2-alpha workflow shell while the selected v2 ref remains the controlled build runtime\n- local pnpm run check passed\n- dev Verify run 29300809262 passed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T02:21:25Z",
          "mergedAt": "2026-07-14T02:23:49Z",
          "additions": 47,
          "deletions": 29,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1181,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1181",
          "title": "fix: bind router controller registry",
          "body": "## Summary\n\nBind the build-channel-router controller plan to the registry inside the checked-out workflow shell.\n\n## Failure reproduced\n\nAlpha self-dogfood run 29301143270 checked out the correct v2-alpha controller runtime but the controller CLI retained its generic default registry path under .buildchain/runtime. Both alpha and stable controller plans therefore failed closed before builds started.\n\n## Validation\n\n- generated channel workflow is current\n- explicit controller-runtime registry assertion added\n- pnpm run generate:site\n- pnpm run check: 587/587",
          "author": "dongkeren",
          "createdAt": "2026-07-14T02:33:13Z",
          "mergedAt": "2026-07-14T02:35:24Z",
          "additions": 6,
          "deletions": 3,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1182,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1182",
          "title": "chore(release): promote router controller registry fix",
          "body": "## Summary\n\nPromote the explicit workflow-shell controller registry binding.\n\n## Evidence\n\n- fix PR #1181 independently approved and merged as 5f5e19d1bd5df0af2d2d017a1fe3f5ac36f75bf4\n- alpha self-dogfood run 29301143270 reproduced the stale default registry path\n- the generated router workflow now binds the registry under the controller-runtime checkout\n- pnpm run check passed 587/587\n- dev Verify run 29301443504 passed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T02:36:39Z",
          "mergedAt": "2026-07-14T02:39:01Z",
          "additions": 6,
          "deletions": 3,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1183,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1183",
          "title": "fix: decouple build controller runtime",
          "body": "## Summary\n\n- execute build-lifecycle controller plans and final receipts from the reusable build workflow shell\n- keep the selected alpha or stable ref as the controlled lifecycle runtime\n- bind controller runtime ref, SHA, contract digest, and registry to the workflow shell\n\n## Failure reproduced\n\nAlpha self-dogfood run 29301749569 passed both channel-router controllers. The stable consumer then failed inside the nested build-lifecycle controller because that controller still executed through the legacy v2 runtime.\n\n## Validation\n\n- alpha consumer path passed in run 29301749569\n- outer alpha and stable controller plans passed in run 29301749569\n- pnpm run generate:site\n- pnpm run check: 587/587",
          "author": "dongkeren",
          "createdAt": "2026-07-14T02:48:56Z",
          "mergedAt": "2026-07-14T02:51:19Z",
          "additions": 27,
          "deletions": 14,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1184,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1184",
          "title": "chore(release): promote build controller compatibility fix",
          "body": "## Summary\n\nPromote the reusable build-controller workflow-shell boundary.\n\n## Evidence\n\n- fix PR #1183 independently approved and merged as 87b9a5bb9cf2c51d6b07ff9bc2ad1d2e7721489b\n- alpha self-dogfood run 29301749569 passed channel-router controller evidence and isolated the nested stable build-controller failure\n- build-lifecycle controller plan and receipt now bind the workflow shell; selected v2 remains the lifecycle runtime\n- pnpm run check passed 587/587\n- dev Verify run 29302075065 passed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T02:52:41Z",
          "mergedAt": "2026-07-14T02:54:59Z",
          "additions": 27,
          "deletions": 14,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 815,
          "url": "https://github.com/kungfu-systems/kungfu/pull/815",
          "title": "feat(runtime): define topology-neutral activation contract",
          "body": "## Summary\n\n- define the KFD-1 runtime activation contract for storage-only, live-optional, and live-required operations\n- bind readiness to durable and projection cuts, with generation fencing, leases, receipts, stable errors, and explicit authority limits\n- register the runtime surface, generate KFD projections, and add source-gate fixtures rejecting six unsafe paths\n- document ProcessRuntimeHost as the next delivery stage and EmbeddedRuntimeHost as a production non-claim\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu docs:check`\n- `./shifu kfd:buildchain:check`\n- `./shifu exec node --test developer/sdk/tests/contract-cli.test.mjs`\n\n## Governance risk\n\nNo credentials, provider APIs, hosted services, release publication, deployment, or production runtime activation are changed. This PR delivers only the topology-neutral contract stage.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Land stage 1: the topology-neutral runtime activation contract, ADR, fixtures, source gate, registry entry, and generated KFD evidence without implementing ProcessRuntimeHost or EmbeddedRuntimeHost.\",\n  \"verification\": [\"./shifu check:source\", \"./shifu docs:check\", \"./shifu kfd:buildchain:check\", \"SDK contract CLI tests\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T02:51:27Z",
          "mergedAt": "2026-07-14T02:56:52Z",
          "additions": 2730,
          "deletions": 58,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 816,
          "url": "https://github.com/kungfu-systems/kungfu/pull/816",
          "title": "docs(adr): stabilize runtime contract evidence",
          "body": "## Summary\n\n- replace the pre-rebase implementation commit reference with the stable merged PR URL\n- preserve ADR-0080 at partial implementation status without changing runtime semantics or qualification claims\n\n## Verification\n\n- `./shifu docs:check`\n\n## Governance risk\n\nDocumentation evidence repair only; no runtime, deployment, release, or production behavior changes.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Replace the non-mainline pre-rebase commit evidence with the stable merged PR #815 evidence for the completed contract stage.\",\n  \"verification\": [\"./shifu docs:check\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T02:58:49Z",
          "mergedAt": "2026-07-14T03:00:29Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1185,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1185",
          "title": "Release v2.12.5 from qualified v2.12.5-alpha.5",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.12.5-alpha.5`\n- Candidate SHA: `38ef5648fd3e127055422c657652084ab4640a54`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.12`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T03:06:24Z",
          "mergedAt": "2026-07-14T03:07:27Z",
          "additions": 7795,
          "deletions": 379,
          "changedFiles": 52
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1187,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1187",
          "title": "fix: preserve controller receipts in release assets",
          "body": "## Summary\n- preserve authoritative controller receipt references when binary distribution re-collects a durable release passport\n- add regression coverage for the public GitHub Release asset path\n- regenerate bundled action and site contract metadata\n\n## Validation\n- `node --test tests/release-passport.test.mjs`\n- `pnpm run check` (587 tests)\n\n## Release evidence\nThis fixes the final gap observed after v2.12.5: the promotion-time passport carried controller receipts, but the public `buildchain.release.json` asset dropped them during binary collection.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T03:21:00Z",
          "mergedAt": "2026-07-14T03:23:04Z",
          "additions": 56,
          "deletions": 41,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1188,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1188",
          "title": "chore(release): promote controller receipt asset fix",
          "body": "## Summary\n\nPromote the durable controller receipt preservation fix into the v2.12 alpha channel.\n\n## Evidence\n\n- fix PR #1187 independently approved and merged as 5a164a8caf0e42b91fa2f2fa4149c24c9eca1749\n- promotion-time v2.12.5 Passport contained the receipt reference while the public binary-collected asset omitted it\n- binary collector now preserves authoritative `controllerReceipts` from durable release state\n- `pnpm run check` passed 587/587\n- dev Verify run 29303387021 passed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T03:24:59Z",
          "mergedAt": "2026-07-14T03:27:23Z",
          "additions": 56,
          "deletions": 41,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 818,
          "url": "https://github.com/kungfu-systems/kungfu/pull/818",
          "title": "feat(runtime): isolate process host from coordinator engine",
          "body": "## Summary\n\n- extract a directly callable `CoordinatorEngine` request seam with typed receipts\n- move PID files, signals, spawning, detachment, child ownership, and process diagnostics behind `ProcessRuntimeHost`\n- preserve the existing CLI and service entrypoints through compatibility delegation\n- keep the full semantic `RuntimeHost` requirement/handle adapter and production `EmbeddedRuntimeHost` as explicit non-claims\n\n## Verification\n\n- `PYTHONPATH=framework/core/src/python ./shifu exec uv run --project framework/core --frozen pytest framework/core/tests/python/test_runtime_service.py -q` (16 passed)\n- `./shifu exec uv run --project framework/core --frozen node scripts/source-acceptance.mjs` (128 contract tests; Ruff, Mypy, Biome, docs, KFD gates passed)\n- staged pre-commit gate passed\n\n## Governance risk\n\nNo credentials, provider APIs, hosted services, production release, deployment, or production embedded runtime are changed. This PR only isolates the current process placement boundary and adds a no-fork qualification seam.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Land stage 2: isolate the current supervisor/coordinator process placement behind ProcessRuntimeHost and add a directly callable CoordinatorEngine no-fork seam without claiming the semantic RuntimeHost broker or EmbeddedRuntimeHost.\",\n  \"verification\": [\"runtime_service pytest: 16 passed\", \"build-free source gate: 128 tests plus Ruff, Mypy, Biome, docs, and KFD checks\", \"staged pre-commit gate\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T03:23:53Z",
          "mergedAt": "2026-07-14T03:28:34Z",
          "additions": 459,
          "deletions": 208,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1189,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1189",
          "title": "fix: isolate controller workflow inputs",
          "body": "## Summary\n- preserve strict undeclared-input validation in the controller evidence core\n- bind reusable workflow controller plans only to descriptor-declared workflow-call inputs\n- prevent caller workflow_dispatch inputs from leaking across the reusable workflow boundary\n\n## Failure evidence\n- stable qualification run 29303872276 failed because site-libkungfu-dev canary run 29303966165 exposed ambient `buildchain_ref` beside declared `buildchain-ref`\n- the controller correctly rejected the ambient field, but the workflow adapter had passed the entire GitHub `inputs` context\n\n## Validation\n- controller/build-surface tests: 83/83\n- `pnpm run check`: 588/588",
          "author": "dongkeren",
          "createdAt": "2026-07-14T03:45:12Z",
          "mergedAt": "2026-07-14T03:47:15Z",
          "additions": 58,
          "deletions": 15,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1190,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1190",
          "title": "chore(release): promote controller input boundary fix",
          "body": "## Summary\n\nPromote reusable workflow controller input-boundary isolation into the v2.12 alpha channel.\n\n## Evidence\n\n- fix PR #1189 independently approved and merged as 7eac19e6375e78c4ce788b261317090edaff2e06\n- site-libkungfu-dev canary 29303966165 exposed caller ambient `buildchain_ref`\n- strict core validation remains unchanged; adapters bind only descriptor-declared workflow-call inputs\n- `pnpm run check` passed 588/588\n- dev Verify run 29304350207 passed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T03:49:01Z",
          "mergedAt": "2026-07-14T03:51:15Z",
          "additions": 58,
          "deletions": 15,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 819,
          "url": "https://github.com/kungfu-systems/kungfu/pull/819",
          "title": "feat(runtime): add capability-driven invocation broker",
          "body": "## Summary\n\n- add a contract-owned runtime operation registry for storage-only and live-required work\n- add `RuntimeCapabilityBroker` with deterministic plans and atomic invoke admission\n- keep storage-only callbacks daemonless and fail live-required process activation closed until semantic readiness exists\n- bind first-party Mission Control actions to the runtime operation authority while preserving older Profile v1 registries\n- keep generation-fenced recovery/readiness, product entrypoints, and production `EmbeddedRuntimeHost` as later-stage non-claims\n\n## Verification\n\n- `PYTHONPATH=framework/core/src/python ./shifu exec uv run --project framework/core --frozen pytest framework/core/tests/python/test_runtime_broker.py -q` (5 passed)\n- `./shifu exec uv run --project framework/core --frozen -- ./shifu check:source` (130 contract tests; docs, Biome, Ruff, mypy across 134 source files, and KFD checks passed)\n- staged pre-commit gate passed\n\n## Governance risk\n\nNo credentials, provider APIs, hosted services, deployment, production release, or production embedded runtime are changed. The process bridge deliberately returns `readiness_not_established` after requesting activation; PID or health diagnostics cannot admit live work.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Land stage 3: add the contract-owned operation registry and capability broker with daemonless storage admission and fail-closed live admission, while leaving generation-fenced readiness and product projection to later stages.\",\n  \"verification\": [\"runtime_broker pytest: 5 passed\", \"build-free source gate: 130 tests plus docs, Biome, Ruff, mypy, and KFD checks\", \"staged pre-commit gate\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T03:49:24Z",
          "mergedAt": "2026-07-14T03:51:48Z",
          "additions": 923,
          "deletions": 49,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1191,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1191",
          "title": "fix: infer controller workflow input boundary",
          "body": "## Summary\n\n- infer the workflow-call input boundary from controller descriptor provenance when a legacy reusable workflow shell does not set the explicit boundary\n- preserve explicit strict/workflow-call overrides and the strict core plan validator\n- cover workflow provenance, strict fallback, invalid overrides, and ambient input filtering\n\n## Validation\n\n- node --test tests/controller-evidence.test.mjs tests/build-surface.test.mjs (84/84)\n- exact legacy-shell smoke: ambient buildchain_ref excluded without BUILDCHAIN_CONTROLLER_INPUT_BOUNDARY\n- pnpm run check (589/589)",
          "author": "dongkeren",
          "createdAt": "2026-07-14T04:03:43Z",
          "mergedAt": "2026-07-14T04:09:00Z",
          "additions": 42,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1192,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1192",
          "title": "chore(release): promote descriptor input boundary inference",
          "body": "## Summary\n\nPromote descriptor-derived workflow-call input boundary inference into the v2.12 alpha channel so candidate runtimes remain compatible with the current stable v2 reusable workflow shell.\n\n## Evidence\n\n- fix PR #1191 merged as 689f8419ec0de91f45ef18220541de2a9b86c1eb\n- exact legacy-shell smoke excludes ambient buildchain_ref without an explicit boundary variable\n- core createControllerPlan still rejects undeclared inputs\n- pnpm run check passed 589/589\n- dev Verify run 29305248633 passed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T04:10:46Z",
          "mergedAt": "2026-07-14T04:12:58Z",
          "additions": 42,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 821,
          "url": "https://github.com/kungfu-systems/kungfu/pull/821",
          "title": "test(durability): retain agent-120 fault evidence",
          "body": "Supersedes #820 after a signed merge of the current dev baseline.\n\n## Summary\n\nAdd and retain the agent-120 Linux/ext4 production-candidate fault campaign while keeping every physical-host, physical-device, off-host, independent-failure-domain, and production claim closed.\n\n## Related issue\n\nN/A\n\n## Changes\n\n- freeze a deterministic 360-trial QEMU matrix across two durability profiles, ten cut points, six virtual device/cache envelopes, and three seeds\n- make preparation and execution dry-run-first, sentinel-protected, local-Shifu-only, and append-only\n- add an explicitly non-qualifying canary with collision-free artifacts\n- retain 360/360 aggregate and raw JSONL evidence from agent-120\n- retain current-head Linux/ext4 process reports for durable_group and durable_sync\n- retain real ENOSPC, three fresh guest reopens, fsck/hash, and same-host offline backup/restore evidence\n- add build-free evidence integrity checks and update public qualification/known-limit documentation\n- align the qualification marker with the current projection candidate output\n\n## Verification\n\n- `./shifu build:core` on agent-120 using existing host-local Conan binaries\n- `./shifu durability:fault-campaign:qemu`: 360/360 passed\n- `./shifu durability:qualify` for `durable_group`: passed\n- `./shifu durability:qualify` for `durable_sync`: passed\n- `./shifu durability:institutional:qemu`: passed\n- `./shifu check:source`: 137 tests passed; build-free source gate passed\n- branch workflow audit: no workflow runs created\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Retain the bounded agent-120 Linux/ext4 process, QEMU device-model, ENOSPC, repeated-recovery, and same-host restore evidence without widening physical or production claims\",\n  \"verification\": [\"Local Core build\", \"360-trial QEMU campaign\", \"dual process qualification\", \"institutional QEMU drill\", \"build-free source acceptance\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T04:09:54Z",
          "mergedAt": "2026-07-14T04:16:29Z",
          "additions": 18973,
          "deletions": 101,
          "changedFiles": 37
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1193,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1193",
          "title": "Release v2.12.6 from qualified v2.12.6-alpha.3",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.12.6-alpha.3`\n- Candidate SHA: `94ea357ff52b7218c4e1439fe7bae2ecb337226c`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.12`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T04:23:34Z",
          "mergedAt": "2026-07-14T04:24:47Z",
          "additions": 165,
          "deletions": 71,
          "changedFiles": 24
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 822,
          "url": "https://github.com/kungfu-systems/kungfu/pull/822",
          "title": "feat(runtime): fence activation readiness generations",
          "body": "## Summary\n\n- serialize first activation with one cross-process owner per canonical workspace\n- persist atomic runtime snapshots and reuse one generation across concurrent first calls\n- advance generation only when process diagnostics are replaced; revalidate expanded capabilities in the same process generation\n- invoke existing durability reconciliation and projection candidate authorities, admitting readiness only at or beyond the requested cut\n- fail closed for missing/corrupt generation state, untracked running processes, absent readiness authority, and behind-cut evidence\n- retain lease/adoption/restart lifecycle, product entrypoint wiring, and production `EmbeddedRuntimeHost` as later-stage non-claims\n\n## Verification\n\n- `PYTHONPATH=framework/core/src/python ./shifu exec uv run --project framework/core --frozen -- python -m pytest -q framework/core/tests/python/test_runtime_broker.py` (17 passed)\n- `XDG_CACHE_HOME=/tmp/kungfu-codex-runtime-readiness-cache ./shifu exec uv run --project framework/core --frozen -- ./shifu check:source` (130 contract tests; 61 documentation contract tests; docs, Biome, Ruff, mypy across 134 source files, and KFD checks passed)\n- `./shifu kfd:buildchain` (KFD-1 witness, 3 KFD-2 claims, 113 KFD-3 surfaces)\n- staged pre-commit gate passed\n\n## Governance risk\n\nNo credentials, provider APIs, hosted services, deployment, production release, or production embedded runtime are changed. PID and health diagnostics remain non-authoritative. A running process without a valid fenced generation fails `stale_generation`; explicit adoption and lease/restart recovery remain stage 5 work. Product evidence discovery and entrypoint wiring remain stage 6 work.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Land stage 4: serialize first activation, persist and fence process generations, and bind native durability/projection readiness to the requested cut while leaving adoption, leases, restart recovery, product projection, and EmbeddedRuntimeHost to later stages.\",\n  \"verification\": [\"runtime_broker pytest: 17 passed\", \"build-free source gate: 130 tests plus 61 documentation contracts, Biome, Ruff, mypy, and KFD checks\", \"staged pre-commit gate\"]\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T04:44:00Z",
          "mergedAt": "2026-07-14T04:48:23Z",
          "additions": 1091,
          "deletions": 36,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 823,
          "url": "https://github.com/kungfu-systems/kungfu/pull/823",
          "title": "feat(runtime): add lease and recovery lifecycle",
          "body": "## Summary\n\n- persist generation-fenced semantic leases with holder, capability-subset, authority, expiry, renew, and release checks\n- atomically fence idle demand as draining before stopping one workspace route, then record stopped or failed completion\n- preserve only an exact fenced orphan coordinator across supervisor replacement; terminate untracked orphans\n- expire old-generation leases before restart and bound coordinator crash recovery to five attempts per 60-second window\n- keep route heartbeat TTL diagnostic and retain cross-machine leases, distributed election, high availability, product projection, and production EmbeddedRuntimeHost as non-claims\n\n## Verification\n\n- `PYTHONPATH=framework/core/src/python ./shifu exec uv run --project framework/core --frozen -- python -m pytest -q framework/core/tests/python/test_runtime_broker.py framework/core/tests/python/test_runtime_service.py` (43 passed)\n- `./shifu exec uv run --project framework/core --frozen -- mypy --config-file framework/core/pyproject.toml framework/core/src/python/kungfu/runtime_broker.py framework/core/src/python/kungfu/runtime_service.py` (passed)\n- `XDG_CACHE_HOME=/tmp/kungfu-codex-runtime-lease-cache ./shifu exec uv run --project framework/core --frozen -- ./shifu check:source` (143 source contract tests; 61 documentation contract tests; runtime contract 4 positive/6 negative fixtures; Ruff; mypy across 134 source files; passed)\n- `./shifu kfd:buildchain` (KFD-1 witness, 3 KFD-2 claims, 113 KFD-3 surfaces)\n- staged pre-commit gate passed\n\n## Governance risk\n\nNo credentials, provider APIs, hosted services, deployment, production release, cross-machine lease, distributed election, high availability, or production embedded runtime are changed. PID and route heartbeat facts remain diagnostics. Adoption requires the exact recorded coordinator generation; untracked or corrupt state fails closed.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Land stage 5: add holder- and generation-fenced semantic leases, atomic idle draining, exact coordinator adoption, old-generation lease expiry, and bounded restart recovery while leaving product projection, cross-machine coordination, and EmbeddedRuntimeHost to later stages.\",\n  \"verification\": [\"runtime broker and service pytest: 43 passed\", \"build-free source gate: 143 tests plus 61 documentation contracts, runtime fixtures, Ruff, mypy, and KFD checks\", \"staged pre-commit gate\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T05:19:20Z",
          "mergedAt": "2026-07-14T05:21:58Z",
          "additions": 1573,
          "deletions": 43,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 824,
          "url": "https://github.com/kungfu-systems/kungfu/pull/824",
          "title": "feat(durability): qualify agent120 absolute SLO",
          "body": "## Summary\n\nFreeze, execute, and retain the first absolute durability SLO for the named agent-120 Linux/x86_64/NVMe/ext4 candidate while keeping wider product and production claims closed.\n\n## Related issue\n\nN/A\n\n## Changes\n\n- add a native durability SLO fixture with complete latency histograms, correctness knockout, recovery, projection, backup/restore, and resource measurements\n- freeze eight pre-measurement workloads for durable_group and durable_sync, including rapid rollover and two 15-minute soaks\n- add a default-dry-run, local-Shifu-only runner that refuses dirty source and existing evidence paths\n- bind execution to agent-120, ext4, and NVMe host facts and fsync every raw workload result\n- retain the passing candidate evidence index plus aggregate/raw artifact hashes\n- update durability, performance qualification, and known-limit documentation without widening mmap, power-loss, off-host, cross-platform, comparator, or production claims\n\n## Verification\n\n- local Mac `./shifu build:core`: passed\n- agent-120 `./shifu build:core` using existing host-local Conan binaries: passed\n- agent-120 `./shifu durability:slo -- --run-id 070e0804b-agent120-slo-v1 --execute`: 8/8 passed, zero violations\n- two 15-minute soaks: 449,984 durable_group and 224,992 durable_sync records\n- `./shifu check:source`: 150/150 tests passed; build-free source gate passed\n- branch workflow audit: no workflow runs created\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Freeze and retain the first bounded agent-120 absolute durability SLO without widening physical, cross-platform, comparator, or production claims\",\n  \"verification\": [\"Local Core build\", \"agent-120 Core build\", \"eight-workload durability SLO\", \"two 15-minute soaks\", \"build-free source acceptance\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T05:31:09Z",
          "mergedAt": "2026-07-14T05:40:58Z",
          "additions": 1628,
          "deletions": 10,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 757,
          "url": "https://github.com/kungfu-systems/kungfu/pull/757",
          "title": "shifu: two-level repo discovery + buildchain-answered KFD-3 layout",
          "body": "## Summary\n\nRepository-root discovery in the shifu launcher becomes two-level, and shifu\nstops holding a copy of the KFD-3 registry path.\n\n- **`resolve KFD-3 registry via buildchain layout`** — the registrar no longer\n  hardcodes `.buildchain/kfd/kfd-3/surfaces.json`. It asks the repo-pinned\n  `buildchain` binary (`buildchain layout --json`, contract\n  `kungfu-buildchain-layout-discovery`) and reads `kfd.registries.\"kfd-3\".path`\n  back, caching the answer per repo and buildchain version. The advisory\n  dispatch hot path resolves cache-only (no forced download), so `check` keeps\n  its fast startup. The registry's `registryPath` self-attestation is read back\n  and a drift warning is emitted on mismatch.\n- **`recognize buildchain-managed repos as a second root level`** —\n  `find_repo_root` gains Level 2: a `.buildchain-version`-pinned repo whose\n  KFD-3 registry declares `distribution.registrar = \"shifu\"` is served directly\n  (delegation no-ops with no entrypoint pair). A pin alone is not enough — the\n  explicit registrar declaration is required, so a buildchain-managed repo that\n  never opted in is not claimed. Lenient verbs (`--version`, `doctor`) skip the\n  Level-2 check and stay useful rootless.\n\nThe two welded seams shifu depends on — the `.buildchain-version` pin name and\nthe `buildchain layout --json` verb — are registered as a contract in\n`docs/contracts.md`. ADR-0044 (delegation) is unchanged. See SHIFU-ADR-0005.\n\n## Verification\n\n- `cargo test -p shifu` (25 tests) and `cargo clippy` / `cargo fmt` clean.\n- End to end against the pinned buildchain: a synthetic downstream repo\n  declaring `registrar: shifu` is recognized and dispatched; the same repo with\n  a non-shifu registrar, and a non-buildchain directory, both fall back to the\n  not-a-repo error.\n- ADR release gate and document-metadata contract validated locally.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0005\"],\n  \"summary\": \"Shifu repo-root discovery becomes two-level and asks buildchain for the KFD-3 layout instead of copying it.\",\n  \"verification\": [\n    \"cargo test -p shifu (25 tests) plus cargo clippy and fmt clean\",\n    \"end-to-end against pinned buildchain: synthetic downstream repo declaring registrar=shifu is recognized and dispatched; a non-shifu registrar and a non-buildchain directory both fall back to the not-a-repo error\"\n  ]\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-13T07:13:16Z",
          "mergedAt": "2026-07-14T05:53:27Z",
          "additions": 524,
          "deletions": 28,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 825,
          "url": "https://github.com/kungfu-systems/kungfu/pull/825",
          "title": "feat(runtime): unify product runtime projections",
          "body": "## Summary\n\n- add one contract-validated product runtime status that treats a daemonless workspace as available and preserves fenced generation, exact cuts, semantic leases, and typed failures\n- expose topology-neutral operation catalogs and read-only plans through CLI, and share the same runtime vocabulary through API, KFX, and libkungfu TypeScript declarations\n- make GUI and TUI product copy capability-driven: GUI startup, tray, ordinary quit no longer own resident runtime process lifecycle, while process facts remain advanced diagnostics\n- add parity/type/CLI/Python/GUI tests and regenerate KFD contract evidence\n- keep stage 6 open: live-required product action invocation and discovery of exact-cut native readiness evidence are not yet wired\n\n## Verification\n\n- `PYTHONPATH=framework/core/build/Release:framework/core/src/python KUNGFU_ALLOW_FOREIGN_RUNTIME=1 ./shifu --filter @kungfu-tech/core exec uv run --frozen python -m pytest tests/python/test_runtime_broker.py tests/python/test_runtime_service.py tests/python/test_runtime_cli.py -q` (50 passed)\n- `./shifu test:runtime-surface` (7 surfaces and 4 KFX actions aligned; libkungfu declaration compile proof passed)\n- API TypeScript build, KFX build, and GUI tests (14 passed)\n- `./shifu --filter @kungfu-tech/core exec uv run --frozen --project framework/core --directory . node scripts/source-acceptance.mjs` (143 source contract tests; 61 documentation contract tests; 221 Markdown files; 220 link/contract checks; Biome; Ruff; mypy across 134 source files; passed)\n- `./shifu kfd:buildchain` (KFD-1 witness, 3 KFD-2 claims, 113 KFD-3 surfaces)\n- staged pre-commit gate passed\n\n## Governance risk\n\nNo credentials, hosted services, deployment, production release, cross-machine leasing, distributed election, high availability, or production EmbeddedRuntimeHost are changed or claimed. Process health cannot establish product readiness. This delivery intentionally does not permit a live-required callback to bypass the broker: product action invocation remains open until exact-cut native evidence can be discovered and supplied fail closed.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Land the stage 6 projection slice: one daemonless-safe product runtime status, topology-neutral CLI planning, shared API and libkungfu vocabulary, and GUI/TUI process-ownership removal, while leaving exact-cut product action invocation and evidence discovery open.\",\n  \"verification\": [\"runtime broker, service, and CLI pytest: 50 passed\", \"runtime surface parity: 7 surfaces and 4 KFX actions\", \"build-free source gate: 143 tests plus 61 documentation contracts, Biome, Ruff, mypy, and KFD checks\", \"staged pre-commit gate\"]\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T06:19:14Z",
          "mergedAt": "2026-07-14T06:27:24Z",
          "additions": 1078,
          "deletions": 108,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 826,
          "url": "https://github.com/kungfu-systems/kungfu/pull/826",
          "title": "feat(durability): qualify same-office off-host restore",
          "body": "## Summary\n\nAdd a default-off, bounded off-host backup/restore protocol and retain the first real agent-120 to Ubuntu 222 same-office restore evidence without widening independent-failure-domain, power-loss, or production claims.\n\n## Related issue\n\nN/A\n\n## Changes\n\n- add a deterministic manifest/data/completion-marker-last transport package with exact digest, path, symlink, and size verification\n- add a dry-run-default Shifu harness with explicit host/filesystem/device/sentinel checks, delete-free transfer, partial-transfer rejection, empty-root restore, and idempotence checks\n- retain exact source, manifest, completion, target verification, restore, and aggregate reports from the named two-host run\n- bind the capability authority and source acceptance to immutable evidence hashes\n- update durability, institutional-trust, and known-limit documentation to distinguish same-office off-host recovery from an independent disaster domain\n\n## Verification\n\n- local Mac `./shifu build:core`: passed using existing Conan cache through a temporary controller-free XDG config\n- local Mac `./shifu test:crash-recovery`: passed, including 16 native recovery contracts and whole-data-root process restart\n- agent-120 `./shifu build:core`: passed using existing host-local Conan binaries\n- agent-120 `./shifu durability:offhost -- --run-id 987201493-agent120-ubuntu222-v1 --execute`: passed\n- Ubuntu 222 target: exact package verification, empty-root restore, Episode/projection equality, partial rejection, and repeated idempotent restore passed\n- `./shifu check:source`: 156/156 tests passed; build-free source gate passed\n- branch workflow audit before PR: no workflow runs created\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Retain a bounded same-office off-host backup and restore protocol without widening independent-failure-domain, physical-power-loss, or production claims\",\n  \"verification\": [\"Local Core build\", \"agent-120 Core build\", \"agent-120 to Ubuntu 222 off-host restore\", \"partial-transfer rejection\", \"empty-root idempotent restore\", \"build-free source acceptance\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T06:37:42Z",
          "mergedAt": "2026-07-14T06:43:42Z",
          "additions": 2018,
          "deletions": 31,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 827,
          "url": "https://github.com/kungfu-systems/kungfu/pull/827",
          "title": "feat(coordination): merge lock arbiter into per-workspace coordinator",
          "body": "Merge the ADR-0077 named-lock arbiter into the per-workspace coordinator and retire the standalone `Arbiter(peer)`, so a workspace keeps a single resident process (the ADR-rejected alternative was a per-agent daemon).\n\n- `observe(carrier_type, callback)` moves down to the common `reactor` base (peer + coordinator share it).\n- The coordinator gains an `on_react()` hook, admits the lock action envelope in `is_reactable()`, hosts the `LockTable`, grants by writing to the holder's command journal, and reclaims dead holders via the registry pid it already owns (`Register` carries pid) — so a lock request no longer carries a pid and the standalone pid reaper is gone.\n- The client requests from / receives grants on the coordinator's journals; `arbiter_peer.py` is retired; the pure `LockTable` (`arbiter.py`) is unchanged.\n- Audit stays frame-native (requests on the coordinator inbound journal, grants on holder journals) — no bolted-on Episode.\n\nADR-0077 stays `partial` (the `kungfu lock` CLI backend switch is still deferred); this increment refines its delivery to the merged coordinator form.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0077\"],\n  \"summary\": \"Merge the ADR-0077 lock arbiter into the per-workspace coordinator; retire the standalone Arbiter peer; reclaim via registry pid.\",\n  \"verification\": [\n    \"full core build exit 0 (shifu install -> conan configure -> compile); reactor/coordinator/peer/py-runtime compile clean\",\n    \"cross-process harness PASS: race serializes with zero-poll grant, SIGKILLed holder reclaimed via registry pid, instruct delivered to lock holder\",\n    \"mypy clean on changed Python; pre-commit gates green (markdown, C++ clang-format, ruff format/lint, carrier-action-envelope, runtime-greenfield)\"\n  ]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T06:51:30Z",
          "mergedAt": "2026-07-14T07:00:31Z",
          "additions": 185,
          "deletions": 286,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 828,
          "url": "https://github.com/kungfu-systems/kungfu/pull/828",
          "title": "feat(agent): define durable session capsule contract",
          "body": "## Summary\n\nFreeze the first bounded delivery stage for a durable AgentSessionCapsule control plane. The new registered KFD-1 contract gives CLI, GUI, and KFX/Agent clients one provider-neutral interaction authority without claiming that the runtime host or provider adapters already exist.\n\n## Related issue\n\nAtlas goal: 2026-07-14-kungfu-agent-session-capsule-contract\n\n## Changes\n\n- add accepted ADR-0081 and register the agent-session-control-plane-contract welded surface\n- define canonical plan, action, topology, status, delivery, input-ledger, and output-read schemas\n- separate coordinator epoch from session stream epoch and fence all writes by Capsule generation and controller lease\n- reject dual PTY ownership, stale lease/epoch, duplicate input writes, blind modal input, shell fallthrough, silent replay gaps, and terminal delivery as work proof\n- update the generated KFD-1 canonical policy, versioning register, qualification docs, and build-free source gate\n\n## Verification\n\n- ./shifu test:agent-session-contract\n- ./shifu check:source\n- pre-commit staged gate\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0081\"],\n  \"summary\": \"Freeze the registered AgentSessionCapsule identity, authority, interaction, receipt, and failure contract with executable negative fixtures\",\n  \"verification\": [\"agent-session contract fixtures\", \"build-free source acceptance\", \"documentation and ADR audit\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR names Codex and Claude only as future provider adapter identities and updates the KFD-1 contract-world policy. It invokes no provider API, stores no provider output or credentials, changes no billing or deployment behavior, and makes no runtime/product qualification claim.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T07:00:03Z",
          "mergedAt": "2026-07-14T07:06:14Z",
          "additions": 1454,
          "deletions": 4,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 830,
          "url": "https://github.com/kungfu-systems/kungfu/pull/830",
          "title": "fix(docs): bind ADR-0081 to merged contract commit",
          "body": "## Summary\n\nRepair ADR-0081 implementation evidence after PR #828 was integrated with the repository-required rebase merge. The contract implementation is now commit 90e878b696a6a6a6a1a9d21f166f0e63bc527bb2 on dev/v4/v4.0; the original feature SHA is no longer the canonical merged coordinate.\n\nThis clean linear replacement supersedes PR #829, whose old feature branch contains merge commits and therefore cannot pass the repository rebase-only merge policy.\n\n## Changes\n\n- replace the pre-merge feature SHA with the merged, dev-reachable contract implementation SHA\n- preserve ADR-0081 partial status and its existing qualification references\n\n## Verification\n\n- ./shifu check:source\n- pre-commit documentation and ADR audit\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0081\"],\n  \"summary\": \"Bind ADR-0081 implementation evidence to the canonical rebased contract commit already merged on dev/v4/v4.0\",\n  \"verification\": [\"build-free source acceptance\", \"documentation and ADR audit\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes one public ADR evidence pointer to an already merged commit. It does not change runtime behavior, provider integration, publishing, or deployment.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T07:13:50Z",
          "mergedAt": "2026-07-14T07:15:24Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 831,
          "url": "https://github.com/kungfu-systems/kungfu/pull/831",
          "title": "feat(runtime): route profile actions through readiness broker",
          "body": "## Summary\n\n- bind every Profile/KFX action runtimeOperation to the canonical runtime invocation plan\n- keep storage-only callbacks daemonless while routing live-required callbacks through RuntimeCapabilityBroker\n- discover workspace-bound native readiness coordinates, then fail closed on absent, malformed, foreign, changed, or insufficient evidence\n- preserve portable KFD-3 plan and receipt identity while rechecking exact execution material before invocation\n- close ADR-0080 stage 6 without claiming a production-qualified evidence producer or EmbeddedRuntimeHost\n\n## Verification\n\n- `./shifu build:core` (passed)\n- Profile/runtime Python suite after latest rebase: 81 passed\n- `./shifu test:runtime-surface` (7 surfaces, 4 KFX actions)\n- KFX Profile suite: Node 13, navigation 6, shared module 1, runtime foreground 9, Python 11; all passed\n- KFD-3 dual-client proof: Agent CLI and typed Human API produced the same plan, receipt, and witness\n- source gate on the implementation base: 150 contract/tooling tests, 61 documentation contracts, Biome, Ruff, and mypy passed\n- latest mainline rerun is currently blocked only by pre-existing ADR-0081 metadata: it references rebase-predecessor `eed8a90cb760593025afe457f98db79289cd506b` instead of reachable mainline implementation `90e878b69`; the target Python suite remains 81/81 on that base\n- staged pre-commit gate passed\n\n## Governance risk\n\nNo credentials, deployment, release, hosted service, cross-machine lease, distributed election, or production EmbeddedRuntimeHost is changed or claimed. The discovery descriptor contains coordinates rather than readiness proof. Native typed authorities still establish durability and projection at the requested cut, and the domain callback is never invoked after broker refusal. Stage 7 still owns producer qualification and cold product activation evidence.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Close ADR-0080 stage 6 by binding Profile and KFX action invocation to the canonical broker, with daemonless storage execution and fail-closed exact-cut native evidence discovery for live-required work.\",\n  \"verification\": [\"core build passed\", \"Profile and runtime Python suite: 81 passed\", \"runtime surface parity and KFX Profile suite passed\", \"KFD-3 dual-client proof passed\", \"source gate passed before the documented upstream ADR-0081 stale-SHA regression\", \"staged pre-commit gate\"]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T07:16:41Z",
          "mergedAt": "2026-07-14T07:22:13Z",
          "additions": 734,
          "deletions": 179,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 120,
          "url": "https://github.com/kungfu-systems/build-images/pull/120",
          "title": "feat(comparator): add qualification evidence runner",
          "body": "## Summary\n\n- add a frozen-plan runner shared by Aeron, ClickHouse, PostgreSQL, and package-fed Kungfu\n- emit self-contained per-repetition and bundle evidence with split authority and offline verification\n- fail closed on input/artifact drift, incomplete repetitions, ad hoc Compose environment, cleanup failure, expert tuning, and source-building Kungfu inputs\n- keep ordinary comparator smoke explicitly unscored and non-authoritative\n\n## Verification\n\n- `pnpm run check`\n- 13 qualification contract and tamper tests\n- `shellcheck pilots/comparator/scripts/pilot.sh`\n- `actionlint .github/workflows/comparator-qualification.yml`\n- all four test-only plans validate and resolve through the same runner\n\nRefs #119",
          "author": "dongkeren",
          "createdAt": "2026-07-14T07:25:27Z",
          "mergedAt": "2026-07-14T07:28:03Z",
          "additions": 2120,
          "deletions": 6,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 833,
          "url": "https://github.com/kungfu-systems/kungfu/pull/833",
          "title": "feat(durability): qualify agent-120 clean host restart",
          "body": "## Summary\n\nAdd a default-off, two-phase clean-host-restart qualification protocol and retain the first real agent-120 reboot/reopen evidence without widening sudden-power-loss or production claims.\n\n## Related issue\n\nN/A\n\n## Changes\n\n- add an existing-root reopen fixture that verifies durable frontier, records, closed Episode, projection, and fenced ownership generations\n- add a dry-run-default Shifu prepare/verify protocol bound to a sentinel root, clean source SHA, durable resume token, and changed Linux kernel boot ID\n- keep reboot and host-service authority outside the repository harness\n- retain exact pre/post/resume/aggregate reports from a real clean agent-120 reboot and lock their digests in source acceptance\n- update durability, institutional-trust, ADR, and known-limit documentation with the named Linux/x86_64/ext4/NVMe envelope\n\n## Verification\n\n- local Mac `./shifu build:core`: passed using existing Conan cache through a temporary controller-free XDG config\n- local fixture export plus fresh-process reopen: passed\n- agent-120 `./shifu build:core`: passed using existing host-local Conan binaries through the same Shifu protocol\n- agent-120 prepare, clean host reboot, and verify: passed in 118 seconds with changed boot ID\n- post-restart: durable cut 7201:1:3, 3 records, 1 closed Episode, matching projection, and owner generations 1 to 3\n- post-restart system: `/data` remounted, Runner active, failed units 0\n- `./shifu check:source`: 162/162 tests passed; build-free source gate passed\n- branch workflow audit: no feature-branch push workflow and no self-hosted build dispatched\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Retain a bounded real agent-120 clean-host-restart protocol without widening physical-power-loss or production claims\",\n  \"verification\": [\"Local Core build\", \"agent-120 Core build\", \"real clean host reboot\", \"boot-ID-bound durable reopen\", \"immutable evidence digests\", \"build-free source acceptance\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T07:25:47Z",
          "mergedAt": "2026-07-14T07:29:04Z",
          "additions": 1164,
          "deletions": 12,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 122,
          "url": "https://github.com/kungfu-systems/build-images/pull/122",
          "title": "chore(release): publish comparator qualification alpha",
          "body": "## Summary\n\nPromote the comparator Phase A Docker pilot series, including #119 frozen-plan qualification receipts, from `dev/v1/v1.2` to the alpha channel.\n\n## Release intent\n\n- patch impact\n- Buildchain v2 dual-channel flow and contract lock remain unchanged\n- Release Passport and GitHub release remain enabled\n- ordinary Docker smoke remains unscored; only complete verified bundles can carry containerized user-outcome qualification authority\n\nRefs #119",
          "author": "dongkeren",
          "createdAt": "2026-07-14T07:28:37Z",
          "mergedAt": "2026-07-14T07:31:37Z",
          "additions": 3124,
          "deletions": 60,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 834,
          "url": "https://github.com/kungfu-systems/kungfu/pull/834",
          "title": "feat(agent): add durable Capsule PTY host",
          "body": "## Summary\n\nAdd the Stage 2 independent AgentSessionCapsule PTY host for ADR-0081. The Capsule directly owns one synthetic provider PTY outside Electron window lifetime while keeping peer transport, controller leases, provider semantics, and product integration explicitly staged.\n\n## Related issue\n\nADR-0081 Stage 2.\n\n## Changes\n\n- add the `@kungfu-tech/agent-session` package and standalone local Capsule worker\n- fence input, resize, and signal actions by attempt, Capsule generation, stream epoch, and process-start identity\n- retain bounded output with monotonic byte sequences, explicit gaps, and printable text-grid VT snapshots\n- record delivery and lifecycle receipts without semantic outcome or work-state claims\n- qualify ANSI, alternate-screen, raw input, approval prompt, burst overflow, client reconnect, and provider exit with a synthetic PTY\n- expose a fail-visible Darwin node-pty helper diagnostic and ignore generated `.buildchain/tmp` Markdown in the documentation gate\n\n## Verification\n\n- `./shifu test:agent-session-capsule-host` — 7 tests passed\n- `./shifu check:source` — 173 source-contract tests passed; documentation, ADR, type, and Biome gates passed\n- commit hook staged gate passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0081\"],\n  \"summary\": \"Deliver the independent synthetic AgentSessionCapsule PTY host with exact process fencing, bounded replay, VT snapshots, and exit-safe input closure\",\n  \"verification\": [\"./shifu test:agent-session-capsule-host\", \"./shifu check:source\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T07:42:56Z",
          "mergedAt": "2026-07-14T07:49:44Z",
          "additions": 1219,
          "deletions": 8,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 836,
          "url": "https://github.com/kungfu-systems/kungfu/pull/836",
          "title": "feat(durability): admit current-hardware production candidate",
          "body": "## Summary\n\nAdmit the completed current-hardware durability work as an explicit, default-off production candidate while keeping production eligibility and unsupported failure domains false.\n\n## Related issue\n\nN/A\n\n## Changes\n\n- freeze six prerequisite deliveries, exact artifact digests, environments, rerun commands, and fail-closed freshness invalidators\n- add one machine-readable production-candidate admission report and a build-free Shifu source gate\n- project the candidate status from the C++ capability authority through Python, Node, CLI, Episode, and Storage surfaces\n- keep the compatibility bridge as default and rollback authority\n- update durability, institutional-trust, architecture, ADR, known-limit, qualification, and versioning documentation\n- keep physical power loss, independent failure domain, production eligibility, HA, replication, and consensus explicitly false\n\n## Verification\n\n- Mac AppleClang 21 arm64 ./shifu build:core: passed using the existing Conan cache through a temporary controller-free XDG config\n- agent-120 GCC 14 x86_64 ./shifu build:core: passed on exact ready commit aaca63c0917390c6f4bea604a4ac0210f3e1f58f\n- Mac and agent-120 ./shifu test:durability-contract: passed across C++, Python, and Node projections\n- ./shifu check:source: 173/173 tests passed; build-free source gate passed\n- admission checker: 6 inputs, inputs SHA-256 8c8ebd939222da77feab62f9e1c5749dfead0e10adb7db86508075bd393519e9, report SHA-256 24bd0a5ff5f40167982227e7a37af23121988a1a9e97f7a38cba3695d91d90f9\n- no GitHub self-hosted or heavy build was dispatched during development verification\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0068\"],\n  \"summary\": \"Admit the complete current-hardware durability evidence set as a default-off production candidate without widening production claims\",\n  \"verification\": [\"Mac Core build\", \"agent-120 Core build\", \"cross-language durability contract\", \"digest-bound six-input admission\", \"build-free source acceptance\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T08:10:42Z",
          "mergedAt": "2026-07-14T08:13:54Z",
          "additions": 694,
          "deletions": 91,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 838,
          "url": "https://github.com/kungfu-systems/kungfu/pull/838",
          "title": "test(shifu): isolate gate task cache partition",
          "body": "## Summary\n\n- isolate the Gate executor lightweight task fixture in a dedicated runner cache partition\n- prove it remains independent while a development qualification owns its Conan lock\n- retain existing same-partition fail-closed coverage\n\n## Validation\n\n- `./shifu check:source`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This test-isolation fix preserves the existing Shifu cache contract and production Conan lock semantics.\"\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation is unchanged because public behavior and contracts are unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-14T08:25:59Z",
          "mergedAt": "2026-07-14T08:31:05Z",
          "additions": 153,
          "deletions": 5,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 124,
          "url": "https://github.com/kungfu-systems/build-images/pull/124",
          "title": "fix(comparator): bind jobs to workload adapters",
          "body": "## Summary\n\n- add a checked-in, digest-locked PostgreSQL Phase A workload adapter registry and exact 3 job by 7 tier production plan\n- cryptographically bind scenario, job, tier, action, adapter, fixture, and registry identities into run evidence\n- copy adapter inputs into qualification bundles and reject relabelled or tampered evidence during offline verification\n- preserve test-only profile smoke coverage while preventing generic smoke from carrying production authority\n\n## Validation\n\n- `pnpm run check`\n- `pnpm run check:qualification` (19 tests)\n- all 21 adapter job/tier mappings pass the read-only adapter plan command\n- production plan passes `validate-plan` and `plan`\n\n## Runtime note\n\nA local macOS single-scenario smoke reached the immutable image fetch step but was stopped after the required digest images were unavailable locally. No containers were created, and project-scoped cleanup completed. The Linux release workflow remains the authoritative locked-image runtime check.\n\nCloses #123\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T08:51:53Z",
          "mergedAt": "2026-07-14T08:54:37Z",
          "additions": 2168,
          "deletions": 57,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 125,
          "url": "https://github.com/kungfu-systems/build-images/pull/125",
          "title": "chore(release): publish workload adapter alpha",
          "body": "## Summary\n\nPromote the #123 comparator workload-adapter fix from `dev/v1/v1.2` to the alpha channel.\n\n## Included\n\n- digest-locked allowlisted PostgreSQL Phase A workload adapter\n- exact J1/J2/J3 by seven-tier production plan\n- cryptographic run/bundle binding and offline relabel/tamper rejection\n- preserved test-only smoke and qualification authority boundaries\n\n## Validation\n\n- implementation PR #124 merged with all required checks passing\n- `pnpm run check`\n- qualification contract suite: 19 tests\n- Buildchain v2 dual-channel trust and contract checks passing\n\nRelease classification remains patch and image identifiers are unchanged.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T08:55:02Z",
          "mergedAt": "2026-07-14T08:57:40Z",
          "additions": 2168,
          "deletions": 57,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 837,
          "url": "https://github.com/kungfu-systems/kungfu/pull/837",
          "title": "feat(agent): add Capsule peer transport authority",
          "body": "## Summary\n\n- add the AgentSessionCapsule journal/notice authority state machine with one writer, independent cursors, one controller lease, input dedup, exact foreground fencing, restart re-registration, and supervisor adoption\n- bind the production port to native Watcher Peers: action envelopes travel through the writer public mmap journal and the existing nng publication remains the payload-free wakeup plane\n- qualify bounded recovery, resize coalescing, notice loss, no per-reader writer fanout, and a real cross-process Coordinator/writer/reader round trip\n- keep provider semantics, product surfaces, machine restart, and real Codex/Claude smoke explicitly staged for ADR-0081 Stages 4-6\n\n## Verification\n\n- `./shifu test:agent-session-peer-transport` (10/10)\n- `./shifu build:core` (Node/Electron/Python/libwasm build passed)\n- `./shifu test:agent-session-peer-transport:native` (real Coordinator + two Watcher processes; repeated pass)\n- `./shifu check:source` (183/183 source tests; full gate passed)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0081\"],\n  \"summary\": \"Complete Stage 3 transport authority and native ADR-0077 mmap journal plus nng adapter; ADR-0081 remains partial pending Stages 4-6.\",\n  \"verification\": [\"source gate 183 tests\", \"Core build\", \"repeated cross-process native Coordinator and Watcher qualification\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T08:12:20Z",
          "mergedAt": "2026-07-14T08:59:05Z",
          "additions": 1764,
          "deletions": 44,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 839,
          "url": "https://github.com/kungfu-systems/kungfu/pull/839",
          "title": "docs(adr): record C++23 + Rx core language strategy (ADR-0082)",
          "body": "## Summary\n\nRecord ADR-0082, closing the recurring \"should the core migrate to Rust\" question with an evidence-based decision: the core stays C++23 + Rx. The single-writer architecture removes the borrow-checker problem domain; the compile-time registry welds already provide set-level exhaustiveness at a stronger position than per-site match; and the Rx routing algebra (three-axis routing, declarative protocol phases, journal-time replayable timers) is a net expressiveness advantage rather than a compensation.\n\n## Related issue\n\nAtlas goal: 2026-07-14-kungfu-cpp23-rx-language-parity\n\n## Changes\n\n- add accepted ADR-0082 with a ratified three-tier error-handling policy (exceptions + loop boundary / `std::expected` at classify-and-continue seams / value-style scan paths)\n- ratify the closed Hana roster + membership + weld pattern as the canonical exhaustiveness mechanism for type families\n- stage the parity increments (`-Werror=switch`, incremental concepts migration, selective `std::expected`, deducing this / ranges opportunistic)\n- define five observable re-evaluation triggers instead of leaving the question open on sentiment\n- append the ADR index row\n- fix ADR-0081 implementation evidence: the transport delivery recorded pre-rebase branch hashes that the rebase merge rewrote; rebind to the merged mainline commits so the documentation gate accepts mainline history again\n\n## Verification\n\n- ./shifu docs:check (markdown structure, links/anchors/contracts, ADR release contract, ADR authority audit — all green)\n- pre-commit staged gate\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0082\"],\n  \"summary\": \"Record the C++23 + Rx core language strategy: ratify the existing error-boundary and registry-weld baseline, stage the parity increments, and define observable re-evaluation triggers\",\n  \"verification\": [\"deterministic documentation gate\", \"ADR release contract and authority audit\", \"pre-commit staged gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\nThis PR adds one architecture decision record and its index row. It changes no code, no contracts, no build configuration, and makes no runtime or qualification claim.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated (this PR is the documentation)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T08:58:58Z",
          "mergedAt": "2026-07-14T09:10:43Z",
          "additions": 255,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 835,
          "url": "https://github.com/kungfu-systems/kungfu/pull/835",
          "title": "feat(qualification): enforce measured layer gate budgets",
          "body": "## Summary\n\n- retain source-bound Linux/macOS/Windows timing evidence for ADR-0049 Layer Gates\n- select explicit alpha, release-candidate, and full-patrol execution profiles\n- bind effective parameters, policy digest, artifact manifest, and reuse tuple into qualification evidence\n- keep the full three-seed/100k Episode baseline available outside recurring PR qualification\n\n## Verification\n\n- timing evidence source: `3ef767623edd84b0a69ea8259f9101561fc51017`; all three native worktrees clean\n- synchronized linear PR head: `be11e085e76e33c27b70d5a31e27e6ab6f05aa30`; latest target changes are included, the affected 43-test suite passed without a cache override, and the ADR-0081 evidence repair is inherited from target mainline\n- local regression: 43/43 targeted tests, catalog 38 Gates/5 profiles/16 invocations, tooling type check, and repository pre-commit passed\n- macOS wall-clock path: alpha `552.32s`, release-candidate `568.95s`\n- Windows wall-clock path: alpha `622.61s`, release-candidate `631.80s`\n- Linux wall-clock path: alpha `662.39s`, release-candidate `932.86s`\n- every summary reports `status=passed` and `budget.withinLimit=true`; all 9 PR checks passed\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0049\"],\n  \"summary\": \"Complete measured budget profiles and source-bound evidence for ADR-0049 Layer Gates\",\n  \"verification\": [\"three-host timing baseline\", \"three-host alpha and release-candidate qualification\", \"Gate catalog and receipt contract tests\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes only qualification evidence and policy. No package, release, tag, alpha, or stable publication is performed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T07:46:24Z",
          "mergedAt": "2026-07-14T09:15:50Z",
          "additions": 6575,
          "deletions": 123,
          "changedFiles": 100
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 840,
          "url": "https://github.com/kungfu-systems/kungfu/pull/840",
          "title": "feat(agent): add provider interaction adapters",
          "body": "## Summary\n\n- add a provider-neutral AgentSession Interaction Port for status, snapshot, instruct, manual sendKey, and fenced interrupt\n- add versioned Codex 0.144.x and Claude Code 2.1.x redacted TUI adapters with fail-visible drift and raw-human fallback\n- enforce ready-only automatic instruction, bounded busy queues, approval/unknown hold, one atomic bracketed paste plus one Enter, and delivery/outcome separation\n- repair ADR-0081 merged evidence coordinates; keep authenticated approval/deny/semantic dogfood explicitly staged for Stage 6\n\n## Verification\n\n- `./shifu test:agent-session-interaction-adapters` (13/13)\n- `./shifu test:agent-session-peer-transport` (11/11)\n- `./shifu check:source` (199/199 source tests; full build-free gate passed)\n- `./shifu test:agent-session-interaction-adapters:native` (2/2; installed Codex 0.144.3 and Claude Code 2.1.209 version probes under temporary HOME, no auth/private transcript inspection)\n\n## Known limits\n\n- version probes do not prove authenticated TUI interaction or provider semantic outcome\n- approval/deny and interrupt outcome require Stage 6 real-provider product dogfood\n- adapter signature drift fails to `unknown` and requires explicit raw-human fallback\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0081\"],\n  \"summary\": \"Complete Stage 4 provider-neutral interaction policy and versioned Codex/Claude adapters; ADR-0081 remains partial pending product surfaces and real-provider recovery qualification.\",\n  \"verification\": [\"source gate 199 tests\", \"interaction adapter 13 tests\", \"transport regression 11 tests\", \"two no-private-state installed CLI version probes\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T09:34:41Z",
          "mergedAt": "2026-07-14T09:38:26Z",
          "additions": 1193,
          "deletions": 21,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 842,
          "url": "https://github.com/kungfu-systems/kungfu/pull/842",
          "title": "docs(adr): define GUI capability ownership",
          "body": "## Summary\n\nFreeze the capability ownership test between Core authority, replaceable System KFX product projections, and domain-owning Profile KFX before the four extraction stages.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add ADR-0083 with the ownership decision, migration order, and product gates\n- register the accepted decision in the canonical ADR index\n- bind the partial baseline to reachable Profile, navigation, and Agent Console commits\n\n## Verification\n\n- `./shifu docs:check`\n- `./shifu adr:audit -- --json`\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Freeze the shared capability ownership boundary before four independently reviewed extraction stages\",\n  \"verification\": [\"./shifu docs:check\", \"./shifu adr:audit -- --json\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T10:10:37Z",
          "mergedAt": "2026-07-14T10:16:01Z",
          "additions": 262,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 127,
          "url": "https://github.com/kungfu-systems/build-images/pull/127",
          "title": "fix(comparator): derive receipts from observed facts",
          "body": "## Summary\n\n- remove expected answers from adapter-visible execution fixtures\n- derive J1/J2/J3 receipts from retained PostgreSQL observations and tier postconditions\n- verify receipts offline against a separate digest-locked verifier oracle\n- preserve the existing adapter allowlist, mapping, cleanup, relabel, and tamper protections\n\n## Validation\n\n- `pnpm run check`\n- 28 comparator qualification tests\n- all 21 production job/tier adapter plans\n- adapter, semantics, fixture, oracle, and registry digests verified\n\n## Release impact\n\nPatch. No published image identifiers or image runtime contracts change.\n\nCloses #126",
          "author": "dongkeren",
          "createdAt": "2026-07-14T10:13:45Z",
          "mergedAt": "2026-07-14T10:16:33Z",
          "additions": 932,
          "deletions": 168,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 128,
          "url": "https://github.com/kungfu-systems/build-images/pull/128",
          "title": "chore(release): promote v1.2.4 alpha",
          "body": "## Summary\n\nPromote the reviewed #126 comparator semantic-receipt fix from `dev/v1/v1.2` to the alpha channel.\n\n## Release evidence\n\n- PR #127 approved and merged\n- complete Buildchain dual-channel checks passed\n- comparator frozen-plan/offline verifier passed\n- patch release impact\n\nThe Buildchain ref-promotion workflow remains authoritative for versioning, Release Passport generation, and GitHub release publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T10:17:18Z",
          "mergedAt": "2026-07-14T10:19:59Z",
          "additions": 932,
          "deletions": 168,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 843,
          "url": "https://github.com/kungfu-systems/kungfu/pull/843",
          "title": "refactor(gui): make shell profile-neutral",
          "body": "## Summary\n\nMake the GUI Shell profile-neutral while preserving Workspace selection, lazy initialization, and recovery behavior.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- replace the Mission Control default and special fallback with a generic product recommendation and persisted Profile focus\n- degrade missing or empty Profiles to Profile Manager instead of a blank or domain-specific page\n- remove the Create Mission form, IPC channel, and main-process domain write from Workspace UI\n- document the generic `KFE_DEFAULT_PROFILE` assembly seam and bind ADR-0083 to the implementation commit\n\n## Verification\n\n- `./shifu test:kfx-profile-suite`\n- `./shifu check:source`\n- `./shifu build:app`\n- `./shifu docs:check`\n- `./shifu adr:audit -- --json`\n- staged pre-commit gate\n\nThe full `./shifu check` reached unrelated baseline SDK contract drift after all changed-scope checks passed: the base branch already exposes `agent-session` while the SDK expected surface list and rendered canonical policy still contain four surfaces.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Complete the profile-neutral GUI Shell stage without changing Workspace or Profile authority\",\n  \"verification\": [\"./shifu test:kfx-profile-suite\", \"./shifu check:source\", \"./shifu build:app\", \"./shifu docs:check\", \"./shifu adr:audit -- --json\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T10:32:43Z",
          "mergedAt": "2026-07-14T10:34:34Z",
          "additions": 50,
          "deletions": 104,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 847,
          "url": "https://github.com/kungfu-systems/kungfu/pull/847",
          "title": "docs(adr): repair rebased implementation evidence",
          "body": "## Summary\n\nRepair ADR-0083 implementation evidence after PR #843 was rebased into `dev/v4/v4.0`: replace the feature-branch commit `7e17031e` with its mainline-equivalent commit `fb67a700`.\n\n## Related issue\n\nUnblocks current dev documentation and source acceptance checks after PR #843.\n\n## Changes\n\n- update one `implementation_commits` entry in ADR-0083 to the reachable mainline hash\n- leave the ADR decision and partial implementation status unchanged\n\n## Verification\n\n- `node scripts/run-docs-check.mjs` (61/61 documentation contract tests)\n- staged documentation and ADR gates passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Repair the first shell-neutrality stage evidence after rebase merge changed its commit identity\",\n  \"verification\": [\"deterministic documentation gate\", \"ADR evidence reachability checks\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T10:48:55Z",
          "mergedAt": "2026-07-14T10:50:38Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 844,
          "url": "https://github.com/kungfu-systems/kungfu/pull/844",
          "title": "fix(gates): require measurements for new gates",
          "body": "## Summary\n\nClose the Kungfu Gate catalog enforcement gap: every Gate added after the frozen adoption baseline must retain passing, source-bound timing measurements for all declared platforms.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add a versioned measurement coverage manifest with a frozen 33-Gate unmeasured adoption baseline\n- seed the five existing Layer Gate measurements from retained three-platform Shifu receipts\n- fail the catalog check on missing platforms, dirty source, stale definitions, registry/source drift, failed or skipped results, duration drift, and missing receipts\n- generate a human-readable timing table and document the exact new-Gate measurement workflow\n- add fail-closed regressions, including proof that a new Gate cannot be hidden by expanding the baseline\n\n## Verification\n\n- `node --test scripts/check-kungfu-gate-catalog.test.mjs` (15/15)\n- `./shifu check:gate-catalog`\n- `node scripts/source-acceptance.mjs` (203/203 contract tests, tooling type check, Biome, documentation and source gate passed before rebasing the latest dev head)\n- staged pre-commit Gate, documentation, schema, and Biome checks passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This patch enforces Kungfu project measurement evidence using the existing SHIFU-ADR-0004 source-bound receipt contract; it does not change Shifu Gate architecture or receipt semantics.\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe patch reads retained public qualification receipts and validates their source, registry, Gate definition, platform, outcome, and duration fields. It adds no credentials, publication authority, or deployment side effects.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T10:42:02Z",
          "mergedAt": "2026-07-14T10:54:43Z",
          "additions": 811,
          "deletions": 7,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 845,
          "url": "https://github.com/kungfu-systems/kungfu/pull/845",
          "title": "feat(storage): execute KFD-1 durability config",
          "body": "## Summary\n\n- add one KFD-1 configuration contract for visible, durable_group, and durable_sync profiles, including user/workspace scopes, deterministic stream rules, bounded group thresholds, request deadlines, and fail-closed activation\n- execute the resolved policy through Coordinator, Python, and native State Service boundaries with independent native admission, fenced writer leases, receipt identity, timeout reconciliation, and restart-safe exact-request recovery\n- document the complete configuration mechanism, precedence, effects, costs, rollback path, and the exact current-hardware/non-HA claim boundary in the public guide and ADR-0084\n- canonicalize the five-surface KFD-1 contract world after agent-session entered the registry, without changing Buildchain or GitHub workflow sources\n\n## Verification\n\n- Mac: ./shifu check\n- Mac: ./shifu build:core using existing local Conan cache through a temporary no-controller-cache XDG_CONFIG_HOME\n- Mac: native state-service, durability-contract, and durable-ingest tests\n- Mac: Python durability/config/runtime tests (30/30), Skill/KFX type checks, and Skill golden fixtures\n- agent-120: ./shifu check\n- agent-120: ./shifu build:core with GNU 14, x64, C++23, and existing $HOME/.conan2 cache\n- agent-120: native state-service, durability-contract, and durable-ingest tests\n- agent-120: Python durability/config/runtime tests (30/30)\n\n## Scope\n\n- no .github or .buildchain changes in the feature diff\n- no self-hosted CI or release build was dispatched\n- activation stays off by default; strong profiles require current-hardware candidate admission and remain production-ineligible\n- this runtime chain protects records written through engine.durability; it does not silently intercept unrelated legacy journal writers\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0084\"],\n  \"summary\": \"Deliver the complete KFD-1 durability configuration and runtime execution chain with fail-closed current-hardware admission, stable PR evidence, and implemented ADR-0084 closure.\",\n  \"verification\": [\"Mac source gate and Core build\", \"agent-120 source gate and Core build\", \"native durability execution and recovery tests\", \"Python config and runtime tests\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T10:43:19Z",
          "mergedAt": "2026-07-14T11:00:32Z",
          "additions": 3072,
          "deletions": 222,
          "changedFiles": 33
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 846,
          "url": "https://github.com/kungfu-systems/kungfu/pull/846",
          "title": "feat(agent-session): expose shared product control surface",
          "body": "## Summary\n\n- expose one self-describing Agent Session action surface through Electron IPC, runtime-scoped POSIX RPC, Python CLI/KFD-3, KFX, and terminal product views\n- bind one-click Go and Assistant launch to the same Capsule, auto-attach presentation, project all Capsules in Console Hub, and preserve one controller lease with plan/foreground/epoch fencing\n- keep delivery receipts separate from work outcome/proof; approval and unknown states remain fail-closed\n- make source acceptance use portable pinned Python tool fallbacks and repair the upstream ADR-0083 post-rebase evidence pointer\n\n## Verification\n\n- `./shifu test:agent-session-product-surfaces` (8/8)\n- `./shifu test:agent-console-contract` (9/9)\n- `./shifu --filter @kungfu-tech/gui build` (main, preload, renderer passed)\n- `./shifu check:source` (208/208 source tests; mypy 134 source files; full build-free gate passed)\n- `./shifu kfd:buildchain:check` (KFD-1 witness, 3 KFD-2 claims, 114 KFD-3 surfaces)\n\n## Known limits\n\n- Stage 5 hosts Capsule ownership in Electron main; detached worker ownership and restart/adoption remain Stage 6\n- authenticated Codex/Claude interaction, machine restart, privacy/performance campaigns, and promoted Mac product evidence remain Stage 6\n- terminal delivery, provider liveness, and transcript text never prove work progress or completion\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0081\"],\n  \"summary\": \"Complete Stage 5 shared GUI, CLI, KFX/Agent, WorkConsole, Console Hub, Profile-bound and KFD-3 product surfaces; ADR-0081 remains partial pending detached recovery and promoted real-provider qualification.\",\n  \"verification\": [\"product surface 8 tests\", \"Agent Console CLI 9 tests\", \"GUI three-bundle build\", \"source gate 208 tests and 134-file mypy baseline\", \"KFD evidence closure\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T10:46:40Z",
          "mergedAt": "2026-07-14T11:09:31Z",
          "additions": 2933,
          "deletions": 168,
          "changedFiles": 52
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 849,
          "url": "https://github.com/kungfu-systems/kungfu/pull/849",
          "title": "feat(agent): pin Codex App Server contract",
          "body": "## Summary\n\nLinear replacement for #848, required because this repository permits rebase merges while the original branch contained mainline merge commits.\n\nStage the exact-version Codex App Server structured-hybrid contract without changing the shared Agent Interaction Port or the existing Claude/PTTY authority.\n\n## Changes\n\n- pin Codex CLI 0.144.3 and the non-experimental stable App Server surface\n- commit a deterministic 267-file semantic schema manifest and regeneration tool\n- add fail-closed method, envelope, identity, response-correlation, and schema-drift admission\n- add redacted positive/negative fixtures and credential-free native regeneration coverage\n- record the bounded contract/schema stage under ADR-0085\n- preserve the newly merged product-surface registration and source acceptance coverage\n\nVersion impact: minor. This adds an optional public agent-session contract/export; it does not activate runtime routing or change existing provider behavior.\n\n## Verification\n\n- focused Codex, native schema, product surface, Interaction Port, and source-plan tests (37/37)\n- `./shifu check:source` (219/219 after product-surface convergence)\n- pre-commit staged gate (61/61 documentation contract tests)\n- original PR #848 completed all 9 CI checks before the repository merge policy rejected its non-linear history\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0085\"],\n  \"summary\": \"Pin and qualify the exact Codex 0.144.3 stable App Server contract and generated schema bundle without activating runtime routing\",\n  \"verification\": [\n    \"./shifu test:codex-app-server-contract\",\n    \"./shifu test:codex-app-server-contract:native\",\n    \"./shifu test:agent-session-interaction-adapters\",\n    \"./shifu test:agent-session-product-surfaces\",\n    \"./shifu docs:check\",\n    \"./shifu check:source\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe contract consumes only the locally installed Codex CLI stable schema surface. The native gate uses temporary `HOME` and `CODEX_HOME` directories and does not read provider credentials, auth state, or session state. This PR performs no package publication or deployment.\n\n## Checklist\n\n- [x] One linear DCO-signed delivery commit\n- [x] Documentation updated for the new contract\n- [x] Existing product surface and Claude/PTTY adapter tests remain green\n- [x] No runtime route or shared Interaction Port authority changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T11:24:04Z",
          "mergedAt": "2026-07-14T11:27:46Z",
          "additions": 3130,
          "deletions": 1,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 841,
          "url": "https://github.com/kungfu-systems/kungfu/pull/841",
          "title": "feat(runtime): qualify activation product delivery",
          "body": "## Summary\n\n- qualify topology-neutral runtime activation with retained deterministic evidence\n- close SDK/product build toolchain gaps on the managed Core Python runtime\n- integrate the frozen `dev/v4/v4.0@16f02290b` baseline, including KFD-1 durability config, shared agent-session product surfaces, and Codex App Server contracts\n- retain machine-readable Mac product qualification evidence and explicit non-claims\n\n## Qualification\n\n- `./shifu check:source` — passed; 224 source-contract tests\n- `./shifu verify --full --with-app` — 82/82 passed\n- `./shifu runtime:qualify -- --mode execute --with-product` — 8/8 suites passed\n- retained report: `docs/qualification/evidence/runtime-activation/8643f1187/report.json`\n- report SHA-256: `be98265b8dffa96b45d38496b6dc27560daab88afc844588c74150fc8ff5594f`\n- Mac artifact: `20260714T113632Z-8643f1187`\n\n## Boundaries\n\n- qualified on macOS arm64 only\n- no production `EmbeddedRuntimeHost` claim\n- no HA/replication or physical power-cut claim\n- process topology remains a placement adapter behind capability/readiness semantics\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Complete topology-neutral capability-driven runtime activation and retain qualified macOS arm64 product evidence with explicit non-claims.\",\n  \"verification\": [\"source gate 224 tests\", \"full product verification 82/82\", \"runtime activation qualification 8/8\", \"retained report be98265b8dffa96b45d38496b6dc27560daab88afc844588c74150fc8ff5594f\"]\n}\n-->\n\n## Governance risk check\n\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo package publication or deployment is performed by this PR; the retained local product evidence is bounded to macOS arm64.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation and qualification evidence updated\n- [x] Claims remain bounded to the retained report\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T09:42:59Z",
          "mergedAt": "2026-07-14T11:48:55Z",
          "additions": 3256,
          "deletions": 89,
          "changedFiles": 49
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1194,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1194",
          "title": "feat(release): add sealed publication authority",
          "body": "## Summary\n- add a closed-world, project-independent publication authority registry and short-lived sealed admission/capability protocol\n- isolate npm, paper, binary release assets, and web production writes behind an independent verifier and protected Environment\n- add honest runner provenance qualification plus read-only GitHub/npm/provider control-plane audit receipts\n- keep build, controller, preview/staging, and failure-evidence lanes free of product publication authority\n\n## Validation\n- pnpm run check (603 tests)\n- node --check scripts/audit-publication-control-plane.mjs\n- git diff --check\n\n## Live rollout boundary\nThis PR does not modify GitHub Environments, OIDC/IAM, npm trusted publishers, branch/ruleset policy, or runner authorization. Product publication remains fail-closed until those controls are audited and configured separately.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T11:50:37Z",
          "mergedAt": "2026-07-14T11:52:57Z",
          "additions": 3709,
          "deletions": 219,
          "changedFiles": 47
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 853,
          "url": "https://github.com/kungfu-systems/kungfu/pull/853",
          "title": "docs(adr): bind runtime evidence after merge",
          "body": "## Summary\n\nRepair ADR-0080 implementation evidence after PR #841 was rebased into `dev/v4/v4.0`: replace the three feature-branch commit identities with their canonical mainline equivalents.\n\n## Changes\n\n- update only the three `implementation_commits` entries in ADR-0080\n- preserve the implemented decision, qualification report, product artifact, and bounded claims\n\n## Verification\n\n- `./shifu docs:check` (61/61 documentation contract tests)\n- staged documentation and ADR gates passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Bind the implemented runtime activation delivery to the canonical commits created by the required rebase merge\",\n  \"verification\": [\"deterministic documentation gate\", \"ADR evidence reachability checks\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes evidence pointers only. It does not change runtime behavior, qualification claims, publishing, or deployment.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T11:53:30Z",
          "mergedAt": "2026-07-14T11:55:10Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1195,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1195",
          "title": "chore(release): promote dev/v2/v2.12 to alpha/v2/v2.12",
          "body": "## Summary\n\nPromote the reviewed sealed-publication-authority implementation from the protected development line into the v2.12 alpha channel.\n\n## Evidence\n\n- source PR: #1194\n- source SHA: `ccfd5455e0560c3158b7da1767cbe77bf26364f4`\n- dev Verify: https://github.com/kungfu-systems/buildchain/actions/runs/29330452478\n\n## Publication boundary\n\nThis PR moves source authority only. Product publication remains fail-closed until the fresh sealed admission, qualified runner receipt, control-plane audit, exact expected bindings, and protected publication environment are supplied.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T11:56:32Z",
          "mergedAt": "2026-07-14T11:58:51Z",
          "additions": 3709,
          "deletions": 219,
          "changedFiles": 47
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 851,
          "url": "https://github.com/kungfu-systems/kungfu/pull/851",
          "title": "feat(agent): add Codex App Server stdio runtime",
          "body": "## Summary\n\nLinear replacement for #850 after `dev/v4/v4.0` advanced while its checks were running. This branch starts at the current mainline and does not force-push or bypass the up-to-date merge requirement.\n\nAdd the Stage 2 direct-stdio runtime host for the pinned Codex App Server surface without activating product routing or changing the shared Agent Interaction Port.\n\n## Changes\n\n- spawn an absolute executable plus argv with direct stdin/stdout/stderr pipes and no shell\n- install the continuous JSONL reader before the initialize request is written\n- correlate client responses and provider server requests by exact typed request id\n- fence every post-handshake write by SessionAttempt, runtime generation, and process-start identity\n- freeze new admission before the bounded consumer queue hard limit and fail visibly on overflow\n- isolate consumer callback failures, retain stderr metadata only, and mark pipe/runtime loss as outcome unknown\n- add a credential-free synthetic provider proving late turn/start response ordering, malformed/unknown frames, queue pressure, identity isolation, stale writers, pipe loss, and unexpected exit\n- register the runtime test in build-free source acceptance\n\nVersion impact: minor. This adds an optional public agent-session runtime export; existing PTY, Claude, product surface, and provider routing behavior remain unchanged.\n\n## Verification\n\n- `./shifu test:codex-app-server-runtime` (10/10)\n- #850 completed all 9 required CI checks before the up-to-date merge rule rejected its stale base\n- #850 local `./shifu check:source` (229/229, exit 0)\n- #850 pre-commit staged gate, including documentation contracts (61/61)\n- Markdown whole-tree lint (234 files, 0 errors)\n\nLocal non-qualifying probe on #850: `./shifu test:agent-session-capsule-host` reached 56/57; its only failure is the pre-existing native peer test requiring `./shifu build:core` to create `framework/core/dist/kungfu/kungfu_node.node`. The build-free source gate and this PR's runtime test both pass.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0085\"],\n  \"summary\": \"Add the pinned direct-stdio runtime host, continuous reader, exact correlation, bounded queue admission, and attempt process generation fencing without activating product routing\",\n  \"verification\": [\n    \"./shifu test:codex-app-server-runtime\",\n    \"./shifu test:codex-app-server-contract\",\n    \"./shifu test:agent-session-product-surfaces\",\n    \"./shifu docs:check\",\n    \"./shifu check:source\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe runtime consumes only the explicit direct-stdio child process. Synthetic tests use Node under temporary process state, retain no stderr content, and do not read Codex credentials, auth storage, private sessions, or transcripts. This PR performs no publication, deployment, product-route activation, or real provider action.\n\n## Checklist\n\n- [x] Linear DCO-signed delivery history on the latest mainline\n- [x] Runtime and source acceptance documentation updated\n- [x] Existing contract and product-surface tests remain green\n- [x] No shared Interaction Port, PTY authority, or product route changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T11:52:44Z",
          "mergedAt": "2026-07-14T11:59:05Z",
          "additions": 1218,
          "deletions": 6,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 852,
          "url": "https://github.com/kungfu-systems/kungfu/pull/852",
          "title": "refactor(profile): extract Mission Control domain capability",
          "body": "## Summary\n\nMove Mission Control domain semantics behind the exact-root Profile surface and remove the generic Atlas capability from Core API, KFX, and GUI.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add a root-bound generic Profile member adapter plus typed intent, query, assessment, authorization, and receipt transports\n- move Mission/Go/claim/assessment/import/export semantics and types into the Mission Control Profile/KFX\n- remove the public TypeScript Atlas capability, KFX atlas handle, and GUI Atlas IPC relay\n- prove independent Week/Day write, query, assessment, and receipt parity through the same Profile API\n- label Atlas-derived projections with Profile/member roots, request cut, and non-writable authority\n- retain `kungfu atlas` as a CLI-only 4.0-alpha compatibility edge and record the boundary in ADR-0083\n\n## Verification\n\n- `./shifu rebuild:core`\n- `./shifu freeze`\n- `./shifu test:agent-profile-sdk` (52 passed)\n- `./shifu test:profile-kfd3-qualification`\n- `./shifu test:kfx-profile-suite`\n- `./shifu --filter @kungfu-tech/api test:query` (17 passed)\n- `./shifu --filter @kungfu-tech/kfx-view-work-dashboard test` (21 passed)\n- `./shifu --filter @kungfu-tech/kfx-view-work-dashboard build`\n- `./shifu --filter @kungfu-tech/api build`\n- `./shifu --filter @kungfu-tech/kfx build`\n- `./shifu build:app`\n- `./shifu check:source`\n- `./shifu kfd:buildchain:check`\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Complete the Profile domain extraction stage while preserving legacy Atlas read compatibility\",\n  \"verification\": [\"./shifu test:agent-profile-sdk\", \"./shifu test:profile-kfd3-qualification\", \"./shifu test:kfx-profile-suite\", \"./shifu check:source\", \"./shifu build:app\", \"./shifu kfd:buildchain:check\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T11:53:24Z",
          "mergedAt": "2026-07-14T12:11:50Z",
          "additions": 1458,
          "deletions": 725,
          "changedFiles": 44
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 854,
          "url": "https://github.com/kungfu-systems/kungfu/pull/854",
          "title": "docs(adr): bind merged Profile API evidence",
          "body": "## Summary\n\nRepair ADR-0083 implementation evidence after PR #852 was rebased into `dev/v4/v4.0`: replace the feature-branch commit identity with its canonical mainline equivalent.\n\n## Changes\n\n- update only the newest `implementation_commits` entry in ADR-0083\n- preserve the accepted decision, partial implementation status, and all existing evidence\n\n## Verification\n\n- `./shifu docs:check` (documentation contracts passed)\n- source acceptance reached the full suite after restoring evidence reachability\n- staged DCO and documentation gates passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Bind the Profile domain extraction stage to the canonical commit created by the required rebase merge\",\n  \"verification\": [\"deterministic documentation gate\", \"ADR evidence reachability checks\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes one evidence pointer only. It does not change runtime behavior, qualification claims, publishing, or deployment.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Evidence points to the canonical mainline commit\n- [x] No behavior or implementation file changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:16:02Z",
          "mergedAt": "2026-07-14T12:20:14Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 855,
          "url": "https://github.com/kungfu-systems/kungfu/pull/855",
          "title": "feat(agent): add Codex App Server structured interaction adapter",
          "body": "## Summary\n\nAdd ADR-0085 Stage 3: a provider-private structured adapter over the fenced Codex App Server runtime stream. It normalizes lifecycle and control traffic without changing the shared Interaction Port, activating a product route, or claiming semantic work outcome.\n\n## Changes\n\n- add deterministic structured plans and receipts for thread, turn, item, tool, approval, usage, error, and lifecycle events\n- bind every event and plan to runtime identity plus SessionAttempt, generation, and process-start fences\n- require exact provider request/thread/turn/item targets; approvals and other server controls default to deny\n- reject stale targets, sequence gaps, duplicate turn terminals, runtime drift, and mutated plans\n- preserve provider method, typed identities, ordering, and private evidence pointers without retaining raw error messages in receipts\n- keep request/control delivery distinct from semantic outcome, Profile/KFD work state, and proof\n- expose the adapter package entry and include its credential-free tests in source acceptance\n\nVersion impact: minor. This is an additive optional agent-session export; existing PTY, Claude, product-surface, and provider-routing behavior remain unchanged.\n\n## Verification\n\n- `./shifu test:codex-app-server-interaction` (7/7)\n- focused contract/runtime/product suite (30/30)\n- `./shifu check:source` on base `5763b3d7` (241/241, docs 61/61, typecheck and Biome passed)\n- post-rebase source gate reaches the documentation contract and is blocked only by the newly merged unrelated ADR-0083 reference to non-mainline commit `c484adc5`; a separate post-merge evidence repair will restore mainline before this PR is merged\n- pre-commit staged gate passed, including docs 61/61 and Biome\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0085\"],\n  \"summary\": \"Normalize fenced Codex App Server lifecycle and control events into deterministic exact-identity plans and receipts with default-deny controls and no semantic outcome overclaim\",\n  \"verification\": [\n    \"./shifu test:codex-app-server-interaction\",\n    \"./shifu test:codex-app-server-runtime\",\n    \"./shifu test:codex-app-server-contract\",\n    \"./shifu test:agent-session-product-surfaces\",\n    \"./shifu docs:check\",\n    \"./shifu check:source\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe adapter consumes only synthetic fenced runtime events in tests. It reads no Codex credentials, auth storage, private sessions, hidden state, prompts, transcripts, or real provider output. This PR performs no publication, deployment, product-route activation, or real provider action.\n\n## Checklist\n\n- [x] Linear DCO-signed delivery history on the latest mainline at push time\n- [x] Structured adapter and source acceptance documentation updated\n- [x] Existing contract, runtime, and product-surface tests remain green\n- [x] No shared Interaction Port, PTY authority, or product route changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:16:48Z",
          "mergedAt": "2026-07-14T12:24:38Z",
          "additions": 829,
          "deletions": 2,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1196,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1196",
          "title": "fix(release): verify independent publication evidence",
          "body": "## Summary\n\n- fetch the exact PR-stage passport, build summary, controller receipt, manifests, and payload artifacts from the admitted Actions run\n- independently recompute candidate, controller, Gate, manifest, payload, and post-merge source-tree bindings before issuing a publication capability\n- fail closed on platform substitution, payload byte drift, unsafe manifest paths, and missing external evidence\n\nFollow-up to #1194 after the first alpha promotion correctly failed closed without an admission.\n\n## Validation\n\n- `pnpm run check`\n- 606 tests passed\n- workflow inventory/site generation and all four bundled actions passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:25:41Z",
          "mergedAt": "2026-07-14T12:28:03Z",
          "additions": 759,
          "deletions": 64,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 130,
          "url": "https://github.com/kungfu-systems/build-images/pull/130",
          "title": "fix(comparator): normalize Compose project names",
          "body": "## Summary\n- normalize all qualification Compose project names to lowercase portable syntax with a 63-character cap\n- validate the complete production project-name set for uniqueness and fail once on locked Compose config before service startup\n- add frozen T/Z, preflight failure/timeout, cleanup-scope, and Ubuntu current-Compose regression coverage\n\n## Validation\n- `pnpm run check`\n- 32 comparator unit tests\n- local Docker Compose 5.1.2 `config --quiet` with the frozen production project name\n- Buildchain v2-alpha contract lock: unchanged\n\n## Release impact\nPatch. No published image identifier or adapter mapping changes.\n\nCloses #129",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:26:37Z",
          "mergedAt": "2026-07-14T12:29:15Z",
          "additions": 147,
          "deletions": 8,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1197,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1197",
          "title": "chore(release): promote v2.12 dev to alpha",
          "body": "## Summary\n\nPromote the sealed publication authority and independent evidence verifier from `dev/v2/v2.12` to `alpha/v2/v2.12`.\n\nThis candidate includes #1194 and the follow-up independent evidence hardening in #1196. Product publication remains fail-closed until an exact fresh admission and the external publication control plane qualify.\n\n## Evidence\n\n- dev Verify run 29332591550 passed\n- local `pnpm run check`: 606/606 tests passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:29:18Z",
          "mergedAt": "2026-07-14T12:31:28Z",
          "additions": 759,
          "deletions": 64,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 131,
          "url": "https://github.com/kungfu-systems/build-images/pull/131",
          "title": "release: promote v1.2 development to alpha",
          "body": "## Summary\n- promote the #129 comparator Compose project-name fix from `dev/v1/v1.2` to alpha\n- retain the Buildchain v2 dual-channel contract locks and Release Passport publishing path\n\n## Evidence\n- #130: 30 successful checks, including Ubuntu current Compose and both Buildchain channels\n- no new Buildchain drift issue was generated\n\n## Release\nBuildchain will prepare and publish the next `v1.2.4-alpha.*` release after merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:29:41Z",
          "mergedAt": "2026-07-14T12:32:23Z",
          "additions": 147,
          "deletions": 8,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1198,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1198",
          "title": "fix(release): scope payload evidence to product bytes",
          "body": "## Summary\n\n- verify every declared product payload file against bytes downloaded from the exact RC Actions run\n- keep the mutable `.buildchain/` diagnostics envelope bound by the manifest digest, but outside the product-byte set\n- record a separate product payload digest per platform\n\nThis follows live RC evidence from #1197: product bytes matched, while diagnostics files were finalized after the lifecycle manifest scan.\n\n## Validation\n\n- fresh #1197 RC passport, source tree, candidate hash, controller receipt, three manifests, and product payload bytes validated locally\n- `pnpm run check`: 606/606 tests passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:37:51Z",
          "mergedAt": "2026-07-14T12:40:01Z",
          "additions": 34,
          "deletions": 22,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1199,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1199",
          "title": "chore(release): promote product payload evidence to alpha",
          "body": "## Summary\n\nPromote the product-byte evidence scope from `dev/v2/v2.12` to `alpha/v2/v2.12`.\n\n## Evidence\n\n- PR #1198 approved and merged\n- dev Verify run 29333363362 passed\n- fresh #1197 RC product payload bytes validated against all three platform manifests\n- local `pnpm run check`: 606/606 tests passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:41:32Z",
          "mergedAt": "2026-07-14T12:43:20Z",
          "additions": 34,
          "deletions": 22,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 856,
          "url": "https://github.com/kungfu-systems/kungfu/pull/856",
          "title": "feat(agent-session): detach product capsule worker",
          "body": "## Summary\n\n- detach Agent Session Capsule ownership from Electron main into one private local worker with a stable, runtime-scoped endpoint and reconnectable RPC client\n- serialize missing-worker startup across independent clients with a private atomic lock so no client can unlink another workers live socket\n- fence shutdown across the worker, RPC surface, runtime, and provider PTYs; a missing worker starts a new empty runtime instead of claiming recovery\n- harden bounded VT/provider state classification against stale screens while keeping volatile terminal text memory-only\n- retain machine-readable Stage 6 qualification evidence and a metadata-only real-provider dogfood runner\n\n## Verification\n\n- `./shifu test:agent-session-recovery-qualification` (real node-pty; retained p95 1.645 ms, final rerun p95 4.402 ms, ceiling 250 ms)\n- `./shifu check:source` after review fix (246/246 source tests; includes independent-client startup race regression)\n- `./shifu --filter @kungfu-tech/gui build` after rebase (main, preload, renderer passed)\n- authenticated Codex 0.144.3: instruction/output, approval deny, interrupt, Electron-main reconnect, provider termination all passed\n\n## Known limits\n\n- authenticated Claude 2.1.209 reached ready, instruction/output, and main-process reconnect, but its tool-approval surface did not converge within the bounded qualification window\n- Claude deny input was therefore not sent and no Claude approval outcome is claimed; the attempted side effect did not execute\n- evidence records `promotionEligible=false`; this PR does not build, register, or promote a Kungfu product artifact\n- machine restart durability remains unqualified; worker loss intentionally produces a new empty runtime and attempt\n- the package-wide native peer test requires a prebuilt Core binding; the source-only PR gate and scoped Stage 6 qualification do not claim that native build\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0081\"],\n  \"summary\": \"Deliver the Stage 6 detached-worker and recovery qualification implementation slice while ADR-0081 remains partial and product promotion stays blocked by degraded authenticated Claude approval qualification.\",\n  \"verification\": [\"recovery qualification with real node-pty\", \"post-review source gate 246 tests\", \"GUI three-bundle build\", \"authenticated Codex loop passed\", \"Claude degradation retained with promotionEligible false\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:30:09Z",
          "mergedAt": "2026-07-14T12:43:56Z",
          "additions": 1611,
          "deletions": 63,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 857,
          "url": "https://github.com/kungfu-systems/kungfu/pull/857",
          "title": "feat(agent): guard Codex App Server recovery receipts",
          "body": "## Summary\n\nDeliver ADR-0085 Stage 4: Kungfu-owned durable admission/result receipts, exact input and side-effect idempotency, and fail-closed recovery boundaries for the Codex App Server structured adapter. This does not activate a product route or claim provider replay semantics.\n\n## Changes\n\n- add a recovery guard that appends prompt-free provider-private admission metadata before any provider request or control response\n- deduplicate exact completed inputs and side effects to the same durable receipt\n- reject opened or unknown duplicates so a crash window cannot create a second provider write\n- mark unresolved inputs and approvals unknown before closing a lost runtime attempt\n- bind read/resume recovery to an exact immutable old boundary and a distinct new attempt\n- reject runtime-fence drift, ledger gaps/root corruption, closed backpressure admission, and stale controls before provider writes\n- allow PTY fallback only as a new attempt while preserving structured receipts\n- inject the existing Agent Session journal seam; add no database and retain no prompt, transcript, provider output, error text, credentials, or private session state\n- expose the recovery adapter and include its credential-free tests in source acceptance\n\nVersion impact: minor. This is an additive optional agent-session export; shared Interaction Port, Claude/PTTY behavior, provider routing, and product surfaces remain unchanged.\n\n## Verification\n\n- `XDG_CACHE_HOME=/tmp/kungfu-recovery-guards-cache ./shifu test:codex-app-server-recovery` (8/8)\n- focused contract/runtime/interaction/recovery/product suite (30/30)\n- `XDG_CACHE_HOME=/tmp/kungfu-recovery-guards-source-cache ./shifu check:source` on base `c44ccb271` (source tests 254/254, docs 61/61, TypeScript and Biome passed)\n- pre-commit staged gate passed, including docs 61/61 and Biome\n- no real provider process, credential, prompt, transcript, or private session state used\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0085\"],\n  \"summary\": \"Add durable prompt-free admission and result receipts, exact input and side-effect idempotency, immutable unknown or interrupted attempt cuts, and no-blind-replay recovery guards for Codex App Server\",\n  \"verification\": [\n    \"./shifu test:codex-app-server-recovery\",\n    \"./shifu test:codex-app-server-interaction\",\n    \"./shifu test:codex-app-server-runtime\",\n    \"./shifu test:codex-app-server-contract\",\n    \"./shifu test:agent-session-product-surfaces\",\n    \"./shifu docs:check\",\n    \"./shifu check:source\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe implementation and tests use only synthetic runtime events and an in-memory deterministic journal. This PR performs no publication, deployment, product-route activation, real provider action, or private-state inspection.\n\n## Checklist\n\n- [x] Linear DCO-signed delivery history on the latest mainline at push time\n- [x] Recovery guard and source acceptance documentation updated\n- [x] Contract, runtime, interaction, recovery, and product-surface tests remain green\n- [x] No shared Interaction Port, PTY authority, Claude behavior, or product route changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:47:29Z",
          "mergedAt": "2026-07-14T12:51:03Z",
          "additions": 1206,
          "deletions": 2,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 858,
          "url": "https://github.com/kungfu-systems/kungfu/pull/858",
          "title": "build(core): promote exhaustive enum switch to a compile error",
          "body": "## Summary\n\nPromote exhaustive `switch` over closed enums from a warning to a compile error, wiring `-Werror=switch` (Clang/GNU) and `/we4062` (MSVC) into `kungfu_compile_contract`. This is staged-adoption item 1 of ADR-0082: an enumerator with neither a case label nor a default arm now fails the build instead of scrolling past as a warning, so the closed-enum exhaustiveness the registry welds already enforce at set level is now also enforced at every hand-written `switch`.\n\n## Related issue\n\nAtlas goal: 2026-07-14-kungfu-adr0082-staged-increments\n\n## Changes\n\n- `framework/core/.cmake/compiler.cmake`: add `-Werror=switch` for AppleClang/Clang and GNU, and `/we4062` for MSVC, to the shared `kungfu_compile_contract` compile options\n- keep the deliberate `default` arms legal: C4061 / `-Wswitch-enum` (which would flag a `switch` even when it carries a `default`) is intentionally NOT enabled, because the storage offline scanners' unknown-record downgrade paths are a designed state, not an oversight — the ADR calls this out explicitly\n\n## Pre-promotion audit\n\n- 89 translation units (libyijinjing, libkungfu incl. tests, libwasm, bindings) compiled clean under the new flag\n- all 57 `switch` sites in `src/` either enumerate every case or carry a deliberate `default`; **zero** required a new case label, so this is a pure weld with no behavioural change\n- the three storage `switch(carrier_type)` offline scanners (`manifest_catalog.cpp`, `source_registry.cpp`, `episode_manifest.cpp`) keep their unknown-record downgrade `default` arms unchanged, matching ADR-0082 §Staged adoption item 1\n\n## Verification\n\n- Mac / AppleClang: full `pnpm run build:core` green; native ctest 9/9\n- Linux / GCC 14.2 (agent-120): full build green (`cmake-js build done`, only unrelated `-Wsign-compare` warnings remain)\n- Windows / MSVC (VS 18): full build green under `/we4062`\n- pre-commit staged gate\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0082\"],\n  \"summary\": \"Promote exhaustive enum switch to a compile error (-Werror=switch / /we4062) as ADR-0082 staged adoption item 1, after a 89-TU three-platform audit that required zero new case labels\",\n  \"verification\": [\"three-platform full core build (AppleClang, GCC 14.2, MSVC)\", \"native ctest\", \"pre-commit staged gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\nThis PR changes one line block of build configuration. It adds no code, changes no runtime behaviour (the audit found zero switch sites needing a new case), and makes no qualification claim.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated (the compile contract carries an inline comment explaining the flag choice and why C4061 stays off)",
          "author": "dongkeren",
          "createdAt": "2026-07-14T12:53:38Z",
          "mergedAt": "2026-07-14T13:01:44Z",
          "additions": 20,
          "deletions": 8,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 859,
          "url": "https://github.com/kungfu-systems/kungfu/pull/859",
          "title": "ci(runtime): gate complete qualification on promotions",
          "body": "## Summary\n\nRun the complete runtime activation and product qualification inside alpha/release Buildchain verification, and retain the machine report together with a checksummed gzip bundle of every raw suite log.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add the full `runtime:qualify -- --mode execute --with-product` stage to release qualification before the final Gate receipt\n- retain `report.json` and `raw-logs.jsonl.gz` together under the release qualification artifact\n- bind the bundle and each suite member by SHA-256 in the report schema\n- align Profile-based product fixtures and ensure product distribution precedes Profile admission\n- retain a clean Darwin arm64 8/8 qualification report and compressed log bundle\n\n## Verification\n\n- `./shifu check:source` (255/255 source-contract tests on latest `dev/v4/v4.0`)\n- `./shifu runtime:qualify -- --mode execute --with-product --retain docs/qualification/evidence/runtime-activation/b325b9739` (8/8 passed, source dirty=false)\n- `./shifu docs:check:readonly` (61/61 documentation contract tests)\n- `gzip -t docs/qualification/evidence/runtime-activation/b325b9739/raw-logs.jsonl.gz`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This tightens the existing ADR-0080 qualification and release-evidence path without changing the runtime architecture contract\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe retained bundle contains only qualification command output, is checksummed beside the report, and does not widen the report claim boundary.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T13:14:40Z",
          "mergedAt": "2026-07-14T13:16:36Z",
          "additions": 585,
          "deletions": 52,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 860,
          "url": "https://github.com/kungfu-systems/kungfu/pull/860",
          "title": "refactor(query): move domain views into profiles",
          "body": "## Summary\n\nMove Mission Control saved-query rendering semantics from Core into its Profile-owned KFX while retaining generic Query authority and explicit degraded compatibility.\n\n## Changes\n\n- replace the closed Mission Control ViewSpec union with a generic Profile renderer envelope\n- move goal-card filters, five-question reducer identity, validation, and migration into Mission Control / Work Dashboard\n- preserve QueryDefinition and revision history when Profile renderers are absent\n- make native and Python Saved Query catalogs accept arbitrary Profile descriptors without domain interpretation\n- prove the boundary with an independent Week/Day Profile view\n\n## Verification\n\n- ./shifu rebuild:core\n- ./shifu check:source (254/254 contract tests)\n- ./shifu test:kfx-profile-suite\n- ./shifu test:profile-kfd3-qualification\n- targeted Python Profile/Query tests (64 passed)\n- API query tests (17 passed)\n- Work Dashboard tests (25 passed)\n- ./shifu build:app\n- ./shifu kfd:buildchain:check\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Complete the Profile-owned Query ViewSpec extraction stage with explicit legacy preservation\",\n  \"verification\": [\"./shifu check:source\", \"./shifu test:kfx-profile-suite\", \"./shifu test:profile-kfd3-qualification\", \"./shifu build:app\", \"./shifu kfd:buildchain:check\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of credentials, hosted services, branding, publishing, or deployment boundaries\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T13:15:20Z",
          "mergedAt": "2026-07-14T13:20:20Z",
          "additions": 805,
          "deletions": 409,
          "changedFiles": 25
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 862,
          "url": "https://github.com/kungfu-systems/kungfu/pull/862",
          "title": "docs(adr): align query extraction evidence",
          "body": "## Summary\n\nAlign ADR-0083 implementation evidence with the commit SHA created by GitHub rebase merge of PR #860.\n\n## Verification\n\n- implementation commit 36381447657fcda49b7b5c48eafd9703236adcb0 is reachable from dev/v4/v4.0\n- ./shifu check:source\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Align Query/Profile extraction evidence with the canonical rebase-merge commit\",\n  \"verification\": [\"git merge-base --is-ancestor 36381447657fcda49b7b5c48eafd9703236adcb0 dev/v4/v4.0\", \"./shifu check:source\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of credentials, hosted services, branding, publishing, or deployment boundaries\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Evidence points to a canonical reachable commit\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T13:22:37Z",
          "mergedAt": "2026-07-14T13:24:31Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 861,
          "url": "https://github.com/kungfu-systems/kungfu/pull/861",
          "title": "feat(agent): route Codex App Server through product surface",
          "body": "## Summary\n\nDeliver ADR-0085 Stage 5: an opt-in Codex App Server direct-stdio route behind the existing Agent Session product surface. The flag is off by default; the existing Codex and Claude PTY route remains unchanged unless explicitly enabled.\n\n## Changes\n\n- add an exact Codex 0.144.3 product adapter that freezes `codex app-server --stdio` in the reviewed start plan\n- route structured start, instruction, interrupt, approval response, status, snapshot, and receipts through the same GUI/CLI/KFD-3 `invoke` seam\n- reuse the existing product controller/attachment authority and injected Agent Session journal seam without adding another database or GUI-private mutation path\n- project exact provider thread, turn, pending-control, transport, and attempt-boundary metadata without retaining prompts or transcripts\n- preserve semantic outcome, work state, and proof as null delivery non-claims\n- keep feature-off and non-Codex plans/capabilities byte-shape compatible with the PTY surface\n- forbid live hot switching; PTY fallback requires the same WorkConsole/provider, a distinct attempt, and an ended unknown/interrupted structured boundary\n- include the synthetic credential-free product qualification in source acceptance\n\nVersion impact: minor. This is an additive opt-in provider route and package export. The default PTY path, Claude behavior, public product endpoint, and Profile/KFD work authority remain unchanged.\n\n## Verification\n\n- `XDG_CACHE_HOME=/tmp/kungfu-product-integration-cache ./shifu test:codex-app-server-product` (3/3)\n- focused contract/runtime/interaction/recovery/product/detached suite (44/44)\n- `XDG_CACHE_HOME=/tmp/kungfu-product-integration-source-cache ./shifu check:source` after rebasing onto `930ded6f6` (source tests 258/258, docs 61/61, TypeScript and Biome passed)\n- pre-commit staged gate passed, including docs 61/61 and Biome\n- local read-only `codex --version` and `codex app-server --help` confirmed the exact 0.144.3 `app-server --stdio` launch surface\n- no real provider session, credential, prompt, transcript, hidden database, or private state was read\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"ADR-0085\"\n  ],\n  \"summary\": \"Add an opt-in exact-version Codex App Server route through the shared GUI CLI and KFD-3 product surface with frozen per-attempt routing and new-attempt-only PTY fallback\",\n  \"verification\": [\n    \"./shifu test:codex-app-server-product\",\n    \"./shifu test:codex-app-server-recovery\",\n    \"./shifu test:codex-app-server-interaction\",\n    \"./shifu test:codex-app-server-runtime\",\n    \"./shifu test:codex-app-server-contract\",\n    \"./shifu test:agent-session-product-surfaces\",\n    \"./shifu docs:check\",\n    \"./shifu check:source\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe implementation and tests use only synthetic provider traffic. The route is opt-in and this PR performs no publication, deployment, real provider action, credential access, or private-state inspection.\n\n## Checklist\n\n- [x] Linear DCO-signed delivery history on the latest mainline at push time\n- [x] Product route and source acceptance documentation updated\n- [x] Feature flag absent preserves the existing PTY route and capabilities\n- [x] GUI, CLI, and KFD-3 share one reviewed structured action path\n- [x] Hot switching is forbidden and fallback creates a new attempt\n- [x] Delivery receipts do not claim semantic outcome, work state, or proof\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T13:18:37Z",
          "mergedAt": "2026-07-14T13:28:49Z",
          "additions": 1134,
          "deletions": 46,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 863,
          "url": "https://github.com/kungfu-systems/kungfu/pull/863",
          "title": "feat(agent-session): own work console registry in core",
          "body": "## Summary\n\nMove WorkConsole identity, SessionAttempt lifecycle, reviewed plans, and metadata-only receipts from Terminal presentation state into the detached Core Agent Session worker.\n\n## Changes\n\n- add a durable kungfu.work-console-registry/v2 schema and single-writer Core registry\n- resolve one primary WorkConsole for generic WorkRef bindings and retain distinct provider attempts\n- expose the same registry through GUI, CLI, and KFD-3 list/show/resolve-console operations\n- preserve history while marking old attempts unrecoverable after worker continuity loss\n- reduce Terminal persistence to stable console/attempt references plus pane/window presentation\n- compose with both PTY/Capsule and structured Codex product routes without choosing a transport\n\n## Verification\n\n- ./shifu check:source (263 source acceptance tests)\n- ./shifu test:agent-session-product-surfaces (13 passed)\n- ./shifu test:agent-session-recovery-qualification\n- ./shifu test:codex-app-server-product (3 passed)\n- ./shifu test:agent-console-contract (9 passed)\n- ./shifu --filter @kungfu-tech/gui build\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Complete the Core WorkConsole authority extraction while preserving presentation and transport boundaries\",\n  \"verification\": [\"./shifu check:source\", \"./shifu test:agent-session-product-surfaces\", \"./shifu test:agent-session-recovery-qualification\", \"./shifu test:codex-app-server-product\", \"./shifu test:agent-console-contract\", \"./shifu --filter @kungfu-tech/gui build\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of credentials, hosted services, branding, publishing, or deployment boundaries\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T13:48:54Z",
          "mergedAt": "2026-07-14T13:50:58Z",
          "additions": 967,
          "deletions": 440,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 864,
          "url": "https://github.com/kungfu-systems/kungfu/pull/864",
          "title": "docs(adr): align work console authority evidence",
          "body": "## Summary\n\nAlign ADR-0083 implementation evidence with the canonical implementation commit created by GitHub rebase merge of PR #863.\n\n## Verification\n\n- implementation commit 19ed717bd1db545782f366fd47b14ec3a1c35add is reachable from dev/v4/v4.0\n- ./shifu check:source\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Align WorkConsole authority evidence with the canonical rebase-merge implementation commit\",\n  \"verification\": [\"git merge-base --is-ancestor 19ed717bd1db545782f366fd47b14ec3a1c35add dev/v4/v4.0\", \"./shifu check:source\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of credentials, hosted services, branding, publishing, or deployment boundaries\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Evidence points to a canonical reachable commit\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T13:56:37Z",
          "mergedAt": "2026-07-14T13:58:38Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 865,
          "url": "https://github.com/kungfu-systems/kungfu/pull/865",
          "title": "fix(terminal): keep WorkRef launch profile neutral",
          "body": "## Summary\n\n- remove the Mission Control fallback from generic Terminal WorkRef construction\n- reject partial WorkRef launch identity instead of silently rebinding another Profile as Mission Control\n- add a regression test that keeps Terminal WorkRef launch Profile-neutral\n\n## Verification\n\n- ./shifu test:agent-session-product-surfaces\n- ./shifu check:source\n- ./shifu build:app\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Close the final generic Terminal Profile identity leak found by the capability boundary audit\",\n  \"verification\": [\"./shifu test:agent-session-product-surfaces\", \"./shifu check:source\", \"./shifu build:app\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of credentials, hosted services, branding, publishing, or deployment boundaries\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Correct Mission Control callers already pass workProfileId explicitly\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T14:13:51Z",
          "mergedAt": "2026-07-14T14:17:35Z",
          "additions": 33,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 867,
          "url": "https://github.com/kungfu-systems/kungfu/pull/867",
          "title": "docs(adr): align terminal neutrality evidence",
          "body": "## Summary\n\nAlign ADR-0083 implementation evidence with the canonical Terminal Profile-neutrality commit created by GitHub rebase merge of PR #865.\n\n## Verification\n\n- implementation commit 88624d97677a439f557d07f7ae0eeb577a7d8206 is reachable from dev/v4/v4.0\n- ./shifu check:source\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Align final Terminal Profile-neutrality evidence with the canonical rebase-merge implementation commit\",\n  \"verification\": [\"git merge-base --is-ancestor 88624d97677a439f557d07f7ae0eeb577a7d8206 dev/v4/v4.0\", \"./shifu check:source\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of credentials, hosted services, branding, publishing, or deployment boundaries\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Evidence points to a canonical reachable commit\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T14:21:13Z",
          "mergedAt": "2026-07-14T14:23:05Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 866,
          "url": "https://github.com/kungfu-systems/kungfu/pull/866",
          "title": "feat(agent): default Codex to structured transport",
          "body": "## Summary\n\nMake the qualified Codex 0.144.3 App Server structured adapter the product default for new Codex attempts, retain an explicit PTY rollback, and close the provider-scoped Mac convergence qualification.\n\n## Changes\n\n- default new Codex 0.144.3 attempts to direct App Server stdio while retaining `KUNGFU_AGENT_SESSION_CODEX_APP_SERVER=0` as new-attempt-only PTY rollback\n- freeze reviewed structured thread defaults: untrusted approval policy, user reviewer, read-only sandbox, and exact workspace cwd\n- admit three real stable-schema notifications as typed telemetry only, without work, outcome, session, or proof authority\n- expose bounded metadata-only adapter failure and exit diagnostics while never retaining stderr content\n- extend real-provider dogfood across structured instruction/output, exact approval denial, interrupt, main reattach, exit closure, and bounded stale-plan replanning\n- keep Claude PTY authority and its known approval degradation explicit rather than widening Codex evidence into Claude claims\n\nVersion impact: minor. Codex changes its default transport for the exact qualified 0.144.3 provider. The retained flag value `0` rolls new attempts back to PTY; Claude remains PTY-based.\n\n## Verification\n\n- `./shifu test:codex-app-server-contract:native`\n- focused contract/runtime/interaction/recovery/product/surface/provider suites\n- `./shifu test:agent-session-recovery-qualification`\n- authenticated Mac Codex 0.144.3 source-checkout structured dogfood: full retained interaction loop passed\n- authenticated Mac Claude 2.1.209 PTY dogfood: degradation retained, no approval outcome claimed\n- `XDG_CACHE_HOME=/tmp/kungfu-convergence-shifu-cache ./shifu check:source` after rebasing onto `a780b2b33`: source tests 264/264, docs 61/61, TypeScript and Biome passed\n- pre-commit staged gate passed\n- no prompt, transcript, credential, raw terminal, stderr content, private environment value, or provider private state retained\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\n    \"ADR-0085\"\n  ],\n  \"summary\": \"Make the qualified Codex 0.144.3 App Server route the default with exact typed telemetry, safe structured thread policy, real provider qualification, and explicit new-attempt PTY rollback\",\n  \"verification\": [\n    \"./shifu test:codex-app-server-contract:native\",\n    \"./shifu test:codex-app-server-product\",\n    \"./shifu test:codex-app-server-recovery\",\n    \"./shifu test:codex-app-server-interaction\",\n    \"./shifu test:codex-app-server-runtime\",\n    \"./shifu test:agent-session-product-surfaces\",\n    \"./shifu test:agent-session-recovery-qualification\",\n    \"./shifu docs:check\",\n    \"./shifu check:source\"\n  ]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe dogfood uses official ambient CLI authentication but reads no credential or private provider state. Retained evidence is metadata-only and this PR itself performs no publication or deployment.\n\n## Checklist\n\n- [x] DCO-signed linear delivery commit on the latest mainline\n- [x] Codex structured route is default only for the exact qualified version\n- [x] Explicit PTY rollback creates a new attempt and never hot-switches\n- [x] Unknown structured methods still fail closed\n- [x] Claude degradation remains visible and provider-scoped\n- [x] Delivery receipts claim no semantic outcome, work state, or proof\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T14:16:29Z",
          "mergedAt": "2026-07-14T14:25:43Z",
          "additions": 365,
          "deletions": 59,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 870,
          "url": "https://github.com/kungfu-systems/kungfu/pull/870",
          "title": "fix(product): package Agent Session worker",
          "body": "## Summary\n\nPackage the detached Agent Session runtime explicitly so the desktop application's main process can resolve the structured Codex product client and launch its packaged worker.\n\n## Changes\n\n- copy the workspace-linked @kungfu-tech/agent-session runtime, contracts, and pinned schemas into the application resources\n- extend the post-package audit to fail when the product client or detached worker is absent\n- add a regression fixture proving a package without the worker is rejected\n\nVersion impact: patch. This fixes packaging of the already-integrated ADR-0085 product route without changing its architecture contract, wire contract, default transport, or rollback policy.\n\n## Verification\n\n- node --test framework/gui/scripts/bundle-core-audit.test.cjs\n- XDG_CACHE_HOME=/tmp/kungfu-packaged-worker-source-cache ./shifu check:source\n- ./shifu dist:dir\n- post-package audit against the real unsigned macOS arm64 .app\n- Electron main-process resolution of @kungfu-tech/agent-session/product-client\n- authenticated packaged-app Codex 0.144.3 structured dogfood: start, instruction/output, exact approval denial, interrupt, main restart reattach, and provider exit all passed\n- approval probe file was not created\n- git diff --check\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This patch only restores the packaged files required by the already-integrated ADR-0085 product route and adds a package audit regression; it does not change the architecture contract.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe packaged dogfood uses ambient CLI authentication but retains no credential, prompt, transcript, raw terminal, stderr content, or private provider state. The build is an unsigned local qualification artifact and this PR does not publish or promote it.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Post-package audit prevents recurrence\n- [x] Existing structured transport and PTY rollback contracts are unchanged\n- [x] Documentation does not change because this is a packaging correction\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T14:44:39Z",
          "mergedAt": "2026-07-14T14:47:16Z",
          "additions": 60,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 869,
          "url": "https://github.com/kungfu-systems/kungfu/pull/869",
          "title": "refactor(core): classify durability commit failures through std::expected",
          "body": "## Summary\n\nLand ADR-0082 staged item 2: write the three-tier error-handling policy into the\ndeveloper docs, and convert the durability barrier-commit `catch` ladder in\n`durable_ingest.cpp` to `std::expected` + a single `transform_error` classifier\nas the tier-2 reference implementation. This is the first use of `std::expected`\nin `libkungfu`.\n\n## Related issue\n\nAtlas goal: 2026-07-14-kungfu-adr0082-staged-increments\n\n## Changes\n\n- `framework/core/src/libkungfu/src/runtime/durable_ingest.cpp`: replace the\n  hand-written three-arm `catch` ladder in `barrier(...)` with\n  `capture_ingest_exception(commit_barrier).transform_error(classify_durability_failure)`.\n  `capture_ingest_exception` runs the throwing commit body and captures any\n  exception as a value; `classify_durability_failure` is the single place that\n  rethrows-and-catches, mapping the exception type onto the ingest-error /\n  receipt-code / message triple. Only this classify-and-continue seam changes;\n  the poison-tail append handler (which re-throws to an outer boundary) is a\n  tier-1 pattern and is left as-is.\n- `docs/development/cpp-error-handling.md` (new): the three-tier policy — tier 1\n  exceptions to the loop/ring boundary, tier 2 `std::expected` at\n  classify-and-continue seams, tier 3 value-style scan paths — with a\n  when-to-use table and the `durable_ingest` reference. Registered in the\n  document metadata registry and linked from the development index and ADR-0082.\n- `docs/adr/ADR-0082-...md`: mark staged item 2 as landed, link the new policy\n  doc, and add the item-1 mainline commit (`6f20d83c`) to\n  `implementation_commits` now that it is reachable.\n\n## Behaviour equivalence\n\nThe exception → outcome projection is identical to the former ladder:\n\n| Caught | ingest_error | receipt error | receipt status |\n| --- | --- | --- | --- |\n| `std::logic_error` | `FencingLost` | `ServiceUnavailable` | `Unknown` |\n| `std::system_error` | `IoError` | `ServiceUnavailable` | `Unknown` |\n| other `std::exception` | `InjectedFault` | `ServiceUnavailable` | `Unknown` |\n\nValid early returns inside the commit body (timeout, unsupported profile) are\nvalues, not errors, so they flow through `capture_ingest_exception` unchanged.\n\n## Verification\n\n- Linux / GCC (agent-120): full `build:core` green; durability ctests pass —\n  `durable_ingest`, `durability_contract`, `runtime_error`, `state_service`,\n  `projection_bootstrap`, `crash_recovery` (0 failures)\n- Windows / MSVC (VS 18): full `build:core` green under the new `<expected>` use\n- pre-commit staged gate (clang-format 20.1.8, docs metadata + link gate)\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0082\"],\n  \"summary\": \"Land ADR-0082 staged item 2: write the three-tier error-handling policy into developer docs and convert the durable-ingest barrier catch ladder to std::expected + a single transform_error classifier as the tier-2 reference implementation, behaviour-equivalent\",\n  \"verification\": [\"Linux/GCC full core build + durability ctests\", \"Windows/MSVC full core build\", \"pre-commit staged gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\nBehaviour-preserving refactor plus developer documentation. No contract, schema,\nor runtime-outcome change.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated (new error-handling policy doc + ADR)",
          "author": "kungfu-origin",
          "createdAt": "2026-07-14T14:38:36Z",
          "mergedAt": "2026-07-14T14:53:21Z",
          "additions": 173,
          "deletions": 24,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1200,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1200",
          "title": "fix(release): preserve caller-bound npm publishing",
          "body": "## Summary\n- fail fast when sealed publication evidence is absent and report the actual admission-layer denial\n- bind provider trust to the caller workflow separately from the reusable authority workflow\n- preserve the existing no-Environment npm Trusted Publishing identity and keep named Environment lanes strict\n\n## Validation\n- pnpm run check\n- node --test tests/publication-authority.test.mjs\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-14T14:56:29Z",
          "mergedAt": "2026-07-14T14:58:42Z",
          "additions": 290,
          "deletions": 79,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1201,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1201",
          "title": "fix(release): defer npm OIDC authorization",
          "body": "## Summary\n- stop requiring an authenticated npm CLI to preflight OIDC Trusted Publishing\n- bind the exact provider identity and defer final authorization to the npm publish transaction\n- retain optional stronger point-in-time trust evidence through sanitized external JSON\n- avoid treating the npm-token mode label as a real long-lived credential\n\n## Evidence\n- live read-only audit: all six control-plane facts pass without npm credentials\n- pnpm run check\n- git diff --check",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:05:13Z",
          "mergedAt": "2026-07-14T15:08:03Z",
          "additions": 116,
          "deletions": 56,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 871,
          "url": "https://github.com/kungfu-systems/kungfu/pull/871",
          "title": "refactor(core): migrate the highest-traffic SFINAE overloads to concepts",
          "body": "## Summary\n\nFirst batch of ADR-0082 staged item 3: migrate the two highest-traffic\n`enable_if` SFINAE overload pairs in the core to C++20 concepts. `libyijinjing`\nalready compiles as C++20, and these two pairs are the most-instantiated\ndiagnostics surface in the codebase.\n\n## Related issue\n\nAtlas goal: 2026-07-14-kungfu-adr0082-staged-increments\n\n## Changes\n\n- `framework/core/src/libyijinjing/include/kungfu/common.h`: add a named\n  `frame_inline_payload<T>` concept (`size_fixed_v<T> or std::is_same_v<T,\n  nlohmann::json>`) and select the two `event::data<T>()` accessor overloads on\n  `requires frame_inline_payload<T>` / `requires (not frame_inline_payload<T>)`.\n  The return type (`const T &` vs `const T`) is now stated directly instead of\n  wrapped in `std::enable_if_t<..., R>`.\n- `framework/core/src/libyijinjing/include/kungfu/yijinjing/schema/registry.h`:\n  select the `copy()` pair on `requires size_fixed_v<DataType>` / `requires (not\n  size_fixed_v<DataType>)`, returning `void` directly.\n- `docs/adr/ADR-0082-...md`: mark staged item 3 in progress (first batch landed)\n  and add the item-2 mainline commit (`531d40d8`) to `implementation_commits`.\n\n## Equivalence\n\nEach pair's two constraints are exact negations, so overload resolution selects\nthe same overload for every `T` as the former `enable_if` pair — a\nbehaviour-preserving refactor. The observable change is diagnostics: an\nunsatisfied constraint reports `constraints not satisfied` at the call site\nrather than a bare `no type named 'type' in 'std::enable_if_t<...>'`.\n\nThis is the first use of concepts in the core; `enable_if` elsewhere migrates in\nlater batches, no flag-day.\n\n## Verification\n\n- Linux / GCC (agent-120): full `build:core` green — every translation unit that\n  instantiates `event::data<T>()` or `copy()` recompiles under the new\n  constraints; durability / journal / recovery ctests pass\n- Windows / MSVC (VS 18): full `build:core` green\n- pre-commit staged gate (clang-format 20.1.8)\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0082\"],\n  \"summary\": \"First batch of ADR-0082 staged item 3: migrate the two highest-traffic enable_if overload pairs (event::data<T>() and registry copy()) to C++20 concepts, a behaviour-preserving refactor that improves constraint diagnostics\",\n  \"verification\": [\"Linux/GCC full core build + ctests\", \"Windows/MSVC full core build\", \"pre-commit staged gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\nBehaviour-preserving compile-time refactor of two overload constraints.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated (ADR staged-item status)",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:07:53Z",
          "mergedAt": "2026-07-14T15:18:10Z",
          "additions": 30,
          "deletions": 9,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1202,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1202",
          "title": "feat(release): assemble self publication admission",
          "body": "## Summary\n- assemble sealed publication evidence automatically for Buildchain self-promotion only\n- audit the exact authority workflow ref without npm login or repository-admin endpoints\n- restrict workflow_run promotion to verified alpha/release/major channel pushes\n- preserve explicit fail-closed admission for manual and external callers\n\n## Validation\n- pnpm run check (609 passed)\n- bash scripts/check-workflows.sh\n- node --test tests/build-surface.test.mjs (77 passed)\n- real release-candidate artifact assembly smoke against run 29333462403\n- live exact-ref control-plane audit",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:24:44Z",
          "mergedAt": "2026-07-14T15:26:47Z",
          "additions": 514,
          "deletions": 53,
          "changedFiles": 17
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 872,
          "url": "https://github.com/kungfu-systems/kungfu/pull/872",
          "title": "fix(agent-session): qualify packaged provider control",
          "body": "## Summary\n\nClose the Mac product slice of ADR-0081: keep each provider process under the\ndetached AgentSessionCapsule authority, make Claude prompt submission and\napproval detection match the real 2.1.209 TUI, retain one GUI/CLI/Agent control\nsurface, and qualify the packaged Codex/Claude worker before promotion.\n\n## Related issue\n\nAtlas goal: 2026-07-14-kungfu-durable-agent-session-control-plane\n\n## Changes\n\n- Submit Claude bracketed paste and Enter as separately idempotent writes, and\n  recognize the bounded Bash confirmation modal before a coexisting ready\n  prompt can admit automatic input.\n- Preserve fail-closed behavior for generic/unknown modals, stale plans,\n  provider exits, approval states, and version drift; expose public exit\n  metadata without retaining terminal output.\n- Extend the real-provider dogfood harness with Claude model/effort policy,\n  explicit Bash ask configuration, packaged-worker assertions, redacted\n  diagnostics, Codex structured transport, and an explicit PTY rollback route.\n- Record packaged Mac qualification and promotion evidence for build\n  `20260714T150829Z-237b7662f` at `/Applications/Kungfu Episodes.app`.\n\n## Verification\n\n- `./shifu check:source`: 268/268 tests, 61 documentation contract fixtures,\n  TypeScript, Biome, Markdown, links, schemas, and contract gates passed at\n  `ad53886ff40939ecfaa760d98a4076239f58cf8e`.\n- `./shifu dist`: packaged build `20260714T150829Z-237b7662f`; afterPack bundle\n  audit passed and both Darwin node-pty spawn helpers are executable.\n- Packaged Claude 2.1.209 PTY: 6/6 cases passed; explicit Bash ask, sonnet/low,\n  approval denied before the disposable probe could run.\n- Packaged Codex 0.144.3 PTY: 6/6 cases passed.\n- Packaged Codex 0.144.3 structured transport: 6/6 cases passed; feature-off\n  rollback creates a distinct PTY attempt.\n- Installed Agent Session package/client/worker and node-pty helper hashes match\n  the promoted candidate; Shifu catalog reports the build as current.\n- All retained reports are metadata-only: no raw terminal bytes or private\n  environment values.\n\n## Retained limits\n\nMachine-restart recovery and Linux/Windows product qualification remain\nnot-run. ADR-0081 therefore remains partial; this PR claims only the qualified\nMac product slice. The repository-wide `./shifu check` remains blocked by the\npre-existing canonical-policy rendered hash mismatch; this branch does not\nchange those policy inputs, while the complete source gate is green.\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0081\"],\n  \"summary\": \"Qualify and promote the packaged Mac AgentSessionCapsule control plane for Codex PTY, Codex structured transport, and Claude PTY while retaining fail-closed authority and privacy boundaries\",\n  \"verification\": [\"Shifu source gate 268/268\", \"packaged Mac dist and bundle audit\", \"packaged Codex PTY 6/6\", \"packaged Codex structured 6/6\", \"packaged Claude PTY 6/6\", \"installed candidate hash verification\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nProvider CLI behavior is version-pinned and tested through temporary runtimes.\nNo credentials, private transcripts, raw terminal bytes, or provider session\nstate are committed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation and qualification evidence updated\n- [x] Packaged product promoted without terminating or relaunching the running GUI\n\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:20:12Z",
          "mergedAt": "2026-07-14T15:30:17Z",
          "additions": 438,
          "deletions": 68,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 875,
          "url": "https://github.com/kungfu-systems/kungfu/pull/875",
          "title": "feat(gates): add source-bound measurement profile",
          "body": "## Summary\n\n- add a manual, non-publication Shifu profile that measures every task-backed Gate on its supported self-hosted platforms\n- retain source-bound receipts through the pinned Buildchain profile controller\n- keep DCO, Buildchain config, and artifact admission on their real remote-controller boundaries\n- distinguish measurement-only bindings from standing Gate policy sources\n\n## Verification\n\n- `./shifu gate validate`\n- measurement plans: Linux 35 Gates, macOS 32 Gates, Windows 31 Gates, no unsupported selections\n- `./shifu check:gate-catalog`\n- `./shifu check:source` (265 tests pass)\n- pre-commit staged gate\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Adds a diagnostic measurement runner and retained evidence path without changing any product architecture or release-policy requirement.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: the workflow is manual, read-only, pinned to Buildchain v2.12.4, and emits source-bound receipts only; it has no publish permission or publication step.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:28:08Z",
          "mergedAt": "2026-07-14T15:36:33Z",
          "additions": 249,
          "deletions": 87,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1203,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1203",
          "title": "Promote v2.12 publication authority fixes to alpha",
          "body": "## Scope\nPromote the three sealed-publication authority fixes now merged on `dev/v2/v2.12`:\n\n- preserve the caller-bound npm trusted-publisher identity and existing no-Environment contract\n- eliminate false npm-login and credential-scan failures\n- assemble and independently verify Buildchain self-publication admission evidence\n\n## Release impact\nMerging this PR advances `alpha/v2/v2.12` at package version `2.12.7-alpha.0`. The successful push verification is expected to invoke Buildchain Ref Promotion and may publish `@kungfu-tech/buildchain@2.12.7-alpha.0` with npm trusted publishing. Do not merge without explicit release authorization.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:27:47Z",
          "mergedAt": "2026-07-14T15:38:39Z",
          "additions": 866,
          "deletions": 134,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 873,
          "url": "https://github.com/kungfu-systems/kungfu/pull/873",
          "title": "fix(gui): package Agent Session runtime",
          "body": "## Summary\n\n- ship the externalized Agent Session workspace runtime inside the packaged Electron app\n- fail after-pack when any static external main-process dependency cannot resolve from the app\n- add regression coverage for the missing-package failure and product packaging config\n\n## Verification\n\n- node --test framework/gui/scripts/bundle-core-audit.test.cjs product/scripts/dist.test.mjs\n- XDG_CACHE_HOME=/tmp/kungfu-gui-package-closure-cache ./shifu check:source\n- XDG_CACHE_HOME=/tmp/kungfu-gui-package-closure-cache ./shifu product gui build\n- isolated packaged cold launch: KF_GUI_QUALIFICATION_READY and exit 0\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Close the packaged GUI main-process dependency boundary so the WorkConsole product cold-starts from its installed artifact\",\n  \"verification\": [\"node --test framework/gui/scripts/bundle-core-audit.test.cjs product/scripts/dist.test.mjs\", \"./shifu check:source\", \"./shifu product gui build\", \"isolated packaged cold launch\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of credentials, hosted services, branding, publishing, or deployment boundaries\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Installed package resolves every static external main-process dependency\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:21:48Z",
          "mergedAt": "2026-07-14T15:40:54Z",
          "additions": 126,
          "deletions": 13,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 876,
          "url": "https://github.com/kungfu-systems/kungfu/pull/876",
          "title": "feat(runtime): recover live peers across coordinator restart",
          "body": "## Summary\n\nMake live Peer and Agent Session Capsule continuity survive Coordinator replacement without restarting the workload process, fenced by one explicit runtime generation and coordinator epoch authority.\n\n## Related issue\n\nAtlas goal: 2026-07-14-kungfu-live-peer-continuity\n\n## Changes\n\n- add the Core continuity state machine, bounded reconnect, stale authority fencing, and persistent Coordinator epoch allocation\n- project runtime generation through broker, routes, Supervisor, Coordinator, Python bindings, and Agent Session Capsule transport\n- add a real cross-process Coordinator crash/restart campaign and wire the full qualification into alpha/release Buildchain\n- retain checksummed `raw-logs.jsonl.gz` beside `report.json`\n- make the native campaign wait for real Coordinator storage readiness instead of a fixed startup sleep\n- pin the C++ source formatter fallback to the repository version when the ambient formatter drifts\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu rebuild:core`\n- `./shifu live-peer:qualify -- --output .buildchain/runtime/qualification/live-peer-continuity/final-clean-01 --retain product/release/qualification/live-peer-continuity-a7b254786`\n- second consecutive `live-peer:qualify` run at the same clean source revision\n- retained report verdict: passed; source: `a7b2547863b4396d934534707528c41256d5a569`; raw bundle SHA-256: `1ec5e3b5679ad559a4a202399d1785aa32edd6074e442113f6e7bab6d96df2db`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0083\", \"ADR-0086\"],\n  \"summary\": \"Repair rebased ADR-0083 evidence and deliver live Peer and Capsule continuity through fenced Coordinator replacement with retained qualification evidence\",\n  \"verification\": [\"docs:check\", \"check:source\", \"rebuild:core\", \"two clean live-peer:qualify campaigns with retained report and raw log bundle\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR changes release qualification composition and retained local evidence only. It adds no publishing credential or deployment authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:30:31Z",
          "mergedAt": "2026-07-14T15:48:35Z",
          "additions": 2275,
          "deletions": 133,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1204,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1204",
          "title": "fix(release): audit provider-enforced branch transactions",
          "body": "## Root cause\nThe credential-free publication auditor called GitHub's detailed branch-protection endpoint. That endpoint requires repository Administration read permission, so the read-only publication verifier received `403` and incorrectly reported a branch-policy failure before npm/OIDC evaluation.\n\n## Fix\n- bind `--source-sha` to GitHub's public protected-branch summary\n- prove current branch head, same-repository merged PR lineage, independent approval, required `check`, and required app identity\n- retain detailed branch-protection/ruleset auditing when configuration is readable\n- keep missing or mismatched transaction evidence fail-closed\n\n## Evidence\n- live audit of `alpha/v2/v2.12@b434fd84`: all six facts pass\n- `pnpm run check`: 610 tests pass\n- targeted publication/build-surface tests: 94 pass\n- workflow and generated-site checks pass\n\nThis PR does not publish or mutate GitHub/npm control-plane configuration.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:51:28Z",
          "mergedAt": "2026-07-14T15:53:50Z",
          "additions": 184,
          "deletions": 34,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1205,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1205",
          "title": "Promote provider-enforced publication audit to alpha",
          "body": "## Scope\nPromote the credential-free protected-branch transaction audit from PR #1204.\n\n## Prior canary evidence\nThe first `2.12.7-alpha.0` promotion attempt (run 29346311363) stopped before npm because GitHub's detailed branch-protection endpoint returned `403` to the read-only verifier. No package or GitHub Release was published.\n\n## Expected result\nMerging this PR reruns the approved alpha publication transaction for `@kungfu-tech/buildchain@2.12.7-alpha.0`, using protected-branch head, merged PR lineage, independent approval, required check, and required app identity as branch-policy evidence.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:54:05Z",
          "mergedAt": "2026-07-14T15:56:18Z",
          "additions": 184,
          "deletions": 34,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 874,
          "url": "https://github.com/kungfu-systems/kungfu/pull/874",
          "title": "refactor(core): fold reader.cpp journal selection to std::ranges",
          "body": "## Summary\n\nOpportunistic ADR-0082 staged item 4 (ranges): fold the manual filter loop in\n`reader::sort_without_buffer()` to `std::ranges`, discharging the `reader.cpp`\nTODO the ADR names. `libyijinjing` already compiles as C++20.\n\n## Related issue\n\nAtlas goal: 2026-07-14-kungfu-adr0082-staged-increments\n\n## Changes\n\n- `framework/core/src/libyijinjing/src/journal/reader.cpp`:\n  `sort_without_buffer()` replaces the hand-written \"collect has-data journals\n  into a vector, then `std::max_element`\" loop with\n  `journals_ | std::views::values | std::views::filter(...)` fed to\n  `std::ranges::max_element(..., later{})`.\n- `docs/adr/ADR-0082-...md`: record staged item 4 ranges as landed and deducing\n  this as deferred (the `kungfu::data<T>` CRTP base is too widely inherited to be\n  a clean opportunistic target), and add the item-3 mainline commit (`6232f1e1`)\n  to `implementation_commits`.\n\n## Equivalence\n\nSame journals with `has_data()` are considered, compared by the same `later{}`\npredicate, and the same one is assigned to `current_`. The view is lazy where\nthe old vector was eager, but `max_element` consumes it fully either way, so the\nselection is identical. `sort_without_buffer()` runs only on join / disjoin /\nseek, not on the per-frame `next()` path.\n\n## Verification\n\n- Linux / GCC (agent-120): full `build:core` green; journal / reader / mmap /\n  durability / crash-recovery ctests pass\n- Windows / MSVC (VS 18): full `build:core` green\n- pre-commit staged gate (clang-format 20.1.8)\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0082\"],\n  \"summary\": \"Opportunistic ADR-0082 staged item 4 ranges: fold reader::sort_without_buffer() to std::views + std::ranges::max_element, discharging the reader.cpp TODO the ADR names, behaviour-preserving\",\n  \"verification\": [\"Linux/GCC full core build + journal/reader ctests\", \"Windows/MSVC full core build\", \"pre-commit staged gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\nBehaviour-preserving refactor of one journal-selection helper.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated (ADR staged-item status)",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:27:46Z",
          "mergedAt": "2026-07-14T15:59:11Z",
          "additions": 18,
          "deletions": 15,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 879,
          "url": "https://github.com/kungfu-systems/kungfu/pull/879",
          "title": "docs(adr): close GUI capability boundary",
          "body": "## Summary\n\n- mark ADR-0083 implemented with canonical mainline evidence\n- retain the exact macOS arm64 Product qualification report for build 20260714T154905Z-611e39d82\n- document explicit Linux, Windows, machine-restart, and interactive-pixel nonclaims\n\n## Verification\n\n- ./shifu check:source (268/268 on exact candidate)\n- ./shifu dist\n- bundle-core-audit: 7 packaged main dependencies resolve\n- isolated packaged cold launch: KF_GUI_QUALIFICATION_READY\n- authenticated packaged Codex structured provider: 6/6 cases\n- promoted build 20260714T154905Z-611e39d82 and observed installed Electron renderer\n- ./shifu docs:check:readonly (passed before upstream ADR-0086 evidence drift)\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Close the GUI capability ownership migration with exact packaged Product qualification and installed promotion evidence\",\n  \"verification\": [\"./shifu check:source\", \"./shifu dist\", \"bundle-core-audit\", \"packaged cold launch\", \"authenticated Codex structured provider 6/6\", \"installed promotion receipt\", \"./shifu docs:check:readonly\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of credentials, hosted services, branding, publishing, or deployment boundaries\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Exact Product artifact is promoted and rollback material is retained\n- [x] Platform gaps are explicit\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T15:55:58Z",
          "mergedAt": "2026-07-14T16:04:08Z",
          "additions": 199,
          "deletions": 2,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1207,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1207",
          "title": "fix(release): reuse provider transaction governance",
          "body": "## Summary\n\n- reuse GitHub provider-enforced transaction evidence when workflow tokens cannot read administrative branch-protection details\n- bind fallback admission to the exact protected head, merged same-repository PR, independent approval, required successful check, and configured GitHub App\n- retain detailed branch-protection auditing whenever the administrative endpoint is readable\n\n## Validation\n\n- `node --test tests/promote-buildchain-ref.test.mjs` (103/103)\n- `pnpm run check` (610/610)\n- action bundles generated successfully\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-14T16:03:50Z",
          "mergedAt": "2026-07-14T16:07:24Z",
          "additions": 201,
          "deletions": 94,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1208,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1208",
          "title": "release: promote dev v2.12 to alpha",
          "body": "## Release intent\n\nPromote the current protected `dev/v2/v2.12` head to `alpha/v2/v2.12` and execute the sealed Buildchain publication transaction.\n\nThis promotion includes the provider-enforced transaction governance fallback required for read-only GitHub workflow tokens.\n\n## Evidence\n\n- dev source SHA: `22de2f779b81cd67c88dbbdf8ef2787318fb31d0`\n- fix PR: #1207\n- local full check: 610/610\n- fix action tests: 103/103",
          "author": "dongkeren",
          "createdAt": "2026-07-14T16:08:03Z",
          "mergedAt": "2026-07-14T16:10:34Z",
          "additions": 201,
          "deletions": 94,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1210,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1210",
          "title": "fix(release): keep promotion dry-run mutation-free",
          "body": "## Summary\n\n- keep release-candidate promotion dry-runs from reading, creating, or moving publish-gate refs\n- still report the exact source-lock plan consumed by the dry-run action\n- lock the behavior in inventory and build-surface tests\n\n## Validation\n\n- `node --test tests/build-surface.test.mjs` (77 passed)\n- `node scripts/check-inventory.mjs`\n- `git diff --check`\n\n## Safety\n\nNon-dry-run promotion behavior is unchanged. Dry-run now exits the ref mutation branch before any GitHub ref API call.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T16:16:22Z",
          "mergedAt": "2026-07-14T16:24:17Z",
          "additions": 35,
          "deletions": 22,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 881,
          "url": "https://github.com/kungfu-systems/kungfu/pull/881",
          "title": "feat(runtime): retire idle desktop supervisors safely",
          "body": "## Summary\n\nMake the desktop runtime self-maintaining without a resident supervisor for on-demand use, while preserving installed always-on service behavior and refusing unsafe PID-based ownership.\n\n## Related issue\n\nAtlas goal: 2026-07-14-kungfu-desktop-runtime-self-maintenance\n\n## Changes\n\n- serialize activation and idle-exit decisions across threads and processes so concurrent ensure calls spawn one supervisor\n- atomically retire inactive routes and let on-demand supervisors exit after the last child drains\n- keep installed launchd, systemd, and Windows service plans resident through KF_SUPERVISOR_ALWAYS_ON=1\n- bind coordinator adoption and every process signal to exact runtime generation, PID, and process-start identity\n- preserve unowned or PID-reused processes without signalling and surface ownership-unknown\n- add 16-way activation, 100-round cleanup, replacement-race, always-on, orphan, and PID-reuse regression coverage\n- project the new self-maintenance coverage into the unified runtime qualification report\n\n## Verification\n\n- framework/core Python runtime service tests: 30 passed\n- ./shifu check:source: 271 contract tests passed; source gate passed\n- ./shifu check: changed-scope gate passed\n- ./shifu runtime:qualify -- --mode dry-run: planned report includes on-demand-runtime-self-maintenance\n- git diff --check\n- all three commits carry Signed-off-by trailers\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0080\"],\n  \"summary\": \"Complete on-demand desktop runtime self-maintenance with race-safe idle exit and process-start identity fencing\",\n  \"verification\": [\"30 runtime service tests\", \"check:source\", \"changed-scope check\", \"runtime qualification dry-run coverage\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR extends the runtime qualification coverage map and changes no publishing credentials or deployment authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T16:23:57Z",
          "mergedAt": "2026-07-14T16:28:33Z",
          "additions": 644,
          "deletions": 121,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1212,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1212",
          "title": "fix(release): preserve provider-managed channel policy",
          "body": "Supersedes #1211 with a linear-history branch based on the latest dev head.\n\n## Summary\n\n- reuse an already qualifying provider-enforced channel policy when the workflow token cannot read the administrative protection document\n- avoid rewriting existing protected channel policy during post-publish reconciliation\n- fail closed when protection, enforcement for everyone, or the exact required check is absent\n\n## Validation\n\n- targeted action tests: 104/104\n- full `pnpm run check`: 611/611\n- latest dev integration targeted tests: 104/104",
          "author": "dongkeren",
          "createdAt": "2026-07-14T16:30:11Z",
          "mergedAt": "2026-07-14T16:32:52Z",
          "additions": 144,
          "deletions": 53,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 883,
          "url": "https://github.com/kungfu-systems/kungfu/pull/883",
          "title": "feat(runtime): add versioned product upgrade control plane",
          "body": "## Summary\n\nAdd the shared Core authority for versioned product runtime upgrades without giving desktop or standalone CLI transport adapters live-generation authority.\n\n## Related issue\n\nAtlas goal `2026-07-14-kungfu-runtime-upgrade-control-plane`.\n\n## Changes\n\n- register ADR-0087 and `kungfu.product-upgrade.contract/v1` in the KFD-1 contract world\n- add digest-verified side-by-side runtime image installation, quarantine, deterministic compatibility planning, generation staging/reconciliation, rollback, and reference-aware GC\n- pin ProcessRuntimeHost child commands and environment to one immutable runtime image\n- expose dry-run-first `kungfu runtime upgrade` contract, inventory, install, plan, stage, reconcile, and GC surfaces\n- weld the upgrade contract into product compatibility evidence and source/shared gates\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu test:runtime-upgrade`\n- `./shifu --filter @kungfu-tech/sdk run build`\n- `./shifu --filter @kungfu-tech/core run test:tooling`\n- contract audit: current, six surfaces, no failures\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0087\"],\n  \"summary\": \"Freeze and implement the first shared runtime upgrade control-plane slice: immutable images, deterministic plans, generation pins, readiness-gated commit and rollback, and reference-aware GC.\",\n  \"verification\": [\"./shifu check:source\", \"./shifu test:runtime-upgrade\", \"SDK contract CLI tests\", \"Core tooling tests\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe PR defines release identity fields and KFD-1 upgrade evidence only. It does not publish artifacts, use credentials, configure endpoints, or claim signed platform delivery.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T16:32:53Z",
          "mergedAt": "2026-07-14T16:36:59Z",
          "additions": 2746,
          "deletions": 16,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1214,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1214",
          "title": "release: publish Buildchain 2.12.7-alpha.2",
          "body": "Supersedes conflicted dev-to-alpha PR #1213 with the repository-supported same-line publish-gate source lock.\n\n## Source\n\n- exact tree equals protected dev `267afc5b541a0037b29b37cd59356834421df790`\n- source-lock ref: `publish-gate/alpha/v2/v2.12/2.12.7-alpha.2`\n- includes #1210 and #1212\n\n## Intent\n\nPublish `@kungfu-tech/buildchain@2.12.7-alpha.2`, complete GitHub Release evidence, and close the durable publication transaction. `latest` must remain stable.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T16:35:52Z",
          "mergedAt": "2026-07-14T16:38:15Z",
          "additions": 176,
          "deletions": 72,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1216,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1216",
          "title": "fix(release): wire protected ref publication authority",
          "body": "## Summary\n\n- expose the existing `BUILDCHAIN_PROMOTION_TOKEN` to the reusable promotion workflow\n- use it only for generated protected-ref updates while retaining `github.token` for Checks\n- replace the regression assertion that incorrectly required the promotion token to be absent\n- refresh generated site contracts\n\n## Validation\n\n- `pnpm run check` (611 tests passed)\n- targeted promotion workflow contract tests\n\n## Context\n\nThis fixes post-publish alpha finalization after npm trusted publishing succeeds. It restores the documented least-privilege authority split without changing repository variables or secrets.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T16:50:48Z",
          "mergedAt": "2026-07-14T16:53:22Z",
          "additions": 45,
          "deletions": 24,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 884,
          "url": "https://github.com/kungfu-systems/kungfu/pull/884",
          "title": "feat(agent-session): project recoverable product states",
          "body": "## Summary\n\n- project live and retained Agent Session attempts into one product recovery vocabulary\n- keep worker-loss attempts visible with a safe action-required recommendation\n- remove ordinary Capsule terminology from the terminal product surface\n- repair the ADR-0087 evidence SHA rewritten by the immediately preceding rebase merge\n\n## Verification\n\n- ./shifu test:agent-session-product-surfaces (16/16)\n- ./shifu --filter @kungfu-tech/kfx-view-terminal test (8/8)\n- ./shifu test:agent-session-recovery-qualification (passed; local list RPC p95 1.143 ms)\n- ./shifu check:source (passed; 272 code tests and 61 docs contract tests)\n- git diff --check\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0081\"],\n  \"summary\": \"Project retained and live Agent Session attempts into one product recovery vocabulary and keep worker-loss action visible without process terminology\",\n  \"verification\": [\n    \"./shifu test:agent-session-product-surfaces\",\n    \"./shifu --filter @kungfu-tech/kfx-view-terminal test\",\n    \"./shifu test:agent-session-recovery-qualification\",\n    \"./shifu check:source\"\n  ]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T16:52:31Z",
          "mergedAt": "2026-07-14T16:55:02Z",
          "additions": 389,
          "deletions": 28,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1217,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1217",
          "title": "fix(release): wire protected ref publication authority",
          "body": "## Summary\n\n- promote the reviewed publication-authority wiring from dev into the protected alpha channel\n- keep GitHub Actions as the generated Check owner\n- use the existing bypass-capable `BUILDCHAIN_PROMOTION_TOKEN` only for protected ref finalization\n\n## Source lock\n\n- source branch: `publish-gate/alpha/v2/v2.12/2.12.7-alpha.3`\n- source tree exactly matches `dev/v2/v2.12` at `ff80442b7c8ff42d5e10efa7b0c191781241712a`\n- expected prerelease: `@kungfu-tech/buildchain@2.12.7-alpha.3`\n\n## Validation\n\n- dev PR #1216 passed all required checks\n- `pnpm run check` passed locally (611 tests)",
          "author": "dongkeren",
          "createdAt": "2026-07-14T16:54:05Z",
          "mergedAt": "2026-07-14T16:56:21Z",
          "additions": 45,
          "deletions": 24,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1218,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1218",
          "title": "fix(release): report concrete promotion failures",
          "body": "## Summary\n\n- expose the concrete promotion action failure as a bounded single-line output\n- classify post-RC promotion failures from that output instead of reusing the successful RC resolver diagnosis\n- reserve duplicate-build advice for actual duplicate PR/build evidence\n- keep RC resolution details as context without presenting them as the failure cause\n\n## Validation\n\n- `pnpm run check` (611 tests passed)\n- regression test proves a protected-ref failure is reported and successful RC diagnosis is excluded\n- action bundle and generated contract refreshed\n\n## Observed false report\n\nIssues #1206, #1209, and #1215 reported successful RC resolution as the diagnosis and suggested deduplication even though the actual failures occurred later in promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T17:06:10Z",
          "mergedAt": "2026-07-14T17:08:41Z",
          "additions": 60,
          "deletions": 9,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 885,
          "url": "https://github.com/kungfu-systems/kungfu/pull/885",
          "title": "test(runtime): aggregate zero-burden release evidence",
          "body": "## Summary\n\n- add one source/platform-bound zero-burden desktop qualification that aggregates runtime activation, live-peer continuity, recovery projection, product build verification, and evidence retention\n- run the aggregate gate after the component gates in every alpha/release Buildchain path\n- retain report.json and raw-logs.jsonl.gz together for component and aggregate evidence\n- document narrow claims and preserve current authenticated Claude approval dogfood as an explicit nonclaim\n\n## Verification\n\n- ./shifu check\n- ./shifu check:source (276 Node tests; 13 runtime upgrade Python tests)\n- ./shifu build\n- live-peer continuity qualification: passed\n- runtime activation qualification: 8/8 passed\n- zero-burden desktop aggregate qualification: 6/6 coverage, passed\n- Codex 0.144.3 PTY + structured provider dogfood: 6/6 + 6/6\n- git diff --check\n\n## Product evidence\n\n- promoted local candidate: 20260714T181903Z-3bd0302eb\n- source revision: 3bd0302ebb5c38430a2691484e037cb0b260ab7f\n- aggregate report SHA-256: bc8693aa79e7319788a2eb8581556985ddc91f671adc8613db622984487d859c\n- aggregate raw logs SHA-256: 46f35fb2c3a388f465ed8b314534a04747d788d02c504be3ac08c82db11319ed\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0080\", \"ADR-0081\", \"ADR-0086\"],\n  \"summary\": \"Aggregate source-bound zero-burden desktop qualification into alpha and release Buildchain gates with paired report and raw-log retention\",\n  \"verification\": [\n    \"./shifu check\",\n    \"./shifu check:source\",\n    \"./shifu build\",\n    \"zero-burden:qualify\"\n  ]\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-14T17:59:52Z",
          "mergedAt": "2026-07-14T18:15:48Z",
          "additions": 648,
          "deletions": 69,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1219,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1219",
          "title": "fix(gates): reset stale Windows source workspaces",
          "body": "## Summary\n\n- reset the fixed `source` checkout directory before Windows Gate jobs\n- bound cleanup to `GITHUB_WORKSPACE` with an explicit path guard\n- preserve the normal locked-source checkout and add workflow contract coverage\n\n## Why\n\nA cancelled or failed Gate preparation can leave deep pnpm dependency trees in the self-hosted Windows workspace. The next `actions/checkout` then fails in `git clean -ffdx` with `Filename too long` before a Gate receipt can be produced. Native Windows directory removal is able to clear the runner-owned, reproducible checkout reliably.\n\n## Validation\n\n- `node --test tests/build-surface.test.mjs` (77 passed)\n- `pnpm run check:workflows`\n- `git diff --check`\n\n## Downstream validation\n\nKungfu Gate Measurement will be dispatched against the exact PR head SHA before merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T18:27:04Z",
          "mergedAt": "2026-07-14T18:30:58Z",
          "additions": 22,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1220,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1220",
          "title": "fix(gates): preserve Windows source object cache",
          "body": "## Summary\n\n- preserve the prior Windows Gate checkout `.git` directory across native workspace cleanup\n- restore the object store before `actions/checkout` while removing all reproducible worktree residue\n- retain the fixed workspace path guard and add contract coverage\n\n## Why\n\nThe Windows-native cleanup from #1219 removes long-path dependency trees reliably, but deleting `.git` would also discard the complete history already cached on a self-hosted runner. Preserving only the Git object store avoids a slow full-history network fetch while still giving `actions/checkout` a clean worktree.\n\n## Validation\n\n- `node --test tests/build-surface.test.mjs` (77 passed)\n- `pnpm run check:workflows`\n- `pnpm run check:site`\n- live DARKHERO contract probe: `.git/config` restored and `node_modules` removed\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-14T18:35:14Z",
          "mergedAt": "2026-07-14T18:37:26Z",
          "additions": 20,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1221,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1221",
          "title": "fix(gates): expose runner user toolchain",
          "body": "## Summary\n- expose the runner account user toolchain before Shifu Gate execution\n- cover Windows and POSIX PATH behavior with contract tests\n- document runner provisioning ownership\n\n## Validation\n- `pnpm run check`\n- `node --test --test-name-pattern=\"reusable Shifu Gate workflow\" tests/build-surface.test.mjs`\n- `git diff --check`\n\nThis unblocks strict cache profiles that require user-scoped `uv` on self-hosted runners.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T19:28:10Z",
          "mergedAt": "2026-07-14T19:36:27Z",
          "additions": 29,
          "deletions": 9,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 887,
          "url": "https://github.com/kungfu-systems/kungfu/pull/887",
          "title": "fix(gui): close packaged agent session gaps",
          "body": "## Summary\n\nClose three implementation defects found by real macOS packaged GUI dogfood. This does not alter the accepted Agent Session, capability-boundary, or structured-provider architecture contracts.\n\n## Changes\n\n- route Agent Session actions through the generic CLI IPC capability\n- normalize Codex and Claude version-probe output to semantic versions\n- include product status in structured snapshots and keep old workers reattachable through a status fallback\n- render structured sessions without assuming a retained terminal transcript\n- add a changed-file semantic TypeScript gate for GUI sources\n\n## Verification\n\n- `./shifu check:source` (281 Node contract tests; 13 runtime-upgrade tests; TypeScript, Biome, Ruff, and mypy passed)\n- `./shifu product gui pack`\n- real packaged Codex 0.144.3: launch, full GUI quit, same worker/provider PID reattach, semantic instruction receipt, ready recovery, 0 console errors/warnings\n- real packaged Claude 2.1.209: workspace-trust modal, full GUI quit, same worker/provider PID reattach, 0 console errors/warnings; authenticated provider work remains a nonclaim because PATH Claude reports not logged in\n- live-peer continuity qualification: passed; paired report/raw bundle hashes `86f1f9b6e...` / `d142c680e...`\n- runtime activation/product qualification: passed; paired report/raw bundle hashes `01d9300ec...` / `396e0c260...`\n- zero-burden aggregate: 6/6, passed; paired report/raw bundle hashes `09b935cba...` / `0ac836cb3...`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fix packaged GUI IPC wiring, provider version parsing, and structured snapshot rendering defects without changing architecture contracts or supported claims\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe provider boundary remains pinned and redacted; no transcript or credential material is retained. Qualification reports remain source/platform-bound and preserve current nonclaims.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Existing qualification documentation remains accurate because this bugfix does not widen claims\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T19:49:30Z",
          "mergedAt": "2026-07-14T19:52:10Z",
          "additions": 287,
          "deletions": 6,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1222,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1222",
          "title": "fix(build): expose runner user toolchain",
          "body": "## Summary\n\n- expose runner-local tools before native build lifecycle execution\n- cover Windows and POSIX self-hosted runners\n- regenerate the Buildchain contract audit digest\n\n## Validation\n\n- node --test tests/build-surface.test.mjs\n- pnpm check",
          "author": "dongkeren",
          "createdAt": "2026-07-14T21:01:50Z",
          "mergedAt": "2026-07-14T21:03:52Z",
          "additions": 30,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 32,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/32",
          "title": "docs(paper): model observer continuity across incarnations",
          "body": "## Summary\n\n- distinguish a stable logical observer from evidence-bearing observer incarnations\n- define continuity witnesses and separate fact, observer, and presentation continuity\n- map exact-cut runtime readiness, fenced Peer recovery, recoverable product states, and immutable upgrades into the KFD-4 systems argument\n- correct stale claims about Episode capability soundness and the not-yet-implemented dedicated Episode projection\n- preserve explicit single-host and multi-machine evidence boundaries\n\n## Checks\n\n- [x] `make check`\n- [x] Tectonic PDF build completed without warnings\n- [x] All 16 rendered pages inspected\n- [ ] Buildchain `Build` workflow passes\n- [ ] Buildchain `Verify` workflow passes\n\n## Governance\n\n- [x] No credentials, tokens, secrets, or private logs\n- [x] Provider/API/data claims are sourced or clearly marked as future work\n- [x] Public branding and trademark language stays factual\n- [x] Evidence from different source revisions remains explicitly separated",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:02:13Z",
          "mergedAt": "2026-07-14T22:03:27Z",
          "additions": 569,
          "deletions": 227,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 34,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/34",
          "title": "chore(release): prepare observer paper alpha.5",
          "body": "## Summary\n\n- publish the third substantive revision of the observer-declared timelines paper\n- model logical observer incarnations and evidenced continuity across restarts\n- align readiness and recovery claims with the current exact-cut, fenced-recovery, and immutable-runtime evidence\n- advance the publication contract to `0.1.0-alpha.5` while preserving `observer-declared-timelines.pdf`\n\n## Validation\n\n- `make check`\n- `make pdf` (16 pages)\n- `git diff --check`\n\n## Boundaries\n\nThis revision does not claim completed multi-machine projection, accepted-range negotiation, cross-source reconciliation policy, exported observer declarations, or projection causal fsck.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:07:28Z",
          "mergedAt": "2026-07-14T22:11:39Z",
          "additions": 629,
          "deletions": 237,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 36,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/36",
          "title": "chore(release): promote observer paper alpha.5",
          "body": "## Summary\n\nPromote the active v0.1 development line to the alpha channel for `0.1.0-alpha.5`.\n\nThis release carries the third substantive revision of the observer-declared timelines paper, including logical observer incarnations, continuity witnesses, exact-cut readiness, fenced recovery, and explicit evidence boundaries.\n\n## Release contract\n\n- package: `@kungfu-tech/paper-observer-declared-timelines`\n- version: `0.1.0-alpha.5`\n- PDF: `observer-declared-timelines.pdf`\n- Buildchain runtime: accepted `v2` contract at `7c1b0059f239a6a8ab784dbaea926f9f9ab22294`\n\n## Source\n\n- preparation PR: #34\n- development head: `24a6eb78aa91a5d4e9a4fca7b27a1df611964f87`\n\nMerging this PR triggers the managed paper release workflow.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:12:12Z",
          "mergedAt": "2026-07-14T22:13:14Z",
          "additions": 629,
          "deletions": 237,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 37,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/37",
          "title": "fix(release): isolate controller generated state",
          "body": "## Summary\n\n- classify `.buildchain/controller/` as Buildchain-generated evidence state\n- keep controller plan/receipt files out of consumer version-state verification\n- preserve the alpha.5 version and publication contract unchanged\n\n## Evidence\n\nThe first alpha.5 release attempt passed build, verification, contract lock, protected authority, package preparation, and publish-source locking, then failed because `.buildchain/controller/plan.json` appeared as an untracked out-of-version-state file:\n\nhttps://github.com/kungfu-systems/paper-observer-declared-timelines/actions/runs/29372265210\n\nUpstream tracking: kungfu-systems/buildchain#1223\n\n## Validation\n\n- `git check-ignore --no-index -v .buildchain/controller/plan.json`\n- `make check`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:16:18Z",
          "mergedAt": "2026-07-14T22:17:20Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 38,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/38",
          "title": "fix(release): retry observer paper alpha.5 promotion",
          "body": "## Summary\n\nPromote the generated-state boundary fix from the v0.1 development line and retry the managed `0.1.0-alpha.5` paper release.\n\n## Failure closure\n\n- failed release run: https://github.com/kungfu-systems/paper-observer-declared-timelines/actions/runs/29372265210\n- consumer fix: #37\n- upstream tracking: kungfu-systems/buildchain#1223\n- the failed attempt stopped before npm publication, so `0.1.0-alpha.5` remains unpublished\n\n## Release contract\n\n- package: `@kungfu-tech/paper-observer-declared-timelines`\n- version: `0.1.0-alpha.5`\n- PDF: `observer-declared-timelines.pdf`\n- development head: `a8ca82f7bf31dac3ef00a831ca3342ddd8bfaab3`",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:17:41Z",
          "mergedAt": "2026-07-14T22:18:44Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 133,
          "url": "https://github.com/kungfu-systems/build-images/pull/133",
          "title": "fix(comparator): isolate cold image preparation",
          "body": "Fixes #132\n\n## Summary\n- add an unscored exact-digest image preparation phase before repetition 1\n- retain pull attempts, timings, registry logs, local image IDs, and repository digests in the bundle\n- retry transient pull failures with bounded 2s/5s delays and force all counted Compose starts to use `--pull never`\n- bind preparation evidence into bundle/run manifests and recompute its claims during offline verification\n- add a cold-host regression that injects the first transport failure before all 63 formal PostgreSQL steps\n\n## Verification\n- `pnpm run check`\n- `jq empty` on touched JSON contracts\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:27:35Z",
          "mergedAt": "2026-07-14T22:31:59Z",
          "additions": 715,
          "deletions": 14,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 136,
          "url": "https://github.com/kungfu-systems/build-images/pull/136",
          "title": "chore(alpha): promote comparator cold-image preparation",
          "body": "Promote the reviewed #132 fix from `dev/v1/v1.2` through the Buildchain v2 alpha channel.\n\n- source PR: #133\n- exact-digest preparation is unscored and retained\n- transient pulls are bounded before formal execution\n- all counted Compose starts use `--pull never`\n- cold-host regression completes all 63 formal steps\n\nBuildchain must publish the next alpha and a passing Release Passport.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:32:26Z",
          "mergedAt": "2026-07-14T22:36:04Z",
          "additions": 715,
          "deletions": 14,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 889,
          "url": "https://github.com/kungfu-systems/kungfu/pull/889",
          "title": "fix(docs): reject PR-only ADR commit evidence",
          "body": "## Summary\n\nReject ADR commit evidence that is reachable only through a pull request merge preview and would become unreachable after a rebase or squash merge.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- pin ADR evidence reachability to the pull request base SHA in the blocking documentation workflow\n- retain the existing local/merge-preview behavior outside the pull request gate\n- add regression coverage for branch-only evidence and workflow drift\n- document the stable PR-evidence path for in-review implementation work\n\n## Verification\n\n- `KUNGFU_ADR_EVIDENCE_BASE_SHA=$(git rev-parse origin/dev/v4/v4.0) ./shifu gate run docs.prose`\n- `./shifu check:source`\n- staged commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix strengthens validation of existing ADR evidence metadata without changing an architecture contract\"\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change is limited to validation of public ADR evidence metadata and fails closed against the immutable pull request base SHA. It does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:38:51Z",
          "mergedAt": "2026-07-14T22:40:31Z",
          "additions": 122,
          "deletions": 24,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1224,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1224",
          "title": "fix(release): seal exact publication version",
          "body": "## Summary\n- plan the exact release transaction version with the real promotion selector before sealing publication authority\n- bind that exact version to the capability verifier, publish-gate source lock, and final promotion action\n- fail closed if the planned capability version and transaction version drift\n\n## Validation\n- actionlint on changed workflows\n- 105 promote-buildchain-ref unit tests\n- 4 targeted build-surface workflow contract tests\n- buildchain inventory check\n- rebuilt promote-buildchain-ref dist with the repository tsup configuration\n- live read-only ref replay selects v2.12.7-alpha.3 for the pre-alpha.3 state\n\n## Release safety\n- no stable release was triggered\n- no repository/org variables, secrets, environments, or protection settings were changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:39:18Z",
          "mergedAt": "2026-07-14T22:44:28Z",
          "additions": 232,
          "deletions": 90,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 890,
          "url": "https://github.com/kungfu-systems/kungfu/pull/890",
          "title": "fix(gui): recover broken workspace runtimes",
          "body": "## Summary\n- surface the real packaged runtime startup error instead of masking every failure as a missing KFE_PATH\n- offer a guarded one-click backup/reset flow for missing, corrupt, or incompatible workspace journals\n- preserve the complete previous runtime under `.kungfu/backups/runtime-recovery` and relaunch with a fresh runtime\n\n## Verification\n- `./shifu check:source`\n- runtime/workspace Node tests: 7 passed\n- `./shifu dist:dir` (Mac arm64, Conan requirements 12/12 from cache)\n- packaged Electron qualification: binding loaded, `KF_GUI_QUALIFICATION_READY`\n- Shifu build: `20260714T224018Z-586470b49`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fixes packaged GUI runtime error projection and adds a guarded backup-reset recovery action without changing an architecture contract or widening supported claims\"\n}\n-->\n\n## Governance risk check\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe recovery receipt and registered local Product build are provenance surfaces only; this change does not publish or deploy artifacts.\n\n## Checklist\n- [x] Commit is signed off (DCO)\n- [x] Existing architecture claims remain unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:41:03Z",
          "mergedAt": "2026-07-14T22:46:52Z",
          "additions": 282,
          "deletions": 6,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1228,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1228",
          "title": "feat(paper): publish declared artifacts to GitHub releases",
          "body": "## Summary\n\n- derive GitHub Release product assets from the generated publication manifest\n- fail before upload when a declared artifact is missing or collides by basename\n- keep paper consumers declarative and preserve existing passport/evidence assets\n- document and project the updated release surface\n\n## Verification\n\n- `pnpm run check`\n- 613 unit tests passed\n- action bundles and site contracts regenerated\n\nFixes #1225",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:57:55Z",
          "mergedAt": "2026-07-14T23:01:00Z",
          "additions": 148,
          "deletions": 66,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1229,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1229",
          "title": "chore(release): reconcile alpha ancestry into dev",
          "body": "Reconcile the existing `alpha/v2/v2.12` history into dev before the next direct dev-to-alpha promotion.\n\nThis is intentionally a history-only merge:\n\n- the resulting tree is byte-identical to current `dev/v2/v2.12` (`b009bfd0` tree `3a1ca508`);\n- it records `af7ab821` (`2.12.7-alpha.3`) as an ancestor;\n- it changes no Buildchain source, version file, workflow, generated bundle, or publication state;\n- it restores a conflict-free, policy-valid direct `dev/v2/v2.12 → alpha/v2/v2.12` PR path.\n\nNo package is published by this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T22:59:04Z",
          "mergedAt": "2026-07-14T23:03:51Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1230,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1230",
          "title": "release: promote sealed publication authority to alpha",
          "body": "Promote the protected v2.12 development source into the alpha channel after #1229 reconciled alpha ancestry.\n\nThis alpha qualifies the sealed publication authority fix from #1224. The publication workflow now plans the exact transaction version before admission, binds the capability and source-lock to that version, and rejects version drift before publication.\n\nExpected next prerelease: `2.12.7-alpha.4`.\n\nStable publication is not part of this PR and remains separately authorized.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:04:37Z",
          "mergedAt": "2026-07-14T23:06:34Z",
          "additions": 481,
          "deletions": 121,
          "changedFiles": 30
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 28,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/28",
          "title": "fix(release): publish paper PDFs with restored microtype",
          "body": "## Summary\n- pin the corrected Build Images LaTeX toolchain and restore microtype font expansion\n- move all Buildchain workflow callers to the audited v2-alpha contract\n- publish declared PDF artifacts alongside release-passport evidence on GitHub Releases\n- keep the publication manifest as the single source of truth for public PDF filenames\n\n## Verification\n- local Docker PDF builds completed for all three papers using the repaired toolchain source\n- no microtype or font-expansion warnings were present in the final LaTeX logs\n- repository checks and workflow linting passed\n- first-page render inspection found no clipping, overlap, or font corruption\n\nThe GitHub Release PDF projection is provided by Buildchain v2.12.7-alpha.4 (kungfu-systems/buildchain#1228).",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:16:58Z",
          "mergedAt": "2026-07-14T23:20:09Z",
          "additions": 64,
          "deletions": 14,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 24,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/24",
          "title": "fix(release): publish paper PDFs with restored microtype",
          "body": "## Summary\n- pin the corrected Build Images LaTeX toolchain and restore microtype font expansion\n- move all Buildchain workflow callers to the audited v2-alpha contract\n- publish declared PDF artifacts alongside release-passport evidence on GitHub Releases\n- keep the publication manifest as the single source of truth for public PDF filenames\n\n## Verification\n- local Docker PDF builds completed for all three papers using the repaired toolchain source\n- no microtype or font-expansion warnings were present in the final LaTeX logs\n- repository checks and workflow linting passed\n- first-page render inspection found no clipping, overlap, or font corruption\n\nThe GitHub Release PDF projection is provided by Buildchain v2.12.7-alpha.4 (kungfu-systems/buildchain#1228).",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:17:07Z",
          "mergedAt": "2026-07-14T23:20:23Z",
          "additions": 81,
          "deletions": 77,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 39,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/39",
          "title": "fix(release): publish paper PDFs with restored microtype",
          "body": "## Summary\n- pin the corrected Build Images LaTeX toolchain and restore microtype font expansion\n- move all Buildchain workflow callers to the audited v2-alpha contract\n- publish declared PDF artifacts alongside release-passport evidence on GitHub Releases\n- keep the publication manifest as the single source of truth for public PDF filenames\n\n## Verification\n- local Docker PDF builds completed for all three papers using the repaired toolchain source\n- no microtype or font-expansion warnings were present in the final LaTeX logs\n- repository checks and workflow linting passed\n- first-page render inspection found no clipping, overlap, or font corruption\n\nThe GitHub Release PDF projection is provided by Buildchain v2.12.7-alpha.4 (kungfu-systems/buildchain#1228).",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:17:16Z",
          "mergedAt": "2026-07-14T23:20:37Z",
          "additions": 13,
          "deletions": 13,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 29,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/29",
          "title": "release: publish restored-microtype paper alpha",
          "body": "Promote the audited paper release changes from dev to the alpha channel.\n\nThis alpha validates the corrected LaTeX toolchain, the accepted Buildchain v2-alpha contract, and declared PDF publication to GitHub Releases.\n\nStable publication is not part of this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:21:33Z",
          "mergedAt": "2026-07-14T23:23:59Z",
          "additions": 64,
          "deletions": 14,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 25,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/25",
          "title": "release: publish restored-microtype paper alpha",
          "body": "Promote the audited paper release changes from dev to the alpha channel.\n\nThis alpha validates the corrected LaTeX toolchain, the accepted Buildchain v2-alpha contract, and declared PDF publication to GitHub Releases.\n\nStable publication is not part of this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:21:37Z",
          "mergedAt": "2026-07-14T23:24:12Z",
          "additions": 81,
          "deletions": 77,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 40,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/40",
          "title": "release: publish restored-microtype paper alpha",
          "body": "Promote the audited paper release changes from dev to the alpha channel.\n\nThis alpha validates the corrected LaTeX toolchain, the accepted Buildchain v2-alpha contract, and declared PDF publication to GitHub Releases.\n\nStable publication is not part of this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:21:39Z",
          "mergedAt": "2026-07-14T23:24:23Z",
          "additions": 13,
          "deletions": 13,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 30,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/30",
          "title": "fix(release): remove legacy publication token",
          "body": "Remove the legacy long-lived promotion token from the Buildchain paper-release caller. Buildchain v2-alpha now uses sealed publication authority plus caller-bound OIDC trusted publishing and intentionally declares no BUILDCHAIN_PROMOTION_TOKEN secret.\n\nThis fixes the GitHub Actions reusable-workflow startup failure seen on the first alpha promotion attempt.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:26:21Z",
          "mergedAt": "2026-07-14T23:28:38Z",
          "additions": 0,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 26,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/26",
          "title": "fix(release): remove legacy publication token",
          "body": "Remove the legacy long-lived promotion token from the Buildchain paper-release caller. Buildchain v2-alpha now uses sealed publication authority plus caller-bound OIDC trusted publishing and intentionally declares no BUILDCHAIN_PROMOTION_TOKEN secret.\n\nThis fixes the GitHub Actions reusable-workflow startup failure seen on the first alpha promotion attempt.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:26:25Z",
          "mergedAt": "2026-07-14T23:28:50Z",
          "additions": 0,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1232,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1232",
          "title": "fix(controller): allow missing optional stages",
          "body": "## Summary\n\n- keep controller receipts fail-closed when required stages are missing\n- allow optional uninstantiated stages to remain non-blocking\n- add a web-surface regression proving a non-publishing canary can qualify\n- refresh generated site contract digests\n\n## Validation\n\n- pnpm run check\n- 614 unit tests passed\n- workflow checks passed\n- site bundle check passed\n- all four action bundles built",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:27:30Z",
          "mergedAt": "2026-07-14T23:29:13Z",
          "additions": 28,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 41,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/41",
          "title": "fix(release): remove legacy publication token",
          "body": "Remove the legacy long-lived promotion token from the Buildchain paper-release caller. Buildchain v2-alpha now uses sealed publication authority plus caller-bound OIDC trusted publishing and intentionally declares no BUILDCHAIN_PROMOTION_TOKEN secret.\n\nThis fixes the GitHub Actions reusable-workflow startup failure seen on the first alpha promotion attempt.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:26:28Z",
          "mergedAt": "2026-07-14T23:29:47Z",
          "additions": 0,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 892,
          "url": "https://github.com/kungfu-systems/kungfu/pull/892",
          "title": "docs(adr): close C++23 strategy implementation",
          "body": "## Summary\n\nClose ADR-0082 after all finite C++23 language-strategy increments have landed. The record now distinguishes implementation completion from ongoing template maintenance and records why deducing this is not adopted for `kungfu::data<T>`.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add the merged ranges commit and qualification references for the compiler, error-policy, concepts, registry, and journal-reader increments\n- define remaining SFINAE conversions as opportunistic maintenance rather than an ADR completion gate\n- record that replacing the reflection and pack-layout CRTP would be an invasive redesign without a measured defect or maintenance burden\n- add a measurable re-evaluation trigger for a future CRTP replacement\n\n## Verification\n\n- `./shifu docs:check`\n- pre-commit staged gate\n- ADR authority and release-contract audits included by the documentation gate\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0082\"],\n  \"summary\": \"Close the finite C++23 language-strategy increments and record the evidence-based decision to retain kungfu::data<T> CRTP\",\n  \"verification\": [\"./shifu docs:check\", \"pre-commit staged gate\", \"ADR authority and release-contract audits\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR updates ADR implementation and qualification evidence only; it does not change release execution or publishing.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:29:12Z",
          "mergedAt": "2026-07-14T23:31:33Z",
          "additions": 41,
          "deletions": 31,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1233,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1233",
          "title": "release: promote dev/v2/v2.12 to alpha",
          "body": "## Summary\n\nPromote the current protected development line to alpha after the controller receipt qualification fix merged in #1232.\n\n## Expected release\n\n- next alpha: 2.12.7-alpha.5\n- exact source SHA: 332375129559aa7340d6cbd9dcc997bca95242cd\n- stable is not requested by this PR",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:29:47Z",
          "mergedAt": "2026-07-14T23:32:05Z",
          "additions": 28,
          "deletions": 4,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 31,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/31",
          "title": "release: publish paper alpha through sealed OIDC",
          "body": "Promote the corrected Buildchain paper-release caller to alpha.\n\nThe legacy long-lived promotion token has been removed; publication now follows the reusable workflow sealed-authority and caller-bound OIDC contract. The previous alpha push failed before workflow expansion and published no package or tag.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:30:01Z",
          "mergedAt": "2026-07-14T23:32:41Z",
          "additions": 0,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 27,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/27",
          "title": "release: publish paper alpha through sealed OIDC",
          "body": "Promote the corrected Buildchain paper-release caller to alpha.\n\nThe legacy long-lived promotion token has been removed; publication now follows the reusable workflow sealed-authority and caller-bound OIDC contract. The previous alpha push failed before workflow expansion and published no package or tag.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:30:03Z",
          "mergedAt": "2026-07-14T23:32:46Z",
          "additions": 0,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 42,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/42",
          "title": "release: publish paper alpha through sealed OIDC",
          "body": "Promote the corrected Buildchain paper-release caller to alpha.\n\nThe legacy long-lived promotion token has been removed; publication now follows the reusable workflow sealed-authority and caller-bound OIDC contract. The previous alpha push failed before workflow expansion and published no package or tag.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:30:07Z",
          "mergedAt": "2026-07-14T23:32:50Z",
          "additions": 0,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1236,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1236",
          "title": "fix(paper): preserve authority action permissions",
          "body": "## Summary\n- grant `actions: read` to the nested paper publication authority\n- assert reusable-workflow permission monotonicity in the paper release contract test\n- refresh the generated Buildchain contract digest\n\n## Verification\n- `pnpm run check`\n- `git diff --check`\n\nCloses #1235\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:38:27Z",
          "mergedAt": "2026-07-14T23:44:32Z",
          "additions": 7,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1237,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1237",
          "title": "release: promote paper authority permission fix to alpha",
          "body": "## Summary\nPromote the paper reusable-workflow permission fix from `dev/v2/v2.12` to the alpha channel.\n\n## Evidence\n- Buildchain PR #1236\n- full local `pnpm run check` passed\n- GitHub Verify and Build Surface Fixture passed\n\n## Expected publication\nThe managed release flow should prepare and publish the next `2.12.7-alpha` version, advancing `v2-alpha` and `v2.12-alpha`.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:45:24Z",
          "mergedAt": "2026-07-14T23:47:27Z",
          "additions": 7,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 138,
          "url": "https://github.com/kungfu-systems/build-images/pull/138",
          "title": "fix(comparator): preserve retried preparation evidence",
          "body": "## Summary\n- preserve image and attempt indices in pull and inspect log paths\n- run actual retry preparation output through the offline bundle verifier and reject failed-log tampering\n- update Buildchain alpha/stable contract locks with separate exact package worlds and regenerate KFD evidence\n\n## Verification\n- `pnpm run check`\n- Buildchain `v2.12.7-alpha.4` and `v2.12.6` Release Passports: `trust: pass`, no issues\n\nCloses #137\nCloses #134\nCloses #135",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:40:08Z",
          "mergedAt": "2026-07-14T23:48:07Z",
          "additions": 214,
          "deletions": 124,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 140,
          "url": "https://github.com/kungfu-systems/build-images/pull/140",
          "title": "chore(release): promote v1.2 fixes to alpha",
          "body": "## Summary\n- publish the #137 comparator retry-evidence fix\n- publish refreshed Buildchain v2 alpha/stable contract locks and KFD evidence\n- retain selective image publishing; this change does not modify Dockerfiles\n\n## Verification\n- PR #138 checks passed\n- local `pnpm run check` passed\n- Buildchain alpha/stable Release Passports verified\n\nRelease Passport and GitHub Release remain required by Buildchain promotion.",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:48:40Z",
          "mergedAt": "2026-07-14T23:51:22Z",
          "additions": 214,
          "deletions": 124,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 896,
          "url": "https://github.com/kungfu-systems/kungfu/pull/896",
          "title": "refactor(core): express data member constraints as concepts",
          "body": "## Summary\n\nDeliver the next bounded ADR-0082 concepts maintenance increment by replacing five function-level SFINAE constraints in `data<T>` with named concepts and `requires` clauses. Runtime behavior and overload partitions remain unchanged.\n\n## Related issue\n\nADR-0082 concepts policy, item 3 incremental maintenance.\n\n## Changes\n\n- Add named concepts for numeric initialization and the three mutually exclusive JSON member-decoding partitions.\n- Convert the two `init_member` overloads and three `restore_from_json` overloads from `enable_if_t<..., void>` to explicit `void` plus `requires`.\n- Keep every function body unchanged.\n- Audit the remaining 37 code-level `enable_if` sites: retain 14 partial-specialization sites because concepts do not remove their specialization-selection role; retain the four `hana_sqlite.h::make_default` SQLite seam overloads for separately scoped validation; leave 14 other Kungfu-owned function constraints for later benefit-ordered batches.\n- Preserve the implemented ADR-0082 closure from PR #892 while recording this later maintenance batch.\n\nRepresentative diagnostic probe:\n\n- Before: the candidate is ignored because the raw predicate requirement is not satisfied.\n- After: the compiler reports `constraints not satisfied`, names `data_json_direct_member`, and shows the exact predicate that evaluated to false.\n\n## Verification\n\n- `./shifu check:source`: passed (281 tooling tests, 13 runtime-upgrade tests, C++ format and source contracts).\n- Staged pre-commit gate and `./shifu docs:check`: passed.\n- AppleClang C++23 `-fsyntax-only` through a sibling compile database: 69 current translation units passed; one stale database entry for removed `webserver.cpp` was excluded explicitly.\n- Negative diagnostic probes: both failed as intended; the concepts version exposed the named constraint chain.\n- Mac AppleClang: `./shifu build:core` plus durability-contract, durable-ingest, crash-recovery, state-service, and projection-bootstrap passed on tree-identical validated head `1bb66940d` and current clean head `e331aa4eb`.\n- Linux GCC 14.2 on agent-120: the same build and five-test matrix passed on tree-identical validated head `1bb66940d` and current clean head `e331aa4eb`.\n- Windows MSVC 19.51 on DARKHERO: `./shifu build:core` passed on tree-identical validated head `1bb66940d` and current clean head `e331aa4eb`; durability-contract, durable-ingest, crash-recovery, and projection-bootstrap passed. The state-service test reached the native binary but its temporary journal stretch returned Win32 error 112 twice despite 1.4 TiB free; Mac/Linux coverage of that test passed.\n- GitHub delivery intent, docs, source acceptance, promotion rehearsal, signoff, and validate checks: passed.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0082\"],\n  \"summary\": \"Migrate the data member initialization and JSON decode overload partition from SFINAE to named concepts without changing behavior\",\n  \"verification\": [\"Source acceptance passed\", \"AppleClang syntax-only passed for 69 current translation units\", \"Mac and Linux native build plus behavior matrix passed\", \"Windows MSVC native build passed\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated; no runtime behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:54:58Z",
          "mergedAt": "2026-07-14T23:56:56Z",
          "additions": 38,
          "deletions": 6,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 32,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/32",
          "title": "chore(release): accept Buildchain alpha.6 contract",
          "body": "## Summary\n- accept Buildchain `v2.12.7-alpha.6` at `63190f90f71fee292212d41d87149e511f5408f2`\n- preserve the unchanged major compatibility digest\n- enable the repaired paper release controller that publishes declared PDFs to GitHub Release\n\n## Verification\n- `make check`\n- `actionlint .github/workflows/*.yml`\n- `git diff --check`\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:55:58Z",
          "mergedAt": "2026-07-14T23:58:29Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 28,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/28",
          "title": "chore(release): accept Buildchain alpha.6 contract",
          "body": "## Summary\n- accept Buildchain `v2.12.7-alpha.6` at `63190f90f71fee292212d41d87149e511f5408f2`\n- preserve the unchanged major compatibility digest\n- enable the repaired paper release controller that publishes declared PDFs to GitHub Release\n\n## Verification\n- `make check`\n- `actionlint .github/workflows/*.yml`\n- `git diff --check`\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:56:06Z",
          "mergedAt": "2026-07-14T23:58:37Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 43,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/43",
          "title": "chore(release): accept Buildchain alpha.6 contract",
          "body": "## Summary\n- accept Buildchain `v2.12.7-alpha.6` at `63190f90f71fee292212d41d87149e511f5408f2`\n- preserve the unchanged major compatibility digest\n- enable the repaired paper release controller that publishes declared PDFs to GitHub Release\n\n## Verification\n- `make check`\n- `actionlint .github/workflows/*.yml`\n- `git diff --check`\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:56:14Z",
          "mergedAt": "2026-07-14T23:58:43Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 34,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/34",
          "title": "release: publish next KFD foundation alpha",
          "body": "Promote the Buildchain alpha.6 paper release path, restored microtype expansion, and declared GitHub Release PDF asset to the next alpha.\n\nReplaces #33 to preserve author/reviewer identity separation.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:02:30Z",
          "mergedAt": "2026-07-15T00:04:55Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 30,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/30",
          "title": "release: publish next Kungfu white paper alpha",
          "body": "Promote the Buildchain alpha.6 paper release path and declared GitHub Release PDF asset to the next alpha.\n\nReplaces #29 to preserve author/reviewer identity separation.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:02:43Z",
          "mergedAt": "2026-07-15T00:05:00Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 45,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/45",
          "title": "release: publish next Observer alpha",
          "body": "Promote the Buildchain alpha.6 paper release path, restored microtype expansion, and declared GitHub Release PDF asset to the next alpha.\n\nReplaces #44 to preserve author/reviewer identity separation.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:02:51Z",
          "mergedAt": "2026-07-15T00:05:05Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 35,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/35",
          "title": "fix(release): grant paper authority evidence access",
          "body": "## Summary\nGrant `actions: read` at the consumer caller boundary so the nested Buildchain publication authority can read exact release evidence without violating reusable-workflow permission monotonicity.\n\n## Verification\n- `make check`\n- `actionlint .github/workflows/*.yml`\n- `git diff --check`\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:07:13Z",
          "mergedAt": "2026-07-15T00:09:44Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 897,
          "url": "https://github.com/kungfu-systems/kungfu/pull/897",
          "title": "fix(core): prefer native Cargo shim on Windows",
          "body": "## Summary\n\nMake libwasm CMake discovery prefer the Windows-native Cargo shims exposed by the Shifu cache overlay. This prevents CMake from caching the POSIX shebang wrapper as `KF_LIBWASM_CARGO` on Windows.\n\n## Related issue\n\nNone. Found while qualifying the zero-burden desktop runtime through the full Buildchain matrix.\n\n## Changes\n\n- Prefer `cargo.cmd`, then `cargo.exe`, before the extensionless wrapper on Windows.\n- Drop stale cached Cargo paths in the shared-membrane slice before resolving the current overlay.\n- Preserve the existing POSIX lookup unchanged.\n\n## Verification\n\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check`\n- staged pre-commit gate\n- Windows Buildchain qualification will provide the platform-native regression proof.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This fixes platform-native executable discovery without changing the libwasm or cache architecture contracts\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not needed; executable discovery only)",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:06:59Z",
          "mergedAt": "2026-07-15T00:09:48Z",
          "additions": 15,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 31,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/31",
          "title": "fix(release): grant paper authority evidence access",
          "body": "## Summary\nGrant `actions: read` at the consumer caller boundary so the nested Buildchain publication authority can read exact release evidence without violating reusable-workflow permission monotonicity.\n\n## Verification\n- `make check`\n- `actionlint .github/workflows/*.yml`\n- `git diff --check`\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:07:16Z",
          "mergedAt": "2026-07-15T00:09:50Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 46,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/46",
          "title": "fix(release): grant paper authority evidence access",
          "body": "## Summary\nGrant `actions: read` at the consumer caller boundary so the nested Buildchain publication authority can read exact release evidence without violating reusable-workflow permission monotonicity.\n\n## Verification\n- `make check`\n- `actionlint .github/workflows/*.yml`\n- `git diff --check`\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:07:19Z",
          "mergedAt": "2026-07-15T00:09:56Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 36,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/36",
          "title": "release: publish next KFD foundation alpha",
          "body": "Promote consumer-level publication authority evidence access to complete the Buildchain alpha.6 paper release path.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:10:13Z",
          "mergedAt": "2026-07-15T00:12:35Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 32,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/32",
          "title": "release: publish next Kungfu white paper alpha",
          "body": "Promote consumer-level publication authority evidence access to complete the Buildchain alpha.6 paper release path.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:10:17Z",
          "mergedAt": "2026-07-15T00:12:40Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 47,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/47",
          "title": "release: publish next Observer alpha",
          "body": "Promote consumer-level publication authority evidence access to complete the Buildchain alpha.6 paper release path.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:10:20Z",
          "mergedAt": "2026-07-15T00:12:46Z",
          "additions": 1,
          "deletions": 0,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 143,
          "url": "https://github.com/kungfu-systems/build-images/pull/143",
          "title": "chore(buildchain): accept alpha.6 contract",
          "body": "## Summary\n- upgrade the exact alpha Buildchain package from 2.12.7-alpha.4 to 2.12.7-alpha.6\n- accept the current v2-alpha contract SHA and digest\n- regenerate KFD-2 upstream evidence and KFD123 summary\n- keep the stable channel pinned to Buildchain 2.12.6\n\n## Verification\n- pnpm install --frozen-lockfile\n- pnpm run check\n- Buildchain v2.12.7-alpha.6 Release Passport: trust pass, issues empty\n- current v2-alpha SHA equals accepted lock SHA 63190f90f71fee292212d41d87149e511f5408f2\n\nCloses #134\nCloses #135\nCloses #139\nCloses #141\nCloses #142",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:11:20Z",
          "mergedAt": "2026-07-15T00:14:43Z",
          "additions": 19,
          "deletions": 19,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 144,
          "url": "https://github.com/kungfu-systems/build-images/pull/144",
          "title": "release(alpha): accept Buildchain alpha.6 contract",
          "body": "## Summary\n- promote the Buildchain 2.12.7-alpha.6 consumer lock to alpha\n- publish refreshed KFD evidence and Release Passport\n- reuse existing image artifacts because no Dockerfile or image manifest changed\n\n## Verification\n- feature PR #143 checks passed\n- local pnpm run check passed\n- upstream Buildchain Release Passport verifies with trust pass and no issues",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:15:20Z",
          "mergedAt": "2026-07-15T00:18:05Z",
          "additions": 19,
          "deletions": 19,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 901,
          "url": "https://github.com/kungfu-systems/kungfu/pull/901",
          "title": "fix(gui): make structured console input discoverable",
          "body": "## Summary\n\nMake the structured Agent Console clearly distinguish read-only session output from the user instruction composer.\n\n## Related issue\n\nUser-reported discoverability friction in the structured Codex console.\n\n## Changes\n\n- label the session output boundary as read-only\n- add a prominent state-aware instruction composer and primary Send action\n- support Enter to send, Shift+Enter for a newline, and preserve drafts until delivery\n- hide raw PTY key controls when the session uses the structured transport\n\n## Verification\n\n- `./shifu --filter @kungfu-tech/kfx-view-terminal test`\n- `./shifu check`\n- source-local SDK KFX bundle build\n- headless browser visual inspection of the ready-state layout\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This bug fix improves existing console affordances without changing an architecture contract\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change presents existing provider session state and does not alter provider API or CLI behavior.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not required for this bounded UI fix)",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:32:24Z",
          "mergedAt": "2026-07-15T00:34:48Z",
          "additions": 417,
          "deletions": 51,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 146,
          "url": "https://github.com/kungfu-systems/build-images/pull/146",
          "title": "fix(images): reuse trusted empty release deltas",
          "body": "## Summary\n- accept verified v1.2.4-alpha.6 image evidence as the reviewed reuse baseline\n- distinguish a Git-proven empty delta from absent changed-path input\n- reuse all five images only when the accepted lock ancestry is valid\n- retain fail-closed full builds for unproven empty input and invalid baselines\n- document the trusted empty-delta rule and regenerate KFD evidence\n\n## Verification\n- pnpm run check\n- 36 comparator qualification tests passed\n- provenance fixture proves trusted empty delta reuses all five images\n- real planner at the accepted baseline reports selective mode, zero selected, five reused\n- explicit unproven empty input remains a full rebuild\n\nCloses #145",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:36:25Z",
          "mergedAt": "2026-07-15T00:39:05Z",
          "additions": 182,
          "deletions": 127,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 899,
          "url": "https://github.com/kungfu-systems/kungfu/pull/899",
          "title": "feat(profile): extract Mission Control domain",
          "body": "## Summary\n\nMove active Mission/Go actions, assessment, query, Atlas admission, and bundle semantics into the exact-root Mission Control Suite member. Keep Core Atlas as a source adapter and compatibility surface, and route `kungfu atlas` through public Profile reads/intents.\n\n## Verification\n\n- `./shifu build`\n- Profile SDK/composition/Mission Control tests: 54 passed\n- Mission Control/Atlas targeted storage tests\n- `./shifu test:kfx-profile-suite`\n- staged Ruff, Biome, docs, authority, and contract gates\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Mission Control active domain semantics are owned and exact-root bound by the Profile Suite; Core retains only public Profile compatibility and source adapter boundaries.\",\n  \"verification\": [\"Mission Control Profile and storage tests\", \"KFX Profile Suite qualification\", \"staged source boundary gates\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:18:21Z",
          "mergedAt": "2026-07-15T00:40:55Z",
          "additions": 2787,
          "deletions": 2545,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 147,
          "url": "https://github.com/kungfu-systems/build-images/pull/147",
          "title": "release(alpha): fix trusted empty-delta reuse",
          "body": "## Summary\n- promote the reviewed v1.2.4-alpha.6 image baseline\n- fix trusted empty release deltas to reuse the complete image family\n- retain fail-closed behavior for unproven empty or invalid baselines\n- publish the required full-build alpha after changing publisher logic\n\n## Verification\n- feature PR #146 checks passed\n- local full check passed\n- real planner proves 5 reused at the accepted baseline",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:39:57Z",
          "mergedAt": "2026-07-15T00:42:25Z",
          "additions": 182,
          "deletions": 127,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 902,
          "url": "https://github.com/kungfu-systems/kungfu/pull/902",
          "title": "feat(kfx): compose system views by product role",
          "body": "## Summary\n\n- add schema-governed KFX product roles and carry them through the host-neutral load plan\n- generate Activity Rail, View, Tools, and Developer menu entries from declarations\n- resolve Console startup, recovery Manager, and status targets by role instead of concrete KFX ids\n- keep boot-critical availability separate from source authority and capability grants\n\n## Verification\n\n- ./shifu test:kfx-profile-suite (KFX contract/plan 15 passed; initial navigation compatibility assertions corrected and rerun)\n- ./shifu --filter @kungfu-tech/tui exec tsx --test <navigation.test.ts> (10 passed)\n- ./shifu --filter @kungfu-tech/kfx build\n- ./shifu build:app\n- ./shifu check:source (281 Node tests and 13 runtime-upgrade tests passed)\n- staged pre-commit gate passed\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0083\"],\n  \"summary\": \"Declare KFX product roles and project System navigation and menus without concrete Shell ids.\",\n  \"verification\": [\n    \"KFX contract and plan fixtures\",\n    \"GUI navigation replacement and boot-critical fixtures\",\n    \"GUI production build\",\n    \"source acceptance gate\"\n  ]\n}\n-->\n\n## Governance\n\n- [x] DCO sign-off present\n- [x] ADR-0083 and versioning projection updated\n- [x] No trust or capability elevation from product roles\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:39:49Z",
          "mergedAt": "2026-07-15T00:45:15Z",
          "additions": 448,
          "deletions": 58,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 903,
          "url": "https://github.com/kungfu-systems/kungfu/pull/903",
          "title": "docs(adr): define core-native KFX runtime authority",
          "body": "## Summary\n\nRecord the Core-native multi-surface KFX runtime decision hierarchy. Define package and lifecycle authority, KFD and Buildchain admission, and surface-neutral contributions while distinguishing the existing partial baseline from the remaining implementation.\n\n## Changes\n\n- Add ADR-0088 as the umbrella architecture for one Core-native KFX authority across GUI, TUI, CLI, and Agent surfaces.\n- Add ADR-0089 for immutable packages and transactional lifecycle state.\n- Add ADR-0090 for KFD-aware trust grades and exact Buildchain artifact admission.\n- Add ADR-0091 for surface-neutral semantic contributions and thin Node/Python bindings.\n- Update the ADR index.\n\n## Verification\n\n- `./shifu docs:check`\n- `./shifu adr:audit -- --json`\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0088\", \"ADR-0089\", \"ADR-0090\", \"ADR-0091\"],\n  \"summary\": \"Accept the layered Core-native KFX runtime architecture, retain exact evidence for the existing partial baseline, and make no claim that the remaining implementation is complete.\",\n  \"verification\": [\"Documentation gate\", \"ADR authority audit\", \"staged source gates\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, secrets, or authentication material\n- [ ] generated artifacts or release binaries\n- [x] release evidence, provenance, or supply-chain policy\n- [ ] externally visible API or compatibility promise\n- [ ] none of the above\n\nADR-0090 defines the future admission design. This PR does not alter runtime trust decisions or release evidence.\n\n## Checklist\n\n- [x] DCO signoff is present.\n- [x] Documentation and ADR authority checks pass locally.\n- [x] The declaration intentionally claims `stage-ready` for an evidence-backed partial baseline, not completed implementation.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:44:20Z",
          "mergedAt": "2026-07-15T00:48:51Z",
          "additions": 653,
          "deletions": 0,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1241,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1241",
          "title": "feat(paper): seal publication candidates before release",
          "body": "## Summary\n\n- add a reusable three-stage sealed paper release workflow\n- bind source, tree, Buildchain runtime, controller receipt, PDF bytes, and npm package bytes before publication\n- keep the final write/OIDC job isolated from consumer build commands\n\n## Verification\n\n- `pnpm run check`\n- `actionlint .github/workflows/.publication-authority.yml .github/workflows/publication-artifact.yml .github/workflows/paper-release-sealed.yml`\n- candidate substitution rejection tests\n\nCloses #1240\nRelates to #1225, #1235, and #1239.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:53:00Z",
          "mergedAt": "2026-07-15T00:55:11Z",
          "additions": 1584,
          "deletions": 100,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 148,
          "url": "https://github.com/kungfu-systems/build-images/pull/148",
          "title": "chore(images): accept alpha.7 canary baseline",
          "body": "## Summary\n- accept the verified v1.2.4-alpha.7 full-build evidence\n- bind the reviewed image lock into KFD evidence\n- establish the post-planner-change baseline for the pure reuse canary\n\n## Verification\n- v1.2.4-alpha.7 Release Passport: trust pass, issues empty\n- pnpm run check\n- real planner reports selective mode, zero selected images, and five reused images",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:53:16Z",
          "mergedAt": "2026-07-15T00:55:51Z",
          "additions": 74,
          "deletions": 74,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1242,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1242",
          "title": "release: promote sealed paper publication to alpha",
          "body": "## Summary\n\nPromote the sealed paper publication candidate workflow from `dev/v2/v2.12` to the alpha channel.\n\n## Evidence\n\n- Buildchain PR #1241\n- `pnpm run check` passed\n- Verify and Build Surface Fixture passed\n\n## Expected publication\n\nPublish the next `2.12.7-alpha` version and advance `v2-alpha` / `v2.12-alpha` to the admitted runtime used by the three paper repositories.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:56:00Z",
          "mergedAt": "2026-07-15T00:58:13Z",
          "additions": 1584,
          "deletions": 100,
          "changedFiles": 23
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 150,
          "url": "https://github.com/kungfu-systems/build-images/pull/150",
          "title": "fix(images): ignore generated KFD publish deltas",
          "body": "## Summary\n- treat generated `.buildchain/kfd/` evidence as image-neutral after a reviewed image-lock acceptance\n- preserve fail-closed handling for other Buildchain metadata\n- cover shallow-history KFD-only and subsequent Dockerfile deltas\n\n## Verification\n- `python3 scripts/test-publish-provenance.py`\n- `pnpm run check`\n- real planner against the accepted `v1.2.4-alpha.7` lock: 5 reused, 0 built\n\nCloses #145",
          "author": "dongkeren",
          "createdAt": "2026-07-15T00:59:27Z",
          "mergedAt": "2026-07-15T01:03:22Z",
          "additions": 84,
          "deletions": 67,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 151,
          "url": "https://github.com/kungfu-systems/build-images/pull/151",
          "title": "release: promote selective KFD delta fix to alpha",
          "body": "Promote the KFD-neutral selective publish fix through the Buildchain v2 dual-channel release flow.\n\nExpected first release behavior: fail-closed full rebuild because publisher code changed. The following accepted-baseline canary must reuse all five image digests.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:03:54Z",
          "mergedAt": "2026-07-15T01:06:24Z",
          "additions": 147,
          "deletions": 130,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 895,
          "url": "https://github.com/kungfu-systems/kungfu/pull/895",
          "title": "feat(product): add versioned runtime upgrades",
          "body": "## Summary\n\nEstablish a shared, versioned product-upgrade protocol for Desktop and the standalone CLI while keeping runtime activation authority in Core. The delivery includes immutable runtime inventory, compatibility planning, safe activation and rollback, explicit user messaging, public upgrade documentation, Electron transport, CLI distribution boundaries, and fail-closed release qualification.\n\nNative platform claims intentionally remain promotion-ineligible until retained signed/notarized and native install campaigns exist.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add the Core runtime upgrade state machine, immutable image inventory, generation pinning, reconciliation, rollback, and reference-aware GC;\n- add the standalone CLI check/download/apply surfaces with strict target, digest, size, archive, concurrency, downgrade, and publication admission boundaries;\n- add the production Electron updater provider while requiring Core plans before download, install handoff, or runtime activation;\n- add one shared release identity, message registry, public guide/reference pages, and product deep links;\n- bind Buildchain publication to retained upgrade evidence and exact runtime/Desktop/CLI artifact identity;\n- add native qualification entry points for Developer ID/notarization, Authenticode, and AppImage evidence, while preserving explicit platform blockers;\n- preserve an explicit macOS certificate hash when multiple keychains contain the same Developer ID subject.\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu test:upgrade-qualification` (19 passed)\n- `./shifu test:desktop-update` (63 passed)\n- `./shifu check:types`\n- staged pre-commit gates, documentation contracts, and ADR audit\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0087\"],\n  \"summary\": \"Deliver the bounded versioned product-upgrade control plane, Desktop and CLI adapters, user contract, and fail-closed native release gate\",\n  \"verification\": [\"./shifu check:source\", \"./shifu test:upgrade-qualification\", \"./shifu test:desktop-update\", \"./shifu check:types\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe release boundary is fail-closed: publication requires exact artifact identity and retained qualification/signature references. Native platform claims remain disabled until their real campaigns are retained.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-14T23:45:53Z",
          "mergedAt": "2026-07-15T01:09:57Z",
          "additions": 9719,
          "deletions": 72,
          "changedFiles": 79
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 37,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/37",
          "title": "ci(release): adopt sealed paper publication",
          "body": "## Summary\n\n- consume Buildchain v2.12.7-alpha.7 through the accepted v2-alpha contract lock\n- replace the legacy paper release caller with the sealed publication preset\n- declare the exact PDF GitHub Release asset and trusted publisher workflow\n\n## Verification\n\n- repository check passed\n- actionlint passed\n- Buildchain contract lock: unchanged, compatible, no drift\n\nExpected release asset: `kfd-foundation-model.pdf`\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:09:52Z",
          "mergedAt": "2026-07-15T01:12:54Z",
          "additions": 7,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 48,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/48",
          "title": "ci(release): adopt sealed paper publication",
          "body": "## Summary\n\n- consume Buildchain v2.12.7-alpha.7 through the accepted v2-alpha contract lock\n- replace the legacy paper release caller with the sealed publication preset\n- declare the exact PDF GitHub Release asset and trusted publisher workflow\n\n## Verification\n\n- repository check passed\n- actionlint passed\n- Buildchain contract lock: unchanged, compatible, no drift\n\nExpected release asset: `observer-declared-timelines.pdf`\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:09:50Z",
          "mergedAt": "2026-07-15T01:12:54Z",
          "additions": 7,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 33,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/33",
          "title": "ci(release): adopt sealed paper publication",
          "body": "## Summary\n\n- consume Buildchain v2.12.7-alpha.7 through the accepted v2-alpha contract lock\n- replace the legacy paper release caller with the sealed publication preset\n- declare the exact PDF GitHub Release asset and trusted publisher workflow\n\n## Verification\n\n- repository check passed\n- actionlint passed\n- Buildchain contract lock: unchanged, compatible, no drift\n\nExpected release asset: `kungfu-real-world-agent-work.pdf`\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:10:40Z",
          "mergedAt": "2026-07-15T01:13:48Z",
          "additions": 7,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 38,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/38",
          "title": "release: publish sealed paper alpha",
          "body": "## Summary\n\nPromote the Buildchain v2.12.7-alpha.7 sealed paper release integration to the alpha channel.\n\n## Expected publication\n\n- publish the next npm alpha\n- create the matching GitHub prerelease\n- attach the declared PDF under its human-readable filename\n- retain the sealed publication capability and release passport evidence\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:14:44Z",
          "mergedAt": "2026-07-15T01:17:41Z",
          "additions": 7,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 34,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/34",
          "title": "release: publish sealed paper alpha",
          "body": "## Summary\n\nPromote the Buildchain v2.12.7-alpha.7 sealed paper release integration to the alpha channel.\n\n## Expected publication\n\n- publish the next npm alpha\n- create the matching GitHub prerelease\n- attach the declared PDF under its human-readable filename\n- retain the sealed publication capability and release passport evidence\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:14:47Z",
          "mergedAt": "2026-07-15T01:17:41Z",
          "additions": 7,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 49,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/49",
          "title": "release: publish sealed paper alpha",
          "body": "## Summary\n\nPromote the Buildchain v2.12.7-alpha.7 sealed paper release integration to the alpha channel.\n\n## Expected publication\n\n- publish the next npm alpha\n- create the matching GitHub prerelease\n- attach the declared PDF under its human-readable filename\n- retain the sealed publication capability and release passport evidence\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:14:47Z",
          "mergedAt": "2026-07-15T01:18:19Z",
          "additions": 7,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 904,
          "url": "https://github.com/kungfu-systems/kungfu/pull/904",
          "title": "feat(core): read the generic decode primitive identically on every membrane",
          "body": "## Summary\n\nADR-0078 exposed one generic frame-decode primitive on three membranes — pybind, the\nembedding C ABI, and the Rust wrapper — so that any language could read a `.kungfu`\nframe without re-implementing FlatBuffers reflection. The three did not agree. The\nde-dup gave the pybind primitive the integer enum form the reflection decoders use,\nwhile the C ABI and its Rust mirror still emitted enum identifiers, so the same frame\nread differently depending on which membrane you came through. This closes that gap,\nthe last open item on ADR-0078.\n\n## Related issue\n\nADR-0078 Follow-up (\"Remaining follow-up: cross-membrane enum representation\nsymmetry\"). Continues #772 (exposure) and #802 (de-dup).\n\n## Changes\n\n- **Integer enums on the C ABI.** `decode_frame_json` decodes enums to their integer\n  form, matching the pybind primitive and the three reflection decoders.\n- **The `object_name` table selector on the C ABI.** This half was not named in the\n  ADR's follow-up, but it belongs to the same symmetry. The primitive's own\n  motivating consumer decodes a bundle whose event tables are **not** the `.bfbs`\n  root (`rewind` passes the action-type table name), so without a selector the ring\n  closure ADR-0078 promises for \"Rust and cross-process consumers, not only Python\n  and in-tree C++\" did not hold for the case that motivated it. `NULL`/empty keeps\n  the root_type behaviour existing single-root callers rely on.\n- **Rust mirror.** `Context::decode_frame_json` takes `object_name: Option<&str>`\n  and forwards it; it wraps the C ABI rather than reimplementing decode, so the\n  contract keeps one implementation. The `kf_embedding_api_v3` table layout is\n  unchanged (`ApiV3 == 104` still holds).\n- **A contract test where there was none.** This membrane path previously had no\n  runtime coverage: the slice host only checks v3 negotiation and non-null pointers,\n  and the Rust tests never touch a live core. `kungfu_embedding_generic_codec_tests`\n  decodes through the C ABI and compares against `schema_handle::decode_json` — both\n  the integer form it must produce and the identifier form it must not — plus the\n  non-root selector, fail-closed on an unknown table, and the argument guard. It\n  asserts the two enum forms actually differ before comparing, so it cannot pass\n  against a fixture that does not discriminate. Wired into the existing\n  embedding-membrane qualification gate rather than a new gate.\n\nABI v3 has not reached a release channel (`v4.0.0-alpha.0` predates it) and there are\nno consumers outside this repository, so the signature is widened in place rather than\nversioned around.\n\n## Verification\n\n- macOS arm64 full core build; `kungfu_embedding_generic_codec_tests` green — and\n  red when the integer-enum argument is reverted, so the test is proven to\n  discriminate rather than pass vacuously.\n- 11/11 native ctest (the 10 existing plus the new one).\n- `cargo test`/`clippy`/`fmt` for `kungfu-embedding`, plus a workspace check.\n- `adr-audit` (`result=pass`, structural=0) and the deterministic docs gate.\n- Linux and Windows evidence comes from the qualification gate rather than a local\n  run, so ADR-0078 moves to `staged`, not `implemented`.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0078\"],\n  \"summary\": \"Make the generic decode primitive read identically on all three membranes: integer enums plus the object_name table selector on the C ABI and its Rust mirror, closing the last ADR-0078 follow-up\",\n  \"verification\": [\"macOS arm64 full core build\", \"kungfu_embedding_generic_codec_tests (green on the change, red when the integer-enum argument is reverted)\", \"11/11 native ctest\", \"cargo test/clippy/fmt plus workspace check\", \"adr-audit and docs gate\"]\n}\n-->\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:03:11Z",
          "mergedAt": "2026-07-15T01:21:08Z",
          "additions": 346,
          "deletions": 21,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 153,
          "url": "https://github.com/kungfu-systems/build-images/pull/153",
          "title": "chore(images): accept v1.2.4-alpha.8 digests",
          "body": "Accept the reviewed alpha.8 publish evidence as the selective-publish baseline.\n\n- Release Passport: trust pass, no issues\n- alpha.8 evidence: 5 built (expected fail-closed planner change)\n- lock acceptance and generated KFD evidence are committed atomically\n- post-acceptance real planner: 5 reused, 0 built\n\nFollow-up: promote a pure canary and prove the published release evidence also records 5 reused.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:20:42Z",
          "mergedAt": "2026-07-15T01:23:31Z",
          "additions": 74,
          "deletions": 74,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1245,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1245",
          "title": "fix(paper): bind required check into authority",
          "body": "## Summary\n\n- carry the exact declared protected-branch check context into sealed publication authority\n- bind provider transaction evidence to that exact context and GitHub App id\n- reject a mismatched check even when another check passed\n\n## Evidence\n\n- all three paper alpha runs reached read-only candidate completion and failed closed at the same branch-policy audit\n- `pnpm run check`: 617 tests passed\n- Actionlint and generated site contract checks passed\n\nCloses #1244\nRelates to #1240.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:24:27Z",
          "mergedAt": "2026-07-15T01:26:21Z",
          "additions": 43,
          "deletions": 13,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 154,
          "url": "https://github.com/kungfu-systems/build-images/pull/154",
          "title": "release: publish selective reuse canary",
          "body": "Promote the reviewed alpha.8 image-lock baseline as a pure selective-publish canary.\n\nPre-promotion planner evidence:\n- mode: selective\n- selected images: 0\n- reused images: 5\n\nAcceptance criterion: the resulting alpha release passport must pass and durable publish evidence must record all five image artifacts as reused with unchanged digests.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:23:53Z",
          "mergedAt": "2026-07-15T01:28:47Z",
          "additions": 74,
          "deletions": 74,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1246,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1246",
          "title": "release: promote exact paper branch audit to alpha",
          "body": "## Summary\n\nPromote the exact required-status-check authority fix to the alpha channel.\n\n## Evidence\n\n- Buildchain PR #1245\n- all 617 unit tests passed\n- three paper dogfood runs proved the previous hard-coded check failed closed before publication\n\n## Expected publication\n\nPublish the next `2.12.7-alpha` runtime so the three paper releases can rerun against the corrected authority.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:26:46Z",
          "mergedAt": "2026-07-15T01:29:12Z",
          "additions": 43,
          "deletions": 13,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 39,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/39",
          "title": "chore(buildchain): accept alpha.8 contract",
          "body": "## Summary\\n\\nAccept Buildchain v2.12.7-alpha.8 after the exact required-status-check authority fix.\\n\\n## Verification\\n\\n- repository check passed\\n- contract lock resolves exact SHA e6c3b27db0552bb0ca075ced4fe1dea621ef06cf\\n- contract status unchanged, compatible, no drift\\n\\nThis unlocks a fresh sealed alpha publication after the prior release correctly failed closed.\\n\\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:36:45Z",
          "mergedAt": "2026-07-15T01:39:26Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 35,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/35",
          "title": "chore(buildchain): accept alpha.8 contract",
          "body": "## Summary\\n\\nAccept Buildchain v2.12.7-alpha.8 after the exact required-status-check authority fix.\\n\\n## Verification\\n\\n- repository check passed\\n- contract lock resolves exact SHA e6c3b27db0552bb0ca075ced4fe1dea621ef06cf\\n- contract status unchanged, compatible, no drift\\n\\nThis unlocks a fresh sealed alpha publication after the prior release correctly failed closed.\\n\\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:36:45Z",
          "mergedAt": "2026-07-15T01:39:32Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 50,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/50",
          "title": "chore(buildchain): accept alpha.8 contract",
          "body": "## Summary\\n\\nAccept Buildchain v2.12.7-alpha.8 after the exact required-status-check authority fix.\\n\\n## Verification\\n\\n- repository check passed\\n- contract lock resolves exact SHA e6c3b27db0552bb0ca075ced4fe1dea621ef06cf\\n- contract status unchanged, compatible, no drift\\n\\nThis unlocks a fresh sealed alpha publication after the prior release correctly failed closed.\\n\\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:36:45Z",
          "mergedAt": "2026-07-15T01:39:38Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 40,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/40",
          "title": "release: publish sealed paper alpha",
          "body": "## Summary\n- promote the unified Buildchain v2.12.7-alpha.8 paper release contract\n- publish the next npm alpha through trusted publishing\n- attach the canonical PDF to the matching GitHub Release\n\n## Verification\n- repository checks pass on dev\n- Buildchain authority verifies the exact protected-branch status context\n- publication uses the sealed candidate digest across read-only build, authority, and isolated publisher stages",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:39:58Z",
          "mergedAt": "2026-07-15T01:42:07Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 36,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/36",
          "title": "release: publish sealed paper alpha",
          "body": "## Summary\n- promote the unified Buildchain v2.12.7-alpha.8 paper release contract\n- publish the next npm alpha through trusted publishing\n- attach the canonical PDF to the matching GitHub Release\n\n## Verification\n- repository checks pass on dev\n- Buildchain authority verifies the exact protected-branch status context\n- publication uses the sealed candidate digest across read-only build, authority, and isolated publisher stages",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:39:58Z",
          "mergedAt": "2026-07-15T01:42:12Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 51,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/51",
          "title": "release: publish sealed paper alpha",
          "body": "## Summary\n- promote the unified Buildchain v2.12.7-alpha.8 paper release contract\n- publish the next npm alpha through trusted publishing\n- attach the canonical PDF to the matching GitHub Release\n\n## Verification\n- repository checks pass on dev\n- Buildchain authority verifies the exact protected-branch status context\n- publication uses the sealed candidate digest across read-only build, authority, and isolated publisher stages",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:39:59Z",
          "mergedAt": "2026-07-15T01:42:18Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1248,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1248",
          "title": "fix(paper): resolve sealed candidate paths exactly",
          "body": "## Summary\n- resolve admitted publication files by their exact candidate-relative paths\n- preserve sealed candidate digest and byte verification\n- handle the valid case where an npm paper package repeats the release PDF under its package tree\n- regenerate the public Node API and contract projections\n\n## Failure evidence\nThe first end-to-end paper release runs reached the isolated publisher and failed closed because suffix matching found both the release PDF and its npm-package copy:\n- KFD: https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/actions/runs/29382281956\n- White Paper: https://github.com/kungfu-systems/paper-kungfu-product-white-paper/actions/runs/29382285669\n- Observer: https://github.com/kungfu-systems/paper-observer-declared-timelines/actions/runs/29382289835\n\n## Verification\n- pnpm run check\n- 618 unit tests passed\n- workflow and generated site-contract checks passed\n- four bundled actions built successfully",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:49:45Z",
          "mergedAt": "2026-07-15T01:51:53Z",
          "additions": 55,
          "deletions": 19,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 906,
          "url": "https://github.com/kungfu-systems/kungfu/pull/906",
          "title": "feat(core): freeze native KFX contract seam",
          "body": "## Summary\n\nFreeze the first versioned native KFX contract and the Core-owned service/binding seam without switching discovery or mutation authority away from the existing loaders.\n\n## Related issue\n\nAtlas goal `2026-07-15-kungfu-native-kfx-contract-and-binding-seam`.\n\n## Changes\n\n- add native KFX contract v1 to the welded KFX contract, including version negotiation, canonical roots, ownership, compatibility policy, and stable error codes\n- add the C++ `native_kfx_service` interface plus strict request, inspection, plan, and receipt validation\n- expose contract and validation through the existing storage JSON edge with transport-only Node and Python helpers\n- add positive and negative fixtures for authority claims, duplicate ownership, generation drift, unknown fields, traversal, missing closure, capability broadening, receipt-as-trust, and GUI-only mutation\n- document the migration-stage authority map while retaining the existing TypeScript loader, Python installer, and Profile lifecycle\n\n## Verification\n\n- `./shifu check`\n- `./shifu test:kfx-profile-suite` (Node, GUI, and Python contract fixtures)\n- `kungfu_native_kfx_contract_tests` through CTest on Linux/GCC 14\n- `./shifu --filter @kungfu-tech/api test:query` (18 passing)\n- native Node `kfx_runtime` contract/validate smoke\n- `pytest framework/core/tests/python/test_native_kfx_contract.py` against the built Python binding\n- `pytest framework/core/tests/python/test_kfx_contract.py` (16 passing)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0088\", \"ADR-0089\", \"ADR-0090\", \"ADR-0091\"],\n  \"summary\": \"Freeze the versioned native KFX contract, Core service interface, and thin Node/Python binding seam without authority cutover\",\n  \"verification\": [\"Shifu changed-scope check\", \"native KFX CTest fixtures\", \"KFX Profile Suite contract gate\", \"Node and Python native binding smokes\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:43:05Z",
          "mergedAt": "2026-07-15T01:52:37Z",
          "additions": 1015,
          "deletions": 7,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1249,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1249",
          "title": "release: promote exact paper candidate paths to alpha",
          "body": "## Summary\n\nPromote the exact-path sealed paper publisher fix to the alpha channel.\n\n## Evidence\n\n- Buildchain PR #1248\n- pnpm run check passed\n- all 618 unit tests passed\n- three paper dogfood runs proved suffix matching failed closed before any publication\n\n## Expected publication\n\nPublish v2.12.7-alpha.9 so the three paper repositories can rerun against exact manifest-relative candidate paths.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:52:11Z",
          "mergedAt": "2026-07-15T01:54:23Z",
          "additions": 55,
          "deletions": 19,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 157,
          "url": "https://github.com/kungfu-systems/build-images/pull/157",
          "title": "chore(buildchain): accept alpha.8 contract",
          "body": "## Summary\n- upgrade `@kungfu-tech/buildchain` to `2.12.7-alpha.8`\n- accept `v2-alpha` at `e6c3b27db0552bb0ca075ced4fe1dea621ef06cf`\n- regenerate KFD2 claims against contract digest `sha256:95e8044b7a42060dd0476f6a4957e810431d57e7982abbc4000c1693396498c7`\n\n## Verification\n- `pnpm run check`\n- `pnpm run check:kfd`\n- compatibility digest unchanged: `sha256:af162b86ab4506e9b5f1d3c59b41f3fd57fbad79ff4d749a7f12ff16460517f8`\n\nFixes #155\nSupersedes #152",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:57:02Z",
          "mergedAt": "2026-07-15T02:00:27Z",
          "additions": 21,
          "deletions": 21,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 41,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/41",
          "title": "chore(buildchain): accept alpha.9 contract",
          "body": "## Summary\n- accept Buildchain v2.12.7-alpha.9 at its exact released SHA\n- retain major-compatible floating-ref policy\n- prepare the paper alpha line to rerun the sealed npm and GitHub Release publication\n\n## Verification\n- generated by the exact released Buildchain runtime\n- repository make check passed\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:05:00Z",
          "mergedAt": "2026-07-15T02:07:14Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 37,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/37",
          "title": "chore(buildchain): accept alpha.9 contract",
          "body": "## Summary\n- accept Buildchain v2.12.7-alpha.9 at its exact released SHA\n- retain major-compatible floating-ref policy\n- prepare the paper alpha line to rerun the sealed npm and GitHub Release publication\n\n## Verification\n- generated by the exact released Buildchain runtime\n- repository make check passed\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:05:05Z",
          "mergedAt": "2026-07-15T02:07:21Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 52,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/52",
          "title": "chore(buildchain): accept alpha.9 contract",
          "body": "## Summary\n- accept Buildchain v2.12.7-alpha.9 at its exact released SHA\n- retain major-compatible floating-ref policy\n- prepare the paper alpha line to rerun the sealed npm and GitHub Release publication\n\n## Verification\n- generated by the exact released Buildchain runtime\n- repository make check passed\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:05:03Z",
          "mergedAt": "2026-07-15T02:07:30Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 42,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/42",
          "title": "release: publish sealed paper alpha with Buildchain alpha.9",
          "body": "## Summary\n- promote the exact Buildchain v2.12.7-alpha.9 contract lock\n- rerun the three-stage sealed paper publication\n- publish the declared npm alpha and attach the canonical PDF to the matching GitHub Release\n\n## Verification\n- dev branch checks passed\n- Buildchain candidate construction and authority remain credential-free\n- isolated publisher resolves release assets by exact manifest-relative path\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:07:44Z",
          "mergedAt": "2026-07-15T02:10:01Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 38,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/38",
          "title": "release: publish sealed paper alpha with Buildchain alpha.9",
          "body": "## Summary\n- promote the exact Buildchain v2.12.7-alpha.9 contract lock\n- rerun the three-stage sealed paper publication\n- publish the declared npm alpha and attach the canonical PDF to the matching GitHub Release\n\n## Verification\n- dev branch checks passed\n- Buildchain candidate construction and authority remain credential-free\n- isolated publisher resolves release assets by exact manifest-relative path\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:07:44Z",
          "mergedAt": "2026-07-15T02:10:07Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 53,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/53",
          "title": "release: publish sealed paper alpha with Buildchain alpha.9",
          "body": "## Summary\n- promote the exact Buildchain v2.12.7-alpha.9 contract lock\n- rerun the three-stage sealed paper publication\n- publish the declared npm alpha and attach the canonical PDF to the matching GitHub Release\n\n## Verification\n- dev branch checks passed\n- Buildchain candidate construction and authority remain credential-free\n- isolated publisher resolves release assets by exact manifest-relative path\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:07:44Z",
          "mergedAt": "2026-07-15T02:10:12Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 159,
          "url": "https://github.com/kungfu-systems/build-images/pull/159",
          "title": "chore(buildchain): accept alpha.9 contract",
          "body": "## Summary\n- upgrade `@kungfu-tech/buildchain` to `2.12.7-alpha.9`\n- accept `v2-alpha` at `14d7952cbf6508b6446971fd6903fba954aad4d6`\n- regenerate KFD2 claims against contract digest `sha256:a773ef118ff98b52ff14a78b0bcc7efbda77d5e5e7a552a31fe6791a4c7d4d76`\n\n## Verification\n- `pnpm run check`\n- `pnpm run check:kfd`\n- compatibility digest unchanged: `sha256:af162b86ab4506e9b5f1d3c59b41f3fd57fbad79ff4d749a7f12ff16460517f8`\n\nFixes #158",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:07:36Z",
          "mergedAt": "2026-07-15T02:11:43Z",
          "additions": 19,
          "deletions": 19,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1251,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1251",
          "title": "fix(paper): isolate admitted publication evidence",
          "body": "## Summary\n- treat .buildchain/admitted as sealed ephemeral publisher evidence during version-state verification\n- keep source/version-state mutation checks strict for every other path\n- rebuild the checked-in promote action\n- add a regression fixture for admitted artifact and controller evidence\n\n## Failure evidence\nThe publisher now passes exact candidate byte verification and publish-gate locking, then fails closed because downloaded sealed evidence appears as untracked source state:\n- KFD: https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/actions/runs/29383428582\n- White Paper: https://github.com/kungfu-systems/paper-kungfu-product-white-paper/actions/runs/29383432238\n- Observer: https://github.com/kungfu-systems/paper-observer-declared-timelines/actions/runs/29383436721\n\n## Verification\n- pnpm run check\n- all 618 unit tests passed\n- bundled actions rebuilt\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:14:41Z",
          "mergedAt": "2026-07-15T02:17:05Z",
          "additions": 12,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 907,
          "url": "https://github.com/kungfu-systems/kungfu/pull/907",
          "title": "fix(product): separate CLI launcher from runtime tree",
          "body": "## Summary\n\nSeparate the versioned CLI runtime tree from the user-facing launcher and refresh the deterministic KFD evidence that the qualification gate found stale.\n\n## Related issue\n\nNone. Found while qualifying the zero-burden desktop runtime through the full Buildchain matrix.\n\n## Changes\n\n- Stage CLI runtime files under `runtime/` while keeping `kungfu` / `kungfu.cmd` as the archive launcher.\n- Add an exact cross-platform archive layout and launcher-path regression test.\n- Refresh the canonical agent-first policy and generated KFD-1/KFD-3 evidence through the repository generators.\n\n## Verification\n\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check`\n- `node developer/sdk/src/sdk.js contract policy --check --json`\n- `node scripts/buildchain-kfd-evidence.mjs --check`\n- `pnpm --filter @kungfu-tech/sdk run build`\n- staged pre-commit gates for both commits\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This fixes archive path collisions and refreshes deterministic evidence without changing the accepted product runtime or KFD architecture contracts\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not needed; archive layout is asserted by tests)",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:16:22Z",
          "mergedAt": "2026-07-15T02:18:47Z",
          "additions": 80,
          "deletions": 48,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1252,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1252",
          "title": "release: promote admitted evidence isolation to alpha",
          "body": "## Summary\n\nPromote the sealed publisher evidence-isolation fix to the alpha channel.\n\n## Evidence\n\n- Buildchain PR #1251\n- pnpm run check passed\n- all 618 unit tests passed\n- three paper runs passed byte verification and publish-gate locking before exposing the version-state false positive\n\n## Expected publication\n\nPublish v2.12.7-alpha.10 so paper publishers can consume admitted evidence without treating it as source mutation.\n\nAgent: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:17:24Z",
          "mergedAt": "2026-07-15T02:19:58Z",
          "additions": 12,
          "deletions": 1,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 156,
          "url": "https://github.com/kungfu-systems/build-images/pull/156",
          "title": "fix(comparator): bound Compose lifecycle cleanup",
          "body": "## Summary\n- bound every PostgreSQL adapter Compose command and retain timeout evidence\n- stabilize final-server health, SIGKILL recovery ordering, and runner shutdown\n- bind zero project-resource cleanup evidence into each qualification step\n- add a gated real 3x21 plus injected-failure lifecycle workflow\n\n## Verification\n- `pnpm run check`\n- 44 comparator qualification tests\n- real lifecycle gate: `run-comparator-lifecycle` label\n\nFixes #149",
          "author": "dongkeren",
          "createdAt": "2026-07-15T01:53:07Z",
          "mergedAt": "2026-07-15T02:27:00Z",
          "additions": 492,
          "deletions": 35,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 43,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/43",
          "title": "chore(buildchain): accept alpha.10 contract",
          "body": "## Summary\n- accept the published Buildchain v2.12.7-alpha.10 contract\n- retain the floating v2-alpha declaration with an exact KFD-1 lock\n\n## Verification\n- make check",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:28:52Z",
          "mergedAt": "2026-07-15T02:31:06Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 39,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/39",
          "title": "chore(buildchain): accept alpha.10 contract",
          "body": "## Summary\n- accept the published Buildchain v2.12.7-alpha.10 contract\n- retain the floating v2-alpha declaration with an exact KFD-1 lock\n\n## Verification\n- make check",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:28:55Z",
          "mergedAt": "2026-07-15T02:31:11Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 54,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/54",
          "title": "chore(buildchain): accept alpha.10 contract",
          "body": "## Summary\n- accept the published Buildchain v2.12.7-alpha.10 contract\n- retain the floating v2-alpha declaration with an exact KFD-1 lock\n\n## Verification\n- make check",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:28:57Z",
          "mergedAt": "2026-07-15T02:31:16Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 44,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/44",
          "title": "release: promote Buildchain alpha.10 publication support",
          "body": "## Summary\n- promote the fixed Buildchain LaTeX image and sealed paper publication flow to alpha\n- publish the next package alpha and matching PDF GitHub Release asset after merge\n\n## Verification\n- protected dev checks passed\n- Buildchain publication candidate passed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:31:27Z",
          "mergedAt": "2026-07-15T02:33:37Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 40,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/40",
          "title": "release: promote Buildchain alpha.10 publication support",
          "body": "## Summary\n- promote the fixed Buildchain LaTeX image and sealed paper publication flow to alpha\n- publish the next package alpha and matching PDF GitHub Release asset after merge\n\n## Verification\n- protected dev checks passed\n- Buildchain publication candidate passed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:31:30Z",
          "mergedAt": "2026-07-15T02:33:43Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 55,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/55",
          "title": "release: promote Buildchain alpha.10 publication support",
          "body": "## Summary\n- promote the fixed Buildchain LaTeX image and sealed paper publication flow to alpha\n- publish the next package alpha and matching PDF GitHub Release asset after merge\n\n## Verification\n- protected dev checks passed\n- Buildchain publication candidate passed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:31:32Z",
          "mergedAt": "2026-07-15T02:33:48Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 161,
          "url": "https://github.com/kungfu-systems/build-images/pull/161",
          "title": "chore(buildchain): accept v2.12.7-alpha.10 contract",
          "body": "## Summary\n- upgrade the managed Buildchain alpha runtime to `2.12.7-alpha.10`\n- accept the reviewed compatible `v2-alpha` contract at `6630a522`\n- regenerate KFD2 claims and the KFD123 summary\n\n## Verification\n- `pnpm run check`\n- 45 Comparator tests pass\n- KFD1/2/3 pass with zero alpha contract drift\n- Release Passport smoke passes\n\nFixes #160",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:32:26Z",
          "mergedAt": "2026-07-15T02:35:52Z",
          "additions": 19,
          "deletions": 19,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 162,
          "url": "https://github.com/kungfu-systems/build-images/pull/162",
          "title": "release(alpha): publish Comparator lifecycle and Buildchain alpha.10",
          "body": "## Summary\n- publish the bounded Comparator Compose lifecycle and cleanup evidence fixes\n- publish selective image reuse and registry-cache closeout changes already verified on dev\n- release with Buildchain `v2.12.7-alpha.10` and the current contract lock\n\n## Verification\n- Comparator real lifecycle: 63/63 steps, 63/63 zero-resource cleanup snapshots, injected-failure cleanup passed\n- post-merge Verify on Comparator fix: https://github.com/kungfu-systems/build-images/actions/runs/29384114345\n- post-merge Verify on Buildchain alpha.10 lock: https://github.com/kungfu-systems/build-images/actions/runs/29384476507\n- current open issue count: 0\n\nThe `dev/v1/v1.2` branch must be preserved after merge.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:38:34Z",
          "mergedAt": "2026-07-15T02:41:38Z",
          "additions": 513,
          "deletions": 56,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1255,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1255",
          "title": "fix(paper): retry unpublished release transactions",
          "body": "## Summary\n- let sealed paper publication explicitly supersede a stale durable transaction only when no material was published\n- preserve version/tag/target/channel identity and fail closed for completed or material-bearing transactions\n- retain the existing version-state finalization replacement path\n- regenerate the action dist and public Buildchain contract\n\nCloses #1254\n\n## Verification\n- `pnpm run check`\n- 618 tests passed before adding the preserved regression case\n- targeted stale transaction tests: 2 passed\n- sealed paper workflow test passed\n\n## Dogfood evidence\n- KFD failed run: https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/actions/runs/29384385077\n- white paper failed run: https://github.com/kungfu-systems/paper-kungfu-product-white-paper/actions/runs/29384388635\n- Observer failed run: https://github.com/kungfu-systems/paper-observer-declared-timelines/actions/runs/29384392610",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:46:44Z",
          "mergedAt": "2026-07-15T02:49:26Z",
          "additions": 151,
          "deletions": 22,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 910,
          "url": "https://github.com/kungfu-systems/kungfu/pull/910",
          "title": "feat(shifu): add documentation protocol contract",
          "body": "## Summary\n\nFreeze the project-independent Shifu Documentation Protocol v1 without moving Kungfu-specific documentation semantics into Shifu.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add versioned project submission and non-qualifying receipt schemas\n- add exact provider, root, visibility, lifecycle, route, and policy validation\n- add deterministic contract/content/submission roots and stable diagnostics\n- expose `shifu docs contract|schema|validate|show` across native, POSIX, and Windows entrypoints\n- map existing Kungfu docs, metadata, ADR, Gate, and Buildchain inputs as compatibility providers\n- add SHIFU-ADR-0006, negative fixtures, and source/check integration\n\n## Verification\n\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source`\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu docs:check`\n- staged pre-commit gate including Rust clippy/tests, Documentation Protocol, Gate, and ADR checks\n- `./shifu check` passed all relevant checks but an unrelated existing KFX Profile Suite Node test retained an idle libuv handle and was interrupted after three minutes\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-0006\"],\n  \"summary\": \"Freeze Documentation Protocol v1, compatibility providers, deterministic roots, diagnostics, receipts, and read-only CLI discovery\",\n  \"verification\": [\"check:source\", \"docs:check\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe new Shifu CLI is read-only and diagnostic-only. It executes no provider probes and receives no credential or network authority.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:36:48Z",
          "mergedAt": "2026-07-15T02:51:25Z",
          "additions": 1915,
          "deletions": 12,
          "changedFiles": 29
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1256,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1256",
          "title": "release: promote paper transaction retry to alpha",
          "body": "## Summary\n- promote the controlled unpublished-transaction retry fix to the Buildchain alpha channel\n- unblock end-to-end paper npm and GitHub Release publication\n\n## Verification\n- PR #1255 checks passed\n- full Buildchain check passed with 618 tests\n- preserved and new stale transaction regressions passed\n\nCloses #1254 after the released alpha is proven by all three paper repositories.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:49:40Z",
          "mergedAt": "2026-07-15T02:52:05Z",
          "additions": 151,
          "deletions": 22,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 912,
          "url": "https://github.com/kungfu-systems/kungfu/pull/912",
          "title": "fix(core): honor projected Python environment",
          "body": "## Summary\n\nMake live-peer qualification launch its native campaign from the Python environment projected by Shifu and Buildchain.\n\n## Related issue\n\nNone. Found while qualifying the zero-burden desktop runtime through the full Buildchain matrix.\n\n## Changes\n\n- Resolve the native campaign Python from `UV_PROJECT_ENVIRONMENT` when projected.\n- Preserve the repository-local Core virtual environment as the development fallback.\n- Cover POSIX and Windows interpreter layouts with a focused regression test.\n\n## Verification\n\n- `./shifu exec node --test framework/core/tests/qualification/live-peer-continuity/run.test.mjs`\n- `./shifu check`\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source`\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This fixes qualification environment resolution without changing the accepted runtime architecture or claim envelope\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not needed; environment behavior is asserted by tests)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:51:07Z",
          "mergedAt": "2026-07-15T02:56:04Z",
          "additions": 22,
          "deletions": 7,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 911,
          "url": "https://github.com/kungfu-systems/kungfu/pull/911",
          "title": "feat(core): add executable layer architecture contract",
          "body": "## Summary\n\nAdd one executable authority for the C++ Core layer model so source ownership, dependency direction, current target evidence, and developer navigation stay synchronized.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- define seven ordered Core layers and seven uniquely owned components in `framework/core/architecture/layers.json`\n- validate every tracked first-party C/C++ file, actual internal includes, declared component dependencies, current CMake target evidence, and navigation entrypoints\n- generate-check the human-readable `LAYERS.md` map from the same authority\n- add the architecture contract and eight controlled negative fixtures to the build-free source acceptance gate\n- link the architecture entry from the existing documentation map\n\n## Verification\n\n- `./shifu check:source`\n- `node framework/core/architecture/check-layers.mjs`\n- `node framework/core/architecture/check-layers.mjs --self-test`\n- `node --test scripts/source-acceptance.test.mjs`\n\n`./shifu check` reaches the existing SDK contract audit and reports an unrelated canonical-policy projection mismatch; this PR does not change `framework/contract`, `developer/sdk`, package manifests, or `pnpm-lock.yaml`.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0049\"],\n  \"summary\": \"Add the executable Core layer, ownership, dependency, and navigation contract required to keep the domain-neutral Core structurally enforceable.\",\n  \"verification\": [\"./shifu check:source\", \"core architecture positive and negative fixtures\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T02:44:47Z",
          "mergedAt": "2026-07-15T03:01:11Z",
          "additions": 803,
          "deletions": 2,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 41,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/41",
          "title": "chore(buildchain): accept alpha.11 contract",
          "body": "## Summary\n- accept published Buildchain v2.12.7-alpha.11\n- enable controlled retry of the existing unpublished paper transaction\n\n## Verification\n- make check\n- exact Buildchain GitHub/npm/tag release fact verified",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:02:02Z",
          "mergedAt": "2026-07-15T03:04:18Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 45,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/45",
          "title": "chore(buildchain): accept alpha.11 contract",
          "body": "## Summary\n- accept published Buildchain v2.12.7-alpha.11\n- enable controlled retry of the existing unpublished paper transaction\n\n## Verification\n- make check\n- exact Buildchain GitHub/npm/tag release fact verified",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:02:00Z",
          "mergedAt": "2026-07-15T03:04:58Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 56,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/56",
          "title": "chore(buildchain): accept alpha.11 contract",
          "body": "## Summary\n- accept published Buildchain v2.12.7-alpha.11\n- enable controlled retry of the existing unpublished paper transaction\n\n## Verification\n- make check\n- exact Buildchain GitHub/npm/tag release fact verified",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:02:05Z",
          "mergedAt": "2026-07-15T03:05:12Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 46,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/46",
          "title": "release: retry sealed paper publication with alpha.11",
          "body": "## Summary\n- promote Buildchain v2.12.7-alpha.11 to the paper alpha channel\n- retry the unchanged planned package version through controlled stale-transaction replacement\n- publish npm alpha and the declared PDF GitHub Release asset after merge\n\n## Verification\n- dev PR checks and publication candidate passed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:05:31Z",
          "mergedAt": "2026-07-15T03:07:54Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 42,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/42",
          "title": "release: retry sealed paper publication with alpha.11",
          "body": "## Summary\n- promote Buildchain v2.12.7-alpha.11 to the paper alpha channel\n- retry the unchanged planned package version through controlled stale-transaction replacement\n- publish npm alpha and the declared PDF GitHub Release asset after merge\n\n## Verification\n- dev PR checks and publication candidate passed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:05:34Z",
          "mergedAt": "2026-07-15T03:08:01Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 57,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/57",
          "title": "release: retry sealed paper publication with alpha.11",
          "body": "## Summary\n- promote Buildchain v2.12.7-alpha.11 to the paper alpha channel\n- retry the unchanged planned package version through controlled stale-transaction replacement\n- publish npm alpha and the declared PDF GitHub Release asset after merge\n\n## Verification\n- dev PR checks and publication candidate passed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:05:37Z",
          "mergedAt": "2026-07-15T03:08:07Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 164,
          "url": "https://github.com/kungfu-systems/build-images/pull/164",
          "title": "chore(images): accept v1.2.4-alpha.10 digests",
          "body": "## Summary\n- join the `alpha.10` release ancestry without content changes\n- accept the complete five-image digest family from the trusted Release Passport\n- regenerate KFD1/KFD2 bindings for `images.lock.json`\n\n## Trust evidence\n- Release Passport: `ok=true`, `trust=pass`, `issues=[]`\n- source SHA: `b939ad8962d590ed21fecb0312694fb6980f3f17`\n- publish run: https://github.com/kungfu-systems/build-images/actions/runs/29384801309\n- baseline after acceptance: `eligible=true`, `mode=selective`, `selected_images=[]`\n\n## Verification\n- `pnpm run check`\n- 45 Comparator tests pass\n- KFD1/2/3 and Release Passport smoke pass\n\nThis PR must be merged with a merge commit so the alpha release source remains an ancestor of the reviewed lock acceptance.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:01:54Z",
          "mergedAt": "2026-07-15T03:08:35Z",
          "additions": 93,
          "deletions": 93,
          "changedFiles": 10
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 913,
          "url": "https://github.com/kungfu-systems/kungfu/pull/913",
          "title": "fix(gui): skip Python bytecode during macOS signing",
          "body": "## Summary\n\n- exclude Python bytecode and `__pycache__` contents from the macOS code-signing walk\n- preserve every existing ignore rule and continue signing native libraries and executables\n- avoid thousands of unnecessary Apple timestamp requests that made signed product packaging intermittently fail\n\n## Failure evidence\n\nTwo exact-source macOS qualification attempts reached `@electron/osx-sign` and failed on different `.pyc` files with `A timestamp was expected but was not found`; signing the same failed file manually succeeded immediately afterward. The failure is therefore isolated to high-volume timestamping of non-code Python cache artifacts.\n\n## Validation\n\n- `node --test framework/gui/scripts/sign-macos.test.mjs` (5 passed)\n- `./shifu check:source` (316 source contract, 76 runtime upgrade, 66 desktop adapter tests passed)\n- commit staged gate passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Stabilizes macOS product signing by excluding non-code Python cache artifacts without changing architecture authority or release policy\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:13:51Z",
          "mergedAt": "2026-07-15T03:16:36Z",
          "additions": 39,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 47,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/47",
          "title": "release: prepare paper 0.1.0-alpha.4",
          "body": "Advances the declared publication version to 0.1.0-alpha.4 after the previous alpha transaction completed. This preserves the pinned fixed LaTeX image, restored microtype expansion, deterministic PDF filename, and sealed Buildchain publication path with GitHub Release assets.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:22:45Z",
          "mergedAt": "2026-07-15T03:25:25Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 43,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/43",
          "title": "release: prepare paper 0.1.0-alpha.3",
          "body": "Advances the declared publication version to 0.1.0-alpha.3 after the previous alpha transaction completed. This preserves the pinned fixed LaTeX image, restored microtype expansion, deterministic PDF filename, and sealed Buildchain publication path with GitHub Release assets.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:22:47Z",
          "mergedAt": "2026-07-15T03:25:33Z",
          "additions": 7,
          "deletions": 7,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 58,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/58",
          "title": "release: prepare paper 0.1.0-alpha.6",
          "body": "Advances the declared publication version to 0.1.0-alpha.6 after the previous alpha transaction completed. This preserves the pinned fixed LaTeX image, restored microtype expansion, deterministic PDF filename, and sealed Buildchain publication path with GitHub Release assets.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:22:50Z",
          "mergedAt": "2026-07-15T03:25:41Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 48,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/48",
          "title": "release: publish 0.1.0-alpha.4 with PDF assets",
          "body": "Promotes the reviewed paper source to the alpha channel. The Buildchain sealed publication workflow will publish the npm package and attach the deterministic PDF plus release passport evidence to GitHub Release v0.1.0-alpha.4.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:26:05Z",
          "mergedAt": "2026-07-15T03:28:23Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 44,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/44",
          "title": "release: publish 0.1.0-alpha.3 with PDF assets",
          "body": "Promotes the reviewed paper source to the alpha channel. The Buildchain sealed publication workflow will publish the npm package and attach the deterministic PDF plus release passport evidence to GitHub Release v0.1.0-alpha.3.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:26:08Z",
          "mergedAt": "2026-07-15T03:29:10Z",
          "additions": 7,
          "deletions": 7,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 59,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/59",
          "title": "release: publish 0.1.0-alpha.6 with PDF assets",
          "body": "Promotes the reviewed paper source to the alpha channel. The Buildchain sealed publication workflow will publish the npm package and attach the deterministic PDF plus release passport evidence to GitHub Release v0.1.0-alpha.6.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:26:11Z",
          "mergedAt": "2026-07-15T03:29:17Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1259,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1259",
          "title": "fix(paper): provision trusted publishing runtime",
          "body": "Closes #1258.\n\nRestores the Node 24 runtime contract in the isolated sealed publisher job so npm can exchange the GitHub OIDC identity. Candidate construction and publication authority remain credential-free.\n\nValidation: `pnpm run check` passed with 619 tests.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:33:55Z",
          "mergedAt": "2026-07-15T03:36:05Z",
          "additions": 8,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 915,
          "url": "https://github.com/kungfu-systems/kungfu/pull/915",
          "title": "feat(xinfa): freeze standalone product boundary",
          "body": "## Summary\n\nFreeze Xinfa as an independently versioned and extractable context compiler product while preserving Shifu as the submission-protocol, conformance, Gate, and thin-invocation authority.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add ADR-0092 and a machine-readable product, boundary, and extraction contract\n- add a dependency-free Rust CLI with stable version, contract, and read-only diagnostic surfaces\n- reject private host imports, dependency tables, monorepo-relative roots, and extraction symlinks with negative fixtures\n- prove clean temporary extraction, host-environment scrubbing, independent state/cache roots, and deterministic contract output\n- keep Xinfa tasks independent of unrelated Kungfu Conan cache contention across POSIX and Windows Shifu entrypoints\n- register the pre-release Xinfa product surface and document the incubation boundary\n\n## Verification\n\n- `./shifu xinfa:check`\n- `./shifu xinfa:standalone`\n- `./shifu check:source`\n- staged pre-commit gate including ADR/docs, boundary, Rust, and entrypoint checks\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0092\"],\n  \"summary\": \"Freeze Xinfa product identity and prove its extraction-first standalone boundary without implementing the full context compiler\",\n  \"verification\": [\"xinfa:check\", \"xinfa:standalone\", \"check:source\", \"staged pre-commit gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR freezes the pre-release Xinfa identity and tag/artifact convention but publishes nothing and opens no release line.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:24:34Z",
          "mergedAt": "2026-07-15T03:36:05Z",
          "additions": 1207,
          "deletions": 0,
          "changedFiles": 27
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1260,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1260",
          "title": "release: promote sealed paper trusted publishing fix to alpha",
          "body": "Promotes #1259 / #1258 to the Buildchain alpha channel so paper consumers can retry their source-locked unpublished transactions with Node 24 npm OIDC support.\n\nThe implementation passed the full Buildchain check suite (619 tests).",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:36:31Z",
          "mergedAt": "2026-07-15T03:38:40Z",
          "additions": 8,
          "deletions": 0,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 916,
          "url": "https://github.com/kungfu-systems/kungfu/pull/916",
          "title": "fix(gui): preserve macOS signing ignore function",
          "body": "## Summary\n\n- pass one combined ignore function to `@electron/osx-sign` instead of an array\n- preserve existing string, array, and function rules inside that function\n- keep Python bytecode out of code signing after the previous array form was discarded by osx-sign 1.3.3\n\n## Runtime evidence\n\nAn exact-source signed product build after PR #913 still spawned `codesign` for a `.pyc` file. Inspection showed osx-sign 1.3.3 normalizes a non-array ignore into an array but returns `undefined` for an array input, silently discarding the prior hook result. The invalid signing run was stopped before further timestamp load.\n\n## Validation\n\n- `node --test framework/gui/scripts/sign-macos.test.mjs` (6 passed)\n- `./shifu check:source` (316 source contract, 76 runtime upgrade, 67 desktop adapter tests passed)\n- commit staged gate passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Corrects the macOS signing adapter compatibility fix without changing architecture authority or release policy\"\n}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:35:18Z",
          "mergedAt": "2026-07-15T03:40:00Z",
          "additions": 29,
          "deletions": 14,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 917,
          "url": "https://github.com/kungfu-systems/kungfu/pull/917",
          "title": "fix(core): run live-peer campaign through uv",
          "body": "## Summary\n\nRun the live-peer native campaign through the Shifu-managed `uv run` project entry so strict cache overlays remain active for the whole campaign.\n\n## Related issue\n\nNone. Found while qualifying the zero-burden desktop runtime through the full Buildchain matrix.\n\n## Changes\n\n- Replace direct virtual-environment interpreter resolution with `uv run --frozen --project framework/core python`.\n- Preserve Windows command resolution through the existing bounded shell path.\n- Cover the Shifu-managed invocation contract with a focused regression test.\n\n## Verification\n\n- `node --test framework/core/tests/qualification/live-peer-continuity/run.test.mjs`\n- `XDG_CACHE_HOME=\"$HOME/.cache/kungfu-agent-partitions/live-peer-uv-run\" ./shifu check`\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source`\n- staged pre-commit gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"This fixes the qualification execution route through the existing Shifu uv authority without changing the accepted runtime architecture or claim envelope\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not needed; execution behavior is asserted by tests)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:35:47Z",
          "mergedAt": "2026-07-15T03:44:43Z",
          "additions": 30,
          "deletions": 23,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 918,
          "url": "https://github.com/kungfu-systems/kungfu/pull/918",
          "title": "fix(shifu): unify managed Conan cache coordination",
          "body": "## Summary\n\nMove managed Conan cache coordination into the Shifu execution boundary. Development worktrees and named runners receive deterministic partitions, ordinary non-Conan tasks no longer acquire the Conan lock, and real Conan invocations use bounded same-partition waiting with fail-closed stale-lock handling.\n\n## Related issue\n\n- Cross-repository checkout-cache dependency: https://github.com/kungfu-systems/buildchain/issues/1261\n\n## Changes\n\n- derive redacted Conan storage partitions from the development worktree or runner principal\n- wrap Conan on demand instead of holding a storage lock for every Shifu task\n- reclaim only locks whose recorded owner process is provably dead\n- preserve unreadable or live locks and fail after a bounded wait\n- document the cache lifecycle and extend the resolution receipt state\n\n## Verification\n\n- `./shifu check`\n- `./shifu check:source`\n- `node --test scripts/shifu-cache-runtime.test.mjs scripts/shifu-gate-executor.test.mjs`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"SHIFU-ADR-0001\"],\n  \"summary\": \"Complete Shifu-owned Conan cache partitioning and on-demand concurrency control\",\n  \"verification\": [\"Shifu cache contract tests\", \"source acceptance gate\", \"full Shifu check\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:41:10Z",
          "mergedAt": "2026-07-15T03:49:16Z",
          "additions": 408,
          "deletions": 77,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 49,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/49",
          "title": "chore(buildchain): accept alpha.12 trusted-publishing contract",
          "body": "Advances the floating Buildchain contract lock to v2.12.7-alpha.12 (90d3ccd8), which restores Node 24 npm OIDC support in the sealed paper publisher. The paper version and candidate contents remain unchanged for safe retry of the incomplete transaction.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:48:24Z",
          "mergedAt": "2026-07-15T03:51:39Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 45,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/45",
          "title": "chore(buildchain): accept alpha.12 trusted-publishing contract",
          "body": "Advances the floating Buildchain contract lock to v2.12.7-alpha.12 (90d3ccd8), which restores Node 24 npm OIDC support in the sealed paper publisher. The paper version and candidate contents remain unchanged for safe retry of the incomplete transaction.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:48:26Z",
          "mergedAt": "2026-07-15T03:51:50Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 60,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/60",
          "title": "chore(buildchain): accept alpha.12 trusted-publishing contract",
          "body": "Advances the floating Buildchain contract lock to v2.12.7-alpha.12 (90d3ccd8), which restores Node 24 npm OIDC support in the sealed paper publisher. The paper version and candidate contents remain unchanged for safe retry of the incomplete transaction.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:48:29Z",
          "mergedAt": "2026-07-15T03:51:59Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 50,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/50",
          "title": "release: retry 0.1.0-alpha.4 with Buildchain alpha.12",
          "body": "Retries the same unpublished 0.1.0-alpha.4 transaction with the released Buildchain alpha.12 trusted-publishing runtime. Candidate bytes remain source-bound; the incomplete prior transaction may be replaced, then npm and named PDF GitHub Release assets must finalize together.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:52:36Z",
          "mergedAt": "2026-07-15T03:54:51Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 46,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/46",
          "title": "release: retry 0.1.0-alpha.3 with Buildchain alpha.12",
          "body": "Retries the same unpublished 0.1.0-alpha.3 transaction with the released Buildchain alpha.12 trusted-publishing runtime. Candidate bytes remain source-bound; the incomplete prior transaction may be replaced, then npm and named PDF GitHub Release assets must finalize together.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:52:39Z",
          "mergedAt": "2026-07-15T03:54:56Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 61,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/61",
          "title": "release: retry 0.1.0-alpha.6 with Buildchain alpha.12",
          "body": "Retries the same unpublished 0.1.0-alpha.6 transaction with the released Buildchain alpha.12 trusted-publishing runtime. Candidate bytes remain source-bound; the incomplete prior transaction may be replaced, then npm and named PDF GitHub Release assets must finalize together.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T03:52:41Z",
          "mergedAt": "2026-07-15T03:55:01Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 919,
          "url": "https://github.com/kungfu-systems/kungfu/pull/919",
          "title": "fix(gui): sign only macOS code artifacts",
          "body": "## Summary\n- restrict the custom macOS signing traversal to Mach-O files and nested code bundles\n- keep existing ignore rules while preventing `@electron/osx-sign` 1.3.3 from treating binary-looking resources such as Electron locale `.pak` and Python bytecode as code\n- fail closed when a signing candidate cannot be inspected\n\n## Verification\n- `./shifu check:source`\n- desktop signing tests: 8 passed\n- real Developer ID re-sign of the complete arm64 app bundle\n- `codesign --verify --deep --strict --verbose=2`: passed\n- observed native `.node`, `.dylib`, `.so`, executables, and `.framework` as signable; `.pyc` and `locale.pak` as sealed resources\n\nNotarization is not claimed by this PR; Gatekeeper correctly reports the locally signed test bundle as unnotarized.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Corrects macOS code-artifact discovery without changing the versioned upgrade or release architecture contract\"\n}\n-->\n\n## Governance risk check\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\n## Checklist\n- [x] Commit is signed off (DCO)\n- [x] Existing architecture claims remain unchanged\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:02:52Z",
          "mergedAt": "2026-07-15T04:05:03Z",
          "additions": 95,
          "deletions": 14,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1264,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1264",
          "title": "fix(release): preserve hidden paper publication assets",
          "body": "Closes #1263\n\nPreserves the hidden publication manifest/passport files across the sealed artifact handoff and adds a workflow contract regression test.\n\nValidation: pnpm run check (619 tests passed).",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:03:26Z",
          "mergedAt": "2026-07-15T04:05:22Z",
          "additions": 4,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1265,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1265",
          "title": "release: promote complete paper publication candidates to alpha",
          "body": "Promotes #1264 / #1263 to the Buildchain alpha channel. The fix preserves hidden publication manifest and passport files across the sealed artifact handoff so admitted npm bytes remain identical at publication time.\n\nThe implementation passed the full Buildchain check suite (619 tests).",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:06:41Z",
          "mergedAt": "2026-07-15T04:08:47Z",
          "additions": 4,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 922,
          "url": "https://github.com/kungfu-systems/kungfu/pull/922",
          "title": "feat(core): add native KFX registry plan parity",
          "body": "## Summary\n\nAdd the Core-native, read-only KFX manifest registry and deterministic load-plan stage while keeping runtime tier, admission grade, lifecycle mutation, and Buildchain admission authority separate.\n\n## Related issue\n\nAtlas goal `2026-07-15-kungfu-native-kfx-registry-plan-parity`.\n\n## Changes\n\n- advance the native KFX contract to v2 with explicit `runtimeTiers` and `admissionGrades`, retaining v1 compatibility\n- add bounded product, user, and workspace manifest discovery with canonical package roots, Suite/profile closure, deterministic registry roots, and plan roots\n- expose thin Node, Python, API, and CLI projections over the native read-only authority\n- add shared fixture parity for native, TypeScript, and Python projections, including optional-member degradation and typed refusals\n- keep package lifecycle mutation, capability authorization, trust assessment, and artifact admission outside this stage\n\n## Verification\n\n- `./shifu rebuild:core`\n- native C++ KFX contract target: 1/1 passed\n- Node storage binding: 13/13 passed\n- Python native KFX binding: 4/4 passed\n- API query projection: 18/18 passed\n- `./shifu test:kfx-profile-suite`\n- `./shifu check:source`\n- `./shifu check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0088\", \"ADR-0089\", \"ADR-0090\", \"ADR-0091\"],\n  \"summary\": \"Add the Core-native read-only KFX manifest registry, Suite closure, deterministic load-plan contract, and cross-language shadow parity without claiming lifecycle mutation or artifact admission.\",\n  \"verification\": [\"./shifu rebuild:core\", \"./shifu test:kfx-profile-suite\", \"./shifu check:source\", \"./shifu check\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe contract now separates runtime placement tiers from admission grades and carries read-only trust inputs. It does not verify Buildchain attestations, grant capabilities, mutate package lifecycle state, publish packages, or claim release qualification.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:13:51Z",
          "mergedAt": "2026-07-15T04:18:19Z",
          "additions": 2038,
          "deletions": 133,
          "changedFiles": 43
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 51,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/51",
          "title": "release: prepare complete paper alpha",
          "body": "Adopts Buildchain v2.12.7-alpha.13, which preserves hidden publication manifest/passport files across the sealed candidate handoff, and advances to a new npm version after the prior incomplete publication was occupied.\n\nThe paper remains pinned to the fixed LaTeX image with microtype support. Local repository checks passed.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:17:29Z",
          "mergedAt": "2026-07-15T04:20:05Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 47,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/47",
          "title": "release: prepare complete paper alpha",
          "body": "Adopts Buildchain v2.12.7-alpha.13, which preserves hidden publication manifest/passport files across the sealed candidate handoff, and advances to a new npm version after the prior incomplete publication was occupied.\n\nThe paper remains pinned to the fixed LaTeX image with microtype support. Local repository checks passed.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:17:32Z",
          "mergedAt": "2026-07-15T04:20:12Z",
          "additions": 10,
          "deletions": 10,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 62,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/62",
          "title": "release: prepare complete paper alpha",
          "body": "Adopts Buildchain v2.12.7-alpha.13, which preserves hidden publication manifest/passport files across the sealed candidate handoff, and advances to a new npm version after the prior incomplete publication was occupied.\n\nThe paper remains pinned to the fixed LaTeX image with microtype support. Local repository checks passed.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:17:34Z",
          "mergedAt": "2026-07-15T04:20:18Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 52,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/52",
          "title": "release: publish complete paper alpha",
          "body": "Promotes the Buildchain v2.12.7-alpha.13 consumer update and the next unoccupied paper alpha version. The release must prove an identical admitted npm package and publish the named PDF plus Buildchain evidence to GitHub Release.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:20:36Z",
          "mergedAt": "2026-07-15T04:23:20Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 48,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/48",
          "title": "release: publish complete paper alpha",
          "body": "Promotes the Buildchain v2.12.7-alpha.13 consumer update and the next unoccupied paper alpha version. The release must prove an identical admitted npm package and publish the named PDF plus Buildchain evidence to GitHub Release.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:20:38Z",
          "mergedAt": "2026-07-15T04:23:26Z",
          "additions": 10,
          "deletions": 10,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 63,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/63",
          "title": "release: publish complete paper alpha",
          "body": "Promotes the Buildchain v2.12.7-alpha.13 consumer update and the next unoccupied paper alpha version. The release must prove an identical admitted npm package and publish the named PDF plus Buildchain evidence to GitHub Release.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:20:41Z",
          "mergedAt": "2026-07-15T04:23:32Z",
          "additions": 4,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1266,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1266",
          "title": "fix(release): select canonical paper evidence",
          "body": "## Summary\n- resolve paper publication manifest and passport from their canonical root paths\n- keep self-describing copies inside the npm package without confusing authority admission\n- cover the duplicate-filename artifact layout in a regression test\n\n## Verification\n- `node --test tests/publication-artifact-candidate.test.mjs`\n- `pnpm run check` (620 tests passed)\n\nCloses #1263",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:31:19Z",
          "mergedAt": "2026-07-15T04:33:27Z",
          "additions": 63,
          "deletions": 24,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 921,
          "url": "https://github.com/kungfu-systems/kungfu/pull/921",
          "title": "refactor(core): enforce internal target boundaries",
          "body": "## Summary\n\nTurn the executable Core layer contract into concrete CMake target boundaries while preserving the public `kungfu` artifact and platform behavior.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- derive five internal target boundaries from `framework/core/architecture/layers.json`\n- generate-check explicit CMake source ownership in `TARGETS.cmake` without recursive globbing\n- aggregate internal OBJECT targets behind the existing public `kungfu` target\n- enforce dependency direction, unique production-source ownership, projection freshness, and target-kind invariants\n- document the internal target graph and add controlled negative fixtures\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu check`\n- `./shifu exec node framework/core/architecture/check-layers.mjs`\n- `./shifu exec node framework/core/architecture/check-layers.mjs --self-test` (11 fixtures)\n- macOS AppleClang 21: clean `rebuild:core` + incremental `build:core`\n- Linux GCC 14 on agent-120: clean `rebuild:core` + incremental `build:core`\n- Windows MSVC 19.5 on DARKHERO: clean `rebuild:core` + incremental `build:core`\n\nThe Windows runner required a worktree-local CMake cache override to bypass an unrelated `sccache` temporary-file permission failure; the MSVC compile/link/package path then completed successfully.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0049\"],\n  \"summary\": \"Enforce concrete internal CMake target boundaries and downward dependencies for the domain-neutral Core while preserving the public libkungfu artifact.\",\n  \"verification\": [\"./shifu check\", \"11 architecture target fixtures\", \"clean and incremental Core builds on macOS, Linux, and Windows\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:12:58Z",
          "mergedAt": "2026-07-15T04:35:04Z",
          "additions": 431,
          "deletions": 42,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1267,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1267",
          "title": "chore(release): promote canonical paper evidence fix",
          "body": "## Summary\n- promote the canonical paper evidence selection fix to the v2.12 alpha channel\n- unblock sealed paper publication when npm packages carry self-describing evidence copies\n\n## Source\n- #1266\n- #1263",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:33:48Z",
          "mergedAt": "2026-07-15T04:35:57Z",
          "additions": 63,
          "deletions": 24,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 924,
          "url": "https://github.com/kungfu-systems/kungfu/pull/924",
          "title": "fix(runtime): make product qualification fresh-runner safe",
          "body": "## Summary\n\n- keep ordinary runtime lifecycle ownership out of the GUI main process while preserving the explicit backup/reset recovery flow through the shared CLI\n- verify the exact product outputs just produced by runtime qualification instead of starting a second native rebuild\n- bootstrap pinned Buildchain layout discovery only for KFD-declared distribution tasks so fresh runners register artifacts before `shifu builds --json`\n\n## Evidence\n\n- `cargo fmt --manifest-path crates/Cargo.toml --all --check`\n- `cargo test --manifest-path crates/Cargo.toml -p shifu registrar::tests` (10 passed)\n- `./shifu check:source` (323 source contract tests, 76 runtime upgrade tests, 69 desktop update/signing tests, TypeScript checks)\n- commit hook: workspace clippy with `-D warnings`, workspace Rust tests, documentation and staged gates\n- agent-120 product verification reached 34/35; the only failure was a duplicate Episode timeout under concurrent IO, so the artifact suite now skips that already-completed outer campaign\n- targeted runtime-activation tests (7 passed) plus a fresh `./shifu check:source` on `efce4b90b`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repairs fresh-runner qualification execution and preserves existing runtime ownership contracts without changing an architecture decision.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change affects qualification evidence generation only. It does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (inline contract comments and tests cover the bounded behavior)\n\n\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:31:14Z",
          "mergedAt": "2026-07-15T04:40:07Z",
          "additions": 130,
          "deletions": 7,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 53,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/53",
          "title": "chore(buildchain): accept alpha.14 contract",
          "body": "## Summary\n- accept Buildchain `v2.12.7-alpha.14` at its immutable `v2-alpha` SHA\n- retain the unchanged major-compatible contract surface\n- unblock the sealed paper publication retry\n\n## Verification\n- repository-local check passed\n- Buildchain compatibility digest is unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:46:56Z",
          "mergedAt": "2026-07-15T04:49:06Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 49,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/49",
          "title": "chore(buildchain): accept alpha.14 contract",
          "body": "## Summary\n- accept Buildchain `v2.12.7-alpha.14` at its immutable `v2-alpha` SHA\n- retain the unchanged major-compatible contract surface\n- unblock the sealed paper publication retry\n\n## Verification\n- repository-local check passed\n- Buildchain compatibility digest is unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:46:59Z",
          "mergedAt": "2026-07-15T04:49:12Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 64,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/64",
          "title": "chore(buildchain): accept alpha.14 contract",
          "body": "## Summary\n- accept Buildchain `v2.12.7-alpha.14` at its immutable `v2-alpha` SHA\n- retain the unchanged major-compatible contract surface\n- unblock the sealed paper publication retry\n\n## Verification\n- repository-local check passed\n- Buildchain compatibility digest is unchanged",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:47:02Z",
          "mergedAt": "2026-07-15T04:49:18Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 54,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/54",
          "title": "chore(release): promote Buildchain alpha.14 lock",
          "body": "## Summary\n- promote the reviewed Buildchain alpha.14 contract lock\n- retry the existing paper alpha publication through sealed authority\n- publish the declared PDF as a GitHub Release asset",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:50:18Z",
          "mergedAt": "2026-07-15T04:52:51Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 50,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/50",
          "title": "chore(release): promote Buildchain alpha.14 lock",
          "body": "## Summary\n- promote the reviewed Buildchain alpha.14 contract lock\n- retry the existing paper alpha publication through sealed authority\n- publish the declared PDF as a GitHub Release asset",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:50:20Z",
          "mergedAt": "2026-07-15T04:52:56Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 65,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/65",
          "title": "chore(release): promote Buildchain alpha.14 lock",
          "body": "## Summary\n- promote the reviewed Buildchain alpha.14 contract lock\n- retry the existing paper alpha publication through sealed authority\n- publish the declared PDF as a GitHub Release asset",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:50:23Z",
          "mergedAt": "2026-07-15T04:53:02Z",
          "additions": 3,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1269,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1269",
          "title": "fix(release): authorize sealed paper bookkeeping",
          "body": "## Summary\n- accept an optional bypass-capable token in the sealed paper preset\n- restrict it to generated protected version-state ref updates\n- keep npm publication bound to OIDC trusted publishing\n- regenerate public workflow and documentation projections\n\n## Verification\n- `node --test tests/build-surface.test.mjs tests/paper-sealed-release.test.mjs`\n- `pnpm run check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:03:50Z",
          "mergedAt": "2026-07-15T05:05:58Z",
          "additions": 42,
          "deletions": 23,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1270,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1270",
          "title": "chore(release): promote v2.12 dev to alpha",
          "body": "Promote the current verified `dev/v2/v2.12` state to the alpha channel.\n\nIncludes sealed paper publication support for protected generated version-state updates while preserving OIDC-only npm publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:06:19Z",
          "mergedAt": "2026-07-15T05:08:40Z",
          "additions": 42,
          "deletions": 23,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 927,
          "url": "https://github.com/kungfu-systems/kungfu/pull/927",
          "title": "fix(kfd): refresh release evidence after contract changes",
          "body": "## Summary\n\n- refresh the generated KFD-1 witness after the canonical policy and KFX contract changed\n- refresh the derived release gate and packaged SDK projections\n- bind the KFD-3 prebuild witness to the exact current source SHA\n\n## Evidence\n\n- `node scripts/buildchain-kfd-evidence.mjs --check --json` (current)\n- `./shifu check:source` (323 source tests, 76 runtime upgrade tests, 69 desktop update/signing tests)\n- commit hook Buildchain KFD evidence check and staged gates\n- exact macOS release qualification reached 41/42; the sole prior failure was the stale KFD witness repaired here\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Refreshes generated release evidence to match already-merged contract sources without changing an architecture decision.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nGenerated evidence only; this PR does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Generated evidence is current under the repository checker",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:06:39Z",
          "mergedAt": "2026-07-15T05:09:10Z",
          "additions": 30,
          "deletions": 30,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 926,
          "url": "https://github.com/kungfu-systems/kungfu/pull/926",
          "title": "feat(xinfa): add dual-first context IR protocol",
          "body": "## Summary\n\nAdd the project-independent, dual-first Xinfa project protocol and minimal Context IR compiler. Human and Agent routes consume the same cut, authority nodes, verification status, evidence semantics, and authority root.\n\n## Related issue\n\nAtlas goal 2026-07-15-xinfa-context-ir-and-project-protocol.\n\n## Changes\n\n- accept ADR-0093 and align ADR-0092 with the verified human-Agent product boundary\n- add public xinfa.project/v1 and xinfa.context-ir/v1 schemas plus validate, canonicalize, and compile CLI surfaces\n- derive stale and invalidated states from exact dependencies while keeping non-claims outside implementation drift\n- enforce exact providers, fail-closed visibility, stable diagnostics, route parity, and standalone dependency boundaries\n- retain two non-isomorphic positive fixtures, ten negative cases, and Mac qualification receipts\n\n## Verification\n\n- ./shifu xinfa:check\n- ./shifu xinfa:standalone\n- ./shifu docs:check:readonly\n- ./shifu check:source\n- AJV 2020 validation for both positive project fixtures\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0092\", \"ADR-0093\"],\n  \"summary\": \"Complete the dual-first project protocol and minimal Context IR compiler stage\",\n  \"verification\": [\"xinfa check\", \"clean extraction standalone smoke\", \"source acceptance\", \"documentation and ADR gates\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR updates the pre-release Xinfa product identity and retained qualification evidence only. It does not publish a package, open a stable line, call a hosted service, or add credentials.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T04:54:19Z",
          "mergedAt": "2026-07-15T05:14:38Z",
          "additions": 2622,
          "deletions": 35,
          "changedFiles": 31
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 55,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/55",
          "title": "release: publish alpha.6 with GitHub PDF",
          "body": "## Summary\n- publish KFD foundation paper `0.1.0-alpha.6`\n- lock Buildchain v2-alpha to v2.12.7-alpha.15\n- forward the protected-ref bookkeeping secret to the sealed paper preset\n- retain the pinned LaTeX Docker image with microtype expansion enabled\n- publish the named PDF through the exact-version GitHub Release\n\n## Local verification\n- repository check passed\n- contract lock generated from Buildchain v2.12.7-alpha.15\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:19:18Z",
          "mergedAt": "2026-07-15T05:21:46Z",
          "additions": 6,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 51,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/51",
          "title": "release: publish alpha.5 with GitHub PDF",
          "body": "## Summary\n- publish Kungfu product white paper `0.1.0-alpha.5`\n- lock Buildchain v2-alpha to v2.12.7-alpha.15\n- forward the protected-ref bookkeeping secret to the sealed paper preset\n- retain the pinned LaTeX Docker image with microtype expansion enabled\n- publish the named PDF through the exact-version GitHub Release\n\n## Local verification\n- repository check passed\n- contract lock generated from Buildchain v2.12.7-alpha.15\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:19:20Z",
          "mergedAt": "2026-07-15T05:21:57Z",
          "additions": 12,
          "deletions": 10,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 66,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/66",
          "title": "release: publish alpha.8 with GitHub PDF",
          "body": "## Summary\n- publish Observer-declared timelines `0.1.0-alpha.8`\n- lock Buildchain v2-alpha to v2.12.7-alpha.15\n- forward the protected-ref bookkeeping secret to the sealed paper preset\n- retain the pinned LaTeX Docker image with microtype expansion enabled\n- publish the named PDF through the exact-version GitHub Release\n\n## Local verification\n- repository check passed\n- contract lock generated from Buildchain v2.12.7-alpha.15\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:19:24Z",
          "mergedAt": "2026-07-15T05:22:07Z",
          "additions": 6,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 56,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/56",
          "title": "chore(release): promote paper alpha",
          "body": "Promote the verified paper release to the alpha channel.\n\nThe release uses Buildchain v2.12.7-alpha.15, publishes the named PDF to the exact-version GitHub Release, and uses the protected-ref token only for generated version-state bookkeeping.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:22:25Z",
          "mergedAt": "2026-07-15T05:24:23Z",
          "additions": 6,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/paper-kungfu-product-white-paper",
          "number": 52,
          "url": "https://github.com/kungfu-systems/paper-kungfu-product-white-paper/pull/52",
          "title": "chore(release): promote paper alpha",
          "body": "Promote the verified paper release to the alpha channel.\n\nThe release uses Buildchain v2.12.7-alpha.15, publishes the named PDF to the exact-version GitHub Release, and uses the protected-ref token only for generated version-state bookkeeping.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:22:29Z",
          "mergedAt": "2026-07-15T05:24:28Z",
          "additions": 12,
          "deletions": 10,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/paper-observer-declared-timelines",
          "number": 67,
          "url": "https://github.com/kungfu-systems/paper-observer-declared-timelines/pull/67",
          "title": "chore(release): promote paper alpha",
          "body": "Promote the verified paper release to the alpha channel.\n\nThe release uses Buildchain v2.12.7-alpha.15, publishes the named PDF to the exact-version GitHub Release, and uses the protected-ref token only for generated version-state bookkeeping.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:22:33Z",
          "mergedAt": "2026-07-15T05:24:34Z",
          "additions": 6,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 930,
          "url": "https://github.com/kungfu-systems/kungfu/pull/930",
          "title": "fix(qualification): isolate installed provider drift",
          "body": "## Summary\n\n- keep the credential-free zero-burden aggregate deterministic across self-hosted runners\n- run the complete Agent Session control-plane/native recovery suite while keeping installed-provider version and Codex schema drift as separate native gates\n- document and test that incidental runner CLI installations cannot widen or block the aggregate claim\n\n## Evidence\n\n- ./shifu build:core\n- ./shifu --filter @kungfu-tech/agent-session test:control-plane (93/93)\n- node --test scripts/run-zero-burden-product-qualification.test.mjs (4/4)\n- ./shifu check\n- SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source (324 source, 76 runtime-upgrade, 69 desktop-update)\n- commit hook staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Keeps credential-free qualification independent of incidental runner provider installations without changing provider compatibility or runtime authority contracts.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo provider credentials or private state are read; installed-provider drift gates remain separately available. This changes qualification composition only and does not publish artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:55:01Z",
          "mergedAt": "2026-07-15T06:02:44Z",
          "additions": 39,
          "deletions": 6,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 929,
          "url": "https://github.com/kungfu-systems/kungfu/pull/929",
          "title": "refactor(core): decompose storage service responsibilities",
          "body": "## Summary\n\nSplit the oversized C++ storage implementation into explicit provider, maintenance, transfer, and domain-dispatch responsibilities while preserving the public storage facade and runtime behavior.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- move file and RocksDB provider ownership behind a private storage provider port in the adapter target\n- isolate status, fsck, rebuild, GC, and compaction planning as a maintenance service\n- isolate manifest bundle import, export, and sync verification as a transfer service\n- move JSON-edge/domain dispatch into the composition target\n- retain the public compatibility facade and shared application helpers in `service.cpp`\n- add executable responsibility seams with source budgets, required/forbidden ownership tokens, and negative fixtures\n- regenerate the architecture map and CMake target projection for all 208 first-party C/C++ sources\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu build:core`\n- `./shifu exec ctest --test-dir framework/core/build --output-on-failure` (12/12)\n- `KUNGFU_DIR=\"$PWD/framework/core/build/Release\" ./shifu exec node --test framework/core/tests/storage-node-binding.test.js` (13/13)\n- `./shifu exec node framework/core/architecture/check-layers.mjs`\n- `./shifu exec node framework/core/architecture/check-layers.mjs --self-test` (14 fixtures)\n\nCross-platform exact-SHA qualification will be completed before merge.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0049\"],\n  \"summary\": \"Decompose the C++ storage runtime into executable provider, service, transfer, and composition responsibilities while preserving the public storage facade.\",\n  \"verification\": [\"./shifu check:source\", \"14 architecture fixtures\", \"CMake/CTest and Node storage parity tests\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T05:30:12Z",
          "mergedAt": "2026-07-15T06:07:38Z",
          "additions": 2801,
          "deletions": 2378,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 931,
          "url": "https://github.com/kungfu-systems/kungfu/pull/931",
          "title": "feat(xinfa): compile repository context packs",
          "body": "## Summary\n\nCompile exact project authority into portable, deterministic Repository Context Packs without changing the existing Context IR compatibility surface. The Pack embeds bounded UTF-8 source units, preserves dual-first route parity, exposes bidirectional coverage and impact, and remains explicitly non-qualifying.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add ADR-0094 and public Pack, manifest, and receipt schemas\n- add atomic compile output plus inspect, offline verify, and impact CLI surfaces\n- fail closed on provider drift, visibility broadening, symlinks, sensitive paths, unsupported providers, and partial output\n- add small, medium, changed-scope, and malicious fixtures with golden roots and standalone qualification\n\n## Verification\n\n- `./shifu xinfa:check` (18 Rust library tests, 1 CLI test, boundary checks)\n- `./shifu xinfa:standalone`\n- `./shifu docs:check:readonly`\n- `./shifu check:source` (324 Node tests, 76 Python tests, 69 desktop tests, typecheck and format/lint)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0094\"],\n  \"summary\": \"Deliver the deterministic Repository Context Pack vertical slice with portable payloads, roots, coverage, impact, offline verification, and standalone proof\",\n  \"verification\": [\"./shifu xinfa:check\", \"./shifu xinfa:standalone\", \"./shifu docs:check:readonly\", \"./shifu check:source\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe new provenance and receipts are local Xinfa compiler artifacts. They explicitly set `qualifying: false` and `selfCertified: false`; they do not attest a release or execute providers/probes.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T06:10:17Z",
          "mergedAt": "2026-07-15T06:18:56Z",
          "additions": 2352,
          "deletions": 17,
          "changedFiles": 40
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 932,
          "url": "https://github.com/kungfu-systems/kungfu/pull/932",
          "title": "fix(shifu): preserve tool path across nested cache apply",
          "body": "## Summary\n\n- preserve the first real Cargo and Conan PATH across nested Shifu cache overlays\n- prevent an inner wrapper from resolving an outer wrapper as the real tool\n- add a bounded regression test for nested wrapper PATH provenance\n\n## Evidence\n\n- `node --test scripts/shifu-cache-runtime.test.mjs` (18/18)\n- `./shifu check:source` (325 Node tests, 76 Python tests, 69 desktop update tests)\n- `./shifu check:shifu-cache-contract`\n\n## Failure prevented\n\nA nested `layers.sdk` Gate under the development cache profile could recursively invoke the Cargo wrapper, repeatedly append registry config, and spawn thousands of Node processes. The Gate was interrupted and all residual overlay processes were verified absent before this patch.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fixes nested cache wrapper execution so existing Shifu and Gate contracts run safely without changing an architecture decision.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes only local cache-wrapper process selection and does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Regression test and source acceptance are green\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T06:11:14Z",
          "mergedAt": "2026-07-15T06:25:43Z",
          "additions": 54,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 933,
          "url": "https://github.com/kungfu-systems/kungfu/pull/933",
          "title": "fix(qualification): preserve RC evidence across platforms",
          "body": "## Summary\n\n- preserve the Buildchain-retained upgrade qualification reference through nested product distribution builds\n- use a platform-safe temporary root for the Windows native live-peer campaign\n- replace the Unix-only machine probe with a portable platform probe\n- add bounded regression coverage for both release evidence and platform planning\n\n## Evidence\n\n- `node --test scripts/run-release-qualification.test.mjs framework/core/tests/qualification/live-peer-continuity/run.test.mjs` (20/20)\n- `./shifu check:source` (325 Node tests, 76 Python tests, 69 desktop update tests)\n- staged DCO hook and Python/TypeScript format checks passed\n\n## Hosted failures fixed\n\n- Linux final qualification rebuilt product artifacts without `KF_UPGRADE_QUALIFICATION_REF`, causing `upgrade:qualify:native` to reject an otherwise RC-qualified build.\n- Windows native live-peer qualification failed immediately because the campaign assumed `/tmp` and later used `os.uname()`.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fixes cross-platform execution of existing release qualification contracts without changing an architecture decision.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes only qualification environment propagation and disposable test workspace selection; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Source acceptance is green\n- [x] No credentials or generated qualification evidence are committed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T06:30:18Z",
          "mergedAt": "2026-07-15T06:32:28Z",
          "additions": 47,
          "deletions": 17,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 935,
          "url": "https://github.com/kungfu-systems/kungfu/pull/935",
          "title": "fix(agent-session): keep Darwin test sockets short",
          "body": "## Summary\n\n- keep direct Agent Session Unix-domain socket tests on the same short Darwin temp-root policy as production\n- prevent deeply nested Buildchain TMPDIR values from turning valid detached-worker and local-RPC assertions into path-length failures\n- preserve the full recovery and RPC assertions on every platform\n\n## Evidence\n\n- ./shifu build:core\n- TMPDIR=\"$PWD/.buildchain/tmp\" node --test framework/agent-session/tests/capsule-worker.test.mjs framework/agent-session/tests/product-surface.test.mjs (17/17)\n- corepack pnpm --filter @kungfu-tech/agent-session test:control-plane (93/93)\n- node --test framework/core/tests/qualification/live-peer-continuity/run.test.mjs (7/7)\n- node --test scripts/check-shifu-cache-contract.test.mjs scripts/shifu-cache-runtime.test.mjs scripts/shifu-uv-cache-adapter.test.mjs (47/47)\n- commit hook staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Aligns test-owned Darwin socket paths with the existing production runtime policy without changing runtime authority or product behavior.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nNo product authority or release contract changes. The patch only prevents qualification-only endpoint paths from exceeding Darwin's Unix-domain socket limit.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T07:05:01Z",
          "mergedAt": "2026-07-15T07:13:56Z",
          "additions": 6,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 936,
          "url": "https://github.com/kungfu-systems/kungfu/pull/936",
          "title": "test(shifu): isolate nested cache path fixtures",
          "body": "## Summary\n\n- make the tool-overlay fixtures explicit about whether they start from a clean environment or an already wrapped Shifu environment\n- keep inherited Cargo and Conan original-path authority when testing nested apply\n- remove inherited wrapper authority only in the fixture that intentionally supplies fake tool binaries\n\n## Evidence\n\n- ./shifu check\n- nested Shifu cache contract tests: 47/47\n- commit hook staged gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Corrects qualification fixture isolation for nested Shifu execution without changing cache runtime behavior or contracts.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change is test-only and prevents a valid outer Shifu cache projection from polluting fixtures that intentionally construct their own PATH.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T07:27:17Z",
          "mergedAt": "2026-07-15T07:30:41Z",
          "additions": 12,
          "deletions": 3,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 937,
          "url": "https://github.com/kungfu-systems/kungfu/pull/937",
          "title": "fix(qualification): close hosted acceptance gaps",
          "body": "## Summary\n\n- preserve the host-owned short temporary root before release qualification redirects build temp into the repository\n- use that short root for the Windows native live-peer campaign and surface its bounded failure reason in hosted logs\n- calibrate the alpha qualification budget from 1800s to 2700s after the exact-source hosted run measured 1467s inside qualification\n- keep every existing native, artifact, Episode, signature, and upgrade gate enabled\n\n## Evidence\n\n- `./shifu exec node --test framework/core/tests/qualification/live-peer-continuity/run.test.mjs scripts/run-release-qualification.test.mjs` (21/21)\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source` (exit 0; build-free source gate passed)\n- staged DCO, docs, catalog, TypeScript, and Biome checks passed\n- hosted diagnosis: run 29394539339 reached all Linux gates before the 810s execution allowance rejected the passing path; Windows reached native live-peer qualification before its repository-scoped temp path failed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Fixes hosted execution of existing release qualification contracts without changing an architecture decision.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes qualification workspace selection and an evidence-backed time budget; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Source acceptance is green\n- [x] No credentials or generated qualification evidence are committed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T07:44:26Z",
          "mergedAt": "2026-07-15T07:49:03Z",
          "additions": 83,
          "deletions": 11,
          "changedFiles": 7
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 938,
          "url": "https://github.com/kungfu-systems/kungfu/pull/938",
          "title": "fix(core): close cross-platform architecture acceptance gaps",
          "body": "## Summary\n\nClose the final Core architecture acceptance gaps discovered while qualifying the remediated target boundaries on macOS, Linux, and Windows at the same code SHA.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- preserve explicit Cargo, Conan, CMake, and Ninja path overrides across nested Shifu cache/apply invocations\n- distinguish Windows mmap resize failures with actionable operating-system diagnostics\n- keep journal test page-size inputs in megabytes instead of accidentally requesting multi-terabyte sparse mappings\n- make Node storage binding parity tests portable across Windows environment and Python command-line semantics\n- tolerate process-cached RocksDB test locks only at the cleanup boundary they actually affect\n- release temporary storage providers before sync-verification cleanup without weakening process-lived runtime caches\n- project the completed cross-platform qualification into ADR-0049\n\n## Verification\n\nQualified code SHA: `0803574a7e68c715ad856550df0d386c8cac3f89`\n\n- macOS Apple Clang: Core build; CTest 12/12; Node binding 13/13\n- agent-120 Linux GNU: Core build; CTest 12/12; Node binding 13/13\n- DARKHERO Windows MSVC: Core build; CTest 12/12; Node binding 13/13\n- `./shifu check`\n- `./shifu check:source`\n- architecture layer checker and self-test (14 fixtures)\n- first-party target ownership projection (208 C/C++ sources, single ownership)\n- navigation route, storage source budget, docs, and ADR structural audits\n- ADR-0066 production modules remain `hold`; no production module was enabled\n\n## Failure modes prevented\n\n- nested cache layers silently reverting explicit tool paths to deleted temporary overlays\n- POSIX sparse mappings hiding a megabytes-versus-bytes test contract error that fails on Windows\n- Windows Python inline-command parsing and environment lookup diverging from POSIX\n- deleting a verification directory while its temporary RocksDB provider still holds a live lock\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0049\"],\n  \"summary\": \"Qualify the remediated Core architecture boundaries on macOS, Linux, and Windows and fix only the portability and lifetime gaps exposed by exact-code-SHA acceptance.\",\n  \"verification\": [\"./shifu check\", \"three-platform Core build\", \"CTest 12/12 on each platform\", \"Node binding 13/13 on each platform\", \"14 architecture fixtures\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T08:02:09Z",
          "mergedAt": "2026-07-15T08:12:24Z",
          "additions": 127,
          "deletions": 30,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 939,
          "url": "https://github.com/kungfu-systems/kungfu/pull/939",
          "title": "feat(xinfa): add Atlas primitive contract",
          "body": "## Summary\n\n- establish xinfa.atlas/v1 and atlas_root as the immutable compiled context primitive\n- preserve xinfa.context-pack/v1 as a byte-identical, non-reinterpreted compatibility input\n- add Atlas-first compile, inspect, verify, diff, impact, schemas, golden and standalone qualification\n\n## Verification\n\n- ./shifu xinfa:check\n- ./shifu xinfa:standalone\n- ./shifu check:source\n\n<!-- kungfu-adr-release:v1\n{\"schema\":\"kungfu.adr-release-pr/v1\",\"kind\":\"dev-delivery\",\"intent\":\"implemented\",\"adrs\":[\"ADR-0095\"],\"summary\":\"Establish the immutable Xinfa Atlas primitive and non-reinterpreted Context Pack compatibility boundary\",\"verification\":[\"./shifu xinfa:check\",\"./shifu xinfa:standalone\",\"./shifu check:source\"]}\n-->",
          "author": "dongkeren",
          "createdAt": "2026-07-15T08:08:02Z",
          "mergedAt": "2026-07-15T08:17:52Z",
          "additions": 1629,
          "deletions": 16,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 108,
          "url": "https://github.com/kungfu-systems/kfd/pull/108",
          "title": "docs(kfd): define primitive discovery procedures",
          "body": "## Summary\n\n- define KFD-5 as the active human-agent primitive discovery procedure\n- define KFD-6 as a draft autonomous discovery procedure grounded in causal experience\n- publish schemas, usage pages, registry metadata, site projection, and KFD-1/2/3 self-proof updates\n\n## Verification\n\n- `node scripts/check.mjs`\n- `git diff --check`\n- `npm pack --dry-run --json`",
          "author": "dongkeren",
          "createdAt": "2026-07-15T08:21:10Z",
          "mergedAt": "2026-07-15T08:24:11Z",
          "additions": 1622,
          "deletions": 136,
          "changedFiles": 22
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 110,
          "url": "https://github.com/kungfu-systems/kfd/pull/110",
          "title": "chore(kfd): anchor alpha 23 version",
          "body": "## Summary\n- Anchor the KFD package release metadata at 1.0.0-alpha.23.\n- Regenerate KFD-1, KFD-2, and KFD-3 release evidence bound to the new package facts.\n\n## Validation\n- npm run check\n- git diff --check\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n- npx -y @kungfu-tech/buildchain@2 validate --cwd . --json\n\n## Package surface\n- KFD-5 and KFD-6 decision documents are included.\n- KFD-5 and KFD-6 schemas are included.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T08:39:59Z",
          "mergedAt": "2026-07-15T08:42:33Z",
          "additions": 32,
          "deletions": 32,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1272,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1272",
          "title": "fix(build): bind controller evidence to selected runtime",
          "body": "## Summary\n- Bind reusable-build controller plans to the channel-selected Buildchain runtime rather than the outer workflow shell.\n- Preserve the stable workflow shell as the implementation source while recording the selected runtime ref, SHA, and contract digest in evidence.\n- Regenerate the public Buildchain contract projection and add regression assertions for split shell/runtime identities.\n\n## Validation\n- node --test tests/build-surface.test.mjs\n- pnpm run check (620 tests passed)\n- git diff --check\n\n## Consumer proof\nThis fixes the false `controller receipt reference runtime SHA mismatch` observed by the KFD alpha promotion when `build.yml@v2` selected `v2-alpha`.\n\nFixes #1271",
          "author": "dongkeren",
          "createdAt": "2026-07-15T08:50:11Z",
          "mergedAt": "2026-07-15T08:52:16Z",
          "additions": 10,
          "deletions": 14,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1273,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1273",
          "title": "chore(release): promote v2.12 dev to alpha",
          "body": "## Summary\nPromote the selected-runtime controller evidence fix to the Buildchain v2.12 alpha channel.\n\n## Included\n- controller plans bind the channel-selected runtime ref, SHA, and contract digest\n- public contract projection updated\n- regression coverage for different workflow-shell and selected-runtime identities\n\n## Validation\n- pnpm run check (620 tests passed)\n- cross-platform libnode-shaped build fixture passed on PR #1272\n\n## Downstream proof\nAfter this promotion, rerun the blocked KFD alpha promotion: https://github.com/kungfu-systems/kfd/pull/111",
          "author": "dongkeren",
          "createdAt": "2026-07-15T08:52:36Z",
          "mergedAt": "2026-07-15T08:55:03Z",
          "additions": 10,
          "deletions": 14,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 940,
          "url": "https://github.com/kungfu-systems/kungfu/pull/940",
          "title": "diag(qualification): retain native peer failure details",
          "body": "## Summary\n\n- preserve fail-closed native peer continuity while reporting the exact peer PID set and return code\n- emit only a bounded 40-line / 16 KiB tail from the test-owned peer log when the native campaign fails\n- make the next hosted Windows failure actionable without retaining credentials or weakening any release claim\n\n## Evidence\n\n- `node --test framework/core/tests/qualification/live-peer-continuity/run.test.mjs` (8/8)\n- Python compile check with external pycache\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source` (exit 0; 325 source contracts, 76 runtime tests, 69 Desktop tests)\n- staged DCO, docs, catalog, TypeScript, Biome, Ruff format and Ruff lint checks passed\n- hosted diagnosis: exact-source run 29398665421 passed Windows packaging, NSIS, CLI smoke, 42/42 build verification and three 90-second fuzz legs, then failed the native cross-process restart assertion without retaining its peer child log\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Improves fail-closed hosted qualification diagnostics without changing architecture or release claims.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR prints only a bounded tail from a disposable qualification-owned peer log; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Source acceptance is green\n- [x] No credentials or generated qualification evidence are committed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T08:53:01Z",
          "mergedAt": "2026-07-15T08:55:39Z",
          "additions": 47,
          "deletions": 2,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 112,
          "url": "https://github.com/kungfu-systems/kfd/pull/112",
          "title": "fix(ci): align alpha shell with selected runtime",
          "body": "## Summary\n- Run the KFD build controller through the official `v2-alpha` Buildchain shell while KFD is an alpha canary.\n- Accept the newly published `v2.12.7-alpha.16` contract lock.\n- Regenerate KFD-1, KFD-2, and KFD-3 evidence bound to the workflow and lock facts.\n\n## Why\nGitHub loads reusable workflow structure from the declared workflow ref. The KFD alpha build selected the `v2-alpha` runtime but retained the stable `v2` shell, so the fixed selected-runtime controller plan was not loaded. This change aligns shell and selected runtime without advancing Buildchain stable.\n\n## Validation\n- npm run check\n- git diff --check\n- npx -y @kungfu-tech/buildchain@2.12.7-alpha.16 validate --cwd . --json\n- npm pack --dry-run --json --registry=https://registry.npmjs.org/\n\nRelated: kungfu-systems/buildchain#1271\nBuildchain fix: kungfu-systems/buildchain#1272",
          "author": "dongkeren",
          "createdAt": "2026-07-15T09:04:49Z",
          "mergedAt": "2026-07-15T09:07:32Z",
          "additions": 65,
          "deletions": 20,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 111,
          "url": "https://github.com/kungfu-systems/kfd/pull/111",
          "title": "release(kfd): promote alpha 23",
          "body": "## Summary\nPromote `dev/v1/v1.0` to `alpha/v1/v1.0` for `@kungfu-tech/kfd@1.0.0-alpha.23`.\n\n## Included\n- KFD-5: human-agent primitive discovery.\n- KFD-6 draft: autonomous episode-grounded discovery loop.\n- Alpha 23 anchored package and release evidence.\n\n## Validation\n- Buildchain Verify and Build gates run on this promotion PR.\n- After merge, the Buildchain promotion workflow publishes the npm alpha, GitHub Release, and release passport through trusted publishing.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T08:42:50Z",
          "mergedAt": "2026-07-15T09:11:08Z",
          "additions": 1834,
          "deletions": 185,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1274,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1274",
          "title": "fix(release): preserve promotion authority receipt",
          "body": "## Summary\n\n- record publication authority as passed when the promotion job succeeds, because that job is hard-gated on the authority reusable workflow\n- preserve the raw authority result on failed or skipped promotions\n- regenerate the public Buildchain contract and add a regression assertion\n\n## Evidence\n\nKFD release run `29403579067` successfully published `@kungfu-tech/kfd@1.0.0-alpha.23`, but the downstream receipt observed an empty reusable-job result and incorrectly marked `publication-authority` as missing.\n\n## Verification\n\n- `pnpm run check` (620 tests)\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T09:22:03Z",
          "mergedAt": "2026-07-15T09:24:21Z",
          "additions": 9,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1275,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1275",
          "title": "release(buildchain): promote alpha 17",
          "body": "## Summary\n\nPromote the Buildchain receipt correction to the `v2-alpha` channel so KFD can re-audit its already-published alpha release with a qualifying controller receipt.\n\n## Included change\n\n- preserve publication authority evidence when a hard-gated promotion succeeds\n\n## Verification\n\n- `pnpm run check` (620 tests)\n- Buildchain PR #1274 cross-platform matrix\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T09:24:45Z",
          "mergedAt": "2026-07-15T09:26:58Z",
          "additions": 9,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 113,
          "url": "https://github.com/kungfu-systems/kfd/pull/113",
          "title": "fix(ci): align alpha promotion runtime",
          "body": "## Summary\n\n- run the KFD alpha promotion controller through Buildchain `v2-alpha`, matching the alpha build shell and selected runtime\n- accept the Buildchain `2.12.7-alpha.17` contract lock\n- anchor the next KFD package as `1.0.0-alpha.24` and regenerate KFD-1/2/3 evidence\n\n## Context\n\nKFD `1.0.0-alpha.23` published successfully, but its post-publish controller receipt was evaluated by the stable reusable workflow shell and incorrectly lost the already-enforced publication-authority result. Buildchain alpha.17 fixes that receipt projection.\n\n## Verification\n\n- `npm run check`\n- Buildchain alpha.17 validate\n- npm pack dry-run: 52 files; KFD-5 and KFD-6 present\n- `git diff --check`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T09:42:24Z",
          "mergedAt": "2026-07-15T09:44:45Z",
          "additions": 44,
          "deletions": 44,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 114,
          "url": "https://github.com/kungfu-systems/kfd/pull/114",
          "title": "release(kfd): promote alpha 24",
          "body": "## Summary\n\nPromote KFD `1.0.0-alpha.24` through the fully aligned Buildchain alpha build and promotion chain.\n\n## Included\n\n- KFD-5 and draft KFD-6 package surfaces from alpha.23\n- Buildchain alpha.17 contract lock\n- alpha promotion shell aligned with `v2-alpha`\n\n## Verification\n\n- KFD checks pass\n- Buildchain build controller receipts qualify\n- npm pack dry-run contains 52 files including KFD-5 and KFD-6\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T09:45:31Z",
          "mergedAt": "2026-07-15T09:48:10Z",
          "additions": 44,
          "deletions": 44,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1277,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1277",
          "title": "fix(release): bind authority to resolved runtime SHA",
          "body": "## Summary\n\n- expose the controller-resolved Buildchain runtime SHA\n- pass the immutable SHA to sealed publication authority\n- preserve floating refs only at the caller/controller resolution boundary\n- add a regression guard and regenerate the public contract projection\n\n## Verification\n\n- `pnpm run check`\n- 620 tests passed\n- workflow lint passed\n- generated action bundles completed\n\nCloses #1276",
          "author": "dongkeren",
          "createdAt": "2026-07-15T09:55:20Z",
          "mergedAt": "2026-07-15T09:57:24Z",
          "additions": 24,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1278,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1278",
          "title": "release(buildchain): promote alpha 18",
          "body": "## Summary\n\nPromote the immutable publication-authority runtime binding to the `v2-alpha` channel.\n\n## Included change\n\n- resolve a floating Buildchain entry ref once in the controller plan\n- pass the resulting immutable runtime SHA into sealed publication authority\n- preserve the consumer contract-lock and floating-channel workflow\n\n## Verification\n\n- `pnpm run check` (620 tests)\n- Buildchain PR #1277 cross-platform matrix\n- KFD failed-run evidence: https://github.com/kungfu-systems/kfd/actions/runs/29405874062\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T09:57:50Z",
          "mergedAt": "2026-07-15T10:00:19Z",
          "additions": 24,
          "deletions": 4,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 943,
          "url": "https://github.com/kungfu-systems/kungfu/pull/943",
          "title": "fix(qualification): track Windows peer workload pid",
          "body": "## Summary\n\n- bind native Peer workload identity to the first self-reported ready marker\n- keep `Popen.pid` as launcher-liveness evidence because Windows Shifu/uv may retain a launcher process in front of Python\n- require the same marker PID across same-generation and generation-advance recovery without weakening the fail-closed process check\n\n## Evidence\n\n- hosted Windows run `29402850286`: launcher PID `7016`, stable Peer marker/log PID `4532`, launcher remained alive (`peer_return_code=None`)\n- `node --test framework/core/tests/qualification/live-peer-continuity/run.test.mjs` (9/9)\n- Python compile check with external pycache\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source` (325 source contracts, 76 runtime tests, 69 Desktop tests; all passed)\n- staged DCO, docs, catalog, Biome, Ruff format and Ruff lint checks passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Corrects a Windows qualification launcher/workload PID distinction without changing runtime architecture or product claims.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR corrects qualification identity evidence only; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Source acceptance is green\n- [x] No credentials or generated qualification evidence are committed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T09:58:40Z",
          "mergedAt": "2026-07-15T10:00:39Z",
          "additions": 27,
          "deletions": 5,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 941,
          "url": "https://github.com/kungfu-systems/kungfu/pull/941",
          "title": "refactor(core): split storage service responsibilities",
          "body": "## Summary\n\nSplit the remaining storage-service monolith into stable responsibility units while preserving the public storage API and runtime behavior.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- reduce `service.cpp` from 4,951 to 2,764 lines and tighten its architecture budget from 5,000 to 3,000\n- extract episode repair planning, fetch, validation, and non-destructive apply into `episode_repair.cpp`\n- extract typed journal queries and stable result rendering into `query_render.cpp`\n- extract JSON compatibility codecs, validation, and typed option parsing into `json_compat.cpp`\n- register each source in the internal target graph with independent responsibility tokens and line budgets\n\n## Verification\n\n- `./shifu build:core`\n- `ctest --test-dir framework/core/build --output-on-failure --parallel 12` (12/12)\n- `./shifu check:source`\n- `SHIFU_CACHE_ACTIVE=1 ./shifu check`\n- `./shifu exec node framework/core/architecture/check-layers.mjs`\n- `./shifu exec node framework/core/architecture/check-layers.mjs --self-test` (14 fixtures)\n- macOS AppleClang full Core build including native, Node, Python, Wasmtime, and Wasmer artifacts\n- Linux GCC 14.2 full Core build and CTest 12/12 at pre-rebase code-bearing SHA `229a61b4a`\n- Windows MSVC 19.51 full Core build and CTest 12/12 at pre-rebase code-bearing SHA `229a61b4a`\n- rebased code-bearing SHA `0b9a328a8` has identical `framework/core/src` and `framework/core/architecture` trees to `229a61b4a`; the intervening base change only updates live-peer-continuity qualification files\n- final candidate `f801a38c3` differs from `0b9a328a8` only in ADR metadata; docs gate passes against the PR base\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0049\"],\n  \"summary\": \"Decompose the Core storage service facade into enforceable internal responsibility units while preserving public storage contracts.\",\n  \"verification\": [\"source and architecture gates\", \"native storage contract tests\", \"same-SHA Core builds on macOS, Linux, and Windows\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T09:34:29Z",
          "mergedAt": "2026-07-15T10:10:44Z",
          "additions": 2314,
          "deletions": 2210,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 115,
          "url": "https://github.com/kungfu-systems/kfd/pull/115",
          "title": "chore(release): accept Buildchain alpha 18 contract",
          "body": "## Summary\n\n- accept the published `v2-alpha` runtime at `6f1b17fac1e0182d1afa6ea9cfe3578e7a5e532c`\n- refresh the KFD-1, KFD-2, and KFD-3 self-evidence projections\n- keep the unpublished KFD version anchored at `1.0.0-alpha.24`\n\n## Verification\n\n- `npm run check`\n- `npm pack --dry-run --json --registry=https://registry.npmjs.org/`\n- package contains 52 files, including `decisions/KFD-5.md` and `decisions/KFD-6.md`\n- `buildchain validate --require-version-state` with `@kungfu-tech/buildchain@2.12.7-alpha.18`\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T10:11:21Z",
          "mergedAt": "2026-07-15T10:13:31Z",
          "additions": 14,
          "deletions": 14,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 116,
          "url": "https://github.com/kungfu-systems/kfd/pull/116",
          "title": "release(kfd): promote alpha 24",
          "body": "## Summary\n\nPromote the unpublished KFD `1.0.0-alpha.24` candidate through the corrected Buildchain `v2-alpha` publication path.\n\n## Included changes\n\n- keep KFD-5 and KFD-6 in the package surface\n- use the Buildchain alpha promotion shell\n- accept Buildchain `2.12.7-alpha.18` at immutable runtime `6f1b17fac1e0182d1afa6ea9cfe3578e7a5e532c`\n- refresh KFD-1, KFD-2, and KFD-3 self-evidence\n\n## Verification\n\n- `npm run check`\n- `npm pack --dry-run --json --registry=https://registry.npmjs.org/`\n- Buildchain alpha.18 `validate --require-version-state`\n- Buildchain promotion run https://github.com/kungfu-systems/buildchain/actions/runs/29406644743\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T10:13:45Z",
          "mergedAt": "2026-07-15T10:17:17Z",
          "additions": 14,
          "deletions": 14,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 942,
          "url": "https://github.com/kungfu-systems/kungfu/pull/942",
          "title": "feat(kfx): add KFD-aware admission assessment",
          "body": "## Summary\n\nAdd a fail-closed native KFX admission assessment that consumes exact KFD lifecycle evidence and a pinned Buildchain verification result without creating a second trust evaluator.\n\n## Related issue\n\nAtlas goal `2026-07-15-kungfu-kfx-kfd-buildchain-admission`.\n\n## Changes\n\n- add the read-only Core `assess` operation with schema-closed trust inputs, policy, lifecycle checks, deterministic report/plan roots, and explicit operation/capability decisions\n- require a fresh purpose-bound ADR-0052 assessment whose report hash and query/contract/policy/fact roots bind the KFX qualification result\n- validate exact Buildchain verifier identity, contract, package/source/dependency/build-plan/toolchain/artifact/qualification roots, issuer/publisher allowlists, expiry, and revocation\n- expose one transport-only Storage projection through Python CLI, Python API, Node API, and KFX TypeScript types for GUI, TUI, KFX, and Agent consumers\n- add positive, downgrade, mismatch, revocation, cache-invalidation, capability-expansion, migration, and Product System fixtures plus a dedicated Shifu task\n- re-render the KFD-1/KFD-3 derived evidence after synchronizing the latest development base\n- correct the latest-base nested cache fixture so an explicit PATH override is checked against the effective original tool path instead of an inherited stale value\n- document the remaining producer boundary: Core validates a supplied pinned verifier result but does not yet execute or authenticate the Buildchain verifier\n\n## Verification\n\n- `./shifu rebuild:core`\n- `./shifu test:native-kfx-admission` (Core 1/1, Python 5/5, API transport 1/1, API/KFX type contracts)\n- `./shifu check:source` (325 Node tests, 76 runtime-upgrade tests, 69 desktop tests; source gate passed)\n- `./shifu check` (changed-scope gate passed; SDK contract audit 31/31)\n- Shifu cache contract group 47/47 after latest-base synchronization\n- staged DCO, documentation, C++, Python, and Biome checks passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0090\"],\n  \"summary\": \"Add a deterministic fail-closed KFX admission assessment over exact KFD lifecycle evidence and pinned Buildchain verification inputs while preserving the producer boundary.\",\n  \"verification\": [\"./shifu rebuild:core\", \"./shifu test:native-kfx-admission\", \"./shifu check:source\", \"./shifu check\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe change consumes provenance and qualification evidence but does not publish, sign, deploy, install, activate, or mutate packages. Invalid, stale, mismatched, revoked, or unsupported evidence fails closed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T09:54:37Z",
          "mergedAt": "2026-07-15T10:24:50Z",
          "additions": 1258,
          "deletions": 46,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 946,
          "url": "https://github.com/kungfu-systems/kungfu/pull/946",
          "title": "feat(xinfa): compile bounded task projections",
          "body": "## Summary\n\nCompile bounded Human View, Task Chart/Agent Context, and GUI View projections from one verified Xinfa Atlas without creating a second authority.\n\n## Related issue\n\nAtlas goal `2026-07-15-xinfa-task-capsule-compiler`.\n\n## Changes\n\n- add deterministic bounded-hop Human/GUI projections and bounded-token Task Chart compilation\n- preserve Atlas root, cut, route status, evidence, omissions, and source-root parity across surfaces\n- add stable cut-preserving expansion handles and fail-closed projection verification\n- exclude `.xinfa/generated/**` from provider authority and document explicit successor-cut acceptance\n- add schemas, four-task golden qualification, standalone extraction coverage, and ADR-0096\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu xinfa:check`\n- `./shifu xinfa:standalone`\n- `./shifu docs:check:readonly`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0096\"],\n  \"summary\": \"Bounded projection compiler, Task Chart contract, expansion boundary, generated-output exclusion, and qualification are implemented for the Xinfa incubation slice\",\n  \"verification\": [\"./shifu check:source\", \"./shifu xinfa:check\", \"./shifu xinfa:standalone\", \"./shifu docs:check:readonly\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T10:20:04Z",
          "mergedAt": "2026-07-15T10:29:02Z",
          "additions": 2127,
          "deletions": 20,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1280,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1280",
          "title": "fix(release): admit managed consumer candidates",
          "body": "## Summary\n\n- generalize exact release-candidate admission assembly from Buildchain self-publication to explicitly opted-in managed consumers\n- require caller-owned RC evidence, a repository-local publisher workflow, matching npm package/target identity, and an explicit Gate aggregate or no-Gate decision\n- audit the caller control plane while binding the exact canonical Buildchain authority runtime\n- document the declarative consumer surface and regenerate the public site contract\n\n## Verification\n\n- `pnpm run check` (`620/620` tests, workflow lint, site contract, all action bundles)\n- `node --test tests/build-surface.test.mjs` (`78/78`)\n- `git diff --check`\n\nCloses #1279\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T10:28:52Z",
          "mergedAt": "2026-07-15T10:31:06Z",
          "additions": 153,
          "deletions": 67,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1281,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1281",
          "title": "release(buildchain): promote alpha 19",
          "body": "## Release intent\n\nPromote the managed-consumer sealed release-candidate admission capability to the Buildchain alpha channel.\n\n## Included\n\n- #1280 / #1279: fail-closed declarative admission for managed consumers\n- exact caller RC evidence and control-plane audit binding\n- explicit Gate aggregate or consumer no-Gate decision\n\n## Verification\n\n- dev Verify run 29408404929 passed\n- PR #1280 full check and Linux/Windows/macOS fixture matrix passed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T10:32:26Z",
          "mergedAt": "2026-07-15T10:35:03Z",
          "additions": 153,
          "deletions": 67,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 117,
          "url": "https://github.com/kungfu-systems/kfd/pull/117",
          "title": "fix(release): adopt sealed Buildchain admission",
          "body": "## Summary\n\n- adopt Buildchain 2.12.7-alpha.19 through the v2-alpha contract lock\n- opt the KFD publisher workflow into managed-consumer sealed publication admission\n- refresh KFD-1/2/3 evidence against the accepted Buildchain runtime\n\n## Evidence\n\n- `npm run check`\n- `npm pack --dry-run --json`\n- `npm exec --package=@kungfu-tech/buildchain@2.12.7-alpha.19 -- buildchain validate --require-version-state`\n\nCloses the KFD release gap exposed by failed run 29407619802.\n\nBuildchain implementation: kungfu-systems/buildchain#1280\nBuildchain issue: kungfu-systems/buildchain#1279",
          "author": "dongkeren",
          "createdAt": "2026-07-15T10:48:04Z",
          "mergedAt": "2026-07-15T10:50:24Z",
          "additions": 24,
          "deletions": 18,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 947,
          "url": "https://github.com/kungfu-systems/kungfu/pull/947",
          "title": "fix(cache): unwrap nested uv projections",
          "body": "## Summary\n\n- preserve the first unwrapped UV PATH across nested Shifu cache projections\n- prevent release layer Gates from treating the outer managed wrapper as the real uv\n- cover the nested-wrapper path with a cross-platform regression fixture\n\n## Verification\n\n- `node --test scripts/shifu-uv-cache-adapter.test.mjs scripts/run-layer-artifact-gate.test.mjs`\n- exact nested `gate run layers.format layers.sdk layers.surfaces` no longer reports a missing UV adapter manifest\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Corrects nested UV cache wrapper discovery without changing architecture, release claims, or product behavior.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR changes qualification cache plumbing only; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Source acceptance is green\n- [x] No credentials or generated qualification evidence are committed\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T10:42:59Z",
          "mergedAt": "2026-07-15T10:50:25Z",
          "additions": 26,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 118,
          "url": "https://github.com/kungfu-systems/kfd/pull/118",
          "title": "release(kfd): promote alpha 24",
          "body": "## Release\n\nPromote KFD `1.0.0-alpha.24` from the active dev line to the active alpha line.\n\nThis promotion includes managed-consumer sealed Buildchain publication admission through `@kungfu-tech/buildchain@2.12.7-alpha.19`.\n\n## Expected publication\n\n- npm: `@kungfu-tech/kfd@1.0.0-alpha.24`\n- GitHub Release: `v1.0.0-alpha.24`\n- release passport and KFD-1/2/3 evidence\n- downstream release propagation",
          "author": "dongkeren",
          "createdAt": "2026-07-15T10:51:06Z",
          "mergedAt": "2026-07-15T10:56:25Z",
          "additions": 24,
          "deletions": 18,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1283,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1283",
          "title": "fix(release): preserve publication check context",
          "body": "## Summary\n\n- forward the exact protected-branch status check into sealed publication authority\n- add a regression assertion scoped to the publication-authority job\n- refresh the generated site contract\n\n## Verification\n\n- `node --test tests/build-surface.test.mjs` (78/78)\n- `pnpm run check` (620/620 plus workflow/site/action checks)\n\nCloses #1282.\n\nExposed by KFD promotion run: https://github.com/kungfu-systems/kfd/actions/runs/29409897208",
          "author": "dongkeren",
          "createdAt": "2026-07-15T11:06:00Z",
          "mergedAt": "2026-07-15T11:07:59Z",
          "additions": 9,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 948,
          "url": "https://github.com/kungfu-systems/kungfu/pull/948",
          "title": "fix(qualification): launch Windows Shifu suites via ComSpec",
          "body": "## Summary\n\n- launch runtime-activation Shifu suites through ComSpec on Windows\n- bind execution to the repository-local absolute `shifu.cmd` path\n- retain spawn failures in checksummed raw qualification logs\n\n## Validation\n\n- `node --test framework/core/tests/qualification/runtime-activation/run.test.mjs`\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Restores the existing Windows runtime-activation qualification launcher without changing runtime architecture or product claims.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR repairs qualification execution and retained diagnostics only; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Source acceptance is green locally\n- [x] No credentials or generated qualification evidence are committed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T11:03:21Z",
          "mergedAt": "2026-07-15T11:08:59Z",
          "additions": 47,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1284,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1284",
          "title": "release(buildchain): promote alpha 20",
          "body": "## Release\n\nPromote the next Buildchain v2.12 alpha containing exact protected-branch status-check propagation into sealed publication authority.\n\nFixes #1282 and unblocks KFD `1.0.0-alpha.24` publication.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T11:09:26Z",
          "mergedAt": "2026-07-15T11:11:43Z",
          "additions": 9,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 119,
          "url": "https://github.com/kungfu-systems/kfd/pull/119",
          "title": "fix(release): accept Buildchain alpha 20",
          "body": "## Summary\n\n- accept the exact Buildchain v2 alpha.20 runtime contract\n- preserve all 24 managed surface breaking digests\n- refresh KFD-1, KFD-2, and KFD-3 witnesses\n\n## Verification\n\n- `npm run check`\n- `npm exec --yes --package=@kungfu-tech/buildchain@2.12.7-alpha.20 -- buildchain validate --require-version-state`\n- `npm pack --dry-run --json`\n\nCloses the KFD-side follow-up to kungfu-systems/buildchain#1282 and kungfu-systems/buildchain#1283.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T11:21:07Z",
          "mergedAt": "2026-07-15T11:23:21Z",
          "additions": 14,
          "deletions": 14,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 120,
          "url": "https://github.com/kungfu-systems/kfd/pull/120",
          "title": "release(kfd): retry alpha 24",
          "body": "## Summary\n\nPromote the verified KFD dev line to alpha and retry the managed publication of `1.0.0-alpha.24`.\n\nThe previous publication stopped before npm/GitHub Release because the sealed authority received the wrong required check context. Buildchain `2.12.7-alpha.20` now preserves KFD's exact `check / check` context, and KFD has accepted that runtime contract.\n\n## Evidence\n\n- KFD dev verification: https://github.com/kungfu-systems/kfd/actions/runs/29411455687\n- Buildchain fix: https://github.com/kungfu-systems/buildchain/pull/1283\n- KFD contract acceptance: https://github.com/kungfu-systems/kfd/pull/119",
          "author": "dongkeren",
          "createdAt": "2026-07-15T11:24:02Z",
          "mergedAt": "2026-07-15T11:26:18Z",
          "additions": 14,
          "deletions": 14,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 950,
          "url": "https://github.com/kungfu-systems/kungfu/pull/950",
          "title": "feat(xinfa): add Shifu Kungfu dogfood path",
          "body": "## Summary\n\nAdd a bounded Xinfa self-dogfood path through Shifu and a read-only Kungfu projection consumer. The adapters delegate compiler and projection authority to the public Xinfa CLI.\n\n## Related issue\n\nAtlas goal 2026-07-15-xinfa-shifu-kungfu-dogfood.\n\n## Changes\n\n- Add a thin Shifu Documentation Protocol adapter for Xinfa Atlas compile and verify.\n- Add Human, Agent, and GUI materialization through one verified Atlas root.\n- Retain a fault campaign covering implementation drift, non-claim drift, feedback exclusion, and successor-only acceptance.\n\n## Verification\n\n- ./shifu xinfa:dogfood\n- ./shifu xinfa:check\n- ./shifu xinfa:standalone\n- ./shifu check:source\n- ./shifu docs:check:readonly\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0096\"],\n  \"summary\": \"Add the retained Shifu and Kungfu dogfood qualification path for the implemented Xinfa projection boundary.\",\n  \"verification\": [\"xinfa/qualification/shifu-kungfu-dogfood-v1.json\", \"./shifu check:source\", \"./shifu docs:check:readonly\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe retained receipt is explicitly non-qualifying and selfCertified=false; it does not create a release claim.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T11:30:49Z",
          "mergedAt": "2026-07-15T11:36:41Z",
          "additions": 1389,
          "deletions": 1,
          "changedFiles": 16
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 951,
          "url": "https://github.com/kungfu-systems/kungfu/pull/951",
          "title": "feat(core): define bounded build capability authority",
          "body": "## Summary\n\nEstablish a single machine-readable authority for bounded Kungfu Core build profiles and replace umbrella dependency propagation with target-scoped dependencies. The default full product remains the only qualified profile at this stage; planned profiles fail closed until their dedicated qualification stages land.\n\n## Related issue\n\nAtlas goal 2026-07-15-kungfu-core-build-capability-authority\n\n## Changes\n\n- define components, providers, projections, bindings, profiles, requirements, conflicts, defaults, and build identity in one authority\n- generate and drift-check CMake, human-readable, and manifest projections\n- thread the selected profile consistently through Shifu, Conan, and CMake\n- remove unconditional CONAN_LIBS usage in favor of generated target-local dependency sets\n- add positive and negative source-gate fixtures\n\n## Verification\n\n- ./shifu check:source\n- ./shifu rebuild:core on macOS arm64\n- KUNGFU_BUILD_PROFILE=journal ./shifu config fails closed with the intended unqualified-profile diagnostic\n- agent-120 Linux x86_64 full-profile build qualification\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0066\"],\n  \"summary\": \"Establish the bounded Core build-profile authority and replace umbrella dependency propagation with profile-scoped target dependencies while retaining full as the only supported default.\",\n  \"verification\": [\"./shifu check:source\", \"./shifu rebuild:core on macOS arm64\", \"negative planned-profile configure fixture\", \"agent-120 Linux x86_64 full-profile build\"]\n}\n-->\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe generated profile manifest adds deterministic build identity and source-gate evidence; no publication or deployment action is performed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T11:35:49Z",
          "mergedAt": "2026-07-15T11:44:16Z",
          "additions": 1022,
          "deletions": 41,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 952,
          "url": "https://github.com/kungfu-systems/kungfu/pull/952",
          "title": "fix(qualification): invoke Windows Shifu shim directly",
          "body": "## Summary\n\n- invoke Windows runtime-activation suites through ComSpec with the repository welded shim token left unquoted\n- quote only suite arguments and reject cmd expansion syntax\n- preserve spawn failures in checksummed raw qualification logs\n\n## Validation\n\n- `./shifu exec node --test framework/core/tests/qualification/runtime-activation/run.test.mjs` (9/9)\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source` (329 Node, 76 runtime upgrade, 69 desktop update; TypeScript and Biome passed)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Restores the existing Windows runtime-activation qualification launcher without changing runtime architecture or product claims.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR repairs qualification execution and retained diagnostics only; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Source acceptance is green locally\n- [x] No credentials or generated qualification evidence are committed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T12:04:02Z",
          "mergedAt": "2026-07-15T12:06:22Z",
          "additions": 22,
          "deletions": 13,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 122,
          "url": "https://github.com/kungfu-systems/kfd/pull/122",
          "title": "feat(kfd): add boundary-pressure discovery gates",
          "body": "## Summary\n- add an optional boundary-pressure diagnostic to active KFD-5 without redefining primitive sufficiency\n- require a falsifiable boundary hypothesis in draft KFD-6 autonomous discovery interface v2\n- refresh package metadata, site bundle, KFD-1/2/3 witnesses, and alpha.25 release facts\n\n## Compatibility\n- KFD-5 primitive-discovery schema remains v1 and backward compatible\n- KFD-6 draft experiment schema advances from v1 to v2 because `boundaryHypothesis` is required\n- the anchored outer KFD package line remains v1.0\n\n## Verification\n- `npm run check`\n- `buildchain validate --require-version-state` with Buildchain 2.12.7-alpha.20\n- AJV draft-2020 schema compilation for KFD-5 and KFD-6\n- `npm pack --dry-run --json`",
          "author": "dongkeren",
          "createdAt": "2026-07-15T12:11:32Z",
          "mergedAt": "2026-07-15T12:14:18Z",
          "additions": 431,
          "deletions": 214,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kfd",
          "number": 123,
          "url": "https://github.com/kungfu-systems/kfd/pull/123",
          "title": "release(kfd): publish alpha 25",
          "body": "## Release\nPromote the exact `dev/v1/v1.0` state to `alpha/v1/v1.0`.\n\nPublishes `@kungfu-tech/kfd@1.0.0-alpha.25` with:\n- KFD-5 optional boundary-pressure diagnostic\n- KFD-6 autonomous-discovery experiment interface v2 with required boundary hypothesis\n- refreshed KFD-1/2/3 witnesses and site bundle\n\nThe package line remains anchored at v1.0. The KFD-6 interface migration is explicitly declared as a major surface impact.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T12:15:02Z",
          "mergedAt": "2026-07-15T12:17:29Z",
          "additions": 431,
          "deletions": 214,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1286,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1286",
          "title": "fix(checkout): isolate locked source fetch config",
          "body": "## Summary\n\nMake locked source fetches independent from mutable runner-global Git configuration. This prevents concurrent jobs from redirecting the same repository URL to another single-SHA bundle while preserving command-scoped authentication and an explicit safe.directory exception.\n\n## Related issue\n\nNone.\n\n## Changes\n\n- ignore account-level and system Git config for every locked network fetch\n- inject the locked checkout path as command-scoped safe.directory configuration\n- preserve any command-scoped GitHub authentication configuration\n- add an end-to-end stale URL rewrite regression and focused environment assertions\n\n## Verification\n\n- `node --test tests/locked-source-checkout.test.mjs` (15 passed)\n- `pnpm run check` (622 unit tests passed; workflow checks and action builds passed)\n- `git diff --check`\n- Git for Windows read-only probe confirmed `GIT_CONFIG_GLOBAL=NUL` is accepted\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [x] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: the fetch environment may carry a command-scoped GitHub authorization header. The implementation preserves that entry without reading, logging, or persisting its value; the regression uses a redacted fixture value.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (behavior is covered by inline rationale and regression tests; no public interface changed)",
          "author": "dongkeren",
          "createdAt": "2026-07-15T12:17:11Z",
          "mergedAt": "2026-07-15T12:19:57Z",
          "additions": 125,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1287,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1287",
          "title": "release(buildchain): promote alpha 21",
          "body": "## Release\n\nPromote the next Buildchain v2.12 alpha containing isolated locked source fetch configuration. This prevents concurrent runner-global single-SHA bundle rewrites from redirecting a consumer checkout while preserving command-scoped authentication and safe.directory.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T12:20:43Z",
          "mergedAt": "2026-07-15T12:23:23Z",
          "additions": 125,
          "deletions": 4,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 954,
          "url": "https://github.com/kungfu-systems/kungfu/pull/954",
          "title": "fix(qualification): separate manual signing policy",
          "body": "## Summary\n\n- keep the complete alpha/release Buildchain qualification fail-closed on native signing and notarization\n- let trusted manual frozen-ref runs exercise the same functional and artifact Gates without importing production signing credentials into ordinary build runners\n- record the selected native upgrade policy in the retained qualification summary\n- retain all existing live Peer, runtime activation, zero-burden desktop, layer Gate, report, and compressed raw-log stages in manual runs\n\n## Related issue\n\nNone.\n\n## Changes\n\n- add a fail-closed `--native-upgrade-policy required|skip` qualification option, defaulting to `required`\n- bind alpha/release pull requests to `required` and workflow dispatch to explicit `skip`\n- update the structured workflow binding and focused contract tests\n\n## Verification\n\n- `node --test scripts/run-release-qualification.test.mjs scripts/qualification-artifact-catalog.test.mjs` (15 passed)\n- `./shifu check:source` (build-free source gate passed)\n- staged repository gate passed during DCO commit\n- `git diff --check`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Separates credential-bearing native signing policy by workflow event without changing the runtime, release identity, or architecture contracts.\"\n}\n-->\n\n## Governance risk check\n\n- [x] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nBoundary: production signing and notarization remain mandatory only in the protected alpha/release PR gate. Manual validation records an explicit skip and never receives or handles signing credentials. No credentials, private logs, or generated qualification evidence are committed.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n- [x] Source acceptance is green\n- [x] No credentials or generated qualification evidence are committed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T12:21:44Z",
          "mergedAt": "2026-07-15T12:23:57Z",
          "additions": 98,
          "deletions": 13,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 956,
          "url": "https://github.com/kungfu-systems/kungfu/pull/956",
          "title": "fix(qualification): budget complete hosted alpha gate",
          "body": "## Summary\n\n- raise the hosted alpha budget to cover the complete measured install, build, and qualification lifecycle\n- retain every gate, fuzz target, and Episode workload while reserving explicit upstream and variance allowances\n- bind the alpha budget contract in tests and record the exact hosted timing evidence\n\n## Validation\n\n- `./shifu exec node --test scripts/run-release-qualification.test.mjs scripts/check-kungfu-gate-catalog.test.mjs` (30/30)\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source` (329 Node, 76 runtime upgrade, 69 desktop update; TypeScript and Biome passed)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Calibrates the existing hosted alpha qualification budget from exact run evidence without changing architecture, gate workload, or product claims.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR adjusts qualification timing policy only; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Source acceptance is green locally\n- [x] No credentials or generated qualification evidence are committed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T12:42:50Z",
          "mergedAt": "2026-07-15T12:45:09Z",
          "additions": 37,
          "deletions": 12,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 82,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/82",
          "title": "feat(site): refresh KFD and paper bundles",
          "body": "## Summary\n\n- refresh the rendered KFD source to `@kungfu-tech/kfd@1.0.0-alpha.24`\n- refresh all three paper publication packages to their latest alpha bundles\n- regenerate lockfile inputs and Buildchain README badges for KFD-5 and KFD-6\n\n## Verification\n\n- `pnpm run build`\n- `pnpm run check`\n- local desktop and 390x844 mobile browser checks for KFD and papers surfaces\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T11:51:54Z",
          "mergedAt": "2026-07-15T12:46:00Z",
          "additions": 39,
          "deletions": 37,
          "changedFiles": 9
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 85,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/85",
          "title": "Release production from f8c09c09edc5",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `f8c09c09edc54abaca9f49f01adaf130d4e64f44`\n- Artifact hash: `45484e579d912474aca6f15ccf5a9b4abcee6ae6f9469d16423f20b3262c8908`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29416487352)\n- Required label: `buildchain-release`\n- Release branch: `release/production-f8c09c09edc5`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-15T12:53:35Z",
          "mergedAt": "2026-07-15T13:00:48Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1288,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1288",
          "title": "fix(checkout): support dumb HTTP cache mirrors",
          "body": "## Summary\n\nAllow locked source checkout to use static dumb HTTP Git mirrors without weakening the bounded GitHub fallback policy. Cache fetches first attempt the existing shallow fetch and retry without `--depth` only for Git's explicit dumb-HTTP capability error.\n\n## Related issue\n\nFollow-up to the multi-platform Kungfu qualification checkout diagnostics.\n\n## Changes\n\n- retry cache-mirror fetches without depth only when dumb HTTP rejects shallow capability negotiation\n- keep GitHub fallback fetches shallow and bounded\n- record the selected cache fetch mode in checkout evidence\n- cover the capability-specific fallback with a regression test\n\n## Verification\n\n- `pnpm run check` (624 tests passed; workflow checks and action builds passed)\n- focused locked source checkout tests (16 passed)\n- `git diff --check`\n- live `BUILDCHAIN_CHECKOUT_CACHE_MODE=require` checkout against the central HTTP mirror resolved the exact locked commit in 4.9 seconds with `transport=mirror-url`, `fetchMode=full`, `fallbackUsed=false`, and `githubFetchAttempts=0`\n\n## Governance risk check\n\nDoes this PR touch any of these boundaries?\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe checkout evidence gains an explicit `fetchMode`; exact commit/tree verification remains fail-closed and is covered by both the full test suite and a live exact-ref mirror checkout.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed (not needed; internal transport compatibility and evidence field only)\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T12:59:29Z",
          "mergedAt": "2026-07-15T13:01:56Z",
          "additions": 59,
          "deletions": 13,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1289,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1289",
          "title": "release(buildchain): promote alpha 22",
          "body": "## Release\n\nPromote the next Buildchain v2.12 alpha containing dumb HTTP cache-mirror capability fallback. Locked source checkout remains exact-ref and fail-closed, retries without depth only for Git's explicit dumb-HTTP shallow-capability error, and keeps GitHub fallback shallow and bounded.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T13:02:25Z",
          "mergedAt": "2026-07-15T13:04:41Z",
          "additions": 59,
          "deletions": 13,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 958,
          "url": "https://github.com/kungfu-systems/kungfu/pull/958",
          "title": "docs(adr): define Project Cut spacetime boundary",
          "body": "## Summary\n\nDefine the authority, identity, publication, and compatibility boundary for Project Cut without introducing a fourth primitive or a Git commit hash cycle.\n\n## Changes\n\n- Add ADR-0097 with the Git/Xinfa/Kungfu authority matrix and one-way dependency DAG.\n- Separate provider-native Episode roots from qualified cross-provider semantic equivalence.\n- Register the pre-release project-cut-protocol surface and route it from the documentation map.\n\n## Verification\n\n- ./shifu docs:check\n- ./shifu docs:prose:required\n- ./shifu check:source\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0097\"],\n  \"summary\": \"Freeze Project Cut authority, identity, cycle prevention, history, compatibility, and recovery constraints before schema implementation\",\n  \"verification\": [\"./shifu docs:check\", \"./shifu docs:prose:required\", \"./shifu check:source\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T13:04:53Z",
          "mergedAt": "2026-07-15T13:10:59Z",
          "additions": 279,
          "deletions": 1,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 87,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/87",
          "title": "fix(site): derive surface channel from Buildchain",
          "body": "## Summary\n- stop deriving the site surface channel from GitHub event shape\n- consume the channel selected by the Buildchain web-surface release-intent gate\n- prevent release PR merges from rendering staging hosts into production artifacts\n\n## Verification\n- preview build/check: `pr-local.preview.libkungfu.dev`\n- staging build/check: `staging.libkungfu.dev`\n- production build/check: `libkungfu.dev`\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-15T13:06:45Z",
          "mergedAt": "2026-07-15T13:16:15Z",
          "additions": 0,
          "deletions": 2,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/site-libkungfu-dev",
          "number": 90,
          "url": "https://github.com/kungfu-systems/site-libkungfu-dev/pull/90",
          "title": "Release production from 8a835f62c2e7",
          "body": "<!-- buildchain:web-surface-production-release-pr -->\n## Buildchain production release intent\n\nStaging has been deployed from the current main commit. Review the staging URLs,\nthen merge this PR to approve production. Buildchain will only publish\nproduction after it verifies that the merged PR is a same-repository release PR\nwith the required label.\n\n### Staging URLs\n\n- hub: https://staging.libkungfu.dev\n- core: https://core.staging.libkungfu.dev\n- buildchain: https://buildchain.staging.libkungfu.dev\n- kfd: https://kfd.staging.libkungfu.dev\n- papers: https://papers.staging.libkungfu.dev\n\n### Release Evidence\n\n- Source SHA: `8a835f62c2e7e47e5fec527f6d30c44a5b24b00e`\n- Artifact hash: `ef685b2fce018bec0c7252ab71b851535d8403e94ef38938f26145246cf7a72a`\n- Staging release passport: [buildchain-web-surface-staging-release-passport](https://github.com/kungfu-systems/site-libkungfu-dev/actions/runs/29418490756)\n- Required label: `buildchain-release`\n- Release branch: `release/production-8a835f62c2e7`\n\nThis PR intentionally contains one empty release-intent commit.",
          "author": "app/kungfu-systems-release-bot",
          "createdAt": "2026-07-15T13:24:24Z",
          "mergedAt": "2026-07-15T13:32:01Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1290,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1290",
          "title": "Release v2.12.7 from qualified v2.12.7-alpha.22",
          "body": "Buildchain qualified-alpha stable promotion.\n\n- Candidate: `v2.12.7-alpha.22`\n- Candidate SHA: `40f808101be476b2f60611395b13c6e4520cb386`\n- Selection: `human-release-now`\n- Ledger ref: `buildchain/candidate-ledger/v2/v2.12`\n\nThe source-lock branch freezes the exact candidate; newer alpha publications do not alter this PR.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T13:45:16Z",
          "mergedAt": "2026-07-15T13:48:51Z",
          "additions": 8145,
          "deletions": 407,
          "changedFiles": 73
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 960,
          "url": "https://github.com/kungfu-systems/kungfu/pull/960",
          "title": "fix(qualification): return from Windows Shifu shim",
          "body": "## Summary\n\n- invoke the welded Windows Shifu batch shim with `call` so nested qualification commands return to the Node harness\n- retain the unquoted shim token and argument quoting/expansion rejection from the prior Windows launcher fix\n- cover the exact `call shifu.cmd ...` payload in the launcher contract test\n\n## Hosted evidence\n\n- exact-source run `29416494142` passed build, product packaging, 42/42 base verify, three 90-second fuzz targets, and live-peer/native restart on Windows\n- the first runtime-activation suite then stopped at `Terminate batch job (Y/N)?`, proving the batch-return boundary was the remaining failure\n\n## Validation\n\n- `./shifu exec node --test framework/core/tests/qualification/runtime-activation/run.test.mjs` (9/9)\n- `SHIFU_CACHE_BYPASS=source-acceptance ./shifu check:source` (329 Node, 76 runtime upgrade, 69 desktop update; TypeScript and Biome passed)\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repairs nested Windows batch return semantics in the existing qualification launcher without changing runtime architecture or product claims.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR repairs qualification execution only; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Source acceptance is green locally\n- [x] No credentials or generated qualification evidence are committed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T13:47:13Z",
          "mergedAt": "2026-07-15T13:49:01Z",
          "additions": 10,
          "deletions": 2,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1291,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1291",
          "title": "fix(evidence): omit stale reasons from qualifying receipts",
          "body": "## Summary\n\n- omit non-authorizing failure reasons from qualifying controller receipts\n- preserve reasons for failed, skipped, partial, or otherwise non-qualifying receipts\n- refresh the generated Node API and Buildchain contract digests\n\n## Evidence\n\nStable promotion run 29420873419 completed successfully, but its qualifying receipt retained `promotion-incomplete` because the workflow expression treated an empty success value as false. This core invariant prevents that contradictory evidence across all controller adapters.\n\n## Validation\n\n- `node --test tests/controller-evidence.test.mjs` (11 passed)\n- `pnpm run check` (624 unit tests passed; generated site and action builds passed)\n- `git diff --check`\n\nGenerated-by: Codex",
          "author": "dongkeren",
          "createdAt": "2026-07-15T13:57:57Z",
          "mergedAt": "2026-07-15T14:00:42Z",
          "additions": 8,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1292,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1292",
          "title": "release(buildchain): promote v2.12.8-alpha.0",
          "body": "## Release\n\nPromote the next Buildchain v2.12 alpha containing the controller receipt invariant from #1291. Qualifying receipts now omit stale non-authorizing failure reasons while failed, skipped, partial, and otherwise non-qualifying receipts preserve their diagnostics.\n\nThe stable v2.12.7 publication remains unchanged; this alpha is the forward-fix evidence for subsequent promotions.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T14:03:33Z",
          "mergedAt": "2026-07-15T14:05:44Z",
          "additions": 8,
          "deletions": 5,
          "changedFiles": 4
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 962,
          "url": "https://github.com/kungfu-systems/kungfu/pull/962",
          "title": "feat(project-cut): define canonical v1 contract",
          "body": "## Summary\n\nDefine and implement the build-free project.cut/v1 schema, canonical root, source projection policy, receipts, and stable failure diagnostics.\n\n## Changes\n\n- Add a closed Project Cut root input with a Project Cut-specific canonical JSON algorithm and explicit no-newline framing.\n- Add source projection and policy schemas, exact exclusions, golden roots, and 12 negative fixtures.\n- Separate semantic, serialization, artifact, and receipt identities; exclude publication coordinates and unknown fields from the semantic preimage.\n- Wire the contract and unit tests into the source acceptance gate and register ADR-0098.\n\n## Verification\n\n- node scripts/check-project-cut-contract.mjs\n- node --test scripts/check-project-cut-contract.test.mjs scripts/source-acceptance.test.mjs\n- node scripts/run-docs-check.mjs\n- node scripts/run-docs-prose-check.mjs --required\n- pinned Biome check over every changed JS and JSON file\n- ./shifu check:source: Project Cut, schema, documentation, and new tests passed; the local aggregate reported two unrelated dependency-worktree environment failures, so hosted CI is authoritative\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0098\"],\n  \"summary\": \"Freeze and implement the build-free Project Cut v1 schema, canonical root, source projection policy, receipts, fixtures, and diagnostics\",\n  \"verification\": [\"./shifu docs:check\", \"./shifu docs:prose:required\", \"./shifu check:source\"]\n}\n-->\n\n## Governance risk check\n\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T14:08:33Z",
          "mergedAt": "2026-07-15T14:12:47Z",
          "additions": 2458,
          "deletions": 2,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 955,
          "url": "https://github.com/kungfu-systems/kungfu/pull/955",
          "title": "feat(core): qualify composable build profiles",
          "body": "## Summary\n\nQualify bounded composable Core profiles and make RocksDB, SQLite projection responsibilities, live KV, bindings, and embedded custom providers explicit build-time capabilities while preserving the full product.\n\n## Related issue\n\nAtlas goals `2026-07-15-kungfu-rocksdb-provider-kv-decoupling`, `2026-07-15-kungfu-sqlite-projection-optionalization`, `2026-07-15-kungfu-embedded-custom-provider-qualification`, and parent `2026-07-15-kungfu-composable-core-build-profiles`.\n\n## Changes\n\n- condition Conan and CMake dependency roots from one bounded profile authority\n- isolate public live KV from RocksDB types and fail explicit missing providers closed\n- express SQLite projection, state-cache, and query-acceleration responsibilities separately\n- qualify journal, embedded-minimal, embedded-sqlite, and unchanged full profiles\n- expose machine-readable build identity including live capability and build root\n- add an instance-local public custom-provider registry and standalone CMake consumer\n- add Apple Clang, GCC, and MSVC matrix coverage for full and embedded-minimal\n\n## Verification\n\n- `./shifu check:source`\n- `KUNGFU_BUILD_PROFILE=embedded-minimal ./shifu rebuild:core`\n- `KUNGFU_BUILD_PROFILE=embedded-sqlite ./shifu rebuild:core`\n- `KUNGFU_BUILD_PROFILE=full ./shifu rebuild:core`\n- embedded-minimal custom-provider and causal fact-ledger CTest: 4/4\n- standalone custom-provider consumer configure/build/run on Apple Clang\n- full native CTest: 13/13\n- embedded-sqlite native CTest rerun: 13/13\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0066\"],\n  \"summary\": \"Qualify bounded composable Core profiles with optional RocksDB and explicit SQLite responsibility roots, embedded custom-provider composition, and retained machine-readable build identity while preserving the default full product.\",\n  \"verification\": [\"./shifu check:source\", \"macOS embedded-minimal, embedded-sqlite, and full rebuilds\", \"embedded custom-provider and fact-authority CTest\", \"three-platform full and embedded-minimal workflow\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [x] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis changes provider composition and build identity evidence only; it performs no publication or deployment action.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T12:30:31Z",
          "mergedAt": "2026-07-15T14:24:52Z",
          "additions": 1101,
          "deletions": 338,
          "changedFiles": 34
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 57,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/57",
          "title": "docs(paper): frame KFD around boundary primitives",
          "body": "## Summary\n\n- preserve KFD-1/2/3 as the ordered foundation and derive KFD-4/5/6 as procedures\n- define boundary pressure as a non-exclusive primitive-discovery diagnostic\n- compare Xinfa Atlas, Kungfu Episode, and Buildchain Release Passport as implementation-backed cases\n- compose the cases through Project Cut and add explicit claim, falsification, and maturity gates\n\n## Validation\n\n- `make check`\n- `make pdf` (15-page PDF; no overfull boxes)\n- citation-key completeness scan\n- rendered visual inspection of title, tables, equations, conclusion, and references\n\n## Evidence boundary\n\nKFD-6 remains draft, Project Cut remains partial, and the paper explicitly avoids historical, universal, or quantitative claims.\n\nGoal: 2026-07-15-foundation-paper-boundary-primitives-rewrite",
          "author": "dongkeren",
          "createdAt": "2026-07-15T14:31:28Z",
          "mergedAt": "2026-07-15T14:32:59Z",
          "additions": 877,
          "deletions": 482,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 59,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/59",
          "title": "release: prepare boundary primitives alpha.7",
          "body": "## Summary\n\nPrepare the next unused alpha for the boundary-primitives rewrite.\n\n## Version\n\n- `0.1.0-alpha.6` -> `0.1.0-alpha.7`\n- existing public versions and artifacts remain immutable\n\n## Validation\n\n- `make check`\n- npm and GitHub exact-version availability verified\n\nGoal: 2026-07-15-foundation-paper-boundary-primitives-rewrite",
          "author": "dongkeren",
          "createdAt": "2026-07-15T14:39:31Z",
          "mergedAt": "2026-07-15T14:40:38Z",
          "additions": 1,
          "deletions": 1,
          "changedFiles": 1
        },
        {
          "repository": "kungfu-systems/paper-kfd-foundation-real-world-agent-work",
          "number": 60,
          "url": "https://github.com/kungfu-systems/paper-kfd-foundation-real-world-agent-work/pull/60",
          "title": "release: promote boundary primitives paper alpha.7",
          "body": "## Promotion\n\nPromote the reviewed boundary-primitives rewrite and `0.1.0-alpha.7` declaration from the development line into the alpha publication channel.\n\n## Included\n\n- KFD-1/2/3 foundation with KFD-4/5/6 derived procedures\n- Xinfa Atlas, Kungfu Episode, and Buildchain Release Passport boundary cases\n- Project Cut composition and falsifiable evaluation program\n- next unused alpha version\n\n## Expected publication\n\n- npm: `@kungfu-tech/paper-kfd-foundation-real-world-agent-work@0.1.0-alpha.7`\n- GitHub prerelease: `v0.1.0-alpha.7`\n- PDF: `kfd-foundation-model.pdf`\n\nGoal: 2026-07-15-foundation-paper-boundary-primitives-rewrite",
          "author": "dongkeren",
          "createdAt": "2026-07-15T14:41:10Z",
          "mergedAt": "2026-07-15T14:42:23Z",
          "additions": 878,
          "deletions": 483,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1294,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1294",
          "title": "feat(core): add sealed KFX admission envelope",
          "body": "## Summary\n\n- add a versioned, sealed artifact-verification envelope that binds exact artifact/provenance roots, issuer and publisher identity, lifecycle, revocation, and an existing fresh KFD assessment\n- expose the same fail-closed verifier and direct KFX projection through Node and CLI without consumer-side field synthesis\n- keep existing `verifyArtifactPassport` callers compatible and add an opt-in sealed result\n- align release-line bootstrap impact metadata with a newly opened minor line\n\n## Verification\n\n- `pnpm run check`\n- `node --test tests/artifact-verification-envelope.test.mjs`\n- `node --test tests/release-passport.test.mjs`\n- `npm pack --dry-run --json`\n\n## Version impact\n\nMinor: opens the `v2.13` artifact-verification-envelope and package-subpath surfaces.\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:02:32Z",
          "mergedAt": "2026-07-15T15:05:04Z",
          "additions": 1257,
          "deletions": 58,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1293,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1293",
          "title": "chore(release): promote v2.13 alpha",
          "body": "Buildchain release line bootstrap opened v2.13. Merge this channel PR to publish the first alpha for the new minor line.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T14:58:26Z",
          "mergedAt": "2026-07-15T15:08:17Z",
          "additions": 1329,
          "deletions": 128,
          "changedFiles": 32
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1296,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1296",
          "title": "fix(workflows): close current release blockers",
          "body": "## Summary\n\n- preserve `actions: read` through the nested web publication-authority call\n- stage the exact downstream propagation lock before checking for changes\n- isolate controller evidence from consumer version-state verification\n- bound reusable build jobs and lifecycle commands with one configurable timeout\n\n## Issues\n\nCloses #1295\nCloses #1285\nCloses #1223\nCloses #1131\n\n## Validation\n\n- `pnpm run check` (633 tests, workflow/action/site generation checks)\n- timeout regression covers command overrides and configured lifecycle stages\n- propagation regression covers first untracked lock and idempotent no-op detection\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:24:17Z",
          "mergedAt": "2026-07-15T15:28:58Z",
          "additions": 325,
          "deletions": 110,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 166,
          "url": "https://github.com/kungfu-systems/build-images/pull/166",
          "title": "feat(images): add pinned ClickHouse mirror",
          "body": "## Summary\n\n- add a build-images-owned ClickHouse 26.3.10.60-lts mirror pinned to the upstream Docker Hub digest\n- declare the image as pending its first reviewed publish\n- make selective publish and provenance tests derive the manifest family size\n\n## Verification\n\n- `pnpm run check`\n\nPart of #165. This bootstrap release establishes the immutable GHCR digest consumed by the final ClickHouse Phase A qualification release.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:27:18Z",
          "mergedAt": "2026-07-15T15:30:27Z",
          "additions": 103,
          "deletions": 21,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1297,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1297",
          "title": "chore(release): promote v2.13 fixes to alpha",
          "body": "## Summary\n\nPromote the completed v2.13 KFX admission envelope and all current issue repairs to the protected alpha channel.\n\n## Admission\n\n- Buildchain open issues: zero\n- feature PR: #1294\n- release blocker PR: #1296\n- local full check: 633 tests plus workflow, action bundle, inventory, and generated-site validation\n\nThe alpha publication remains governed by the post-merge Verify and Buildchain Ref Promotion workflows.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:32:08Z",
          "mergedAt": "2026-07-15T15:34:23Z",
          "additions": 325,
          "deletions": 110,
          "changedFiles": 28
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 169,
          "url": "https://github.com/kungfu-systems/build-images/pull/169",
          "title": "chore(buildchain): accept v2.12.8 alpha contract",
          "body": "## Summary\n\n- update the alpha Buildchain runtime to `2.12.8-alpha.0` and accept the current `v2-alpha` contract\n- update the stable runtime to `2.12.7` and refresh the `v2` contract lock\n- regenerate KFD123 evidence bound to both locks\n\n## Verification\n\n- `pnpm run check`\n\nCloses #167.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:36:08Z",
          "mergedAt": "2026-07-15T15:41:59Z",
          "additions": 36,
          "deletions": 36,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 963,
          "url": "https://github.com/kungfu-systems/kungfu/pull/963",
          "title": "feat(core): add git workspace episode provider",
          "body": "## Summary\n\nAdd a build-free Git Workspace Episode shadow provider that stores one qualified sealed Episode per immutable canonical JSONL segment without replacing yijinjing authority.\n\n## Changes\n\n- preserve the qualified journal-native Episode root while computing a separate provider root\n- use per-Episode generation leases and temp/fsync/atomic-rename publication\n- reject raw runtime/private material and require a safe `.kungfu/.gitignore`\n- add deterministic import/export, recovery, concurrency, and corruption fixtures\n- document the authority and capability boundary in ADR-0099\n\n## Verification\n\n- `node --test scripts/check-git-episode-provider.test.mjs scripts/source-acceptance.test.mjs` (21 passed)\n- `node scripts/adr-audit.mjs`\n- `node scripts/check-project-cut-contract.mjs`\n- `git diff --check`\n- `./shifu check:source` reached the dependency-backed Kungfu Gate catalog and stopped because local `yaml` is not installed; hosted CI must complete the full gate\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0099\"],\n  \"summary\": \"Implement the Git Workspace Episode shadow provider with immutable per-Episode JSONL segments and qualified root preservation\",\n  \"verification\": [\"Build-free provider contract and fault fixtures\", \"ADR registry audit\", \"Project Cut regression contract\", \"Hosted source acceptance\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe provider is shadow-only, rejects private/runtime bytes, and cannot advertise journal authority or recompute the Episode semantic root.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed",
          "author": "dongkeren",
          "createdAt": "2026-07-15T14:52:05Z",
          "mergedAt": "2026-07-15T15:43:15Z",
          "additions": 1035,
          "deletions": 0,
          "changedFiles": 8
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1299,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1299",
          "title": "fix(release): install publication plan dependencies",
          "body": "## Summary\n- install promotion-source dependencies before exact version-state planning\n- keep pnpm, yarn, npm, and custom behavior aligned with the promote job\n- lock the install-before-plan ordering in workflow inventory and tests\n\n## Validation\n- corepack pnpm@11.7.0 run check\n- 633/633 unit tests passed\n- workflow validation and all four action bundles passed\n\nCloses #1298",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:46:20Z",
          "mergedAt": "2026-07-15T15:56:57Z",
          "additions": 76,
          "deletions": 14,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1300,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1300",
          "title": "chore(release): promote publication planner fix to alpha",
          "body": "## Summary\n- promote the exact publication-planner dependency fix from dev/v2/v2.13\n- retain the sealed KFX admission envelope and all prior v2.13 release-blocker fixes\n- restore alpha publication after the failed exact-version planning run\n\n## Evidence\n- dev Verify: https://github.com/kungfu-systems/buildchain/actions/runs/29430323213\n- fix PR Build Surface Fixture: https://github.com/kungfu-systems/buildchain/actions/runs/29429568411\n- open Buildchain issues: 0",
          "author": "dongkeren",
          "createdAt": "2026-07-15T16:03:32Z",
          "mergedAt": "2026-07-15T16:04:52Z",
          "additions": 76,
          "deletions": 14,
          "changedFiles": 12
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 171,
          "url": "https://github.com/kungfu-systems/build-images/pull/171",
          "title": "chore(release): join alpha.10 ancestry for ClickHouse bootstrap",
          "body": "## Summary\n- join the `v1.2.4-alpha.10` release commit into the current dev ancestry\n- preserve the current dev tree byte-for-byte\n- unblock the protected `dev/v1/v1.2` to `alpha/v1/v1.2` ClickHouse bootstrap promotion\n\n## Verification\n- `git diff origin/dev/v1/v1.2 HEAD --stat` is empty\n- merge parents are current dev `fff5b43` and alpha release `724e747`\n\nThis PR must be merged with its merge commit so the release ancestry remains explicit.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:57:23Z",
          "mergedAt": "2026-07-15T16:16:08Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 168,
          "url": "https://github.com/kungfu-systems/build-images/pull/168",
          "title": "chore(release): publish ClickHouse mirror bootstrap alpha",
          "body": "## Summary\n\nPromote the reviewed ClickHouse mirror bootstrap from `dev/v1/v1.2` to the alpha channel. This release establishes the immutable GHCR digest required by the final ClickHouse Phase A plan in #165.\n\n## Required release outputs\n\n- Buildchain v2 dual-channel promotion\n- Release Passport: `trust=pass`\n- GitHub release enabled\n- six-image publish evidence with only the new ClickHouse image built when the accepted lock permits reuse",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:31:37Z",
          "mergedAt": "2026-07-15T16:20:25Z",
          "additions": 213,
          "deletions": 131,
          "changedFiles": 20
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1303,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1303",
          "title": "fix(release): make alpha preflight race-safe",
          "body": "## Summary\n- keep dry-run exact version planning read-only when lifecycle verification materializes derived files\n- wait up to ten minutes for the exact merged channel PR's successful RC run and paired artifacts\n- retain strict PR/head matching and fail closed on timeout or sibling evidence\n\n## Validation\n- targeted promote/resolver tests: 123/123\n- full Buildchain check: 635/635 tests, workflow validation, generated site check, four action bundles\n\nCloses #1301\nCloses #1302",
          "author": "dongkeren",
          "createdAt": "2026-07-15T16:27:05Z",
          "mergedAt": "2026-07-15T16:29:09Z",
          "additions": 320,
          "deletions": 77,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1304,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1304",
          "title": "chore(release): promote race-safe alpha preflight",
          "body": "## Summary\n- promote read-only exact publication planning and bounded exact-PR RC polling\n- include the sealed KFX admission envelope and all v2.13 blocker fixes\n- retry alpha publication only after #1301 and #1302 are fixed and closed\n\n## Evidence\n- fix PR Build Surface Fixture: https://github.com/kungfu-systems/buildchain/actions/runs/29432456390\n- dev Verify: https://github.com/kungfu-systems/buildchain/actions/runs/29432597639\n- open Buildchain issues: 0",
          "author": "dongkeren",
          "createdAt": "2026-07-15T16:30:45Z",
          "mergedAt": "2026-07-15T16:35:09Z",
          "additions": 320,
          "deletions": 77,
          "changedFiles": 15
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 172,
          "url": "https://github.com/kungfu-systems/build-images/pull/172",
          "title": "fix(release): prefer workflow package token",
          "body": "## Summary\n- prefer the workflow-scoped `GITHUB_TOKEN` for GitHub Packages visibility reads\n- retain `GH_TOKEN` as the local fallback\n- contract-test the token precedence in `check-workflows.sh`\n\n## Root cause\nBuildchain v2.12.8 exposes the narrower ref-promotion credential as `GH_TOKEN`. The publisher selected it ahead of the workflow token, so the alpha.11 transaction pushed and anonymously smoke-tested `base-linux` but failed the package metadata check with `403 read:packages` before moving release refs.\n\nFailed transaction: https://github.com/kungfu-systems/build-images/actions/runs/29432207706\n\n## Verification\n- `bash -n scripts/verify-ghcr-public.sh scripts/check-workflows.sh`\n- `bash scripts/check-workflows.sh`\n- `pnpm run check`\n\nThe existing Buildchain transaction is resumable after this fix reaches the alpha source.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T16:30:05Z",
          "mergedAt": "2026-07-15T16:37:41Z",
          "additions": 9,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 173,
          "url": "https://github.com/kungfu-systems/build-images/pull/173",
          "title": "chore(release): join failed alpha.11 transaction ancestry",
          "body": "## Summary\n- join the failed alpha.11 channel merge into dev ancestry\n- preserve the current dev tree byte-for-byte\n- allow the GHCR token-precedence fix to enter a clean protected promotion PR\n\n## Evidence\n- failed transaction: https://github.com/kungfu-systems/build-images/actions/runs/29432207706\n- fix PR: #172\n- `git diff origin/dev/v1/v1.2 HEAD --stat` is empty\n\nThis PR must retain its merge commit so the alpha channel ancestry remains explicit.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T16:38:22Z",
          "mergedAt": "2026-07-15T16:42:35Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 174,
          "url": "https://github.com/kungfu-systems/build-images/pull/174",
          "title": "fix(release): resume alpha.11 with package token authority",
          "body": "## Summary\n- promote the GHCR package-token authority fix through the standard dev-to-alpha channel\n- resume the durable alpha.11 publish transaction after its safe pre-ref failure\n- retain the first-party ClickHouse image as the new six-image family member\n\n## Evidence\n- failed transaction (no release ref moved): https://github.com/kungfu-systems/build-images/actions/runs/29432207706\n- token fix: #172\n- ancestry closure: #173\n- local full check: `pnpm run check`\n\nExpected Buildchain behavior: reuse the already-pushed matching base image where valid, complete the family, verify public anonymous pulls, publish evidence and Release Passport, then move exact/floating refs.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T16:42:53Z",
          "mergedAt": "2026-07-15T16:46:18Z",
          "additions": 9,
          "deletions": 1,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1306,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1306",
          "title": "fix(release): preserve promotion authority on new lines",
          "body": "## Summary\n\n- carry declared promotion bypass apps, users, and teams into release-line branch protection\n- fail closed before protection changes when no promotion authority is declared\n- document and test the new-line publication authority invariant\n\nCloses #1305\n\n## Validation\n\n- `pnpm run check` (635 tests; workflow/site/inventory checks and all action bundles passed)\n- `git diff --check`",
          "author": "dongkeren",
          "createdAt": "2026-07-15T16:48:09Z",
          "mergedAt": "2026-07-15T16:49:26Z",
          "additions": 56,
          "deletions": 14,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 965,
          "url": "https://github.com/kungfu-systems/kungfu/pull/965",
          "title": "feat(release): close workflow publication authority",
          "body": "## Summary\n\nClose Kungfu's GitHub Actions execution surface into one machine-checked authority inventory and add an independent consumer predicate for sealed product publication.\n\n## Changes\n\n- classify all 15 workflows, 24 jobs, and 82 steps with exact activation, permission, credential, external-action, and definition digests\n- reject unknown workflows/jobs/steps, one-sided activation or permission drift, mutable authority-bearing refs, qualification jobs with inherited secrets, and qualification Environment access\n- pin source/build/promotion controllers to Buildchain 2.12.7 and reduce write/OIDC/secret scope to the smallest declared jobs\n- independently reverify source, current Gate policy, Buildchain runtime/contract, controller receipt, three-platform Gate aggregate, runner provenance, live control-plane audit, artifact bytes, channel, freshness, and nonce replay\n- document workflow authority and release admission, and register SHIFU-ADR-0007\n\n## Verification\n\n- `./shifu check:gate-catalog`\n- `./shifu test:release-admission`\n- `./shifu check:source`\n- staged pre-commit gate, documentation contract, ADR audit, Biome, and KFD evidence checks\n\n## Current publication boundary\n\nThis PR makes missing sealed inputs fail closed and does not execute a product publication. Successful live cutover remains stage-ready until Buildchain transports the complete Gate aggregate/capability through a consumer-owned predicate immediately before the provider write; no static or no-Gate fallback is introduced here.\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"SHIFU-ADR-0007\"],\n  \"summary\": \"Close Kungfu workflow authority and stage a project-owned sealed release-admission predicate while preserving fail-closed publication until the upstream capability handoff exists.\",\n  \"verification\": [\"./shifu check:gate-catalog\", \"./shifu test:release-admission\", \"./shifu check:source\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis changes release authority and verification contracts only; it performs no product publication or deployment.\n\n## Checklist\n\n- [x] Commit is signed off (DCO)\n- [x] Source acceptance is green locally\n- [x] Documentation and negative fixtures are included\n- [x] No credential values or generated live evidence are committed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:20:23Z",
          "mergedAt": "2026-07-15T16:51:06Z",
          "additions": 2936,
          "deletions": 70,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 968,
          "url": "https://github.com/kungfu-systems/kungfu/pull/968",
          "title": "feat(xinfa): admit qualified Episode evidence",
          "body": "## Summary\n\nAdd a standalone Xinfa Episode evidence provider that admits only qualified, sealed public Git Workspace Episode segments into a deterministic successor Atlas without becoming Episode authority.\n\n## Related issue\n\nADR-0100\n\n## Changes\n\n- add `xinfa.episode-provider-submission/v1`, `xinfa.review-chart/v1`, and `xinfa episode compile`\n- verify public Git provider, qualification, canonical JSONL, and all recorded roots before source closure\n- compile explicit Mission/Go declarations, proof/receipt refs, and review findings through the existing Repository Pack to Atlas authority path\n- preserve existing Atlas and Context Pack roots while adding isolated impact/invalidation and anti-feedback fixtures\n- retain standalone CLI qualification and public extraction boundaries\n\n## Verification\n\n- `./shifu xinfa:check` — 33 Rust tests plus boundary and lint gates passed\n- `./shifu xinfa:standalone` — extracted Cargo build/test and real Episode successor-Atlas CLI smoke passed\n- `./shifu docs:check:readonly` — 62 documentation contract tests passed\n- `./shifu check:source` — 344 source contract tests, 76 runtime-upgrade tests, 69 desktop-update tests, TypeScript, Biome, and all source gates passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0100\"],\n  \"summary\": \"Deliver the qualified Xinfa Episode evidence provider and successor Atlas contract\",\n  \"verification\": [\"Xinfa check and standalone qualification\", \"source acceptance\", \"documentation contract gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe provider/CLI boundary consumes only public schemas and explicitly refuses private, runtime, generated, missing, open, unverified, and raw-transcript inputs.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T16:44:12Z",
          "mergedAt": "2026-07-15T16:55:01Z",
          "additions": 1812,
          "deletions": 5,
          "changedFiles": 18
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 175,
          "url": "https://github.com/kungfu-systems/build-images/pull/175",
          "title": "fix(release): trust anonymous GHCR manifest proof",
          "body": "## Summary\n- remove the GitHub Packages metadata API from the release publicness gate\n- retain anonymous GHCR token issuance plus manifest `200` and immutable digest as the direct authority\n- contract-test that public verification has no package API scope dependency\n\n## Root cause\nBoth the narrower promotion credential and the workflow `GITHUB_TOKEN` receive `403` from the org package metadata endpoint for historical packages. The same images are anonymously pullable, which is the actual consumer contract and conclusively fails for private images.\n\nFailed transactions:\n- https://github.com/kungfu-systems/build-images/actions/runs/29432207706\n- https://github.com/kungfu-systems/build-images/actions/runs/29433955836\n\n## Verification\n- `bash -n scripts/verify-ghcr-public.sh scripts/check-workflows.sh`\n- `bash scripts/check-workflows.sh`\n- `pnpm run check`",
          "author": "dongkeren",
          "createdAt": "2026-07-15T16:53:52Z",
          "mergedAt": "2026-07-15T17:03:09Z",
          "additions": 5,
          "deletions": 30,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 176,
          "url": "https://github.com/kungfu-systems/build-images/pull/176",
          "title": "chore(release): join failed alpha.12 transaction ancestry",
          "body": "## Summary\n- join the failed alpha.12 channel merge into dev ancestry\n- preserve the current dev tree byte-for-byte\n- unblock the anonymous-GHCR-authority fix for protected promotion\n\n## Evidence\n- failed transaction: https://github.com/kungfu-systems/build-images/actions/runs/29433955836\n- publicness authority fix: #175\n- `git diff origin/dev/v1/v1.2 HEAD --stat` is empty\n\nThis PR must retain its merge commit.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T17:03:45Z",
          "mergedAt": "2026-07-15T17:07:38Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 177,
          "url": "https://github.com/kungfu-systems/build-images/pull/177",
          "title": "fix(release): publish with anonymous GHCR authority",
          "body": "## Summary\n- promote the direct anonymous-GHCR publicness proof through the standard dev-to-alpha channel\n- close failed alpha.12 ancestry before promotion\n- publish the first-party ClickHouse mirror as part of the six-image family\n\n## Evidence\n- anonymous authority fix: #175\n- failed transaction ancestry closure: #176\n- local full check: `pnpm run check`\n\nExpected release result: Buildchain publishes the next exact alpha, verifies all six image manifests anonymously, emits `evidence.json` and a trusted Release Passport, then moves exact/floating refs.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T17:08:03Z",
          "mergedAt": "2026-07-15T17:10:43Z",
          "additions": 5,
          "deletions": 30,
          "changedFiles": 2
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 178,
          "url": "https://github.com/kungfu-systems/build-images/pull/178",
          "title": "fix(release): allow declared first package publish",
          "body": "## Summary\n- distinguish a first-party package that is not yet publicly addressable from ordinary GHCR auth failures\n- allow token-stage `403/404` only when the image manifest declares `pending-first-publish`\n- keep all ordinary package token failures fail-closed\n- add positive and negative provenance fixtures\n\n## Root cause\nThe ClickHouse package does not exist yet. GHCR returns `403` at anonymous token issuance before any manifest request, while `--allow-missing` previously handled only a manifest-level `404`.\n\nFailed transaction: https://github.com/kungfu-systems/build-images/actions/runs/29435586702\n\n## Verification\n- `python3 -m py_compile scripts/ghcr-manifest.py scripts/test-publish-provenance.py`\n- `bash -n scripts/build-image-family.sh`\n- `python3 scripts/test-publish-provenance.py` (9 fixtures)\n- `pnpm run check`",
          "author": "dongkeren",
          "createdAt": "2026-07-15T17:22:03Z",
          "mergedAt": "2026-07-15T17:24:48Z",
          "additions": 88,
          "deletions": 18,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 179,
          "url": "https://github.com/kungfu-systems/build-images/pull/179",
          "title": "chore(release): join failed alpha.13 transaction ancestry",
          "body": "## Summary\n- join the failed alpha.13 channel merge into dev ancestry\n- preserve the current dev tree byte-for-byte\n- unblock the declared first-package fix for protected promotion\n\n## Evidence\n- failed transaction: https://github.com/kungfu-systems/build-images/actions/runs/29435586702\n- first-package fix: #178\n- `git diff origin/dev/v1/v1.2 HEAD --stat` is empty\n\nThis PR must retain its merge commit.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T17:25:16Z",
          "mergedAt": "2026-07-15T17:28:08Z",
          "additions": 0,
          "deletions": 0,
          "changedFiles": 0
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 180,
          "url": "https://github.com/kungfu-systems/build-images/pull/180",
          "title": "fix(release): complete declared ClickHouse first publish",
          "body": "## Summary\n- promote the manifest-gated first-package handling through the standard dev-to-alpha channel\n- retain fail-closed handling for every non-declared GHCR token failure\n- publish and verify the complete six-image family\n\n## Evidence\n- first-package fix and negative test: #178\n- alpha.13 failure ancestry closure: #179\n- local full check: `pnpm run check`\n\nExpected result: first-party `clickhouse-server` package creation, six anonymous manifest proofs, durable publish evidence, trusted Release Passport, and exact alpha ref movement.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T17:28:20Z",
          "mergedAt": "2026-07-15T17:31:34Z",
          "additions": 88,
          "deletions": 18,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 964,
          "url": "https://github.com/kungfu-systems/kungfu/pull/964",
          "title": "fix(core): probe Windows liveness without signaling",
          "body": "## Summary\n\n- probe Windows lock-holder liveness through `OpenProcess` / `GetExitCodeProcess` instead of `os.kill(pid, 0)`\n- use psutil's non-signaling PID query for runtime service adoption checks\n- anchor contract registry discovery at the module directory and make interrupted Windows table guards close without unlocking a lock they never acquired\n- retain the welded Windows `call shifu.cmd` qualification surface\n\n## Root cause and evidence\n\n- hosted runs `29416494142`, `29420852660`, and self-hosted run `29422161962` reproduced `Terminate batch job` during the concurrent `activation-core` case\n- verbose run `29426977705` exposed one independent Windows source-discovery defect, fixed here by starting at `contract.py`'s parent\n- exact-topology run `29429837068` then exposed the decisive causal chain: the second activation caller invokes `_pid_alive(holder_pid)`; on Windows `os.kill(pid, 0)` is `CTRL_C_EVENT`, so the liveness probe interrupts every process sharing the console, including pytest and the outer batch\n- the same run showed expected lock contention (`PermissionError` from `LK_NBLCK`) immediately before the Ctrl-C cascade; the lock was an effect/observer, not cross-thread business coupling\n\n## Validation\n\n- focused contract, coordination lock, runtime broker, and runtime service suite: 72 passed\n- Windows-like regressions assert PID liveness probes never call `os.kill(pid, 0)`\n- Ruff format/lint, `git diff --check`, and staged source acceptance hook passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"adr-neutral\",\n  \"reason\": \"Repairs Windows process-liveness and contract discovery behavior without changing runtime architecture or product claims.\"\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [x] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThis PR repairs qualification and runtime liveness observation only; it does not publish or deploy artifacts.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Source acceptance is green locally\n- [x] No credentials or generated qualification evidence are committed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:13:42Z",
          "mergedAt": "2026-07-15T17:39:37Z",
          "additions": 96,
          "deletions": 11,
          "changedFiles": 6
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 181,
          "url": "https://github.com/kungfu-systems/build-images/pull/181",
          "title": "chore(images): accept v1.2.4-alpha.14 digests",
          "body": "## Summary\n\n- accept all six immutable image digests published by `v1.2.4-alpha.14`\n- retire the ClickHouse `pending-first-publish` marker now that the package is publicly resolvable\n- refresh generated KFD witnesses against the accepted image lock\n\n## Release evidence\n\n- release: https://github.com/kungfu-systems/build-images/releases/tag/v1.2.4-alpha.14\n- publish run: https://github.com/kungfu-systems/build-images/actions/runs/29437027447\n- Release Passport: `ok=true`, `trust=pass`, `issues=[]`\n- ClickHouse: `ghcr.io/kungfu-systems/build-images/clickhouse-server@sha256:964dfcdf7f33ed509f50757061456618e1a13d99340e86c678130f9bd235cdc8`\n\n## Validation\n\n- `pnpm run check`\n- image-lock baseline remains eligible as a reviewed lock acceptance\n\nRefs #165",
          "author": "dongkeren",
          "createdAt": "2026-07-15T17:48:20Z",
          "mergedAt": "2026-07-15T17:51:32Z",
          "additions": 99,
          "deletions": 78,
          "changedFiles": 5
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 182,
          "url": "https://github.com/kungfu-systems/build-images/pull/182",
          "title": "feat(comparator): qualify ClickHouse Phase A",
          "body": "## Summary\n\n- add the production ClickHouse Phase A qualification plan for 3 repetitions across 21 job/tier scenarios\n- add a registry-bound ClickHouse workload adapter, fixture, oracle, and semantic verifier\n- generalize the qualification runner to resolve multiple adapters without weakening digest or identity checks\n- add the ClickHouse 3x21 qualification job to the comparator workflow\n- pin the subject to the accepted build-images digest from `v1.2.4-alpha.14`\n\n## Scope boundary\n\nThis PR establishes containerized user-outcome qualification. Native-host performance, fresh-install cost, final scoring, and winner declarations remain out of scope.\n\n## Validation\n\n- `pnpm run check`\n- 49 comparator unit/integration tests\n- both PostgreSQL and ClickHouse production plans validate against fixed input digests\n- KFD123 and alpha/stable contract locks unchanged\n\n## Release input\n\n- ClickHouse image: `ghcr.io/kungfu-systems/build-images/clickhouse-server@sha256:964dfcdf7f33ed509f50757061456618e1a13d99340e86c678130f9bd235cdc8`\n- source release: https://github.com/kungfu-systems/build-images/releases/tag/v1.2.4-alpha.14\n\nRefs #165",
          "author": "dongkeren",
          "createdAt": "2026-07-15T17:53:53Z",
          "mergedAt": "2026-07-15T18:13:06Z",
          "additions": 2189,
          "deletions": 108,
          "changedFiles": 21
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 183,
          "url": "https://github.com/kungfu-systems/build-images/pull/183",
          "title": "release(alpha): publish ClickHouse Phase A qualification",
          "body": "## Summary\n\n- publish the production ClickHouse Phase A 3x21 qualification surface\n- bind the plan to the accepted first-party ClickHouse image from `v1.2.4-alpha.14`\n- ship multi-adapter bundle closure and digest-bound dynamic semantics verification\n- retain the split authority boundary: user-outcome qualification only\n\n## Qualification evidence\n\n- implementation: #182\n- lifecycle run: https://github.com/kungfu-systems/build-images/actions/runs/29438476318\n- retained artifact: https://github.com/kungfu-systems/build-images/actions/runs/29438476318/artifacts/8352828032\n- 3 repetitions, 63/63 steps passed\n- 63/63 cleanup proofs passed; zero scoped containers, volumes, and networks remain\n- offline bundle verification passed with `user_outcome_qualification_authority=true`\n- native performance, fresh-install cost, and final scoring authority remain false\n\n## Required release outputs\n\n- Buildchain v2 dual-channel promotion\n- GitHub release enabled\n- Release Passport with `trust=pass`\n- exact source and qualification contract binding for clean-tag replay on agent-120\n\nRefs #165",
          "author": "dongkeren",
          "createdAt": "2026-07-15T18:13:38Z",
          "mergedAt": "2026-07-15T18:17:01Z",
          "additions": 2288,
          "deletions": 186,
          "changedFiles": 26
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1308,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1308",
          "title": "fix(build): retain lifecycle failure evidence",
          "body": "## Summary\n- upload lifecycle evidence directly when install/build/verify fails\n- cover both native and Linux-container jobs\n- keep the existing success publication and relay behavior unchanged\n\n## Validation\n- node --test tests/build-surface.test.mjs\n- corepack pnpm run check:workflows\n- git diff --check\n\nSigned-off-by: Keren Dong <[email-redacted]>",
          "author": "dongkeren",
          "createdAt": "2026-07-15T18:21:55Z",
          "mergedAt": "2026-07-15T18:27:51Z",
          "additions": 38,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 966,
          "url": "https://github.com/kungfu-systems/kungfu/pull/966",
          "title": "refactor(core): define bounded domain components",
          "body": "## Summary\n\nReplace the coarse Core service and adapter buckets with a bounded, machine-checked domain component graph while preserving the production source set and the public libkungfu facade.\n\n## Related issue\n\nAtlas child goal `2026-07-15-kungfu-domain-component-graph` and parent `2026-07-15-kungfu-core-architecture-level5`.\n\n## Changes\n\n- define 11 production components within an enforced 6-12 component budget\n- generate 11 real internal CMake targets from the architecture authority\n- require every component to declare an owner, entry points, and contract tests\n- reject component and target cycles, undeclared target edges, missing CMake evidence, and source ownership drift\n- map every production architecture component into the build-profile authority\n- split the view adapter into an independently linkable target without the libkungfu facade\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu build:core`\n- architecture and build-capability negative fixtures\n- `kungfu_view_component_link_tests`, `yijinjing_mmap_tests`, and `yijinjing_content_hash_tests`: 3/3\n- production source-set equality: 54 before and 54 after\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0066\"],\n  \"summary\": \"Replace coarse Core build buckets with a bounded domain component and target graph, preserving the public facade and production source set.\",\n  \"verification\": [\"./shifu check:source\", \"./shifu build:core\", \"independent view component link test\", \"architecture and build-profile negative fixtures\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T15:35:36Z",
          "mergedAt": "2026-07-15T18:32:38Z",
          "additions": 552,
          "deletions": 147,
          "changedFiles": 11
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 969,
          "url": "https://github.com/kungfu-systems/kungfu/pull/969",
          "title": "feat(project-cut): add agent-first settlement",
          "body": "## Summary\n\nAdd an agent-first Project Cut settlement surface that binds the Git index, qualified Episode providers, and a verified Xinfa successor Atlas without changing `project.cut/v1` or making hooks authoritative.\n\n## Related issue\n\nADR-0101\n\n## Changes\n\n- add versioned settlement request, plan, state, action-receipt, and contract roots\n- prepare deterministic cuts from a temporary stage-0 index snapshot with explicit dry-run, execute, and exact-stage boundaries\n- verify public Xinfa Atlas and Git Episode provider roots without reinterpreting their native root algorithms\n- distinguish sealed-unpublished from published commit observation and add headless commit reconcile\n- add optional thin pre/post-commit adapters that call the same public core and report `authority: false`\n- weld focused tests and contract checks into source acceptance, including a real Xinfa successor-Atlas integration\n\n## Verification\n\n- `./shifu check:project-cut-settlement` — 4 schemas and the settlement contract root verified\n- `./shifu test:project-cut-settlement` — 6 deterministic, recovery, privacy, hook, CLI, and reconcile tests passed\n- `./shifu test:project-cut-settlement:integration` — real Xinfa successor Atlas compile/verify and staged settlement passed\n- `./shifu docs:check:readonly` — documentation contracts passed\n- `./shifu check:source` — 355 source contract tests, 76 runtime-upgrade tests, 69 desktop-update tests, TypeScript, Biome, and all source gates passed\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"implemented\",\n  \"adrs\": [\"ADR-0101\"],\n  \"summary\": \"Deliver agent-first Project Cut settlement and stage-0 recovery without hook authority\",\n  \"verification\": [\"Project Cut settlement contract and focused tests\", \"real Xinfa successor Atlas integration\", \"source acceptance\", \"documentation contract gate\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [x] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [ ] none of the above\n\nThe CLI consumes only tracked public source/provider material, rejects private paths, never commits or pushes caller code, and keeps hook state local and rebuildable.\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T17:40:17Z",
          "mergedAt": "2026-07-15T19:27:14Z",
          "additions": 2412,
          "deletions": 9,
          "changedFiles": 19
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 971,
          "url": "https://github.com/kungfu-systems/kungfu/pull/971",
          "title": "feat(core): govern public contract compatibility",
          "body": "## Summary\n\nClassify every exported Core contract and add executable compatibility evidence for stable C ABI, public headers, retained journal layout, binding parity, and deprecation policy without freezing the experimental C++ ABI.\n\n## Related issue\n\nAtlas child goal `2026-07-15-kungfu-public-contract-compatibility` and parent `2026-07-15-kungfu-core-architecture-level5`.\n\n## Changes\n\n- extend the single Core architecture authority with public header, stable symbol, layout/schema, binding, and deprecation inventories\n- generate the public header compilation projection from that authority\n- freeze independently compiled old C consumers for embedding v1-v3 and native-storage v1 negotiation\n- retain and verify the journal-wire-v1 layout fixture\n- fail closed on header classification, stable symbol, binding parity, fixture, or deprecation-ledger drift\n- preserve `libyijinjing` as source-embedding-only with no shared ABI promise\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu build:core`\n- `./shifu test:mmap`\n- `ctest --test-dir framework/core/build -R 'yijinjing_(custom_provider|fact_authority|mmap)|kungfu_public_contract_compatibility' --output-on-failure` (6/6)\n- public-contract compatibility negative fixtures\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0066\"],\n  \"summary\": \"Classify Core public contracts and retain executable stable C ABI, public-header, journal-layout, binding-parity, and deprecation evidence.\",\n  \"verification\": [\"./shifu check:source\", \"./shifu build:core\", \"./shifu test:mmap\", \"public contract compatibility CTest 6/6\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T18:42:45Z",
          "mergedAt": "2026-07-15T21:14:08Z",
          "additions": 1023,
          "deletions": 12,
          "changedFiles": 13
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 973,
          "url": "https://github.com/kungfu-systems/kungfu/pull/973",
          "title": "feat(core): gate affected native changes",
          "body": "## Summary\n\nTurn Core architecture ownership into a deterministic affected-native development gate that resolves changed paths to the smallest supported profile, native targets, and contract tests while failing closed on unknown impact.\n\n## Related issue\n\nAtlas child goal `2026-07-15-kungfu-affected-native-pr-gate` and parent `2026-07-15-kungfu-core-architecture-level5`.\n\n## Changes\n\n- resolve implementation, header, public-contract, schema, build, and architecture changes through the single Core authority\n- compile, link, and test the bounded closure on GitHub-hosted `ubuntu-24.04`\n- retain source, authority, profile, toolchain, cache, timing, plan, step, and raw-log evidence in a verified receipt\n- require the same `source.changed-scope` Gate locally and in CI\n- emit a valid tier-none receipt for outside-Core PRs so the protected required check cannot deadlock\n- enforce a 20-minute budget, 25-minute timeout, and maximum parallelism of 12 without deleting required tests\n\n## Verification\n\n- `./shifu check:source`\n- `./shifu core:affected -- --self-test` (8/8 determinism and failure fixtures)\n- outside-Core tier-none receipt generation and verification\n- agent-120 Linux execution: passed in 243,184 ms (Conan 129,607 ms; build 113,055 ms; CTest 115 ms)\n- `./shifu build:core`\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0066\"],\n  \"summary\": \"Add a deterministic, fail-closed affected-native development gate with retained plan, build, test, timing, and cache evidence.\",\n  \"verification\": [\"./shifu check:source\", \"./shifu core:affected -- --self-test\", \"agent-120 affected-native receipt passed in 243184 ms\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T21:21:04Z",
          "mergedAt": "2026-07-15T22:46:35Z",
          "additions": 998,
          "deletions": 35,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/buildchain",
          "number": 1309,
          "url": "https://github.com/kungfu-systems/buildchain/pull/1309",
          "title": "chore(release): promote v2.12 failure evidence retention to alpha",
          "body": "Promotes the merged failure-evidence retention workflow from dev/v2/v2.12 to alpha/v2/v2.12.\\n\\nEvidence:\\n- PR #1308 merged at c2571d8df5b90ecd542695b64644e6423eb42358\\n- pnpm check passed (624 tests)\\n- reusable build workflow uploads lifecycle evidence on failure\\n\\nThis is the governed channel promotion required before downstream Kungfu alpha qualification can consume the outer workflow change.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T23:28:46Z",
          "mergedAt": "2026-07-15T23:33:17Z",
          "additions": 38,
          "deletions": 3,
          "changedFiles": 3
        },
        {
          "repository": "kungfu-systems/kungfu",
          "number": 974,
          "url": "https://github.com/kungfu-systems/kungfu/pull/974",
          "title": "feat(core): expose architecture query and health",
          "body": "## Summary\n\nExpose the Level-5 Core architecture authority as a stable offline query, generated navigation/review projections, and baseline-ratcheted health report, while documenting the exact build-profile and source-responsibility trimming controls.\n\n## Related issue\n\nAtlas child goal `2026-07-15-kungfu-architecture-query-health-ownership` and parent `2026-07-15-kungfu-core-architecture-level5`.\n\n## Changes\n\n- query architecture by path, component, target, stable symbol, error text, capability, or build profile with human and JSON output\n- return ownership, entry points, dependencies, targets, profiles, tests, public surfaces, diagnostics, docs, runbooks, ADRs, products, and impact reasons\n- generate the architecture index, review routes, and health report from the same authority\n- ratchet cycles, fan-out, public propagation, responsibility utilization, affected-native duration, and external dependency closure; retain explicit advisory reasons for churn and binary size\n- fail visibly on missing owners, missing backup review, cycles, unknown navigation, projection drift, or health regression\n- document build-profile selection and `service.cpp`/episode/query-render/JSON-compatibility source responsibility budgets\n\n## Verification\n\n- `./shifu check:source`\n- `KUNGFU_BUILD_PROFILE=full ./shifu rebuild:core`\n- `ctest --test-dir framework/core/build -R '^(kungfu_durability_contract_tests|kungfu_public_contract_compatibility_tests|kungfu_view_component_link_tests|yijinjing_custom_provider_qualification)$' --output-on-failure` (4/4)\n- `./shifu core:architecture --self-test`\n- `./shifu core:architecture:health`\n- representative path, symbol, error, capability, and profile queries\n- GitHub-hosted affected-native receipt: 610,610 ms against a 1,200,000 ms budget; the earlier agent-120 observation remains retained\n\n## ADR delivery / release declaration\n\n<!-- kungfu-adr-release:v1\n{\n  \"schema\": \"kungfu.adr-release-pr/v1\",\n  \"kind\": \"dev-delivery\",\n  \"intent\": \"stage-ready\",\n  \"adrs\": [\"ADR-0066\"],\n  \"summary\": \"Expose offline Core architecture query, ownership routing, generated navigation, and baseline-ratcheted health from one authority.\",\n  \"verification\": [\"./shifu check:source\", \"KUNGFU_BUILD_PROFILE=full ./shifu rebuild:core\", \"architecture query self-test\", \"representative Core CTest 4/4\"]\n}\n-->\n\n## Governance risk check\n\n- [ ] credentials, tokens, secrets, or private logs\n- [ ] provider APIs, CLIs, OpenTelemetry, billing, quota, or usage attribution\n- [ ] official hosted or managed services\n- [ ] official branding, package names, release identity, or domains\n- [ ] release evidence, provenance, package publishing, or deployment surfaces\n- [x] none of the above\n\n## Checklist\n\n- [x] Commits are signed off (DCO)\n- [x] Documentation updated if behavior changed\n",
          "author": "dongkeren",
          "createdAt": "2026-07-15T22:59:14Z",
          "mergedAt": "2026-07-15T23:55:04Z",
          "additions": 1064,
          "deletions": 3,
          "changedFiles": 14
        },
        {
          "repository": "kungfu-systems/build-images",
          "number": 184,
          "url": "https://github.com/kungfu-systems/build-images/pull/184",
          "title": "feat(images): add Aeron native qualification kit",
          "body": "## Summary\n\n- add a release-owned Aeron 1.52.2 native qualification kit image\n- pin the compiler JDK, runtime JRE, Aeron JAR, and noninteractive harness\n- retain the first-publish lock so production plans cannot self-reference an unpublished digest\n- extend selective-publish fixtures and repository checks for the new image family\n\n## Authority boundary\n\nThe OCI image is distribution-only. Container execution cannot grant native performance authority. The follow-up qualification change will extract and verify the accepted kit before any host-native measurement.\n\n## Validation\n\n- `pnpm run check`\n- `bash -n images/aeron-native-kit/bin/aeron-native-harness images/aeron-native-kit/tests/smoke.sh`\n- BuildKit compiled the Java 21 harness successfully; the reviewed alpha publish will perform the complete image smoke on GitHub-hosted Linux\n\n## Version impact\n\nPatch within the active v1.2 alpha line: this is a locked prerequisite for #170 and does not yet grant a new qualification authority.",
          "author": "dongkeren",
          "createdAt": "2026-07-15T23:47:42Z",
          "mergedAt": "2026-07-15T23:58:19Z",
          "additions": 635,
          "deletions": 1,
          "changedFiles": 9
        }
      ],
      "developmentAttribution": {
        "repository": "kungfu-systems/kungfu",
        "branch": "dev/v4/v4.0",
        "window": {
          "id": "kungfu-v4-through-operating-cutoff",
          "label": "Kungfu v4 public branch through the operating cutoff",
          "startInclusive": "2026-06-16T00:00:00.000Z",
          "endExclusive": "2026-08-01T00:00:00.000Z",
          "duration": "P46D"
        },
        "windowRelation": "overlaps-bootstrap-and-operating-observations",
        "totalCommitsScanned": 2908,
        "explicitlyAttributedCommits": 135,
        "byAgent": [
          {
            "agent": "Codex",
            "commits": 78,
            "markerTypes": [
              {
                "name": "agent-field",
                "count": 78
              }
            ]
          },
          {
            "agent": "Claude",
            "commits": 34,
            "markerTypes": [
              {
                "name": "agent-field",
                "count": 34
              }
            ]
          },
          {
            "agent": "Cursor",
            "commits": 21,
            "markerTypes": [
              {
                "name": "co-author-trailer",
                "count": 21
              }
            ]
          },
          {
            "agent": "Amp",
            "commits": 2,
            "markerTypes": [
              {
                "name": "co-author-trailer",
                "count": 2
              }
            ]
          }
        ],
        "records": [
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "a20748de6117b627d8ad9e41551f53fe7fa9f5f2",
            "url": "https://github.com/kungfu-systems/kungfu/commit/a20748de6117b627d8ad9e41551f53fe7fa9f5f2",
            "title": "build(v4): arm64 点亮 C++ 内核，conan2 + fmt10 现代化",
            "observedAt": "2026-06-16T10:01:10Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "01cf26faab988082b65bb0b37a8c35d87df50a6c",
            "url": "https://github.com/kungfu-systems/kungfu/commit/01cf26faab988082b65bb0b37a8c35d87df50a6c",
            "title": "build(v4): Step 2 点亮 Python 绑定 pykungfu，journal 写读往返通过",
            "observedAt": "2026-06-16T10:51:20Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "1599ab1cc50a2eeef0f7f4dfd54b8d2030f674b8",
            "url": "https://github.com/kungfu-systems/kungfu/commit/1599ab1cc50a2eeef0f7f4dfd54b8d2030f674b8",
            "title": "build(v4): Step 3 点亮 Node 绑定 kungfu_node，三语言共享同一条 journal",
            "observedAt": "2026-06-16T11:29:29Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "5f3ab0786cba51bde94b6a075c8720c913bf6143",
            "url": "https://github.com/kungfu-systems/kungfu/commit/5f3ab0786cba51bde94b6a075c8720c913bf6143",
            "title": "build(v4): Step 4 点亮单进程三语言联动，技术终点达成",
            "observedAt": "2026-06-16T12:15:12Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "d07fe5a894b55a4600c360e194b27206ac40ff69",
            "url": "https://github.com/kungfu-systems/kungfu/commit/d07fe5a894b55a4600c360e194b27206ac40ff69",
            "title": "build(v4): .v4 跨平台适配 Linux(rpath/linker/测试脚本)",
            "observedAt": "2026-06-16T15:05:18Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "fa4feb44e7cc39bc71c6f53b44545e1c6a88bac7",
            "url": "https://github.com/kungfu-systems/kungfu/commit/fa4feb44e7cc39bc71c6f53b44545e1c6a88bac7",
            "title": "fix(yijinjing): time.h 显式 #include <cstdint> 修 gcc13 编译",
            "observedAt": "2026-06-16T15:17:33Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "77ee308fb5f66a6a7f57fb095da5f4d4a0dba4c5",
            "url": "https://github.com/kungfu-systems/kungfu/commit/77ee308fb5f66a6a7f57fb095da5f4d4a0dba4c5",
            "title": "fix(v4): Linux 单进程内嵌设 RTLD_GLOBAL，修 napi_* undefined symbol",
            "observedAt": "2026-06-16T16:01:07Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "0e41c8e0257ed5c199f18de93be43bc925a54780",
            "url": "https://github.com/kungfu-systems/kungfu/commit/0e41c8e0257ed5c199f18de93be43bc925a54780",
            "title": "build(v4): 去掉 FMT_USE_CONSTEVAL=0 workaround，恢复 fmt 编译期检查",
            "observedAt": "2026-06-16T22:40:50Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "1775eb2378da27255bdb77916fe0453e0308ef22",
            "url": "https://github.com/kungfu-systems/kungfu/commit/1775eb2378da27255bdb77916fe0453e0308ef22",
            "title": "docs(v4): 建 conan2 迁移理解与决策日志",
            "observedAt": "2026-06-17T02:38:14Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "326179cac308f91469e1fea8723ee555095bf269",
            "url": "https://github.com/kungfu-systems/kungfu/commit/326179cac308f91469e1fea8723ee555095bf269",
            "title": "refactor(core): conanfile.py 端口到 conan2 (Stage A-1)",
            "observedAt": "2026-06-17T02:54:15Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "77d126a3bc3abbbafa2c984921f100f5ab49bb49",
            "url": "https://github.com/kungfu-systems/kungfu/commit/77d126a3bc3abbbafa2c984921f100f5ab49bb49",
            "title": "refactor(core): 主 CMakeLists 适配 conan2 桥接 (Stage A-2a)",
            "observedAt": "2026-06-17T03:04:38Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "6831fb222d47bb183752ff30560767bf251e2f01",
            "url": "https://github.com/kungfu-systems/kungfu/commit/6831fb222d47bb183752ff30560767bf251e2f01",
            "title": "docs(v4): 摸清欠债② libnode→dist 真实形态并落档(排序调整)",
            "observedAt": "2026-06-17T03:15:30Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "7f57c318d78aed8686f0b9642cd0a5e80eb0a6e0",
            "url": "https://github.com/kungfu-systems/kungfu/commit/7f57c318d78aed8686f0b9642cd0a5e80eb0a6e0",
            "title": "docs(v4): 记录欠债② libnode→dist 双平台落位完成",
            "observedAt": "2026-06-17T03:25:08Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "103b66851dcaa647f1ca9a5abeb151e4a0828128",
            "url": "https://github.com/kungfu-systems/kungfu/commit/103b66851dcaa647f1ca9a5abeb151e4a0828128",
            "title": "docs(v4): 立 v4 产品长期目标与分阶段实施计划(恢复点)",
            "observedAt": "2026-06-17T03:53:41Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "ad0f812e14e54e0f40ed1db5faa10112657347e6",
            "url": "https://github.com/kungfu-systems/kungfu/commit/ad0f812e14e54e0f40ed1db5faa10112657347e6",
            "title": "build(core): kungfu-core devDep 升级 + 真实绑定首编 (A-2b 进行中)",
            "observedAt": "2026-06-17T04:18:08Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "0d5db708abbcf0fbb2c9fda9541a55d8d888e47b",
            "url": "https://github.com/kungfu-systems/kungfu/commit/0d5db708abbcf0fbb2c9fda9541a55d8d888e47b",
            "title": "docs(v4): A-2b cmake-js+conan2 集成打通(node+electron，Mac)",
            "observedAt": "2026-06-17T05:09:03Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "f2a0bd93c4ab12363ad3bfab302f52daaff62609",
            "url": "https://github.com/kungfu-systems/kungfu/commit/f2a0bd93c4ab12363ad3bfab302f52daaff62609",
            "title": "build(core): A-2b Mac 侧收尾(Python pin/run-conan conan2/electron) ①②③",
            "observedAt": "2026-06-17T06:38:24Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "c859683a262e3912106e52140c4e7a4bb1e17a8c",
            "url": "https://github.com/kungfu-systems/kungfu/commit/c859683a262e3912106e52140c4e7a4bb1e17a8c",
            "title": "chore(core): gitignore conan2/cmake 构建工件",
            "observedAt": "2026-06-17T07:11:19Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "2149a187862b65f92d7e62d80e12580beb8bb0ee",
            "url": "https://github.com/kungfu-systems/kungfu/commit/2149a187862b65f92d7e62d80e12580beb8bb0ee",
            "title": "docs(v4): A-2b 双平台闭环完成(node+electron 真实绑定)",
            "observedAt": "2026-06-17T07:22:17Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "ae8b29a0b96c90f10d8442b5de4502001b65363a",
            "url": "https://github.com/kungfu-systems/kungfu/commit/ae8b29a0b96c90f10d8442b5de4502001b65363a",
            "title": "docs(v4): Stage C(freeze+kfc)分析与前置决策",
            "observedAt": "2026-06-17T08:29:58Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "2600b382b8ae2287d0c845023ddf41dadbe2b2c6",
            "url": "https://github.com/kungfu-systems/kungfu/commit/2600b382b8ae2287d0c845023ddf41dadbe2b2c6",
            "title": "build(core): Stage C 基础 — Python 栈现代化到 3.13(pyproject+Pipfile)",
            "observedAt": "2026-06-17T08:52:24Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "44c02919758ed7aaeb516106131e151ed6f4be18",
            "url": "https://github.com/kungfu-systems/kungfu/commit/44c02919758ed7aaeb516106131e151ed6f4be18",
            "title": "build(core): Stage C env bootstrap 通过 — Python 3.13 数据栈解析+安装成功",
            "observedAt": "2026-06-17T09:19:52Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "6b95fe388cd83ccc531391613b627f6e8dded528",
            "url": "https://github.com/kungfu-systems/kungfu/commit/6b95fe388cd83ccc531391613b627f6e8dded528",
            "title": "fix(python): kfc 适配 click 8.1.7+ (F→本地 TypeVar)",
            "observedAt": "2026-06-17T09:37:33Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "29f6685d18995d45a70bc96c1b4e2ab370ba0093",
            "url": "https://github.com/kungfu-systems/kungfu/commit/29f6685d18995d45a70bc96c1b4e2ab370ba0093",
            "title": "docs(v4): Stage C env bootstrap + kfc 运行验证完成(记录+下一步 Nuitka freeze)",
            "observedAt": "2026-06-17T09:41:43Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "d0e969649e570a78a5e39d08fd2ab7c5d66d2db6",
            "url": "https://github.com/kungfu-systems/kungfu/commit/d0e969649e570a78a5e39d08fd2ab7c5d66d2db6",
            "title": "docs(v4): Nuitka freeze 进展与卡点(bundle 出+卡 certifi/stdlib)",
            "observedAt": "2026-06-17T12:43:27Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "f0c2886a5fd8e2483b36c6575f093e9ffe02a04b",
            "url": "https://github.com/kungfu-systems/kungfu/commit/f0c2886a5fd8e2483b36c6575f093e9ffe02a04b",
            "title": "build(core): 数据栈加 plotly 6.8(kfc freeze include-package=plotly 需要)",
            "observedAt": "2026-06-17T12:48:37Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "28f4f9cadbc8219d2f66eaebee7948022bf335a1",
            "url": "https://github.com/kungfu-systems/kungfu/commit/28f4f9cadbc8219d2f66eaebee7948022bf335a1",
            "title": "build(core): kfc Nuitka freeze 调通(升 4.1.2 修 certifi)，kfc.bin 独立运行",
            "observedAt": "2026-06-17T14:45:01Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "4e4127d888d58228c0a1a085a0e64edabfb57d0e",
            "url": "https://github.com/kungfu-systems/kungfu/commit/4e4127d888d58228c0a1a085a0e64edabfb57d0e",
            "title": "chore(core): poetry.lock 重锁匹配 nuitka ~4.1(Linux freeze 用 4.1.2)",
            "observedAt": "2026-06-17T23:17:05Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "4e85bf22a7c008b2c2e5d8e7268be0037b358109",
            "url": "https://github.com/kungfu-systems/kungfu/commit/4e85bf22a7c008b2c2e5d8e7268be0037b358109",
            "title": "docs(core): 记录 Stage C Linux freeze 调通，双平台 kfc 独立运行完成",
            "observedAt": "2026-06-18T00:18:37Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "3ab57f1cdd170498ece61113a46a673f88338a1a",
            "url": "https://github.com/kungfu-systems/kungfu/commit/3ab57f1cdd170498ece61113a46a673f88338a1a",
            "title": "build(core): Stage C 收尾 — freeze 入口脚本化 + kungfubuildinfo 自动化",
            "observedAt": "2026-06-18T01:20:53Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "ddbaf32b2cddc266349641c544dee2e03cacc9bd",
            "url": "https://github.com/kungfu-systems/kungfu/commit/ddbaf32b2cddc266349641c544dee2e03cacc9bd",
            "title": "build(core): Windows 端口 — libkungfu 改 STATIC 解 LNK1189，Stage D GUI 路径跑通",
            "observedAt": "2026-06-18T05:52:08Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "4c26196e7826311273cbee0684cfc492a0eadc00",
            "url": "https://github.com/kungfu-systems/kungfu/commit/4c26196e7826311273cbee0684cfc492a0eadc00",
            "title": "chore(core): .v4 退役 — bootstrap 删除，文档迁 framework/core/docs",
            "observedAt": "2026-06-18T11:17:43Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "faea6ad26076269f2608408924c382c6c3936595",
            "url": "https://github.com/kungfu-systems/kungfu/commit/faea6ad26076269f2608408924c382c6c3936595",
            "title": "chore(core): P0 收尾 — Windows cppstd=17 固化进 run-conan + ⑤⑦ 落档",
            "observedAt": "2026-06-18T14:23:05Z"
          },
          {
            "agent": "Claude",
            "markerType": "agent-field",
            "marker": "Agent: Claude (Code)",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "7f7aab5fa4c2d52a283e6b6e5192d79bf8e3c2c2",
            "url": "https://github.com/kungfu-systems/kungfu/commit/7f7aab5fa4c2d52a283e6b6e5192d79bf8e3c2c2",
            "title": "feat(longfist,ledger): born-FB Asset(第四类型) + Position/Asset ledger 写侧 dual-write(默认 OFF)",
            "observedAt": "2026-06-22T11:02:39Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "8c51591dd3c0c834fa16d946752c51890cd7233e",
            "url": "https://github.com/kungfu-systems/kungfu/commit/8c51591dd3c0c834fa16d946752c51890cd7233e",
            "title": "feat(config): make Kungfu config contract-first",
            "observedAt": "2026-07-06T03:12:14Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "2132071b0c6efe8651026334fb789b009145be40",
            "url": "https://github.com/kungfu-systems/kungfu/commit/2132071b0c6efe8651026334fb789b009145be40",
            "title": "feat(storage): move atlas integrity checks into core",
            "observedAt": "2026-07-08T15:37:01Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "f93c90c726e13a15d2d82fc925fd5a9d4e0a8e66",
            "url": "https://github.com/kungfu-systems/kungfu/commit/f93c90c726e13a15d2d82fc925fd5a9d4e0a8e66",
            "title": "docs(mission-control): design workspace product flow",
            "observedAt": "2026-07-11T15:46:26Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "42c0107dff94ad56485cd39a93cbd2172306b206",
            "url": "https://github.com/kungfu-systems/kungfu/commit/42c0107dff94ad56485cd39a93cbd2172306b206",
            "title": "perf(yijinjing): avoid transaction frame refcounts",
            "observedAt": "2026-07-12T08:04:32Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "eceb82e66481e5d8ea42e2ba112ee389c46233de",
            "url": "https://github.com/kungfu-systems/kungfu/commit/eceb82e66481e5d8ea42e2ba112ee389c46233de",
            "title": "fix(yijinjing): contain compatibility deprecation warnings",
            "observedAt": "2026-07-12T08:04:32Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "a8393059cb18bf6ec3cf25ea23301b1da2697254",
            "url": "https://github.com/kungfu-systems/kungfu/commit/a8393059cb18bf6ec3cf25ea23301b1da2697254",
            "title": "test(yijinjing): stabilize transaction qualification",
            "observedAt": "2026-07-12T08:04:32Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "26b97c3b9af68c808d5d0da89c0e3c50c1c5f080",
            "url": "https://github.com/kungfu-systems/kungfu/commit/26b97c3b9af68c808d5d0da89c0e3c50c1c5f080",
            "title": "perf(yijinjing): qualify lifetime ownership costs",
            "observedAt": "2026-07-12T08:04:32Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "527d8c1f954ba6bd540451e3b9f526be5ed5a28a",
            "url": "https://github.com/kungfu-systems/kungfu/commit/527d8c1f954ba6bd540451e3b9f526be5ed5a28a",
            "title": "fix(yijinjing): isolate reader management snapshots",
            "observedAt": "2026-07-12T08:04:32Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "e8d1d6d26d6199e39bccfb34118a595bb9ae5471",
            "url": "https://github.com/kungfu-systems/kungfu/commit/e8d1d6d26d6199e39bccfb34118a595bb9ae5471",
            "title": "feat(yijinjing): add exception-safe writer transactions",
            "observedAt": "2026-07-12T08:04:32Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "a296e6dfdf3a43340093accafbee646ef97ea821",
            "url": "https://github.com/kungfu-systems/kungfu/commit/a296e6dfdf3a43340093accafbee646ef97ea821",
            "title": "fix(runtime): make error stop ownership local",
            "observedAt": "2026-07-12T08:55:18Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "3fd04734143d4ffb252aab33b3838fb8276c3eba",
            "url": "https://github.com/kungfu-systems/kungfu/commit/3fd04734143d4ffb252aab33b3838fb8276c3eba",
            "title": "docs(core): define strong durability and recovery path",
            "observedAt": "2026-07-12T09:46:09Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/root",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "6ecd48e6b1a89097430c907122df88b27eabb848",
            "url": "https://github.com/kungfu-systems/kungfu/commit/6ecd48e6b1a89097430c907122df88b27eabb848",
            "title": "feat(profile): add generic composition manager",
            "observedAt": "2026-07-12T18:40:27Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/root",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "0cc689769fd74326856ec19bf63a8811ce72dfd4",
            "url": "https://github.com/kungfu-systems/kungfu/commit/0cc689769fd74326856ec19bf63a8811ce72dfd4",
            "title": "feat(profile): bind assessments to exact query cuts",
            "observedAt": "2026-07-12T18:40:27Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/root",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "45ff4dfa94f0ee1d288cf8213f9f6d7529336a07",
            "url": "https://github.com/kungfu-systems/kungfu/commit/45ff4dfa94f0ee1d288cf8213f9f6d7529336a07",
            "title": "fix(profile): require installed composition schemas",
            "observedAt": "2026-07-12T18:40:27Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/root",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "7353682b28e99229eb7b1e1ee531b854e2714e17",
            "url": "https://github.com/kungfu-systems/kungfu/commit/7353682b28e99229eb7b1e1ee531b854e2714e17",
            "title": "feat(profile): expose composition query plans",
            "observedAt": "2026-07-12T18:40:27Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/root",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "e554acf2ef58236af6b9c2c84fdf103352191bab",
            "url": "https://github.com/kungfu-systems/kungfu/commit/e554acf2ef58236af6b9c2c84fdf103352191bab",
            "title": "feat(profile): start generic composition catalog",
            "observedAt": "2026-07-12T18:40:27Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "0aa72aedc310b8b42d8fbc323406fcd034f63b32",
            "url": "https://github.com/kungfu-systems/kungfu/commit/0aa72aedc310b8b42d8fbc323406fcd034f63b32",
            "title": "fix(gui): inject complete KFX shared-module contract",
            "observedAt": "2026-07-14T01:16:07Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "b9862da2a0187316037b2f7774d20ca339c089a8",
            "url": "https://github.com/kungfu-systems/kungfu/commit/b9862da2a0187316037b2f7774d20ca339c089a8",
            "title": "feat(project-cut): admit live completion episode",
            "observedAt": "2026-07-17T14:38:04Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "aa3cdede12708b95d3859e71361e06955dff0218",
            "url": "https://github.com/kungfu-systems/kungfu/commit/aa3cdede12708b95d3859e71361e06955dff0218",
            "title": "test(project-cut): seal live go completion episode",
            "observedAt": "2026-07-17T14:38:04Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/019f7402-9d55-70f1-b562-1d2dfd86036b",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "c1ab522675d653261962c5d66f016bd5e690ecb0",
            "url": "https://github.com/kungfu-systems/kungfu/commit/c1ab522675d653261962c5d66f016bd5e690ecb0",
            "title": "fix(fact): harden portable protocol validation",
            "observedAt": "2026-07-20T14:20:14Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/root",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "9daacb38a91e406e07654ec6b1fdf4a9e833b0df",
            "url": "https://github.com/kungfu-systems/kungfu/commit/9daacb38a91e406e07654ec6b1fdf4a9e833b0df",
            "title": "chore(project-cut): bind linear invariant qualification",
            "observedAt": "2026-07-20T18:41:25Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/root",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "a2762d18251f8630fdd0c9791ea4a5be2c13e5a8",
            "url": "https://github.com/kungfu-systems/kungfu/commit/a2762d18251f8630fdd0c9791ea4a5be2c13e5a8",
            "title": "fix(invariant): qualify Fact native harness cross-platform",
            "observedAt": "2026-07-20T18:41:25Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/root",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "8aa1f9ab9a9eee6129be3e43ac6e0acb971da135",
            "url": "https://github.com/kungfu-systems/kungfu/commit/8aa1f9ab9a9eee6129be3e43ac6e0acb971da135",
            "title": "chore(project-cut): publish Agent Hub trunk successor",
            "observedAt": "2026-07-20T22:39:04Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/019f7d00-2611-7603-bfa5-716304dfc6cc",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "ffe68d7ff52d71cb99cd486053cf298547811e17",
            "url": "https://github.com/kungfu-systems/kungfu/commit/ffe68d7ff52d71cb99cd486053cf298547811e17",
            "title": "docs(core): bind queue-linear KFD-7 ABI cut",
            "observedAt": "2026-07-20T22:42:22Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/019f7d00-2611-7603-bfa5-716304dfc6cc",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "b95b1f459d6ebf02fc5395fe5c05be3a1dfbd7ce",
            "url": "https://github.com/kungfu-systems/kungfu/commit/b95b1f459d6ebf02fc5395fe5c05be3a1dfbd7ce",
            "title": "chore(project-cut): collapse superseded KFD-7 cuts",
            "observedAt": "2026-07-20T22:42:22Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/019f7d00-2611-7603-bfa5-716304dfc6cc",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "c7df73a2bcf724709df552120e0ff2957f58fdca",
            "url": "https://github.com/kungfu-systems/kungfu/commit/c7df73a2bcf724709df552120e0ff2957f58fdca",
            "title": "docs(core): bind rebased KFD-7 ABI successor cut",
            "observedAt": "2026-07-20T22:42:22Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/019f7d00-2611-7603-bfa5-716304dfc6cc",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "465c3b27dff85fe229b1f8cabb04bda92d703fd7",
            "url": "https://github.com/kungfu-systems/kungfu/commit/465c3b27dff85fe229b1f8cabb04bda92d703fd7",
            "title": "test(fact): preserve typed ledger boundary assertions",
            "observedAt": "2026-07-20T22:42:22Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "054148cbb45ff607d7cc5d282649485928814390",
            "url": "https://github.com/kungfu-systems/kungfu/commit/054148cbb45ff607d7cc5d282649485928814390",
            "title": "chore(project-cut): republish empty-delta cut on current merge base tip",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "4cfceb9392d90cb9cfb80b75afd45feb98579460",
            "url": "https://github.com/kungfu-systems/kungfu/commit/4cfceb9392d90cb9cfb80b75afd45feb98579460",
            "title": "chore(project-cut): drop cut drifted by intervening merge-queue tip",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "218a6cb16552950ae58699c8994a62d6d23f083a",
            "url": "https://github.com/kungfu-systems/kungfu/commit/218a6cb16552950ae58699c8994a62d6d23f083a",
            "title": "chore(project-cut): republish empty-delta cut on merge-queue tip",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "dbad3bdfe7b08c42bc70486f082961b846c8c640",
            "url": "https://github.com/kungfu-systems/kungfu/commit/dbad3bdfe7b08c42bc70486f082961b846c8c640",
            "title": "chore(project-cut): drop rebase-drifted empty-delta cut before republish",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "657a6131eb42f0e311c198b97de115d257b97a90",
            "url": "https://github.com/kungfu-systems/kungfu/commit/657a6131eb42f0e311c198b97de115d257b97a90",
            "title": "chore(project-cut): publish final empty-delta cut for native action authority",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "6a411bd6bf428ec34531959f36de9c61033cf224",
            "url": "https://github.com/kungfu-systems/kungfu/commit/6a411bd6bf428ec34531959f36de9c61033cf224",
            "title": "chore(project-cut): drop overlapping pre/post-rebase cut publications",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "64aa1f437e34dad40ae45de1695ef4740e405224",
            "url": "https://github.com/kungfu-systems/kungfu/commit/64aa1f437e34dad40ae45de1695ef4740e405224",
            "title": "fix(core): sync ADR-0123 delivery evidence and architecture health projections",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "ff4232a65f43541bff65e2caca02602a2384e946",
            "url": "https://github.com/kungfu-systems/kungfu/commit/ff4232a65f43541bff65e2caca02602a2384e946",
            "title": "fix(core): repair architecture projections after rebase",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "2c59c4cf1ccd4351663d080e39565199eae324ca",
            "url": "https://github.com/kungfu-systems/kungfu/commit/2c59c4cf1ccd4351663d080e39565199eae324ca",
            "title": "chore(project-cut): republish empty-delta cut after rebase onto dev/v4/v4.0",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "0357cb17bb406af7e3846c13eb53c28eb0fab83d",
            "url": "https://github.com/kungfu-systems/kungfu/commit/0357cb17bb406af7e3846c13eb53c28eb0fab83d",
            "title": "chore(project-cut): stage empty-delta cut for action-geometry native authority",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "ff9dc497a8eb96cf99690c735497a3b41a24780e",
            "url": "https://github.com/kungfu-systems/kungfu/commit/ff9dc497a8eb96cf99690c735497a3b41a24780e",
            "title": "test(core): shadow-compare action_runtime and confirm authority flip",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "7691fff485bca47c03baad870bcd8374e6f49ec1",
            "url": "https://github.com/kungfu-systems/kungfu/commit/7691fff485bca47c03baad870bcd8374e6f49ec1",
            "title": "feat(core): wire action_runtime edge and Python shims",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "a3795a79b7419167022b4d2505b0caf5b84ec136",
            "url": "https://github.com/kungfu-systems/kungfu/commit/a3795a79b7419167022b4d2505b0caf5b84ec136",
            "title": "feat(core): port Profile action orchestration to libkungfu",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "a2339161d158130190cbc86cc6ae674bd473f463",
            "url": "https://github.com/kungfu-systems/kungfu/commit/a2339161d158130190cbc86cc6ae674bd473f463",
            "title": "feat(core): port Domain Profile engine to libkungfu",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "9b1bec9965c20d64fc1ae776aa1718261762368b",
            "url": "https://github.com/kungfu-systems/kungfu/commit/9b1bec9965c20d64fc1ae776aa1718261762368b",
            "title": "feat(core): port Action Geometry evaluator to libkungfu",
            "observedAt": "2026-07-21T05:05:20Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "610ef7c9bb61953e85a8b8cd0972a49a0b32b9bb",
            "url": "https://github.com/kungfu-systems/kungfu/commit/610ef7c9bb61953e85a8b8cd0972a49a0b32b9bb",
            "title": "chore(xinfa): record portable shim cut",
            "observedAt": "2026-07-21T06:57:59Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "ce3e846c10b07d1239bc5742e210aaf72a112815",
            "url": "https://github.com/kungfu-systems/kungfu/commit/ce3e846c10b07d1239bc5742e210aaf72a112815",
            "title": "fix(xinfa): let Node invoke Windows shim",
            "observedAt": "2026-07-21T06:57:59Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "fadac5121d0b36b5a89b0c25d860447ff4ab5b36",
            "url": "https://github.com/kungfu-systems/kungfu/commit/fadac5121d0b36b5a89b0c25d860447ff4ab5b36",
            "title": "chore(xinfa): record Windows qualification cut",
            "observedAt": "2026-07-21T06:57:59Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "693a44d4927c1401b28f9e5bf079c4c3b04dd02f",
            "url": "https://github.com/kungfu-systems/kungfu/commit/693a44d4927c1401b28f9e5bf079c4c3b04dd02f",
            "title": "fix(xinfa): qualify wasm shim on Windows",
            "observedAt": "2026-07-21T06:57:59Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "1a9e6355b4b162e37a1b9ef01c06b7cc91724038",
            "url": "https://github.com/kungfu-systems/kungfu/commit/1a9e6355b4b162e37a1b9ef01c06b7cc91724038",
            "title": "chore(project-cut): bind refreshed Xinfa context",
            "observedAt": "2026-07-21T10:50:44Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "5e303f2c464b8ebe2d77f87c0a08be231afc212d",
            "url": "https://github.com/kungfu-systems/kungfu/commit/5e303f2c464b8ebe2d77f87c0a08be231afc212d",
            "title": "chore(project-cut): rebind workspace migration to current dev",
            "observedAt": "2026-07-21T10:50:44Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "f4adf4c5dbd6c2a7781b8dc58182734585a0185c",
            "url": "https://github.com/kungfu-systems/kungfu/commit/f4adf4c5dbd6c2a7781b8dc58182734585a0185c",
            "title": "fix(storage): close workspace layout coverage gaps",
            "observedAt": "2026-07-21T20:24:42Z"
          },
          {
            "agent": "Amp",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Amp",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "8857b44ff5ced6328524508639f30353238f63ed",
            "url": "https://github.com/kungfu-systems/kungfu/commit/8857b44ff5ced6328524508639f30353238f63ed",
            "title": "chore(project-cut): publish composition-replay settlement witness for cut 551ba04b",
            "observedAt": "2026-07-21T22:44:42Z"
          },
          {
            "agent": "Amp",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Amp",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "152eaea082d506e0f24fc559707e9a538615e69e",
            "url": "https://github.com/kungfu-systems/kungfu/commit/152eaea082d506e0f24fc559707e9a538615e69e",
            "title": "fix(project-cut): replay squash-published cut chains order-independently",
            "observedAt": "2026-07-21T22:44:42Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "2901313005f7c9f7cfc31ac67cc4787bc979a74e",
            "url": "https://github.com/kungfu-systems/kungfu/commit/2901313005f7c9f7cfc31ac67cc4787bc979a74e",
            "title": "style(work): format facade contract test",
            "observedAt": "2026-07-22T04:22:11Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "c09d3be1cf4a586ee1b15a4d56fdffd042f1693e",
            "url": "https://github.com/kungfu-systems/kungfu/commit/c09d3be1cf4a586ee1b15a4d56fdffd042f1693e",
            "title": "fix(work): preserve runtime and Cut authority boundaries",
            "observedAt": "2026-07-22T04:22:11Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "46df537e1b3c2868fb5eb1a70ed11281eafb59ff",
            "url": "https://github.com/kungfu-systems/kungfu/commit/46df537e1b3c2868fb5eb1a70ed11281eafb59ff",
            "title": "docs(adr): bind Project Cut facade delivery",
            "observedAt": "2026-07-22T04:22:11Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "f5a9025a605feb4d57e2a386031a0da22d4499b5",
            "url": "https://github.com/kungfu-systems/kungfu/commit/f5a9025a605feb4d57e2a386031a0da22d4499b5",
            "title": "docs(adr): define Project Cut Work facade",
            "observedAt": "2026-07-22T04:22:11Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "969f6148881f99da6a81b559efd69b8ad6bb4f04",
            "url": "https://github.com/kungfu-systems/kungfu/commit/969f6148881f99da6a81b559efd69b8ad6bb4f04",
            "title": "feat(work): bind managed runs and settlement plans",
            "observedAt": "2026-07-22T04:22:11Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "f24b67efd285858d7c85c128cc37c844b35390e2",
            "url": "https://github.com/kungfu-systems/kungfu/commit/f24b67efd285858d7c85c128cc37c844b35390e2",
            "title": "feat(work): add Project Cut facade read model",
            "observedAt": "2026-07-22T04:22:11Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "06fb9eb5465e14bfc3344e224a2f5e10baaca924",
            "url": "https://github.com/kungfu-systems/kungfu/commit/06fb9eb5465e14bfc3344e224a2f5e10baaca924",
            "title": "chore(project-cut): bind 088 queue baseline",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "6b753fa3633a75876da1b2e691c779f51f4fd186",
            "url": "https://github.com/kungfu-systems/kungfu/commit/6b753fa3633a75876da1b2e691c779f51f4fd186",
            "title": "chore(project-cut): bind 0bee queue baseline",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "445127935ff72c24a0e9e095ee718ffa507bb92e",
            "url": "https://github.com/kungfu-systems/kungfu/commit/445127935ff72c24a0e9e095ee718ffa507bb92e",
            "title": "chore(project-cut): bind a297 queue baseline",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "dcf11a4afdcd6d02e4f16f7985a46afca6551c43",
            "url": "https://github.com/kungfu-systems/kungfu/commit/dcf11a4afdcd6d02e4f16f7985a46afca6551c43",
            "title": "chore(project-cut): bind final rebased baseline",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "bec10e401e7a404844f1f9802a75604ae14e3c7e",
            "url": "https://github.com/kungfu-systems/kungfu/commit/bec10e401e7a404844f1f9802a75604ae14e3c7e",
            "title": "chore(project-cut): bind final queue baseline",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "e9fce77cef2b462bea2743edff00ef4500543445",
            "url": "https://github.com/kungfu-systems/kungfu/commit/e9fce77cef2b462bea2743edff00ef4500543445",
            "title": "chore(project-cut): bind verified completion evidence",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "98c99300d0eff4e5cf1bd9391a3b59009d849207",
            "url": "https://github.com/kungfu-systems/kungfu/commit/98c99300d0eff4e5cf1bd9391a3b59009d849207",
            "title": "chore(project-cut): seal verified integration episode",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "b5f3508b5a61e63c83e3442648d98739b48b2b3d",
            "url": "https://github.com/kungfu-systems/kungfu/commit/b5f3508b5a61e63c83e3442648d98739b48b2b3d",
            "title": "chore(project-cut): admit queue integration",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "20dd3cc0b04b18bd621ce50bac7108cdb1987e6e",
            "url": "https://github.com/kungfu-systems/kungfu/commit/20dd3cc0b04b18bd621ce50bac7108cdb1987e6e",
            "title": "chore(project-cut): seal queue integration evidence",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "25a0d13f081324101ecfcebed7fd1b4c6cf341cc",
            "url": "https://github.com/kungfu-systems/kungfu/commit/25a0d13f081324101ecfcebed7fd1b4c6cf341cc",
            "title": "chore(project-cut): bind protected queue baseline",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "55d2ab229611dae8b18b76d5247f148024f4c73b",
            "url": "https://github.com/kungfu-systems/kungfu/commit/55d2ab229611dae8b18b76d5247f148024f4c73b",
            "title": "chore(project-cut): bind latest dev baseline",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "4516a55d3f0ba8a4e2e1d9d7d4cd1fbcf768ef68",
            "url": "https://github.com/kungfu-systems/kungfu/commit/4516a55d3f0ba8a4e2e1d9d7d4cd1fbcf768ef68",
            "title": "chore(project-cut): bind Windows fixture qualification",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "148a179d4b94a51641d733eafac9d9ca58367eb6",
            "url": "https://github.com/kungfu-systems/kungfu/commit/148a179d4b94a51641d733eafac9d9ca58367eb6",
            "title": "test(core): make API fixture cleanup non-throwing",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "b9b91128007cd92ea1717543849402175545244a",
            "url": "https://github.com/kungfu-systems/kungfu/commit/b9b91128007cd92ea1717543849402175545244a",
            "title": "chore(project-cut): bind locked source transport",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "026a0724115316faa28e3a2de26c344b8f02022c",
            "url": "https://github.com/kungfu-systems/kungfu/commit/026a0724115316faa28e3a2de26c344b8f02022c",
            "title": "ci(gate): persist locked source transport policy",
            "observedAt": "2026-07-23T01:16:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex\\nGoal: 2026-07-23-agent-hub-binary-kfd123-passport-reference\\nMission: kungfu-technical-stewardship",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "b82786544e4474aecd6095b78c641ea2868dfb22",
            "url": "https://github.com/kungfu-systems/kungfu/commit/b82786544e4474aecd6095b78c641ea2868dfb22",
            "title": "fix(assignment): bind admitted work to native source",
            "observedAt": "2026-07-23T06:26:29Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "00bc84e9bc51aff1fc2bc1703853a323d3a9da44",
            "url": "https://github.com/kungfu-systems/kungfu/commit/00bc84e9bc51aff1fc2bc1703853a323d3a9da44",
            "title": "fix(assignment): reject partial source assemblies",
            "observedAt": "2026-07-24T00:23:19Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "f6e6e3e74d64279bb50097decbb63636001522ca",
            "url": "https://github.com/kungfu-systems/kungfu/commit/f6e6e3e74d64279bb50097decbb63636001522ca",
            "title": "fix(assignment): refresh initialized workspace identity",
            "observedAt": "2026-07-24T00:23:19Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "e054d96a7b36fe9aa149108b2a007cc46f8cead9",
            "url": "https://github.com/kungfu-systems/kungfu/commit/e054d96a7b36fe9aa149108b2a007cc46f8cead9",
            "title": "fix(assignment): preserve source admission diagnostics",
            "observedAt": "2026-07-24T00:23:19Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "50d169751e092b34955c4e42c696ca87bf09d3cc",
            "url": "https://github.com/kungfu-systems/kungfu/commit/50d169751e092b34955c4e42c696ca87bf09d3cc",
            "title": "fix(mission-control): authenticate native completion evidence",
            "observedAt": "2026-07-24T03:02:51Z"
          },
          {
            "agent": "Cursor",
            "markerType": "co-author-trailer",
            "marker": "Co-authored-by: Cursor",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "54ed3edce763f156d41991d55c83337abb3780cd",
            "url": "https://github.com/kungfu-systems/kungfu/commit/54ed3edce763f156d41991d55c83337abb3780cd",
            "title": "feat(core): admit native Work journal ownership",
            "observedAt": "2026-07-25T01:59:58Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "589bdf1fd2f794f67414549cf1c85dac2816ddda",
            "url": "https://github.com/kungfu-systems/kungfu/commit/589bdf1fd2f794f67414549cf1c85dac2816ddda",
            "title": "docs(primitive): record authority closure delivery",
            "observedAt": "2026-07-25T03:17:07Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "74d2f5f1894f26d33346ab26b6d2a3ef85a6596a",
            "url": "https://github.com/kungfu-systems/kungfu/commit/74d2f5f1894f26d33346ab26b6d2a3ef85a6596a",
            "title": "feat(primitive): close authority consumption paths",
            "observedAt": "2026-07-25T03:17:07Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: codex/pro-2088/root",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "cbcce6c49b20a6a14da7535ac0fbae9604cda485",
            "url": "https://github.com/kungfu-systems/kungfu/commit/cbcce6c49b20a6a14da7535ac0fbae9604cda485",
            "title": "feat(agent): add repository work experiment",
            "observedAt": "2026-07-27T14:37:40Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "0ebf87ebdb5be31996b2ddb0dc0abf62b1bdafeb",
            "url": "https://github.com/kungfu-systems/kungfu/commit/0ebf87ebdb5be31996b2ddb0dc0abf62b1bdafeb",
            "title": "fix(core): adopt Linux ARM64 libnode package",
            "observedAt": "2026-07-27T19:28:56Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "55c406c91c9ad37b55136a14426d7b31e28140ee",
            "url": "https://github.com/kungfu-systems/kungfu/commit/55c406c91c9ad37b55136a14426d7b31e28140ee",
            "title": "chore(release): refresh qualification projections",
            "observedAt": "2026-07-27T22:06:27Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "d404ada50a2aeaee213436fa97ea95cd27d9cff3",
            "url": "https://github.com/kungfu-systems/kungfu/commit/d404ada50a2aeaee213436fa97ea95cd27d9cff3",
            "title": "fix(release): scope ARM64 Hub qualification to CLI",
            "observedAt": "2026-07-27T22:06:27Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "d22606161449e7c6c84fcbf890506594e55b1b62",
            "url": "https://github.com/kungfu-systems/kungfu/commit/d22606161449e7c6c84fcbf890506594e55b1b62",
            "title": "fix(release): preserve execution context compatibility",
            "observedAt": "2026-07-27T23:06:13Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "e097ed411cceb03a9a390f7b7428c145dc53b30b",
            "url": "https://github.com/kungfu-systems/kungfu/commit/e097ed411cceb03a9a390f7b7428c145dc53b30b",
            "title": "fix(deps): remove stale Buildchain KFD override",
            "observedAt": "2026-07-28T00:28:21Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "eb6e53284f7462208bf65b80e1c25e1b2cbcddf1",
            "url": "https://github.com/kungfu-systems/kungfu/commit/eb6e53284f7462208bf65b80e1c25e1b2cbcddf1",
            "title": "fix(core): consume qualified libnode alpha.3",
            "observedAt": "2026-07-28T00:28:21Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "d68fe84a5935780a933df4e19e6d094ee5fb06ab",
            "url": "https://github.com/kungfu-systems/kungfu/commit/d68fe84a5935780a933df4e19e6d094ee5fb06ab",
            "title": "feat(ci): add dedicated local agent patrol",
            "observedAt": "2026-07-28T09:02:39Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "ce9d80f9bec73813c230cc214c334716b7bc5ca7",
            "url": "https://github.com/kungfu-systems/kungfu/commit/ce9d80f9bec73813c230cc214c334716b7bc5ca7",
            "title": "fix(ci): support rootless Patrol bind mounts",
            "observedAt": "2026-07-28T10:40:53Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "e8cfee73d2569ed6321c7422dae72038ba027596",
            "url": "https://github.com/kungfu-systems/kungfu/commit/e8cfee73d2569ed6321c7422dae72038ba027596",
            "title": "fix(readme): preserve public source signature",
            "observedAt": "2026-07-30T14:31:56Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "c08720588a64c5f597e04bb620dbbbe11f81c488",
            "url": "https://github.com/kungfu-systems/kungfu/commit/c08720588a64c5f597e04bb620dbbbe11f81c488",
            "title": "docs(readme): lead with agent work continuity",
            "observedAt": "2026-07-30T14:31:56Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "b2d71e03f13e804f717182c0fd4cf8f72a2c771f",
            "url": "https://github.com/kungfu-systems/kungfu/commit/b2d71e03f13e804f717182c0fd4cf8f72a2c771f",
            "title": "fix(signing): consume source-bound native identity",
            "observedAt": "2026-07-30T22:39:45Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "e8853e3a364f7d6f76296d513300c8691910b1d1",
            "url": "https://github.com/kungfu-systems/kungfu/commit/e8853e3a364f7d6f76296d513300c8691910b1d1",
            "title": "perf(ci): add auditable Windows compiler cache",
            "observedAt": "2026-07-31T00:50:39Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "b0eccac6a95e22ca5b5c1462451c3039ab6ca42c",
            "url": "https://github.com/kungfu-systems/kungfu/commit/b0eccac6a95e22ca5b5c1462451c3039ab6ca42c",
            "title": "fix(release): align Alpha sentinel with demo catalog",
            "observedAt": "2026-07-31T03:52:09Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "7536ebf8a0157e1e09f92a0dc8bbdea69fae2608",
            "url": "https://github.com/kungfu-systems/kungfu/commit/7536ebf8a0157e1e09f92a0dc8bbdea69fae2608",
            "title": "fix(signing): delegate notarization to Buildchain",
            "observedAt": "2026-07-31T04:32:17Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "0e33bb0dd2b4a9246d0eaf493ec73ea32fa1b6d1",
            "url": "https://github.com/kungfu-systems/kungfu/commit/0e33bb0dd2b4a9246d0eaf493ec73ea32fa1b6d1",
            "title": "fix(release): pin signing lifecycle manifest authority",
            "observedAt": "2026-07-31T07:04:10Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "d423cf756aa3668a0ee48e8e3215bd1740adf629",
            "url": "https://github.com/kungfu-systems/kungfu/commit/d423cf756aa3668a0ee48e8e3215bd1740adf629",
            "title": "fix(kfx): admit Projects capability in Core policy",
            "observedAt": "2026-07-31T08:49:24Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "a5e19ac2287ab0628553d31f81080ffd183429c3",
            "url": "https://github.com/kungfu-systems/kungfu/commit/a5e19ac2287ab0628553d31f81080ffd183429c3",
            "title": "docs(shifu): bind Windows repair PR evidence",
            "observedAt": "2026-07-31T09:52:26Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "1f46a9d43b675e83ac02909d35166b03848ae346",
            "url": "https://github.com/kungfu-systems/kungfu/commit/1f46a9d43b675e83ac02909d35166b03848ae346",
            "title": "fix(shifu): bind Windows consumer to exact closure",
            "observedAt": "2026-07-31T09:52:26Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "99d4e2f2023e3c7b09ec68fc98757f4da0aca89b",
            "url": "https://github.com/kungfu-systems/kungfu/commit/99d4e2f2023e3c7b09ec68fc98757f4da0aca89b",
            "title": "test(shifu): reject registrar artifact size drift",
            "observedAt": "2026-07-31T15:28:27Z"
          },
          {
            "agent": "Codex",
            "markerType": "agent-field",
            "marker": "Agent: Codex",
            "repository": "kungfu-systems/kungfu",
            "branch": "dev/v4/v4.0",
            "sha": "3ffa6a78bcccf56ec7a92d094858df0ab1359807",
            "url": "https://github.com/kungfu-systems/kungfu/commit/3ffa6a78bcccf56ec7a92d094858df0ab1359807",
            "title": "refactor(shifu): share local artifact identity validation",
            "observedAt": "2026-07-31T15:28:27Z"
          }
        ]
      }
    }
  },
  "comparison": {
    "pullRequestRatio": 22.77,
    "changedLinesRatio": 36.28,
    "changedFilesRatio": 43.24,
    "kungfuPrimaryAuthor": {
      "account": "dongkeren",
      "mergedPullRequests": 2261,
      "share": 0.9733
    },
    "publicAuthorLeverage": {
      "unit": "public output per accountable GitHub author identity over the fixed calendar window",
      "kungfuPrimary": {
        "account": "dongkeren",
        "mergedPullRequests": 2261,
        "activeMergeDays": 18,
        "totalAdditions": 1030962,
        "totalDeletions": 305150,
        "grossChangedLines": 1336112,
        "totalChangedFiles": 22703,
        "medianChangedLinesPerPullRequest": 129,
        "central90": {
          "pullRequests": 2035,
          "grossChangedLines": 708321,
          "meanChangedLinesPerPullRequest": 348.07
        },
        "topTenGrossChangedLinesShare": 0.1661
      },
      "axTopAuthor": {
        "account": "rakyll",
        "mergedPullRequests": 53,
        "activeMergeDays": 14,
        "totalAdditions": 4541,
        "totalDeletions": 16223,
        "grossChangedLines": 20764,
        "totalChangedFiles": 316,
        "medianChangedLinesPerPullRequest": 109,
        "central90": {
          "pullRequests": 49,
          "grossChangedLines": 13515,
          "meanChangedLinesPerPullRequest": 275.82
        },
        "topTenGrossChangedLinesShare": 0.7581
      },
      "axTopThree": {
        "accounts": [
          "rakyll",
          "wjjclaud",
          "joycel-github"
        ],
        "combined": {
          "mergedPullRequests": 87,
          "activeMergeDays": 21,
          "totalAdditions": 8470,
          "totalDeletions": 22276,
          "grossChangedLines": 30746,
          "totalChangedFiles": 495,
          "medianChangedLinesPerPullRequest": 118,
          "central90": {
            "pullRequests": 79,
            "grossChangedLines": 17972,
            "meanChangedLinesPerPullRequest": 227.49
          },
          "topTenGrossChangedLinesShare": 0.6313
        },
        "average": {
          "mergedPullRequests": 29,
          "grossChangedLines": 10248.67,
          "totalChangedFiles": 165
        }
      },
      "axAllAuthors": {
        "accounts": [
          "rakyll",
          "wjjclaud",
          "joycel-github",
          "anj-s",
          "zbl94"
        ],
        "combined": {
          "mergedPullRequests": 102,
          "activeMergeDays": 21,
          "totalAdditions": 15516,
          "totalDeletions": 22484,
          "grossChangedLines": 38000,
          "totalChangedFiles": 541,
          "medianChangedLinesPerPullRequest": 141,
          "central90": {
            "pullRequests": 92,
            "grossChangedLines": 23498,
            "meanChangedLinesPerPullRequest": 255.41
          },
          "topTenGrossChangedLinesShare": 0.559
        },
        "average": {
          "mergedPullRequests": 20.4,
          "grossChangedLines": 7600,
          "totalChangedFiles": 108.2
        }
      },
      "ratios": {
        "kungfuPrimaryToAxTopAuthor": {
          "mergedPullRequests": 42.66,
          "grossChangedLines": 64.35,
          "totalChangedFiles": 71.84
        },
        "kungfuPrimaryToAxTopThreeCombined": {
          "mergedPullRequests": 25.99,
          "grossChangedLines": 43.46,
          "totalChangedFiles": 45.86
        },
        "kungfuPrimaryToAxTopThreeAverage": {
          "mergedPullRequests": 77.97,
          "grossChangedLines": 130.37,
          "totalChangedFiles": 137.59
        },
        "kungfuPrimaryToAxAllAuthorsCombined": {
          "mergedPullRequests": 22.17,
          "grossChangedLines": 35.16,
          "totalChangedFiles": 41.96
        },
        "kungfuPrimaryToAxAllAuthorsAverage": {
          "mergedPullRequests": 110.83,
          "grossChangedLines": 175.8,
          "totalChangedFiles": 209.82
        }
      }
    }
  },
  "bootstrapCommitPhase": {
    "repository": "kungfu-systems/kungfu",
    "branch": "dev/v4/v4.0",
    "commits": 99,
    "activeDays": 12,
    "authorAccounts": 2,
    "rolling7": {
      "minimumCommits": 26,
      "maximumCommits": 57,
      "minimumActiveDays": 6,
      "maximumActiveDays": 7,
      "observations": [
        {
          "endDay": "2026-06-22",
          "commits": 47,
          "activeDays": 6
        },
        {
          "endDay": "2026-06-23",
          "commits": 44,
          "activeDays": 6
        },
        {
          "endDay": "2026-06-24",
          "commits": 26,
          "activeDays": 6
        },
        {
          "endDay": "2026-06-25",
          "commits": 26,
          "activeDays": 6
        },
        {
          "endDay": "2026-06-26",
          "commits": 41,
          "activeDays": 7
        },
        {
          "endDay": "2026-06-27",
          "commits": 57,
          "activeDays": 7
        },
        {
          "endDay": "2026-06-28",
          "commits": 54,
          "activeDays": 7
        }
      ]
    },
    "daily": [
      {
        "name": "2026-06-16",
        "count": 8
      },
      {
        "name": "2026-06-17",
        "count": 20
      },
      {
        "name": "2026-06-18",
        "count": 5
      },
      {
        "name": "2026-06-20",
        "count": 5
      },
      {
        "name": "2026-06-21",
        "count": 7
      },
      {
        "name": "2026-06-22",
        "count": 2
      },
      {
        "name": "2026-06-23",
        "count": 5
      },
      {
        "name": "2026-06-24",
        "count": 2
      },
      {
        "name": "2026-06-25",
        "count": 5
      },
      {
        "name": "2026-06-26",
        "count": 15
      },
      {
        "name": "2026-06-27",
        "count": 21
      },
      {
        "name": "2026-06-28",
        "count": 4
      }
    ],
    "records": [
      {
        "sha": "a20748de6117b627d8ad9e41551f53fe7fa9f5f2",
        "url": "https://github.com/kungfu-systems/kungfu/commit/a20748de6117b627d8ad9e41551f53fe7fa9f5f2",
        "committedAt": "2026-06-16T10:01:10Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "build(v4): arm64 点亮 C++ 内核，conan2 + fmt10 现代化",
        "message": "build(v4): arm64 点亮 C++ 内核，conan2 + fmt10 现代化\n\n- 新增 framework/core/.v4 干净 conan2+cmake 内核构建驱动(仅 libkungfu)\n- 升级 fmt 8.1.1→10.2.1 / spdlog 1.10→1.14.1(clang21 拒编 fmt8 consteval)\n- common.h: kungfu::array 加 fmt::ostream_formatter 特化 + fmt/std.h\n- enums.h: enums 命名空间加 ADL format_as(枚举按 int32)\n- 产物 libkungfu.dylib arm64 原生; Step1 恢复点\n\nAgent: Claude (Code)"
      },
      {
        "sha": "01cf26faab988082b65bb0b37a8c35d87df50a6c",
        "url": "https://github.com/kungfu-systems/kungfu/commit/01cf26faab988082b65bb0b37a8c35d87df50a6c",
        "committedAt": "2026-06-16T10:51:20Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "build(v4): Step 2 点亮 Python 绑定 pykungfu，journal 写读往返通过",
        "message": "build(v4): Step 2 点亮 Python 绑定 pykungfu，journal 写读往返通过\n\nconan2 装 pybind11/2.13.6，CMake 加 KFV4_BUILD_PYTHON 开关编精简 pykungfu\n(只绑 longfist + yijinjing)。pykungfu_lightup.cpp 用 C++ noop_publisher\n(实现 resource/publisher 全部纯虚)解决 Python 子类化抽象基类问题。\ntest_journal_roundtrip.py 验证 Python 经 journal 写一帧 Quote 再读回字段一致。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "1599ab1cc50a2eeef0f7f4dfd54b8d2030f674b8",
        "url": "https://github.com/kungfu-systems/kungfu/commit/1599ab1cc50a2eeef0f7f4dfd54b8d2030f674b8",
        "committedAt": "2026-06-16T11:29:29Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "build(v4): Step 3 点亮 Node 绑定 kungfu_node，三语言共享同一条 journal",
        "message": "build(v4): Step 3 点亮 Node 绑定 kungfu_node，三语言共享同一条 journal\n\n标准 N-API addon kungfu_node(只绑 longfist + journal 读取)，对系统 Node 22 +\nnode-addon-api 8 编，不依赖 libnode(进程内嵌 Node 是 Step 4 的事)。CMake 加\nKFV4_BUILD_NODE 开关；node-addon-api 经 .v4/node npm 装(header-only)。\n\ntest_cross_lang.sh 编排 Python 写一帧 Quote → Node 读回同一帧，genTime 完全一致，\n打通 C++(libkungfu)/Python(pykungfu)/Node(kungfu_node) 共享 yijinjing journal。\n\n关键坑：①NODE_API_MODULE 对 regfunc 做 token 粘贴须传未限定标识符；②node-addon-api 8\n的 include_dir 是相对 cwd 路径须补绝对；③现有 Node Reader 写死 GetDefaultRuntimeLocator，\n只认 KF_RUNTIME_DIR，读自定义目录须设该环境变量(编排器已处理)。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "5f3ab0786cba51bde94b6a075c8720c913bf6143",
        "url": "https://github.com/kungfu-systems/kungfu/commit/5f3ab0786cba51bde94b6a075c8720c913bf6143",
        "committedAt": "2026-06-16T12:15:12Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "build(v4): Step 4 点亮单进程三语言联动，技术终点达成",
        "message": "build(v4): Step 4 点亮单进程三语言联动，技术终点达成\n\narm64 从源码 --shared 编出 Node 22 libnode(ABI 127)，pykungfu 经\npy-libnode.cpp 的 node::Start 在本进程内启真正的 Node。CMake 加\nKFV4_BUILD_LIBNODE 开关 + KFV4_LIBNODE_DIR(不写死进仓库，configure 传入)。\n\ntest_single_process.py 验证：单个 Python 进程内(全程同一 pid) Python 写一帧\nQuote → node::Start 启 Node 读回同一帧 → 干净返回 Python。objective 达成：\narm64 原生、C++/Python/Node 单进程零拷贝、共享同一条 yijinjing journal 的运行时。\n\nNode22 的 node.h 仍导出 node::Start(int,char**)，py-libnode.cpp 未改。\nlibnode 编译 ~9min@M1Ultra，clang21 仅 deprecation 警告无 error。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "d07fe5a894b55a4600c360e194b27206ac40ff69",
        "url": "https://github.com/kungfu-systems/kungfu/commit/d07fe5a894b55a4600c360e194b27206ac40ff69",
        "committedAt": "2026-06-16T15:05:18Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "build(v4): .v4 跨平台适配 Linux(rpath/linker/测试脚本)",
        "message": "build(v4): .v4 跨平台适配 Linux(rpath/linker/测试脚本)\n\nLinux 版 kungfu4 开发：Step 1(libkungfu)在 Ubuntu gcc13 零改动编绿(libkungfu.so)。\n为 Step 2/3 跨平台：rpath 起点 @loader_path(mac)/$ORIGIN(linux)；-undefined\ndynamic_lookup 仅 APPLE(Linux 共享对象默认放行未定义符号)；libnode glob 区分\n.dylib/.so.*；test_cross_lang.sh 按 OS 探测 PY/NODE、Linux 去 arch -arm64。\nMac 行为不变(全部 if(APPLE) 条件保留原值)。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "fa4feb44e7cc39bc71c6f53b44545e1c6a88bac7",
        "url": "https://github.com/kungfu-systems/kungfu/commit/fa4feb44e7cc39bc71c6f53b44545e1c6a88bac7",
        "committedAt": "2026-06-16T15:17:33Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "fix(yijinjing): time.h 显式 #include <cstdint> 修 gcc13 编译",
        "message": "fix(yijinjing): time.h 显式 #include <cstdint> 修 gcc13 编译\n\nLinux/gcc13(新 libstdc++)收紧传递包含，time.h 用 uint32_t/int64_t 却未引\ncstdint，node/python 绑定 TU 在 gcc 下报 \"uint32_t does not name a type\"\n(clang21 靠传递包含侥幸通过)。补 cstdint 后 Linux Step 1–3 全绿：Python 写、\nNode 读同一 journal 往返成功。对 Mac 无害。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "77ee308fb5f66a6a7f57fb095da5f4d4a0dba4c5",
        "url": "https://github.com/kungfu-systems/kungfu/commit/77ee308fb5f66a6a7f57fb095da5f4d4a0dba4c5",
        "committedAt": "2026-06-16T16:01:07Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "fix(v4): Linux 单进程内嵌设 RTLD_GLOBAL，修 napi_* undefined symbol",
        "message": "fix(v4): Linux 单进程内嵌设 RTLD_GLOBAL，修 napi_* undefined symbol\n\nLinux 默认 RTLD_LOCAL 载入扩展模块，pykungfu 经 DT_NEEDED 带入的 libnode 的\nnapi_* 符号不进全局符号域，内嵌 Node dlopen kungfu_node.node 时报 undefined\nsymbol: napi_create_error。import pykungfu 前在 Linux 设 RTLD_NOW|RTLD_GLOBAL\n解决。macOS dyld 平面查找 + dynamic_lookup 已处理，仅 Linux 生效。\n\n至此 Linux x86_64 Step 1–4 全绿：单进程内(同一 pid)Python 写、node::Start\n启 Node 读同一条 journal —— Linux 版三语言联动点亮，与 Mac arm64 对齐。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "0e41c8e0257ed5c199f18de93be43bc925a54780",
        "url": "https://github.com/kungfu-systems/kungfu/commit/0e41c8e0257ed5c199f18de93be43bc925a54780",
        "committedAt": "2026-06-16T22:40:50Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "build(v4): 去掉 FMT_USE_CONSTEVAL=0 workaround，恢复 fmt 编译期检查",
        "message": "build(v4): 去掉 FMT_USE_CONSTEVAL=0 workaround，恢复 fmt 编译期检查\n\n欠债清理①：该 workaround 是 Step1 为绕开 fmt8.1.1 在 clang21 的 consteval\n报错临时加的。升级到 fmt10.2.1 后问题消失，去掉后双平台全量重编无 consteval\n报错、单进程三语言联动测试通过(Mac arm64/clang21 + Linux x64/gcc13)。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "1775eb2378da27255bdb77916fe0453e0308ef22",
        "url": "https://github.com/kungfu-systems/kungfu/commit/1775eb2378da27255bdb77916fe0453e0308ef22",
        "committedAt": "2026-06-17T02:38:14Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "docs(v4): 建 conan2 迁移理解与决策日志",
        "message": "docs(v4): 建 conan2 迁移理解与决策日志\n\n记录 kungfu-core 构建编排全景理解、可人确认的历史成因(双UI形态/两条构建路径/\nkfc freeze/imports 是 kfx 交付物/prebuilt/pipenv)、迁移决策逻辑链、分阶段逐文件\n规格(A conan2核心 / B electron / C freeze+kfc / D windows)、待验证假设。\n声明:理解可能片面、以代码为准。供未来 agent 深读不必重读全代码。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "326179cac308f91469e1fea8723ee555095bf269",
        "url": "https://github.com/kungfu-systems/kungfu/commit/326179cac308f91469e1fea8723ee555095bf269",
        "committedAt": "2026-06-17T02:54:15Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "refactor(core): conanfile.py 端口到 conan2 (Stage A-1)",
        "message": "refactor(core): conanfile.py 端口到 conan2 (Stage A-1)\n\nconan1→conan2 端口：from conans→from conan；generators=cmake+imports()→\ngenerate()(CMakeDeps+CMakeToolchain)；tools.*→platform/os/shutil/subprocess；\nself.copy→conan.tools.files.copy；options 用 pkg/*:opt；deps 升 fmt10.2.1+\nspdlog1.14.1。imports() 拷 Python headers/lib 的职责移到 package()(kfx 交付)。\n保留 node+electron 双 runtime、with_yarn/纯cmake 两条路径、freeze、kfc 打包逻辑。\n\n验证：conan inspect 加载成功(10 requires)；conan install 成功，generate() 产出\nconan_toolchain.cmake + 各 *Config.cmake(Mac arm64)。build()/package()/freeze\n运行逻辑待下一步随主 CMakeLists conan2 适配 + libkungfu 构建验证。逻辑链见\n.v4/docs/conan2-migration.md。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "77d126a3bc3abbbafa2c984921f100f5ab49bb49",
        "url": "https://github.com/kungfu-systems/kungfu/commit/77d126a3bc3abbbafa2c984921f100f5ab49bb49",
        "committedAt": "2026-06-17T03:04:38Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "refactor(core): 主 CMakeLists 适配 conan2 桥接 (Stage A-2a)",
        "message": "refactor(core): 主 CMakeLists 适配 conan2 桥接 (Stage A-2a)\n\nconanbuildinfo.cmake + conan_basic_setup → conan2 find_package + CONAN_LIBS\n列表 + link_libraries(照 .v4 已验证桥接)，src/libkungfu 的 ${CONAN_LIBS}\n零改动复用。vendored .deps/pybind11-2.9.0 → find_package(pybind11)(conan\n2.13.6，旧版不支持 Py3.13)。\n\n验证：configure 全目标(含 pybind11)解析成功；libkungfu 实编 libkungfu.dylib\n链接成功(Mac arm64)。node/python 绑定全流程 + run-conan.js flags 待下一步。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "6831fb222d47bb183752ff30560767bf251e2f01",
        "url": "https://github.com/kungfu-systems/kungfu/commit/6831fb222d47bb183752ff30560767bf251e2f01",
        "committedAt": "2026-06-17T03:15:30Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "docs(v4): 摸清欠债② libnode→dist 真实形态并落档(排序调整)",
        "message": "docs(v4): 摸清欠债② libnode→dist 真实形态并落档(排序调整)\n\n发现 Stage A 完整 bindings build 依赖② 先完成：正式 python/node 绑定经\nuse_libnode() 从 npm 包 @kungfu-trader/libnode 的 dist 取 Node22 头+库。② 是\n现代化链(libnode 仓铺 Node22 dist + 版本升 + 跨机同步 + kungfu-core devDep\nelectron19.1.8/libnode16.15→现代版 + npm link)，非单纯拷贝。可人定:覆盖旧 dist、\nplan a(两机各自铺)。排序:先② 再 A-2b 完整 bindings 再 B/C/D。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "7f57c318d78aed8686f0b9642cd0a5e80eb0a6e0",
        "url": "https://github.com/kungfu-systems/kungfu/commit/7f57c318d78aed8686f0b9642cd0a5e80eb0a6e0",
        "committedAt": "2026-06-17T03:25:08Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "docs(v4): 记录欠债② libnode→dist 双平台落位完成",
        "message": "docs(v4): 记录欠债② libnode→dist 双平台落位完成\n\nelectron 选 Electron 37.x；libnode 仓建 NAS bare 仓+dev/v22.x(version 22.22.3)。\nMac/Ubuntu 各铺 Node22 dist(arm64 .dylib / x64 .so.127，各 333 头)，\n@kungfu-trader/libnode 两机解析✓。下一步 A-2b：kungfu-core devDep 升级\n(libnode→22.22.3 local link + electron→37.x) + run-conan.js conan2 化 + 完整 bindings。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "103b66851dcaa647f1ca9a5abeb151e4a0828128",
        "url": "https://github.com/kungfu-systems/kungfu/commit/103b66851dcaa647f1ca9a5abeb151e4a0828128",
        "committedAt": "2026-06-17T03:53:41Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "docs(v4): 立 v4 产品长期目标与分阶段实施计划(恢复点)",
        "message": "docs(v4): 立 v4 产品长期目标与分阶段实施计划(恢复点)\n\n可人定稿 objective：journal-first 非量化通用流式数据流运行时+平台(数据平面/\n客户端GUI+TUI/operator计算+确定性重放/沿v3 AWS遗产的在线化服务)。技术选型：\nGUI=Electron+React+TS、TUI=Ink、共享TS核心 over kungfu_node。路线 P0-P5\n(P0 conan2地基进行中 → P1 Journal Inspector 即 Wireshark-for-journal → ...)。\n含 v3 可继承资产清单(tracer/assemble/replay/Context/StreamDataBatcher/operator/\nwebserver/AWS体系)与引用注意。供跨会话无缝衔接。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "ad0f812e14e54e0f40ed1db5faa10112657347e6",
        "url": "https://github.com/kungfu-systems/kungfu/commit/ad0f812e14e54e0f40ed1db5faa10112657347e6",
        "committedAt": "2026-06-17T04:18:08Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "build(core): kungfu-core devDep 升级 + 真实绑定首编 (A-2b 进行中)",
        "message": "build(core): kungfu-core devDep 升级 + 真实绑定首编 (A-2b 进行中)\n\npackage.json devDep：electron 19.1.8→^37.10.3(Electron 37 捆绑 Node22)、\nnode-addon-api ^5→^8、删 nan(已被 node-addon-api 取代)。@kungfu-trader/libnode\n不进 package.json(未发布+两机路径不同)，dev 走 npm link。\n\n验证：完整 configure(libkungfu+kungfu_node+pykungfu 全 enabled，libnode/\nnode-addon-api 头解析)；手动 cmake 实编真实 libkungfu + pykungfu(py-libnode\n内嵌链 Node22 libnode.127.dylib，Mac arm64)。\n\n待办：①kungfu_node 走 cmake-js(with_yarn)路径(需 NODE_RUNTIME，真实双绑定不走\npure-cmake)；②pykungfu 误链 Python3.14 需 pin 3.13。详见 .v4/docs/conan2-migration.md。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "0d5db708abbcf0fbb2c9fda9541a55d8d888e47b",
        "url": "https://github.com/kungfu-systems/kungfu/commit/0d5db708abbcf0fbb2c9fda9541a55d8d888e47b",
        "committedAt": "2026-06-17T05:09:03Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "docs(v4): A-2b cmake-js+conan2 集成打通(node+electron，Mac)",
        "message": "docs(v4): A-2b cmake-js+conan2 集成打通(node+electron，Mac)\n\n最大不确定项验证：cmake-js 7.4.0 + conan2 toolchain 共存。集成法＝cmake-js\nconfigure/build --runtime node|electron --CDCMAKE_TOOLCHAIN_FILE=<conan> ...\n(cmake-js 传 -DNODE_RUNTIME + 透传 conan toolchain；NODEJS_ORG_MIRROR 走域内\n下 headers)。Mac 验证：runtime=node 编出真实 kungfu_node.node(含 watcher/全\nstore)+drone.node；runtime=electron configure 通过(kungfu_electron)→B de-risk。\n剩余：pin Python3.13 / run-conan.js conan2化 / electron full build / Linux 重做。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "f2a0bd93c4ab12363ad3bfab302f52daaff62609",
        "url": "https://github.com/kungfu-systems/kungfu/commit/f2a0bd93c4ab12363ad3bfab302f52daaff62609",
        "committedAt": "2026-06-17T06:38:24Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "build(core): A-2b Mac 侧收尾(Python pin/run-conan conan2/electron) ①②③",
        "message": "build(core): A-2b Mac 侧收尾(Python pin/run-conan conan2/electron) ①②③\n\n①Python pin：cmake-js --CDPYTHON_EXECUTABLE 锁 3.13，pykungfu→cpython-313；\nconfig.python_version 3.9→3.13。②run-conan.js conan2 化：-if/-bf/-pf→\n--output-folder + --build=missing；去 -o arch(conan2 setting)；getNodeVersionOptions\nelectron 去^/node_version 读 config(libnode 移出 devDep)；conanfile cmake-js cmd\n补 arch 映射(armv8→arm64)+透传 conan toolchain。③electron full build 出\nkungfu_electron.node(arm64)→B 阶段 Mac 验证。剩 ④Linux 重做。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "c859683a262e3912106e52140c4e7a4bb1e17a8c",
        "url": "https://github.com/kungfu-systems/kungfu/commit/c859683a262e3912106e52140c4e7a4bb1e17a8c",
        "committedAt": "2026-06-17T07:11:19Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "chore(core): gitignore conan2/cmake 构建工件",
        "message": "chore(core): gitignore conan2/cmake 构建工件\n\n新增 framework/core/.gitignore：CMakeUserPresets.json / CMakePresets.json /\nbuild-conan2/ / node_modules/。避免 conan2 迁移生成的本地工件误入仓\n(配合 cmake-js + conan install 在 framework/core 直接生成的 preset/缓存)。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "2149a187862b65f92d7e62d80e12580beb8bb0ee",
        "url": "https://github.com/kungfu-systems/kungfu/commit/2149a187862b65f92d7e62d80e12580beb8bb0ee",
        "committedAt": "2026-06-17T07:22:17Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "docs(v4): A-2b 双平台闭环完成(node+electron 真实绑定)",
        "message": "docs(v4): A-2b 双平台闭环完成(node+electron 真实绑定)\n\n④Linux 侧整条 cmake-js 路径跑通：node runtime 出 kungfu_node+drone+kungfu_kfc\n+pykungfu.cpython-312，electron runtime 出 kungfu_electron.node(ELF x86-64)。\nMac arm64：kungfu_node+kungfu_electron+pykungfu.cpython-313+drone。全部经\nconan2 + cmake-js + Node22 libnode 跑通。Linux cmake-js 用 --disturl 域内镜像。\nA-2b 完成。P0 剩 C(freeze+kfc)/D(windows)→ .v4 退役。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "ae8b29a0b96c90f10d8442b5de4502001b65363a",
        "url": "https://github.com/kungfu-systems/kungfu/commit/ae8b29a0b96c90f10d8442b5de4502001b65363a",
        "committedAt": "2026-06-17T08:29:58Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "docs(v4): Stage C(freeze+kfc)分析与前置决策",
        "message": "docs(v4): Stage C(freeze+kfc)分析与前置决策\n\nkfc=冻 kungfu Python 包+numpy/pandas/plotly 成独立 exe(PyInstaller kfc.spec /\nNuitka kfc.py 双路径)。前置冲突：pyproject 钉 python<3.12 与 v4 runtime(3.13/\n3.12)冲突且 freeze Python 须=pykungfu 构建 Python；数据栈(numpy1.25/nuitka1.5)\n需为 3.13 升级；conan2 无独立 conan package 需脱离 package()。待决策：freeze\nPython 版本/freezer(Nuitka 2.x vs PyInstaller)/数据栈升级范围。\n\nAgent: Claude (Code)\nEOF"
      },
      {
        "sha": "2600b382b8ae2287d0c845023ddf41dadbe2b2c6",
        "url": "https://github.com/kungfu-systems/kungfu/commit/2600b382b8ae2287d0c845023ddf41dadbe2b2c6",
        "committedAt": "2026-06-17T08:52:24Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "build(core): Stage C 基础 — Python 栈现代化到 3.13(pyproject+Pipfile)",
        "message": "build(core): Stage C 基础 — Python 栈现代化到 3.13(pyproject+Pipfile)\n\n决策(可人)：统一 Python 3.13 双平台、freezer Nuitka 2.x、数据栈升 3.13 最新稳定。\npyproject.toml：python>=3.13,<3.14；numpy~2.1/pandas~2.2/scipy~1.14/statsmodels\n~0.14.4/nuitka~2.5/pyinstaller~6.11(dev fallback)+ 工具链/杂项同步升；移除 vestigial\nconan~1.60 dev-dep(conan2 由系统 pipx 提供)；dev-deps→group.dev。\nPipfile：pip24.3.1/setuptools75.6/virtualenv20.28/wheel0.45/poetry1.8.5/urllib3\n2.2.3/cffi1.17.1/cryptography43.0.3 + [requires]python_version=3.13。\n\n剩余(长迭代)：env bootstrap(pipenv→poetry lock/install，预计迭代修冲突)、Ubuntu\n装 python3.13 + Linux pykungfu 重编 3.13、Nuitka freeze 产 dist/kfc 脱离 conan2\npackage()。版本为最佳实践估值，lock 时按冲突微调。详见 .v4/docs/conan2-migration.md §4c。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "44c02919758ed7aaeb516106131e151ed6f4be18",
        "url": "https://github.com/kungfu-systems/kungfu/commit/44c02919758ed7aaeb516106131e151ed6f4be18",
        "committedAt": "2026-06-17T09:19:52Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "build(core): Stage C env bootstrap 通过 — Python 3.13 数据栈解析+安装成功",
        "message": "build(core): Stage C env bootstrap 通过 — Python 3.13 数据栈解析+安装成功\n\npipenv 升级 2026.6.2(py3.13；旧 pipenv 在 3.12+ venv 缺 pkg_resources 崩溃)→\npipenv install 造 3.13 venv + poetry 1.8.5 → poetry lock(3 轮修冲突：\nrailroad-diagrams/certifi/传递依赖放宽为 *)→ poetry install。验证：numpy 2.1.3 /\npandas 2.2.3 / scipy 1.14.1 / nuitka 2.5.9 全在 Python 3.13，kungfu 包安装成功。\npyproject 加 aliyun 国内 PyPI 源(避免占出海链路)。lock 文件随之更新。\n\n下一步：Nuitka freeze 产 dist/kfc(需 venv 内 pykungfu)+ Ubuntu python3.13 + Linux 重做。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "6b95fe388cd83ccc531391613b627f6e8dded528",
        "url": "https://github.com/kungfu-systems/kungfu/commit/6b95fe388cd83ccc531391613b627f6e8dded528",
        "committedAt": "2026-06-17T09:37:33Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "fix(python): kfc 适配 click 8.1.7+ (F→本地 TypeVar)",
        "message": "fix(python): kfc 适配 click 8.1.7+ (F→本地 TypeVar)\n\nclick 8.1.7+ 移除私有 TypeVar F，kungfu/console/commands 的\n`from click.decorators import F as CLI` 报 ImportError。CLI 仅用于装饰器类型\n标注，改本地 `CLI = typing.TypeVar(...)`，不依赖 click 内部符号。\n\n验证：venv(py3.13) 内 kfc --help 正常输出完整 kungfu CLI(assemble/login/run/\nbacktest/journal/slicetool/engage)，full pykungfu(longfist/yijinjing/wingchun/\nlibnode)import 成功。env bootstrap + kfc 运行端到端验证通过。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "29f6685d18995d45a70bc96c1b4e2ab370ba0093",
        "url": "https://github.com/kungfu-systems/kungfu/commit/29f6685d18995d45a70bc96c1b4e2ab370ba0093",
        "committedAt": "2026-06-17T09:41:43Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "docs(v4): Stage C env bootstrap + kfc 运行验证完成(记录+下一步 Nuitka freeze)",
        "message": "docs(v4): Stage C env bootstrap + kfc 运行验证完成(记录+下一步 Nuitka freeze)\n\nAgent: Claude (Code)"
      },
      {
        "sha": "d0e969649e570a78a5e39d08fd2ab7c5d66d2db6",
        "url": "https://github.com/kungfu-systems/kungfu/commit/d0e969649e570a78a5e39d08fd2ab7c5d66d2db6",
        "committedAt": "2026-06-17T12:43:27Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "docs(v4): Nuitka freeze 进展与卡点(bundle 出+卡 certifi/stdlib)",
        "message": "docs(v4): Nuitka freeze 进展与卡点(bundle 出+卡 certifi/stdlib)\n\nNuitka standalone 产出完整 bundle(kfc.bin 380M + pykungfu/libkungfu/libnode\nnative 库全打进)，已解 libnode 同目录/buildinfo 坑。卡点：冻结二进制 certifi\n走 else(<3.11)分支(3.13 已移除 importlib.resources.path)+启动 import warnings\nfailed，同源=Nuitka stdlib/分支异常。修复假设+下次起点已记 .v4/docs §4c。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "f0c2886a5fd8e2483b36c6575f093e9ffe02a04b",
        "url": "https://github.com/kungfu-systems/kungfu/commit/f0c2886a5fd8e2483b36c6575f093e9ffe02a04b",
        "committedAt": "2026-06-17T12:48:37Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "build(core): 数据栈加 plotly 6.8(kfc freeze include-package=plotly 需要)",
        "message": "build(core): 数据栈加 plotly 6.8(kfc freeze include-package=plotly 需要)\n\nAgent: Claude (Code)"
      },
      {
        "sha": "28f4f9cadbc8219d2f66eaebee7948022bf335a1",
        "url": "https://github.com/kungfu-systems/kungfu/commit/28f4f9cadbc8219d2f66eaebee7948022bf335a1",
        "committedAt": "2026-06-17T14:45:01Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "build(core): kfc Nuitka freeze 调通(升 4.1.2 修 certifi)，kfc.bin 独立运行",
        "message": "build(core): kfc Nuitka freeze 调通(升 4.1.2 修 certifi)，kfc.bin 独立运行\n\n- 修改：pyproject nuitka ~2.5→~4.1；kfc.py 去 no_warnings/numpy/anti-bloat 显式启用、\n  distutils 改 --nofollow-import-to、nofollow chardet 与 engage dev 工具桥接(mypyc 包)\n- 验证：env -u PYTHONPATH kfc.dist/kfc.bin --help 干净输出完整 CLI，无 warnings/certifi 报错\n- 真因：certifi 崩非版本问题，是 Nuitka 2.5.9 anti-bloat 对新版 certifi 的 stale 替换；\n  4.1.2 用 when: version(certifi)<(2025,) 门控规避，保 anti-bloat 同时修好\n- 风险：Linux 侧 freeze 未做(nuitka 也需升 4.1.2)；engage dev 工具冻结版打包另案；体积 910M 留优化\n- 详档：.v4/docs/conan2-migration.md §4c\n\nAgent: Claude (Code)"
      },
      {
        "sha": "4e4127d888d58228c0a1a085a0e64edabfb57d0e",
        "url": "https://github.com/kungfu-systems/kungfu/commit/4e4127d888d58228c0a1a085a0e64edabfb57d0e",
        "committedAt": "2026-06-17T23:17:05Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "chore(core): poetry.lock 重锁匹配 nuitka ~4.1(Linux freeze 用 4.1.2)",
        "message": "chore(core): poetry.lock 重锁匹配 nuitka ~4.1(Linux freeze 用 4.1.2)\n\nAgent: Claude (Code)"
      },
      {
        "sha": "4e85bf22a7c008b2c2e5d8e7268be0037b358109",
        "url": "https://github.com/kungfu-systems/kungfu/commit/4e85bf22a7c008b2c2e5d8e7268be0037b358109",
        "committedAt": "2026-06-18T00:18:37Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "docs(core): 记录 Stage C Linux freeze 调通，双平台 kfc 独立运行完成",
        "message": "docs(core): 记录 Stage C Linux freeze 调通，双平台 kfc 独立运行完成\n\n- Ubuntu python3.13.14 + pykungfu 重编 313 + env bootstrap + Nuitka 4.1.2 freeze 全通\n- 坑记录：headless keyring 卡死(null backend)、Linux 需 patchelf、libnode symlink、json 引号\n- Stage C 剩 ④⑤⑥⑦ 收尾/优化项；下一步 D(windows) 或收尾后 .v4 退役 → P1\n\nAgent: Claude (Code)"
      },
      {
        "sha": "3ab57f1cdd170498ece61113a46a673f88338a1a",
        "url": "https://github.com/kungfu-systems/kungfu/commit/3ab57f1cdd170498ece61113a46a673f88338a1a",
        "committedAt": "2026-06-18T01:20:53Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "build(core): Stage C 收尾 — freeze 入口脚本化 + kungfubuildinfo 自动化",
        "message": "build(core): Stage C 收尾 — freeze 入口脚本化 + kungfubuildinfo 自动化\n\n- 新增 .gyp/freeze-kfc.sh：两平台通用 kfc freeze 入口(生成 buildinfo + 同目录 libnode + nuitka)\n- 新增 .gyp/gen_kungfubuildinfo.py：复刻 conanfile __gen_build_info，供 cmake-js 直编/freeze 补 buildinfo\n- nuitka --include-data-files 把 buildinfo 自动放进 dist 根，消除手动 cp(Stage C 剩余④)\n- 验证：Mac kfc.bin --version=3.2.0-alpha.1、--help 完整 CLI、buildinfo 自动就位\n- ⑤engage dev 工具打包/⑦体积优化 明确延后(非 P1/非正确性)\n\nAgent: Claude (Code)"
      },
      {
        "sha": "ddbaf32b2cddc266349641c544dee2e03cacc9bd",
        "url": "https://github.com/kungfu-systems/kungfu/commit/ddbaf32b2cddc266349641c544dee2e03cacc9bd",
        "committedAt": "2026-06-18T05:52:08Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "build(core): Windows 端口 — libkungfu 改 STATIC 解 LNK1189，Stage D GUI 路径跑通",
        "message": "build(core): Windows 端口 — libkungfu 改 STATIC 解 LNK1189，Stage D GUI 路径跑通\n\n- src/libkungfu/CMakeLists.txt：WIN32 用 STATIC(SHARED 自动导出 >65535 符号撞 LNK1189)，\n  Mac/Linux 维持 SHARED；journal 是 mmap 跨实例共享，static 不破坏多语言模型\n- DARKHERO(VS2026/MSVC19.5)经 conan2(-s cppstd=17)+cmake-js electron 编出 kungfu_node.node+drone.node\n- 文档记录 Stage D：GUI 路径✅；libnode/pykungfu/kfc 待 VS2022(Node22 不认 VS2026)\n- 详档 .v4/docs/conan2-migration.md Stage D 段\n\nAgent: Claude (Code)"
      },
      {
        "sha": "4c26196e7826311273cbee0684cfc492a0eadc00",
        "url": "https://github.com/kungfu-systems/kungfu/commit/4c26196e7826311273cbee0684cfc492a0eadc00",
        "committedAt": "2026-06-18T11:17:43Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "chore(core): .v4 退役 — bootstrap 删除，文档迁 framework/core/docs",
        "message": "chore(core): .v4 退役 — bootstrap 删除，文档迁 framework/core/docs\n\n- P0 conan2 迁移成果已提升为正式 conanfile.py + 主 CMakeLists(三平台全可构建+kfc 三平台 freeze)\n- 删 .v4 bootstrap：conanfile.txt/.v4 CMakeLists/.gitignore + node·python lightup + tests(主构建零引用 KFV4_)\n- 文档迁 docs/：conan2-migration.md / v4-product-roadmap.md / v4-dev-log.md(原 .v4/README)\n- conanfile.py + run-conan.js 注释 .v4/docs→docs；文档加退役说明 + Stage D 完成回写\n\nAgent: Claude (Code)"
      },
      {
        "sha": "faea6ad26076269f2608408924c382c6c3936595",
        "url": "https://github.com/kungfu-systems/kungfu/commit/faea6ad26076269f2608408924c382c6c3936595",
        "committedAt": "2026-06-18T14:23:05Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "chore(core): P0 收尾 — Windows cppstd=17 固化进 run-conan + ⑤⑦ 落档",
        "message": "chore(core): P0 收尾 — Windows cppstd=17 固化进 run-conan + ⑤⑦ 落档\n\n- run-conan.js platformConanSettings()：仅 Windows 给 conan install/build/package 加 -s compiler.cppstd=17\n  (MSVC profile detect 误判 14；Mac/Linux gnu17 不动以免缓存失效)\n- 文档 P0 收尾处置：⑤ engage dev 工具冻结版不打包(设计闭环)；⑦ 体积分析(strip -x libkungfu 401M→365M，\n  主体是合法编译代码)+优化计划(strip/lto/剔 plotly 待 P1)\n- P0 核心达成 + 收尾项处置完毕，下一步 P1 Journal Inspector\n\nAgent: Claude (Code)"
      },
      {
        "sha": "9424d68d973a22e912447a15365cbbcf23ac84c9",
        "url": "https://github.com/kungfu-systems/kungfu/commit/9424d68d973a22e912447a15365cbbcf23ac84c9",
        "committedAt": "2026-06-20T05:28:54Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "build(core): nng 1.6→1.11 升级 + 引入 flatbuffers 25.9.23",
        "message": "build(core): nng 1.6→1.11 升级 + 引入 flatbuffers 25.9.23\n\n- conanfile.py: nng/1.6.0→1.11.0;requires 加 flatbuffers/25.9.23\n- CMakeLists.txt: find_package(flatbuffers) + flatbuffers::flatbuffers 进 CONAN_LIBS\n- nng/1.11.0 conan recipe 仍暴露公开 nng_url struct,webserver.cpp 零改动\n- libkungfu Mac arm64 重编全绿(conan 图共存无冲突,nng 源码编译)"
      },
      {
        "sha": "ae1d06eaa51685bde2ada62d25603e3f05b042fb",
        "url": "https://github.com/kungfu-systems/kungfu/commit/ae1d06eaa51685bde2ada62d25603e3f05b042fb",
        "committedAt": "2026-06-20T10:57:54Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "fix(core): StackWalker.cpp 在 <tchar.h> 前 #undef strcpy/strncpy(Windows)",
        "message": "fix(core): StackWalker.cpp 在 <tchar.h> 前 #undef strcpy/strncpy(Windows)\n\ncommon.h:48-50 在 _WINDOWS 下全局 #define strcpy/strncpy→_s 安全版,污染随后\n<tchar.h> 内联 _strcpy_l/_strncpy_l(SDK 10.0.26100 servicing 新增,体内调用真实\nstrcpy/strncpy)→返回类型不匹配 C2440。在 include <tchar.h> 前撤销宏即解;\nStackWalker 自身用真实 strncpy_s/MyStrCpy,不依赖该宏。与 nng/FB 升级无关,\n属先存 Windows-build 问题(SDK 近期更新引入)。"
      },
      {
        "sha": "dde8c6439cc2832e8ea3cc9e47daf7cd8882fb8e",
        "url": "https://github.com/kungfu-systems/kungfu/commit/dde8c6439cc2832e8ea3cc9e47daf7cd8882fb8e",
        "committedAt": "2026-06-20T14:03:54Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "fix(core): 移除 common.h 全局 strcpy/strncpy 宏,改 kungfu::copy_string",
        "message": "fix(core): 移除 common.h 全局 strcpy/strncpy 宏,改 kungfu::copy_string\n\ncommon.h _WINDOWS 下全局 `#define strcpy/strncpy → _s 安全版` 有三隐患:\n1. 污染随后 include 的系统/三方头里的 strcpy/strncpy(如 SDK <tchar.h> 内联 _strncpy_l\n   被改写返回 errno_t → C2440,曾需 StackWalker.cpp #undef band-aid 绕过);\n2. 对裸指针目标用 sizeof(指针)=8 取容量,误判截断;\n3. 仅 _WINDOWS 定义,与 Mac/Linux 裸 strcpy 不一致。\n\n改为跨平台 kungfu::copy_string:4 参核心(显式 size,限定 dest[0,size) 内 bounded+补 NUL)\n+ array<char,N>& / char(&)[N] 两便捷重载(编译期取容量 N、拒裸指针)。array<char,N>::operator=\n改用之;40 处调用点 strcpy(X,Y)→kungfu::copy_string(X,Y)。py-libnode.cpp 不 include common.h、\n其 strncpy 本就是真函数(非宏),保留原样。\n\n三平台验证:Mac(libkungfu+全绑定 84/84)、Linux(libkungfu 66/66)、Windows(libkungfu 66/66,\n**StackWalker.cpp 无 band-aid 自绿**)均 0 error。"
      },
      {
        "sha": "d064c6ef5911d78a85686e4fb149e2a6acc4dce2",
        "url": "https://github.com/kungfu-systems/kungfu/commit/d064c6ef5911d78a85686e4fb149e2a6acc4dce2",
        "committedAt": "2026-06-20T15:30:24Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "Merge branch 'dev/v4/v4.0' into feature/v4-fb-nng",
        "message": "Merge branch 'dev/v4/v4.0' into feature/v4-fb-nng"
      },
      {
        "sha": "03d7307d3e8de4d733f1fe77a1bda4fdbed0186e",
        "url": "https://github.com/kungfu-systems/kungfu/commit/03d7307d3e8de4d733f1fe77a1bda4fdbed0186e",
        "committedAt": "2026-06-20T15:30:49Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "Revert \"fix(core): StackWalker.cpp 在 <tchar.h> 前 #undef strcpy/strncpy(Windows)\"",
        "message": "Revert \"fix(core): StackWalker.cpp 在 <tchar.h> 前 #undef strcpy/strncpy(Windows)\"\n\nThis reverts commit ae1d06eaa51685bde2ada62d25603e3f05b042fb."
      },
      {
        "sha": "899fe83a4e9b95372a2651d9dfef814e02552a4b",
        "url": "https://github.com/kungfu-systems/kungfu/commit/899fe83a4e9b95372a2651d9dfef814e02552a4b",
        "committedAt": "2026-06-21T00:20:50Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "feat(cache): Phase2 — 开放层运行时投影 fb_projector(FB .bfbs 反射→裸 sqlite3)",
        "message": "feat(cache): Phase2 — 开放层运行时投影 fb_projector(FB .bfbs 反射→裸 sqlite3)\n\nPhase 2 首切片的投影层(与 hana 并存,不碰 longfist 闭集/make_storage_ptr/热路径):\n运行时 .bfbs 反射 -> CREATE TABLE/INSERT bind/ALTER ADD COLUMN,取代 sqlite_orm\n编译期模板壳的投影一端。header-only,暂未被生产代码引用(后续 Step 接 journal+reader)。\n\n验证(debug-example 本地 gitignored,不入仓):fb_projector_slice exe 在 kungfu 真实工具链\n(apple-clang gnu++20/-O3/LTO)编译+运行 PASS:position 运行时建表/bind/6 类 SQL 对等(R2);\nAgentTask 从未 codegen 类型同一二进制不重编端到端(§5 核心);position_v2 运行时演进。\n坑:.bfbs 字节须比 reflection::Schema* 活得久(GetSchema 返回 buffer 视图),registry 须 own。"
      },
      {
        "sha": "459df37c4b7f60a99c6e5d9537d7fbd2109a1c11",
        "url": "https://github.com/kungfu-systems/kungfu/commit/459df37c4b7f60a99c6e5d9537d7fbd2109a1c11",
        "committedAt": "2026-06-21T05:23:08Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "feat(cache): 开放层 FB 运行时投影接入 cached seam(默认 OFF,与 hana 并存)",
        "message": "feat(cache): 开放层 FB 运行时投影接入 cached seam(默认 OFF,与 hana 并存)\n\n- 新增 fb_schema_registry.h:运行时 schema registry,own .bfbs 字节(防 GetSchema 视图\n  use-after-free)、按 msg_type 路由多类型、缓存反射列计划/DDL/SQL;evolve/reconcile 支持\n  .bfbs 演进运行时 ALTER ADD COLUMN。\n- 新增 open_layer_projector.h:封装 registry + 自有 sqlite db,setup(manifest) own 字节注册建表、\n  feed(event) 零拷贝反射投影;未注册 msg_type no-op 放行。\n- fb_projector.h:瘦索引坐标列 kf_offset -> kf_gen_time(reader 仅 seek_to_time,mmap offset\n  无法 seek/持久化无意义),保留 frame_uid 精确匹配 + stream_id 流过滤。\n- cached.{h,cpp}:feed() 末尾挂开放层投影器,仅当环境变量 KF_OPEN_LAYER_SCHEMAS 设定时由 ctor\n  启用(默认 OFF),与 hana 闭集并存、未启用零行为变化;forward-decl + unique_ptr 不污染 cached.h。\n- 验证:投影/journal 写读/瘦索引回环/registry/演进/seam/真 cached e2e 七切片 Mac arm64 全 PASS;\n  libkungfu relink 0 error;默认 OFF 经真 cached 经验证不建 db。验证 exe 在 debug-example\n  (gitignored 本地,未入仓)。\n- 风险:feed() 内同步逐帧 sqlite INSERT,放量前须批量/异步化;schema 来源(env+manifest)与\n  open_layer db 路径为切片占位,生产应落 KF_HOME。"
      },
      {
        "sha": "efe99d0e529def9907b238d21e905fee4e7c7f31",
        "url": "https://github.com/kungfu-systems/kungfu/commit/efe99d0e529def9907b238d21e905fee4e7c7f31",
        "committedAt": "2026-06-21T06:13:52Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "perf(cache): 开放层投影批量/异步化,拆掉 feed 热路径同步 sqlite",
        "message": "perf(cache): 开放层投影批量/异步化,拆掉 feed 热路径同步 sqlite\n\nfeed() 不再在 reader 热路径上同步逐帧 INSERT,改为镜像 hana 路径的\n「内存缓冲 + 后台 worker 批量 flush」模式:\n\n- open_layer_projector.h:feed() 把帧字节拷贝进内存 buffer_(仅 buf_mtx_,不碰 sqlite;\n  journal mmap page 会被回收,故必须拷出而非存指针);新增 flush()(flush_mtx_ 串行化 db_,\n  一个 BEGIN/COMMIT 事务批量投影)、start_worker/stop_worker(后台异步、幂等)、pending_count();\n  dtor 收尾 stop_worker + 最终 flush。\n- cached.cpp:ctor setup 成功后 start_worker() 启动生产异步;cached dtor 经 unique_ptr 析构\n  自动收尾,无需改析构逻辑。\n- 验证(gitignored fb_open_layer_async_slice):feed 3 帧 -> pending=3/db=0(热路径无 sqlite),\n  flush() -> db=3,start_worker+feed 2+sleep -> 后台自动落盘 db=5;seam/真 cached e2e 回归 PASS。\n- 残余:批量 flush 内仍逐行 prepare/finalize,可进一步每类型 prepared-stmt 复用(次要)。"
      },
      {
        "sha": "660f93af329521f39517c1f32221f1ddc5e063a0",
        "url": "https://github.com/kungfu-systems/kungfu/commit/660f93af329521f39517c1f32221f1ddc5e063a0",
        "committedAt": "2026-06-21T11:30:26Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "feat(strategy): born-FB Order 写侧首切 — Matcher dual-write(默认 OFF,与 POD 并存)",
        "message": "feat(strategy): born-FB Order 写侧首切 — Matcher dual-write(默认 OFF,与 POD 并存)\n\n主体 longfist→FB 的写侧首个垂直切片:仿真 Matcher 在 feature flag 下额外写 born-FB Order 帧。\n\n- 新增 longfist/fb/ 的 born-FB Order schema/codegen/写侧 helper(R3 一 schema 同驱 journal+SQLite 投影):\n  - order.fbs:char-array/enum 表示口径(array<char,N>→string、enum class:int8_t→FB enum:byte 镜像 enums.h);\n    首切为 Order 可查询列+代表性 payload 子集,放量补全全字段。\n  - order_generated.h:flatc25.9.23 codegen(committed;build-time codegen 后续优化)。\n  - order_fb_builder.h:build_fb_order(const types::Order&) 按口径序列化 POD Order→born-FB 载荷;ORDER_FB_TAG=30202。\n- matcher.cpp Matcher::update_order:POD 写(tag 202)不变;仅当 KF_ORDER_BORN_FB 设定时额外 write_raw 一条\n  born-FB Order,与 POD 并存。flag 未设=POD-only,实盘/仿真零行为变化;不改 matcher.h。\n- 验证:libkungfu 编译链接通过;debug-example fb_order_builder_slice(gitignored)以真 POD longfist::Order\n  验 build_fb_order→反射投影列类型(status→INTEGER/instrument_id→TEXT)+值保真+R2 四类 SQL 对等。\n- 残余:full sim e2e(起 backtest 跑撮合)、order.fbs 补全全字段、Trader 实盘 producer、build-time codegen。"
      },
      {
        "sha": "134f27266eb3f79c1604f1f07fdd7f30510513e9",
        "url": "https://github.com/kungfu-systems/kungfu/commit/134f27266eb3f79c1604f1f07fdd7f30510513e9",
        "committedAt": "2026-06-21T12:52:45Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "feat(longfist): born-FB Order schema 补全 longfist Order 全字段(27 列)",
        "message": "feat(longfist): born-FB Order schema 补全 longfist Order 全字段(27 列)\n\n把 born-FB order.fbs 从首切 7 字段子集补全为 longfist::types::Order 全字段(types.h:266-302),\n让 born-FB Order 携带与 POD Order 完全相同数据,成为真正的 drop-in 替代候选。\n\n- order.fbs(7→27 字段):全镜像 Order 字段(字段名严格对齐 longfist 以保 SQLite 列与既有 sqlite_orm 一致);\n  按 char-array/enum 口径镜像 8 个 enum(OrderStatus/InstrumentType/Side/Offset/HedgeFlag/PriceType/\n  VolumeCondition/TimeCondition,全 enum:byte,值逐一对齐 enums.h,含 Side 的 Unknown=99);6 个 array<char,N>→string。\n- order_generated.h + order.bfbs:flatc25.9.23 重生成。\n- order_fb_builder.h build_fb_order:填全 27 字段(6 string 先建 Offset、8 enum 经 int8_t 中转 cast)。\n- 验证(debug-example gitignored):build_fb_order 真 POD Order→投影 27 列/列类型/值保真+R2;\n  side-by-side 与真 sqlite_orm storage 逐列逐行 0 不符;真 Matcher::update_order e2e 产 born-FB Order 端到端。"
      },
      {
        "sha": "1d450a92bda4907af6bbddd68e870ca647dfd12e",
        "url": "https://github.com/kungfu-systems/kungfu/commit/1d450a92bda4907af6bbddd68e870ca647dfd12e",
        "committedAt": "2026-06-21T14:47:52Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "feat(longfist): born-FB Trade 迁移 — Order 同法第二类型",
        "message": "feat(longfist): born-FB Trade 迁移 — Order 同法第二类型\n\n- 新增 longfist/fb/trade.fbs(include order.fbs 复用 InstrumentType/Side/Offset/HedgeFlag enum,避免同 TU ODR 冲突)\n  + trade_generated.h/trade.bfbs(flatc 25.9.23 --gen-mutable --scoped-enums)\n  + trade_fb_builder.h(build_fb_trade,TRADE_FB_TAG=30203;char-array→string、enum class:int8_t→FB enum:byte 口径)\n- matcher.cpp: update_trade 加 dual-write,flag KF_TRADE_BORN_FB 默认 OFF,与 POD Trade(tag 203)并存;flag 未设=零变化\n- 验证(Mac arm64,gitignored slice): born-FB Trade 投影 vs 真 sqlite_orm storage 逐列逐行对等 19 列 0 不符;Order parity 无回归"
      },
      {
        "sha": "c8a82798cb1f38a12757dbb087b429ce72d49f5f",
        "url": "https://github.com/kungfu-systems/kungfu/commit/c8a82798cb1f38a12757dbb087b429ce72d49f5f",
        "committedAt": "2026-06-21T15:19:25Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "build(core): flatc 构建期生成 longfist FB 头(取代手动跑+入仓产物)",
        "message": "build(core): flatc 构建期生成 longfist FB 头(取代手动跑+入仓产物)\n\n- CMakeLists: add_custom_command 用 flatbuffers::flatc 在 build 期生成 order/trade 的\n  *_generated.h(--cpp --gen-mutable --scoped-enums) + *.bfbs(-b --schema);add_custom_target\n  longfist_fb_codegen,libkungfu OBJECT 库(kungfu_cache/kungfu_optim)依赖之。\n- 关键:flatbuffers::flatc 由 conan flatbuffers 的 cmake_build_modules(FlatcTargets.cmake)在\n  find_package(flatbuffers)时已暴露,三平台 native build(非交叉)用包内 bin/flatc——无需改 conanfile/tool_requires。\n- .gitignore 忽略 longfist/fb/*_generated.h + *.bfbs;git rm --cached 4 个生成物(变构建产物,\n  保留 .fbs/*_fb_builder.h 手写源),消手动跨 schema 重跑 + 漂移风险。\n- 验证(Mac arm64): 删生成物→reconfigure→flatc 重生成 4 文件→libkungfu+order/trade parity slice\n  编过+跑 PASS(27/19 列 0 不符,功能不变);Linux/Win 复测待下一步。"
      },
      {
        "sha": "788d2170788b9a2e95f59619809a019f7016c6ab",
        "url": "https://github.com/kungfu-systems/kungfu/commit/788d2170788b9a2e95f59619809a019f7016c6ab",
        "committedAt": "2026-06-22T09:38:26Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "feat(longfist): born-FB Position 迁移 — Order/Trade 同法第三类型(state)",
        "message": "feat(longfist): born-FB Position 迁移 — Order/Trade 同法第三类型(state)\n\nposition.fbs(include order.fbs 复用 InstrumentType + 补 Direction/LedgerCategory enum，28 字段全镜像 longfist Position，复合 5 PK) + position_fb_builder.h(build_fb_position, POSITION_FB_TAG=30103) + CMakeLists position flatc build-time codegen。R2 终验(gitignored slice)：born-FB Position 投影 vs 真 sqlite_orm storage 逐列逐行 0 不符，证模式可推广到复合 PK + state 类型。"
      },
      {
        "sha": "7f7aab5fa4c2d52a283e6b6e5192d79bf8e3c2c2",
        "url": "https://github.com/kungfu-systems/kungfu/commit/7f7aab5fa4c2d52a283e6b6e5192d79bf8e3c2c2",
        "committedAt": "2026-06-22T11:02:39Z",
        "author": "Claude (Code)",
        "authorName": "Claude (Code)",
        "committerName": "Claude (Code)",
        "title": "feat(longfist,ledger): born-FB Asset(第四类型) + Position/Asset ledger 写侧 dual-write(默认 OFF)",
        "message": "feat(longfist,ledger): born-FB Asset(第四类型) + Position/Asset ledger 写侧 dual-write(默认 OFF)\n\nasset.fbs(include position.fbs 复用 LedgerCategory，40 字段单 PK holder_uid) + asset_fb_builder.h(ASSET_FB_TAG=30101) + CMakeLists asset flatc codegen。ledger 写侧:KF_POSITION_BORN_FB/KF_ASSET_BORN_FB 设定时在 write_book/update_account_book/write_strategy_data/write_positions 的 POD Position(103)/Asset(101) 写之外额外写 born-FB 帧(30103/30101)并存,flag 未设=POD-only 零变化;3 helper 集中(FB include 仅 ledger.cpp，helper protected 供 TestLedger e2e)。验证:Asset R2 parity 40列0不符、libkungfu+ledger hook 编译链接0err、真 Ledger 写侧 e2e(_to/_as 两路径写真 journal 2 Position+1 Asset+投影 R2、flag OFF 零写入)、6 slice 无回归。\n\nAgent: Claude (Code)"
      },
      {
        "sha": "45397f35b66412c838e8cb7d67dc1ef1f3bfc237",
        "url": "https://github.com/kungfu-systems/kungfu/commit/45397f35b66412c838e8cb7d67dc1ef1f3bfc237",
        "committedAt": "2026-06-23T01:31:24Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "feat(ledger): 加 KF_SKIP_POD_WRITE 迁移 cutover 开关(默认 OFF)",
        "message": "feat(ledger): 加 KF_SKIP_POD_WRITE 迁移 cutover 开关(默认 OFF)\n\nwrite_book 在 KF_SKIP_POD_WRITE 设定时跳过 POD Position(103)/Asset(101) 写,只走 born-FB(终态形态);默认不设=POD 路径零变化,加法式 guard。配合 KF_POSITION/ASSET_BORN_FB 支持 POD-only / dual-write / FB-only 三态,用于 FB 替 POD 的灰度 cutover。"
      },
      {
        "sha": "879e7acfeb23be6c82cd17f1563f9ae412f06a03",
        "url": "https://github.com/kungfu-systems/kungfu/commit/879e7acfeb23be6c82cd17f1563f9ae412f06a03",
        "committedAt": "2026-06-23T09:07:35Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "fix(yijinjing): 改用 atomic_ref release/acquire 发布帧,修 ARM 弱序撕裂",
        "message": "fix(yijinjing): 改用 atomic_ref release/acquire 发布帧,修 ARM 弱序撕裂\n\njournal 发布协议原用 volatile length/msg_type + 普通读写,ARM 弱内存序下无屏障,读者可能观测到撕裂帧/陈旧帧(x86-TSO 侥幸正确)。改为 length 作发布令牌:写侧所有可见状态写完后最后一步 release 存储(publish_data_length),读侧 acquire 闸门(has_data);copy_frame 同步修复;去掉 frame_header 的 volatile。新增 ADR-0001 正文。对齐已核验(aligned(8),length offset 0)。未编译/未测试,ARM 压测见后续验证。"
      },
      {
        "sha": "7ca62bb1520a3c959b0b58480916f430083be908",
        "url": "https://github.com/kungfu-systems/kungfu/commit/7ca62bb1520a3c959b0b58480916f430083be908",
        "committedAt": "2026-06-23T09:56:14Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "docs(adr): ADR-0001 回填 S4 对抗压测数据(ARM 复现+x86 印证+修复清零)",
        "message": "docs(adr): ADR-0001 回填 S4 对抗压测数据(ARM 复现+x86 印证+修复清零)\n\nMac arm64 volatile 1463万撕裂->atomic 0;x86 volatile 0(TSO 印证侥幸正确)。待真实在树编译进 final。"
      },
      {
        "sha": "edbcab6980f402b5403fefaf863924c645fdb6be",
        "url": "https://github.com/kungfu-systems/kungfu/commit/edbcab6980f402b5403fefaf863924c645fdb6be",
        "committedAt": "2026-06-23T10:08:42Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "docs(adr): ADR-0001 在树编译验证通过(arm64 -fsyntax-only,offsetof 断言成立)",
        "message": "docs(adr): ADR-0001 在树编译验证通过(arm64 -fsyntax-only,offsetof 断言成立)"
      },
      {
        "sha": "700e2a39e7309820026501b6c30bd523cff36de2",
        "url": "https://github.com/kungfu-systems/kungfu/commit/700e2a39e7309820026501b6c30bd523cff36de2",
        "committedAt": "2026-06-23T16:14:52Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "Merge feature/v4-yijinjing-barrier: ADR-0001 yijinjing 发布协议改 atomic_ref release/acquire",
        "message": "Merge feature/v4-yijinjing-barrier: ADR-0001 yijinjing 发布协议改 atomic_ref release/acquire\n\n修 yijinjing journal 发布协议在 ARM 弱内存序下的撕裂帧 latent bug:volatile length/msg_type 改 std::atomic_ref release/acquire(写侧最后一步 release、读侧 acquire,copy_frame 同步)。双平台全量 libkungfu 编译+链接通过(Mac arm64 + Linux x64);ARM 对抗压测 1463万撕裂->0,x86 印证 TSO 侥幸正确。ADR 正文见 framework/core/docs/adr/ADR-0001-yijinjing-publish-barrier.md。"
      },
      {
        "sha": "2f3e5ffbc094ff755bf54d51bc85198dc5660682",
        "url": "https://github.com/kungfu-systems/kungfu/commit/2f3e5ffbc094ff755bf54d51bc85198dc5660682",
        "committedAt": "2026-06-24T16:16:08Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "Merge dev/v4/v4.0 into feature/v4-fb-nng: 吸收 ADR-0001(yijinjing atomic_ref 发布屏障)",
        "message": "Merge dev/v4/v4.0 into feature/v4-fb-nng: 吸收 ADR-0001(yijinjing atomic_ref 发布屏障)\n\nADR-0001 与 FB 迁移互不重叠(journal 发布文件未被 FB 改动),自动合并干净。为 FB 线合入主线前对齐 dev/v4 基线并重新双平台验证组合态。"
      },
      {
        "sha": "14acd68f5fcb25a98bf8673be66046492a488c91",
        "url": "https://github.com/kungfu-systems/kungfu/commit/14acd68f5fcb25a98bf8673be66046492a488c91",
        "committedAt": "2026-06-24T23:55:12Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "build(core): 摘 wingchun 出 libkungfu 编译流程(tracing 基石 Phase 1 第一刀·1/3)",
        "message": "build(core): 摘 wingchun 出 libkungfu 编译流程(tracing 基石 Phase 1 第一刀·1/3)\n\n把 wingchun(交易语义,32 cpp)排除出 libkungfu GLOB 源;核心 journal/longfist/yijinjing 对 wingchun include=0,故仅排除 .cpp。实测:libkungfu 33 TU(原 65)编译+链接 0 error。sqlite_orm cache 改 fb_projector、交易类型拆死源为后续两块。"
      },
      {
        "sha": "9121eaba41bbe820f6eea067f1c192860f9cefec",
        "url": "https://github.com/kungfu-systems/kungfu/commit/9121eaba41bbe820f6eea067f1c192860f9cefec",
        "committedAt": "2026-06-25T00:20:43Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "build(core): 交易类型移出 StateDataTypes 闭集 cache(tracing 基石 Phase1 3/3)",
        "message": "build(core): 交易类型移出 StateDataTypes 闭集 cache(tracing 基石 Phase1 3/3)\n\n从 StateDataTypes/StaticDataTypes/StatisticDataTypes 移除交易类型(Order/Trade/Position/Asset/Algo/Quote/OrderStat 等),只留非交易内核 runtime 状态(Config/RiskSetting/Commission/Instrument/Basket/StrategyStateUpdate/OperatorStateUpdate/TimeValue/TimeKeyValue);cached.cpp 移除 TradingDataTypes transfer + Order/AlgoOrder restore。实测 libkungfu:unstripped 410->61.7MiB,__text 22.7->9.77MiB,sqlite_orm 符号 34727->10306,编译 0 error。交易类型仍定义于 types.h(死源,未进闭集);AllTypes hana 序列化暂保留。"
      },
      {
        "sha": "bbb46761fa619b919c36e77cb2444c8f707b285d",
        "url": "https://github.com/kungfu-systems/kungfu/commit/bbb46761fa619b919c36e77cb2444c8f707b285d",
        "committedAt": "2026-06-25T00:36:23Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "build(python): drop py-wingchun 绑定(tracing 基石 Phase1 工具链)",
        "message": "build(python): drop py-wingchun 绑定(tracing 基石 Phase1 工具链)\n\npykungfu.cpp 去 py-wingchun include + wingchun submodule bind;CMakeLists list(FILTER ... EXCLUDE py-wingchun)。py-longfist 保留(交易类型仍定义于 types.h)。未 build-verify(需 npm/libnode 环境)。"
      },
      {
        "sha": "9e687349bf3254b41bc01e8b49a53d505bce0317",
        "url": "https://github.com/kungfu-systems/kungfu/commit/9e687349bf3254b41bc01e8b49a53d505bce0317",
        "committedAt": "2026-06-25T06:08:29Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "build(node): carve Watcher 脱 wingchun(tracing 基石 Phase1·kungfu_node)",
        "message": "build(node): carve Watcher 脱 wingchun(tracing 基石 Phase1·kungfu_node)\n\n- Changed: 移除 kungfu_node Watcher 的 wingchun 交易记账耦合——\n  WatcherAutoClient(SilentAutoClient)/bookkeeper_/内嵌 BookListener/\n  交易 UpdateBook 模板/WriteInstruction/InteractWithTD/UpdateTradingData(FromCacheD)/\n  refresh_books(account_book)/UpdateAsset/UpdateBook(Quote/Position)/broker::map_is_own_event 全删;\n  下单撤单 JS 方法(Issue/Cancel/Toggle*)保签名 stub 返回 0;\n  交易数据 sync(SyncTradingData/FromCached)no-op;\n  仅保留 wingchun/common.h 的 header-only instrument 工具(hash_instrument/get_instrument_type,无 .cpp 链接符号)。\n  保留 yijinjing apprentice/journal/event/location/非交易 state 缓存与全部 JS API 表面。\n  同时修复:交易类型移出 StateDataTypes(9121eaba4)导致的 watcher.cpp hana at_key 编译错(根因统一)。\n- Verified: -fsyntax-only(libkungfu conan include + node v24 头 + node-addon-api@8 头)rc=0,watcher.cpp 编译干净;\n  grep 确认无 bookkeeper/Book/broker/BookListener/SilentAutoClient/map_is_own_event 残留符号。\n- Risk: syntax-only 不验链接;完整 kungfu_node 链接(libnode env)与 Electron app 启动 gate 待后续验证。\n  交易 JS 方法退化为 no-op(Phase 2「喂 agent 事件」新 Watcher 重建);instrument 工具迁出 wingchun 命名空间留作 cleanup。"
      },
      {
        "sha": "e1bd28e525f121eeb60af173622139a414207f88",
        "url": "https://github.com/kungfu-systems/kungfu/commit/e1bd28e525f121eeb60af173622139a414207f88",
        "committedAt": "2026-06-25T15:12:21Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "build(core): 修 setup.py install_requires 无下限依赖 + lockfile 补 node-addon-api@8",
        "message": "build(core): 修 setup.py install_requires 无下限依赖 + lockfile 补 node-addon-api@8\n\n- setup.py: 依赖约束无 min(如 \"*\")时输出裸包名,避免非法的 \"certifi>=None\" 致 bdist_wheel 失败\n- yarn.lock: yarn install 补入 node-addon-api@8(framework/core 声明 ^8.0.0 但 lockfile 缺条目)"
      },
      {
        "sha": "33d74385fe48761671b4edcd1fc715f5c567d733",
        "url": "https://github.com/kungfu-systems/kungfu/commit/33d74385fe48761671b4edcd1fc715f5c567d733",
        "committedAt": "2026-06-25T15:13:13Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "Move on to v4.0.0-alpha.0",
        "message": "Move on to v4.0.0-alpha.0"
      },
      {
        "sha": "28f4b531b8806d359542ffde712c386eeb6e003e",
        "url": "https://github.com/kungfu-systems/kungfu/commit/28f4b531b8806d359542ffde712c386eeb6e003e",
        "committedAt": "2026-06-26T01:11:41Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "docs(build): kungfu v4 编译依赖与各平台 libnode 构建工具链",
        "message": "docs(build): kungfu v4 编译依赖与各平台 libnode 构建工具链\n\n- 记录 kungfu-core + libnode v22.22.3 各平台(mac/linux/win)本地编译依赖\n- node22/python+distutils/nasm/VS+ClangCL/pipenv/Verdaccio + node-pre-gyp 分发\n- 收录踩过的坑:setup.py certifi None、pandas clean-rebuild、._* 资源叉、Win 长路径、ittapi EPERM、ClangCL MSB8020、clang-cl 直编 link_node、.npmrc scope 覆盖等"
      },
      {
        "sha": "198020b682f444d421a13aba5e311457f1af0a70",
        "url": "https://github.com/kungfu-systems/kungfu/commit/198020b682f444d421a13aba5e311457f1af0a70",
        "committedAt": "2026-06-26T02:53:26Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "feat(pykungfu): 重新暴露最小 wingchun utils 绑定(tracing-foundation Phase 1)",
        "message": "feat(pykungfu): 重新暴露最小 wingchun utils 绑定(tracing-foundation Phase 1)\n\n- carve 后 Python 层 kungfu/wingchun 仍需 instrument utils(get_instrument_type/\n  hash_instrument/is_valid_price/get_instrument_product/hash_product),均为 common.h\n  inline(header-only),不依赖已移除的 wingchun 交易 lib。\n- py-wingchun.cpp bind() 只留 bind_utils;CMakeLists 排除改为只排交易绑定源\n  (book/broker/factor/map/operator/orderbook/service/strategy/streamdatabatcher/tool),\n  保留 py-wingchun.cpp + py-wingchun-utils.cpp;pykungfu.cpp 注册 wingchun 子模块。\n- 验证:重编 EXIT=0,import pykungfu.wingchun.utils 全部函数到位。\n- 注:kfc 运行仍需 carve Python 交易运行时(executor/strategy/operator 链),另起一轮。"
      },
      {
        "sha": "1513802187c0d5c1ed7f6f045b494c85c6457231",
        "url": "https://github.com/kungfu-systems/kungfu/commit/1513802187c0d5c1ed7f6f045b494c85c6457231",
        "committedAt": "2026-06-26T04:39:07Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "feat(kfc): Python 交易运行时降级 lazy,kfc 独立运行通过(Phase 1 gate 第一半)",
        "message": "feat(kfc): Python 交易运行时降级 lazy,kfc 独立运行通过(Phase 1 gate 第一半)\n\noption A(可人选定):让 carved core 上 kfc 能起来,交易运行时降级为 lazy 占位。\n- executor.py:wingchun strategy/sliceindexer/report/operator import 包 try/except,\n  缺则 None;符号仅在真正执行 run/strategy 交易路径(StrategyRunner/OperatorRunner\n  方法内)用到,Phase 1 不走。\n- slicetool.py:wingchun.sliceindexer import 同样降级 lazy。\n- master.py 无需改(其引的 default_commissions 在 wingchun/__init__.py 是纯 pandas 表)。\n\n验证(冻结 kfc 实测):kfc --version → 4.0.0-alpha.0;kfc --help 全命令加载;\nkfc journal --help 子命令(archive/clean/sessions/show)全可用;无 wingchun import 报错。\n注:交易命令(run/backtest/slicetool)加载得起但实跑会因 lazy 占位报错,Phase 1 本不需。"
      },
      {
        "sha": "8801047253abd786230eae0fc6a5ec5647a5eec3",
        "url": "https://github.com/kungfu-systems/kungfu/commit/8801047253abd786230eae0fc6a5ec5647a5eec3",
        "committedAt": "2026-06-26T05:03:42Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "chore(electron): 统一 electron 到 42.5.0(最新 stable,tracing-foundation Phase 1)",
        "message": "chore(electron): 统一 electron 到 42.5.0(最新 stable,tracing-foundation Phase 1)\n\n口径(可人 2026-06-26):electron 统一到能支持的最新现代版本 = 42.5.0。\n- framework/core/package.json devDep electron ^37.10.3 → ^42.5.0(kungfu_electron.node 构建源,\n  run-conan.js 从此读 electron_version)。\n- framework/app/package.json electron 19.1.8 → 42.5.0(app 运行时;原 19 已 EOL 且与构建版本不一致)。\n\n注:electron 42 自带 node 24.17,与 libnode v22.22.3(kfc 运行时)node 大版本不同;\nN-API(NAPI_VERSION=8)ABI 稳定,kungfu_electron.node 跨 node 版本通用,功能无碍。\n待办:yarn install 取 electron 42 → 重编 kungfu_electron.node@42 → freeze 布局 reconciliation → build:app → GUI 启动。"
      },
      {
        "sha": "e8abeee02fe2b718ea4e6c41dc34f8e4ca5378b4",
        "url": "https://github.com/kungfu-systems/kungfu/commit/e8abeee02fe2b718ea4e6c41dc34f8e4ca5378b4",
        "committedAt": "2026-06-26T06:18:32Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "docs(build): Electron app 构建 + electron 镜像/缓存(electron 42 / LAN 缓存 / freeze 布局)",
        "message": "docs(build): Electron app 构建 + electron 镜像/缓存(electron 42 / LAN 缓存 / freeze 布局)\n\n- electron 统一 42.5.0(node24,N-API 解耦 libnode22);声明两处\n- electron 头:npmmirror 头镜像不稳(504)→ 官方 artifacts.electronjs.org via 代理\n- electron 二进制:CN CDN 超时 → 缓存到 LAN 8088/electron/v42.5.0(289MB/s);\n  未来构建 ELECTRON_MIRROR=http://192.168.100.222:8088/electron/ ELECTRON_CUSTOM_DIR='v{{ version }}'\n- kfc freeze 布局:pyinstaller _internal vs app 扁平 dist;contents_directory='.' 在 MERGE 下不灵,\n  临时 promote 符号链解锁,正式 Stage C 待补"
      },
      {
        "sha": "dbb6eb5323253f9ebfe6551578e22d335e6b4c20",
        "url": "https://github.com/kungfu-systems/kungfu/commit/dbb6eb5323253f9ebfe6551578e22d335e6b4c20",
        "committedAt": "2026-06-26T07:25:43Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "build(toolchain): kungfu-code 起手式 — fnm 单点收敛 node/yarn 到 node22(去 ignore-engines 补丁)",
        "message": "build(toolchain): kungfu-code 起手式 — fnm 单点收敛 node/yarn 到 node22(去 ignore-engines 补丁)\n\n根治 node 版本兼容:构建/dev driver 统一到 node 22.22.3(=libnode),与系统 node 24 解耦。\n- .node-version=22.22.3:fnm 读,锁定 driver node。\n- package.json packageManager=yarn@1.22.22:corepack 派发 yarn(node 自带,无需单装)。\n- kungfu-code / kungfu-code.cmd:跨平台「起手式」wrapper —— `./kungfu-code <yarn 任务>`\n  在钉定 node 下执行(fnm exec → corepack yarn)。使用者只需一次性装 fnm 这一个前置,\n  node/npm/yarn 全由 fnm+corepack 级联派发。\n- CN 友好:FNM_NODE_DIST_MIRROR=npmmirror(node)、COREPACK_NPM_REGISTRY=LAN Verdaccio(yarn),\n  均可外部覆盖/指向 LAN 8088 缓存。\n- 验证:./kungfu-code --version → node22 下 yarn 1.22.22,零 engine 报错。"
      },
      {
        "sha": "b3c5eb1329bc1c20b48a67c5444171b888237889",
        "url": "https://github.com/kungfu-systems/kungfu/commit/b3c5eb1329bc1c20b48a67c5444171b888237889",
        "committedAt": "2026-06-26T07:34:57Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "build(toolchain): electron 全声明统一 42.5.0 + kungfu-code 起手式接管 electron LAN 镜像",
        "message": "build(toolchain): electron 全声明统一 42.5.0 + kungfu-code 起手式接管 electron LAN 镜像\n\n- developer/toolchain electron 19.1.8 → 42.5.0(漏网点;旧版 @electron/get 不认 {{version}}\n  模板且 LAN 无 19.x 致 404,统一到 42 后用新 @electron/get + LAN 缓存)。\n- kungfu-code/.cmd 加 ELECTRON_MIRROR=LAN 8088 + ELECTRON_CUSTOM_DIR='v{{ version }}':\n  electron 二进制经 LAN 缓存取(避免 CN CDN 踩坑),起手式一并接管。\n- 验证:./kungfu-code install 在 node22 下 engine 报错=0、Done 15s;electron 42 二进制\n  经 LAN 取到位(Electron --version=v42.5.0)。"
      },
      {
        "sha": "d7d074a9a991083239f8264d878573b361047484",
        "url": "https://github.com/kungfu-systems/kungfu/commit/d7d074a9a991083239f8264d878573b361047484",
        "committedAt": "2026-06-26T07:46:54Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "fix(core): getTargetArch 回退 process.arch + electron 镜像用默认 v<version> 目录",
        "message": "fix(core): getTargetArch 回退 process.arch + electron 镜像用默认 v<version> 目录\n\nPhase 1 gate 第二半(Electron app 启动)收尾两处:\n- shell.js getTargetArch:config.arch 未设时回退 process.arch(原硬编码 x64,arm64 机误判\n  \"Electron arch arm64 does not match target\")。本机构建自动匹配,保留显式 config.arch 供交叉编译。\n- kungfu-code/.cmd:去掉 ELECTRON_CUSTOM_DIR='v{{version}}'(@electron/get 不展开该模板,曾致\n  v%7B%7B URL 404);@electron/get 默认目录即 v<version>,正好匹配 LAN 缓存布局。\n\n验证(./kungfu-code app,node22+electron42):Electron 主+渲染进程起、加载 carved kungfu_node、\nKungfu banner、稳定运行(timeout 180s 杀非崩溃);零 engine 报错。视觉窗口确认待亮屏。"
      },
      {
        "sha": "f9240a37a724e5c7586de00f60d9e2525f3371eb",
        "url": "https://github.com/kungfu-systems/kungfu/commit/f9240a37a724e5c7586de00f60d9e2525f3371eb",
        "committedAt": "2026-06-26T08:11:06Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "build(toolchain): kungfu-code 默认 node 镜像指向 LAN 缓存(node 22 已 publish)",
        "message": "build(toolchain): kungfu-code 默认 node 镜像指向 LAN 缓存(node 22 已 publish)\n\nLAN 缓存三件套补齐:libnode(prebuilt CDN)+ electron(8088/electron)+ node(8088/node/v22.22.3,\n三平台 dist + SHASUMS,publish-large-file-cache.sh)。fnm 从 LAN 取 node 实测 276MB/s、校验一致。\nFNM_NODE_DIST_MIRROR 默认 http://192.168.100.222:8088/node/(离网用 npmmirror 覆盖)。\n至此 kungfu-code 起手式所有构建输入(node/yarn/electron)均走 LAN,CN 机器零踩坑。"
      },
      {
        "sha": "d72922f4a1b804a796b007dbd397cf6b4b41047f",
        "url": "https://github.com/kungfu-systems/kungfu/commit/d72922f4a1b804a796b007dbd397cf6b4b41047f",
        "committedAt": "2026-06-26T08:13:30Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "docs(build): node-LAN 缓存 + kungfu-code 起手式 + 修 electron 模板/corepack 斜杠坑",
        "message": "docs(build): node-LAN 缓存 + kungfu-code 起手式 + 修 electron 模板/corepack 斜杠坑\n\n- node 22 三平台 dist 入 LAN 8088/node;kungfu-code 默认 FNM_NODE_DIST_MIRROR=LAN\n- electron 声明三处(补 developer/toolchain)+ 去掉失效的 ELECTRON_CUSTOM_DIR 模板说明\n- corepack COREPACK_NPM_REGISTRY 末尾勿带斜杠(否则 //yarn 404)\n- 构建三大输入 node/yarn/electron + libnode 全 LAN 化"
      },
      {
        "sha": "1078f8743c877e2f8723fd7aafed7d9452369ecf",
        "url": "https://github.com/kungfu-systems/kungfu/commit/1078f8743c877e2f8723fd7aafed7d9452369ecf",
        "committedAt": "2026-06-26T09:40:39Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "feat(core): freeze 独立入口 run-freeze.js，一步 staging+pyinstaller+promote",
        "message": "feat(core): freeze 独立入口 run-freeze.js，一步 staging+pyinstaller+promote\n\n- 新增 .gyp/run-freeze.js：staging(src/include→build/include)+pyinstaller(kfc.spec)+kfs 合并+promote(_internal/*→dist/kfc 顶层,Unix 符号链/Win 拷贝)\n- freeze 脱离 conan2(无独立 conan package)；core/顶层 package.json freeze 入口改指 run-freeze.js\n- run-conan.js package 注释订正：仅留 conan build 语义，不再承担 freeze\n- 去掉手动 promote 符号链 hack；./kungfu-code freeze 一步可复现\n- 验证：freeze 跑通(promote 63 项)、kfc --version=4.0.0-alpha.0、build:app webpack 绿"
      },
      {
        "sha": "68dcd81c999247faf5fe31b046b0b7b350559ce7",
        "url": "https://github.com/kungfu-systems/kungfu/commit/68dcd81c999247faf5fe31b046b0b7b350559ce7",
        "committedAt": "2026-06-26T11:40:24Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "feat(core): freeze 默认改 Nuitka(承接 6-17 决策)，run-freeze.js 支持双 freezer",
        "message": "feat(core): freeze 默认改 Nuitka(承接 6-17 决策)，run-freeze.js 支持双 freezer\n\n- run-freeze.js 重构：据 config.freezer 选 nuitka(默认)/pyinstaller(fallback)\n- nuitka 路径：freeze kfc.py→kfc.dist(扁平)→移 dist/kfc→kfc.bin 改名 kfc→补拷 app native(drone/kungfu_node/kungfu_electron/link_node)\n- nuitka 真编译产物本就扁平，退役 pyinstaller onedir 的 _internal/promote 符号链层\n- config.freezer: pyinstaller→nuitka\n- 验证：./kungfu-code freeze(463s)/kfc --version=4.0.0-alpha.0/build:app webpack compiled successfully/dist/kfc 730M 无 _internal"
      },
      {
        "sha": "2c043949fe75c567615e839014f64f3c18d27e47",
        "url": "https://github.com/kungfu-systems/kungfu/commit/2c043949fe75c567615e839014f64f3c18d27e47",
        "committedAt": "2026-06-26T15:16:09Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "feat(core): uv 迁移阶段A — pyproject [project]/[tool.uv] + uv.lock(env 接管)",
        "message": "feat(core): uv 迁移阶段A — pyproject [project]/[tool.uv] + uv.lock(env 接管)\n\n- pyproject 加 [project]/[tool.uv](uv 接管 env+lock+install),合并 Pipfile os deps;暂保留 [tool.poetry] 给 setup.py wheel build(阶段B收敛)\n- uv.lock: uv 解析 99 包(deps poetry~/^/*→PEP621 ~=/>=,</裸名 转换全对)\n- 验证: uv sync 装全数据栈 + nuitka 4.1.3(uv .venv);结构性消除 pipenv+poetry hybrid 坑(seed re-lock pandas/Pipfile污染/venv顺序)\n- 未接入构建流程(binding.gyp/conanfile/freeze 仍 pipenv/poetry),双轨并行;阶段A下半(接入)+三平台验证下轮\n\nGoal: 2026-06-26-kungfu-buildchain-modernization"
      },
      {
        "sha": "91e87b94633b89f7155673fc4cc6023ae9f070b5",
        "url": "https://github.com/kungfu-systems/kungfu/commit/91e87b94633b89f7155673fc4cc6023ae9f070b5",
        "committedAt": "2026-06-26T16:18:46Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "build(core): 构建链 pipenv+poetry 切 uv（S1 阶段A 接入）",
        "message": "build(core): 构建链 pipenv+poetry 切 uv（S1 阶段A 接入）\n\n把 kungfu-core 的 Python 构建链从 pipenv+poetry 切到 uv：\n- binding.gyp: pipenv+poetry 两 install target 合为单 uv(uv sync --frozen) target；conan/wheel 依赖与 inputs 改指向 uv\n- gyp_action_uv.py(新): uv sync --frozen\n- run-conan/run-freeze/run-wheel/run-format-python/conanfile.py: pipenv run → uv run --frozen\n- run-build.js: 把 node-gyp 的 python 钉到 uv venv python(setuptools 带 _distutils shim)，根治 node-gyp 选到无 distutils 的系统 python(如 Homebrew python@3.14)\n- package.json: pyinstaller/nuitka/dev:kfc/dev:kfs → uv run --frozen\n- 双轨保留 Pipfile/[tool.poetry]/poetry-core(setup.py)/run-pipenv/run-poetry/gyp_action_pipenv|poetry，阶段B 退役\n\n验证(Mac arm64): build:core 全链(uv sync→conan→C++ compile→wheel→nuitka freeze)绿；dist/kfc/kfc --version=4.0.0-alpha.0、--help 正常；build:app webpack 编译绿"
      },
      {
        "sha": "8eb0fed5bc44785c0dd14387348c8e162c4747a0",
        "url": "https://github.com/kungfu-systems/kungfu/commit/8eb0fed5bc44785c0dd14387348c8e162c4747a0",
        "committedAt": "2026-06-26T18:19:03Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "build(core): setup.py 脱 poetry-core，构建链单一真相源收敛到 [project]（S1 阶段B）",
        "message": "build(core): setup.py 脱 poetry-core，构建链单一真相源收敛到 [project]（S1 阶段B）\n\n- setup.py: 脱 poetry-core，改 tomllib 读 [project](PEP 621)，向上查找 pyproject；wheel 元数据等价\n- pyproject: 删 [tool.poetry]/[[tool.poetry.source]]，build-system 换 setuptools，加 [project.urls]，[project].deps 删 poetry-core\n- uv.lock: 重锁移除 poetry-core(98 包)\n- freeze-kfc.sh: pipenv run → uv run --frozen\n- 退役 pipenv/poetry: 删 Pipfile/Pipfile.lock/poetry.lock/run-pipenv.js/run-poetry.js/gyp_action_pipenv|poetry.py + package.json pipenv/poetry/poetry:clear|lock scripts(含顶层 workspace)\n\n验证(Mac arm64): yarn wheel 单独绿(wheel 元数据 Name/Version/License/Author/49 Requires-Dist/entry 等价); 完整 rebuild:core 全链绿(uv sync 98 包→conan→compile→wheel(新 setup.py)→nuitka freeze, dist/kfc 85 项, Done 497s); kfc --version=4.0.0-alpha.0"
      },
      {
        "sha": "4b7745441195ea716185777da8f5bc69aaa73483",
        "url": "https://github.com/kungfu-systems/kungfu/commit/4b7745441195ea716185777da8f5bc69aaa73483",
        "committedAt": "2026-06-27T00:40:08Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "chore(deps): lerna 5.6.2 → 9.0.7（S2 现代化，CI 自动版本机制不变）",
        "message": "chore(deps): lerna 5.6.2 → 9.0.7（S2 现代化，CI 自动版本机制不变）\n\n- package.json: lerna ^5.0.0 → ^9.0.0；yarn.lock 重解析(引入 nx 生态)\n- lerna version 用法(action-bump-version 调 `lerna version premajor --preid alpha`)5→9 零行为变化:\n  本地实测产出仍为全 23 包统一 4.0.0-alpha.0 → 5.0.0-alpha.0,命令参数全兼容,无需 lerna.json/nx 适配\n- 回归: rebuild:core 全链绿(node-gyp/node-addon-api/fs-extra 等构建依赖经 yarn.lock 重解析后构建不变);\n  kfc --version=4.0.0-alpha.0;wheel 正常;Done 440s\n- 澄清: node-ipc engine 不兼容 node24 的痛点非 lerna(yarn why 实证),而是 @vue/cli-shared-utils\n  (kungfu-toolchain → @vue/cli-plugin-babel),本次未动\n- 待后续(落地 CI): 组织仓 action-bump-version 的 ensureLerna `^5.0.0`→`^9` + patch 路径 lernaBumpBranch workaround 复验,CI 方真正用 lerna 9"
      },
      {
        "sha": "5a5c0884c7cb396be7ea0fd20867267350352106",
        "url": "https://github.com/kungfu-systems/kungfu/commit/5a5c0884c7cb396be7ea0fd20867267350352106",
        "committedAt": "2026-06-27T03:12:20Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "build(toolchain): 镜像配置单源(pypi 3→1)+ 端到端 verify 命令",
        "message": "build(toolchain): 镜像配置单源(pypi 3→1)+ 端到端 verify 命令\n\n构建链现代化 B1a(镜像单源)+ B3(端到端绿验证),仅仓内、不动 LAN 基建。\n\n- B1a 镜像单源:\n  - 删 framework/core/package.json 死的 pypi 配置(config.pypi_mirror + 仅含死值的\n    configGithub):旧消费者 run-pipenv/poetry 已随 uv 迁移删除,uv 读 pyproject\n    [[tool.uv.index]],故 npm config 那两处无人消费;pypi 生效单源收敛到 pyproject。\n  - kungfu-code 起手式加「镜像/缓存总览」单一发现入口:一张表登记全部上游→镜像映射\n    及其权威声明位置(只指位置不复制值),读起手式即见全图。\n- B3 端到端 verify:新增 verify.js + 根 \"verify\" 脚本(./kungfu-code verify)。\n  把分散的 freeze→build:core→build:app→启 app gate 收敛成「一条命令+断言产物」:\n  断言 framework/core/dist/kfc 目录、kfc 可执行、kfc --version 退 0 且版本匹配\n  (运行时冒烟)、(--with-app)build:app 产物;--full 先 rebuild:core+freeze 再断言。\n  作 CI smoke 基础。\n\n验证:\n- package.json/JSON 合法(node -e JSON.parse);kungfu-code sh -n 通过。\n- verify.js node --check 通过;快速模式在干净 worktree 优雅报告缺产物并退 1,不崩溃。\n- 完整真跑(--full,rebuild:core+freeze+断言,约数百秒,需全工具链+LAN 缓存)未在本机\n  执行,留作验收门(建议在构建机/CI 跑)。\n- 不解决项:npm install registry 统一(走公网)依赖 Verdaccio 透明回源 = B1b 基建,\n  本轮不做。node-pre-gyp host 本地 .cc/CI .io 为有意分流,未动。"
      },
      {
        "sha": "07ff0818b7a71e78e757bcab09aad5bff0aaea84",
        "url": "https://github.com/kungfu-systems/kungfu/commit/07ff0818b7a71e78e757bcab09aad5bff0aaea84",
        "committedAt": "2026-06-27T03:50:02Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "build(core): conan 并行度认 tools.build:jobs,大核机可封顶防 thrash",
        "message": "build(core): conan 并行度认 tools.build:jobs,大核机可封顶防 thrash\n\nconanfile.py 原硬编码 parallel_level/-j = os.cpu_count(),且经 --CDCMAKE_BUILD_PARALLEL_LEVEL\n覆盖 env,大核机(如 agent-120 32 线程)无法限并行:kungfu -flto+重模板单路峰值约 2GB,\n32 路并行撑爆内存换页 thrash(实测 50min,CPU 仅 0.6 核)。\n\n改用 conan 惯用 build_jobs(self):优先读 conf tools.build:jobs(可在 profile/global.conf\n按机器封顶),未设时回退 os.cpu_count() 保持原行为。封装 __parallel_jobs() 供 cmake-js\n路径(--parallel/--CDCMAKE_BUILD_PARALLEL_LEVEL)与 KUNGFU_BUILD_SKIP node cmake 路径(-j)共用。\n\n验证:py_compile 通过;agent-120 端配合 global.conf tools.build:jobs=12 验全量构建。"
      },
      {
        "sha": "63e683bbb529401355b8fae48f99beffd77e059b",
        "url": "https://github.com/kungfu-systems/kungfu/commit/63e683bbb529401355b8fae48f99beffd77e059b",
        "committedAt": "2026-06-27T04:12:56Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "build(core): uv 钉 standalone python,根治 nuitka freeze 段错误+跨机可复现",
        "message": "build(core): uv 钉 standalone python,根治 nuitka freeze 段错误+跨机可复现\n\nfreeze(nuitka 4.1.3)在系统 Debian python(flavor 'Debian Python')下 SIGSEGV(139);\n不同机器 uv venv 取到不同 python(Mac=Homebrew/Clang 绿,agent-120=/usr/bin Debian 崩)\n=跨机 freeze 不可复现。pyproject [tool.uv] 加 python-preference=only-managed:uv 一律用\n自管 standalone CPython(新机自动下载对应版本),freeze 行为跨机一致。\n\n验证:tomllib 解析通过;agent-120 端 uv python install 3.13 + 重建 venv 后验全量构建。"
      },
      {
        "sha": "49ecc82687bf04b0d9648a90dbf3c589a86199e2",
        "url": "https://github.com/kungfu-systems/kungfu/commit/49ecc82687bf04b0d9648a90dbf3c589a86199e2",
        "committedAt": "2026-06-27T04:37:26Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "build(core): Linux nuitka freeze 改 clang 后端,避 gcc 13 ICE+跨机一致",
        "message": "build(core): Linux nuitka freeze 改 clang 后端,避 gcc 13 ICE+跨机一致\n\ngcc 13 编译 nuitka 为 scipy.stats._continuous_distns 生成的巨型 C 文件触发 internal\ncompiler error(cfgcleanup.cc:580 try_forward_edges, RTL cprop pass)。Mac 默认 clang\n不撞。run-freeze.js 仅在 Linux 给 nuitka 加 --clang:避开 gcc ICE,并让两平台 freeze\n用同一 C 编译器(clang)更可复现。需 Linux 机器装 clang(agent-120 已有 clang 18)。\n\n验证:node --check 通过;agent-120 freeze+verify 复跑确认产物绿。"
      },
      {
        "sha": "8113bd1f7640468df31912316a9ea7bc5872bea4",
        "url": "https://github.com/kungfu-systems/kungfu/commit/8113bd1f7640468df31912316a9ea7bc5872bea4",
        "committedAt": "2026-06-27T05:00:53Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "build(toolchain): kungfu-code 起手式纳入 uv 前置,补 fnm/uv 对称(B2)",
        "message": "build(toolchain): kungfu-code 起手式纳入 uv 前置,补 fnm/uv 对称(B2)\n\n起手式此前只检查/引导 fnm(node 侧),uv(python 侧)假定在 PATH、仅由 .gyp 脚本内部\n调用,不对称。本补丁:\n- 加 uv 在位检查(缺则报错引导 brew install uv / astral 安装脚本),与 fnm 检查对称。\n- 头部说明改为「双驱动起手式」:fnm 管 node/yarn,uv 管 standalone CPython+uv.lock+\n  跑 conan/nuitka;使用者一次性装 fnm+uv 两个前置。\n- 镜像总览补 uv standalone python 下载行(UV_PYTHON_INSTALL_MIRROR 可 env 覆盖;LAN 发布待 B1b)。\n\n不动 Windows .cmd(本周期不在 Windows 构建,未验证);留作小跟进。\n验证:sh -n 通过。"
      },
      {
        "sha": "722d079d116f8c8547bd9b4f5a283254b4907083",
        "url": "https://github.com/kungfu-systems/kungfu/commit/722d079d116f8c8547bd9b4f5a283254b4907083",
        "committedAt": "2026-06-27T05:17:35Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "docs(release): add version/release mechanism design rationale",
        "message": "docs(release): add version/release mechanism design rationale\n\nRecord the design intent behind the version/release pipeline so it is not mistaken\nfor replaceable scaffolding:\n- machine-fits-human: version intent is read from the branch-channel flow developers\n  already perform, requiring zero per-change declaration;\n- the git tag is the artifact; package.json version is a downstream projection;\n- a release tag = code-freeze (X) binary-distribution, performed atomically (kungfu\n  ships prebuilt cross-platform binaries, unlike source-distributed ecosystems);\n- release-worthiness is enforced by an un-cheatable pipeline (3-platform verify +\n  review + strict checks, isAdminEnforced), not by judgment;\n- weak-centralization: a release is the promotion of a user-validated alpha, not any\n  one developer's unilateral call.\n\nExplains why changesets/semantic-release are a downgrade in this context and lists\nreplacement criteria, so future maintainers (human or AI) don't swap it out blindly."
      },
      {
        "sha": "7d3bdb78683ad2ffbffb8ad8efe99c52dfb6b6aa",
        "url": "https://github.com/kungfu-systems/kungfu/commit/7d3bdb78683ad2ffbffb8ad8efe99c52dfb6b6aa",
        "committedAt": "2026-06-27T06:25:53Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "build(toolchain): 缓存代理配置外置(仓零 LAN 耦合)+ kungfu-code 三层子集 + libnode 改 devDep",
        "message": "build(toolchain): 缓存代理配置外置(仓零 LAN 耦合)+ kungfu-code 三层子集 + libnode 改 devDep\n\n按「仓里不放本地缓存/LAN 配置,走用户全局/env,开源安全」重塑(B1b):\n- kungfu-code(L1 sh)收薄为 bootstrap+委派;删除硬编码 LAN 默认(FNM/COREPACK/ELECTRON 镜像)。\n  改为可选 source 用户全局 ${XDG_CONFIG_HOME:-~/.config}/kungfu/cache-proxy.env(主仓+所有\n  worktree 共用、仓外、多机同步一份)+ 可选仓内 ./cache-proxy.env(.gitignore)覆盖。\n- kungfu-code.js(L2 node,新):富子命令 proxy get/set/list/init/edit/path/unset 管理上述配置;\n  纯 node builtins;配置读写 module.exports 供未来 L3 TUI 复用。L1 缺 fnm 时回退系统 node 跑 L2。\n- cache-proxy.env.example:提交模板,无任何真实内网地址(公网镜像示例+占位)。.gitignore 加 /cache-proxy.env。\n- pyproject [tool.uv]:去掉硬编码 aliyun [[tool.uv.index]];pypi index 改走用户 uv.toml / UV_DEFAULT_INDEX。\n- framework/core libnode 改 devDep @kungfu-trader/libnode@22.22.3:从用户 ~/.npmrc 的 registry\n  解析 + node-pre-gyp 拉 prebuilt,替代 v4 的本地 checkout/npm-link(yarn.lock 随后在构建机重生)。\n\n验证:sh -n / shellcheck / node --check / json / toml 均过;L2 proxy set/get/list/unset 功能冒烟过。\n注:本提交未含 yarn.lock(libnode 条目需在有 registry 的构建机 regen);随 120 验收一并补。"
      },
      {
        "sha": "b4071895ab72903d55bb51bc08f4643776fa73f4",
        "url": "https://github.com/kungfu-systems/kungfu/commit/b4071895ab72903d55bb51bc08f4643776fa73f4",
        "committedAt": "2026-06-27T06:45:49Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "build(toolchain): build-local.env 化(镜像+编译参数统一)+ 编译并发走 env + libnode lock",
        "message": "build(toolchain): build-local.env 化(镜像+编译参数统一)+ 编译并发走 env + libnode lock\n\n承上一提交,把本机构建配置机制统一、并补 libnode 锁:\n- 配置文件改名 cache-proxy.env(.example) → build-local.env(.example):不仅镜像/缓存,也含\n  编译参数,名实相符;命令统一 config(proxy 留别名)。kungfu-code / kungfu-code.js / .gitignore\n  全部同步改名。\n- 编译并发走同一机制:新增 KUNGFU_BUILD_JOBS 配置键;conanfile.py __parallel_jobs() 改 env\n  优先(KUNGFU_BUILD_JOBS > conan conf tools.build:jobs > os.cpu_count)。每机在 build-local.env\n  里按内存封顶,仓内不硬编码,亦不再依赖手改 conan global.conf。\n- yarn.lock 补 @kungfu-trader/libnode@22.22.3(从 registry 解析,配合上一提交的 devDep)。\n\n验证(agent-120,仓零 LAN 耦合下全绿):libnode 走 devDep+prebuilt(无本地 link)、镜像走\n用户全局 build-local.env、uv 走 devpi、--parallel 12、nuitka clang freeze 成功、\nkfc --version 4.0.0-alpha.0;verify 5/5。"
      },
      {
        "sha": "54e5d915016c6df2b716dcdfc8ad46f5f7d3cdf0",
        "url": "https://github.com/kungfu-systems/kungfu/commit/54e5d915016c6df2b716dcdfc8ad46f5f7d3cdf0",
        "committedAt": "2026-06-27T06:50:31Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "fix(toolchain): 补齐 build-local.env 内容改动(上一提交因 add 失败只落了重命名)",
        "message": "fix(toolchain): 补齐 build-local.env 内容改动(上一提交因 add 失败只落了重命名)\n\n上一提交 git add 含不存在 pathspec 导致整条 add 失败,只提交了 git mv 的文件重命名,\nkungfu-code/.js、conanfile、.gitignore、yarn.lock 的内容改动未落。本提交补齐:\n- kungfu-code/.js 全部引用改 build-local.env;L2 KEYS 加 KUNGFU_BUILD_JOBS;config 命令说明扩。\n- conanfile.py __parallel_jobs() env 优先(KUNGFU_BUILD_JOBS > conf > cpu_count)。\n- build-local.env.example 扩为镜像+编译参数模板;.gitignore 改 /build-local.env;yarn.lock 补 libnode。\n\n验证:sh -n / node --check / py_compile 过;config set/get/list(含 KUNGFU_BUILD_JOBS)过。"
      },
      {
        "sha": "b9f29c30804123eb8b0d992f3243c29058642c16",
        "url": "https://github.com/kungfu-systems/kungfu/commit/b9f29c30804123eb8b0d992f3243c29058642c16",
        "committedAt": "2026-06-27T12:07:15Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "build(toolchain): kungfu-code.cmd 对齐三层子集 + 仓零 LAN 耦合(Windows)",
        "message": "build(toolchain): kungfu-code.cmd 对齐三层子集 + 仓零 LAN 耦合(Windows)\n\n与 macOS/Linux 的 kungfu-code(sh)对齐:\n- 删除硬编码 LAN 镜像默认(FNM/COREPACK/ELECTRON),改为纯 cmd 解析用户全局\n  %USERPROFILE%\\.config\\kungfu\\build-local.env(sh 格式 export 行)+ 可选仓内 .\\build-local.env 覆盖。\n- 加 uv 前置检查(与 fnm 对称);proxy/config 富子命令委派 L2 kungfu-code.js(有 fnm 优先 fnm node,否则系统 node)。\n- 三层子集说明对齐;开源者克隆零 LAN 耦合。\n\n注:Windows 构建未在本机验证(DARKHERO manual_only);拟在 DARKHERO 做非构建 config 冒烟验证委派/解析。"
      },
      {
        "sha": "81e9124198dc03ed64deb0afa5066566c22d2d85",
        "url": "https://github.com/kungfu-systems/kungfu/commit/81e9124198dc03ed64deb0afa5066566c22d2d85",
        "committedAt": "2026-06-27T12:19:06Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "fix(toolchain): kungfu-code.cmd 改 ASCII-only(修 GBK Windows cmd 解析 UTF-8 崩溃)",
        "message": "fix(toolchain): kungfu-code.cmd 改 ASCII-only(修 GBK Windows cmd 解析 UTF-8 崩溃)\n\nDARKHERO 实测发现:.cmd 含 UTF-8 中文注释/echo,Windows cmd 按 OEM codepage(GBK/936)\n读批处理 → 中文字节被误解析,把 node 调用搞成乱码模块名(Cannot find module '...鍧囧彲'),\nconfig 委派直接崩。批处理跨 codepage 必须 ASCII-only(sh 版可 UTF-8)。\n\n改:全文英文注释/消息,逻辑不变。DARKHERO 实测复跑全过:\n- config path/init/set/list 委派 L2 node 正确;loadenv 纯 cmd 解析 sh-format build-local.env 正确\n  (loadenv_FNM/JOBS 取值对);bootstrap loadenv 先于 fnm-check、fnm 缺失正确报 127。\n- 仅 fnm exec yarn 未跑(fnm 不在该会话 PATH,被 fnm-check 正确拦,与 sh 同)。"
      },
      {
        "sha": "e22f83a9e565c33319f0cee936215d928490d230",
        "url": "https://github.com/kungfu-systems/kungfu/commit/e22f83a9e565c33319f0cee936215d928490d230",
        "committedAt": "2026-06-27T13:25:20Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "perf(toolchain): ccache 作为编译器 launcher(UNIX,可用即启用)",
        "message": "perf(toolchain): ccache 作为编译器 launcher(UNIX,可用即启用)\n\n实测 rebuild:core 581s 主成本=libkungfu 重模板重编(clean 每次抹 build/),freeze 378s\n=nuitka 编 numpy/pandas/scipy 巨型 C;全仓零 ccache。本改在 compiler.cmake 单点\nfind_program(ccache) 条件设 CMAKE_C/CXX_COMPILER_LAUNCHER:\n- 命中编译缓存,显著加速 clean-rebuild 的 libkungfu 重编。\n- libkungfu(conan build)与 node/electron bindings(cmake-js)共用本文件,一处全覆盖。\n- 零强制耦合:仅 UNIX 且 PATH 有 ccache 时启用,开源克隆/Windows/未装机 no-op。\n- nuitka(scons)在 PATH 有 ccache 时自动用,freeze 侧无需改码。\n\nS4 评估副产物(不引入 Nx/Turborepo,ccache 更对症)。验证待 120 实测重建提速。"
      },
      {
        "sha": "8703b918d05588fa586cd2cd8ef029c18cae4165",
        "url": "https://github.com/kungfu-systems/kungfu/commit/8703b918d05588fa586cd2cd8ef029c18cae4165",
        "committedAt": "2026-06-27T14:20:06Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "test(core): 协程事件循环 fake-hero 测试网(阶段0,坐实 coloop 缺陷)",
        "message": "test(core): 协程事件循环 fake-hero 测试网(阶段0,坐实 coloop 缺陷)\n\n- 新增 framework/core/tests/python/test_coloop_concurrency.py\n- 按文件路径载入 coloop.py 绕开 pykungfu(C++ 扩展),FakeHero 驱动,不依赖行情/网关\n- 3 测试全红坐实:\n  * P2 定时器 off-by-one: call_at 到期时刻 now==when 当轮不触发(coloop:57 严格 <)\n  * post_step 无条件重新入队 self._current 与 asyncio Task 自调度冲突,\n    多轮 await 协程对已完成 Task 重复 __step => InvalidStateError(单协程即触发)\n- 修复在阶段1"
      },
      {
        "sha": "b226331a516679c0cb9b97182aa6cdc74851bd16",
        "url": "https://github.com/kungfu-systems/kungfu/commit/b226331a516679c0cb9b97182aa6cdc74851bd16",
        "committedAt": "2026-06-27T14:30:47Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "fix(core): coloop 事件循环调度修正(阶段1,P0/P2 转绿)",
        "message": "fix(core): coloop 事件循环调度修正(阶段1,P0/P2 转绿)\n\n- post_step 去单槽 _current + 无条件重新入队,改 handle 一次性执行;\n  消除与 asyncio Task 自调度(call_soon __step / future callback)的冲突,\n  不再对已完成 Task 重复 __step(InvalidStateError)\n- 定时器到期判断 < => <=(到期时刻当轮触发,修回测离散时间延迟一拍)\n- call_soon/call_at 透传 contextvars context;call_later args => *args\n- 测试扩到 5 绿:并发协程各完成一次、定时器到期触发、\n  未完成 future 正确挂起、set_result 事件驱动唤醒\n- 连带(待阶段1下一步):移除重排后旧 AsyncOrderAction(永不完成 future+重轮询)\n  会死锁,strategy.py 需改成 on_order 回调 set_result 的事件驱动+超时"
      },
      {
        "sha": "aaeaea3ba891ebd1d1ceb72aefdb3e3f50782ce3",
        "url": "https://github.com/kungfu-systems/kungfu/commit/aaeaea3ba891ebd1d1ceb72aefdb3e3f50782ce3",
        "committedAt": "2026-06-27T14:40:03Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "test(core): 坐实新 coloop 下旧 AsyncOrderAction 死锁(阶段1)",
        "message": "test(core): 坐实新 coloop 下旧 AsyncOrderAction 死锁(阶段1)\n\n- 照搬 AsyncOrderActionIter 真实逻辑(不 import strategy.py,避开 pykungfu),mock book:\n  新 coloop 下订单成交后 await ctx.buy() 仍死锁(无事件回调 set_result)\n- ground:await ctx.buy/sell 全仓仅 examples/strategy-python-simple/coroutine_trade.py\n  1 个示例使用,无生产策略\n- 6 测试绿"
      },
      {
        "sha": "916dd54845448e4cdfc0bb9377b318973d1d6245",
        "url": "https://github.com/kungfu-systems/kungfu/commit/916dd54845448e4cdfc0bb9377b318973d1d6245",
        "committedAt": "2026-06-27T14:45:48Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "perf(toolchain): 编译器缓存 launcher 改跨平台(优先 sccache 次 ccache,覆盖 Windows)",
        "message": "perf(toolchain): 编译器缓存 launcher 改跨平台(优先 sccache 次 ccache,覆盖 Windows)\n\n承接 ccache(Linux)+ Windows 缓存评估(goal windows-compile-cache-ci Phase1):\nfind_program(NAMES sccache ccache)+ 去 if(UNIX) 守卫 → Linux/mac 仍命中 ccache、\nWindows 命中 sccache。命中即用/缺失 no-op。VS 生成器 launcher 命中率以 DARKHERO 实测为准。"
      },
      {
        "sha": "84184f5a864ba2d74142bfe86f2cc8121680f8eb",
        "url": "https://github.com/kungfu-systems/kungfu/commit/84184f5a864ba2d74142bfe86f2cc8121680f8eb",
        "committedAt": "2026-06-27T14:54:43Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "fix(core): 协程下单 await 改事件驱动(阶段1 完成)",
        "message": "fix(core): 协程下单 await 改事件驱动(阶段1 完成)\n\n- 新增 wingchun/async_order.py: OrderFutureRegistry + AsyncOrderAction\n  (事件驱动 set_result + 可选超时 + 停机 cancel 防泄漏),纯 Python 不依赖 binding,可独立单测\n- strategy.py: 删旧忙轮询 AsyncOrderAction/Iter; __async_insert_order 用新 action\n  (含快速路径已终态/可选 timeout_ns); on_order 包 framework resolve hook\n  (无条件 resolve 协程下单 future 再转发用户 on_order)\n- 新增 tests/python/test_async_order.py: 6 测试(resolve/非终态/快速路径/超时/取消超时/停机防泄漏)\n- 全套 12 测试绿\n- 覆盖盲区: strategy.py 的 binding 胶水(on_order lf_data 字段/book.orders/ctx.loop)\n  需真机集成验证; v4 Python 运行时当前 lazy 占位未实跑(阶段2 前置)"
      },
      {
        "sha": "d96e95f350fd0e22cb6d469964191063841f5aa3",
        "url": "https://github.com/kungfu-systems/kungfu/commit/d96e95f350fd0e22cb6d469964191063841f5aa3",
        "committedAt": "2026-06-27T15:09:30Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "build(toolchain): Windows cmake-js 改 Ninja 生成器(启用 sccache 编译缓存)",
        "message": "build(toolchain): Windows cmake-js 改 Ninja 生成器(启用 sccache 编译缓存)\n\nVS/MSBuild 生成器忽略 CMAKE_CXX_COMPILER_LAUNCHER(Phase1 DARKHERO 实证:VS gen 0 compile\nrequests / Ninja round2 命中)。Windows 分支 --toolset/--platform → --generator Ninja --parallel。\nNinja 下 cl 需 vcvars 激活,构建须在 Developer 环境跑。与 compiler.cmake 跨平台 launcher 捆绑。\n待 DARKHERO 全构建实测命中率(未验证)。"
      },
      {
        "sha": "b2faf3d00d8d305ab803619bccc628c1c3d60a94",
        "url": "https://github.com/kungfu-systems/kungfu/commit/b2faf3d00d8d305ab803619bccc628c1c3d60a94",
        "committedAt": "2026-06-27T15:20:15Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "fix(toolchain): kungfu-code.cmd 用 corepack.cmd(fnm exec 不套 PATHEXT)",
        "message": "fix(toolchain): kungfu-code.cmd 用 corepack.cmd(fnm exec 不套 PATHEXT)\n\nDARKHERO 实测:fnm exec --using-file -- corepack 报 program not found——fnm exec 直接 spawn\n不套 PATHEXT,Windows 下 bare corepack 找不到(只 corepack.cmd 在)。改 corepack.cmd 修复\nWindows 构建起手式(此前 config smoke 未走构建路径故未暴露)。"
      },
      {
        "sha": "392198dea46c8519a48d0fdfa4a54bcc30acc324",
        "url": "https://github.com/kungfu-systems/kungfu/commit/392198dea46c8519a48d0fdfa4a54bcc30acc324",
        "committedAt": "2026-06-27T16:04:48Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "fix(toolchain): Windows+Ninja 钉 SDK rc.exe(避 npm rc 配置包遮蔽)",
        "message": "fix(toolchain): Windows+Ninja 钉 SDK rc.exe(避 npm rc 配置包遮蔽)\n\nDARKHERO 实证:Ninja 下 cmake 走 PATH 探测 rc,yarn/cmake-js 前置 node_modules/.bin,\n其中 npm rc 配置包(rc/rc.cmd)遮蔽 SDK rc.exe → cmake 误用它当资源编译器、链接 manifest 崩\n(Detecting C compiler ABI - failed / RC Pass 1 failed)。显式 --CDCMAKE_RC_COMPILER=<vcvars SDK rc.exe>。\n仅 Windows+Ninja 需要(VS 生成器经 MSBuild 不踩)。"
      },
      {
        "sha": "7bf24d3a188e1f783eeb17c2cd01c0e0d731340a",
        "url": "https://github.com/kungfu-systems/kungfu/commit/7bf24d3a188e1f783eeb17c2cd01c0e0d731340a",
        "committedAt": "2026-06-28T08:33:40Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "ci(core): switch python formatter from black to ruff",
        "message": "ci(core): switch python formatter from black to ruff\n\n- pyproject: black~=24.10.0 -> ruff~=0.15.0; add [tool.ruff] (line-length 88\n  to match black's default, target py313, exclude vendored .deps)\n- run-format-python.js: invoke `uv run --frozen ruff format` instead of black\n- uv.lock: regenerated (drop black + its deps, add ruff)\n\nPart of kungfu pre-check modernization (P2). ruff check (lint) deferred to S2."
      },
      {
        "sha": "151feed2fbfb1080357370f2e8357e3d437f6d89",
        "url": "https://github.com/kungfu-systems/kungfu/commit/151feed2fbfb1080357370f2e8357e3d437f6d89",
        "committedAt": "2026-06-28T08:33:41Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "style(core): apply ruff format to python sources",
        "message": "style(core): apply ruff format to python sources\n\nMechanical reformat by ruff (replacing black). Mostly f-string quote\nnormalization; conanfile.py also gets long call-arg line-wrapping that had\ndrifted unformatted under black. Vendored .deps excluded from formatting."
      },
      {
        "sha": "09ed8b43e7f1ac411f8272eaab541133757e5592",
        "url": "https://github.com/kungfu-systems/kungfu/commit/09ed8b43e7f1ac411f8272eaab541133757e5592",
        "committedAt": "2026-06-28T09:29:58Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "ci(core): enable ruff lint (curated E + F)",
        "message": "ci(core): enable ruff lint (curated E + F)\n\nAdd [tool.ruff.lint]: select E,F; ignore E501 (line length is owned by the\nformatter), F403/F405 (intentional `from x import *`); per-file-ignore F401\nin __init__.py (re-exports). The project previously had no python linter.\n\nkungfu pre-check modernization (P2/S2)."
      },
      {
        "sha": "468e4e683e9069ceff23d6007dd8ee7498417486",
        "url": "https://github.com/kungfu-systems/kungfu/commit/468e4e683e9069ceff23d6007dd8ee7498417486",
        "committedAt": "2026-06-28T09:29:59Z",
        "author": "dongkeren",
        "authorName": "Keren Dong",
        "committerName": "Keren Dong",
        "title": "fix(core): resolve ruff lint findings",
        "message": "fix(core): resolve ruff lint findings\n\nAuto-fixed (46): unused imports, f-string placeholders, etc.\nManual (17): bare except -> except Exception (E722); ==/!= True -> truthiness\n(E712); != None -> is not None (E711); type(x) == Y -> is (E721); move imports\nabove local TypeVar (E402); drop unused platform/sys (F841/F401). noqa with\nreason on site.py side-effect imports (F401) and a latent __name__ local in\npython.py variant (F841, flagged for human review)."
      }
    ],
    "explicitClaudeAuthoredCommits": 34
  },
  "collection": {
    "repository": "https://github.com/kungfu-systems/site-libkungfu-dev",
    "script": "scripts/collect-agent-output-comparison.mjs",
    "command": "node scripts/collect-agent-output-comparison.mjs --window bootstrap",
    "api": "GitHub CLI over public GitHub GraphQL and REST APIs",
    "normalization": "Public PR fields are retained; email addresses in titles and bodies are replaced with [email-redacted].",
    "independentSearchCounts": {
      "ax": 102,
      "kungfu": 2323
    },
    "recordDigest": {
      "ax": "c69358ffc1e1b321f5a3f4763e1dbd5028e67d7056d4982566c5e752cf00a155",
      "kungfu": "dd398a9916be31412bb6d0231f77a43f0e5c0604b679b1b2656828252546d588"
    }
  },
  "boundaries": [
    "A merged pull request is a public work item, not a feature, quality, maturity, or value unit.",
    "The comparison observes public GitHub delivery only. Google internal work and all other private work are outside the dataset.",
    "The scopes intentionally reflect the two real organization forms: AX is one product repository; Kungfu is a multi-repository product and release system.",
    "Author accounts are public GitHub identities. They do not by themselves identify whether a human or an Agent produced the underlying change.",
    "Per-author comparisons observe public responsibility identities, not verified team headcount, labor hours, employment roles, or individual authorship of every line.",
    "Kungfu pull requests operate as settlement objects while AX pull requests follow a conventional contribution workflow; their counts are visible responsibility throughput, not interchangeable feature units.",
    "Additions, deletions, and changed-file totals are gross PR statistics and may include generated files, vendored material, formatting, or repeated edits.",
    "Explicit attribution markers establish some Agent participation in both repositories. AX's Gemini co-author history predates the measured windows; Kungfu's census spans the v4 bootstrap through the operating cutoff.",
    "Attribution examples do not prove AI authorship of every change or isolate Agent use as the sole cause of the output difference.",
    "Different review, merge, and PR-splitting disciplines remain a confounder; the raw records are published so readers can test alternative measures."
  ]
}
